AI Act and education in Malta: obligations and risks
- 27 July 2026
- Posted by: Sergio Passariello
- Categories: Innovation, Regulatory
The AI Act changes the governance of Maltese educational institutions. After the extension of the Digital Omnibus, here is what remains in force from 2 August 2026 and what is postponed to 2027, with the impacts on the Internal Quality Assurance MFHEA.
In the last two years, artificial intelligence has become a permanent part of the daily life of every Maltese educational institution, often without anyone having formally decided so. A teacher who uses a language model to sketch the material of a course, an admissions office that relies on an automatic screening tool, an orientation service that proposes study paths based on an algorithm, an online proctoring system that reports suspicious behavior during an exam: these are all cases that are already present, in different forms, in Further Education Institution, Higher Education Institution, universities and training providers operating in Malta.
What is changing is therefore not the presence of AI, but the legal framework that governs it. The European Regulation on Artificial Intelligence, together with the recent changes introduced by the so-called Digital Omnibus, requires educational institutions to treat the adoption of AI not as a simple technological choice, but as a matter of governance, risk management and Internal Quality Assurance. This applies to chatbots and virtual tutors, learner analytics tools, automated administrative support, and, with particular attention, any system that affects decisions regarding admission, assessment, progression, or orientation of students.
When the AI Act applies
Regulation (EU) 2024/1689, known as the AI Act, came into force on 1 August 2024. Since then, its application has proceeded in phases, and the timing of these phases was the subject of a significant change in the summer of 2026, which every Maltese educational institution should know.
The first substantive obligations have already been in place for some time: from 2 February 2025, the prohibition of AI practices considered to be at unacceptable risk (Article 5) and the AI literacy obligations for those who develop or use AI systems will apply. From 2 August 2025, on the other hand, the governance rules, the obligations relating to AI models for general purposes and the sanctioning system provided for in Article 99 are operational.
The date that guided compliance planning across Europe for two years was 2 August 2026, set as the deadline for the general application of the Regulation, including the obligations for high-risk systems listed in Annex III, a category that includes, among other things, systems used for access to and admission to educational pathways and for the assessment of learning outcomes. This date, however, was changed by the Digital Omnibus on AI, the simplification package proposed by the European Commission on 19 November 2025 and definitively approved by the Council of the European Union on 29 June 2026, following the vote of the European Parliament on 16 June 2026. The text was signed on 8 July 2026 and published in the Official Journal of the European Union on 24 July 2026, entering into force on the third day following its publication.
For the education sector, the practical effect is as follows: the obligations related to the autonomous high-risk systems of Annex III, which include the admission, guidance and learning assessment systems, have been deferred from 2 August 2026 to 2 December 2027. For AI systems integrated into products already regulated by sectoral safety regulations (Annex I), the deadline is further postponed, to 2 August 2028. On the other hand, the transparency obligations provided for in Article 50 remain set at 2 August 2026, with the exception of Article 50, paragraph 2, relating to systems already on the market, the application of which has also been extended, to 2 December 2026, the date on which the new prohibitions introduced by the Omnibus, relating to the non-consensual generation of intimate images, also come into force.
In summary: the deferral concerns the most onerous obligations related to high-risk systems, not the entire AI Act system. Prohibited practices, AI literacy and most transparency obligations remain fully applicable according to the original timetable. Given the speed with which the framework has evolved over the past year, MQE recommends that the status of implementation be regularly reviewed with official EU sources before finalising any internal compliance plan.
This is accompanied by the national implementation framework. In Malta, the AI Act has been implemented at the enforcement level with the Artificial Intelligence Regulations, 2025 (Legal Notice 226 of 2025, registered as Subsidiary Legislation 591.05 under the Malta Digital Innovation Authority Act, Cap. 591), in force since 10 October 2025, which designate the MDIA as a market surveillance authority and single point of contact for the European Regulation. In parallel, Legal Notice 227 of 2025 designates the Information and Data Protection Commissioner (IDPC) as the competent authority for high-risk systems involving particularly sensitive data processing. For a Maltese educational institution, this means that the national interlocutor for any verification or notification related to an AI system is the MDIA, except for profiles specifically assigned to the IDPC.
Why education is a sensitive sector
The AI Act takes a risk-based approach: not all AI systems are treated equally, and not all tools used in education are automatically considered high-risk. An AI-assisted spell checker or a tool that generates draft educational slides is, in principle, among the uses with limited or minimal risk. It is a different matter when a system directly affects a decision that affects a person’s educational path: it is here that the Regulation introduces more stringent obligations, because the right to education, non-discrimination and future professional opportunities of students are at stake.
Which education systems can be classified as high risk
In principle, AI tools used to determine access to or admission to an institution or program, to assign students to specific educational or training pathways, to assess learning outcomes with effects on student progression, or to monitor and detect prohibited behavior during tests and exams fall into the category of high-risk systems in Annex III. Even with the deferral introduced by the Digital Omnibus, which moves the deadline for full adaptation to 2 December 2027, this classification remains relevant: institutions that already use these tools should start mapping the systems in use, as the extension allows time to prepare, not an exemption from obligations.
What uses of artificial intelligence can be prohibited
The AI Act prohibits, among other practices, the inference of emotions in the workplace and in educational institutions, with limited exceptions related to medical or safety reasons. This ban, effective from 2 February 2025, has direct implications for facial analysis, attention detection, stress monitoring, engagement detection and behavioural analysis tools that may be integrated into educational or proctoring platforms.
It does not automatically follow that every online proctoring system is prohibited: it is necessary to examine the functionalities active, the data processed and the declared purpose. A system that merely verifies the identity of the student or detects technical anomalies operates on a different level than one that claims to infer the emotional state of the exam-taker. It is an evaluation that must be carried out on a case-by-case basis, functionality by functionality.
AI and online, blended, and hybrid teaching
For institutions that deliver online or blended programs, the obligations of the AI Act are in addition to, and in some cases are directly intertwined, with the quality standards that the MFHEA applies to this type of provision. In recent years, the MFHEA has progressively refined its requirements in the field of distance learning, with particular attention to the calculation of contact hours, the ratio between synchronous and asynchronous component, the governance of the LMS/VLE platform and the adequacy of the technical and administrative support offered to students. These requirements have also been incorporated into recent publications by the Authority dedicated specifically to the quality of online teaching at higher education level.
It is in this space that AI tools become particularly relevant from a regulatory point of view. A virtual tutor, an engagement analytics system or an online proctoring tool should not only be evaluated in the light of the AI Act, but also with respect to what the institution must in any case demonstrate to the MFHEA: that the interaction between teacher and student is effective and documentable, that the calculation of contact hours is not based on purely automated interactions passed off as teaching assisted by qualified personnel, that the technological platform is governed with clear policies, and that the identity of the student is verified with robust and proportionate methods. An AI system that helps comply with these standards is an ally; one that obfuscates its verifiability, for example because it replaces the required human interaction without adequate transparency, becomes a risk on two fronts at the same time, that of the AI Act and that of accreditation.
As MFHEA requirements on online, blended and hybrid learning are evolving, MQE recommends that you do not assume that a given technology setup is automatically compliant, and that you verify your specific setup, including the AI systems used, directly with the MFHEA or a qualified consultant before consolidating it into a training offering.
The obligations of educational institutions
Regardless of the deferral of the most burdensome obligations due to high risk, a responsible Maltese educational institution should already move on some fronts: role-differentiated training (AI literacy), keeping a register of AI systems actually in use, a first risk classification for each tool, a clear institutional policy, human supervision mechanisms on AI-assisted decisions, continuous monitoring, incident reporting procedures, log management, transparency to students and staff, due diligence on technology providers, data protection and appropriate cybersecurity measures.
One point deserves particular attention: distributing a generic policy or simply forwarding the technology vendor’s manual does not constitute a credible risk management system in the eyes of an external evaluator. A coherent document system is needed, adapted to the specific reality of the institution, and above all applied in daily practice, including the so-called shadow AI, i.e. the use of unauthorized tools by staff or students outside of any formal governance.
Provider e deployer
The AI Act distinguishes between those who develop an AI system and place it on the market (providers) and those who use it as part of their business (deployers). An educational institution that limits itself to using a tool developed by a third party operates, in most cases, as a deployer, with less extensive obligations than those who produce the system.
However, this qualification can change. An institution assumes the role of provider, for example, when it internally develops its own AI tool, markets it under its own brand, substantially modifies its operation, changes its intended purpose from the original one, or integrates it into a proprietary product or service offered to third parties. In such cases, the applicable obligations are considerably broader, and the qualification should be checked on a case-by-case basis before entering into contractual or commercial commitments based on an in-house developed AI tool.
The impact on MFHEA quality procedures
The AI Act does not replace the Maltese regulatory framework in any way: provider licensing, provider accreditation, programme accreditation, Internal Quality Assurance and External Quality Assurance remain governed by Chapter 607, S.L. 607.03 and the standards published by the MFHEA. What changes is that the use of AI becomes, to all intents and purposes, an element to be overseen within that framework, not a separate issue.
The impact potentially extends to a wide number of areas: mission and strategic management, governance, organizational structure, quality management, programme design and learning outcomes, curriculum design, student-centred learning, assessment, academic integrity, teaching staff and related continuous professional development, student support, information management, public information, monitoring and periodic review of programs, risk management and business continuity.
When auditing or renewing accreditation, an institution should be able to produce verifiable evidence, not just declarations of intent. Useful evidence includes: an AI Systems Register, the minutes of the bodies that approved the adoption of each tool, documented risk assessments and vendor assessments, reports of the training activities provided, the history of the versions of the policies adopted, the evaluation moderation logs, the incident log, the complaints received and their management, feedback collected from students and teachers, performance data and, where necessary, corrective action plans and quality improvement plans.
AI, assessment e academic integrity
The use of AI in student assessment deserves a separate discussion, because it is the area where regulatory, academic and reputational risk overlap the most. Certain principles should guide any institution: academic responsibility for evaluation decisions always remains attributed to qualified human personnel; the outputs produced by AI tools must always be verified before being used; rubrics and evaluation criteria must be clearly communicated to students and teachers; there must be effectively accessible moderation and appeal procedures; No disciplinary sanction should be based solely on an algorithmic result.
In particular, AI-generated text automatic detection tools (so-called AI detectors) should not be treated as conclusive evidence per se, given their well-known fallibility, while alerts generated by proctoring systems should always be subjected to human verification before producing consequences for the student. These measures are not just a procedural precaution: they directly affect the validity, reliability, transparency, fairness and authenticity of the assessment, i.e. some of the parameters that the MFHEA evaluates when accrediting the programmes.
What teachers must do
Teachers should limit themselves to the tools authorized by the institution, understand their technical limitations, always verify the outputs before using them in the classroom or during assessment, protect students’ personal data, define clear rules on the use of generative AI by the classroom, redesign assessments taking into account the availability of these tools, distinguish precisely between permitted assistance and improper replacement of student work, and document relevant academic decisions.
What students and users need to do
Students and users of educational services also have an active role: comply with institutional policies, declare the use of AI when required, verify the accuracy of information and sources produced with automated tools, respect copyright and academic integrity, avoid uploading personal or confidential data to unauthorized tools, understand when they are interacting with an automated system rather than with a person, and know the channels available to request a human review of a decision that affects them.
Penalties
Article 99 of the AI Act, which has not been modified in structure by the Digital Omnibus, provides for three levels of administrative sanction. Violations of prohibited practices (Article 5) are punishable by up to €35 million or 7% of the previous year’s annual worldwide turnover, whichever is higher. Violations of operators’ obligations, including those related to high-risk systems, are punishable by up to €15 million or 3% of worldwide turnover. Reporting inaccurate, incomplete or misleading information to the competent authorities is punishable by up to €7.5 million or 1% of worldwide turnover. For small and medium-sized enterprises, the lower of the two applies in each band, and not the higher as for larger companies.
In Malta, the Malta Digital Innovation Authority (MDIA) was designated, by Legal Notice 226 of 2025 (S.L. 591.05, in force from 10 October 2025), as the market surveillance authority and single point of contact for the AI Act, while the Information and Data Protection Commissioner (IDPC) was designated, by Legal Notice 227 of 2025, for high-risk systems involving particular data processing profiles.
In addition to the penalties provided for by the AI Act, an educational institution should consider that incorrect use of AI can generate additional consequences: violations of the GDPR, complaints by students, reputational damage, requests for invalidation or revision of academic decisions, findings during MFHEA audits, conditions imposed on the license or, in the most serious cases, requests for corrective action up to measures on the license itself. This is a risk framework that deserves proportionate attention, without the need for alarmist reactions.
How Malta Quality Education can help
Malta Quality Education supports Maltese universities, Higher Education Institutions, Further Education Institutions and training providers in understanding these requirements, developing the necessary documentation and improving their readiness with respect to the AI Act, GDPR and MFHEA standards.
Among the services available: AI compliance and quality readiness assessment, mapping of AI systems, preliminary risk classification, gap analysis with respect to the AI Act, GDPR and MFHEA requirements, development of governance policies and procedures, human supervision, procurement, vendor due diligence, assessment, academic integrity and incident management; guidelines for staff and students; AI Systems Register; targeted training for governance, QA, faculty, administrative, technicians, and students; updating of the IQA Manual, programme document and role description; preparation of evidence packs and support for licensing, accreditation, EQA audit, corrective action plan and institutional capacity building.
Malta Quality Education does not replace the MFHEA, does not replace the MDIA, does not replace the institution’s Data Protection Officer and does not provide guarantees of approval. Where necessary, MQE directs the client to qualified legal advice.
Request an AI compliance and quality readiness assessment
If your institution is already using AI tools — or considering doing so — a preliminary assessment can help you identify the systems actually in place, the associated risks, missing policies, staff training needs, necessary interventions on internal quality assurance procedures, and priorities for upcoming MFHEA licensing appointments. accreditation or audit.
