"Fill in our HECVAT" — the AI questions in higher-education vendor assessments
A college or university is evaluating your product, and the request lands: "please complete our HECVAT." Here is what you have received, how to answer its AI questions, and the one line edtech vendors must not cross.
What a HECVAT is and who sends it
The HECVAT — Higher Education Community Vendor Assessment Toolkit — is the standard vendor-risk questionnaire of the higher-education sector, maintained by EDUCAUSE. It usually arrives from the institution's information-security office or procurement, forwarded by the person on campus who wants your product. It comes in tiers (full for services handling sensitive institutional data, lighter for lower-risk services); check which edition and tier you were sent — the triage in the first-24-hours playbook applies unchanged.
One property raises the stakes: as a community standard, a completed HECVAT circulates — the document you fill in for one institution is often shared with, or accepted by, the next. You are writing your security narrative for a whole sector; overstated answers do not stay contained in one deal.
The AI questions to expect
Whether they sit inside the toolkit itself or arrive as a supplemental sheet, the AI questions track what buyers typically ask AI vendors: an inventory of AI systems and features; model provenance (provider, version, purpose, fine-tuning, processing region); AI subprocessors; data flows into models; whether institutional data trains models; output controls; and documented governance evidence, typically around 90 days of it. The full method is in how to answer the AI section; two answers deserve extra care:
- "Is our data used to train your models?" Answer from the model provider's current data-processing agreement, verified before you write — not from memory — plus your own policy. Details: the training-data question.
- "Are you compliant with the EU AI Act?" Never a bare yes. Classification, applicable obligations, status per obligation, gaps with a plan — the four-part structure.
Mind the role trap: if you ship a third-party model under your own name or trademark, you are the provider of the resulting system, so the Article 50(1) duty to inform users they are interacting with an AI system is yours — unless that is obvious to a person who is "reasonably well-informed, observant and circumspect". Article 50 applies from 2 August 2026 (the Digital Omnibus did not postpone it); machine-readable marking under Article 50(2) has a transition until 2 December 2026 for systems already on the market. The free Article 50 checker maps your duties in six questions.
The hard line for edtech: emotion inference is prohibited, not disclosable
Most AI-questionnaire findings are fixable with transparency: disclose the chatbot, mark the synthetic content, document the gap. One is not. Article 5(1)(f) of Regulation (EU) 2024/1689 prohibits placing on the market, putting into service or using AI systems "to infer emotions of a natural person in the areas of workplace and education institutions", except where the system is intended for medical or safety reasons. It is one of the Regulation's outright prohibitions, applicable since 2 February 2025 — eighteen months before the Article 50 transparency rules.
| Provision | What it covers | Applies from | Consequence |
|---|---|---|---|
| Art. 5(1)(f) | AI systems that infer emotions of a natural person in workplace and education institutions (exception: medical or safety reasons) | 2 Feb 2025 | Prohibited practice — Art. 99(3): up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher; SMEs and startups: the lower (Art. 99(6)) |
| Art. 50(3) | Transparency: informing people exposed to an emotion-recognition system, in contexts where such systems remain lawful | 2 Aug 2026 | Transparency duty of the deployer — Art. 99(4)(g): up to €15,000,000 or 3%, whichever is higher; SMEs and startups: the lower |
Article 50(3) is a disclosure duty for emotion-recognition systems where they are allowed; in an education institution, the prohibition comes first. An edtech product that infers students' or staff's emotions — affect analytics in a learning platform, emotion-reading proctoring — is not carrying a transparency gap: it is describing a prohibited practice, and no notice or consent banner cures that. If that is your territory and you touch the EU market, stop drafting and take legal advice — this is beyond what any questionnaire service should paper over, ours included.
Answering it well
Because HECVATs get reused, consistency errors multiply: a contradiction between your HECVAT and your website, or between this year's and last year's version, will eventually sit in front of the same reviewer. One person owns the canonical answer set. Gaps go in the format procurement accepts: current state, compensating control, "in progress", and a target date someone in your company actually approved. Never invent a control to make a cell green.
Mini-FAQ
Does the EU AI Act matter if the university is in the US?
The HECVAT is a US higher-ed instrument and the AI Act is EU law — but the AI questions appear anyway, because they serve as a gauge of AI governance in general. The Regulation reaches non-EU vendors that place an AI system on the EU market or whose output is used in the EU. Answer about your actual exposure — the map is in the US-vendor guide.
Our product measures student engagement — is that emotion inference?
It depends on what the system infers. Activity metrics — logins, submissions, time on task — are not emotion inference; reading affect, attention or frustration from faces, voice or behaviour may be. If there is any doubt, take legal advice before answering; do not resolve it with a disclosure.
Can we reuse a HECVAT completed for another university?
Often yes — that is part of the design, and the reason accuracy compounds. Keep one canonical version, refresh dates and facts before each reuse, and check the AI answers still match the product.
Related: who owes what under Article 50, and all answer guides for the rest of the document.