EU AI Act from 2 August 2026: What Universities Need to Know

From 2 August 2026, further key provisions of the EU AI Act apply. Does this affect us as a university? Do we now need to have our AI tools reviewed? What happens if we do nothing? The short answer: it very much depends on what you do with AI. The longer answer is here.

Lecturer and student looking at digital AI icons with EU map in the background – EU AI Act and universities
Illustration: AI-generated image (Dr. Maex / TraiNex) – EU AI Act and universities in the digital age

What Applies from 2 August 2026?

Anyone who interacts with an AI system must in principle be able to recognise that they are dealing with AI. A chatbot for students or a digital assistant should therefore identify itself clearly as an AI system at the latest at the beginning of the conversation – unless this is already obvious.

For universities, this means above all:

  • Clearly label AI chatbots,
  • Do not present AI-generated media as authentic recordings,
  • Define responsibilities for AI systems in use,
  • Document AI deployment in a traceable manner.

AI Literacy Remains Mandatory

Since February 2025, institutions have been required to offer measures to promote the AI competence of their staff. From August 2026, compliance with this obligation can be more strictly monitored.

A specific certificate is not required. However, the following are advisable:

  • Internal rules for ChatGPT and other AI tools,
  • Training on data protection, hallucinations and confidential data,
  • Special briefings for sensitive areas such as the examinations office, admissions and HR,
  • Documentation of the measures offered.
  • TraiNex supports you with the e-tutorial “AI at the University in 10 Chapters”. You can store this directly in TraiNex for teaching staff and administrative employees, have them complete it and automatically document the evidence. Contact us.

Are Students Affected?

When using generally available AI tools privately, students are normally neither providers nor operators within the meaning of the AI Act. They are, however, protected as data subjects. If a university uses AI for admissions, examination assessment or examination monitoring, obligations arise for the university.

What Applies to Teaching Staff?

Teaching staff are likewise neither providers nor operators within the meaning of the AI Act. However, they must comply with the university’s requirements, data protection law, copyright law and examination regulations. In order to assess the use of AI in these areas, participation in further training is necessary.

How TraiNex Classifies AI Functions

At TraiNex, we assess every AI function based on its specific purpose and impact.

AI-supported search functions, text suggestions, summaries and general chatbots assist users without themselves making decisions about admissions, grades or sanctions. These risk classes are largely permitted without issue.

The picture may look different when an AI result is used directly for consequential decisions. An automatic evaluation of attendance data, for example, is to be assessed differently if examination eligibility is derived from it without further review.

That is why we specifically examine:

  • Purpose and data used,
  • Impact on students and staff,
  • Degree of automation,
  • Human control options,
  • Logging and traceability,
  • Data protection and IT security.

What Applies to AI Agents?

AI agents do not form a separate risk category in the AI Act. Here too, what matters is which tasks they take on.

An agent that prepares documents, transfers information or proposes changes for approval is to be assessed differently from an agent that independently rejects admissions, changes grades or sanctions individuals. The latter would be too autonomous and too risky under the AI Act. To achieve an acceptable and permitted risk class, at minimum human approval would be mandatory.

At TraiNex AI agents, we therefore rely on:

  • clearly defined areas of responsibility,
  • graduated access rights,
  • complete logging,
  • human approvals for consequential actions,
  • the ability to stop or reverse actions,
  • restriction of AI autonomy.
    See waas.campus-management-system.de

What Universities Should Do Now

Universities and educational institutions should now:

  1. Record the AI systems they use,
  2. Document their specific purposes of use,
  3. Correctly label AI chatbots and generated content,
  4. Offer staff appropriate training and guidelines,
  5. Particularly scrutinise applications that influence admissions, examinations or HR decisions.

Conclusion

From 2 August 2026, transparency, labelling and documented accountability will become more important for universities above all. Next milestone: the comprehensive high-risk requirements for the education sector apply from 2 December 2027.