ISHIGHRISK AI
Sector guide

Education and training AI under the AI Act

Annex III point 3 makes admissions, exam scoring and proctoring AI high-risk, and Article 5(f) bans emotion inference in education outright. The full test.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Annex III point 3 makes four education uses high-risk: admission and assignment to institutions, evaluating learning outcomes, assessing the level of education a person will receive or access, and monitoring prohibited behaviour during tests. It reaches institutions at all levels, not just universities. Cutting across it is a hard prohibition: Article 5(1)(f) bans inferring emotions in education settings, so proctoring that scores stress or engagement is off the table, not merely regulated. Because grading and streaming profile students, the Article 6(3) derogation is foreclosed for those functions. High-risk obligations apply from 2 December 2027, but the emotion prohibition has bound since 2 February 2025.

Annex III point 3: the four education uses that make AI high-risk

Annex III point 3 covers education and vocational training, and it reaches institutions at all levels, from primary school through higher and vocational training. Like the employment entry next to it, it does not describe exotic technology. It describes what admissions offices, exam boards, learning platforms and online invigilation already do. From 2 December 2027 the full Chapter III obligation stack attaches to systems that perform any of its four functions.

  • 3(a) Admission and assignment. Systems used to determine access or admission, or to assign natural persons to educational and vocational training institutions. Admissions ranking and school-placement algorithms sit here.
  • 3(b) Evaluating learning outcomes. Systems used to evaluate learning outcomes, including where those outcomes are used to steer the learning process. Automated grading and adaptive learning are both named by this limb.
  • 3(c) Assigning a level of education. Systems used to assess the appropriate level of education a person will receive or will be able to access. Ability streaming and tracking tools sit here.
  • 3(d) Monitoring behaviour during tests. Systems used to monitor and detect prohibited behaviour of students during tests. This is the proctoring limb, and it is the one that runs straight into a prohibition.

As everywhere in Annex III, the classification attaches to the function, not the vendor label, so a single platform can hold a non-high-risk module and three high-risk ones. If you run any modern admissions, assessment or proctoring software, assume you are inside the Annex III high-risk classification until you can write down why you are not.

Emotion inference in education is prohibited, not merely high-risk

Before classifying anything, screen for the hard ban that overlaps this sector. Article 5(1)(f) prohibits AI systems that infer emotions of a natural person in the areas of the workplace and education institutions, with narrow exceptions for medical or safety reasons. It has applied since 2 February 2025, and it sits in the top penalty tier of 35,000,000 EUR or 7 percent of total worldwide annual turnover. Art 5(1)(f)

In education this is not a corner case, because emotion inference has been marketed straight into classrooms and exam halls: engagement analytics that read attention from a webcam, proctoring that scores stress or suspicion from a face, tutoring that infers frustration or confidence. In an education institution, all of that is inferring emotional state, and the prohibition applies whatever the stated pedagogical benefit. This is the same line the workplace emotion ban draws for hiring, written into the same provision.

The prohibition does not wait for 2027.The Digital Omnibus moved the high-risk regime for standalone Annex III systems to 2 December 2027. It did not postpone the Article 5 prohibitions in force since 2 February 2025. If a tool in your estate infers a student's emotional state, the exposure is live now, at the highest tier, and the Article 4 AI-literacy duty on the staff using it has also applied since 2 February 2025.

Where proctoring crosses from high-risk to prohibited

Proctoring is the use case where the two regimes meet, so it deserves its own line. Point 3(d) makes monitoring and detecting prohibited behaviour during tests a high-risk activity, which means it is permitted if you meet the Chapter III requirements. Article 5(1)(f) makes inferring emotions in that same setting a prohibited one. The difference is what the system claims to detect.

Proctoring featureWhat it doesStatus
Detecting a second person or second face in frameIdentifies a defined, observable behaviourHigh-risk under 3(d), permitted with obligations
Flagging that the candidate left the camera viewDetects a defined event, no inference about state of mindHigh-risk under 3(d), permitted with obligations
Scoring anxiety, stress or nervousness from the face or voiceInfers an emotional state in an education settingProhibited under 5(1)(f)
Rating engagement, attention or confidence from a webcamInfers an emotional or affective stateProhibited under 5(1)(f)
Gaze or head-pose flags used as a proxy for suspicion of cheatingContested, drifts toward inferring intent or stateTreat as prohibited unless it is a defined behaviour, not an emotion

The conservative reading, and the defensible one until there is authoritative guidance, is that anything scoring how a student feels or seems is prohibited, while detecting a specific, described behaviour is high-risk and can be run under the Chapter III controls. If a vendor cannot tell you which side of that line a feature sits on, treat it as the risky side.

The institutional-context limit, and where edtech sits

Three of the four limbs, 3(b), (c) and (d), are tied to the context of or within an educational or vocational training institution. That qualifier decides a lot of edtech. A revision app, a language tool or a coding tutor that a person buys and uses privately, with no institution admitting, grading, streaming or invigilating them through it, is a different analysis from the same product deployed by a school or university.

The classification turns on use, not on the product. The moment an institution adopts a tool to evaluate outcomes, assign a level or proctor a test, the institutional context is met and the high-risk classification attaches, and the institution's adoption can also change who counts as the provider. Do not read the institutional qualifier as a loophole for classroom tools; read it as the fact that decides whether limbs (b) to (d) engage.

The Article 6(3) derogation in education tooling

The Article 6(3) derogation is argued in education the same way it is in hiring, and it fails for the same reasons on the functions that matter. Grading a student, assigning a level and scoring behaviour all evaluate the personal aspects of a natural person, which is profiling, and profiling triggers the absolute override that makes the system high-risk with no way out. Even setting that aside, an admission, a grade or a proctoring flag materially influences the outcome, so the significant-risk limb of the test closes the door. Art 6(3)

A genuinely narrow procedural tool can still be a candidate: one that only formats a submission, checks a file type or deduplicates entries makes no judgement about the person. The moment a tool decides what a grade should be, which stream a student belongs in, or whether behaviour was suspicious, it is evaluating, and the argument collapses. Under Article 6(4) the provider must document the assessment before placing the system on the market, and a system self-assessed as non-high-risk must still be registered, so the choice is the full high-risk stack against a documented, registered, defensible assessment, not against nothing.

Roles, and what to fix before 2 December 2027

In a typical deployment the edtech vendor is the provider and the institution is the deployer, and that split holds only while the tool is used as supplied for the intended purpose. An institution that puts its own brand on a platform, retrains the model on its own cohort, or points a general tool at admissions or grading can flip into provider status under Article 25 and inherit the full obligation set. Settle which role you hold before an inspection settles it for you. Provider and deployer roles sets out the flip.

2 Feb 2025Article 5 prohibitions, including emotion inference in education, and the Article 4 AI-literacy duty. Already binding on schools, universities and their vendors.
2 Aug 2025Penalties enforceable. The Article 99 tiers are live against the duties already in force.
2 Dec 2027High-risk obligations apply to standalone Annex III systems, which is where admissions, assessment, streaming and proctoring AI sits.

Four asks that belong in procurement and the vendor questionnaire now:

  1. An emotion-inference screen first. Ask every proctoring, engagement and tutoring vendor, in writing, whether the tool infers any emotional or affective state. A yes is a prohibited practice under 5(1)(f), live today, not a 2027 project.
  2. A per-function classification. Which modules the vendor treats as high-risk under 3(a) to 3(d), which it claims outside Annex III, and the documented Article 6(4) assessment behind each claim.
  3. A conformity and registration commitment. A dated plan to complete the assessment, issue the EU declaration of conformity and register ahead of 2 December 2027, with the Annex IV technical documentation available to the institution.
  4. Human oversight that is real. A moderator who can actually overturn an automated grade or admission decision, with the time and information to do it, not a rubber stamp on a ranked list.

To get the per-system answer, run each tool through the free seven-stage triage classifier, which screens the Article 5 prohibitions before it reaches the Annex III question and keeps the dated output as the start of your record. Getting the classification wrong is expensive, with the detail on the penalties and enforcement page. The primary text is on EUR-Lex.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Is AI used in schools and universities high-risk under the EU AI Act?

Much of it is. Annex III point 3 names four education uses as high-risk: determining admission or assignment to educational and vocational training institutions, evaluating learning outcomes including where they steer the learning process, assessing the appropriate level of education a person will receive or can access, and monitoring or detecting prohibited behaviour during tests. Admissions algorithms, automated exam and essay scoring, adaptive-streaming tools and exam proctoring all sit inside those limbs. The point reaches institutions at all levels, from primary school to higher and vocational training, so it is not limited to universities.

Can we use AI to detect student emotions or stress during exams?

No. Article 5(1)(f) prohibits AI systems that infer emotions of natural persons in the areas of the workplace and education institutions, with narrow exceptions for medical or safety reasons, and it has applied since 2 February 2025. A proctoring tool that scores anxiety, engagement, confidence or suspicion from a student's face, voice or expression is inferring emotional state in an education setting, which is not a compliance project with a 2027 deadline, it is a prohibited practice now. It sits in the top penalty tier of 35,000,000 EUR or 7 percent of worldwide annual turnover. Detecting a defined behaviour, such as a second face in frame, is a different, high-risk activity you can run compliantly.

Is exam or essay auto-grading caught by the AI Act?

Yes. Annex III point 3(b) names AI systems used to evaluate learning outcomes as high-risk, and automated grading of exams, essays or coursework is exactly that. The point expressly extends to outcomes used to steer the learning process, so an adaptive-learning system that grades a student and then routes their next material is caught as well. Because grading evaluates the personal aspects of an individual, it also engages the profiling override in Article 6(3), which makes it high-risk with no derogation available. Human moderation of results does not change the classification; it is part of running the system compliantly, not a way out of it.

Are consumer learning apps used at home high-risk?

It depends on whether the use is in the context of or within an educational or vocational training institution. Point 3 limbs (b), (c) and (d) are tied to that institutional context, so a language app or a revision tool a person buys and uses privately, with no institution admitting, grading, streaming or invigilating them through it, is a different analysis from the same tool deployed by a school or university. The moment an institution adopts the tool to evaluate outcomes, assign levels or proctor tests, the institutional context is met and the high-risk classification attaches. Look at who is using the output and in what setting, not at the app store listing.

Can an edtech tool use the Article 6(3) derogation?

Rarely for the functions that matter. Article 6(3) ends with an absolute bar: a system that performs profiling of natural persons is always high-risk. Grading a student, assigning a level or scoring behaviour evaluates personal aspects of a person, which is profiling, so the derogation is foreclosed for those functions. Even without the profiling override, the first limb of the test fails where the system materially influences the outcome, and an admission, a grade or a proctoring flag plainly does. A genuinely narrow procedural tool, such as one that only formats a submission or checks a file type, can be a candidate, but the assessment must be documented before market placement and the system registered even when the derogation is claimed.

When do the education AI rules apply?

The high-risk obligations for standalone Annex III systems apply from 2 December 2027, after the Digital Omnibus moved them from the original 2 August 2026 date, and education AI is standalone Annex III. Two things already bind you: the Article 5 prohibitions, including emotion inference in education, and the Article 4 AI-literacy duty have applied since 2 February 2025, and penalties have been enforceable since 2 August 2025. Procurement cycles and academic-year deployments mean tools chosen now will still be in classrooms and admissions offices in 2027, so the date is a planning horizon, not permission to wait.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.