Answer guide

"Fill in our HECVAT" — the AI questions in higher-education vendor assessments

A college or university is evaluating your product, and the request lands: "please complete our HECVAT." Here is what you have received, how to answer its AI questions, and the one line edtech vendors must not cross.

What a HECVAT is and who sends it

The HECVAT — Higher Education Community Vendor Assessment Toolkit — is the standard vendor-risk questionnaire of the higher-education sector, maintained by EDUCAUSE. It usually arrives from the institution's information-security office or procurement, forwarded by the person on campus who wants your product. It comes in tiers (full for services handling sensitive institutional data, lighter for lower-risk services); check which edition and tier you were sent — the triage in the first-24-hours playbook applies unchanged.

One property raises the stakes: as a community standard, a completed HECVAT circulates — the document you fill in for one institution is often shared with, or accepted by, the next. You are writing your security narrative for a whole sector; overstated answers do not stay contained in one deal.

The AI questions to expect

Whether they sit inside the toolkit itself or arrive as a supplemental sheet, the AI questions track what buyers typically ask AI vendors: an inventory of AI systems and features; model provenance (provider, version, purpose, fine-tuning, processing region); AI subprocessors; data flows into models; whether institutional data trains models; output controls; and documented governance evidence, typically around 90 days of it. The full method is in how to answer the AI section; two answers deserve extra care:

Mind the role trap: if you ship a third-party model under your own name or trademark, you are the provider of the resulting system, so the Article 50(1) duty to inform users they are interacting with an AI system is yours — unless that is obvious to a person who is "reasonably well-informed, observant and circumspect". Article 50 applies from 2 August 2026 (the Digital Omnibus did not postpone it); machine-readable marking under Article 50(2) has a transition until 2 December 2026 for systems already on the market. The free Article 50 checker maps your duties in six questions.

The hard line for edtech: emotion inference is prohibited, not disclosable

Most AI-questionnaire findings are fixable with transparency: disclose the chatbot, mark the synthetic content, document the gap. One is not. Article 5(1)(f) of Regulation (EU) 2024/1689 prohibits placing on the market, putting into service or using AI systems "to infer emotions of a natural person in the areas of workplace and education institutions", except where the system is intended for medical or safety reasons. It is one of the Regulation's outright prohibitions, applicable since 2 February 2025 — eighteen months before the Article 50 transparency rules.

ProvisionWhat it coversApplies fromConsequence
Art. 5(1)(f)AI systems that infer emotions of a natural person in workplace and education institutions (exception: medical or safety reasons)2 Feb 2025Prohibited practice — Art. 99(3): up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher; SMEs and startups: the lower (Art. 99(6))
Art. 50(3)Transparency: informing people exposed to an emotion-recognition system, in contexts where such systems remain lawful2 Aug 2026Transparency duty of the deployer — Art. 99(4)(g): up to €15,000,000 or 3%, whichever is higher; SMEs and startups: the lower

Article 50(3) is a disclosure duty for emotion-recognition systems where they are allowed; in an education institution, the prohibition comes first. An edtech product that infers students' or staff's emotions — affect analytics in a learning platform, emotion-reading proctoring — is not carrying a transparency gap: it is describing a prohibited practice, and no notice or consent banner cures that. If that is your territory and you touch the EU market, stop drafting and take legal advice — this is beyond what any questionnaire service should paper over, ours included.

Answering it well

Because HECVATs get reused, consistency errors multiply: a contradiction between your HECVAT and your website, or between this year's and last year's version, will eventually sit in front of the same reviewer. One person owns the canonical answer set. Gaps go in the format procurement accepts: current state, compensating control, "in progress", and a target date someone in your company actually approved. Never invent a control to make a cell green.

Mini-FAQ

Does the EU AI Act matter if the university is in the US?

The HECVAT is a US higher-ed instrument and the AI Act is EU law — but the AI questions appear anyway, because they serve as a gauge of AI governance in general. The Regulation reaches non-EU vendors that place an AI system on the EU market or whose output is used in the EU. Answer about your actual exposure — the map is in the US-vendor guide.

Our product measures student engagement — is that emotion inference?

It depends on what the system infers. Activity metrics — logins, submissions, time on task — are not emotion inference; reading affect, attention or frustration from faces, voice or behaviour may be. If there is any doubt, take legal advice before answering; do not resolve it with a disclosure.

Can we reuse a HECVAT completed for another university?

Often yes — that is part of the design, and the reason accuracy compounds. Keep one canonical version, refresh dates and facts before each reuse, and check the AI answers still match the product.

Related: who owes what under Article 50, and all answer guides for the rest of the document.

A HECVAT is blocking your campus deal right now?

Send it — first 3 answers free within 24h, full delivery in 48h for $490 flat up to 60 questions, paid after delivery. Every legal claim cited to its article. Judge the work on the public sample first.

Send your questionnaire →