Classification first. Six categories of tool a university typically has under contract, scored against Annex III point 3 of Regulation (EU) 2024/1689 and the Article 6(3) derogation. This is a classification map to take to your legal team and your data protection officer, not legal advice.
| Tool category | Annex III point 3 limb engaged | Article 6(3) derogation plausible? | Working classification |
|---|---|---|---|
| Admissions scoring or applicant ranking | (a) determining access or admission | No — it influences the outcome, and profiling triggers the override | High risk |
| Placement or level-setting (e.g. language streaming) | (c) assessing the appropriate level of education | Rarely | High risk |
| Online proctoring / behaviour monitoring in exams | (d) monitoring and detecting prohibited behaviour during tests | No | High risk |
| Automated or AI-assisted grading that produces or materially influences a mark | (b) evaluating learning outcomes | Only if genuinely a narrow procedural task or improving a completed human activity | High risk in most deployments |
| AI-text detection on submitted coursework | (d) is drafted “during tests”; (b) comes into view if the output drives an outcome | Arguable both ways | Contested — see below |
| Writing support with no assessment role | None engaged | Not needed | Not high risk |
The reason this is now a procurement question rather than a horizon-scanning one is a single sentence in Article 113: “It shall apply from 2 August 2026.” The Annex III obligations are in force.
What Annex III point 3 actually says
It is short, and reading it is faster than reading anyone’s summary of it. The four education limbs are AI systems intended to be used:
- “to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels”;
- “to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels”;
- “for the purpose of assessing the appropriate level of education that an individual will receive or will be able to access”; and
- “for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions at all levels”.
Two features of that drafting decide most classifications. The test is the system’s intended use, not the vendor’s product category — so the same underlying model is high risk in one deployment and not in another. And limb (b) is broad: “evaluate learning outcomes” reaches formative assessment used to steer learning, not only summative marking.
The derogation, and why it is narrower than it looks
Article 6(3) is the provision every vendor will point at. It says an Annex III system “shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making”, and then lists four conditions, any one of which can apply:
- (a) the system performs “a narrow procedural task”;
- (b) it is “intended to improve the result of a previously completed human activity”;
- (c) it detects decision-making patterns or deviations and “is not meant to replace or influence the previously completed human assessment, without proper human review”; or
- (d) it performs “a preparatory task to an assessment” relevant to an Annex III use case.
Then the sentence that closes most of the gap: “Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.”
Two practical consequences. Condition (b) is the one that fits a genuine writing-support deployment, because improving a draft the student has already written is improving the result of a previously completed human activity. And under Article 6(4) it is the provider who must document a not-high-risk assessment before the system is placed on the market or put into service, and supply it to national competent authorities on request. That is a procurement question with a documentary answer: ask for the assessment.

The contested one: is an AI-text detector a high-risk system?
This is the row that will generate the most argument in your committee, so here is the honest reading rather than a confident one.
Limb (d) is drafted around behaviour “during tests”. A detector run on an essay submitted through the VLE a week after it was written is not monitoring a student during a test, and on the plain words limb (d) is not engaged. That is a real argument and it is not a weak one.
Limb (b) is the harder question. If a detector’s output feeds an academic judgment about a piece of assessed work — and in practice that is exactly what it is bought to do — then the system is being used in the evaluation of learning outcomes, and Article 6(3)’s own opening words are about whether it “materially influences the outcome of decision making”. A tool used purely as a triage flag, with the actual judgment made by a human on independent evidence, has a real derogation case under condition (c) or (d). A tool whose score in practice determines whether a case is brought does not.
The institutional consequence is that your process, not the vendor’s classification, decides your exposure. That is an uncomfortable finding, and it is the same conclusion reached from an evidential direction in whether AI detection is reliable enough to base a case on, and from a definitional one in the difference between plagiarism detection and AI detection.
What a high-risk classification actually triggers for you
You are the deployer, not the provider, and the deployer duties in Article 26 are operational rather than technical. The ones that bite a university:
- Use it as instructed, with appropriate technical and organisational measures (26(1)).
- Assign human oversight “to natural persons who have the necessary competence, training and authority, as well as the necessary support” (26(2)). Naming an overworked module leader with no authority to overturn an output does not meet this.
- Control the input data where you control it, ensuring it is “relevant and sufficiently representative in view of the intended purpose” (26(4)).
- Monitor, and suspend. Where you have reason to consider that use in accordance with the instructions may present a risk, you must inform the provider and the market surveillance authority “without undue delay” and suspend the use of that system (26(5)).
- Keep the automatically generated logs for at least six months where they are under your control (26(6)).
- Tell staff first if it is deployed at the workplace: employers must inform workers’ representatives and affected workers before putting it into service (26(7)).
- Register, and refuse to use an unregistered system. Public-authority deployers must comply with the Article 49 registration obligations, and where the system is not in the EU database “they shall not use that system and shall inform the provider or the distributor” (26(8)).
- Tell the people affected. Deployers of Annex III systems that make or assist decisions about natural persons “shall inform the natural persons that they are subject to the use of the high-risk AI system” (26(11)).
And the one most likely to be missed. Article 27(1) requires a fundamental rights impact assessment before deploying an Annex III high-risk system, and it applies to “deployers that are bodies governed by public law, or are private entities providing public services” — which is most publicly funded universities. It has six prescribed contents, including the categories of persons affected, the specific risks of harm, the human oversight measures and the complaint mechanism. Article 27(3) then requires you to notify the market surveillance authority of the result. Article 27(4) allows the parts already covered by a GDPR Article 35 assessment to be relied on, which is the strongest argument for running the two together rather than sequentially — see how to run a data protection review before deploying an AI writing tool.

The recommendation
Separate the contracts. The single most useful procurement decision available here is to keep writing support and assessment tooling in different agreements with different scopes of intended use. A writing-support tool with no assessment role sits outside Annex III entirely; bundle it into a platform whose scope of use includes grading or integrity screening and you have dragged a low-obligation deployment into a high-obligation one for no functional gain. Scoring vendors on what they do with the text, rather than on feature lists, is the same discipline applied in the ranked comparison of AI writing platforms for universities.
For a different institutional profile: if you are outside the EU and not offering services into it, none of the above applies to you as law — but Annex III point 3 is still the best-drafted taxonomy of educational AI risk currently in existence, and using it as your internal classification scheme costs nothing and travels well.
Three things then belong on the register for every deployed system: the intended use as written in the contract, the classification with the reasoning, and the named human overseer with the authority to overturn an output. The wider component set is in what a university AI policy should include, and the Article 4 literacy duty that applies regardless of classification is covered in how to build an AI literacy curriculum. The staff-facing side of the same question — who may put student work into which tool — is in can our staff put student work into an AI tool.
If you would like your current tool estate mapped against Annex III with the reasoning written out for a committee, request an institutional evaluation and we will go through it with your procurement and data protection leads.
Frequently asked questions
Which AI tools are high risk under the EU AI Act in a university?
Those whose intended use falls in Annex III point 3: admissions and access decisions, evaluating learning outcomes, assessing the appropriate level of education, and monitoring for prohibited behaviour during tests. Writing support with no assessment role is not among them.
When did this start applying?
Article 113 states that the Regulation applies from 2 August 2026, with Chapters I and II from 2 February 2025 and Article 6(1) from 2 August 2027.
Is an AI writing assistant a high-risk system?
Not on its own. It engages no Annex III limb where it has no assessment role, and improving a draft the student has already written also fits the Article 6(3)(b) condition. What changes the answer is the scope of intended use written into your contract.
Is an AI detector high risk?
Contested. Limb (d) is drafted around behaviour during tests, which a post-submission scan is not. Limb (b) becomes relevant if the output materially influences an assessment decision, so your process determines the answer more than the product does.
Does the Article 6(3) derogation apply to us or to the vendor?
The documentation duty sits with the provider: Article 6(4) requires a provider who considers an Annex III system not to be high-risk to document that assessment before the system is placed on the market or put into service, and to supply it to competent authorities on request. Ask for it in procurement.
What is the profiling override?
Article 6(3) states that notwithstanding the derogation conditions, an Annex III system is always high risk where it performs profiling of natural persons. It removes the derogation from most scoring and ranking tools.
Do we need a fundamental rights impact assessment?
If you are a body governed by public law or a private entity providing public services and you deploy an Annex III high-risk system, yes, under Article 27(1), before first use, with the six prescribed contents and notification of the result to the market surveillance authority.
Can our GDPR assessment cover it?
Partly. Article 27(4) provides that where obligations are already met through a data protection impact assessment under Article 35 GDPR, the fundamental rights assessment complements it rather than duplicating it. Running them together is materially cheaper than running them in sequence.
How long must we keep the logs?
At least six months for logs automatically generated by the high-risk system and under your control, unless other Union or national law — in particular data protection law — provides otherwise (Article 26(6)).
Are there official examples of what is and is not high risk?
Article 6(5) required the Commission, after consulting the Board, to provide guidelines on the practical implementation of Article 6 together with a comprehensive list of practical use-case examples no later than 2 February 2026. Check for the current text before finalising a classification, and record which version you relied on.
Does data residency change the classification?
No. Classification follows intended use, not where the processing happens. Residency is a separate procurement criterion and does not move a system into or out of Annex III.
What should we do first?
Build the register. List every deployed AI system, write the intended use as it appears in the contract, classify it with the reasoning, and name the human overseer. Most institutions discover at that point that they cannot produce the list, which is itself the finding.
