← All research Comparative governance analysis · ICHORA 2026 · IEEE

From post-hoc regulation to runtime governance

Mirka Saarela & Prashanth Shenoy · Faculty of Information Technology, University of Jyväskylä

High-risk

how the Act classifies educational AI that determines access, evaluation or progression

Art. 14

human oversight becomes a design obligation, not a policy statement

Banned

emotion inference in educational settings, under Recital 31(f)

3

points in a system's life where a safeguard can actually bite

The argument in six slides
01 / 06

Two different things are now called AI governance

One is external regulation: an authority sets rules, a system is certified against them before it goes to market, and it is audited afterwards.

The other is ethical constraint built into how a model behaves while it is running, shaping what it says and refuses to say in the moment.

Both are called governance. They do not govern the same thing, and they do not govern at the same time.

02 / 06

The useful question is when the constraint bites

Fairness research already sorts interventions by stage: pre-processing fixes the data, in-processing changes the learning, post-processing adjusts the output after the fact.

Explainability sorts the same way: intrinsic (interpretable by design), in-hoc (reading the model during inference), post-hoc (an external explainer applied to a decision already made).

Read that way, an argument about explainability stops being technical. It is an argument about when a commitment should take effect.

03 / 06

What the Act actually does to a school

The EU AI Act is risk-based, and it puts educational AI that determines access, evaluation or progression in the high-risk category. That is not a niche classification; it covers admissions screening, assessment, placement and exam monitoring.

Providers must run risk management, meet data governance standards, keep technical documentation, and enable human oversight. Article 14 requires systems be built so a person can effectively oversee them. Conformity assessment and post-market monitoring extend accountability past launch.

And some things are simply prohibited: inferring emotions in an educational setting is banned outright.

04 / 06

The other paradigm governs at runtime

Some developers now publish structured normative commitments intended to shape the model's behaviour during training and deployment. Anthropic's constitution for Claude is the worked example in this paper.

It instructs the model to be transparent, not pursuing hidden agendas or misrepresenting its own reasoning, and forthright, volunteering what a user would want in order to judge for themselves.

That relocates explainability. It stops being a document produced for an auditor and becomes a property of the conversation a student is having.

05 / 06

Each one has a hole the other fills

Regulation carries democratic legitimacy and real sanction, but it concentrates at certification and audit. Training data selection, architecture and inference constraints sit between those moments and are comparatively undergoverned.

Design-embedded constraints operate exactly there, continuously and portably across jurisdictions. But they are authored by the developer. There is no public authorisation, and no enforceable penalty for changing them.

REGULATORY GOVERNANCE Ex-ante conformity Audit, monitoring little regulatory purchase here Design & training Runtime & interaction Deployment & audit DESIGN-EMBEDDED GOVERNANCE Runtime constraints
06 / 06

Three questions worth asking your vendor

  1. Which of the things we use this system for fall inside the high-risk category, and who has written that down?
  2. For each safeguard you have described, at what point in the system's life does it actually take effect: before release, while it is running, or only when someone audits it?
  3. Who authored the constraints that operate at runtime, and what happens, to us, if they change them?

Compliance and design are not alternatives. Concentrating everything at audit reduces governance to paperwork; relying only on a vendor's constitution privatises the rules.

PS

Swipe, or use ← →

The two logics, side by side

Regulatory Design-embedded
Purpose Compliance, accountability, auditability Understanding, trust, interaction
When it acts Post-hoc or periodic Runtime, at the interaction
Enforcement External oversight, documentation Internal behavioural constraint
Audience Regulators, auditors, institutions Learners, educators, end users
The user is A recipient of explanations A participant in the explanation
Explainability under external regulation compared with design-embedded ethical frameworks.

Why the comparison is not just European

Regulatory strategies differ by jurisdiction. The United States has proceeded through executive guidance, agency standards and sector-specific initiatives rather than a single statute. China emphasises algorithmic registration, security review and content obligations for generative systems. UNESCO has articulated global ethical principles grounded in human rights and accountability.

What these converge on is instructive: documentation, auditing, risk assessment and institutional oversight. The instruments differ; the temporal position does not. All of them concentrate their force outside the model, before release and after deployment.

Educational AI, meanwhile, has become transnational. A model developed under one regulatory regime is delivered through cloud services into classrooms governed by another. The paper draws the parallel with commercial aviation, where nobody seriously argues that safety oversight can remain local and discretionary once the aircraft crosses borders.

What changes as systems become more autonomous

The paper traces a ladder. Human-led instruction, where AI is minimal. AI-assisted systems offering decision support and analytics. AI-integrated systems generating automated feedback and adaptive responses. Then agentic systems that initiate actions and coordinate workflows.

The human role shifts at every rung: from performing the instructional task, to supervising it, to validating outputs, to governing and allocating authority. Governance is not an administrative layer bolted on top of that progression. It is what the human job becomes.

A note on what this paper is and is not. It is a conceptual and comparative analysis, not an empirical study and not legal advice. It reads two governance paradigms against each other to show that they operate at different points in a system's life. An institution deciding its actual obligations under the Act needs counsel, not a conference paper.

Citation

Saarela, M., & Shenoy, P. (2026). From post-hoc regulation to runtime governance: Ethics and explainability in AI-driven education. In 2026 8th International Congress on Human-Computer Interaction, Optimization and Robotic Applications (ICHORA) (pp. 1–9). IEEE.

Contact

Ask about any of this

Sessions and seminars on this work usually run to about ninety minutes. The shape of one is set after a training needs analysis with the school or organisation's own leadership, never before it.

Email prshenoy@jyu.fi University of Jyväskylä
WhatsApp Finland · UTC+2