Education is named directly in the EU AI Act. Annex III, point 3 covers AI used to decide access to education, to evaluate learning outcomes, to assess the appropriate level of education a person should receive, and to monitor for prohibited behaviour during tests. If your product does any of those, it is presumptively high-risk - and unlike most sectors, there is a second trap sitting next to it in Article 5.
Proctoring is the case to look at first. Monitoring exam behaviour is explicitly high-risk under Annex III 3(d). If that monitoring includes emotion inference, it is not high-risk - it is prohibited outright under Article 5, in educational settings, with no documentation route out.
Where EdTech lands
| System | Likely tier | Why |
|---|---|---|
| Admissions scoring or applicant ranking | High-risk | Annex III 3(a) - determines access to education, and profiles individuals |
| Automated grading or essay scoring | High-risk | Annex III 3(b) - evaluates learning outcomes |
| Placement / streaming into levels | High-risk | Annex III 3(c) - assesses the appropriate level of education |
| Exam proctoring | High-risk | Annex III 3(d) - monitoring prohibited behaviour during tests |
| Proctoring with emotion or stress inference | Prohibited | Article 5 - emotion inference in education, outright |
| Adaptive practice that suggests the next exercise | Likely minimal | Sequencing content is not evaluating the learner - document the position |
| AI tutor / study chatbot | Limited | Article 50 disclosure - live now |
| Content generation for teachers | Minimal | Article 4 literacy; Article 50(2) marking of generated media |
| Timetabling, admin, attendance counting | Minimal | Logistics, not assessment |
The line that decides it: sequencing vs judging
An adaptive system that picks the next exercise because the last one was answered wrong is sequencing content. A system that produces a score, a level, a readiness judgement or a recommendation about the learner is evaluating the person - and that is both Annex III and profiling, which closes the Article 6(3) exemption absolutely.
Vendors often sit closer to the line than they think, because the same engine that sequences content usually also produces a mastery estimate. If that estimate is surfaced to a teacher, an admissions officer or an employer, it is doing assessment work.
School or vendor - who owes what
A school or university buying an AI grading tool is a deployer under Article 26: human oversight, monitoring, input-data relevance, logging, and informing affected students. It does not inherit the vendor's Chapter III duties - risk management, technical documentation, conformity assessment, CE marking - which stay with the provider. The full test.
Two traps specific to education procurement. First, a school that substantially modifies a tool - retraining it on its own cohort, repurposing a placement model into an admissions filter - can become the provider. Second, public-sector deployers of Annex III systems have additional duties, including a fundamental rights impact assessment. Universities and state schools should assume the heavier deployer set applies to them.
What is live today, whatever your tier
- Article 50 - a study bot tells students it is an AI, at first contact.
- Article 4 - teachers and admin staff operating these systems need recorded AI literacy. In education this is easier to argue you've done and harder to argue you don't need.
- Article 5 - no emotion inference on students. Check any proctoring or engagement-tracking feature now, not in 2027.
High-risk obligations run to 2 December 2027. That is not far off for a grading or admissions product: conformity assessment realistically takes 12 to 18 months, and academic procurement cycles are annual. Full deadline map.
GDPR does much of the work already. Student data is often children's data, so if you have a DPIA, an age-appropriate design position and a lawful basis that survive scrutiny, a large share of Article 10 data governance is evidenced by work you have done. Reglynn reports flag those overlaps rather than billing you twice.
Sequencing content, or judging the learner?
That distinction decides your tier. The free check works through it in about two minutes.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.