Discuss how extraterritorial regulations like the EU AI Act shape technology governance in third countries such as India. Suggest a suitable regulatory response.
In this answer
The EU AI Act (Regulation 2024/1689), whose core obligations became enforceable on 2 August 2026, applies to any provider whose AI outputs are used in the EU, irrespective of where the provider is located [1][2]. Such extraterritorial reach makes Indian AI governance partly a response to rules India did not write.
Channels of influence on third-country governance
- Market access: the Act's risk-based tiers — prohibited, high-risk (hiring, credit scoring, education, border control) and limited-risk — require Indian HR-tech and ed-tech exporters to complete conformity assessment, EU registration and quality-management systems before entry [1].
- Norm diffusion ("Brussels Effect"): the GDPR template visibly informed India's Digital Personal Data Protection Act, 2023 [6]; the AI Act is similarly pushing risk-tiering into Indian policy discourse.
- Compliance costs: enforcement by the EU AI Office with national authorities [2] favours large IT majors possessing governance-risk-compliance capacity over smaller startups.
- Design mismatch: EU law assumes AI is a finished product, whereas India's iterative, continuously-updated software model creates post-approval conformity gaps.
India's evolving response
- India AI Governance Guidelines (MeitY, under IndiaAI Mission) adopt a techno-legal, pro-innovation framework of seven sutras with proportionate safeguards for high-risk uses, rather than a standalone AI statute [3].
- An institutional layer through the AI Governance and Economic Group (AIGEG) as the inter-ministerial coordinating mechanism [4].
- Use of existing law: the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 mandate labelling and traceable metadata for synthetically generated content [5].
A suitable regulatory response
- Retain the guidelines-plus-existing-law route, but codify a statutory risk classification so Indian documentation gains recognition abroad.
- Pursue standards interoperability — mutual recognition of audits via BIS and international standards bodies — to avoid duplicate certification.
- Convert burden into advantage by nurturing an "AI compliance-as-a-service" industry on India's IT-services base.
- Support MSMEs through regulatory sandboxes and shared testing infrastructure under the IndiaAI Mission.
Extraterritorial regimes thus govern third countries less by command than by market gravity, making compliance a condition of trade. A calibrated Indian path — light-touch domestic rules married to interoperable global standards — can protect innovation while securing market access, enabling India to move from rule-taker to norm-shaper at the India–AI Impact Summit 2026.
Sources
- 1Regulation (EU) 2024/1689 — the AI Act, EUR-Lexextraterritorial scope and risk-based classification of AI systems
- 2Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commissionenforcement from 2 August 2026 by the AI Office and national authorities
- 3MeitY Unveils India AI Governance Guidelines under IndiaAI Mission — PIBseven *sutras*, techno-legal and risk-proportionate approach; India–AI Impact Summit 2026
- 4Government Constitutes AI Governance and Economic Group (AIGEG) — PIBcentral inter-ministerial mechanism for AI governance
- 5Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 — MeitYlabelling and traceable metadata for synthetically generated information
- 6The Digital Personal Data Protection Act, 2023 — MeitYIndia's data law as evidence of EU-influenced norm diffusion