The AI Act is now in force. Is your AI learning tool compliant?
On 2 August 2026, the European AI Act entered fully into force. Five weeks later, almost no publisher of LMS tools and AI assistants for education has published a clear position on it. This is surprising: the implications are real, immediate and not that difficult to understand without legal jargon.
This article is for learning leaders, Moodle administrators and IT directors already using, or preparing to integrate, an AI tool into their platform. Its purpose is simple: provide a practical reading of what the regulation changes for you, what to check with providers and why some sectors are more exposed than others.
What the AI Act is, and why education is affected
The European regulation on artificial intelligence (EU 2024/1689) takes a graduated, risk-based approach. It defines four levels: prohibited AI, high-risk AI, limited-risk AI and minimal-risk AI.
For most AI tools used in education - instructional assistants, conversational tutors and activity generators - the applicable level is limited risk. This entails transparency obligations: learners must know they are interacting with an AI system. No CE marking or heavy audit, but clear, traceable information.
By contrast, an AI system that automatically evaluates learner performance, determines access to training or informs HR decisions from learning data falls within the high-risk category (Annex III of the regulation). Its obligations are substantial: technical documentation, mandatory human oversight, logging and verifiable compliance.
In practice, an AI assistant that helps a learner understand a concept is limited risk. A system that grades automatically and informs an admission or certification decision is high risk. If you have not made this distinction for every AI tool on your platform, that is your first task.
Another date to remember: Article 4 of the AI Act, which imposes an AI literacy obligation (training people who operate or use AI systems), has applied since 2 February 2025. It is not just for technology enthusiasts: every organisation deploying an AI tool to its teams must be able to show it has taken concrete measures so they understand what they use.
Three questions to ask your AI learning-tool provider
Before enabling anything, these three questions need clear answers.
Where is your learners' data hosted?
The AI Act does not replace the GDPR: it supplements it. Messages sent to an AI assistant, attachments and course-context data all leave your LMS for a third-party service. The hosting question - whether it is in Europe and with which cloud provider - is not incidental. It determines whether you can answer a data-erasure request, ensure effective pseudonymisation and account to your DPO. A provider unable to answer it precisely is not ready.
Which AI model is used, and how transparently?
The regulation's transparency obligation means your learners need to know they are interacting with AI. But a technical question matters behind that: does the service you integrate call a general LLM (GPT, Claude or Gemini) directly, without filtering your data? Or does it use an orchestration layer that controls what goes to the model? The answer radically changes your exposure.
What traceability is retained for AI actions?
The AI Act requires limited- and high-risk systems to be auditable. For learning tools, this means: are exchanges between learners and AI recorded? By whom? For how long? Who can access them? Traceability is not just a regulatory matter: it also lets you, as a learning leader, check that the tool behaves as intended.
What this means specifically for Moodle
Moodle introduced its native AI subsystem (core_ai)
in version 4.5. It is now possible to enable AI features directly
within the platform through providers configured by the administrator.
The key point is that Moodle itself does not do AI. It provides the plumbing. The provider configured in Moodle - whether an external service or a dedicated plugin - actually processes your data and generates the responses. That provider is subject to the AI Act's obligations.
The same care is required in the plugin ecosystem. A Moodle plugin containing an AI feature can call any external service, with or without anonymisation and with or without logs. Being available in the Moodle Plugins Directory does not guarantee European regulatory compliance.
On your Moodle platform, check the following: which plugins use AI features, actively or passively? Which external services do they send data to? Are learner identities pseudonymised before data is sent? Is consent for AI use collected and configurable by the administrator?
The most exposed sectors
All organisations using AI tools in education are affected, but some sectors face greater exposure.
Public higher education handles data belonging to underage students or young adults within a public-service framework with enhanced obligations for data protection and assessment fairness. If an AI tool influences an academic decision, even indirectly, its AI Act risk level rises.
Healthcare and medical training combine sensitive data and critical-skills challenges. A poorly designed AI assistant in a training pathway for healthcare professionals is more than a faulty tool: it can validate incorrect knowledge.
The public sector is subject to traceability and accountability requirements that the private sector does not always face. Any delegation to an AI system of a task previously related to an administrative decision must be documented and reversible.
What this changes when choosing an AI tool for Moodle
AI Act compliance cannot be declared on a product sheet. It must be verified in the architecture: how data flows, who processes it, what traceability is retained and how the platform administrator remains in control.
At Pimenko, we designed PimenkoAI with these requirements in mind. Learner identities are never sent in raw form to the processing service: a systematic anonymisation mechanism is applied. Our application infrastructure is hosted in France by Scaleway, and inference is provided by the API of Mistral, a French company. Neither component is subject to US law and therefore to the CLOUD Act. Tutor-mode exchanges are retained for a period configurable by the institution, with configurable automatic deletion and support for Moodle Privacy requests. The DPO can review processing declarations directly in Moodle administration, without querying an external provider.
This is not marketing posturing. It follows from the architecture choices we made from the beginning of the project.
See how PimenkoAI is built to meet these requirements →
References
-
Regulation (EU) 2024/1689 of the European Parliament and of the
Council laying down harmonised rules on artificial intelligence.
Article 4 (AI literacy), applicable since 2 February 2025. Annex
III (high-risk systems, point 3: education and vocational
training). Fully applicable since 2 August 2026.
Online: https://eur-lex.europa.eu/eli/reg/2024/1689/oj -
Moodle Developer Resources, AI Subsystem, moodledev.io
- subsystem introduced in Moodle 4.5 (MDL-80888).
Online: https://moodle.atlassian.net/browse/MDL-80888