Blog

The EU AI Act in schools: what applies now and what arrives in 2027

August 3, 2026

The EU AI Act in schools: what applies now and what arrives in 2027

The EU AI Act in schools: what applies now and what arrives in 2027

On 2 August 2026, Regulation (EU) 2024/1689 — the AI Act — became generally applicable across the European Union. For most leadership teams the news arrived wrapped in considerable noise: some headlines announced that AI-based assessment was now subject to strict requirements from that very day, others explained that almost everything had been postponed. Both are partly true, and that ambiguity is exactly the problem this article sets out to solve.

Three timelines, not one

The short answer is that there are three blocks of obligations on three different dates, and almost all the confusion comes from mixing them up:

  • Since 2 February 2025: prohibited practices and the AI literacy duty. This applies to every school without exception and has been in force for a year and a half.
  • Since 2 August 2026: transparency obligations. These have just landed and are the easiest to breach without noticing.
  • From 2 December 2027: the Annex III high-risk regime, which covers admissions and assessment. This is the block that was deferred and the one that produced the headlines.

Working out which of the three each of your tools falls into is the whole job.

Prohibited since 2025: emotion recognition

Of all the prohibited practices, the one that hits education directly is the ban on emotion recognition systems in educational institutions. This is not a restriction subject to a risk assessment or to consent: it is simply prohibited, with very limited exceptions on medical or safety grounds. Any tool promising to infer a student's emotional state, attention or motivation from their face, voice or behaviour is out. It is the one obligation in the regulation that leaves no operational room.

AI literacy: the duty almost nobody remembers

The regulation requires those deploying AI systems to ensure a sufficient level of AI competence among the staff who operate them. Translated into school reality: if your office uses a tool that drafts communications, if the leadership team consults a dashboard with predictions, or if teachers use a marking assistant, those people need to understand what the tool does, where its limits are and when not to trust it.

There is no official certificate to issue; you need to be able to show the training happened and keep a record of it. Folding it into the year's professional development plan is the simplest route, because it generates evidence without creating a new procedure.

What changed on 2 August 2026

Transparency obligations became enforceable this month. They are the most visible to families and boil down to three rules:

  • Declared interaction: when a person interacts with an AI system, they must know it, unless it is obvious from the context.
  • Marked synthetic content: artificially generated or manipulated content must be identified as such in a machine-readable format.
  • Disclosed deep fakes: images, audio and video constituting deep fakes must be declared as such.

The three reviews to run this week

For a school, those three rules translate into three short, concrete checks:

  • The website chatbot: add a clear identification at the start of the conversation, so it is explicit that the responder is not someone in the office.
  • Family communications: settle on an internal policy about when you state that a text was drafted with AI help and when it is unnecessary.
  • Marketing material: review facility photographs, promotional videos and testimonials in case any were generated or retouched with generative tools.

What was deferred to December 2027

Here is the headline that caused the most confusion. Annex III of the regulation classifies four types of system in education and vocational training as high-risk:

  • Access and admission: those determining entry or assignment to an educational programme.
  • Learning assessment: those evaluating the outcomes achieved by students.
  • Appropriate level of education: those guiding or deciding the pathway a person should follow.
  • Exam monitoring: those detecting prohibited behaviour during tests, which includes proctoring.

The agreement reached under the Digital Omnibus delayed the application of these obligations until 2 December 2027.

What the high-risk regime will demand when it arrives

It is worth knowing now, because it shapes which tools are worth contracting today. High-risk systems fall under documented risk management, data governance, technical documentation, event logging, effective human oversight, demonstrated accuracy and robustness, and registration in the European database.

The deferral is real, but read it carefully. It does not mean anything goes until 2027: it means the specific high-risk obligations are not yet enforceable. The rest of the legal framework applies unchanged, starting with the GDPR, which already requires a legal basis, information, minimisation and an impact assessment when automated decisions are taken about minors.

How to classify the tools you already use

The useful exercise is not reading the whole regulation but taking an inventory. List every tool in the school that includes an AI component, including the ones built into your management software, which are often forgotten.

The three inventory questions

For each tool on the list, three questions are enough to place it:

  • Does it replace or shape a decision about a specific person? A dashboard showing attendance trends decides nothing. A model ranking admission applications by likelihood of fit does.
  • Does it produce output that reaches students or families without human review? A draft circular someone reads and approves before sending is one thing; an automatic message that goes out on its own is another.
  • Does it process specially protected data? Health, origin, socioeconomic situation or any category requiring reinforced safeguards.

With those three answers, most tools in a school land in the limited-risk category, whose only real obligation is transparency. The ones left in the grey zone are the ones worth a conversation with the vendor and with your data protection officer.

What to ask your vendors in writing

As a deployer you have the right to enough information to use the system correctly, and the duty to use it in line with the provider's instructions. That makes four questions essential:

  • Which features include AI and which do not? The answer usually surprises in both directions.
  • How does the vendor classify each one against the regulation? And on what reasoning, not just with what label.
  • What documentation and instructions for use do they hand over? And do these include the system's known limitations.
  • What happens to the school's data? Whether it is used to train models, where it is processed and under what guarantees.

Keep the answers. In compliance, the difference between a diligent school and a negligent one is rarely the technology: it is whether there is a documentary trail of the decisions taken and why they were taken.

Case study (Spain)

An education group with three sites carried out the inventory in July and found eleven tools with some AI component. Nine turned out to be limited-risk: proofreaders, draft generators, an informational chatbot and several descriptive dashboards. Two landed in the grey zone: an early dropout alert system that ranked students by risk, and an online exam invigilation tool trialled during the pandemic and still under contract without being used.

The decisions were straightforward once the map was clear. The invigilation tool was cancelled, because nobody used it and its future classification was plainly high-risk. The early alerts were kept, but the procedure changed: instead of ranking students by score, the system now flags objective indicators — accumulated absences, arrears, sharp grade changes — that a tutor interprets before acting. The website chatbot was relabelled in two days. And AI training for administrative staff was folded into the year's professional development plan.

Related articles

Conclusion

The AI Act does not force schools to give up artificial intelligence: it forces them to know what they are using, what for and with what oversight. Most tools in a school today are limited-risk and are resolved with transparency and training. The serious work starts when a system takes part in deciding about a person, and there the deferral to December 2027 is a window to prepare, not a reason to look away.

At Edena we design AI features so the school always keeps the decision: the platform flags, ranks and prepares, but a person with context is the one who resolves. Book a demo and we will walk you through exactly what each component does and what documentation we hand over for your inventory.

Frequently asked questions

This content was generated by Ena, Edena's artificial intelligence agent. It may contain errors or inaccuracies and does not constitute legal, tax or professional advice. Edena does not warrant the accuracy, completeness or currency of the information. Consult official sources and, where appropriate, a qualified professional before taking any decision. The cover image is from Unsplash .

Edena Logo - Transform your school management

Less Admin. More Enrolments. Happier Families.

Edena mobile app home screen for families