1.4 Compliant Use of AI
Take Home message
-
There is no legal vacuum. Data protection law has applied all along.
- The timetable moved. The high-risk duties for education AI start on 2 December 2027, not August 2026. Check your school's handouts.
- Already binding since February 2025. Emotion recognition in schools is prohibited, and schools deploying AI must ensure staff competence. Labelling of AI-generated content starts in August 2026.
- The hardest layer is data protection. No personal data about pupils without a contract that excludes training on your inputs; consent usually does not carry; deleting names is not anonymizing.
- In copyright, the upload is the problem. The teaching exception does not cover feeding protected works into an AI.
- Detectors do not hold up as evidence. Reasoned inference from concrete signs does. Rules must be clear in advance, and labeling beats banning.
- Grades stay human — and rubber-stamping an AI's suggestion is not a human decision.
- Responsibility sits with procurement, not with you — and compliance enables. The schools with clear rules are the ones whose teachers report saving the most time.
If you remember only one sentence from this page: Compliance is a house, not a wall.
The reading journal, third look
Our ninth-grade student, his reading journal, his teacher's suspicion. In Chapter 1.3, it was a question about learning; in Chapter 1.4, about professional judgment. Here it is a court file.
In December 2025 the Administrative Court of Hamburg, Germany, ruled on an urgent application in the case. The teacher had noticed that the journal did not match the boy's writing style in a class test. As a consequence, the school treated it as deception. This was followed by an urgent application to stop this, but the court refused. Undisclosed AI use in schoolwork counts as deception even where the school has no explicit rule against AI. All students must assume they are to work independently unless they have been told which aids are allowed. One caveat to keep in mind from the outset: this is a single court, and the decision is not yet final.
This is a good moment to address the most common misconception in this field. There is no legal vacuum. There never has been.
The house has three storeys
Most teachers envisage AI law as a single wall under construction somewhere in Brussels. However, it is more useful to picture a house that you already live in. The foundation is data protection. It is load-bearing. It was laid years ago. It governs your Tuesday morning. The upper storey is the EU AI Act, Europe's AI law, which categorizes systems according to their potential for harm and imposes stricter obligations the higher the risk. It is partly occupied and still under construction, with the completion date just pushed back. The doors and windows are copyright and examination law — small and specific, and touched daily without noticing.
Ground floor: data protection, clearer than many think
Handling someone's personal data always requires legal permission. As a public body, a school's permission essentially comes from its statutory duties under school law. There is no general license that comes with being a teacher.
Three consequences follow, forming the practical core of this chapter.
Consent does not provide a solution. One obvious solution would be to simply ask the parents. However, this approach has two drawbacks. Firstly, consent must be freely given. In a school context where grades are a factor, a teacher's request does not constitute a free choice. Secondly, consent must be informed, which is difficult to achieve when nobody knows where the data will end up. Permission must come from school law, not a signature, as this shifts responsibility upwards, away from you.
Removing names does not anonymize data. In 2024, Germany's data protection authorities jointly stated that if someone could still be identified from the context, the data is still personal. This is particularly problematic in schools because the types of text that teachers most want help with — such as essays, free writing and learning journals — identify their author by style.
The dividing line is the contract: a provider may handle your data if it does so strictly on your instructions and there is a written agreement to this effect. However, the moment it uses what you type for its own purposes, the arrangement collapses because it is no longer working on your behalf. So the practical test is this: Is there such an agreement, and does it exclude training on your inputs? If not, no personal data should be entered.
Two footnotes worth noting: Data relating to health, disability, and special educational needs is subject to even stricter protection under EU law, and at least one German state (Baden-Württemberg) has explicitly prohibited its use in AI systems by ministerial decree. Where private devices are involved, the legal responsibility lies with the school, not you personally, which relieves you and obliges your head teacher.
Upper floor: what the AI Act does and does not require yet
Here is the correction that makes most existing guidance out of date. In July 2026, the EU postponed the heaviest set of AI Act duties for education, which are those attaching to systems classed as high-risk, meaning systems used to decide admissions, to assess what pupils have learned, or to monitor them during examinations, from August 2026 to 2 December 2027. A great many handouts written in 2025 and early 2026 still print the old date. If a document in your school does, it needs a footnote.
The more useful correction runs the other way: what already applies is underestimated, and what is endlessly discussed does not apply yet.
Two things have been binding since 2 February 2025.
- Emotion recognition in schools is prohibited outright. Systems that claim to read pupils' feelings — attention detection, mood analytics, "engagement" scoring from a webcam — are not a grey area. They sit on the Act's short list of practices that are simply banned.
- Schools that deploy AI must make sure their staff know what they are doing with it. No fine is attached to this one, which is why it is widely overlooked. It is binding all the same.
Read that second duty alongside Chapter 1.3 and something clicks. The gap between knowing about AI and being able to teach with it is no longer only a professional problem. Since February 2025 it has been a legal obligation.
Since 2 August 2026, AI-generated content has to be labeled as such. From 2 December 2027, systems used to decide who gets admitted, to assess what pupils have learned, or to monitor them during examinations count as high-risk. Whoever uses such a system then assumes the duties that come with it. This incorporates a requirement that the people overseeing it be, in the Act's words, "competent, trained and authorised". Note the wording. The law has arrived at the same conclusion as the pedagogy: oversight without expertise is not oversight.
Doors and windows: copyright and examinations
Counter-intuitively, what comes out is the easy part. A text or image generated by an AI generally has no human author in the sense copyright requires, so it is usually free of copyright itself. It is not, however, guaranteed to be clean: in the first major European ruling of its kind, a Munich court found that a chatbot had memorized song lyrics and reproduced them almost word-for-word. The court placed the liability on the provider, not on the person who typed the request. Whether a teacher who passes on such material could be liable is, as things stand, an open question. What goes in is the clearer problem, but note that this is a question of copyright, not of the AI Act. The AI Act says nothing about what teachers may feed into a system; that is an older and entirely separate body of law.
The exception that lets teachers copy material for their classes covers exactly that: copying a limited share of a work, for that class. Uploading a protected work into a commercial AI system is a different act, and the exception does not address it. Material intended for school teaching, which is mainly textbooks, is excluded from the exception in any case. So scanning a chapter to have it summarised is an everyday act that the teaching exception does not obviously cover.
How much should that worry you? Less than the gap suggests, and more than nothing. The question is genuinely unsettled: no higher court has ruled on it, and the specialist literature regards the existing exceptions as a poor fit for the situation. Where a rights holder objects, the claim would be a civil one, and in practice, this is a matter for school policy and procurement rather than something an individual teacher can settle. What is not unsettled is the narrow case, and it is the line worth remembering: school textbook and publisher material should not go into AI tools at all — neither scanned nor retyped, not even to generate a worksheet.
Case law in this field seems currently inconsistent across Europe. In February 2026, the Administrative Court of Kassel, Germany, decided two university cases the same way, and sharply: where a student has signed a declaration that the work is their own, the line is crossed "already with a single undisclosed use of generative AI". A Paris administrative court, in February 2026, forbade a university to sanction a student at all: it had produced no rule governing AI use, and without a rule set out in advance there was no disciplinary breach to find. A Swedish appeal court had reached the same result earlier, on facts almost identical to a Dutch case that went the other way. In this case, a student submitted invented sources, but the course rules permitted "all aids" in take-home work, so there was nothing to have broken. Where fabrication was clearly proven, and a rule existed, courts have upheld sanctions. The Dutch Supreme Administrative Court did so in 2025.
So the pattern across jurisdictions is not about countries. It is about whether a rule existed beforehand, and whether the deception was actually shown.
Three rules follow for practice.
- Detectors do not carry the burden of proof. What the law does allow is an inference from typical signs. This includes repeated, oddly polished phrasing, a mismatch between what they can write and what they can say, and sources that turn out not to exist. The student can then explain. That is a legitimate route, and it does not require software. Detector output, at best, is one sign among others. The failure rate reported in Chapter 1.4 renders the instrument unusable as evidence.
- Rules must be clear before the assessment, not after. Neither a blanket ban nor a blanket permission holds up. What works is a declaration of independent work with a general clause about AI, plus a duty to state what was used. In Germany, Bavaria went furthest in 2026: its universities may not forbid AI in unsupervised assessments at all, but must require students to declare it. Labeling instead of banning.
- Grades stay human. No decision with legal consequences for a person may be made by a machine alone, and a grade is such a decision. Germany's Standing Conference of the Education Ministers puts it even more strongly: assessment is a task only teachers can perform. Crucially, formally waving through an AI's suggestion does not count as a human decision. So the finding from Chapter 1.4, wrong AI feedback is also a pedagogical and a legal problem.
Law, ethics and didactics therefore converge on the same answer: assess the process, not just the product.
The real address of responsibility
In response, Germany has introduced state-provided school AI environments. These are vetted platforms with negotiated contracts, rather than leaving teachers to sign up to whatever is free. While these solve problems that individual teachers cannot solve alone, they are still criticized for how they are governed, whether teachers actually accept them and whether the assessments they support are sound. Since the rollout is currently limited to a select group of schools and specific subjects, we will need to monitor over the next few months how teachers are faring with the platforms.
What is distinctive is narrower than it may initially appear, and it is worth stating precisely: Rather than putting it out to tender or buying access to someone else's, Germany is the only European system where a state body builds and runs the platform itself. France also provides a platform for an entire year group, but it commissioned one and two private companies deliver it: one wrote the software and the other hosts the data. Most of the rest of the continent has simply purchased one. Slovakia has gone the furthest, with 20,000 licences for teacher training faculties that will be extended towards some 80,000 school teachers by 2026. The state will only pay for the licences actually used, and the provider is contractually barred from training on Slovak school data. Estonia negotiated a similar arrangement for its upper secondary schools, and Northern Ireland invested £10.7 million in licences for all teachers in all schools. The contractual guarantee that your inputs are not used for training — the feature that the German platform was designed to provide — can be purchased.
Building it yourself does not automatically give you more control. The German platform runs on the same commercial language models as everyone else's on European servers, as an industry association has pointed out. By contrast, the French system is hosted in France under the highest security certification issued by the French state. One country built the surface and rents the engine, while the other bought the software and keeps the keys to the building. Neither option is clearly the most sovereign choice, which is worth bearing in mind before using the term.
The Netherlands took a different approach, and it is worth knowing about because it offers a more honest answer to the same question. Rather than building or buying, Dutch schools and universities joined forces and had the major providers formally assessed. When they examined Microsoft's AI assistant, they found two issues that could not be resolved: the criteria for an automatic content filter that the provider would not disclose and the retention of eighteen months of diagnostic data that could not be justified. They negotiated. In March 2026, however, the provider declined to change. The assessment therefore remains amber, and Dutch schools are advised to exercise caution and use their own judgement on a case-by-case basis rather than granting clearance. One country removed the risk by building around it, while another took a closer look and decided it was not ready yet. Both approaches offer solutions to the problem set out at the start of this chapter.
The comparison also settles one more thing. The complaint that teachers prefer the free chatbot to the official one is not due to a failure of implementation in Germany. In Estonia, where the state negotiated access for every upper-secondary student, barely more than a third were using the official chatbot weekly after a year. In turned out, that most of them had been using free tools before the program started. Everywhere, the vetted environment competes with the more convenient one. Providing the official tool is necessary. But this is not sufficient.
However, the structural point stands: compliance is an enabling condition, not a hindrance. Remember what was said in Chapter 1.2? The schools with clear rules were the ones whose teachers said they saved the most time. There is nothing in the sources behind these chapters that suggests otherwise.