The EU AI Act 2028 refers to the milestone year when the European Union's Artificial Intelligence Act (AI Act) reaches full operational enforcement, completing the phased implementation that began after the regulation entered into force on 1 August 2024. The AI Act is a comprehensive regulation establishing a common regulatory and legal framework for Artificial intelligence within the EU, covering most AI systems across a wide range of sectors. It classifies non-exempt AI applications by their risk of causing harm into four levels - unacceptable, high, limited, and minimal - plus an additional category for general-purpose AI. As a form of product regulation, it does not create individual rights but places duties on AI providers and organisations that use AI in a professional context.
The Act was proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. The draft was revised to address the rise of Generative AI systems such as ChatGPT, whose general-purpose capabilities did not fit the main framework. By 2028, all provisions, including those for high-risk applications and general-purpose AI models, are scheduled to be fully applicable, with the European Artificial Intelligence Board overseeing national cooperation and compliance.
Risk Categories and Obligations
The AI Act's risk-based scheme follows a product-safety model. Applications with unacceptable risks are banned, except for specific exemptions, including AI that manipulates human behaviour, real-time remote biometric identification in public spaces, and social scoring. High-risk applications - those posing significant threats to health, safety, or fundamental rights, such as in health, education, recruitment, critical infrastructure, law enforcement, or justice - must comply with security, transparency, and quality obligations, and undergo conformity assessments. Some require a Fundamental Rights Impact Assessment before deployment, an ex ante review to identify and mitigate potential impacts on fundamental rights. These systems must be evaluated before market placement and throughout their life cycle, and citizens have the right to submit complaints and receive explanations of decisions made by high-risk AI affecting their rights.
Limited-risk systems, such as deepfake generators, have transparency obligations ensuring users know they interact with AI. Minimal-risk applications, like video games or spam filters, are not regulated, and member states cannot impose additional regulations due to maximum harmonisation rules. The list of high-risk applications can be expanded over time without modifying the Act itself.
General-Purpose AI and Foundation Models
Added in 2023, the general-purpose AI category includes foundation models like large language models that perform a wide range of tasks. If a model's weights and design are open source, developers must publish a training data summary and a copyright policy; closed-source models face broader transparency requirements. High-impact models posing systemic risks - requiring more than 10^25 floating-point operations to train - must undergo extra evaluation. The General-Purpose AI Code of Practice, published on 10 July 2025, outlines chapters on transparency, copyright, and safety and security to help providers demonstrate compliance, with voluntary participation. Providers of general-purpose AI models must publish training data summaries, adopt copyright policies, and provide technical documentation to downstream providers and authorities. Models designated as posing systemic risk must carry out model evaluations, adversarial testing, assess and mitigate risks like bias and security failures, report serious incidents, and ensure adequate cybersecurity.
Exemptions and Extraterritoriality
Articles 2.3 and 2.6 exempt AI systems used exclusively for military, defence, or national security purposes, as well as pure scientific research and development, from the AI Act. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU. This means companies based in the United States, Asia, or elsewhere must comply when offering AI services to EU residents, regardless of where the systems are developed.
Enforcement Timeline and 2028 Milestones
The regulation entered into force on 1 August 2024, with provisions coming into operation gradually over 6 to 36 months. By 2028, the final tranche of obligations becomes effective, particularly for high-risk AI systems in sectors like healthcare, education, and law enforcement. The European Artificial Intelligence Board, created by the Act, plays a central role in promoting national cooperation and ensuring uniform compliance across member states. National supervisory authorities are expected to have established conformity assessment procedures, and providers must have completed certifications for their high-risk systems. The 2028 milestone also marks the point where the Act's full enforcement machinery, including penalties for non-compliance, is operational across all categories.
Impact on AI Development and Deployment
The full enforcement in 2028 affects a wide ecosystem of AI developers and deployers. Companies like OpenAI, Anthropic, and Google DeepMind that produce general-purpose models must comply with transparency and evaluation requirements if their models are used in the EU. Hardware providers such as NVIDIA (though not listed, implied by ecosystem) and AMD may see indirect effects as their chips power models subject to systemic risk assessments. Cloud service providers like Amazon Web Services, Microsoft Azure, and Google Cloud must ensure their AI offerings meet the Act's standards. Research institutions, including MIT CSAIL, Stanford AI Lab, and BAIR (Berkeley AI Research), are affected when their models are deployed commercially in the EU, though pure research is exempt. The Act's emphasis on transparency and risk mitigation aligns with technical practices such as Model Pruning, Data Augmentation, and reinforcement learning from AI feedback, which can help demonstrate compliance.
Compliance Challenges and Industry Response
As of 2028, many organisations face significant compliance challenges. High-risk AI systems require rigorous documentation, human oversight mechanisms, and continuous monitoring. The Fundamental Rights Impact Assessment process, informed by earlier work on algorithmic impact assessments, requires identifying affected communities, describing possible harms, and providing a basis for public scrutiny. For general-purpose models, the 10^25 floating-point operations threshold for systemic risk designation captures the largest models, such as those trained by major labs. The voluntary code of practice, while not mandatory, provides a structured approach for providers to demonstrate compliance, covering transparency, copyright, and safety. Industry responses have included developing internal governance frameworks, investing in evaluation tools, and engaging with the European Artificial Intelligence Board. Some smaller providers, particularly those offering open-source models, benefit from reduced requirements, but must still publish training data summaries and copyright policies.
Broader Implications for Global AI Governance
The EU AI Act 2028 serves as a benchmark for AI regulation worldwide. Its risk-based approach and extraterritorial application influence policy discussions in other jurisdictions, including the United States and Asia. The Act's distinction between open-source and closed-source models has sparked debate about innovation versus safety, with some arguing that open-source transparency requirements are insufficient while others see them as a balanced approach. The 2028 enforcement also coincides with advances in Machine learning and Deep learning, including developments in Transformer (architecture) architectures and Multi-Head Attention mechanisms, which may introduce new capabilities not fully anticipated by the regulatory framework. The Act's provisions for updating the high-risk list and adapting to technological change are designed to address such evolutions, but their effectiveness will depend on the European Artificial Intelligence Board's responsiveness. As of 2028, the full impact of the Act on AI innovation, market competition, and fundamental rights protection remains an ongoing subject of analysis among legal scholars, technologists, and policymakers.
Future Outlook
Looking beyond 2028, the AI Act is expected to evolve as AI technologies advance. The European Commission may propose amendments to address emerging areas such as neural network interpretability, large language model alignment, or AI in autonomous systems like autonomous vehicles. The Act's maximum harmonisation provisions prevent member states from imposing additional regulations on minimal-risk systems, but allow for expansion of the high-risk list. The General-Purpose AI Code of Practice may be updated to reflect new technical standards and best practices. The 2028 milestone thus represents not an endpoint but a foundation for ongoing regulatory adaptation, with the EU positioning itself as a global leader in AI governance. The interplay between the Act and other EU regulations, such as data protection and digital services, will continue to shape the compliance landscape for AI providers and deployers within and outside the EU.