EU AI Act High-Risk Series, Part 3: Education & EdTech
Admissions, grading, and exam monitoring tools are named high-risk under the EU AI Act - and one common exam-monitoring feature is banned outright, not just regulated. Heres what changed, and what applies to EdTech now.
This is Part 3 of our five-part series on high-risk AI under the EU AI Act. Each instalment covers one regulated vertical - what "high-risk" means for it, what the current timeline actually requires, and what has to be different about how you build or buy AI in that space. Part 1 covered recruitment and HR tech; Part 2 covered finance and insurance; Part 4 covers healthcare and MedTech; Part 5 covers critical infrastructure.
An exam proctoring tool flags a student for "suspicious eye movement" during a test. The real cause is a vision impairment, not cheating. That failure mode is well documented in AI-powered proctoring software, and it's exactly the kind of system the EU AI Act names directly - alongside admissions tools, grading systems, and anything that decides what level of education someone gets access to. As with recruitment, one specific technique shows up here that isn't just high-risk - it's banned outright.
What just changed
As covered earlier in this series, the "Digital Omnibus on AI" - Regulation (EU) 2026/1744, in force since 27 July 2026 - pushed the compliance deadline for standalone high-risk AI systems back from 2 August 2026 to 2 December 2027. Education AI is covered by the same postponement as recruitment and finance - one fixed date, applied uniformly.
What wasn't touched by the delay:
- Since 2 February 2025: prohibited AI practices are banned outright, and staff AI-literacy obligations apply (the literacy standard itself was softened by the Omnibus, from an obligation to "ensure" to one to "support").
- Since 2 August 2025: obligations for general-purpose AI models, plus the Act's governance and penalty framework, apply.
- From 2 August 2026 (unaffected by the delay): transparency duties apply wherever relevant - for example, disclosing that a student is interacting with an AI system.
Education shares something specific with recruitment here: Article 5(1)(f)'s ban on AI systems that infer a person's emotions from biometric data applies explicitly to workplace and education institutions alike, at every level, with the same narrow exception for medical or safety reasons. That ban has applied since February 2025. An exam proctoring tool that scores a student's anxiety, distress, or engagement from their facial expression or webcam feed isn't a 2027 problem - it's a feature that shouldn't be running in an EU classroom today.
Why education AI counts as "high-risk"
The Act names four specific uses of AI in education and vocational training as high-risk, at all levels of education (Annex III, point 3):
- Access, admission, or assignment - AI used to determine whether someone gets into an institution or programme, or which one they're assigned to.
- Evaluating learning outcomes - including where that evaluation then steers a student's subsequent learning path, not just where it produces a grade.
- Assessing the appropriate level of education - determining what level of education a person can access or should receive.
- Monitoring and detecting prohibited behaviour during tests - the Act's own phrase for what the industry markets as exam proctoring software.
That last category is worth sitting with, because it's the one drawing the most real-world bias evidence already. A peer-reviewed 2022 study found race and skin-tone disparities in automated proctoring flag rates, and disability advocates have documented students with disabilities being flagged for atypical eye movement or facial expressions. Students testing from shared or lower-income living spaces have also reported being flagged for background noise or movement, though that specific pattern is less formally studied than the skin-tone and disability findings. These aren't hypothetical edge cases - they're the reason this category exists.
As with the other verticals in this series, being named in Annex III isn't automatically the final word - the Act includes a narrower derogation (Article 6(3)) for systems that don't pose a significant risk and meet specific conditions. Worth raising with your own advisers, not something to assume applies by default.
What actually has to change by December 2027
For an admissions, grading, or proctoring system in scope, the obligations translate into concrete build work:
- Bias testing across the groups most affected. Particularly disability and demographic bias in proctoring and assessment tools, given the documented failure patterns above.
- A human who can actually intervene. A flagged "cheating" incident or a borderline admissions score needs a real person able to review and override it - not a downstream approval that just confirms what the model already decided.
- Full technical documentation and automatic logging, so a disputed grade or flagged exam can be reconstructed and explained after the fact.
- Transparency to students that AI was involved in a decision that affects their education - and in most cases, to parents or guardians where students are minors.
- Conformity assessment and EU database registration before the system goes to market, plus ongoing monitoring once it's live.
Institutions and EdTech vendors serving minors carry an extra layer worth flagging: children's data is subject to stricter consent and processing rules under GDPR, layered on top of everything above. A compliance plan that only accounts for the AI Act and misses that overlap is an incomplete one.
The European Commission has draft guidelines on classification of high-risk AI systems - covering education among other Annex III categories - that were open for consultation through July 2026, with final guidance still pending. Worth checking for the most current interpretation as it firms up.
What we've left out of this piece, on purpose
To keep this readable, we've deliberately skipped some detail: the fuller mechanics of the Article 6(3) derogation, the general-purpose AI model rules (a separate part of the Act), and the specific interplay with national education-sector regulation, which varies significantly by member state. Those are conversations for your legal and compliance advisers, not a paragraph in a primer.
What's actually at stake
Fines follow a tiered structure under Article 99, and none of these tiers were changed by the Digital Omnibus:
- Up to €35M or 7% of global annual turnover, whichever is higher - reserved for violations of the Act's outright prohibitions, like the emotion-recognition ban above.
- Up to €15M or 3% - the tier that actually applies to non-compliance with the high-risk obligations this post is about (admissions, evaluation, and proctoring system requirements).
- Up to €7.5M or 1% for supplying incorrect or misleading information to a regulator.
- For SMEs, each of these caps applies as whichever figure is lower, not higher.
Education AI failures tend to become public fast - a biased admissions or proctoring tool is a story universities, ministries of education, and parents pay attention to, well before any regulator gets involved. Institutional buyers - universities, exam boards, government education bodies - are increasingly building AI Act compliance into procurement requirements. An EdTech vendor that can't answer those questions doesn't make the shortlist.
We've built AI systems used by students at real scale before - see our work with Gradvisor - so we understand what it actually takes to instrument a recommendation or assessment engine for accountability, not just accuracy.
Getting ready
If you're building or running AI anywhere in admissions, assessment, or exam monitoring and aren't sure where you stand, get in touch - we'll help you work out whether you're in scope, what's already binding today, and what to prioritise before December 2027 arrives faster than expected.
This is our take on the operational and technical side of compliance, not legal advice - pair it with your own legal counsel for formal sign-off. Next in the series: Part 4, Healthcare & MedTech.