EU AI Act compliance for edtech and online learning companies
Education has its own Annex III category, so edtech companies need to look at point 3 closely. Admission decisions, evaluation of learning outcomes, level assessment, and monitoring during tests are all named.
Adaptive practice and content recommendation generally sit outside that list. Grading, placement, and proctoring do not.
Are you a provider or a deployer?
Building the platform makes you a provider. Schools and universities using it are deployers, and public institutions among them also carry an Article 27 fundamental rights impact assessment duty.
How this is classified under the Act
Annex III point 3 covers admission and assignment to institutions, evaluation of learning outcomes, assessment of the appropriate level of education, and monitoring and detecting prohibited behaviour during tests. Features doing those things are high-risk. Practice recommendation and content sequencing usually are not.
What changes the answer: Article 5(1)(f) prohibits emotion inference in educational institutions outside medical and safety purposes. Engagement, attention, and mood detection in a learning product is a prohibition problem rather than a documentation one.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 5(1)(f) No emotion or attention inference
Review any engagement or attention detection feature against the prohibition before treating it as a high-risk compliance task.
- Article 13 Instructions for use for institutions
Your customers need documentation that lets them meet their deployer duties, including accuracy, limitations, and supported oversight measures.
- Article 10 Data governance and bias
Assessment models must be examined for bias across student populations. Language, disability, and socioeconomic proxies are the usual failure points.
- Article 50 Disclosure to learners
AI tutors and generated learning content need transparency toward the learner, from 2 August 2026.
Common mistakes
- Shipping attention tracking in a classroom product without checking Article 5.
- Classifying an entire platform at once when only the assessment features are high-risk.
- Leaving public sector customers without the information they need for their Article 27 assessment.
- Testing model accuracy only on the majority student population.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.