Updated 12 August 2026 following the adoption of the AI Omnibus, Regulation (EU) 2026/1744, which moved the Annex III high-risk obligations to 2 December 2027. Legal-architecture revision 18 August 2026. The original version was published on 8 April 2026.
AI is no longer an optional layer in credentialing operations. It is in the scoring pipeline, in the proctoring tools, in the content generation workflows, and in the systems your vendors use behind the scenes. It is also a regulated activity. The EU AI Act has moved AI in credentialing from a technology decision into a compliance obligation, and the implications reach beyond Europe.
This article translates the Act into what credentialing leaders need to do now to stay defensible. It is written for boards, executives, and operational owners who need to know what to demand from their teams and their suppliers, not just what the regulation says.
AI in your credentialing pipeline is now a regulated activity
The EU AI Act designates specific uses of AI in education and vocational training as high-risk, including determining access or admission, evaluating learning outcomes, assessing the level a person can access, and monitoring prohibited behaviour during tests. For credentialing programmes whose activities fall within those use cases, that reaches many of the places AI is being deployed today. Automated scoring, pass and fail recommendations, admission and placement decisions, and proctoring or anomaly detection are all candidates for classification. Whether any of them is legally high-risk is a use-case question, settled by the classification exercise covered later in this article, not by the word credential.
The Act also has extraterritorial reach. A credential owner outside the EU can still be in scope where an AI system is placed on the EU market or used in the EU, or where output produced by the system is used there. Serving EU candidates should therefore trigger a scope assessment under Article 2, not an assumption in either direction about where incorporation leaves you.
This is not a future concern. Prohibited practices have been enforceable since 2 February 2025, and the Article 4 AI literacy duty has applied since the same date. The general purpose AI rules and the governance and penalty framework have applied since 2 August 2025. Transparency obligations under Article 50 have applied to specific systems since 2 August 2026. The high-risk system rules for Annex III now apply from 2 December 2027, following the AI Omnibus.
“A reactive approach to this Act will not survive an audit or a stakeholder challenge.”
First, determine your role
The Act does not hand every organisation the same obligations. It allocates them by role. A provider develops an AI system or places it on the market under its own name. A deployer uses an AI system under its own authority. Most credentialing bodies buying AI-enabled scoring or proctoring from a vendor will be deployers for those systems. Build the system yourself, put your own name on it, or substantially modify it, and provider obligations can attach instead.
The difference is material. Providers carry the heavyweight duties, including risk management systems, technical documentation, conformity assessment, quality management, and registration. Deployers carry a narrower operational set, including using the system in line with its instructions, assigning competent human oversight, monitoring operation, controlling the input data they supply, retaining available logs, and informing affected people in specified circumstances.
So the first compliance question is not whether a system is high-risk. It is what your organisation is in relation to it. Every obligation described in this article lands differently depending on that answer, and the practical division it creates runs through everything that follows: the evidence you must produce yourself, and the evidence you must contractually obtain from your vendor.
“The first compliance question is not whether a system is high-risk. It is what your organisation is in relation to it.”
The dates that matter, and what the deferral actually bought you
When this article first published in April 2026, the high-risk regime was set for 2 August 2026 and the deferral was an unconfirmed proposal. The position taken here was to plan for August 2026 on the basis that a delay would buy preparation time rather than remove the work. The delay arrived.
The Digital Omnibus on AI, now generally called the AI Omnibus, was adopted as Regulation (EU) 2026/1744, published on 24 July 2026 and in force from 27 July 2026. It moves the core high-risk obligations for Annex III systems from 2 August 2026 to 2 December 2027, and those for high-risk AI embedded in regulated products under Annex I to 2 August 2028. These dates are binding law, not a proposal.
Read the deferral correctly. It is a resourcing window, not relief. The Omnibus simplifies parts of the framework, but the substantive core of the high-risk regime remains. Risk management, technical documentation, human oversight, and monitoring all still arrive, joined for providers by conformity assessment and registration, and they arrive with sixteen additional months of regulator preparation behind them.
“It is a resourcing window, not relief.”
Sixteen months is close to what the structural work genuinely takes in a credentialing body. Mapping the AI estate, building validity evidence, renegotiating vendor contracts, and standing up oversight that survives an appeal are not quarterly tasks. Organisations that read December 2027 as permission to stop will reach the deadline with the same evidence gap, and without the excuse.
A reactive approach to this Act will not survive an audit or a stakeholder challenge. The work is structural, and structural work runs slowly even when the team knows what it is doing.
What already applies to you today
The deferral concerns the high-risk regime only. Three sets of obligations are already live, and they land directly on credentialing operations.
Article 5 prohibitions have applied since 2 February 2025 and were not deferred. There is no grandfathering and no transitional arrangement. This includes the emotion recognition prohibition covered below. The Omnibus also added further prohibited practices, including a ban on so-called nudification tools, which take effect from 2 December 2026.
Article 50 transparency obligations took effect on 2 August 2026 as originally scheduled, and they are narrower than most summaries suggest. Article 50 attaches specific duties to specific systems. Where candidates interact directly with an AI system, a chatbot handling queries, say, or a conversational assessment agent, the system must be designed so they know they are dealing with AI, unless that is already obvious. Where a system generates synthetic content, machine-readable marking duties fall on its provider, with a grace period to 2 December 2026 for certain generative systems already on the market before 2 August 2026. And where a permitted system infers emotion or performs biometric categorisation, the people exposed to it must be informed, although test the Article 5 prohibition first, because in education settings most such uses are banned outright rather than merely disclosable.
What Article 50 does not do is impose a general duty to tell candidates wherever AI sits in your process. The broad disclosure duty for high-risk systems, informing a person that they are subject to a decision made or assisted by high-risk AI, sits in Article 26(11) and arrives with the high-risk regime in December 2027. Broader candidate transparency before then is good assessment governance, and I recommend it. It is a choice, not yet a command.
“It is a choice, not yet a command.”
The Article 4 AI literacy duty has applied since 2 February 2025 and was rewritten by the Omnibus with effect from 27 July 2026. It is now an obligation to take measures supporting the development of AI literacy among your personnel, rather than an obligation to guarantee a specific level for any individual. For a credentialing body, that is likely to cover the examiners, markers, invigilation staff, and operational and leadership personnel who use or oversee the AI systems concerned.
If your programme has done nothing since the spring, these are the obligations you are already behind on. The high-risk audit pack is the 2027 problem. Transparency, where it applies, is the 2026 one. Literacy has been live since 2025.
Which credentialing uses may be high-risk
Annex III is the relevant section for credentialing programmes. It identifies AI as high-risk in education and vocational training when it is used in any of the following ways:
- evaluating learning outcomes, including the steering of a learner through a programme
- determining access or admission to a programme
- assessing the level a person can be admitted to or assessed against
- monitoring and detecting prohibited behaviour during tests
In credentialing terms, that maps to AI scoring, automated pass and fail recommendations, placement and progression decisions, and AI proctoring or cheating detection. Treat these as uses requiring classification rather than as settled conclusions, because Article 6 contains a filter. An Annex III use falls outside the high-risk category where it does not pose a significant risk of harm and does not materially influence the decision, for example where it performs a narrow procedural task or a preparatory step that a human then completes and owns. AI that profiles individuals never gets the benefit of the filter.
The Commission’s draft classification guidelines, published in May 2026, draw the line in territory credentialing leaders will recognise. AI contributing to summative assessment, the evaluations that drive final grades and certification decisions, is high-risk under Annex III. Formative tools that help a candidate practise without driving the final outcome are not high-risk on that basis. The guidelines read educational and vocational training institutions broadly, reaching private, online, and continuing education settings, so a certification programme should not bet on falling outside the definition without analysis. And a human reviewer does not, on their own, take a system out of the high-risk category. If the review is rubber-stamping rather than independent judgement, the AI is still materially influencing the outcome.
The classification needs evidence either way. Where a provider relies on the Article 6 filter, the Act requires that assessment to be documented. If you are the deployer, obtain that rationale and keep it, because when a candidate’s lawyer asks why a scoring tool was treated as out of scope, a vendor’s undocumented opinion will not carry the day.
The red line: emotion recognition is prohibited
One specific use deserves immediate attention. Article 5 prohibits AI that infers emotions in workplace and education institution settings, with a narrow exception for medical or safety purposes. This prohibition was not touched by the AI Omnibus and has been enforceable since February 2025.
The prohibition turns on inferring emotional states from biometric data, such as facial expression or voice. Whether an independent certification environment counts as an education institution is itself a scope question, but the draft guidelines’ broad reading of the term is not encouraging for anyone hoping to sit outside it, and it is not a point to gamble a programme on. If a proctoring vendor in your stack claims to detect stress, deception, engagement, or intent from candidates’ video or audio, the feature needs immediate review against Article 5. Do not assume that calling the output engagement, behavioural insight, or risk scoring takes it outside the prohibition.
The action is simple. Audit every proctoring and integrity tool you use, including features that may have been added to existing products by vendors as part of routine updates. Disable anything that infers emotional state from biometric data unless it clearly falls within the medical or safety exception, which routine integrity monitoring is unlikely to. Get written confirmation from vendors that these features are off and will remain off. Do this now, not in the next procurement cycle.
The audit-pack mindset
High-risk AI under the Act carries documentation expectations that should feel familiar to anyone who has worked in regulated industries. These are the obligations that land on 2 December 2027, and they divide by role.
Where you carry provider obligations
- structured risk management for each high-risk system, with mitigations and residual risk sign-off
- data governance evidence covering training data, validation data, quality, and privacy
- technical documentation describing what the system does, how it was validated, and how it should be used
- a quality management system, conformity assessment, and registration
As a deployer
- evidence that the system is used in line with the provider’s instructions
- human oversight that is real, not symbolic, assigned to named and trained people with authority to intervene, override, and stop
- monitoring of operation, with logs retained where the system generates them
- control over the input data you supply, with escalation and incident reporting when something goes wrong
- candidate information where the Act requires it, and broader transparency where you choose it as good practice
Then ask the strategic question of every entry in your AI register: which of these do we own, and which must we contractually obtain from our vendor? A vendor contract that does not deliver documentation, log access, change notification, and audit support leaves you holding deployer duties you cannot evidence.
“Which of these do we own, and which must we contractually obtain from our vendor?”
This is what I mean by an audit-pack mindset. The question to ask of every AI use in your pipeline is not whether it works today, but whether you could demonstrate that the decision was sound if a regulator, an employer, or a candidate’s lawyer asked you to. If the honest answer is no, the gap is documentation discipline, not technology. The companion piece on ISO 42001 and 23894 walks through the operating model that produces that discipline, and ISO/IEC 17024:2026 now makes the same evidence an accreditation matter.
Scale your controls by stakes
A practice diagnostic does not need the same governance as a chartered status exam. Be clear about one thing first, though. Low, medium, and high stakes are my operating model, not the Act’s legal categories. High stakes does not automatically mean high-risk in the statutory sense, and a minimal-risk AI use does not acquire statutory duties because of the label you give it. The legal classification comes from Annex III and the Article 6 filter. The stakes model is how you scale governance effort onto that classification, and onto all the AI the Act never touches.
Low-stakes uses, such as practice tests and formative feedback, need transparency, basic quality assurance, logging, and an honest classification rationale. Medium-stakes uses, such as micro-credentials and modular components, need stronger bias monitoring, structured human review, and documented risk treatment. High-stakes uses, such as licensure and regulated practice gating, need the full audit pack and human authority that can stand up in an appeal.
“The trap to avoid is treating low stakes as no paperwork.”
The trap to avoid is treating low stakes as no paperwork. Even a low-stakes classification needs the rationale on file. That is a small effort that saves a large argument later.
A 90-day plan that survives a board challenge
If you are starting from a standing start, the following sequence is achievable in three months and gives you a defensible foundation. With December 2027 as the high-risk date, ninety days of structured work now leaves you with runway rather than a scramble.
In the first 30 days, build your AI register. Map every AI touchpoint across content creation, delivery, proctoring, scoring, and credential decisions. Include the AI features your vendors have embedded in products you already buy. Give every entry four fields: the system’s intended purpose, your stakes rating, your legal role for that system, provider, deployer, or unresolved, and its candidate classification under the Act, prohibited, Annex III candidate, possible Article 6 exclusion, Article 50 relevant, or out of scope. Assign a single accountable owner who can coordinate legal, psychometrics, assessment operations, and product. AI governance fails when it lives in a committee with no decision rights.
In days 31 to 60, run risk assessments for every medium and high-stakes use. Document validity, fairness, transparency, security, and privacy considerations. Define human oversight points: who can approve, pause, or stop an AI use, and what training they need. Update vendor contracts to require change notification, log access, audit support, and incident reporting.
In days 61 to 90, build the audit pack itself. Construct statements for each component, validity evidence, monitoring plans, override logs, incident playbooks, and the supporting policies. Train assessment operations and leadership on AI literacy, which is already a live duty under Article 4, and on consistent enforcement. Run a tabletop incident scenario so the playbook is not theoretical.
This is not a project that ends. It is the new operating model for credentialing in a regulated AI environment.
The 90-day playbook
- Days 1 to 30: Build the AI register, with an intended purpose, stakes rating, legal role, and Act classification on every entry. Assign a single accountable owner with decision rights across legal, psychometrics, operations, and product.
- Days 31 to 60: Run risk assessments for every medium and high-stakes use. Define human oversight points. Update vendor contracts.
- Days 61 to 90: Assemble the audit pack. Train your teams. Run a tabletop incident scenario.
Trust is the credential’s moat
A credential is a public trust product. Its value depends entirely on the confidence that candidates, employers, and regulators have in the soundness of the decision. AI can sharpen that confidence when it is governed well. It can erode it overnight when it is not.
The EU AI Act is not asking credentialing bodies to do anything that good practice did not already suggest. It is formalising expectations that the market was already moving toward. The organisations that use the deferral window will have an audit pack ready when buyers and regulators ask for one. The organisations that treat it as a reprieve will find themselves explaining gaps under pressure, in a market that has had sixteen more months to raise its expectations.
If you are unsure where your programme sits on this curve, the most useful thing you can do this quarter is build the AI register, with its role and classification fields, and assign the owner. Everything else follows from those two decisions. The companion articles on the AERA, APA, and NCME Testing Standards and on design-led integrity drawing on Ofqual and JCQ walk through the parallel work on validity evidence and assessment integrity.
Ready to make your AI use audit-ready under the EU AI Act?
Talk to our team about how Globebyte can help you build a defensible AI operating model for credentialing.