Written by Dr. Jasmin (Bey) Cowin
Enforcement Begins in Brussels
“From 2 August 2026, the European Commission’s AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act.” European Commission press release, July 31, 2026
The European Union’s Artificial Intelligence Act, which took effect on August 1, 2024, as the world’s first comprehensive regulatory framework for AI, has now moved from legislative architecture to active enforcement. As of August 2, 2026, the European Commission’s AI Office, working in concert with national market surveillance authorities, holds the power to investigate, sanction, and compel compliance across the full range of the Act’s risk-based obligations, including the demanding requirements attached to high-risk systems enumerated in Annex III.
The compliance clock is precise, and it has been running for some time. Prohibited practices became enforceable in February 2025, technical documentation for newly placed general-purpose models came due in August 2025, and the conformity assessments required of high-risk systems reached their deadline this summer. What has changed now is that the machinery of oversight, from the AI Office in Brussels to the national authorities charged with market surveillance, has moved from preparation to practice, and institutions that regarded the Act as a distant European concern will find that its reach extends considerably beyond the borders of the Union.
Transparency Becomes Law Rather Than Aspiration
“Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system.” EU AI Act, Article 50
The same date activates the Act’s transparency regime, a set of obligations that translates an abstract principle of informed interaction into enforceable design requirements. Under the new rules, chatbots and other interactive AI systems must disclose to users that they are dealing with a machine rather than a human interlocutor, deepfakes must be labelled as such, and AI-generated or altered content must carry machine-readable marks that permit its detection. The Commission’s guidelines, published on July 20, clarify the division of labor: providers must build disclosure and marking into the systems themselves, while deployers must inform people when they are exposed to deepfakes, to AI-generated content on matters of public interest published without human editorial review, and to emotion recognition or biometric categorization systems.
These requirements are neither ornamental nor peripheral to educational technology. Even limited-risk systems must satisfy transparency rules that mandate clear user notification and explicit labelling of AI-generated content, which means that the advising chatbot answering a prospective student’s questions in Dublin, or the automated feedback tool reviewing essays submitted from a partner campus in Bologna, now operates under statutory disclosure duties rather than institutional discretion. The Commission has coupled these obligations with a voluntary Code of Practice on transparency of AI-generated content, to which more than 180 organizations have already committed, signaling that much of the industry has concluded that early alignment is preferable to later confrontation.
A Formal Channel for Grievance
“The AI Act Complaint Tool allows individuals and organisations to submit complaints to the AI Office concerning alleged infringements of the AI Act by providers or deployers of AI systems.” European Commission press release, July 31, 2026
Alongside its enforcement powers, the Commission has opened a formal complaint mechanism through which both natural and legal persons may bring alleged infringements before the AI Office. Complaints may be submitted in any of the EU’s official languages, must identify the country in which the incident occurred, and require complainants to provide identification and contact details, while a separate whistleblower channel offers anonymity to eligible individuals professionally connected to AI providers or deployers who wish to report violations that could endanger fundamental rights, health, or public trust.
The significance of this mechanism for higher education should not be underestimated, because it distributes the work of enforcement beyond the regulator itself. A student subjected to automated proctoring without adequate disclosure, a faculty member who questions the data governance behind an admissions screening tool, or a European partner institution uneasy about an American collaborator’s learning analytics platform now possesses a direct procedural route to the AI Office, and the confidential handling of such complaints means that institutions may first learn of an inquiry only after it has begun.
Education’s Place in the High-Risk Tier
“AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels.” EU AI Act, Annex III
The Act’s framework defines four categories of risk with corresponding obligations, and educational applications are directly addressed within it, with Annex III classifying as high-risk those systems that determine access or admission, evaluate learning outcomes, assess the appropriate level of education an individual will receive, or monitor and detect prohibited behavior during tests. This classification covers a broad spectrum of familiar campus technologies, including adaptive tutoring systems that adjust learning pathways based on student performance, automated proctoring platforms, admission and financial-aid scoring, and learning analytics dashboards that steer the learning process.
Providers of high-risk systems must implement a comprehensive life-cycle risk-management system, rigorous data governance and bias testing, detailed technical documentation, mandatory human oversight in decision-making processes, extensive logging capabilities for traceability, and post-market monitoring, with serious malfunctions reportable within fifteen days to the relevant authority. Emotion-recognition and social-scoring tools are prohibited outright by Article 5, a prohibition that in higher education settings encompasses systems analyzing student facial expressions, voice patterns, or biometric indicators to assess engagement, stress levels, or emotional states. The financial consequences of noncompliance mirror the severity of each violation, and penalties of up to €35 million or 7 percent of global turnover create financial exposure comparable to the loss of accreditation or federal-aid eligibility.
The Brussels Effect Reaches the Non-EU Campus
“Providers placing on the market or putting into service AI systems, or where the output of an AI system is used in the Union, irrespective of whether those providers are established within the Union or in a third country.” EU AI Act, Article 2(1)
For university systems outside the Union that maintain European partnerships, the operative provision is Article 2(1), whose extraterritorial clause expands EU regulatory requirements well beyond traditional territorial boundaries, obliging institutions to examine every AI-enabled service that can affect users or operations within the European Union. Four common activities meet the Act’s threshold: enrolling EU nationals in distance or hybrid programs that rely on adaptive-learning platforms or AI-supported assessment, operating EU-based study-abroad centers that use home-campus chatbots or proctoring software, licensing ed-tech tools to European partner campuses when the underlying model is supplied from abroad, and running domestically hosted AI systems whose outputs are viewed or applied inside the Union.
Because European universities are roughly twice as likely as their American counterparts to offer at least one joint degree, this asymmetry magnifies the regulatory exposure of institutions that must align not only with their own national higher-education regulations and accreditation standards but also with EU AI Act requirements whenever a collaborative program involves EU participants. The University of Amsterdam’s proctoring litigation, upheld in Dutch courts despite privacy challenges, illustrates that digital education initiatives cannot be separated from regulatory oversight, and a partner institution coadministering online examinations with a European university inherits the same conformity assessment, transparency, and human oversight obligations.
High-risk AI systems and Tools in Education
“The measures are intended to reduce deception and manipulation and help people make informed choices.” European Commission press release, July 31, 2026
What are high-risk AI systems and tools in education?
The EU AI Regulation classifies AI systems as high-risk AI if they meet one or both of the following conditions: The AI system is intended to be used as a safety component of a high-risk product (Annex I of the AI Act) or if the high-risk product itself is an AI system. For example, if AI is used in cars, medical devices and elevators.
The AI system falls under one of the areas listed in Annex III of the Act, including the educational sector:
· AI systems and tools intended to determine access, admission and allocation to education (or a course, track or minor, etc.)
· AI systems and tools that evaluate learning outcomes and, where appropriate, guide the learning process (e. g. automated grading, learning analytics systems with AI)
· AI systems and tools that assess the appropriate level of education or determine who has access to a particular level of education (e. g. adaptive learning systems with AI)
· AI systems and tools that monitor and detect unauthorized behavior during tests (proctoring)
Not covered by the AI Act
· AI systems and tools used exclusively for military or defense purposes; Art 2.3
· AI systems and tools used exclusively for scientific research and scientific development as their sole purpose; Art. 2.6 and 2.8
· AI systems and tools purely for non-professional purposes; Art. 2.10. For example, teachers who experiment with an AI tool solely for their own private experience.
· Open source AI systems and tools that do not function as independent AI systems or are not used for regulated applications; Art 2.12
Roles within the AI Act
The requirements of the EU AI Act vary and depend on the role/actor. The two most common roles within the UU are:
· Deployer in the role of end user or data controller
· Provider
Requirements for providers of high-risk AI systems and tools (Art. 16 et seq.)
Compliant with the requirements of Art. 16a, includes:
· Data management: representative, bias-limited and authorised datasets; Art. 10
· Transparency and human oversight measures built in and clear instructions for the user; Art. 13–14
· Ensuring the accuracy, robustness and cyber security of the AI system; Art. 15
· Post-market monitoring and incident reporting and subsequent corrective actions; Art. 20, 72–73
· Carry out conformity assessment and draw up/affix EU declaration of conformity and CE marking; Art. 16. b,f–i and 43
· Apply a risk management system for the entire life cycle; Art. 16c and 9, 17
· Maintain technical documentation and logs; Art. 16d and 18, 19
· Take corrective action if not AI act compliant; Art. 16j and 20
· Register the AI system in the EU database; Art. 16. i
· Maintain a quality management system (QMS); Art. 17.1
· Be available to supervisory authorities such as the Dutch Data Protection Authority and be able to demonstrate compliance; Art. 16k and 21
· Ensure that the AI system is accessible to persons with disabilities; Art. 16l
Provider, Deployer, or Both: Locating the University in the Act’s Taxonomy
“Deployers, defined in Article 3(4) as users operating an AI system under their authority, must follow the provider’s instructions, monitor the system, and log significant incidents.” EU AI Act, Article 3(4)
The life cycle of an AI system is divided across distinct actors under the Act, with different corresponding responsibilities, and a university’s obligations therefore depend not on what it is but on what it does with a given system. An institution may occupy the role of provider, of deployer, or of both simultaneously, and a European Commission Q&A has clarified that these roles can be held by different entities in a single supply chain, with each role triggering a distinct set of compliance tasks. The four situations set out below map the most common institutional configurations onto the Act’s taxonomy:
Provider and Deployer Roles Under the EU AI Act: Four University Scenarios
Scenario 1: The university develops an AI system and places it on the market.
When a university develops an AI system or tool and makes it available to third parties, it acts as a provider only. Provider obligations alone attach, including conformity assessment, preparation of the technical file, and CE (Conformité Européenne) marking (arts. 16–24).
Scenario 2: The university procures a ready-made AI tool for internal use.
When a university procures an existing AI tool and deploys it internally with its lecturers, teaching support staff, or students, it acts as a deployer only. Deployer obligations apply: following the provider’s instructions, monitoring the system, and logging significant incidents (art. 3(4)).
Scenario 3: The university develops an AI system and operates it itself.
When a university both develops and operates an AI system with its own lecturers, teaching support staff, or students, it holds provider and deployer status simultaneously. Both sets of obligations attach across the system’s life cycle, from technical groundwork through operational oversight.
Scenario 4: The university fine-tunes an existing AI system in a way that changes its purpose or risk profile.
When a university adopts an existing AI system but modifies it so that the system’s intended purpose or risk profile changes, it assumes provider status through substantial adaptation while remaining a deployer. Both sets of duties attach once the modification is made.
Governance Beyond Technical Compliance
“The measures are intended to reduce deception and manipulation and help people make informed choices.” European Commission press release, July 31, 2026
Effective governance of AI for educational institutions requires more than technical compliance; it demands proactive alignment with the Act’s risk classification framework, adoption of institutional governance mechanisms, and the cultivation of AI literacy across all levels of staff and students. Several European universities offer working models, with Utrecht University classifying AI systems by risk level, pre-approving tools through an internal review process, and appointing compliance officers across faculties, while the University of Edinburgh has published governance guidelines aligned with the Act’s principles of transparency, human oversight, and rights protection.
Institutions beyond the EU should begin by mapping AI use cases against the Act’s risk categories and preparing their communities for compliance through open discussion, recognizing that documentation need not reside physically in Europe so long as records remain organized, secure, and electronically transmissible to competent authorities upon request. These layers of record-keeping and scrutiny can slow collaborative timelines, but they now form the mandatory framework for all trans-Atlantic research that employs advanced AI, and as AI tools increasingly underpin admissions, assessment, and student support in international partnerships, the Act will continue to shape compliance obligations and influence the strategic direction of cross-border higher education collaboration for years to come.
The stakes of that obligation, and the trajectory it sets, are captured in the conclusion of the Rockefeller Institute of Government’s November 2025 policy brief on the Act and its implications for New York State higher education:
“As AI tools increasingly underpin admissions, assessment, and student support in international partnerships, the AI Act will continue to shape compliance obligations and influence the strategic direction of US-EU higher education collaboration for years to come.” Cowin, J. (2025, November). The European AI Act and its implications for New York State higher education institutions [Policy brief]. Rockefeller Institute of Government.
Dr. Jasmin (Bey) Cowin is an associate professor at Touro University, where she held the CETL Faculty Fellowship for 2024–2025. A Fulbright Scholar and SIT graduate, she was selected as a U.S. Department of State English Language Specialist in 2024. She served as a Richard P. Nathan Public Policy Fellow at the Rockefeller Institute of Government and as an education policy fellow (EPFP™) at Columbia University, Teachers College. She writes on artificial intelligence in education and on the long horizon she calls “Education for 2060.” You can connect with her through LinkedIn.

