Standards interpretation

Institutional controls under risk-based artificial intelligence regulation: defining responsibilities and exclusions

Standards Interpretation

Examines the practical meaning of institutional controls under risk-based artificial intelligence regulation and the evidence required to distinguish formal adoption from effective operation.

The policy and evidence context for institutional controls under risk-based artificial intelligence regulation has been materially shaped by the artificial Intelligence Act entered into force in August 2024. Oversight of the matter under review should reflect the principle that interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope. Proportionality requires controls sufficient to protect learners without imposing measures unrelated to the identified risk.

The applicability described by the artificial Intelligence Act entered into force in August 2024 changes the implementation context for the assurance matter. Entry into force or applicability establishes an operative reference point, but the resulting duties must still be traced to the persons, services and jurisdictions covered. Authorities should distinguish immediate duties from staged provisions, and providers should retain the legal and operational basis for any conclusion about application.

The quality significance of the assurance matter follows from a basic distinction between availability and effective provision. A decision concerning the relevant requirement should recognise that technology may support teaching, administration and access, but consequential educational decisions must remain accountable, explainable and open to effective review. Oversight should examine implementation throughout the learner journey, not only at entry or through one reported outcome.

Purpose and present context

The European Union Artificial Intelligence Act entered into force on 1 August 2024. It applies a risk-based framework and includes provisions relevant to certain education and vocational-training uses, particularly systems capable of influencing access, evaluation or progression. Requirements apply according to the Act’s staged timetable. Providers should classify intended uses, identify their role in the supply chain and preserve human oversight, data governance and incident controls.

A focused examination of institutional controls under risk-based artificial intelligence regulation requires a clear analytical discipline. A decision concerning the control should recognise that scope should identify the people, decisions, services, locations and periods to which the arrangement applies. Exclusions require an objective reason and should not be inferred from organisational custom or the absence of an earlier complaint. An imprecise scope or measure may produce a credible-looking record that does not answer the relevant decision question.

Responsibility for the relevant requirement should be visible at the point where consequential decisions are made. In reviewing the assurance matter, the assessment question is whether the control operates across the relevant sites, programmes, delivery modes and learner groups, including material exceptions. Escalation should follow whenever the available record cannot support a safe conclusion for the affected learners.

Responsibilities and material risks

Risk assessment of institutional controls under risk-based artificial intelligence regulation should give particular attention to loss of meaningful human review, unclear responsibility between providers and suppliers, and unverified outputs entering teaching or assessment. A provider should also consider unequal performance across learner groups and automation bias in consequential decisions. Stronger controls are required where learners may not detect an error or where later correction cannot restore the lost opportunity.

Relevant evidence for the matter under review will normally include data provenance and access controls, records of human review and overrides, pre-deployment and periodic performance testing, supplier change and incident records, and documented authority for each consequential use. Evidence outside the relevant period or scope should be identified and given no more weight than its limitations permit. An unresolved contradiction is a limitation on the conclusion and should be reported as such.

Implementation of the stated expectation can be tested without imposing unnecessary reporting. In reviewing the control, responsible bodies should begin with the intended public or educational outcome, map every activity capable of affecting that outcome, and record where responsibility passes between functions or organisations. Test boundary cases before confirming the scope. The assurance record may draw on existing sources, provided their limitations and fitness for the current purpose are examined.

Evidence and assurance

The final record on institutional controls under risk-based artificial intelligence regulation should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. Departure from an illustrative method may be justified where equivalent outcome and evidence are established. No complete conclusion should be recorded while a material evidential limitation remains.

The analysis of the assurance matter should remain within the limits of the evidence. The analysis of the assurance matter proceeds on the basis that the volume of documentation is not a measure of conformity. Relevance, integrity and coverage are more important than the number of records produced. Oversight of the stated expectation should reflect the principle that a technical capability is not evidence that a use is educationally justified. Accuracy measured in one setting may not transfer to another population, language, curriculum or decision context. If uncertainty could change a consequential decision, additional evidence or a narrower conclusion is required.

Decisions concerning the relevant requirement should remain traceable to the information available for the stated reference period. The reason for revision should be explicit, including whether it arises from new evidence, a methodological change or a different interpretation. A break in method or coverage must not be presented as if it demonstrated a change in educational performance.

Public reporting on the stated expectation should distinguish established fact, analytical judgement and planned action. A material change should not remove the earlier position from the evidential trail. If definitions, coverage or evidence alter an earlier conclusion, the reason should be stated so that revision is not mistaken for changed performance.

The appropriate response to the control is therefore one of controlled implementation and review. Neither administrative activity nor general assurance should obscure the intended result or its effect on learners. Assurance should be withheld for the affected scope until the limitation is resolved.