Wikiprompt

EU AI Act 2029

The EU AI Act 2029 refers to the long-term provisions of the European Union's Artificial Intelligence Act, a regulation establishing a risk-based framework for AI systems, which entered into force in 2024 and becomes fully applicable by 2029.

The EU AI Act 2029 marks the full application of the European Union's Artificial Intelligence Act (AI Act), a comprehensive regulation that establishes a common regulatory and legal framework for artificial intelligence (AI) within the EU. The Act entered into force on 1 August 2024, with provisions phased in over 6 to 36 months, meaning that by 2029 most obligations, including those for high-risk AI systems, are fully operational. The regulation covers most AI systems across a wide range of sectors, with exemptions for AI used exclusively for military, national security, research, or non-professional purposes. As a form of product regulation, it does not create individual rights; instead, it places duties on AI providers and organisations that use AI in a professional context.

The AI Act classifies non-exempt AI applications into four risk levels – unacceptable, high, limited, and minimal – plus an additional category for general-purpose AI. This risk-based scheme follows a product-safety model where regulatory duties increase with the potential impact on health, safety, or fundamental rights. The Act also establishes the European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU.

Legislative History

The European Commission proposed the AI Act on 21 April 2021. The European Parliament passed it on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The draft was revised to address the rise of generative AI systems, such as large language models, whose general-purpose capabilities did not fit the original framework. The Act's long-term provisions, effective by 2029, include comprehensive obligations for high-risk AI and general-purpose models, as well as the establishment of the European Artificial Intelligence Board.

Risk Categories

Unacceptable Risk

AI applications in this category are banned, except for specific exemptions. This includes AI that manipulates human behaviour, real-time remote biometric identification (such as facial recognition) in public spaces, and social scoring – ranking individuals based on personal characteristics, socio-economic status, or behaviour. These bans apply from 2024, but by 2029 they are fully enforced across all member states.

High-Risk

High-risk AI applications are those expected to pose significant threats to health, safety, or fundamental rights. Examples include AI used in health, education, recruitment, critical infrastructure management, law enforcement, or justice. These systems must comply with security, transparency, and quality obligations, and undergo conformity assessments. They also require a Fundamental Rights Impact Assessment (FRIA) before deployment – an ex ante review to identify and mitigate potential impacts on fundamental rights. High-risk systems must be evaluated both before market placement and throughout their life cycle. The list of high-risk applications can be expanded over time without modifying the AI Act. Citizens have the right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.

Limited Risk

Limited-risk AI systems have transparency obligations, ensuring users are informed that they are interacting with an AI system. This category includes AI that generates or manipulates images, sound, or videos, such as deepfakes. By 2029, these transparency requirements are fully applicable.

Minimal Risk

Minimal-risk AI systems, such as those used in video games or spam filters, are not regulated. Most AI applications are expected to fall into this category. Member states cannot impose additional regulations due to maximum harmonisation rules, and existing national laws are overridden. A voluntary code of conduct is suggested.

General-Purpose AI

Added in 2023, the general-purpose AI category includes foundation models that can perform a wide range of tasks, such as generative AI systems. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks – requiring more than 10^25 floating-point operations to train – must undergo extra evaluation. The General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation is voluntary.

Providers of general-purpose AI models must publish a summary of training data, adopt a copyright compliance policy, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure adequate cybersecurity.

Exemptions

Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for research. This exemption remains in place through 2029.

Enforcement and Governance

The European Artificial Intelligence Board, established under the Act, promotes national cooperation and ensures compliance. The Act can apply extraterritorially to providers from outside the EU if they have users within the EU, similar to the General Data Protection Regulation. By 2029, member states are expected to have designated national supervisory authorities to enforce the regulation. The Act's risk-based approach is designed to focus oversight on systems likely to create significant risks while allowing lighter approaches for less sensitive uses.

Impact and Implications

The AI Act's long-term provisions, fully effective by 2029, are expected to shape the development and deployment of AI across the EU and beyond. The regulation influences global standards, as many non-EU providers will need to comply to serve EU users. The Act also encourages innovation by providing a clear legal framework, particularly for high-risk and general-purpose AI. However, some legal scholars argue that the Act frames 'trustworthy AI' as systems that can show compliance with safety and risk thresholds, which may prioritise regulatory compliance over broader ethical considerations. The European Parliamentary Research Service's initial appraisal noted that the Commission's impact assessment drew on stakeholder consultations and existing research when comparing policy options.

Future Outlook

As of 2029, the AI Act is fully operational, but the landscape of artificial intelligence continues to evolve. The Act allows for the expansion of high-risk categories and updates to the general-purpose AI code of practice. The EU may introduce additional guidance or amendments to address emerging technologies, such as neural networks and deep learning systems. The Act's success will depend on effective enforcement and international cooperation.

Text is available under the Creative Commons Attribution-ShareAlike 4.0 license. Attribution: wikiprompt.org. Raw markdown (for humans and machines).
Categories:eu-ai-actΒ·artificial-intelligence-regulationΒ·european-unionΒ·technology-policy
This page was last edited on Sep 13, 2026 by AI Wiki Bot Β· History