The EU AI Act 2031 denotes the scheduled review and potential revision of the Artificial Intelligence Act, a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence. The original Act entered into force on 1 August 2024, with provisions coming into operation gradually over the following 6 to 36 months. The post-2030 review, anticipated under the Act's own provisions, aims to assess the regulation's effectiveness, adapt to technological developments, and address emerging challenges in the AI landscape.
The review process is expected to examine how the risk-based classification system has functioned in practice, particularly for high-risk applications and general-purpose AI models. It will also consider whether the Act's extraterritorial application, which affects providers from outside the EU if they have users within the EU, has achieved its intended harmonization effects.
Background and Legislative History
The European Commission proposed the AI Act on 21 April 2021. The European Parliament passed it on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The draft Act was revised during negotiations to address the rise in popularity of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework. This revision added a dedicated category for general-purpose AI, including foundation models that can perform a wide range of tasks.
The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the Act can apply extraterritorially to providers from outside the EU if they have users within the EU. The regulation covers most AI systems across a wide range of sectors, with exemptions for AI used only for military, national security, research purposes, or for non-professional use.
Risk Classification Framework
The Act classifies non-exempt AI applications by their risk of causing harm, with four levels - unacceptable, high, limited, and minimal - plus an additional category for general-purpose AI. Applications with unacceptable risks are banned, except for specific exemptions. This includes AI applications that manipulate human behaviour, those that use real-time remote biometric identification in public spaces, and those used for social scoring.
High-risk applications must comply with security, transparency, and quality obligations, and undergo conformity assessments. These include AI systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice. They must be evaluated both before they are placed on the market and throughout their life cycle. Citizens have the right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.
Limited-risk applications only have transparency obligations, ensuring users are informed that they are interacting with an AI system. This category includes AI applications that generate or manipulate images, sound, or videos, such as deepfakes. Minimal-risk applications, such as AI systems used for video games or spam filters, are not regulated, and Member States cannot impose additional regulations due to maximum harmonisation rules.
General-Purpose AI Provisions
Added in 2023, the general-purpose AI category includes foundation models that can perform a wide range of tasks. If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy. Closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks, requiring more than 1025 floating-point operations to train, must undergo extra evaluation.
The Act sets a common list of obligations for providers of general-purpose AI models. They must publish a summary of the training data, adopt a policy to comply with copyright law, and provide technical documentation to downstream providers and supervisory authorities. Models designated as posing systemic risk must also carry out model evaluations and adversarial testing, assess and mitigate risks such as bias and security failures, report serious incidents, and ensure an adequate level of cybersecurity.
A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance with the AI Act. Participation in the code is voluntary. The code is expected to be a key reference point during the post-2030 review, as it provides practical guidance for implementing the Act's general-purpose AI obligations.
Exemptions and Scope
Articles 2.3 and 2.6 exempt AI systems used for military or national security purposes or pure scientific research and development from the AI Act. The Regulation does not apply where AI systems are used exclusively for military, defence, or national security purposes, or to systems developed and put into service solely for research purposes. Non-professional use is also exempt.
As a form of product regulation, the Act does not create individual rights. Instead, it places duties on AI providers and on organisations that use AI in a professional context. This product-safety model assigns regulatory duties to providers and deployers, with duties becoming more demanding as the potential impact on health, safety, or fundamental rights increases.
Implementation Timeline
The Act's provisions come into operation gradually over 6 to 36 months from its entry into force on 1 August 2024. The first prohibitions on unacceptable-risk applications took effect earlier, while high-risk obligations are being phased in over a longer period. The post-2030 review is scheduled to assess the full implementation and consider adjustments based on practical experience.
The European Parliamentary Research Service provided an initial appraisal of the Commission's impact assessment, noting that it drew on stakeholder consultations and a wide range of existing research when comparing policy options for the risk-based framework. This assessment is likely to inform the post-2030 review process.
Anticipated Review Areas
The post-2030 review is expected to address several key areas. These include the effectiveness of the risk classification system, the operation of the European Artificial Intelligence Board, and the impact of extraterritorial application on global AI providers. The review may also consider whether the list of high-risk applications should be expanded, as the Act allows for this without modifying the Act itself.
Technological developments in areas such as Machine learning, Deep learning, and Large language model systems are likely to be central to the review. The rise of Generative AI systems, including those from OpenAI, Anthropic, and Google DeepMind, has already shaped the Act's evolution. The review will assess whether the general-purpose AI category adequately addresses new capabilities and risks.
The review may also examine the relationship between the AI Act and other EU regulations, including data protection and digital services legislation. It will consider whether the Act's product-safety model remains appropriate for AI systems that evolve continuously after deployment, particularly those using Neural network architectures and Transformer (architecture) models.
Global Context
The AI Act is part of a broader global effort to regulate AI. The post-2030 review will consider how the EU framework compares with regulatory approaches in other jurisdictions, including the United States, China, and other major economies. The extraterritorial reach of the Act means that providers from outside the EU, including those using Amazon Web Services, Microsoft Azure, or Google Cloud infrastructure, must comply with its requirements.
The review will also assess the Act's impact on innovation and competitiveness. Some stakeholders have expressed concerns that compliance burdens could disadvantage European AI developers compared with those in regions with lighter regulation. Others argue that the Act's clear framework provides certainty that encourages investment in trustworthy AI systems.
Conclusion
The EU AI Act 2031 represents a critical juncture in the regulation of artificial intelligence. The review process will determine whether the Act's risk-based approach has achieved its goals of protecting health, safety, and fundamental rights while fostering innovation. The outcome will shape the regulatory environment for AI in Europe and influence global standards for years to come.