
The classroom note
A school weighing an AI proctoring tool for exams needed to know whether a new European law reached it. On 12 July 2024 the EU published Regulation (EU) 2024/1689, the AI Act, in the Official Journal. Under Article 6(2), Annex III names four education uses as "high-risk": deciding admission to an institution, evaluating learning outcomes, assessing what level of education someone can access, and "monitoring and detecting prohibited behaviour of students during tests" — proctoring software, named directly. High-risk status does not ban a tool; it triggers duties for whoever builds it and whoever deploys it.
What the evidence says
This is binding regulation, not research evidence, so the useful distinction is require versus recommend. For providers building the system, the law requires a documented risk-management system maintained through the product's life, technical documentation, a conformity assessment before market, and design supporting "human oversight by natural persons" able to intervene or override it. For deployers — the school using the system — a separate Article 26 sets lighter duties: use it "in accordance with the instructions for use," assign oversight to people with real competence, training and authority, monitor its operation, report serious incidents, and keep its logs for at least six months. These fall on two different parties, and a school checking its own compliance needs to know which apply to it.
The implementation question
A proctoring vendor selling into the EU must produce a conformity assessment and documentation before selling a system that falls under Annex III, not merely describe it as "AI-powered." A school deploying it must name a staff member with real authority and training to override a false "prohibited behaviour" flag, not a general policy that a teacher "can" intervene. Keeping six months of logs is a records cost few schools have budgeted for; it lets an incident be reconstructed if a student disputes a flagged result. None of this is optional once a tool falls into an Annex III category.
What holds and what fails
The date matters: high-risk obligations under Annex III apply from 2 August 2026, so a system bought before that date is not automatically compliant once it passes. It holds as a floor unlike guidance elsewhere in this batch: non-compliance here is legal exposure, not unmet advice. It fails wherever a vendor markets a tool as meeting "AI Act requirements" without a school ever seeing the conformity assessment or documentation the law requires it to produce. This is an editorial reading: a claim of compliance is not the same as the document a school is entitled to ask for.
- Does the vendor's exam-monitoring or admissions tool fall under Annex III, and can they produce a conformity assessment for it?
- Who at the school has the authority and training to override a flagged decision, and have they used it?
- Are the system's logs retained for six months, and who is responsible for that?
Unlike a department's guidance, a regulation carries a date after which "we did not know" stops being a defence; 2 August 2026 is that date for these four uses of AI in education.
Sources & reading trail
Publishes the AI Act in the Official Journal and establishes Annex III high-risk categories including education uses, with obligations phased to 2 August 2026.
Source published: 12 July 2024 · Retrieved: 16 September 2026
Quotes the four education-specific high-risk categories: admission/access, evaluating learning outcomes, assessing education level, and exam-monitoring software.
Source published: Not established · Retrieved: 16 September 2026
Sets deployer obligations distinct from provider obligations: use per instructions, human oversight, monitoring, and six-month log retention.
Source published: Not established · Retrieved: 16 September 2026
Departments, studies and vendor documents establish the record; the implementation reading and the boundary are School AI Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.