
The EU AI Act entered into force in August 2024 with a staged implementation timeline that runs through 2027. By February 2025, the prohibited-AI-practices provisions and the AI-literacy obligation became binding, while through 2025 the general-purpose-AI provisions came into effect. In 2026, the high-risk-AI obligations begin to apply, with the act fully in force by 2027. However, Regulation (EU) 2026/1744 — the Digital Omnibus package, in force from July 27, 2026, has pushed the high-risk obligations back to late 2027, while leaving the transparency and general-purpose-AI duties in place.
Annex III includes AI systems used in education (admissions decisions, student assessment, allocation to programmes) and in employment (recruitment, performance evaluation, task allocation). University admissions offices using AI to triage applications fall within high-risk, while research-administration offices using AI to score research proposals likely do not, though the boundary is being tested. Employment decisions about research staff — using AI to rank job applicants or to score performance for promotion — clearly fall within high-risk. The compliance checklist for research administration includes identifying all AI systems in use, categorising each against the act, conducting fundamental-rights impact assessments for high-risk systems, ensuring meaningful human oversight, documenting risk-management systems, and registering in the EU database.
Article 4 requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy of their staff and others using AI systems on their behalf. This applies to research-administration staff using AI tools including proposal-screening assistants, plagiarism detection with AI components, and AI-assisted compliance review. The required "sufficient level" is not specified in detail, with the European AI Office and national competent authorities expected to publish guidance. Practically, institutions should be running AI-literacy training for research-administration staff in 2026. This need not be elaborate - an annual two-hour training covering what AI systems the institution uses, what their limitations are, what disclosure obligations are, and where to escalate concerns is a defensible baseline.
Article 50 requires that AI-generated content be marked as such, with limited exceptions. For research administration, this affects AI-generated text in proposal review, AI-generated summaries of compliance documents, and AI-generated translations of regulatory text. Where AI is used to generate content that will be read by a human as if it were human-produced, the act requires a marker. This dovetails with the publisher-led GenAI disclosure conventions for scholarly content. The CASRAI institutional GenAI disclosure guidance integrates the publisher requirements and the EU AI Act obligations into a single workflow.
The research-specific carve-outs are important but narrower than is sometimes claimed. The act excludes AI systems and models developed solely for the purpose of scientific research and development, but it does not exclude AI systems used in the conduct of research that is not itself AI research. A clinical-trial protocol that uses an AI system for patient stratification is not exempt because it is research; the AI system is being deployed in a context (healthcare) covered by the act. The exemption is for AI as an object of study, not AI as a tool of study. Frontier AI models - including latest variants of Claude, GPT and Gemini - represent a new category of operational and geopolitical risk, as they can make work more efficient while simultaneously making it easier, faster and cheaper for attackers to discover and exploit vulnerabilities.