Skip to main content

1.6 Legislation

Take Home message

    The EU AI Act is the legal basis for all of this. Regulation (EU) 2024/1689 is the EU’s single rulebook for AI, in force since August 2024 and phasing in through 2027 — it applies to schools, not just tech companies. AI literacy is a duty, not a course to tick off. Schools must support staff in building AI literacy. Two uses are banned outright. Inferring students’ emotions from facial or vocal data is prohibited in schools, and so is AI that exploits children’s vulnerabilities to distort their behaviour and cause them harm. Risk depends on the decision, not the product. Ordinary writing, research, translation and lesson-planning tools are not high-risk simply because they are used at school. They become high-risk once they influence admission, learning pathways, exam outcomes or employment decisions. Not everything AI-generated needs a label. The disclosure duty mainly sits with the provider; teacher-reviewed material with human editorial control is exempt. High-risk AI needs a human who can overrule it. AI output is never the final decision. You must understand its limits and be able to disregard or override it. The AI Act sits on top of other law, it doesn’t replace it. National data protection, education, employment, child protection and copyright law continue to apply alongside it.

    If you remember only one sentence from this page: Use AI to support your professional judgement, not replace it—stricter rules apply as soon as AI helps make decisions about grades, educational pathways or people.

    Who is responsible for the use of AI?

    If a school introduces and controls an AI system, the school or school authority is usually the deployer (Art. 3(4)). The teacher is normally not a separate deployer when using the tool under the school’s instructions, but must still follow those instructions and all relevant school and data-protection rules.

    Teachers need to know what they are using

    Schools and school authorities must take appropriate measures to support the development of AI literacy among those who use AI systems on their behalf (Art. 4). The AI Act does not specify a particular level of competence, certificate or training format. These rather depend on the AI system used, how it is used, and who may be affected.

    Two red lines for schools

    There are two no-gos in regard to the usage of AI systems in schools:

    1. Using AI systems in educational institutions to infer emotions or intentions from biometric data (such as students' facial or vocal characteristics) is generally forbidden. Narrow exceptions exist for medical or safety purposes (Art. 3(39); Art. 5(1)(f)).
    2. AI systems that exploit children'someone’s vulnerabilities becausedue ofto theirage age,(as andwith therebychildren), distortdisability, theiror behavioursocial or economic situation, in a way that distorts their behaviour and causes them harm, are banned regardless of intent (Art. 5(1)(b)).

    Does AI-generated content always need a label?

    If students interact directly with an AI system, such as a chatbot, they must be informed that they are interacting with AI. Usually the system provider is responsible for making this clear (Art. 50(1)).

    Schools and teachers must disclose deepfakes, or AI-generated text published on matters of public interest, when these are used in the classroom (Art. 50(4)). This requirement does not apply where the AI-generated content has undergone effective human review or editorial control, and a person or institution assumes editorial responsibility for its publication. An AI-assisted worksheet reviewed by a teacher therefore does not automatically require a label.

    When AI in education becomes high-risk

    Ordinary writing, translation, research and lesson-planning tools are not high-risk simply because they are used for work. Classification depends on the system's intended purpose, not simply on which product is used (Art. 6 · Annex III).

    AI systems may be classified as high-risk when they are intended to:

    For Teachers For Schools
    • decide about students' access, admission or assignment to educational or vocational institutions and programmes;
    • evaluate students' learning outcomes or steer their learning processes;
    • assess the appropriate level of education a student will receive or can access; or
    • detect students' prohibited behaviour during examinations.

    (Annex III, point 3)

    • recruit or select teachers, including screening applications;
    • decide on contract terms, promotion or termination of a teacher's employment;
    • allocate tasks based on a teacher's behaviour or personal traits; or
    • evaluate teachers' performance.

    (Annex III, point 4)

    A limited checking or preparatory tool may also fall outside the high-risk category if it does not significantly influence a decision. However, an education system that profiles individuals is always considered high-risk.

    What high-risk AI means for schools and teachers

    Classification of an AI system as high-risk does not automatically rule it out from use in schools. But high-risk systems come with obligations (Art. 26):

    These obligations for high-risk AI in education apply from 2 December 2027 — but the prohibitions above and the AI-literacy duty already apply today.

    For Teachers For Schools
    • use it only for its approved purpose and follow its instructions;
    • do not treat its output as a final decision;
    • understand its main limitations and likely sources of error;
    • watch for overreliance on apparently convincing results; and
    • be prepared to disregard or override its output.
    • provide competent and authorised human oversight;
    • ensure that any input data under its control is relevant and sufficiently representative;
    • monitor the system and respond to risks or serious incidents;
    • keep automatically generated logs for at least six months where those logs are under its control; and
    • inform students, teachers or affected people in advance when the system assists decision-making about them.

    Public bodies and private organisations providing public services may also have to complete a fundamental rights impact assessment before using high-risk AI (Art. 27). Public authorities and organisations acting on their behalf may additionally have to register the system in the EU database (Art. 49). Whether this is the responsibility of the school or its governing authority depends on the national school system.

    The AI Act is not the only law that matters

    The AI Act does not replace national regulations on data protection, education, employment and worker participation, child protection or copyright (Art. 2(7)). For example, the fact that a tool is not high-risk does not mean that you may upload students' work or personal data to it. A tool may be acceptable under the AI Act but still prohibited by data-protection law or your school's rules.

    Where to find help

    Enforcement is organised differently in each EU country. Because national responsibilities may change, use the European Commission's current list of national market-surveillance authorities. Anyone (a teacher, a student, a parent) can lodge a complaint with that authority if they believe the Act has been breached (Art. 85). Where a high-risk system, such as an admission or exam-monitoring tool, has led to a decision that significantly affects a student, they (or their parents) can also ask for an explanation of that individual decision (Art. 86).

    National rules for your country

    The AI Act is EU-wide, but enforcement bodies, school law and data-protection practice differ by country. Country-specific notes for the Playbook's partner countries will be added here:

    • Austria
    • Czechia
    • Germany
    • Latvia
    • Slovakia
    • Slovenia
    • Spain