← Back to all posts
AI in Education

EU AI Act: The Education Deadline Moved, Three Duties Didn't

August 17, 2026 · EdTechXperts

On 27 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force three days after publication in the Official Journal, six days before the EU AI Act's headline compliance date of 2 August 2026. For education the practical effect was large: obligations for stand-alone high-risk AI systems listed in Annex III now apply from 2 December 2027 rather than this month.

A lot of institutions read that headline and closed the tab. That is the wrong read. Three sets of duties that reach education AI were untouched by the delay, and one of them has been enforceable for more than a year.

What actually moved

Annex III, point 3 of the AI Act classifies four education uses as high risk: systems that determine access or admission to institutions, systems that evaluate learning outcomes, systems that assess the appropriate level of education a person will receive, and systems used "for monitoring and detecting prohibited behaviour of students during tests." That last clause is a plain description of automated proctoring.

Those systems still carry the full high-risk regime: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, conformity assessment, and registration. The Omnibus moved the date, not the architecture. AI embedded in products already covered by EU sectoral safety law under Annex I moved further out, to 2 August 2028.

What did not move

The emotion-recognition prohibition. Article 5(1)(f) bans placing on the market, putting into service, or using AI systems to infer emotions of a natural person in the workplace and in education institutions, except where the system is intended for medical or safety reasons. That prohibition has applied since 2 February 2025 and sits in the Act's highest penalty tier. It is not a future obligation. So if a proctoring, engagement-analytics, or classroom-monitoring product advertises detection of attention, stress, confusion, or sentiment in students, the first question is not whether it is high risk. It is whether it is permitted at all.

Article 50 transparency. These obligations apply from 2 August 2026 and cover four situations: AI that interacts directly with people, AI that generates synthetic content, AI used for emotion recognition or biometric categorisation, and deepfakes or AI-generated text published to inform the public on matters of public interest. Critically, Article 50 is not limited to high-risk systems. The advising chatbot on an admissions page is in scope even if nothing about it is high risk. Systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2).

AI literacy. The Article 4 duty has applied since 2 February 2025. The Omnibus softened it, so providers and deployers must support the development of AI literacy among their staff rather than guarantee a level of it, but the obligation survived the rewrite.

Why a US institution should read the scope clause

The AI Act's reach is not limited to European organizations. Article 2 extends the Regulation to providers placing AI systems on the market in the Union regardless of where they are established, to deployers located in the Union, and to providers and deployers located in a third country "where the output produced by the AI system is used in the Union." Whether that third clause captures a US institution with an EU branch campus, EU-resident online learners, or a European teaching partner is a fact-specific legal question. This post is reporting, not legal advice; institutions with any European footprint should get a written scope determination from counsel rather than assume they are outside the perimeter.

There is a second, less legalistic reason to pay attention. Vendors building toward December 2027 will ship the same documentation to every customer, not just European ones. A data-governance description, a stated accuracy and bias-testing method, a logged human-review path, an incident process. Those artifacts are exactly what a US accreditor, a state AI-in-education statute, or a general counsel asks for. Institutions that write them into contracts now get them at no extra cost.

What to do with sixteen months

  • Inventory before you classify. List every AI system touching admissions, placement, grading, and exam monitoring, including AI features shipped inside an LMS, SIS, or proctoring platform you did not procure as "AI."
  • Screen for the prohibition first. Ask each vendor in writing whether any component infers emotional state, and get the answer into the agreement rather than the sales deck.
  • Sort provider from deployer. An institution that fine-tunes or substantially modifies a system can pick up provider obligations it did not expect. Know which role you occupy for each tool.
  • Fix the human oversight path. Name the human who can overturn an automated flag, and document the appeal route for a student flagged by a proctoring system. This is the single control most institutions cannot currently evidence.
  • Handle Article 50 this fall. Label chatbots at first interaction, in a form that meets accessibility requirements, and inventory where AI-generated content is published externally.

Most of this work is governance, not engineering: deciding who owns which decision, what gets documented, and where a human is required in the loop. Our institutional AI governance charter worksheet walks a cabinet through those choices, assigning decision rights, escalation thresholds, and review triggers for each category of system, so the answers exist on paper before an accreditor or a regulator asks. Institutions that want help mapping an existing tool inventory against Annex III can start with our AI and assessment services.

The takeaway

The Digital Omnibus bought education AI programs sixteen extra months on the heaviest obligations, and nothing else. The ban on inferring student emotions was already live. Transparency duties landed this month. The literacy obligation never went away. Treat 2 December 2027 as the deadline for a program you start building now, not the date you start thinking about it.

Sources & further reading

  1. Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex, Official Journal of the European Union
  2. Digital Omnibus on AI Enters Into Force — Hunton Andrews Kurth, Privacy & Information Security Law Blog
  3. Annex III: High-Risk AI Systems Referred to in Article 6(2) — EU Artificial Intelligence Act (Future of Life Institute)
  4. Article 5: Prohibited AI Practices — EU Artificial Intelligence Act (Future of Life Institute)
  5. Article 2: Scope — EU Artificial Intelligence Act (Future of Life Institute)
  6. The EU AI Act's Transparency Rules: A Practical Guide to Article 50 — EU Artificial Intelligence Act (Future of Life Institute)
  7. EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn
Work with EdTechXperts More posts