1.6 Legislation
The EU AI Act
Take-home messages
-
When AI is deployed institutionally, the school or school authority is generally responsible—not each individual teacher.
-
Schools must support the development of AI literacy among their staff. No specific training course or certificate is prescribed.
-
Biometric emotion recognition is generally prohibited in educational institutions.
-
Not all AI-generated teaching materials have to be labelled.
-
Ordinary writing, research, translation and lesson-planning tools are not automatically classified as high-risk AI.
-
AI may become high-risk when it influences admission, educational pathways, learning outcomes, examinations or employment decisions.
-
The specific obligations for high-risk AI in education will generally apply from 2 December 2027.
-
High-risk AI may only be used with effective human oversight.
-
National data protection, education, employment, child protection and copyright law continue to apply alongside the AI Act.
If you remember only one sentence from this page:
Use AI to support your professional judgement, not replace it—stricter rules apply as soon as AI helps make decisions about grades, educational pathways or people.
What teachers need to know
Who is responsible for the use of AI?
If a school introduces and controls an AI-system, the school or school authority is usually the deployer (Art. 3). The teacher is normally not a separate deployer when he or she uses the tool under the school’s instructions. However, the teacher must follow those instructions and all relevant school and data-protection rules.
Teachers need to know what they are using
Schools and school authorities must take appropriate measures to support the development of AI literacy among those who use AI systems on their behalf (Art. 4). The AI Act does not specify a particular level of competence, certificate or training format, but rather describes this as depending on the AI-system to be used, the intended way of usage and who may be affected by the usage.
Emotion recognition is a red line
Using AI systems in educational institutions to infer emotions or intentions from biometric data, such as students' facial or vocal characteristics, is generally forbidden (Art. 3(39); Art. 5). Narrow exceptions exist for medical or safety purposes.
Does AI-generated content need a label?
If students interact directly with an AI system, such as a chatbot, they must be informed that they are interacting with AI. The system provider is primarily responsible for making this clear (Art. 50).
Schools and teachers must disclose or label deepfakes or published AI-generated text on matters of public interest when they are used in classroom. However, this requirement does not apply where the Ai-generated content has undergone effective human review or editorial control and a person or institution assumes editorial responsibility for its publication (Art. 50). An AI-assisted worksheet reviewed by a teacher therefore does not automatically require a label.
When AI in education becomes high-risk
Ordinary writing, translation, research and lesson-planning tools are not high-risk simply because they are used for work. Classification depends on the system’s intended purpose, not simply on which product is used (Art. 6 · Annex III).
AI systems may be classified as high-risk when they are intended to:
| For Teachers | For Schools |
|
|
A limited checking or preparatory tool may also fall outside the high-risk category if it does not significantly influence a decision. However, an education system that profiles individuals is always considered high-risk.
What high-risk AI means for schools and teachers
Classification of an AI system as high-risk does not automatically rule it ouzt from usage in schools. But high-risk systems come with obligations (Art. 26):
| For Teachers | For Schools |
|
|
Public bodies and private organisations providing public services may also have to complete a fundamental rights impact assessment before using high-risk AI (Art. 27). Public authorities and organisations acting on their behalf may additionally have to register the system in the EU database. Whether this is the responsibility of the school or its governing authority depends on the national school system (Art. 49).
The AI Act is not the only law that matters
The AI Act does not replace national regulations on data protection, education, employment and worker participation, child protection or copyright. For example, the fact that a tool is not high-risk does not mean that you may upload students’ work or personal data to it (Art. 2). A tool may be acceptable under the AI Act but still prohibited by data-protection law or your school’s rules.
Where to find help
Enforcement is organised differently in each EU country. Because national responsibilities may change, use the European Commission’s current list of national market-surveillance authorities.