← All researchComparative governance analysis · ICHORA 2026 · IEEE
From post-hoc regulation to runtime governance
Mirka Saarela & Prashanth Shenoy · Faculty of Information Technology, University of Jyväskylä
High-risk
how the Act classifies educational AI that determines access, evaluation or progression
Art. 14
human oversight becomes a design obligation, not a policy statement
Banned
emotion inference in educational settings, under Recital 31(f)
3
points in a system's life where a safeguard can actually bite
The argument in six slides
01 / 06
Two different things are now called AI governance
One is external regulation: an authority sets rules, a system is certified against
them before it goes to market, and it is audited afterwards.
The other is ethical constraint built into how a model behaves while it is running,
shaping what it says and refuses to say in the moment.
Both are called governance. They do not govern the same thing, and they do
not govern at the same time.
02 / 06
The useful question is when the constraint bites
Fairness research already sorts interventions by stage: pre-processing
fixes the data, in-processing changes the learning, post-processing
adjusts the output after the fact.
Explainability sorts the same way: intrinsic (interpretable by design),
in-hoc (reading the model during inference), post-hoc
(an external explainer applied to a decision already made).
Read that way, an argument about explainability stops being technical. It is an
argument about when a commitment should take effect.
03 / 06
What the Act actually does to a school
The EU AI Act is risk-based, and it puts educational AI that determines access,
evaluation or progression in the high-risk category. That is not a
niche classification; it covers admissions screening, assessment, placement and
exam monitoring.
Providers must run risk management, meet data governance standards, keep technical
documentation, and enable human oversight. Article 14 requires
systems be built so a person can effectively oversee them. Conformity assessment
and post-market monitoring extend accountability past launch.
And some things are simply prohibited: inferring emotions in an educational setting
is banned outright.
04 / 06
The other paradigm governs at runtime
Some developers now publish structured normative commitments intended to shape the
model's behaviour during training and deployment. Anthropic's constitution for
Claude is the worked example in this paper.
It instructs the model to be transparent, not pursuing hidden agendas or
misrepresenting its own reasoning, and forthright, volunteering what a user
would want in order to judge for themselves.
That relocates explainability. It stops being a document produced
for an auditor and becomes a property of the conversation a student is having.
05 / 06
Each one has a hole the other fills
Regulation carries democratic legitimacy and real sanction, but it concentrates at
certification and audit. Training data selection, architecture and inference
constraints sit between those moments and are comparatively undergoverned.
Design-embedded constraints operate exactly there, continuously and portably across
jurisdictions. But they are authored by the developer. There is no public
authorisation, and no enforceable penalty for changing them.
06 / 06
Three questions worth asking your vendor
Which of the things we use this system for fall inside the high-risk category, and who has written that down?
For each safeguard you have described, at what point in the system's life does it actually take effect: before release, while it is running, or only when someone audits it?
Who authored the constraints that operate at runtime, and what happens, to us, if they change them?
Compliance and design are not alternatives. Concentrating everything at audit reduces
governance to paperwork; relying only on a vendor's constitution privatises the rules.
PS
Swipe, or use ← →
The two logics, side by side
Regulatory
Design-embedded
Purpose
Compliance, accountability, auditability
Understanding, trust, interaction
When it acts
Post-hoc or periodic
Runtime, at the interaction
Enforcement
External oversight, documentation
Internal behavioural constraint
Audience
Regulators, auditors, institutions
Learners, educators, end users
The user is
A recipient of explanations
A participant in the explanation
Explainability under external regulation compared with design-embedded ethical frameworks.
Why the comparison is not just European
Regulatory strategies differ by jurisdiction. The United States has proceeded through
executive guidance, agency standards and sector-specific initiatives rather than a
single statute. China emphasises algorithmic registration, security review and
content obligations for generative systems. UNESCO has articulated global ethical
principles grounded in human rights and accountability.
What these converge on is instructive: documentation, auditing, risk assessment and
institutional oversight. The instruments differ; the temporal position does not. All
of them concentrate their force outside the model, before release and after deployment.
Educational AI, meanwhile, has become transnational. A model developed under one
regulatory regime is delivered through cloud services into classrooms governed by
another. The paper draws the parallel with commercial aviation, where nobody seriously
argues that safety oversight can remain local and discretionary once the aircraft
crosses borders.
What changes as systems become more autonomous
The paper traces a ladder. Human-led instruction, where AI is minimal. AI-assisted
systems offering decision support and analytics. AI-integrated systems generating
automated feedback and adaptive responses. Then agentic systems that initiate actions
and coordinate workflows.
The human role shifts at every rung: from performing the instructional task, to
supervising it, to validating outputs, to governing and allocating authority. Governance
is not an administrative layer bolted on top of that progression. It is what the human
job becomes.
A note on what this paper is and is not. It is a conceptual and comparative analysis,
not an empirical study and not legal advice. It reads two governance paradigms against
each other to show that they operate at different points in a system's life. An
institution deciding its actual obligations under the Act needs counsel, not a
conference paper.
Citation
Saarela, M., & Shenoy, P. (2026). From post-hoc regulation to runtime governance: Ethics and explainability in AI-driven education. In 2026 8th International Congress on Human-Computer Interaction, Optimization and Robotic Applications (ICHORA) (pp. 1–9). IEEE.
Sessions and seminars on this work usually run to about ninety minutes. The shape of
one is set after a training needs analysis with the school or organisation's own
leadership, never before it.