regulacyjna · 5 min czytania ·

GDPR and AI Act at a University: How to Implement AI Lawfully

GDPR and the AI Act at a university: when AI in education is a high-risk system, how to label AI-generated content, and how to keep data in the EU. Practical compliance guide 2026.

Implementing artificial intelligence at a university in a lawful manner rests on four pillars: data processed exclusively within the European Union, clear labelling of AI-generated content, role-based access control, and a full event log. These requirements are not an afterthought. They determine whether a project is fit to run on student data at all.

This article clarifies what must be in place — under GDPR and the EU AI Act — before AI touches student affairs and teaching.

Disclaimer: the following is a compliance framework, not individual legal advice. Final assessment depends on the specific application and should go through the institution’s Data Protection Officer and legal department.

Why the Stakes Are So High

A university processes sensitive data at scale: students, applicants, doctoral researchers, staff, study records, and sometimes health data. Every AI deployment touching these datasets operates under the full GDPR regime; it is also now covered by the EU AI Act. The consequences of getting it wrong are not abstract. Across the country, CERT Poland recorded a record 260,783 incidents in 2025; universities have been among the targets of attacks that ended in student data leaks. Compliance and security here are one conversation, not two.

GDPR: Four Things You Must Be Able to Demonstrate

GDPR does not require giving up AI. It requires that processing can be demonstrated and controlled. In deployment practice, this means specifics.

  • EU data localisation. Personal data stored and processed exclusively in the EU simplifies the issues of transfers and supervision.
  • Principle of minimal access. Roles and permissions limit data access to those who genuinely need it.
  • Accountability. A full event log — who did what with data, and when — allows compliance to be demonstrated to a supervisory authority.
  • Data subject rights. The right of access and erasure must be exercisable in practice, not merely declared.

Meeting these requirements is made harder by a fragmented IT architecture. When data lives across several separate systems and spreadsheets, accountability is also fragmented — and demonstrating compliance becomes laborious.

AI Act: When Education Becomes “High Risk”

Here lies a nuance that a decision-maker must understand precisely. The EU AI Act calibrates obligations by risk level, and education was placed directly on the high-risk list in Annex III. This refers to systems that decide on university admissions, assess learning outcomes, assign an educational level, or monitor examinations. Such applications attract comprehensive requirements: data governance, technical documentation, conformity assessment, logs, human oversight, pre-deployment testing.

The key word is “decide.” A system that merely supports a human — suggesting a resolution in a student matter, proposing a task variant, helping draft feedback — but leaves the final decision to a staff member or lecturer typically does not fall into the high-risk category. The boundary therefore runs not at the technology itself, but at who makes the decision. Designing with a human in the loop is therefore simultaneously best practice and legal protection.

A second issue is also urgent — transparency: materials and responses produced with AI support should be clearly labelled. The transparency obligations of Art. 50 AI Act are due to apply from August 2026, though the calendar is moving — the Digital Omnibus package and the Polish implementing legislation may shift some deadlines for high-risk systems (a shift to as late as December 2027 is being discussed). Regardless of dates, the AI Literacy obligation has been in force since February 2025, and it is advisable to conduct a conscious risk classification at the deployment stage rather than infer it after the fact.

Accessibility as Part of Compliance

On top of GDPR and the AI Act, there is a third, often overlooked regime: digital accessibility (WCAG), mandatory for public universities. An audit of 309 universities showed that half of public university websites have serious accessibility errors. When deploying a new platform, an accessible interface should be treated as a default requirement across the entire solution — not a separate project to be deferred.

Built-In Compliance vs Bolt-On Compliance

The difference determines costs and risk. Built-in compliance means that data is in the EU from the outset, AI content carries a label at the source, access is role-based, and every operation leaves a trace. Bolt-on compliance is patching — more expensive, slower, harder to demonstrate at an inspection. The same principle applies to operational security, which is the other side of the same coin; we discuss it in the article on university cybersecurity.

How We Address This in MenToR

The MenToR platform was built around these requirements. Data processed exclusively in the Union. GDPR and AI Act built in, with clear labelling of AI-assisted content and an architecture in which the human makes the decision — which typically keeps the solution outside the high-risk system category (final classification depends on the specific application at the institution). Role-based access control and an event log are included, backups are regular and encrypted, and the whole is rounded off by an accessible interface (WCAG). Compliance is a shared layer for the Dean’s Office (DEAN) and teaching (LUMEN), not a separate deployment for each module.

Want to deploy AI in a way that passes inspection by your Data Protection Officer and legal department without improvisation? Let us start with a brief conversation about your data and processes.

Frequently Asked Questions

Is AI at a university a high-risk system under the AI Act? It depends on the application. Education is a high-risk area under Annex III when AI decides on student admissions, assesses learning outcomes, or monitors examinations. A system that merely supports a human and leaves the final decision to a staff member typically does not fall into this category.

When do AI Act provisions applicable to universities take effect? The AI Literacy obligation has been in force since February 2025. Transparency obligations under Art. 50 are due to apply from August 2026, but the timeline for high-risk systems may shift under the Digital Omnibus package and the Polish implementing legislation — potentially to December 2027.

Can student data be processed in AI outside the EU? The safest approach is to process it exclusively within the European Union, which simplifies the issues of transfers and supervision under GDPR. EU data localisation, access control, and an event log are the pillars a supervisory authority expects when AI is deployed.

How should AI-generated content be labelled? The AI Act requires transparency, so materials and responses produced with AI support should carry a clear label, readable by both student and lecturer. A good solution has this function built in at the source, not added manually afterwards.

NEWSLETTER // MONTHLY AI DIGEST FOR BUSINESS

What next // you read the article · time to talk?

Do these topics apply to your company?

30 minutes with the CEO. No sales rep. We will check together whether what you read applies to you.

Book a call with the CEO Check ROI calculator
Paleta poleceń
  • Strona główna/
  • Kontakt/kontakt/
  • Kalkulator ROI/kalkulator/
  • Audyt AiP/audyt-aip/
  • QDeployment/qdeployment/
  • QCare/qcare/
  • Pełen proces/proces/
  • MenToR — AI dla uczelni/mentor/
  • Engineering Lab/engineering-lab/
  • Venture Projects/projekty/
  • O nas/o-nas/
  • Case Studies/case-studies/
  • Baza wiedzy/baza-wiedzy/
  • Umów diagnostykę 30 min/kontakt/#booking
  • Oblicz ROI/kalkulator/
  • Kalkulator Dig.IT/kalkulator/
  • dlaNGO MVP demo/projekty/#dlango-mvp
  • LSO:ATOM/o-nas/#lso-atom
  • FAQ /projekty//projekty/#faq
CtrlK|Esc|Enter19