Skip to content

Level 2 · The framing — why the law enters and which law applies

Level 1 ran on flowers, and that was the point: no person was affected, so no law applied, and we managed risk purely because it is good engineering. The instant a system makes a decision about a person, the calculus changes. A student-selection model predicts whether an applicant will pass, and that prediction is used to admit, reject, or place them. The output lands on someone’s education, their access, their future. That is the trigger the EU AI Act watches for: not “is it AI?” but “does it decide something that matters to a person?”

So Level 2 is where the law walks in. Nothing about the method changes — Nerea still declares, James still approves, Martha still treats and signs, git still closes the loop — but now the loop is also a legal obligation, not just good practice. And the honesty bar rises with the stakes: when a wrong decision can deny someone a place, “the metric looks fine” is not good enough. You have to be able to prove it is fine, with enough evidence — and when you can’t, you have to say so.

§2 — Which law applies: Annex III §3 (education)

Section titled “§2 — Which law applies: Annex III §3 (education)”

The EU AI Act does not call every AI system high-risk. It keeps a listAnnex III — of uses that are high-risk because of where they are applied. Section 3 of Annex III is education and vocational training: systems used to decide admission to or assignment within educational institutions, to evaluate learning outcomes, or to assess the appropriate level of education for a person. A model that sorts applicants for admission or placement is a textbook Annex III §3 case.

Nerea classifies the system from the portal (mission classify-system): tier: high under Annex III §3 — a person declares it and owns it, with the basis spelled out in plain words: “EU AI Act Annex III §3 (education and vocational training) — the system decides admission/placement of students.” The engine does not infer the tier. James reviews and merges the PR the mission opens. Declaring high is what pulls Articles 9–15 into scope.

§3 — ISO 23894 vs prEN 18228, in one paragraph

Section titled “§3 — ISO 23894 vs prEN 18228, in one paragraph”

This level declares two risk-management standards alongside the AI Act, and they are not interchangeable. ISO 23894 is the published, international process guide — identify → analyse → evaluate → treat → monitor — and it grants no presumption of conformity (it is global good practice, not European law). prEN 18228 is the harmonised draft the EU is writing specifically to operationalise Article 9; the engine treats it as a higher-authority candidate, but its presumption flag is false today, because a draft is not yet a standard cited in the Official Journal. So this system follows a real, projectable European process — while honestly carrying presumption = false. If that distinction is fuzzy, spend five minutes here before going on: