AI in Education
Educational institutions are deploying AI for admissions screening, student assessment, adaptive learning platforms, academic integrity monitoring, and administrative automation. These systems process sensitive data about minors, make high-stakes determinations about students' educational futures, and operate in an environment with strong data protection obligations under the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and the EU AI Act. Several AI applications in education are classified as high-risk under EU law, triggering conformity assessment and transparency requirements.
Key board-level questions
- 1.Do our AI-assisted admissions and assessment tools comply with anti-discrimination law and EU AI Act high-risk obligations?
- 2.Are we handling student data — including data about minors — in compliance with FERPA, COPPA, and applicable data protection law?
- 3.How do we ensure meaningful human oversight over AI systems that affect students' academic records or institutional standing?
- 4.Have we audited AI tools for bias that could disadvantage students based on demographic characteristics?
Regulatory frameworks
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
Colorado AI Act (SB 24-205), repealed
Colorado's SB 24-205, signed in May 2024, would have regulated developers and deployers of high-risk AI. It never took effect: its start date slipped from February 2026 to June 2026. In May 2026 Colorado repealed it and replaced it with SB 26-189, a narrower automated decision-making law effective 1 January 2027.
NIST AI Risk Management Framework (AI RMF 1.0) and Playbook
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.
ISO/IEC 42001:2023 - Artificial Intelligence Management System
ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.
