It is one of the questions I hear most often when working with educational institutions.
An AI system flags an original assignment as plagiarism. A guidance tool makes an inappropriate recommendation. An AI assistant gives incorrect information to a family. Then comes the same question, usually asked with genuine concern: If AI gets it wrong, who is responsible?
Many schools are asking this question. Very few have a documented answer before they actually need one. The short answer is that, in most cases, the educational institution acts as the deployer of the AI system under the AI Act and is therefore responsible for complying with the obligations assigned to deployers.
The complete answer requires understanding how responsibilities are distributed across the AI value chain—between providers, deployers and other actors—and why the absence of documented governance makes it much harder for a school to demonstrate that it acted with due diligence.
The Concept of the Deployer Under the AI Act
Regulation (EU) 2024/1689 distinguishes between providers, who develop AI systems, and deployers, who use those systems in a professional context.
When a school uses an AI system as part of its educational activities, it will generally act as the deployer and must comply with the obligations assigned to that role.
Article 26 requires deployers to use AI systems in accordance with the provider’s instructions, ensure that staff possess an appropriate level of AI literacy, and implement effective human oversight where required.
Failure to meet these obligations may have regulatory consequences and make it significantly harder for the institution to demonstrate that it acted with the required level of care.
The Applicable Timeline
The AI Act entered into force in August 2024.
The obligations for deployers of high-risk AI systems under Article 26, originally scheduled to apply from August 2026, were postponed until 2 December 2027 following the Digital Omnibus package, approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026.
Article 4, which requires organisations to ensure an appropriate level of AI literacy among staff, has applied since 2 February 2025 and was not affected by the Omnibus amendments.
In practice, organisations are increasingly expected to provide AI literacy that is tailored to the specific context in which AI is being used.
Three Common Scenarios in Educational Institutions
1. The AI System Makes Decisions and Nobody Realises It
This is by far the most common situation. A digital platform introduces AI features without the school ever consciously evaluating them. Teachers simply use the functionality because it is already included in the platform. No one can explain how decisions are produced. If something goes wrong, the school has no documentation demonstrating that it assessed the risks before deploying the system.
2. Someone Approved the Tool, but There Was No Governance Process
This represents a step forward. Someone authorised the adoption of the tool. However, if there is no documented approval process based on technical, legal and ethical criteria, that informal approval offers very little protection. An email from a provider stating that the system complies with the GDPR is not evidence of organisational due diligence.
3. The System Fails, but the School Has a Protocol
This is where every educational institution should aim to be. The school has an AI policy that defines how AI tools are approved, who is responsible for each system, how incidents are recorded, and who communicates with the competent authorities where necessary.
When something goes wrong, there is a documented process to follow and evidence demonstrating that the institution acted responsibly. The objective is not to prevent AI from ever failing. AI systems will fail. The objective is to have decided in advance how the organisation will respond.
Human Oversight: The Most Frequently Overlooked Requirement
The AI Act requires human oversight for high-risk AI systems.
Many educational institutions already use AI in situations that may fall within this category, including systems influencing access to education, student assessment, academic guidance or the identification of special educational needs.
Human oversight does not simply mean that a teacher is present while the AI operates. It means the institution has documented criteria explaining how AI outputs are reviewed, challenged and, where appropriate, overridden. Without those criteria, human oversight may exist in theory, but not in practice—and certainly not during an inspection.
A Requirement Many Schools Will Overlook: Transparency from August 2026
One important obligation comes into force on 2 August 2026 and was not postponed by the Omnibus package.
Unlike the obligations relating to high-risk AI systems, the transparency requirements under Article 50 remain unchanged. The European Commission’s Guidelines, published on 18 July 2026, confirm that the obligation to inform individuals when they are interacting with an AI system still applies from August 2026.
For educational institutions, compliance is relatively straightforward. If a school uses a chatbot to answer questions from students or families, a conversational assistant on its website, or any AI system that interacts directly with individuals, users must be clearly informed from the beginning that they are communicating with AI.
It is not sufficient to hide this information in a privacy policy. The notice must appear at the start of the interaction.
It is equally important to avoid a common misunderstanding. Not every piece of content created with the assistance of AI must be labelled. The obligation to disclose AI-generated text applies only to specific categories of content published to inform the public on matters of public interest—and even then, not where the content has undergone meaningful human review under editorial responsibility. A school newsletter, circular, poster or communication drafted with AI and reviewed by a member of staff would not normally fall within that obligation.
The transparency obligation that applies generally is much simpler: If an AI system is interacting directly with a person, that person must know.
AESIA and Possible Enforcement
Since August 2025, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has held supervisory and enforcement powers under the AI Act.
It is important to keep this in perspective. The highest fines under the AI Act are primarily aimed at providers of AI systems, not schools operating a chatbot on their website.
Educational institutions are mainly subject to the obligations applicable to deployers. Where serious non-compliance occurs, formal administrative proceedings may follow, particularly where public educational authorities are involved.
At present, there is no established body of case law and no systematic inspection programme for educational institutions. However, Article 50 begins to apply from 2 August 2026. For schools, the immediate risk is less about large financial penalties and more about exposure following an incident—particularly where minors are involved.
The legal framework is already in place. That alone is reason enough to establish clear governance before an incident occurs.
What Should Your School Do If It Still Has No AI Protocol?
The first step is to create an accurate inventory. Identify which AI systems are currently being used, who approved them, and whether they influence decisions affecting students. It does not have to be perfect. It simply has to exist.
The second step is to establish an AI use policy. Not a twenty-page document. A clear policy approved by school leadership that defines what may be used, who authorises AI systems, how incidents are recorded, who communicates with families and educational authorities, and how the school complies with transparency obligations when AI interacts with individuals.
The third step is staff training. The AI Act is explicit. People operating AI systems must possess an appropriate level of AI literacy. This has been a legal requirement since 2 February 2025. A workshop on prompts or ChatGPT alone does not fulfil that obligation.
Frequently Asked Questions
Who is responsible when AI fails in a school?
In most cases, the school acts as the deployer of the AI system and must comply with the obligations assigned to deployers under the AI Act. This does not exclude responsibilities that may also fall on the provider or other economic operators.
Can a teacher be held responsible for an AI-related error?
Individual responsibility depends on employment duties, organisational procedures and the specific circumstances of the incident. Clear governance and documented protocols help define responsibilities and reduce legal uncertainty.
What documentation should a school have if an AI incident occurs?
At a minimum, the institution should have:
-
A documented record of the incident.
-
The AI policy that was in force at the time.
-
Evidence of the approval process followed before the system was deployed.
Depending on the type of AI system involved and the applicable legal obligations, providers and competent authorities may also become involved. Without prior documentation, it is considerably more difficult for the institution to demonstrate that it acted with due diligence.