The EU AI Act's education provisions are narrower than the discourse around them, and the narrowness is the useful part. The Act does not classify educational AI as high-risk wholesale; it lists specified institutional uses: systems used to determine access or admission to educational institutions, to evaluate learning outcomes where those outcomes steer a learner's educational process, to assess the level of education a person should receive, and to monitor prohibited behaviour during tests. The relevant high-risk obligations are currently scheduled to apply from 2 December 2027. Everything practical follows from reading that list precisely, which is what this guide does, for medical schools deploying tools and providers building them; it is general orientation, not legal advice, and consequential classifications deserve specific counsel.
The risk-based logic, and what the listed uses share
The Act regulates by use and consequence, not by technology: the same underlying model can sit outside the framework in one deployment and inside high-risk in another. The listed educational uses share one property worth internalising, institutional consequence: each one shapes a learner's access, pathway or standing through an institution's decision. Admission scoring decides who enters; outcome evaluation that steers the educational process decides where a learner is routed; level assessment decides what education someone receives; proctoring decides accusations of misconduct. High-risk status attaches to systems intended for those consequential institutional functions, and brings the corresponding obligations, risk management, data governance, transparency, human oversight, accuracy and robustness requirements, allocated between providers and deployers.
What is not automatically high-risk
The clarification most of the market needs: a consumer self-study question bank is not automatically high-risk merely because it recommends questions. Optional consumer learning tools, ordinary content recommendation, and low-consequence practice feedback sit outside the listed categories when they are not used by an institution to evaluate or steer consequential pathways; the Act also contains limited exceptions within its classification machinery for systems whose listed-area use does not pose significant risk, subject to conditions and documentation. Two honest caveats keep this from becoming complacency. Classification depends on intended purpose and deployment context, so the same adaptive product sold to individuals and embedded by a medical school into progression decisions can carry different statuses in the two settings, and the institutional embedding is what changes it. And this reading is an inference from the statutory categories, not a definitive legal determination; providers approaching the boundary should classify formally, with advice, and say so in their documentation.
Medical-school examples, run through the logic
Concrete cases, decided by function. An admissions screening algorithm ranking applicants: squarely listed, high-risk. An OSCE or written-exam scoring system whose outputs steer progression: outcome evaluation with institutional consequence, listed. A proctoring system flagging suspected misconduct in online examinations: listed by name. A school licensing an adaptive question bank as optional self-study for students: consumer-style use, not automatically caught. The same bank's analytics wired into the school's formal identification of students for remediation pathways: the outputs are now steering an educational process institutionally, and the deployment has walked toward the listed categories, which is exactly the migration risk procurement should watch, features and integrations added after purchase changing the classification the purchase was assessed under. The decision habit for institutions: classify the use, not the product, and re-classify when the use changes.
What providers and deployers should do before December 2027
For edtech providers, iatroX included in the discipline: document intended purpose precisely, including what the product is not for; know which side of the listed categories each deployment mode sits on; and where institutional, consequential uses are the offer, build the compliance machinery now, because the obligations reward preparation. For medical schools and deployers: inventory AI touching admission, assessment, progression or proctoring; assign classification owners; ask vendors the intended-purpose question in writing; and fold the answer into the same governance that already handles data protection, where UK deployments add their own GDPR profiling duties alongside. The strategic reading for the category is the constructive one: the Act formalises a distinction good educational AI already respects, between tools that help learners practise and systems that decide learners' fates, and building on the right side of that line was worth doing before any regulation said so.
Frequently asked questions
Does the Act apply to UK institutions at all?
It applies by reach and market: EU deployments, EU-facing offerings and EU learners can bring UK-based providers and programmes into scope, which is why UK edtech should classify rather than assume exemption.
Is adaptive difficulty itself a high-risk feature?
No feature is high-risk in isolation; the listed uses are institutional functions, and adaptivity inside optional self-study is not among them, while adaptivity inside institutional level-assessment is.
What should a procurement question sound like?
"State the intended purpose, which Act categories you have assessed this use against, and who carries provider and deployer obligations"; a vendor with a crisp answer has done the work.
