The EU AI Act is the first comprehensive law on artificial intelligence, and children appear in it more often than many organisations realise. Some practices that harm children are already banned. AI used to make decisions about students is classed as high-risk. Chatbots must say they are chatbots. And in July 2026 the Union amended the Act itself, moving some deadlines back and adding new prohibitions aimed squarely at abuse imagery. Schools, edtech vendors, platforms and charities need to know which rules already bite and which are still to come.

How does the EU AI Act protect children?

The AI Act bans AI that exploits age-related vulnerabilities, classes AI used in education as high-risk, requires providers of high-risk systems to consider the impact on under-18s, and makes chatbots disclose that they are AI. Amendments adopted in July 2026 also ban AI that generates child sexual abuse material from 2 December 2026.

The timeline, as amended

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. On 19 November 2025 the European Commission proposed a Digital Omnibus on AI to simplify implementation and defer the high-risk rules. That proposal is no longer a proposal. The European Parliament approved it on 16 June 2026, the Council adopted it on 29 June 2026, and it was published as Regulation (EU) 2026/1744 on 24 July 2026, entering into force on 27 July 2026. The dates that now apply are:

  • 2 February 2025: prohibited practices and the AI literacy duty apply.
  • 2 August 2025: obligations for providers of general-purpose AI models, governance and penalties apply.
  • 2 August 2026: transparency duties under Article 50 apply, including telling people they are interacting with AI. The Commission's enforcement powers over general-purpose AI models also began.
  • 2 December 2026: the new prohibitions on AI-generated child sexual abuse material and non-consensual intimate imagery apply, and providers of generative systems already on the market before 2 August 2026 must meet the machine-readable marking duty.
  • 2 December 2027: obligations for stand-alone high-risk systems listed in Annex III, including education, apply. The original date was 2 August 2026.
  • 2 August 2028: obligations for high-risk AI embedded in products covered by EU product safety law, such as toys, apply. The original date was 2 August 2027.

The deferral is adopted law. It moves the high-risk deadlines without removing any obligation, and it does not delay the prohibitions or transparency rules.

Prohibited practices that concern children

Article 5 lists AI practices that are banned outright, with fines of up to €35 million or 7 per cent of worldwide annual turnover. Three matter most for children.

  • Exploiting vulnerabilities due to age. Article 5(1)(b) prohibits AI that exploits the vulnerabilities of a person or group because of their age, disability or social or economic situation, with the objective or effect of materially distorting their behaviour in a way that causes or is reasonably likely to cause significant harm. The Commission's guidelines on prohibited AI practices, published on 4 February 2025, treat children as a clear example of a group whose age-related vulnerabilities are protected. Persuasive design that keeps a child engaged or spending in ways that harm them is squarely in view.
  • Emotion recognition in education. Article 5(1)(f) bans AI that infers the emotions of people in education institutions, except for medical or safety reasons. Classroom "engagement" or attention analytics that read students' faces or voices sit very close to this line.
  • Child sexual abuse material. The Digital Omnibus added a prohibition on placing on the market or using AI systems that generate child sexual abuse material, alongside a ban on tools that create non-consensual intimate imagery, often called nudification apps. These apply from 2 December 2026. The harm they target is described in our article on AI-generated child abuse imagery.

Where children appear in the rest of the Act

Beyond the bans, the Act builds children into how risk is assessed. Recital 48 refers to children's rights under Article 24 of the EU Charter of Fundamental Rights and the UN Convention on the Rights of the Child, as developed in General Comment 25. Article 9(9) requires providers of high-risk systems, when running their risk management system, to consider whether the system is likely to have an adverse impact on persons under the age of 18 and, as appropriate, other vulnerable groups. That is a legal hook for a structured, documented look at children, which is what a child rights impact assessment provides.

High-risk AI in education

Point 3 of Annex III lists four uses of AI in education and vocational training as high-risk:

  1. Determining access or admission to, or assigning people to, educational and vocational training institutions at all levels.
  2. Evaluating learning outcomes, including when those outcomes are used to steer a student's learning process.
  3. Assessing the appropriate level of education an individual will receive or be able to access.
  4. Monitoring and detecting prohibited behaviour of students during tests, which covers AI proctoring.

Providers will need risk management, data governance, documentation, logging, human oversight, a conformity assessment and EU database registration. Deployers, such as schools and universities, will need to use systems according to instructions, assign competent human oversight, keep logs and inform the people affected. Public bodies and private entities providing public services must also carry out a fundamental rights impact assessment before first use. A listed system that performs only a narrow procedural task may fall outside the high-risk category, but never where it profiles individuals, and the reasoning must be documented.

Biometrics is also an Annex III area. Remote biometric identification, biometric categorisation by sensitive or protected attributes, and emotion recognition are high-risk where they are not already banned. Biometric verification, whose sole purpose is to confirm that a person is who they claim to be, is expressly excluded. For age assurance, this means classification depends on how a system works: a check that a user matches their own ID document is treated differently from estimating a characteristic from a face.

Transparency: chatbots and deepfakes

Article 50 has applied since 2 August 2026. Providers must design AI systems that interact with people so that users are told they are dealing with AI, unless that is obvious from the context. Providers of generative systems must mark synthetic audio, images, video and text in a machine-readable way, with a grace period to 2 December 2026 for systems already on the market. Deployers who publish deepfakes must disclose that the content is artificially generated. For a child, knowing a friendly voice is a machine is a basic safeguard, though not a sufficient one, as our guide to talking with children about chatbots explains.

General-purpose AI and AI literacy

Providers of general-purpose AI models, the large models behind most chatbots, have been subject to documentation, copyright and transparency obligations since 2 August 2025, with additional safety and security duties for models with systemic risk. The Commission published a voluntary General-Purpose AI Code of Practice on 10 July 2025 as a route to compliance. An organisation building a children's product on such a model remains responsible for its own system.

Article 4 on AI literacy has applied since 2 February 2025. The Omnibus rewrote it: providers and deployers must now take measures to support the development of AI literacy among their staff and others operating AI on their behalf, without guaranteeing any individual's level of literacy. It is an obligation of effort, but a school or NGO that has rolled out AI tools without any staff training will struggle to show it has been met.

How the AI Act interacts with the DSA and GDPR

The AI Act does not replace other EU law. A chatbot on an online platform is also subject to the Digital Services Act, including the Article 28 duty to ensure a high level of privacy, safety and security for minors and the Commission's July 2025 guidelines on meeting it, compared in detail in our article on the UK Online Safety Act and the EU DSA. The Omnibus also gave the AI Office supervision of AI systems built into very large online platforms and search engines.

Any AI system that processes a child's personal data is subject to the GDPR in full, including lawful basis, data minimisation and the age of digital consent, covered in our guide to GDPR and children's data. The Omnibus widened the circumstances in which special categories of personal data may be processed to detect and correct bias, but only where strictly necessary and with safeguards.

What schools, edtech vendors, platforms and NGOs should do now

The extra time is for preparation, not waiting. Conformity work built from nothing can take longer than the fifteen months that remain.

  • Schools and universities: inventory every AI tool used for admissions, grading, placement, proctoring or monitoring. Stop any use of emotion recognition on students. Ask vendors how each product is classified and what evidence supports that. Public bodies should plan a fundamental rights impact assessment.
  • Edtech vendors: classify your products against Annex III now and document the reasoning. Build the Article 9 risk management system with an explicit assessment of impact on under-18s. Confirm Article 50 disclosures are live.
  • Platforms and AI developers: review engagement and persuasive features against Article 5(1)(b). Test generative features against the new abuse-imagery prohibition before 2 December 2026, and align AI Act, DSA and GDPR assessments into one evidence base.
  • NGOs and public bodies: record which AI systems staff use with children or children's data, deliver proportionate AI literacy training, and write AI into your safeguarding policy framework so procurement and incident response cover it.

For organisations that want an independent view of a specific system, Child Safe ME carries out child-centred AI impact assessments that map a product against the AI Act, the DSA and children's rights standards in one piece of work.

Frequently asked questions

Has the EU delayed the AI Act? Partly. Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for AI in regulated products. Prohibitions, AI literacy, general-purpose AI rules and Article 50 transparency were not deferred.

Is AI used in schools banned under the AI Act? No. Most educational AI is lawful. Emotion recognition in education institutions is banned except for medical or safety reasons, and AI used for admissions, grading, placement or exam proctoring is high-risk, with full obligations from 2 December 2027.

Does the AI Act set a minimum age for using chatbots? No. The AI Act does not set age limits. Age requirements come from platform terms, the GDPR's consent rules and, for platforms, the Digital Services Act.

Are age verification tools high-risk AI? It depends on the method. Biometric verification that only confirms a person is who they claim to be is excluded from the high-risk list. Other biometric systems may fall within Annex III.

Does the AI Act apply to organisations outside the EU? Yes. It applies to providers placing AI systems on the EU market and to providers and deployers outside the EU where the system's output is used in the EU.

Regulatory details cited here are accurate as of September 2026 and should be checked against the Official Journal and the European Commission's AI Act guidance before being relied on in a compliance decision.

Work with Maryam

Looking for expert guidance on child safeguarding, online safety, or AI governance? Maryam and the Child Safe ME team are here to help.

Get in Touch