AI in EdTech Under the EU AI Act: Which Features Are High-Risk and What to Build by December 2027

Under the EU AI Act, AI used in education is high-risk when it performs one of four specific functions: screening admissions, evaluating learning outcomes, assessing a person’s appropriate level of education, or monitoring students during tests. The heavy obligations that come with that classification take effect on 2 December 2027. Education and vocational training is one of the eight high-risk areas the Act names in Annex III, but the classification turns on what a feature does, not on the fact that it is used in a school.
For an EdTech company, this matters more than the deferred date suggests, and in two directions at once. The high-risk obligations are substantial and cannot be assembled in the final quarter before the deadline, so 2 December 2027 is a preparation window, not a reprieve. And a second set of obligations, transparency and AI literacy, is not deferred at all and applies now. This guide explains which EdTech features are actually high-risk, which are not, what the obligations require, and what to build before the deadline.
Atta Systems builds custom EdTech software for schools, universities, and education companies, including the education products EdXP and StudySmart, and treats AI Act classification as part of the product design rather than a compliance step bolted on before launch.
The deadline moved, but not the way most coverage suggests
The EU AI Act, Regulation (EU) 2024/1689, originally set its high-risk obligations to apply from 2 August 2026. The Digital Omnibus on AI, which became law in 2026, moved the standalone high-risk obligations under Annex III, the category that includes education, to 2 December 2027. This is the same AI Act change that reset the timeline for medical device software, applied to a different Annex: education sits in Annex III, which lands on 2 December 2027, while medical devices sit in Annex I, which lands on 2 August 2028.
These are fixed dates. The Commission’s original proposal would have tied the high-risk start to a future decision that the necessary standards and support were in place, but that conditional mechanism was removed during negotiations, and the final law sets 2 December 2027 and 2 August 2028 outright. For an EdTech team, that means December 2027 can be planned against as a firm date, not a moving one, and the planning should start now because the obligations are substantial.
The dates that matter to an EdTech platform:
| Obligation | Applies from | Status |
| Article 50 transparency (disclose AI interaction and mark AI-generated content) | 2 August 2026 | Live now, not deferred |
| Article 4 AI literacy (amended, softened wording) | Live now | Binds providers and deployers, including schools; not deferred |
| Article 50(2) content marking, systems on the market before 2 Aug 2026 | 2 December 2026 | Grace period for pre-existing synthetic-content systems |
| New Article 5 prohibitions (non-consensual intimate imagery, child sexual abuse material) | 2 December 2026 | Added by the omnibus |
| Annex III high-risk obligations (education AI) | 2 December 2027 | Deferred from 2 August 2026, now a fixed date |
Aside from the single most important line for a MedTech comparison, the two lines that matter most to an EdTech team are the last one and the first two: the heavy, high-risk work is due 2 December 2027, while the transparency and AI literacy duties are already live. A team that read “the AI Act was delayed” and stood down may already be behind on the obligations that never moved.
Which EdTech AI features are high-risk, and which are not
An EdTech AI feature is considered high-risk under the AI Act only when it performs one of the four education functions listed in Annex III, point 3. This is the distinction that decides the entire compliance burden, and it is where most coverage is imprecise: it is the function the AI performs, not the fact that the product is used in education, that triggers the high-risk classification.

The four high-risk education functions under Annex III point 3:
- Admissions and access. AI that determines access or admission to an educational or vocational institution, or assigns people to one, such as an application-screening or ranking tool. This is Annex III point 3(a).
- Evaluating learning outcomes. AI that evaluates learning outcomes, including when the result steers a learner’s path, such as automated grading or an adaptive engine that decides what a student sees next. This is point 3(b).
- Assessing the level of education. AI that assesses the appropriate level of education a person will receive or be able to access, such as placement or streaming tools. This is point 3(c).
- Proctoring. AI that monitors and detects prohibited behavior during tests, such as automated remote-exam proctoring that flags suspected cheating. This is point 3(d).
Features that do not perform any of these functions are not high-risk on that basis. A general study chatbot, a content-generation tool that drafts lesson material, or a scheduling assistant performs none of the Annex III education functions, so it does not carry the high-risk obligation set, though the transparency and AI literacy duties can still apply to it. Drawing this line correctly is the first step because it determines which parts of a platform require full high-risk treatment and which do not.
For borderline features, the classification is not left entirely to interpretation. The Commission published draft guidelines on high-risk classification under Article 6 and on the Article 50 transparency obligations alongside the final omnibus text, and a team classifying its own features should track those guidelines as they are finalized, because they are the reference the authorities will apply.

What the high-risk obligations require
A high-risk EdTech AI feature carries the full set of high-risk obligations under the AI Act, which is an engineering and documentation burden, not a policy statement. These obligations fall on the provider that builds the system and, in part, on the deployer (the school or institution) that uses it. The main requirements:
- Risk management. A documented, ongoing process to identify and mitigate the risks the AI feature poses to students, running across the entire lifecycle rather than just at launch.
- Data governance. Training, validation, and test data that is relevant, representative, and checked for bias, which matters acutely where the AI affects admissions or grading.
- Technical documentation and logging. Documentation detailed enough to show how the system works and meets the requirements, plus automatic logging of the system’s operation for traceability.
- Human oversight. The feature must be designed so a person can understand, oversee, and override its output. A grading or admissions decision cannot be fully automated without meaningful human review.
- Transparency and accuracy. Clear information to the deployer on how to use the system, and appropriate levels of accuracy, robustness, and cybersecurity.
There is meaningful relief for smaller providers, which matters because much of EdTech is built by funded startups rather than large vendors. The omnibus gives SMEs and small mid-caps — companies with fewer than 750 employees and under EUR 150 million in annual turnover — lighter technical documentation requirements for high-risk AI systems, along with more proportionate treatment elsewhere. The obligations still apply, but the documentation burden is scaled to the company’s size, so a small EdTech provider is not held to the same paperwork burden as a large one.
These map onto product engineering directly. Data governance is a data-pipeline requirement, human oversight is an interface and workflow requirement, logging is an architecture requirement, and technical documentation is captured cheaply during development and expensively afterward. This is why 2 December 2027 is a build window: a team that starts near the deadline is reconstructing evidence it should have generated along the way.
What an EdTech team should build before December 2027
An EdTech team prepares for the high-risk obligations by classifying its AI features now and building the required controls into the covered ones, while meeting the transparency and AI literacy duties that already apply. The work divides into what is due now and what is due by 2 December 2027.
- Classify every AI feature against Annex III point 3. Decide, and document in writing, which features perform an admissions, evaluation, level-assessment, or proctoring function, and are therefore high-risk, and which do not. This classification scopes all the work that follows.
- Meet the live obligations now. Implement Article 50 transparency (disclose when a user interacts with AI, and mark AI-generated content) and support the Article 4 AI literacy duty for staff. These apply now, not in 2027, and a team that stood down after hearing the deadline moved may already be behind on them.
- Build the high-risk controls into covered features. For each high-risk feature, build in the data governance, human oversight, logging, and documentation the obligations require, rather than planning to add them before submission. Human oversight in particular is a design decision that is hard to retrofit.
- Prepare for the deployer relationship. Institutions that use the software are deployers with their own obligations, so provide the usage information and oversight tooling they need to meet theirs. This is also a sales advantage: a platform that makes a school’s compliance easier is easier to buy.
Atta Systems builds EdTech software with these controls designed into the covered features from the first version, so an assessment engine or admissions tool ships with the human oversight, data governance, and logging that the high-risk obligations require, rather than needing them retrofitted before the deadline.
FAQ about AI in EdTech under the EU AI Act
No. Education AI is high-risk only when it performs one of the four functions named in Annex III point 3: determining admissions or access, evaluating learning outcomes, assessing a person’s appropriate level of education, or monitoring students during tests. A general study chatbot or a content-generation tool performs none of these and is not high-risk on that basis, though the Article 50 transparency and Article 4 AI literacy duties can still apply.
The high-risk obligations for education AI apply from 2 December 2027. Education sits in Annex III of the AI Act, and the Digital Omnibus on AI moved standalone Annex III obligations from 2 August 2026 to 2 December 2027. This is a fixed date: the Commission had proposed tying the start to a standards-readiness decision, but that conditional mechanism was removed during negotiation, so December 2027 can be planned against as firm.
Admissions and application-screening tools, automated grading and adaptive engines that evaluate learning outcomes, placement and level-assessment tools, and automated exam proctoring all count as high-risk, because each performs an Annex III point 3 education function. Whether a specific feature is covered depends on what it does, not on whether it is used in a school, so the same platform can contain both high-risk and non-high-risk features. The Commission’s draft guidelines on Article 6 classification are the reference to watch for borderline cases.
Yes. The omnibus gives SMEs and small mid-caps — companies with fewer than 750 employees and under EUR 150 million in annual turnover — lighter technical documentation requirements for high-risk AI systems, along with more proportionate treatment elsewhere. The obligations themselves still apply, but the documentation burden is scaled to the company’s size, which matters for the funded startups that build much of the EdTech.
Two obligations apply now regardless of the December 2027 deferral. Article 50 transparency requires disclosing when a user is interacting with an AI system and marking AI-generated content. Systems already on the market before 2 August 2026 have until 2 December 2026 to implement the machine-readable content-marking requirement. The Article 4 AI literacy duty, which binds both providers and deployers, including schools, requires supporting AI literacy among the people who operate these systems. Both apply now, so an EdTech platform should already be meeting them.
Both, in different roles. The EdTech company that builds the AI is the provider and carries the bulk of the high-risk obligations, including risk management, data governance, and technical documentation. The school or institution that uses it is the deployer and has its own duties, including human oversight and using the system as instructed. A vendor that supplies the information and oversight tooling deployers need makes compliance easier, which is a commercial as well as a legal advantage.
Atta Systems builds custom EdTech software for schools, universities, and education companies, including EdXP and StudySmart, classifying AI features against the AI Act and building the high-risk controls into the covered ones from the first version.
Atta Systems focuses on custom EdTech development where privacy, accessibility, and AI Act obligations are built in across learning management, assessment, and adaptive learning software, rather than off-the-shelf platform resale or general consumer app development that lacks education-specific requirements.
Related Articles

