Annex III point 3: the four education uses that make AI high-risk
Annex III point 3 covers education and vocational training, and it reaches institutions at all levels, from primary school through higher and vocational training. Like the employment entry next to it, it does not describe exotic technology. It describes what admissions offices, exam boards, learning platforms and online invigilation already do. From 2 December 2027 the full Chapter III obligation stack attaches to systems that perform any of its four functions.
- 3(a) Admission and assignment. Systems used to determine access or admission, or to assign natural persons to educational and vocational training institutions. Admissions ranking and school-placement algorithms sit here.
- 3(b) Evaluating learning outcomes. Systems used to evaluate learning outcomes, including where those outcomes are used to steer the learning process. Automated grading and adaptive learning are both named by this limb.
- 3(c) Assigning a level of education. Systems used to assess the appropriate level of education a person will receive or will be able to access. Ability streaming and tracking tools sit here.
- 3(d) Monitoring behaviour during tests. Systems used to monitor and detect prohibited behaviour of students during tests. This is the proctoring limb, and it is the one that runs straight into a prohibition.
As everywhere in Annex III, the classification attaches to the function, not the vendor label, so a single platform can hold a non-high-risk module and three high-risk ones. If you run any modern admissions, assessment or proctoring software, assume you are inside the Annex III high-risk classification until you can write down why you are not.
Emotion inference in education is prohibited, not merely high-risk
Before classifying anything, screen for the hard ban that overlaps this sector. Article 5(1)(f) prohibits AI systems that infer emotions of a natural person in the areas of the workplace and education institutions, with narrow exceptions for medical or safety reasons. It has applied since 2 February 2025, and it sits in the top penalty tier of 35,000,000 EUR or 7 percent of total worldwide annual turnover. Art 5(1)(f)
In education this is not a corner case, because emotion inference has been marketed straight into classrooms and exam halls: engagement analytics that read attention from a webcam, proctoring that scores stress or suspicion from a face, tutoring that infers frustration or confidence. In an education institution, all of that is inferring emotional state, and the prohibition applies whatever the stated pedagogical benefit. This is the same line the workplace emotion ban draws for hiring, written into the same provision.
The prohibition does not wait for 2027.The Digital Omnibus moved the high-risk regime for standalone Annex III systems to 2 December 2027. It did not postpone the Article 5 prohibitions in force since 2 February 2025. If a tool in your estate infers a student's emotional state, the exposure is live now, at the highest tier, and the Article 4 AI-literacy duty on the staff using it has also applied since 2 February 2025.
Where proctoring crosses from high-risk to prohibited
Proctoring is the use case where the two regimes meet, so it deserves its own line. Point 3(d) makes monitoring and detecting prohibited behaviour during tests a high-risk activity, which means it is permitted if you meet the Chapter III requirements. Article 5(1)(f) makes inferring emotions in that same setting a prohibited one. The difference is what the system claims to detect.
| Proctoring feature | What it does | Status |
|---|---|---|
| Detecting a second person or second face in frame | Identifies a defined, observable behaviour | High-risk under 3(d), permitted with obligations |
| Flagging that the candidate left the camera view | Detects a defined event, no inference about state of mind | High-risk under 3(d), permitted with obligations |
| Scoring anxiety, stress or nervousness from the face or voice | Infers an emotional state in an education setting | Prohibited under 5(1)(f) |
| Rating engagement, attention or confidence from a webcam | Infers an emotional or affective state | Prohibited under 5(1)(f) |
| Gaze or head-pose flags used as a proxy for suspicion of cheating | Contested, drifts toward inferring intent or state | Treat as prohibited unless it is a defined behaviour, not an emotion |
The conservative reading, and the defensible one until there is authoritative guidance, is that anything scoring how a student feels or seems is prohibited, while detecting a specific, described behaviour is high-risk and can be run under the Chapter III controls. If a vendor cannot tell you which side of that line a feature sits on, treat it as the risky side.
The institutional-context limit, and where edtech sits
Three of the four limbs, 3(b), (c) and (d), are tied to the context of or within an educational or vocational training institution. That qualifier decides a lot of edtech. A revision app, a language tool or a coding tutor that a person buys and uses privately, with no institution admitting, grading, streaming or invigilating them through it, is a different analysis from the same product deployed by a school or university.
The classification turns on use, not on the product. The moment an institution adopts a tool to evaluate outcomes, assign a level or proctor a test, the institutional context is met and the high-risk classification attaches, and the institution's adoption can also change who counts as the provider. Do not read the institutional qualifier as a loophole for classroom tools; read it as the fact that decides whether limbs (b) to (d) engage.
The Article 6(3) derogation in education tooling
The Article 6(3) derogation is argued in education the same way it is in hiring, and it fails for the same reasons on the functions that matter. Grading a student, assigning a level and scoring behaviour all evaluate the personal aspects of a natural person, which is profiling, and profiling triggers the absolute override that makes the system high-risk with no way out. Even setting that aside, an admission, a grade or a proctoring flag materially influences the outcome, so the significant-risk limb of the test closes the door. Art 6(3)
A genuinely narrow procedural tool can still be a candidate: one that only formats a submission, checks a file type or deduplicates entries makes no judgement about the person. The moment a tool decides what a grade should be, which stream a student belongs in, or whether behaviour was suspicious, it is evaluating, and the argument collapses. Under Article 6(4) the provider must document the assessment before placing the system on the market, and a system self-assessed as non-high-risk must still be registered, so the choice is the full high-risk stack against a documented, registered, defensible assessment, not against nothing.
Roles, and what to fix before 2 December 2027
In a typical deployment the edtech vendor is the provider and the institution is the deployer, and that split holds only while the tool is used as supplied for the intended purpose. An institution that puts its own brand on a platform, retrains the model on its own cohort, or points a general tool at admissions or grading can flip into provider status under Article 25 and inherit the full obligation set. Settle which role you hold before an inspection settles it for you. Provider and deployer roles sets out the flip.
Four asks that belong in procurement and the vendor questionnaire now:
- An emotion-inference screen first. Ask every proctoring, engagement and tutoring vendor, in writing, whether the tool infers any emotional or affective state. A yes is a prohibited practice under 5(1)(f), live today, not a 2027 project.
- A per-function classification. Which modules the vendor treats as high-risk under 3(a) to 3(d), which it claims outside Annex III, and the documented Article 6(4) assessment behind each claim.
- A conformity and registration commitment. A dated plan to complete the assessment, issue the EU declaration of conformity and register ahead of 2 December 2027, with the Annex IV technical documentation available to the institution.
- Human oversight that is real. A moderator who can actually overturn an automated grade or admission decision, with the time and information to do it, not a rubber stamp on a ranked list.
To get the per-system answer, run each tool through the free seven-stage triage classifier, which screens the Article 5 prohibitions before it reaches the Annex III question and keeps the dated output as the start of your record. Getting the classification wrong is expensive, with the detail on the penalties and enforcement page. The primary text is on EUR-Lex.