Skip to main content

1.6 Legislation

The EU AI Act

Take-home messages

    Der EUWhen AI Act,is alsdeployed derinstitutionally, the school or school authority is generally responsible—not each individual teacher.

    Schools einheitlichemust Rechtsrahmensupport fürthe Künstlichedevelopment Intelligenzof derAI EU,literacy tratamong amtheir 01.08.2024staff. offiziellNo specific training course or certificate is prescribed.

    Biometric emotion recognition is generally prohibited in Kraft.educational Derinstitutions.

    Rechtsrahmen teilt KI-Systeme

    Not nachall AI-generated teaching materials have to be labelled.

    Ordinary derenwriting, Risikoresearch, fürtranslation dieand menschlichelesson-planning Gesundheit,tools Sicherheitare undnot Grundrechteautomatically einclassified as high-risk AI.

    AI undmay reguliertbecome derenhigh-risk Einsatzwhen entsprechendit dieserinfluences Einteilungadmission, educational pathways, learning outcomes, examinations or employment decisions.

    .The Diespecific fürobligations Schulenfor undhigh-risk Lehrkräfte zentralen RegelungenAI in aeducation nutshell:will generally apply from 2 December 2027.

    Pflichten

    SchulenHigh-risk oderAI Lehrkräftemay geltenonly nachbe demused EUwith effective human oversight.

    National data protection, education, employment, child protection and copyright law continue to apply alongside the AI Act.

    If you remember only one sentence from this page:

    Use AI to support your professional judgement, not replace it—stricter rules apply as soon as AI helps make decisions about grades, educational pathways or people.

    What teachers need to know

    Who is responsible for the use of AI?

    If a school introduces and controls an AI-system, the school or school authority is usually the deployer (Art. 3). The teacher is normally not a separate deployer when he or she uses the tool under the school’s instructions. However, the teacher must follow those instructions and all relevant school and data-protection rules.

    Teachers need to know what they are using

    Schools and school authorities must take appropriate measures to support the development of AI literacy among those who use AI systems on their behalf (Art. 4). The AI Act alsdoes KI-Betreiber.not Siespecify sinda entsprechendparticular fürlevel denof ordnungsgemäßencompetence, undcertificate verantwortungsbewusstenor Einsatztraining bzw.format, Betriebbut desrather KI-Systemsdescribes verantwortlich.this Dasas bedeutet,depending dieon KIthe gemäßAI-system derto durchbe dieused, KI-Anbeiterthe (e.g.,intended Softwareunternehmen)way mitgelierfertenof Betriebsanleitungusage zuand nutzenwho undmay diebe menshclicheaffected Aufsichtby sicherzustellen.

    the

    KI-Fortbildung (§4):usage. Schulleitungen sind gesetzlich dazu verpflichtet Maßnahmen zu ergreifen, um sicherzustellen dass Lehrkräfte und Verwaltung, die KI-Systemen im Rahmen ihrer Arbeit einsetzen über ein "ausreichendes Maß an KI-Kompetenz" verfügen. KI-Fortbildungen sind entsprechend für den rechtskonformen Einsatz von KI eine verpflichtende Voraussetzung. Während angemessene KI-Kompetenz nach dem AI Act mit dem jeweiligen Eisnatzkontext etc. abhängt, wird ausdrücklich ein grundlegendes technisches Verständnis der FUnktionsweise von KI-Systemen als Teil dessen beschrieben, da dieses notwendig ist, um eine verantwortliche Überwachung und Risikobeurteilung beim Einsatz von Hochrisikosystemen zu gewährleisten.

    Infromations- bzw. Transparenzpflicht (§26): Bei der Interaktion mit KI-Systemen (z.B. Chatbot) oder KI-generierten Inhalten (z.B. bei Lehr-Lernmaterialien) muss der KI-Hintergrund klar offengelegt werden.

    Registrierungspflicht (§49): Schulen, Hochrisikosysteme betreiben, müssen sich und das verwendete System in einer öffentlichen EU-Datenbank für Hochrisiko-KI-Systeme registrieren.

    Grundrechte-Folgeabschätzung (§27): Vor dem Einsatz eines Hochrisikosystems, muss eine formale Abschätzung spezifischer Risiken bzw. Auswirkungen auf die Grundrecht aller betroffenen Personengruppen (Lehrkräfte, Eltern, SchülerInnen) durchgeführt werden. Entsprechend müssen Abhilfemaßnahmen dokumentiert werden. Ergebnisse dieser Abschätzung sind an nationale Marktüberwachungsbehörden zu übermitteln.

    Interne Zuständigkeiten: Schulen müssen intern Zuständigkeiten für die menschliche Aufsicht und das Risikomanagement festlegen.

     

    Verbote

    Verboten: KI zur "flächendeckenden" bzw. klassenübergreifenden Emotionserkennung in Schulen grundsätzlich verboten (ausgenommen sind medizinische oder sicherheitstechnische Gründe) 

    Hochrisikosysteme: sobald KI-Systeme einen Einfluss auf Benotung oder Bewertung jeglicher Art nehmen (und damit den Bildungszugang potenziell beeinflussen) oder wenn sie ein Profiling vornehmen, gelten sie als Hochrisikosysteme -

    Solche System dürfen zwar eingesetzt werden, aber es muss sichergestellt werden, dass sie
    (1) Strikt nach Betriebsanleitung verwendet werden,
    (2) die eingespeisten Daten (z.B. Schülerarbeiten) relevant und ausreichend repräsentativ für den Bewertungszweck (§26, Abs. 4) sind,
    (3) jegliche Ausgabe des Systems unter qualifizierter menschlicher Aufsicht (durch die Lehrkraft) geprüft/überwacht wird (§14 & 26),
    (4) von dem KI-System erzeugte Protokolle (sogenannte Logs) für mindestens sechs Monate aufbewahrt werden (§26) und
    (5) die SchülerInnen über den Einsatz der Systeme akiv informiert werden.

    Ausnahme: Ein System, das für die Bewertung/Benotung verwendet wird, gilt ausnahmsweise NICHT als Hochrisikosystem, wenn es lediglich als ein Korrektiv ohne Profiling eignesetzt wird - wenn es also dazu dient Entschiedungsmuster oder Abweichungen von früheren Entscheidungen zu erkennen und darauf aufmerksam zu machen.

    Emotion recognition is a red line

    Zusammenspiel mit nationalem Recht: Der EUUsing AI Actsystems lässtin bestehendeeducational nationaleinstitutions Gesetzeto ausdrücklichinfer unberührtemotions undor verweistintentions auffrom diese.biometric Dasdata, bedeutet,such dassas nationalestudents' Rechtsvorschriftenfacial or vocal characteristics, is generally forbidden (z.B.Art. zum3(39); Datenschutz,Art. 5). SchutzNarrow vonexceptions Minderjährigenexist for medical or safety purposes.

    Does oderAI-generated content need a label?

    If students interact directly with an AI system, such as a chatbot, they must be informed that they are interacting with AI. The system provider is primarily responsible for making this clear Arbeitnehmerschutzrechte(Art. für Lehrkräfte) weiterhin zu gültig sind. Hier verlinken bzw. verweisen auf die nationalen Erweiterungen50).

    VoraussichtlichSchools nationaland zuständigeteachers Marktüberwachungsbehörden:
    must disclose or label deepfakes or published AI-generated text on matters of public interest when they are used in classroom. However, this requirement does not apply where the Ai-generated content has undergone effective human review or editorial control and a person or institution assumes editorial responsibility for its publication (Art. 50).
    An AI-assisted worksheet reviewed by a teacher therefore does not automatically require a label.

    When AI in education becomes high-risk

    Ordinary writing, translation, research and lesson-planning tools are not high-risk simply because they are used for work. Classification depends on the system’s intended purpose, not simply on which product is used (Art. 6 · Annex III).

    AI systems may be classified as high-risk when they are intended to:

    • Österreich:

      decide Dieadmission or access to education;Rundfunk

      und Telekom Regulierungs-GmbH (RTR) wurde als zentrale KI-Servicestelle benannt; die Marktüberwachung wird voraussichtlich im Verbund mit Fachministerien erfolgen.
    • Deutschland:

      assign Diestudents to schools, programmes or educational pathways;Bundesnetzagentur

      (BNetzA) ist als zentrale Marktüberwachungsbehörde vorgesehen, in enger Abstimmung mit dem Bundesbeauftragten für den Datenschutz (BfDI).
    • Spanien:

      evaluate Spanienlearning hatoutcomes mitor derguide a student’s learning process;AESIA

      (Agencia Española de Supervisión de la Inteligencia Artificial) bereits als erstes Land eine dedizierte KI-Aufsichtsbehörde geschaffen.
    • Tschechien:

      determine Diethe Zuständigkeitappropriate liegtlevel primärof beimeducation for a student;Ministerium

      für Industrie und Handel.
    • Slowakei:

      detect Hierprohibited übernimmtbehaviour voraussichtlichduring dasexaminations;

      Amt für die Regulierung der elektronischen Kommunikation und der Postdienste.
    • Lettland:

      recruit Dieteachers;

      Marktüberwachung wird voraussichtlich durch das Zentrum für den Schutz von Verbraucherrechten (PTAC) wahrgenommen.
    • Slowenien:

      allocate Daswork among teachers; or Ministerium

      für
    digitale Transformation

    evaluate koordiniertteachers’ dieperformance.

    Umsetzung.


    A limited checking or preparatory tool may also fall outside the high-risk category if it does not significantly influence a decision. However, an education system that profiles individuals is always considered high-risk.

    What must additionally be organised for high-risk AI?

    The following obligations will generally apply to high-risk AI uses in education from 2 December 2027. They are primarily addressed to schools and school authorities:

      Operation and monitoring: The system must be used in accordance with its instructions and monitored for risks and serious incidents (Art. 26(1) and (5)).

      Human oversight: Suitable individuals must be assigned to oversee the system. They need the necessary competence, training and authority, as well as the ability to disregard, override or reverse its outputs (Art. 14(4); Art. 26(2)).

      Input data: Where input data is under the school’s control, it must be relevant to the system’s intended purpose and sufficiently representative (Art. 26(4)).

      Logs: Automatically generated logs must generally be retained for at least six months where they are under the deployer’s control (Art. 26(6)).

      Information: People affected must be informed when the system makes or assists with decisions about them. Where it is used in the workplace, employees and workers’ representatives must also be informed in advance (Art. 26(7) and (11)).

      Public-law bodies and private organisations providing public services must also conduct a fundamental rights impact assessment before first using such a system (Art. 27). Public authorities and entities acting on their behalf must generally register the relevant high-risk system in the EU database (Art. 49(3)).

      Whether these obligations fall on an individual school or its governing authority depends on the national organisational structure. The AI Act does not require the appointment of a specific AI officer.

      AustriaNational guidelines and supervision

      The AI Act does not replace national regulations on data protection, education, employment and worker participation, child protection or copyright. An application may therefore be permissible under the AI Act but prohibited under data protection or education law. Conversely, compliance with data protection law does not automatically mean that an application complies with the AI Act.

      Market surveillance is organised nationally and may be divided between several general and sector-specific authorities. As responsibilities may change, an information page should link to the European Commission’s current overview of national market surveillance authorities rather than provide a static country list.

       

      Czechia

      Germany

      Latvia