By sector · Education and training
AI regulation in education and training
Education is named as a high-risk area in several instruments: admissions, assessment, proctoring and the allocation of learning are decisions about people, often minors. Institutions are deployers; edtech vendors are providers; the duties on both are listed here with the controls that meet them.
- Jurisdictions
- 3
- Evidence items
- 39
Minors raise the bar
Data-protection law and AI law both treat children as needing stronger safeguards. Notices have to be understood by the people receiving them, oversight has to be real, and emotion recognition and some biometric uses are prohibited outright in some jurisdictions.
Procurement again
Most educational AI is bought, so the contract and the vendor's documentation are the institution's first evidence. The contractual and vendor controls below carry that.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| Decision explanation, human review and appeal route Process | 3 | 1 | Customer operations lead · once per ai system |
| AI risk assessment and lifecycle risk register Process | 3 | 1 | AI system owner · once per ai system |
| AI interaction and use disclosure notices Process | 3 | 0 | Product owner · at launch and on material change |
| AI governance policy and accountability structure Policy | 2 | 1 | Executive sponsor for AI · annual |
| Technical documentation, model cards and instructions for use Process | 2 | 1 | Product or model owner · at launch and on material change |
| AI incident management and regulatory reporting Process | 2 | 0 | Incident coordinator · continuous |
| AI impact and fundamental-rights impact assessment Process | 1 | 0 | AI system owner · once per ai system |
| Prohibited and unacceptable-use screening gate Process | 1 | 0 | AI governance lead · once per ai system |
| AI system inventory and classification Process | 0 | 3 | AI governance lead · continuous |
| Post-deployment monitoring and drift detection Technical measure | 0 | 2 | AI system owner · continuous |
| Automatic event logging and record retention Technical measure | 0 | 1 | Engineering lead · continuous |
| Training-data provenance and copyright register Process | 0 | 1 | Model development lead · at launch and on material change |
| Accuracy, robustness, fairness and security testing Technical measure | 0 | 1 | Quality or testing lead · at launch and on material change |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
Colorado (United States) 9 duties
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(3)applies from 30 Jun 2026Deployers must complete impact assessments for high-risk AI
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(2)applies from 30 Jun 2026Deployers must implement a risk management policy and programme
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(7)applies from 30 Jun 2026Deployers must notify the Attorney General of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(5)applies from 30 Jun 2026Deployers must publish a statement about the high-risk AI systems they use
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(1)applies from 30 Jun 2026Deployers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702applies from 30 Jun 2026Developers must document high-risk systems and disclose known risks
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(5)applies from 30 Jun 2026Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(1)applies from 30 Jun 2026Developers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(4)applies from 30 Jun 2026Notify consumers and explain adverse consequential decisions
European Union 3 duties
-
Legal requirementEU AI Act · Article 86applies from 2 Aug 2026Deployers must explain individual decisions taken with high-risk AI on request
-
Legal requirementEU AI Act · Article 26(11)applies from 2 Aug 2026Deployers must tell natural persons that a high-risk AI system is used in decisions about them
-
Legal requirementEU AI Act · Article 5applies from 2 Feb 2025Do not deploy or provide AI for prohibited practices
South Korea 3 duties
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must be able to explain outputs and the main criteria behind them
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must establish and operate a risk management plan
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
What evidence would a reviewer expect?
- AI decision challenge and human review procedure Procedure or standard operating process
- AI governance forum minutes Governance meeting record
- AI impact assessment Impact assessment
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI intake and classification procedure Procedure or standard operating process
- AI interaction or use notice Disclosure or notice
- AI policy Policy document
- AI responsibility map Register entry
- AI system event logs Access or activity log
- AI system register Register entry
- AI system risk assessment Risk assessment
- Adverse-decision explanation template Disclosure or notice
- Board or executive approval of the AI policy Approval or sign-off record
- Challenge and reversal log Monitoring record
- Copyright and rights-reservation policy Policy document
- Impact assessment approval Approval or sign-off record
- Impact assessment procedure and template Procedure or standard operating process
- Incident report to an authority Regulatory filing or notification
- Instructions for use Disclosure or notice
- Log integrity and retention check Audit or assurance report
- Log schema and retention standard Procedure or standard operating process
- Model card or deployer information pack Model documentation
- Monitoring dashboard or periodic monitoring report Monitoring record
- Monitoring review decision Approval or sign-off record
- Notice catalogue Register entry
- Notice wording approval Approval or sign-off record
- Per-system AI risk register Risk register
- Post-market monitoring plan Procedure or standard operating process
- Pre-release test report Evaluation or test report
- Prohibited-use screening record Approval or sign-off record
- Public summary of training content Disclosure or notice
- Release test sign-off Approval or sign-off record
- Residual-risk acceptance Approval or sign-off record
- Risk-tier classification sign-off Approval or sign-off record
- Screening list and escalation procedure Procedure or standard operating process
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Training source register Register entry
Latest changes to these instruments
European Commission proposes Digital Omnibus adjustments to AI Act timelines
Colorado delays the AI Act effective date to 30 June 2026
EU AI Act general-purpose AI, governance and penalty provisions start to apply
European Commission publishes the General-Purpose AI Code of Practice
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is automated proctoring regulated?
- Under several instruments, monitoring students during tests is a high-risk use, and emotion recognition in education is prohibited in at least one. Check the duty pages for the article.
- What should an institution keep?
- A register of the systems in use, the vendor documentation, the notices given to students and parents, the human-review procedure for assessments, and the impact assessment where required.