
www.ijcrsee.com
142
Dimić, G. et al. (2026). Education in the Age of AI: Adaptive Systems, Assessment, and Responsible Governance, International
Journal of Cognitive Research in Science, Engineering and Education (IJCRSEE), 14(1), 135-144.
set clear escalation protocols for edge cases, and publish intelligible grading rationales to preserve due
process for students (European Commission, 2025), (European Parliament, 2025).
Because risk classification is the linchpin on which obligations hang, education policymakers can
profitably integrate the OECD Framework for the Classification of AI Systems into their institutional risk
triage: mapping an AI system along the framework’s dimensions—People & Planet, Economic Context,
Data & Input, AI Model, Task & Output—helps expose where a given adaptive tutor or proctoring tool
implicates fundamental rights (e.g., equality in access), what data flows create privacy and representa-
tiveness risks, which model characteristics stress explainability, and how task-output couplings might en-
able or foreclose pedagogically sound override mechanisms; the OECD framework’s lifecycle orientation
(planning/design; data collection; model building/validation; deployment and monitoring) dovetails with
the Act’s demands for pre-market conformity assessment and post-market vigilance, offering a shared
vocabulary by which school systems, vendors, and regulators can align on evidence of safety and ac-
countability (OECD, 2022).
In domains where generative AI becomes a co-author of learning artefacts (lesson plans, forma-
tive feedback, worked examples), UNESCO’s global Guidance for Generative AI in Education and Re-
search supplies a concrete programmatic complement to the Act’s legal minimalism: beyond compliance,
UNESCO calls for age-appropriate guardrails, teacher-led validation workflows, and explicit curricular
integration of AI literacy to sustain a human-centered, rights-preserving adoption; taken together, the
UNESCO guidance and the AI Act suggest that the legitimate pedagogical uses of GPAI are those that
preserve human agency, embed privacy-by-design, and make the limits of model knowledge visible to
learners (Miao and Holmes, 2023).
Notably, the AI Act’s emphasis on robustness, cybersecurity, and accuracy is not decorative: the
ENISA Threat Landscape underscores that ransomware, DDoS, phishing, and related attacks remain
persistent and adaptive, while AI-enabled threats (e.g., automated phishing, synthetic-voice fraud, data
exfiltration targeting model pipelines) complicate institutional risk profiles; in education settings—where
networks carry sensitive learner data and assessment systems may present tempting extortion targets—
the Act’s requirements for logging, incident reporting, and resilience should translate into concrete pro-
curement clauses (e.g., secure model-update channels, adversarial-robustness testing, rate-limiting and
anomaly detection) and operational controls (e.g., separation of duties, recovery plans, red-team exer-
cises) commensurate with the sector’s exposure (European Commission, 2025), (ENISA, 2024).
On governance, the Act’s distributed architecture—European AI Office, national market-surveil-
lance authorities, AI Board and advisory bodies—creates escalation and coordination pathways likely to
affect education in three ways: first, by generating codes of practice and interpretive guidance that lower
transaction costs for small ministries and school networks; second, by standardizing registries and docu-
mentation templates that enable comparability of high-risk deployments (e.g., exam-scoring engines); and
third, by anchoring enforcement in administrative routines that encourage continuous improvement (e.g.,
corrective action plans, proportional penalties) rather than one-off punitive gestures (European Commis-
sion, 2025), (European Parliament, 2025). Strategically, aligning adaptive learning with the Act means
institutionalizing a pedagogy-first compliance culture:
• needs analysis and theory-of-change before tool selection;
• explainability criteria tied to specific learner decisions (placement, feedback, progression);
• calibration studies that check algorithmic recommendations against expert judgments across student
subgroups;
• a duty to furnish students with recourse, including the right to a human review of impactful automated
decisions (European Commission, 2025), (OECD, 2022).
For assessment, the combination of transparency duties and high-risk obligations invites renewed
attention to validity and fairness: if a proctoring classifier generates false positives differentially by lighting,
skin tone, or disability status, then both the Act’s dataset-quality requirement and equity commitments in
education policy are implicated, compelling iterative retraining, alternative accommodations, or—where
irreparable—retirement of the system; conversely, where automated scoring aids formative feedback
without deciding high-stakes outcomes, limited-risk transparency may suffice, provided institutions clearly
signal to learners when AI is involved and how its suggestions are moderated by instructors (European
Commission, 2025), (European Parliament, 2025), (Miao and Holmes, 2023).