1.6 Legislation
Take Home message
- The EU AI Act is the legal
basis for all of this.basis. Regulation (EU) 2024/1689 is the EU’s single rulebook for AI, in force since August 2024 and phasing in through2027 —2027, it applies to schools, not just tech companies. - AI literacy is a duty, not a course to tick off. Schools must support staff in building AI literacy.
- Two uses are banned outright. Inferring students’ emotions from facial or vocal data is prohibited in schools, and so is AI that exploits children’s vulnerabilities to distort their behaviour and cause them harm.
- Risk depends on the decision, not the product. Ordinary writing, research, translation and lesson-planning tools are not high-risk simply because they are used at school. They become high-risk once they influence admission, learning pathways, exam outcomes or employment decisions.
- Not everything AI-generated needs a label. The disclosure duty mainly sits with the provider; teacher-reviewed material with human editorial control is exempt.
- High-risk AI needs a human who can overrule it. AI output is never the final decision. You must understand its limits and be able to disregard or override it.
- The AI Act sits on top of other law, it doesn’t replace it. National data protection, education, employment, child protection and copyright law continue to apply alongside it.
If you remember only one sentence from this page: Use AI to support your professional judgement, not replace it—stricter rules apply as soon as AI helps make decisions about grades, educational pathways or people.
Who is responsible for the use of AI?
If a school introduces and controls an AI system, the school or school authority is usually the deployer (Art. 3(4)). The teacher is normally not a separate deployer when using the tool under the school’s instructions, but must still follow those instructions and all relevant school and data-protection rules.
Teachers need to know what they are using
Schools and school authorities must take appropriate measures to support the development of AI literacy among those who use AI systems on their behalf (Art. 4). The AI Act does not specify a particular level of competence, certificate or training format. These rather depend on the AI system used, how it is used, and who may be affected.
Two red lines for schools
There are two no-gos in regard to the usage of AI systems in schools:
- Using AI systems in educational institutions to infer emotions or intentions from biometric data (such as students' facial or vocal characteristics) is generally forbidden. Narrow exceptions exist for medical or safety purposes (Art. 3(39); Art. 5(1)(f)).
- AI systems that exploit someone’s vulnerabilities due to age (as with children), disability, or social or economic situation, in a way that distorts their behaviour and causes them harm, are banned regardless of intent (Art. 5(1)(b)).
Does AI-generated content always need a label?
If students interact directly with an AI system, such as a chatbot, they must be informed that they are interacting with AI. Usually the system provider is responsible for making this clear (Art. 50(1)).
Schools and teachers must disclose deepfakes, or AI-generated text published on matters of public interest, when these are used in the classroom (Art. 50(4)). This requirement does not apply where the AI-generated content has undergone effective human review or editorial control, and a person or institution assumes editorial responsibility for its publication. An AI-assisted worksheet reviewed by a teacher therefore does not automatically require a label.
When AI in education becomes high-risk
Ordinary writing, translation, research and lesson-planning tools are not high-risk simply because they are used for work. Classification depends on the system's intended purpose, not simply on which product is used (Art. 6 · Annex III).
AI systems may be classified as high-risk when they are intended to:
| For Teachers | For Schools |
(Annex III, point 3) |
(Annex III, point 4) |
A limited checking or preparatory tool may also fall outside the high-risk category if it does not significantly influence a decision. However, an education system that profiles individuals is always considered high-risk.
What high-risk AI means for schools and teachers
Classification of an AI system as high-risk does not automatically rule it out from use in schools. But high-risk systems come with obligations (Art. 26):
These obligations for high-risk AI in education apply from 2 December 2027 — but the prohibitions above and the AI-literacy duty already apply today.
| For Teachers | For Schools |
|
|
Public bodies and private organisations providing public services may also have to complete a fundamental rights impact assessment before using high-risk AI (Art. 27). Public authorities and organisations acting on their behalf may additionally have to register the system in the EU database (Art. 49). Whether this is the responsibility of the school or its governing authority depends on the national school system.
The AI Act is not the only law that matters
The AI Act does not replace national regulations on data protection, education, employment and worker participation, child protection or copyright (Art. 2(7)). For example, the fact that a tool is not high-risk does not mean that you may upload students' work or personal data to it. A tool may be acceptable under the AI Act but still prohibited by data-protection law or your school's rules.
Where to find help
Enforcement is organised differently in each EU country. Because national responsibilities may change, use the European Commission's current list of national market-surveillance authorities. Anyone (a teacher, a student, a parent) can lodge a complaint with that authority if they believe the Act has been breached (Art. 85). Where a high-risk system, such as an admission or exam-monitoring tool, has led to a decision that significantly affects a student, they (or their parents) can also ask for an explanation of that individual decision (Art. 86).
National rules for your country
The AI Act is EU-wide, but enforcement bodies, school law and data-protection practice differ by country. Country-specific notes for the Playbook's partner countries will be added here:
- Austria
- Czechia
- Germany
- Latvia
- Slovakia
- Slovenia
- Spain