AI in Schools Under the EU AI Act: Which Education Software Is High-Risk (Annex III, Point 3)
Schools use AI every day now. Some of that software falls under the EU AI Act. Four school uses are high-risk by law: deciding admissions, evaluating learning outcomes, assigning education levels, and proctoring exams. One use is banned outright: reading students' emotions.
This guide explains each case in plain language. It covers what applies today, what starts on 2 December 2027, and what schools and vendors should do now.
The Four High-Risk School Uses (Annex III, Point 3)
Annex III of the AI Act lists education and vocational training as a high-risk area. It names four uses. A system intended for any of them is high-risk by default:
- Access and admission (point 3(a)) — systems that determine access or admission, or assign people to schools, universities, or training institutions.
- Evaluating learning outcomes (point 3(b)) — systems that assess what a student has learned, including when those results steer the student's learning path.
- Assigning an education level (point 3(c)) — systems that assess which level of education a person will receive or can access.
- Exam proctoring (point 3(d)) — systems that monitor and detect prohibited behaviour of students during tests.
The list covers institutions at all levels: schools, universities, and vocational training.
The Hard Stop: Reading Students' Emotions Is Banned
Article 5(1)(f) bans AI that infers the emotions of people inside education institutions. This is not a high-risk case — it is a prohibited practice. The ban has applied since 2 February 2025, and fines can reach EUR 35 million or 7% of global turnover.
There is one narrow exception: systems put in place for medical or safety reasons. General engagement scoring or stress tracking of students does not qualify.
Proctoring: High-Risk or Banned? It Depends What It Reads
A proctoring tool that flags prohibited behaviour — a second person in the room, a phone, tab switching — is high-risk under point 3(d). It is allowed, with obligations.
A proctoring tool that infers a student's emotional state — stress, nervousness, a "suspicious mood" — crosses into the Article 5(1)(f) ban. That feature cannot be used in education, full stop.
When School Software Is NOT High-Risk (Article 6(3))
Not every tool in these areas is high-risk. Article 6(3) filters out systems that pose no significant risk to health, safety, or fundamental rights — but only where at least one of four conditions is met: the system performs a narrow procedural task; it improves the result of a completed human activity; it detects decision patterns without replacing the human assessment; or it performs a preparatory task.
Example: a timetable planner performs a narrow procedural task and is usually out. Automated grading that produces a final mark evaluates learning outcomes and is in.
Two limits matter. A system that profiles natural persons is always high-risk. And the filter is not a free pass: the provider must document the assessment and register the system in the EU database (Article 6(4), Article 49(2)).
The Real Dates, After the Digital Omnibus
Regulation (EU) 2026/1744 (the Digital Omnibus, in force since 27 July 2026) moved the high-risk deadlines. The dates that matter for education:
- 2 February 2025 — the emotion-recognition ban and the AI-literacy duty. Already in force.
- 2 August 2026 — Article 50 transparency. A chatbot used by students must say it is a machine. Already in force.
- 2 December 2027 — the full high-risk obligations for Annex III systems, the four school uses included.
- 2 August 2028 — high-risk systems embedded in products regulated under Annex I.
One circulating error, corrected: several articles report the new date as "2 August 2027". That is wrong. The enacted date for Annex III systems is 2 December 2027.
What Schools Should Do Now (as Deployers)
A school that uses AI it did not build is a deployer. Five steps cover most of the duty:
- List every AI tool in use — including features inside bigger platforms. A "wellbeing" module can hide an emotion-reading feature.
- Switch off anything that infers emotions. That ban applies today.
- Ask each vendor two questions: is this system high-risk under Annex III point 3, and where is its technical documentation?
- Plan a fundamental rights impact assessment (FRIA, Article 27). It covers public bodies and private entities providing public services — which includes most schools.
- Set house rules for AI use and train staff. The AI-literacy duty (Article 4) already applies.
What Edtech Vendors Should Do Now
A company that builds or sells school AI is a provider. The 2 December 2027 clock is running:
- Classify every product against the four uses in point 3 — and document any "not high-risk" conclusion under Article 6(4).
- Start the Annex IV technical documentation now. It takes months, not days.
- Remove or disable any emotion-inference feature for EU education customers.
- Prepare for registration in the EU database (Article 49) and a conformity assessment before the deadline.
Frequently asked questions
Which school software is high-risk under the EU AI Act?
Four kinds: systems deciding access or admission, systems evaluating learning outcomes, systems assigning a level of education, and exam-proctoring systems that detect prohibited behaviour. Annex III, point 3 lists them, for institutions at all levels.
Is emotion recognition in schools high-risk?
No — it is banned. Article 5(1)(f) prohibits AI that infers emotions inside education institutions, with a narrow medical-or-safety exception. The ban has applied since 2 February 2025. Outside work and education, emotion recognition is high-risk instead.
When do the high-risk rules for school AI apply?
From 2 December 2027, after the Digital Omnibus (Regulation (EU) 2026/1744) moved the date. The emotion ban (since February 2025) and the Article 50 chatbot-transparency duty (since August 2026) already apply.
Is automated grading always high-risk?
Grading that evaluates learning outcomes falls under point 3(b), so it is high-risk by default. The Article 6(3) filter can cover narrow helper tools a teacher fully reviews — but never a system that profiles students, and the provider must document and register the conclusion.
What should a school do first?
Make an inventory of every AI feature in use, switch off emotion inference, and ask every vendor for its Annex III classification and its documentation. Then plan the FRIA and staff training.
Related resources
- Annex III risk classification, category by category
- Article 50 transparency obligations explained
- Free AI Act risk self-assessment — get a shareable readiness report
This guide is information, not legal advice. For decisions about a specific system, confirm the analysis with counsel.
Not sure where a school tool falls? LandingRed's risk classification engine walks it through every Annex III category — the education points included — and produces a documented Article 6 conclusion with an evidence trail.
LandingRed automates all of this
Stop managing compliance in spreadsheets. Classify, document, assess, and monitor your AI systems from one platform.