The classic trap
Recital 56 locks in the high-risk classification of any AI system used in education and vocational training, from admission to exam proctoring. In practice, many Luxembourg institutions deploy SaaS tools (automated grading, anti-cheating, algorithmic orientation) without realising they fall under Article 6(2) and Annex III. The EU AI Office and the CNPD (personal data side) will sanction the absence of impact assessment, technical documentation and human oversight. The trap: assuming that an off-the-shelf edtech tool shifts all compliance to the vendor, when the institution is actually a deployer under the AI Act and carries its own obligations.
The 6 education use cases that automatically become high-risk
- Admission platforms or application scoring (universities, vocational programmes, apprenticeships).
- Algorithmic assignment to an institution or programme.
- Automated assessment of learning outcomes (test grading, AI-based marking, AI-assisted continuous assessment).
- Algorithmic orientation influencing the level of education (track recommendation).
- Proctoring and detection of prohibited behaviour during exams (video, audio, eye-tracking analysis).
- Dropout detection or academic success prediction systems.
The legal consequences are heavy: registration in the EU database (Art. 49), fundamental rights impact assessment (Art. 27), effective human oversight (Art. 14), bias management (Art. 10) and transparent information to learners. Recital 56 explicitly targets historical patterns of discrimination (gender, age, disability, origin, orientation), making bias auditing non-negotiable.
How Luxgap automates this risk
Our Luxgap Education AI Classifier is the AI agent that scans your edtech ecosystem (Moodle, Microsoft Teams Education, Google Workspace for Education, IRIS, Untis, proctoring platforms like Proctorio or Respondus) and automatically classifies each tool against Annex III of the AI Act. It turns a vague conversation with your DPO into an opposable map of high-risk systems deployed in your institution, with the exact list of remaining obligations.
- Automatically detects every AI tool used in your pedagogical processes via Azure AD or Google Identity SSO logs, with no on-site deployment.
- Classifies each system under Annex III point 3 (education) and indicates deployer or provider status under Article 25.
- Generates the Fundamental Rights Impact Assessment (FRIA, Article 27) pre-filled with the discrimination patterns targeted by Recital 56 (gender, age, disability, origin, orientation).
- Audits the bias of grading and proctoring models on representative datasets and produces an algorithmic fairness report.
- Maps effective human oversight (who validates, when, with what contestation margin) and alerts on fully automated loops that are prohibited.
- Produces a timestamped compliance file opposable to the EU AI Office and the CNPD, ready for audit or incident notification.
Available as part of a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real ecosystem, with a free 48h white audit to identify your high-risk systems before any commitment.