High-Risk AI in Education: the Annex III Category
9 min read · updated August 11, 2026
Annex III point 3 does not make AI in education high-risk. It makes four specific uses high-risk, all of them decisions about a person’s educational path, and the gap between those four and the rest of edtech is where almost every classification question in this sector is decided.
The four uses in Annex III(3)
Point 3 of Annex III to Regulation (EU) 2024/1689 lists AI systems intended to be used:
- (a) to determine access or admission, or to assign natural persons to educational and vocational training institutions at all levels;
- (b) to evaluate learning outcomes, including where those outcomes are used to steer the learning process of natural persons in such institutions at all levels;
- (c) to assess the appropriate level of education that an individual will receive or will be able to access, in the context of or within such institutions at all levels;
- (d) to monitor and detect prohibited behaviour of students during tests in the context of or within such institutions at all levels.
The thread running through (a) to (c) is that the system’s output shapes what education a person gets. Admission is the obvious case; “assign to” catches streaming and placement; (b) reaches automated marking and, through its second limb, adaptive learning systems that use assessment to route a learner down one path rather than another; (c) catches level-setting and tracking decisions taken outside a formal assessment.
The institution limiter
Points (b), (c) and (d) are all qualified by “in the context of or within educational and vocational training institutions”, and (a) by assignment or admission “to” them. That limiter is doing real work. A language-learning app sold direct to consumers assesses learning outcomes constantly and is not operating in the context of an institution. A corporate training platform that scores employees is likewise outside point 3 — but is very likely inside point 4, because Annex III(4)(b) covers systems used to evaluate performance and behaviour in work-related relationships. The obligation does not disappear; it moves. See the employment category.
“At all levels” removes the other obvious argument. There is no carve-out for primary schooling, for vocational training, or for non-degree adult education. A driving-school theory assessment tool and a university admissions model are in the same category.
What is not automatically high-risk
A great deal of what is sold as education AI does not appear in point 3 at all: timetabling and room allocation, plagiarism detection that flags text for a human to judge, lesson-plan generation, translation and accessibility tooling, tutoring assistants that answer a student’s question without recording an assessment, administrative chatbots.
Two mechanisms decide the borderline cases. The first is intended purpose: Annex III speaks of systems “intended to be used” for the listed purposes, and intended purpose is the provider’s declaration under Article 3(12), evidenced by the instructions for use and the marketing material. A general assistant that a school in fact uses to grade essays raises the Article 25(1)(c) problem instead: the deployer that modifies the intended purpose so that the system becomes high-risk is treated as its provider.
The second is Article 6(3). An Annex III system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making, and one of four conditions is met: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from prior patterns and is not meant to replace or influence the previously completed human assessment without proper human review; or it performs a preparatory task to an assessment. A tool that ranks applications for a human admissions officer is a preparatory task in form and, if it materially influences the outcome, not one in substance — which is the tension the Commission’s Article 6(5) guidelines were meant to resolve with worked examples.
The override in the final subparagraph of Article 6(3) applies here more often than elsewhere: an Annex III system is always high-risk where it performs profiling of natural persons. A system building a persistent learner profile to drive decisions is profiling within the meaning of Article 4(4) GDPR, and the exemption route is closed to it entirely.
Proctoring, and where Article 5 cuts across
Point 3(d) is written narrowly: monitoring and detecting prohibited behaviour of students during tests. Identity verification at the start of an exam is a one-to-one biometric verification and falls in the Annex III(1)(a) carve-out; general classroom attention monitoring outside a test is not point 3(d) either, though it may be caught by data protection law and by national education law.
The decisive rule for this product category is not in Annex III at all. Article 5(1)(f) prohibits placing on the market, putting into service or using AI systems to infer the emotions of a natural person in the areas of workplace and education institutions, except where intended to be put in place or into the market for medical or safety reasons. A proctoring system that infers stress, nervousness, confusion or deception from a face or a voice is inferring emotion in an education institution, and it is prohibited — not high-risk. That prohibition has applied since 2 February 2025 and was not touched by the 2026 amendment that moved the Annex III dates back. A proctoring vendor cannot treat the later high-risk date as breathing space here: the emotion-inference question has been live for over a year already.
A proctoring system that detects a second face in frame, a person leaving the camera view, or a second device, without inferring an emotional state, is not caught by Article 5(1)(f) and is a point 3(d) high-risk system. That distinction is the entire compliance boundary for the category. See the emotion recognition prohibition and the biometrics category.
The duties that apply regardless
Three obligations reach education deployers whether or not a given system is high-risk. Article 4, the AI literacy duty, has applied since 2 February 2025 to providers and deployers alike, and requires measures to ensure a sufficient level of AI literacy among staff and others dealing with the operation and use of AI systems on their behalf — an obligation that fits an educational institution more naturally than most. See the AI literacy obligation.
Article 50 transparency duties apply to any system interacting directly with natural persons and to synthetic content, which reaches student-facing assistants regardless of risk tier. And the GDPR applies throughout, with Article 8 conditions for children’s consent in information society services and the Article 22 restriction on solely automated decisions with legal or similarly significant effects — a real constraint on automated admissions. See children’s data and AI and what meaningful human involvement requires.
Where a public school or university deploys an Annex III system, two further duties land on the deployer: Article 27 requires a fundamental rights impact assessment from bodies governed by public law and private entities providing public services, and Article 49(3) requires such deployers to register in the EU database before putting the system into use. The text is on EUR-Lex.