Free tool

EU AI Act checker for education: is this AI use high-risk?

Describe how your institution uses an AI system and get its likely category under the EU AI Act, the obligations that follow for you as deployer, and the date they apply. The dates reflect the Digital Omnibus on AI, Regulation (EU) 2026/1744, which moved the high-risk rules for education to 2 December 2027.

Published 7 October 2026 · Sources checked 7 October 2026

Pick the closest description of its intended purpose at your institution.

Runs entirely in your browser. Nothing you select is stored or sent anywhere.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

The four categories in education

The AI Act sorts AI systems by risk. For a university, four outcomes matter.

Prohibited: emotion recognition

Article 5(1)(f) bans placing on the market, putting into service or using AI systems that infer the emotions of a natural person in the workplace or in education institutions, unless the system is intended for medical or safety reasons. Article 3(39) defines an emotion recognition system by reference to biometric data. "Engagement" or "attention" tracking from webcam images in a lecture or an online exam is the obvious example to look for in vendor material.

High-risk: Annex III, point 3

Annex III, point 3 lists four education use cases as high-risk:

Transparency obligations: Article 50

Providers of systems that interact directly with people must make sure people are told they are dealing with AI, unless that is obvious (Article 50(1)). Providers of generative systems must mark output in a machine-readable way (Article 50(2)). Deployers must disclose deep fakes, and must disclose AI-generated text published to inform the public on matters of public interest unless it has gone through human review or editorial control (Article 50(4)).

Minimal risk

Everything else, such as summarising, translation or coding help, carries no specific AI Act obligations beyond AI literacy under Article 4. GDPR, copyright and your own policies still apply.

What applies when (after the Digital Omnibus)

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It replaced the application dates in Article 113 of the AI Act. The dates below are the ones in force on 7 October 2026.

RuleApplies from
Prohibited practices, including emotion recognition in education (Article 5(1)(f))2 February 2025
AI literacy (Article 4)2 February 2025; new, softer wording since 27 July 2026
Transparency obligations (Article 50)2 August 2026
Machine-readable marking for generative systems already on the market before 2 August 2026 (Article 50(2), via new Article 111(4))2 December 2026
New prohibitions on non-consensual intimate imagery and child sexual abuse material (Article 5(1)(ba) and (bb))2 December 2026
High-risk rules for Annex III systems, including education, and the deployer duties in Articles 26 and 272 December 2027 (originally 2 August 2026)
High-risk rules for AI in products under Annex I2 August 2028
High-risk systems intended for use by public authorities and already in service before the application date (Article 111(2))Compliance by 2 August 2030

For systems already placed on the market or put into service before 2 December 2027, amended Article 111(2) says the Regulation applies only if they are significantly changed in their design after that date, except that providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030.

What a deployer of a high-risk system must do

A university that uses a vendor's high-risk system is a deployer. Article 26 requires it, among other things, to:

Article 27 adds a fundamental rights impact assessment (FRIA) before first use for deployers that are bodies governed by public law or private entities providing public services. The Digital Omnibus amended Article 27(4) so that the FRIA can cross-refer to, or include parts of, the GDPR DPIA, and asked the AI Office to provide a questionnaire template.

The Article 6(3) derogation

An Annex III system is not high-risk if it does not pose a significant risk of harm, including by not materially influencing the outcome of decision making. Article 6(3) gives four conditions, any of which can apply: a narrow procedural task, improving the result of a completed human activity, detecting patterns or deviations without replacing human assessment, or a preparatory task. A system that profiles natural persons is always high-risk. The provider makes this assessment, documents it and registers the system (Article 6(4)); the Digital Omnibus simplified that registration but kept it. As deployer, ask the vendor for its documented assessment rather than assuming the derogation applies.

When the university becomes the provider

Under Article 25(1), a deployer is treated as the provider of a high-risk system, with the provider obligations of Article 16, if it puts its name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of a system that was not high-risk (including a general-purpose system) so that it becomes high-risk. A system built in-house and put into service under the institution's own name makes the institution the provider under Article 3(3).

Validemic's analysis
The most common way a university becomes a provider without noticing is the third case: a general-purpose chatbot set up by a department to mark assignments or rank applicants. Treat that as a new high-risk system and involve your DPO and legal team before it goes live.

Research use

Article 2(6) excludes AI systems and models, and their output, developed and put into service for the sole purpose of scientific research and development. Article 2(8) excludes research, testing and development before a system is placed on the market or put into service, but not testing in real-world conditions. A commercial AI tool that researchers simply use is not, in our reading, developed for the sole purpose of research, so check it like any other deployment.

Sources

All sources retrieved 7 October 2026.

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 2 to 6, 25 to 27, 50, 111, 113 and Annex III, EUR-Lex: eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  2. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ L, 24.7.2026, EUR-Lex: eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
  3. European Parliamentary Research Service, briefing "Digital Omnibus on AI" (legislative history): europarl.europa.eu, EPRS briefing
  4. Regulation (EU) 2016/679 (GDPR), Articles 22 and 35, EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng

About this tool

We built this tool from the consolidated effect of the AI Act and the Digital Omnibus on AI as published in the Official Journal, read on 7 October 2026. The category it shows is a likely category based on your answers, not a legal classification: the intended purpose stated by the provider, the contract and the way the system is configured all matter. It is not legal advice. The Commission is expected to publish further guidance and templates; check for anything newer than our check date. If you spot an error, please contact us and we will correct it.

Frequently asked questions

Is AI used for grading high-risk under the EU AI Act?

Annex III, point 3(b) lists AI systems intended to evaluate learning outcomes, including when the outcomes steer the learning process, as high-risk. Grading and marking tools therefore fall in scope unless the Article 6(3) derogation applies, for example because the system only performs a narrow procedural task. Systems that profile people are always high-risk.

When do the high-risk rules apply to universities?

Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published on 24 July 2026, set the date for high-risk systems listed in Annex III, which includes education, to 2 December 2027. The original date was 2 August 2026. Prohibitions have applied since 2 February 2025 and the Article 50 transparency rules since 2 August 2026.

Is emotion recognition banned in universities?

Article 5(1)(f) prohibits AI systems that infer the emotions of a natural person in education institutions and workplaces, except for medical or safety reasons. The prohibition has applied since 2 February 2025.

Does the AI Act apply to AI used in research?

Article 2(6) excludes AI systems and models developed and put into service for the sole purpose of scientific research and development, and Article 2(8) excludes research, testing and development before a system is placed on the market or put into service. Testing in real-world conditions is not covered by that exclusion, and a commercial tool used for teaching or administration is in scope.

Do universities have to do a fundamental rights impact assessment?

Article 27 requires deployers that are bodies governed by public law, or private entities providing public services, to assess the impact on fundamental rights before deploying most Annex III high-risk systems. Most universities fall in one of those groups. After the Digital Omnibus, the FRIA can cross-refer to the GDPR DPIA where that already covers an element.

What is the AI literacy obligation now?

Article 4, as replaced by Regulation (EU) 2026/1744, requires providers and deployers to take measures to support the development of AI literacy of their staff and others operating AI on their behalf. It states that this does not require guaranteeing any specific level of AI literacy of any individual.