Responsible AI Platform
Annex III point 3High-risk domain

AI in education and vocational training

For education institutions, EdTech providers and L&D teams using AI for admission, assessment, level assignment or student monitoring.

Annex III point 3 is broader than schools. The guidelines cover formal and non-formal education, vocational training, adult education and programmes that may provide certificates.

Scope according to the guidelines

The four routes are access/admission/assignment, evaluation of learning outcomes, assessment of education level and monitoring or detecting prohibited student behaviour.

Classification question

Does the AI influence a natural person’s learning path, assessment or access?

What to document

Intended purpose and context of use.
Why Article 6(2) and Annex III do or do not apply.
Whether the Article 6(3) filter may apply, and whether profiling blocks it.
Which provider and deployer obligations are triggered.

Education AI classification check

Check whether your EdTech, assessment or student monitoring falls under Annex III point 3.

Frequently asked questions

Short answers for classification, evidence and next steps under Annex III.

When should education be assessed under Annex III?

The four routes are access/admission/assignment, evaluation of learning outcomes, assessment of education level and monitoring or detecting prohibited student behaviour. The practical starting question is: Does the AI influence a natural person’s learning path, assessment or access?

Which use cases are included in Education and vocational training?

This domain page expands the main routes: Access, admission and assignment, Evaluation of learning outcomes, Assessing the appropriate level of education and Student monitoring and prohibited behaviour. For each system, check the intended purpose, the output and the impact on access, rights or safety.

What should be documented before obligations are determined?

Document the intended purpose, use context, relevant Annex III route, Article 6(3) assessment, any profiling, provider/deployer roles and the required safeguards.