EU AI Act checker for education: is this AI use high-risk?
Describe how your institution uses an AI system and get its likely category under the EU AI Act, the obligations that follow for you as deployer, and the date they apply. The dates reflect the Digital Omnibus on AI, Regulation (EU) 2026/1744, which moved the high-risk rules for education to 2 December 2027.
Runs entirely in your browser. Nothing you select is stored or sent anywhere.
Next step: the category depends on the vendor's documentation too. Run a full vendor review in Validemic to check it against the AI Act and GDPR.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
The four categories in education
The AI Act sorts AI systems by risk. For a university, four outcomes matter.
Prohibited: emotion recognition
Article 5(1)(f) bans placing on the market, putting into service or using AI systems that infer the emotions of a natural person in the workplace or in education institutions, unless the system is intended for medical or safety reasons. Article 3(39) defines an emotion recognition system by reference to biometric data. "Engagement" or "attention" tracking from webcam images in a lecture or an online exam is the obvious example to look for in vendor material.
High-risk: Annex III, point 3
Annex III, point 3 lists four education use cases as high-risk:
- (a) determining access or admission, or assigning people to educational institutions at all levels;
- (b) evaluating learning outcomes, including when they are used to steer the learning process;
- (c) assessing the appropriate level of education an individual will receive or can access;
- (d) monitoring and detecting prohibited behaviour of students during tests.
Transparency obligations: Article 50
Providers of systems that interact directly with people must make sure people are told they are dealing with AI, unless that is obvious (Article 50(1)). Providers of generative systems must mark output in a machine-readable way (Article 50(2)). Deployers must disclose deep fakes, and must disclose AI-generated text published to inform the public on matters of public interest unless it has gone through human review or editorial control (Article 50(4)).
Minimal risk
Everything else, such as summarising, translation or coding help, carries no specific AI Act obligations beyond AI literacy under Article 4. GDPR, copyright and your own policies still apply.
What applies when (after the Digital Omnibus)
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It replaced the application dates in Article 113 of the AI Act. The dates below are the ones in force on 7 October 2026.
| Rule | Applies from |
|---|---|
| Prohibited practices, including emotion recognition in education (Article 5(1)(f)) | 2 February 2025 |
| AI literacy (Article 4) | 2 February 2025; new, softer wording since 27 July 2026 |
| Transparency obligations (Article 50) | 2 August 2026 |
| Machine-readable marking for generative systems already on the market before 2 August 2026 (Article 50(2), via new Article 111(4)) | 2 December 2026 |
| New prohibitions on non-consensual intimate imagery and child sexual abuse material (Article 5(1)(ba) and (bb)) | 2 December 2026 |
| High-risk rules for Annex III systems, including education, and the deployer duties in Articles 26 and 27 | 2 December 2027 (originally 2 August 2026) |
| High-risk rules for AI in products under Annex I | 2 August 2028 |
| High-risk systems intended for use by public authorities and already in service before the application date (Article 111(2)) | Compliance by 2 August 2030 |
For systems already placed on the market or put into service before 2 December 2027, amended Article 111(2) says the Regulation applies only if they are significantly changed in their design after that date, except that providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030.
What a deployer of a high-risk system must do
A university that uses a vendor's high-risk system is a deployer. Article 26 requires it, among other things, to:
- use the system in line with the provider's instructions for use;
- assign human oversight to people with the necessary competence, training, authority and support;
- make sure input data it controls is relevant and sufficiently representative;
- monitor operation, and inform the provider and the market surveillance authority of risks or serious incidents;
- keep the logs under its control for at least six months, unless other law says otherwise;
- inform workers' representatives and affected workers before using the system at the workplace;
- for public authorities, check that the system is registered in the EU database and not use it if it is not;
- use the provider's information to carry out a DPIA under Article 35 GDPR where applicable;
- inform students and other people that they are subject to the system when it makes or assists decisions about them.
Article 27 adds a fundamental rights impact assessment (FRIA) before first use for deployers that are bodies governed by public law or private entities providing public services. The Digital Omnibus amended Article 27(4) so that the FRIA can cross-refer to, or include parts of, the GDPR DPIA, and asked the AI Office to provide a questionnaire template.
The Article 6(3) derogation
An Annex III system is not high-risk if it does not pose a significant risk of harm, including by not materially influencing the outcome of decision making. Article 6(3) gives four conditions, any of which can apply: a narrow procedural task, improving the result of a completed human activity, detecting patterns or deviations without replacing human assessment, or a preparatory task. A system that profiles natural persons is always high-risk. The provider makes this assessment, documents it and registers the system (Article 6(4)); the Digital Omnibus simplified that registration but kept it. As deployer, ask the vendor for its documented assessment rather than assuming the derogation applies.
When the university becomes the provider
Under Article 25(1), a deployer is treated as the provider of a high-risk system, with the provider obligations of Article 16, if it puts its name or trademark on a high-risk system, makes a substantial modification to one, or changes the intended purpose of a system that was not high-risk (including a general-purpose system) so that it becomes high-risk. A system built in-house and put into service under the institution's own name makes the institution the provider under Article 3(3).
Validemic's analysis
The most common way a university becomes a provider without noticing is the third case: a general-purpose chatbot set up by a department to mark assignments or rank applicants. Treat that as a new high-risk system and involve your DPO and legal team before it goes live.
Research use
Article 2(6) excludes AI systems and models, and their output, developed and put into service for the sole purpose of scientific research and development. Article 2(8) excludes research, testing and development before a system is placed on the market or put into service, but not testing in real-world conditions. A commercial AI tool that researchers simply use is not, in our reading, developed for the sole purpose of research, so check it like any other deployment.
Sources
All sources retrieved 7 October 2026.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 2 to 6, 25 to 27, 50, 111, 113 and Annex III, EUR-Lex: eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), OJ L, 24.7.2026, EUR-Lex: eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- European Parliamentary Research Service, briefing "Digital Omnibus on AI" (legislative history): europarl.europa.eu, EPRS briefing
- Regulation (EU) 2016/679 (GDPR), Articles 22 and 35, EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng
About this tool
We built this tool from the consolidated effect of the AI Act and the Digital Omnibus on AI as published in the Official Journal, read on 7 October 2026. The category it shows is a likely category based on your answers, not a legal classification: the intended purpose stated by the provider, the contract and the way the system is configured all matter. It is not legal advice. The Commission is expected to publish further guidance and templates; check for anything newer than our check date. If you spot an error, please contact us and we will correct it.
Frequently asked questions
Is AI used for grading high-risk under the EU AI Act?
Annex III, point 3(b) lists AI systems intended to evaluate learning outcomes, including when the outcomes steer the learning process, as high-risk. Grading and marking tools therefore fall in scope unless the Article 6(3) derogation applies, for example because the system only performs a narrow procedural task. Systems that profile people are always high-risk.
When do the high-risk rules apply to universities?
Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published on 24 July 2026, set the date for high-risk systems listed in Annex III, which includes education, to 2 December 2027. The original date was 2 August 2026. Prohibitions have applied since 2 February 2025 and the Article 50 transparency rules since 2 August 2026.
Is emotion recognition banned in universities?
Article 5(1)(f) prohibits AI systems that infer the emotions of a natural person in education institutions and workplaces, except for medical or safety reasons. The prohibition has applied since 2 February 2025.
Does the AI Act apply to AI used in research?
Article 2(6) excludes AI systems and models developed and put into service for the sole purpose of scientific research and development, and Article 2(8) excludes research, testing and development before a system is placed on the market or put into service. Testing in real-world conditions is not covered by that exclusion, and a commercial tool used for teaching or administration is in scope.
Do universities have to do a fundamental rights impact assessment?
Article 27 requires deployers that are bodies governed by public law, or private entities providing public services, to assess the impact on fundamental rights before deploying most Annex III high-risk systems. Most universities fall in one of those groups. After the Digital Omnibus, the FRIA can cross-refer to the GDPR DPIA where that already covers an element.
What is the AI literacy obligation now?
Article 4, as replaced by Regulation (EU) 2026/1744, requires providers and deployers to take measures to support the development of AI literacy of their staff and others operating AI on their behalf. It states that this does not require guaranteeing any specific level of AI literacy of any individual.