Skip to main content

1.6 Legislation

The EU AI Act

Take-home messages

  • When AI is deployed institutionally, the school or school authority is generally responsible—not each individual teacher.

  • Schools must support the development of AI literacy among their staff. No specific training course or certificate is prescribed.

  • Biometric emotion recognition is generally prohibited in educational institutions.

  • Not all AI-generated teaching materials have to be labelled.

  • Ordinary writing, research, translation and lesson-planning tools are not automatically classified as high-risk AI.

  • AI may become high-risk when it influences admission, educational pathways, learning outcomes, examinations or employment decisions.

  • The specific obligations for high-risk AI in education will generally apply from 2 December 2027.

  • High-risk AI may only be used with effective human oversight.

  • National data protection, education, employment, child protection and copyright law continue to apply alongside the AI Act.

If you remember only one sentence from this page:

Use AI to support your professional judgement, not replace it—stricter rules apply as soon as AI helps make decisions about grades, educational pathways or people.

What teachers need to know

Who is responsible for the use of AI?

If a school introduces and controls an AI-system, the school or school authority is usually the deployer (Art. 3). The teacher is normally not a separate deployer when he or she uses the tool under the school’s instructions. However, the teacher must follow those instructions and all relevant school and data-protection rules.

Teachers need to know what they are using

Schools and school authorities must take appropriate measures to support the development of AI literacy among those who use AI systems on their behalf (Art. 4). The AI Act does not specify a particular level of competence, certificate or training format, but rather describes this as depending on the AI-system to be used, the intended way of usage and who may be affected by the usage.

Emotion recognition is a red line

Using AI systems in educational institutions to infer emotions or intentions from biometric data, such as students' facial or vocal characteristics, is generally forbidden (Art. 3(39); Art. 5). Narrow exceptions exist for medical or safety purposes.

Does AI-generated content need a label?

If students interact directly with an AI system, such as a chatbot, they must be informed that they are interacting with AI. The system provider is primarily responsible for making this clear (Art. 50).

Schools and teachers must disclose or label deepfakes or published AI-generated text on matters of public interest when they are used in classroom. However, this requirement does not apply where the Ai-generated content has undergone effective human review or editorial control and a person or institution assumes editorial responsibility for its publication (Art. 50). An AI-assisted worksheet reviewed by a teacher therefore does not automatically require a label.

When AI in education becomes high-risk

Ordinary writing, translation, research and lesson-planning tools are not high-risk simply because they are used for work. Classification depends on the system’s intended purpose, not simply on which product is used (Art. 6 · Annex III).

AI systems may be classified as high-risk when they are intended to:

  • decide admission or access to education;

  • assign students to schools, programmes or educational pathways;

  • evaluate learning outcomes or guide a student’s learning process;

  • determine the appropriate level of education for a student;

  • detect prohibited behaviour during examinations;

  • recruit teachers;

  • allocate work among teachers; or 

  • evaluate teachers’ performance.

A limited checking or preparatory tool may also fall outside the high-risk category if it does not significantly influence a decision. However, an education system that profiles individuals is always considered high-risk.

What must additionally be organised for high-risk AI?

The following obligations will generally apply to high-risk AI uses in education from 2 December 2027. They are primarily addressed to schools and school authorities:

  • Operation and monitoring: The system must be used in accordance with its instructions and monitored for risks and serious incidents (Art. 26(1) and (5)).

  • Human oversight: Suitable individuals must be assigned to oversee the system. They need the necessary competence, training and authority, as well as the ability to disregard, override or reverse its outputs (Art. 14(4); Art. 26(2)).

  • Input data: Where input data is under the school’s control, it must be relevant to the system’s intended purpose and sufficiently representative (Art. 26(4)).

  • Logs: Automatically generated logs must generally be retained for at least six months where they are under the deployer’s control (Art. 26(6)).

  • Information: People affected must be informed when the system makes or assists with decisions about them. Where it is used in the workplace, employees and workers’ representatives must also be informed in advance (Art. 26(7) and (11)).

Public-law bodies and private organisations providing public services must also conduct a fundamental rights impact assessment before first using such a system (Art. 27). Public authorities and entities acting on their behalf must generally register the relevant high-risk system in the EU database (Art. 49(3)).

Whether these obligations fall on an individual school or its governing authority depends on the national organisational structure. The AI Act does not require the appointment of a specific AI officer.

National guidelines and supervision

The AI Act does not replace national regulations on data protection, education, employment and worker participation, child protection or copyright. An application may therefore be permissible under the AI Act but prohibited under data protection or education law. Conversely, compliance with data protection law does not automatically mean that an application complies with the AI Act.

Market surveillance is organised nationally and may be divided between several general and sector-specific authorities. As responsibilities may change, an information page should link to the European Commission’s current overview of national market surveillance authorities rather than provide a static country list.