In a little over five weeks, on 2 August 2026, a new phase of the EU AI Act kicks in across Europe. From that date, extra rules apply to anyone using AI to grade learners, decide who gets admitted to a course, or watch over them during a test. That might sound like a problem for big universities and corporate HR departments, but the law does not distinguish between a solo trainer with twenty students and an institute with two thousand. If you use AI in any of the ways described below, the rules apply to you too.
What changes on 2 August 2026
The AI Act rolls out in phases. The first set of bans took effect back in February 2025, a second wave hit providers of general-purpose AI models in August 2025. On 2 August 2026 comes the third and heaviest wave: obligations for so-called high-risk AI systems become enforceable. Education and vocational training are explicitly named as one of the sectors this covers. (1)(4)
The four education scenarios the law specifically names
The Act names four concrete uses of AI in education and training that are automatically treated as high-risk. AI used to decide access or admission to a course or institution. AI that evaluates learning outcomes, including automatically generated grades or decisions that feed into a certificate. AI that determines the appropriate level of education for someone. And AI that flags prohibited behaviour during a test, such as proctoring software that watches through a webcam and marks anomalies. (1)
If you recognise one of these four in your own course or platform, you almost certainly fall under the rules.
What this does not cover
Not every AI feature in your course counts as high-risk. A chatbot that answers learners' questions about the material, a tool that drafts a course outline from a document, or AI that generates practice questions for self-study that never affect a certificate: those stay firmly in the low-risk category. The line is about consequences. Does the AI's decision affect someone's access, grade, or certificate? Then it counts. Is it purely supportive or formative, with no official outcome attached? Then it doesn't.
Provider or deployer: the distinction that matters for you
The Act draws a line between providers, the parties who build and place an AI system on the market, and deployers, the parties who put that system to use. As an independent trainer or training institute, you are in practice almost always a deployer: you buy or use a proctoring tool, an AI grading module, or an adaptive learning engine built by someone else.
The heavy obligations, things like conformity assessments, technical documentation, and registration in the EU database, sit with the provider, meaning the software vendor. But as a deployer you carry real obligations of your own. You must use the system exactly as the vendor instructs, assign someone who actually exercises human oversight, keep automatically generated logs for at least six months, and tell learners when an AI system has a say in a decision about them. If you spot a risk, you must report it to the vendor within fifteen days and suspend use if needed. (4)
Five things you can sort out this summer
You do not need a lawyer on retainer to start today.
First, list every AI tool in your course that touches grading, admission, level placement, or proctoring. Plenty of training providers do not actually know which parts of their platform run on AI, and that is exactly the problem: research shows more than half of organisations have no systematic inventory of the AI systems they use. (4)
For each tool, decide whether the outcome has consequences. An automated grade that ends up on a certificate counts. A nudge suggesting a learner revisit a chapter does not.
Ask your vendor for the instructions for use and, if one exists, the declaration of conformity. A serious proctoring or grading vendor has already thought this through and should be able to share it without a fuss.
Make sure an actual person reviews every automated grade or flagged incident before it becomes official. Never let a proctoring tool fail someone on its own.
Be upfront with your learners. One line in your course information, something like "this assessment is partly evaluated by an AI system, a trainer reviews every result", heads off surprises and builds trust.
The complication: a delay that might be coming
Here is where it gets messier. In November 2025, the European Commission proposed, as part of its Digital Omnibus package, pushing the high-risk deadline from 2 August 2026 to 2 December 2027, largely because the technical standards meant to support compliance arrived late. (4)(5)
That proposal still needs approval from the European Parliament and the Council. Until it is formally adopted, 2 August 2026 remains the legally binding date. Major law firms are advising clients not to bet on the delay and to keep preparing as planned. (4) Wait it out and the postponement fails to materialise, and you could find yourself behind on compliance the moment August arrives.
The short version
If you only use AI to create content or support learners, very little changes for you. If you use AI to grade, admit, or monitor learners during a test, you become a deployer of a high-risk system from 2 August 2026, with a small but real set of obligations. Spending an hour mapping which tools you use, and making sure a human checks every decision that actually counts, is by far the cheapest insurance you can buy this summer.
Sources
- Future of Life Institute, "Annex III: High-Risk AI Systems Referred to in Article 6(2)", EU Artificial Intelligence Act Explorer, 2026. https://artificialintelligenceact.eu/annex/3/
- AI Act Service Desk, European Commission, "Implementation Timeline". https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
- OneTrust, "EU Digital Omnibus Proposes Delay of AI Compliance Deadlines", November 2025. https://www.onetrust.com/blog/eu-digital-omnibus-proposes-delay-of-ai-compliance-deadlines/
- Cloud Security Alliance, "EU AI Act High-Risk Deadline: Enterprise Readiness Gap", March 2026. https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-compliance-deadline-20/
- Orrick, "The EU AI Act: 6 Steps to Take Before 2 August 2026", November 2025. https://www.orrick.com/en/Insights/2025/11/The-EU-AI-Act-6-Steps-to-Take-Before-2-August-2026