AI systems deployed in education, such as adaptive platforms or automated grading, are generally classified as high-risk by the AI Act. This article details the distinct responsibilities of EdTech providers and educational institutions, addresses issues related to minors' data and bias, and specifies the deadlines to be met by 2027.
The majority of artificial intelligence solutions used in the education sector are subject to the "high-risk" category of the AI Act. This classification entails strict regulatory requirements for both providers and user institutions.
Annex III of Regulation (EU) 2024/1689 defines AI systems considered high-risk. Point 3 specifically targets tools used in education and vocational training, including:
Why EdTech is directly targeted by the AI Act
- Automated student assessment solutions,
- Adaptive learning platforms,
- Academic or professional guidance systems,
- Behavior or fraud detection devices.
For example, an automated essay grading application deployed in a university will be considered high-risk. The same applies to an AI-based guidance tool that recommends academic paths based on a student's profile.
This categorization is due to the significant potential impact of these technologies on the fundamental rights of learners. An algorithmic error or bias in an assessment solution can affect access to education or distort academic guidance.
> **References:** Annex III, point 3 of Regulation (EU) 2024/1689
> AI Regulatory Framework - European Commission
EdTech Providers: What are the obligations under the AI Act?
Educational software publishers integrating AI are legally recognized as providers. As such, they must comply with several major technical and organizational obligations:
1. **Verify system classification**: Determine if the tool falls under the high-risk category (Annex III, point 3). Adaptive platforms and automated grading systems are typically affected.
2. **Compile complete technical documentation**: Provide documentation compliant with Annex IV, detailing the system's operation, limitations, performance, and risk management measures.
3. **Implement active risk management**: Identify, assess, and mitigate risks related to the use of the system, particularly biases in assessments or recommendations.
4. **Ensure transparency for users**: Clearly inform users that the system uses AI and explain its operating principles (Article 13).
5. **Guarantee data quality and representativeness**: Models must be trained on relevant, unbiased data. Article 10 imposes increased requirements, especially for sensitive data concerning minors.
6. **Register the system in the dedicated European database**: Any high-risk AI system must be registered in the European database provided for this purpose.
For illustration, a publisher of automated grading solutions must explicitly state the evaluation criteria, methods for detecting and correcting biases in their documentation, and inform their clients of the system's limitations.
Providers located outside the European Union must appoint a legal representative in the EU, responsible for ensuring compliance within European territory.
> **References:** Article 16 – Obligations of providers
> Annex IV – Technical documentation
> Guide to provider obligations
Educational Institutions: Responsibilities as Deployers
Schools, universities, and training organizations using AI systems are considered deployers. Their role involves specific obligations, distinct from those of providers:
1. **Ensure the compliance of used systems**: Verify that the chosen tool respects the AI Act regulation by checking the technical documentation and the system's registration.
2. **Supervise system use**: Implement procedures to monitor the tool and detect potential malfunctions or biases.
3. **Inform all stakeholders**: Students, parents, and teachers must be informed of the use of AI and its potential consequences.
4. **Maintain an incident log**: Record any incident related to the system and inform the provider.
5. **Conduct a FRIA for public bodies**: Public institutions must conduct a Fundamental Rights Impact Assessment (FRIA) for each high-risk system used (Article 27).
Example: A university using an AI-based cheating detection system must ensure the provider has properly documented the solution, inform students of its use, and monitor false positives that could unfairly penalize certain students.
The FRIA, mandatory for public institutions, aims to assess the system's impact on fundamental rights, particularly regarding non-discrimination and data protection.
> **References:** Article 27 – FRIA for public bodies
> CNIL – AI and Education
> FRIA Diagnostic for institutions
Data of Minors and Bias Management: Specific Challenges in Education
Personal Data of Minors: Enhanced Requirements
Student personal information, particularly that of minors, is subject to increased protection under the GDPR. The AI Act complements these requirements:
- **Mandatory parental consent**: For students under 15, parental consent is generally required to process their data.
- **Data minimization**: Only strictly necessary information should be collected and processed.
- **Data security**: Providers must guarantee the technical and organizational security of student data.
For example, an adaptive platform should not collect information on ethnic origin or political opinions, unless absolutely necessary and with explicit consent.
Combating Bias in Assessment and Guidance
AI systems for assessment or guidance can reproduce or exacerbate existing biases. The AI Act requires providers to:
- **Use representative datasets**: Training must include all student profiles to limit biases related to under-representation.
- **Test and detect biases**: Systems must be evaluated to identify potential gender, social origin, or other protected criteria biases.
- **Document corrective actions**: Measures taken to correct biases must be described in the technical documentation.
Example: If a guidance system recommends scientific tracks to boys and literary tracks to girls more often, it must be adjusted to avoid perpetuating these stereotypes.
Biases in educational AI can have lasting repercussions on student paths and increase social inequalities.
> **References:** GDPR – Protection of minors' data
> Article 10 – Data quality
> Ministry of National Education – AI Guidelines for schools
Deadlines and Upcoming Steps for Compliance
All obligations concerning high-risk AI systems in education will apply from December 2, 2027. Several intermediate milestones should be anticipated:
- **November 2, 2026**: Transparency requirements for generative AI systems come into force (watermarking, user information). Educational chatbots or pedagogical content generators are particularly affected.
- **December 2, 2027**: Obligations for high-risk systems listed in Annex III become effective. EdTech providers and institutions must be compliant by this date.
- **2026-2027**: The Higher Council for Digital Education (CSEN) and the Ministry will publish specific guidelines for the use of AI in schools to support institutions in their compliance efforts.
EdTech providers must start compiling their technical documentation and implementing risk management procedures now. Institutions are encouraged to inventory their AI tools and verify their regulatory compliance.
> **To go further:** Complete AI Act timeline
> AI Office – Regulatory Calendar