1.6 Legislation
The EU AI Act
Take-home messages
-
When AI is deployed institutionally, the school or school authority is generally responsible—not each individual teacher.
-
Schools must support the development of AI literacy among their staff. No specific training course or certificate is prescribed.
-
Biometric emotion recognition is generally prohibited in educational institutions.
-
Not all AI-generated teaching materials have to be labelled.
-
Ordinary writing, research, translation and lesson-planning tools are not automatically classified as high-risk AI.
-
AI may become high-risk when it influences admission, educational pathways, learning outcomes, examinations or employment decisions.
-
The specific obligations for high-risk AI in education will generally apply from 2 December 2027.
-
High-risk AI may only be used with effective human oversight.
-
National data protection, education, employment, child protection and copyright law continue to apply alongside the AI Act.
If you remember only one sentence from this page:
Use AI to support your professional judgement, not replace it—stricter rules apply as soon as AI helps make decisions about grades, educational pathways or people.
What teachers need to know
Who is responsible for the use of AI?
If a school introduces and controls an AI-system, the school or school authority is usually the deployer (Art. 3). The teacher is normally not a separate deployer when he or she uses the tool under the school’s instructions. However, the teacher must follow those instructions and all relevant school and data-protection rules.
Teachers need to know what they are using
Schools and school authorities must take appropriate measures to support the development of AI literacy among those who use AI systems on their behalf (Art. 4). The AI Act does not specify a particular level of competence, certificate or training format, but rather describes this as depending on the AI-system to be used, the intended way of usage and who may be affected by the usage.
Emotion recognition is a red line
Using AI systems in educational institutions to infer emotions or intentions from biometric data, such as students' facial or vocal characteristics, is generally forbidden (Art. 3(39); Art. 5). Narrow exceptions exist for medical or safety purposes.
Does AI-generated content need a label?
If students interact directly with an AI system, such as a chatbot, they must be informed that they are interacting with AI. The system provider is primarily responsible for making this clear (Art. 50).
Schools and teachers must disclose or label deepfakes or published AI-generated text on matters of public interest when they are used in classroom. However, this requirement does not apply where the Ai-generated content has undergone effective human review or editorial control and a person or institution assumes editorial responsibility for its publication (Art. 50). An AI-assisted worksheet reviewed by a teacher therefore does not automatically require a label.
When AI in education becomes high-risk
Ordinary writing, translation, research and lesson-planning tools are not high-risk simply because they are used for work. Classification depends on the system’s intended purpose, not simply on which product is used (Art. 6 · Annex III).
AI systems may be classified as high-risk when they are intended to:
-
decide admission or access to education;
-
assign students to schools, programmes or educational pathways;
-
evaluate learning outcomes or guide a student’s learning process;
-
determine the appropriate level of education for a student; or
-
detect prohibited behaviour during
examinations;examinations.
-
recruit teachers;
-
allocate work among teachers; or
-
evaluate teachers’ performance.
A limited checking or preparatory tool may also fall outside the high-risk category if it does not significantly influence a decision. However, an education system that profiles individuals is always considered high-risk.
What musthigh-risk additionallyAI be organisedmeans for high-riskschools AI?and teachers
TheClassification followingof obligationsan willAI generallysystem apply toas high-risk AIdoes usesnot automatically rule it ouzt from usage in educationschools. fromBut 2high-risk Decembersystems 2027.come Theywith areobligations primarily(Art. addressed26):
Operationdo andnot monitoring: The system must be used in accordance withtreat its instructionsoutput andas monitoreda forfinal risks and serious incidents (Art. 26(1) and (5)).decision;
Human oversight:understand Suitableits individualsmain must be assigned to oversee the system. They need the necessary competence, traininglimitations and authority,likely assources wellof as the ability to disregard, override or reverse its outputs (Art. 14(4); Art. 26(2)).error;
watch for Input data:overreliance Whereon inputapparently dataconvincing is under the school’s control, it must be relevant to the system’s intended purposeresults; and sufficiently representative (Art. 26(4)).
be prepared to Logs:disregard or override its output.
provide competent and authorised human oversight;
monitor the system Automaticallyand respond to risks or serious incidents;
ensure that any input data under its control is relevant and sufficiently representative;
keep automatically generated logs must generally be retained for at least six months where theythose logs are under theits deployer’scontrol; control (Art. 26(6)).and
Information:inform Peoplestudents, teachers or affected mustpeople bein informedadvance when the system makes or assists with decisionsdecision-making about them. Where it is used in the workplace, employees and workers’ representatives must also be informed in advance (Art. 26(7) and (11)).
Public-lawPublic bodies and private organisations providing public services mustmay also conducthave to complete a fundamental rights impact assessment before first using suchhigh-risk a systemAI (Art. 27)27). Public authorities and entitiesorganisations acting on their behalf mustmay generallyadditionally have to register the relevant high-risk system in the EU databasedatabase. (Art. 49(3)).
Whether thesethis obligationsis fallthe onresponsibility anof individualthe school or its governing authority depends on the national organisationalschool structure.system (Art. 49).
The AI Act doesis not require the appointmentonly oflaw athat specific AI officer.
National guidelines and supervisionmatters
The AI Act does not replace national regulations on data protection, education, employment and worker participation, child protection or copyright. AnFor applicationexample, the fact that a tool is not high-risk does not mean that you may thereforeupload students’ work or personal data to it (Art. 2). A tool may be permissibleacceptable under the AI Act but still prohibited underby data protection or education law. Conversely, compliance with data data-protection law doesor notyour automaticallyschool’s meanrules.
Where anto applicationfind complies with the AI Act.help
Market surveillanceEnforcement is organised nationallydifferently andin mayeach beEU dividedcountry. betweenBecause several general and sector-specific authorities. Asnational responsibilities may change, an information page should link touse the European Commission’s current overviewlist of national market market-surveillance authoritiesauthorities. rather than provide a static country list.