Artificial Intelligence Act (Regulation (EU) 2024/1689)
The EU's horizontal AI regulation, published in the Official Journal on 12 July 2024 (OJ L, 2024/1689) and in force since 1 August 2024 (the twentieth day after publication, Art. 113), applying in phases through 2028 (see APPLICATION-TIMELINE.md). It takes a risk-based approach: prohibited practices, high-risk systems with conformity requirements, transparency duties for certain systems, and a separate regime for general-purpose AI models. It applies to providers placing AI systems on the Union market wherever established, to deployers in the Union, and extraterritorially where a system's output is used in the Union (Art. 2(1)). Enforced by national market surveillance authorities; the Commission's AI Office supervises general-purpose AI models.
Amended. This folder reproduces the consolidated text CELEX 02024R1689-20260727: the Regulation as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI", 8 July 2026). The amendment materially changed the parts EdTech cares about — it postponed the application of the high-risk regime for Annex III systems to 2 December 2027 (Annex I systems: 2 August 2028) (Art. 113(c)), added prohibitions on AI generation of non-consensual intimate imagery and child sexual abuse material (points (ba)/(bb), applying from 2 December 2026), softened the Art. 4 AI-literacy duty, and inserted Art. 4a permitting special-category processing for bias detection. Secondary commentary describing the pre-amendment timeline (high-risk from August 2026) is now wrong.
Applicability to EdTech
- Education is a named high-risk area. Annex III point 3 lists AI systems intended to determine access or admission, evaluate learning outcomes (including steering the learning process), assess the appropriate level of education, or monitor and detect prohibited behaviour of students during tests. A vendor whose system is intended for these uses is a high-risk provider (Arts. 8–17); the school using it is a deployer (Art. 26).
- Emotion inference in education institutions is prohibited except for medical or safety reasons (Art. 5(1)(f)) — directly relevant to any classroom affect-detection or engagement-scoring feature. Emotion recognition outside the prohibition is itself Annex III high-risk (point 1(c)) and carries a disclosure duty (Art. 50(3)).
- Transparency duties apply regardless of risk class: telling people they are interacting with an AI system, and marking synthetic (AI-generated) content (Art. 50).
- Deployers that are bodies governed by public law or private entities providing public services — categories education institutions typically fall into — owe a fundamental rights impact assessment prior to deploying an Annex III high-risk system (Art. 27(1)); expect this to surface in procurement questionnaires.
- Integrating a general-purpose AI model (e.g. an LLM behind a classroom assistant) makes the GPAI provider's downstream-information duty (Art. 53(1)(b)) the integrator's entitlement; becoming a provider of a high-risk system by putting one's name on it, substantially modifying it, or repurposing it is governed by Art. 25.
- Both providers and deployers owe AI literacy measures to staff operating AI systems (Art. 4).
Contents
| Document | Covers |
|---|---|
| GENERAL-PROVISIONS.md | Arts. 1–4a — subject matter, scope, definitions, AI literacy, bias-detection processing |
| PROHIBITED-PRACTICES.md | Art. 5 — prohibited practices (incl. education emotion inference) |
| HIGH-RISK-CLASSIFICATION.md | Arts. 6, 7; Annex III — what counts as high-risk |
| HIGH-RISK-REQUIREMENTS.md | Arts. 8–15 — requirements for high-risk systems |
| OPERATOR-OBLIGATIONS.md | Arts. 16, 25–27 — provider/deployer obligations, value chain, FRIA |
| TRANSPARENCY.md | Art. 50 — disclosure and synthetic-content marking |
| GPAI.md | Arts. 51, 53, 55 — general-purpose AI models |
| REMEDIES-AND-PENALTIES.md | Arts. 85, 86, 99, 101 — complaints, explanation right, fines |
| APPLICATION-TIMELINE.md | Arts. 111, 113 — application dates (as amended) and transitional rules |
Scope note: the conformity-assessment machinery (Arts. 28–49), governance chapters and the remaining annexes can be added with the same tooling when needed.
Key obligations at a glance
- No emotion inference on students in education institutions, save medical/safety uses (Art. 5(1)(f)); applies since 2 February 2025 (Art. 113(a)).
- Annex III education systems: providers must meet risk-management, data-governance, documentation, human-oversight and accuracy requirements (Arts. 8–15) and the Art. 16 obligations — applying from 2 December 2027 (Art. 113(c)(i)).
- Deployers of high-risk systems: use per instructions, assign human oversight, ensure input-data relevance, monitor and keep logs (Art. 26).
- Disclose AI interaction and mark synthetic content (Art. 50(1)–(2)); pre-existing generators must comply with Art. 50(2) by 2 December 2026 (Art. 111(4)).
- AI-literacy measures for staff of providers and deployers (Art. 4(1)).
Enforcement
National market surveillance authorities (Chapter IX); the AI Office enforces the GPAI chapter with Omnibus-added powers (Arts. 75a–75d, not reproduced here). Fine ceilings: EUR 35m / 7% of worldwide turnover for prohibited practices (Art. 99(3)); EUR 15m / 3% for most operator obligations (Art. 99(4)); EUR 7.5m / 1% for misleading information (Art. 99(5)); GPAI providers up to 3% / EUR 15m (Art. 101(1)). Affected persons may complain to a market surveillance authority (Art. 85) and obtain explanations of individual decisions based on Annex III systems (Art. 86).
Related
- EU GDPR — the Act is without prejudice to it (Art. 2(7)); most Annex III education uses also process pupils' personal data
Sources
- EUR-Lex — Regulation (EU) 2024/1689 (AI Act), consolidated text 02024R1689-20260727
- EUR-Lex — Regulation (EU) 2024/1689, original OJ text
- EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- European Commission — AI Office
Meta
Built and re-verified mechanically — see tools/eur-lex: build_eu_ai_act.py extracts from the Cellar API copy of the consolidated text; build_eu_ai_act.py verify confirms every source paragraph appears verbatim. Do not hand-edit article text. The consolidated CELEX id is pinned in the script — on the next amendment, adopt the new consolidation id deliberately. Consolidation markers (▼M1/▼B) are stripped as apparatus. Known source quirk: the consolidated text renders Article 1's title as Subject matter' (stray trailing apostrophe) — present in both the Cellar XHTML and the EUR-Lex HTML view, reproduced here verbatim; do not "fix" it.