The regulatory landscape: when AI use crosses from policy into law
Last reviewed: 2026-07-18. Review cadence: every semester, and after any major instrument changes.
This note is orientation, not legal advice. It exists because one sentence in Learning with AI needs a current companion: AI used to make or support decisions about students can be regulated activity, not merely a matter of institutional policy. The book carries that durable principle. This note carries the moving parts: which instruments exist, what they tend to require, and where the lines sat on the date above. Laws in this area are being written, amended, delayed, and litigated as you read. Before your institution relies on anything here, confirm it with counsel.
Three questions that locate you
Most of the regulatory landscape sorts itself once a department answers three questions.
1. Do any of our tools make or support decisions about students? Admissions screening, automated or AI-assisted grading, placement, progression, proctoring. Decision-touching uses are where regulation concentrates. A chatbot that answers questions about parking is not the concern. A system that scores an essay, flags an exam, or ranks an applicant is.
2. Does any tool watch students? Exam monitoring, behavior detection, and anything that claims to read attention, stress, or emotion. Surveillance-shaped uses draw the strictest treatment, and one class of them is now flatly prohibited in a major jurisdiction.
3. Whose students, and whose data? Modern regulation reaches across borders. A university far from Brussels can be in scope of European law when it processes EU students’ data or deploys systems whose output is used there. A tool serving users in Korea picks up Korean duties. Inside the United States, the binding rules increasingly depend on which states your students, employees, and applicants are in.
The European Union: the most developed regime
The EU AI Act is the most complete AI statute in force anywhere, and it names education explicitly.
Already in force. Since February 2025, the Act prohibits AI that infers emotions in educational institutions, with a narrow exception for medical and safety purposes. If any proctoring or engagement tool in your stack claims to read stress, attention, or emotional state from a student’s face or behavior, that feature is not a risk to manage but a prohibited practice in the EU, and it deserves counsel review anywhere. The same date brought an AI-literacy duty: organizations deploying AI must ensure the staff operating it have sufficient understanding to use it responsibly. A department that runs the training plan in Learning with AI is already doing what this duty asks.
The high-risk list names education. The Act’s high-risk annex covers systems used for admissions, for evaluating learning outcomes, for assessing the level of education a person should receive, and for monitoring and detecting prohibited student behavior during tests. Ordinary AI proctoring is on that list. High-risk classification brings obligations that fall partly on the university as the deploying organization: documented human oversight by people with the competence and authority to override the system, logging, care with input data, telling affected people the system is in use, and, for public institutions, a fundamental-rights impact assessment before deployment.
Timing is in flux, which is the point of this note. The Act’s main application date is August 2,
- A pending amendment package, provisionally agreed in May 2026, would defer the high-risk deadline to December 2027. As of the review date above, that deferral had not been formally adopted. Do not plan around either date on the strength of a summary, including this one.
Reach. The Act applies to organizations outside the EU when their systems’ output is used inside it, and penalties scale with global revenue. A US institution with EU students, EU-facing online programs, or EU research partnerships should ask counsel where it stands rather than assume distance is protection.
The United States: no federal statute, fast-moving states
There is no comprehensive federal AI law. The federal layer is executive orders and procurement policy, and a push for federal preemption of state AI law was live at the review date. The binding obligations sit mostly in state law, and they are accumulating quickly: by early 2026, lawmakers in most states had introduced AI bills, and several broad frameworks had taken effect.
Colorado is the cautionary tale, and the reason this note tells you to call counsel. Its 2024 act, the broadest state framework, aimed at algorithmic discrimination by high-risk systems, was delayed from February to June 2026, then paused by a federal court, with replacement legislation moving on a different timeline. Any static summary of Colorado, including this one, is likely wrong by the time it is read.
Duties in force elsewhere. Texas bans a short list of AI uses and sets rules for state agencies. California requires frontier-model transparency and training-data disclosure from developers. Utah requires generative-AI disclosure in some interactions. Illinois regulates AI in employment decisions, and New York City requires bias audits for automated hiring tools; both reach universities in their role as employers, where AI touches hiring, screening, or promotion.
The stable floor. Student-privacy law, FERPA in the United States and its equivalents elsewhere, applies to AI tools the way it applies to any system handling student records. The book’s privacy and data-governance section covers that ground, and nothing in the newer AI statutes relaxes it.
The direction of travel elsewhere
Australia. The higher-education regulator, TEQSA, required every registered provider to submit an institutional action plan addressing generative AI’s risks to award integrity, and its guidance pushes institutions toward assessment redesign rather than detection. Australia treats institutional AI planning as a regulatory expectation, not a courtesy.
South Korea. The AI Basic Act and its enforcement decree took effect in January 2026. It requires advance notice to users when high-impact or generative AI is in use, labeling of generative outputs, and documented risk management, and it reaches foreign organizations serving Korean users. Enforcement began with a guidance-first grace period.
Different instruments, one direction: notice, human oversight, documentation, and accountability for decisions about people. Institutions that build those habits now are preparing for rules that do not yet exist as much as complying with the ones that do.
What a department does with this
Four moves cover most of it, and each maps to practice the framework already teaches.
Inventory the decision-touching tools. List every AI system that grades, screens, places, proctors, or monitors, whoever procured it. Regulation attaches to uses, and you cannot assess uses you have not listed. The approved-tool list your institution keeps for privacy reasons is the natural home.
Send the watchers to counsel first. Anything that monitors exams or claims to infer attention or emotion is the highest-priority review item in the stack, prohibited in one major jurisdiction and high-risk almost everywhere else that regulates.
Document the human in the loop. The framework’s standing posture, instructors own grading and integrity judgments and no automated score is treated as the sole or primary evidence, is the substance of what high-risk oversight duties require. Write down who reviews, what authority they have to override, and how. If a regulator ever asks, the answer should already be on paper.
Let the training plan do double duty. Faculty and staff AI literacy is now a legal duty in one jurisdiction and a plain expectation in others. The department that trains its people has satisfied the spirit of every version of this rule so far.
The departmental adoption kit in this folder sets up the vocabulary, syllabus practice, and review cycle these moves plug into.
Keeping this note honest
This note carries a review date because an undated summary of a moving field misleads more than it informs. If the date at the top is more than a semester old, treat everything here as a set of questions for counsel rather than a set of answers. Corrections and updates are welcome through the repository’s feedback channel.
Part of the companion repository for Learning with AI: A Framework for Students, Instructors, and Universities (James M. Hyman, SIAM Books). These materials are free to use and adapt with attribution. Nothing here is legal advice.