EU AI Act High-Risk Series, Part 3: Education & EdTech
Admissions, grading and exam-monitoring tools are high-risk under the EU AI Act, and emotion recognition in proctoring is banned outright. What universities, exam boards and EdTech vendors have to build by December 2027, and why institutional buyers are already asking.
Cameron Mukherjee, Director · · Updated
For: Universities, exam boards, EdTech vendors and training providers using AI in admissions, assessment or proctoring
Key points
- AI used for admissions, evaluating learning outcomes, deciding the level of education a person receives, and monitoring behaviour during tests is high-risk under Annex III point 3; the deadline is 2 December 2027.
- Emotion recognition from biometric data in education institutions has been prohibited since 2 February 2025; proctoring tools that score anxiety or engagement from webcam feeds are banned.
- Automated proctoring has documented disparities by skin tone and disability, which is why bias testing across affected groups is central to compliance.
- Children’s data carries stricter GDPR consent and processing rules on top of the AI Act obligations.
- Institutional buyers are building AI Act compliance into procurement; vendors that cannot evidence it do not make the shortlist.
Part 3 of our five-part series on high-risk AI under the EU AI Act, written for the directors who have to decide what to build, buy and sign off. Part 1 covered recruitment and HR technology; Part 2 covered finance and insurance; Part 4 covers healthcare and MedTech; Part 5 covers critical infrastructure.
An exam proctoring tool flags a student for "suspicious eye movement". The cause is a vision impairment, not cheating. That failure is well documented in automated proctoring software, and it is exactly the kind of system the EU AI Act names directly, alongside admissions tools, grading systems and anything that decides what level of education someone can access. As in recruitment, one technique in this sector is not merely high-risk. It is banned.
For universities, exam boards, training providers and the technology vendors that serve them, this article sets out what is in scope, what has to be built, and why institutional buyers are already asking.
What has changed
The "Digital Omnibus on AI", Regulation (EU) 2026/1744, in force since 27 July 2026, moved the compliance deadline for standalone high-risk AI systems from 2 August 2026 to 2 December 2027. Education AI is covered by the same postponement as recruitment and finance.
What the delay did not touch:
- Since 2 February 2025: prohibited AI practices are banned and staff AI-literacy obligations apply (softened from "ensure" to "support").
- Since 2 August 2025: general-purpose model obligations and the governance and penalty framework.
- From 2 August 2026: transparency duties, for example disclosing that a student is dealing with an AI system.
Education shares a specific prohibition with recruitment. Article 5(1)(f) bans AI that infers emotions from biometric data in workplaces and education institutions alike, at every level, with the same narrow medical and safety exception. A proctoring tool that scores a student's anxiety, distress or engagement from a webcam feed is not a 2027 problem. It should not be running in an EU classroom today.
Which education AI is high-risk
The Act names four uses at all levels of education and vocational training (Annex III, point 3):
- Access, admission or assignment: deciding whether someone gets into an institution or programme, or which one.
- Evaluating learning outcomes, including where that evaluation steers the student's subsequent learning path.
- Assessing the appropriate level of education a person can access or should receive.
- Monitoring and detecting prohibited behaviour during tests: the Act's phrase for exam proctoring.
The last category carries the most real-world bias evidence. A peer-reviewed 2022 study found race and skin-tone disparities in automated proctoring flag rates, and disability advocates have documented students with disabilities flagged for atypical eye movement or expression. That evidence is why the category exists.
As elsewhere in the series, Article 6(3) offers a narrow derogation for systems that do not pose a significant risk. Raise it with your advisers; do not assume it.
What has to be in place by December 2027
For an admissions, grading or proctoring system in scope:
- Bias testing across the groups most affected, particularly disability and demographic bias in proctoring and assessment, given the documented failure patterns.
- A human who can intervene. A flagged exam or a borderline admissions score reviewed and overridable by a person, not confirmed downstream.
- Technical documentation and automatic logging, so a disputed grade or flagged exam can be reconstructed and explained.
- Transparency to students, and to parents or guardians where students are minors.
- Conformity assessment and EU database registration before the system goes to market, and monitoring once live.
Institutions and vendors serving minors carry a further layer: children's data is subject to stricter consent and processing rules under GDPR. A plan that covers the AI Act and misses that overlap is incomplete.
The Commission's draft guidelines on classification of high-risk AI systems, covering education among other categories, were open for consultation through July 2026 with final guidance pending.
What is at stake commercially
Fines under Article 99 are tiered and unchanged:
- Up to €35M or 7% of global turnover for breaching a prohibition such as the emotion-recognition ban.
- Up to €15M or 3% for non-compliance with the high-risk obligations above.
- Up to €7.5M or 1% for supplying incorrect information to a regulator.
- For SMEs, each cap applies as whichever figure is lower.
Education AI failures become public quickly. A biased admissions or proctoring tool is a story universities, ministries and parents pay attention to long before a regulator does. Universities, exam boards and government education bodies are building AI Act compliance into procurement requirements now. A vendor that cannot answer those questions does not reach the shortlist, and an institution that cannot evidence its own diligence carries the reputational risk.
What to do now
- Inventory every AI tool touching admissions, assessment, progression or exams, and classify it.
- Check any proctoring product for emotion inference from biometric data and switch it off if present.
- Commission bias testing on your own cohort data, with disability and demographic groups explicitly covered.
- Design the human review step so it can actually change an outcome, and log every decision.
- Align the AI Act work with your children's-data obligations so both are evidenced once.
How Hexploits helps
We do the engineering side of EU AI Act readiness: classification, documentation, logging and human oversight built into the systems rather than kept in a binder. We have built platforms used by students at scale, for the charity Gradvisor, including the recommendation and assistant engines that these obligations apply to, so we know what it takes to instrument them for accountability as well as accuracy. We are also the core team behind swarmd.ai, an EU AI Act readiness platform for governing AI agents in regulated industries.
Request a proposal or talk to an engineer. You will have a written scope and an indicative price within two working days.
This is our view of the operational and technical side of compliance, not legal advice. Pair it with your legal counsel for formal sign-off. Next in the series: Part 4, healthcare and MedTech.
Questions this raises
Is exam proctoring software high-risk?
Which education AI uses are high-risk?
What has to be in place by December 2027?
How Hexploits helps
- EU AI Act readiness for UK businesses
EU AI Act readiness is the work of classifying each AI system against the Act’s risk tiers, and building the risk management, technical documentation, logging, human oversight and post-market monitoring that high-risk systems must have before their deadline.
- Web platform and portal development
A web platform or portal is the system through which customers, suppliers or staff interact with a business: accounts, orders, cases, documents and reporting behind a login.
More insights
EU AI Act High-Risk Series, Part 5: Critical Infrastructure
11 September 2026
AI managing power grids, water supply or road traffic is high-risk under the EU AI Act only where it is a genuine safety component, and part of the scope test is still draft guidance. How utilities, operators and their vendors should classify, and what to build if they are in scope.
EU AI Act High-Risk Series, Part 4: Healthcare & MedTech
4 September 2026
Healthcare AI has two EU AI Act deadlines eight months apart, and which applies depends on whether your product is legally a medical device. How to classify correctly, what goes in the technical file, and why health-system procurement is already asking.
EU AI Act High-Risk Series, Part 2: Finance & Insurance
21 August 2026
Credit scoring and life or health insurance pricing are high-risk under the EU AI Act, with a mandatory impact assessment for every deployer. What a lender, insurer or payments business has to build by December 2027, and how to do it once for every regulator.
Next step
Have a question this raised?
Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.