The EU AI Act is groundbreaking both in its scope and subject matter. This act, the first of its kind, is a comprehensive legal framework impacting hundreds of institutions globally from August 2026.
In a recent webinar we discussed what the EU AI Act means for institutions, and what responsible AI use looks like in reality. This blog gives you the headline takeaways, and you can catch the recording here.
This session was hosted by Fran Colombo, Customer Success Manager for EMEA, and brought together insights from Zach Pendleton, Instructure’s Chief Architect and Jody Sailor, Academic Strategy and Innovation Director.
1. The remit of the Act stretches beyond the EU
The webinar kicked off with some clarification around whom the EU AI Act applies to. The Act is not a blanket requirement that every education institution must comply with in the same way. In a similar vein, the Act’s purpose is not to ban AI or prevent innovation. Its obligations depend on how an institution uses AI, what role it plays, and the level of risk attached to the AI system. Put simply:
- EU-based institutions using AI in teaching, learning, assessment, admissions or student support should assume the Act is highly relevant and assess their tools carefully.
- Non-EU institutions may also be affected if they serve EU-based learners, use AI outputs in the EU, or process data connected to people in the EU.
- Under the Act, AI systems can still be used, but they require stronger safeguards, including transparency, human oversight, data governance and AI literacy.
2. You’re probably complying with most of the Act already
A central message from Jody was that the EU AI Act should not be seen as a new compliance problem. Many of its requirements reflect what good educators already do.
The Act expects AI-driven decisions to be explainable. In practice, this means people should know when AI has influenced an outcome and should be able to ask why. Jody connected this to long-standing educational practice: students learn best when they understand how they are being assessed, what criteria are being used and why they have received particular feedback.
3. There are four risk levels to know about
Fran explained that the EU AI Act groups AI systems into four risk levels: minimal, limited, high and unacceptable.
In education, AI can fall into the high-risk category when it moves beyond simple content delivery and starts to affect a learner’s educational path. High-risk examples discussed during the webinar included AI-enabled exam monitoring tools, adaptive learning systems that decide whether a student is ready to progress, admissions tools that score or rank applicants, and AI-generated feedback that directly influences grades without educator oversight.
The speakers were clear that “high risk” does not mean “do not use”. It means such systems must be used carefully, with transparency, governance and meaningful human oversight.
4. Some AI uses are prohibited
The webinar also addressed unacceptable-risk AI uses. Jody highlighted two examples that are particularly relevant to education: emotion recognition and social scoring.
Emotion recognition refers to AI that observes a student’s face or behaviour in order to infer how they are feeling. Social scoring refers to AI that builds a behavioural profile of a student over time and uses it to make broader judgements about them as a person. These uses were described as prohibited in educational settings under the Act.
5. Your input is more critical than ever
A recurring point was that the AI product experience should encourage users to review, challenge, edit, reject or approve AI outputs before those outputs affect learners.
Zach explained how this principle shapes Instructure’s approach to AI development. For example, AI-generated rubrics appear within the normal rubric-building workflow, where an educator can review and edit the criteria before using them. The AI does not replace the educator’s judgement; it speeds up a task while leaving the educator in control.
The same principle applies to higher-stakes use cases such as grading. Fran noted that AI systems used to evaluate learning outcomes, assess submissions or influence grades would fall into the high-risk category, which is why educator oversight is essential.
6. Transparency should be built into your AI products
Zach described Instructure’s use of AI “nutrition facts”: small model-card-style notices that explain key information about an AI feature. These include the model being used, what data is sent to it, how the data is used, expected results and possible risks.
This is intended to help educators make informed decisions about whether a feature is appropriate in a particular setting. It also reflects one of the Act’s core themes: people should know when AI is being used and understand what it is doing.
Zach also explained that Ignite AI features use consistent branding, including a purple-to-blue gradient and a sparkle icon, so users can recognise when AI is involved.
7. Data privacy and regionalisation are foundational
The discussion placed strong emphasis on data privacy and regional hosting. Zach said Instructure’s AI features are built on a foundation of data privacy and regionalisation, meaning that AI features follow the same expectations around hosting and data use as the rest of Canvas.
For EU customers, this means AI features are hosted in the EU alongside institutional data. The webinar also stated that institutional data remains the institution’s own and is not used to train external models.
8. AI literacy is both a requirement and an opportunity
Jody highlighted AI literacy as one of the most important obligations in the Act. Article 4 of the Act requires those deploying AI to have sufficient understanding to use it responsibly.
The speakers argued that beyond compliance, AI fluency will become part of the broader digital fluency learners need. For education institutions, this means helping people understand not only how to use AI tools, but how to use them responsibly and critically.
9. AI should support educators, not replace them
Zach repeatedly emphasised that AI should augment human work rather than replace it. The question guiding Instructure’s product thinking is not “what can AI do instead of a person?”, but “what would an educator do if they had more time?”
Discussion summaries were one example. In large or active classes, it may be difficult for an instructor to read every post in detail. AI-generated summaries can help educators identify common questions, areas of confusion or recurring themes, enabling them to respond more effectively.
Another example was the course-level accessibility checker. Jody explained that, unlike the accessibility checker within the rich content editor, this tool scans a whole course and identifies issues such as missing alternative text, table captions, descriptive links and colour contrast. Some fixes can be supported by AI, but the educator remains involved in reviewing and applying them.
10. Student-facing AI should encourage better learning habits
The webinar also covered student-facing AI study tools. Zach described AI products that can help students summarise content, generate personalised quizzes and create flashcards.
The important distinction was that these tools are designed to support learning behaviours, not replace student thinking. Zach noted the importance of preserving productive struggle in learning, rather than use AI to bypass the learning process.
11. Institutions need control over how AI is used
Control was another important takeaway. Zach explained that Ignite AI features are off by default and can be enabled and configured at account and course level. This means institutions can decide which features are appropriate, and instructors can have control within their own courses.
Fran also explained how Canvas LMS administrators can access Ignite AI during the free access period: by going into their Canvas instance, opening settings, selecting feature options, searching for Ignite and enabling the relevant tools. He also recommended testing in beta before enabling tools in a production environment.
12. Open AI platforms matter
Zach also discussed what Instructure means by an open AI platform. He referred to Canvas APIs, LTI 1.3 and model context protocol as ways to make Canvas extensible and accessible to other tools and partners.
The broader point was that institutions should not feel locked into one AI approach. An open platform allows customers and partners to build, connect and choose tools that fit their needs.
Zach also highlighted the importance of context. AI tools connected to a learning management system need safe and secure access to relevant course context, such as what is being taught and what students are working on, so that responses can be aligned with the instructor’s goals rather than generic model output.
In summary: Responsible AI is a shared journey
The webinar closed with reflections from Jody, Zach Pendleton and Fran on how Instructure will continue to approach the EU AI Act.
Jody said Instructure will continue to monitor the Act and other education policy developments around the world, while focusing on responsible, scalable and supportive AI practices for educators and students.
Zach described the EU AI Act as more than a set of compliance obligations. He framed it as an invitation to build a more human-centred future for AI in education.
Fran emphasised the customer experience perspective: institutions should know they are not navigating these regulations alone. Instructure’s message was that it is building its AI roadmap with these responsibilities in mind and wants to support institutions as they make decisions about AI adoption.
The discussion made one point especially clear: responsible AI in education goes beyond compliance. It is about building systems that support educators, protect learners and improve educational experiences without removing human judgement.
Related Content
nn_instcon2026.pngBlogs
1000141729.jpgBlogs
instructure_2022-may_cofi-372.jpgBlogs