·The Hindu·15 marks·250–350 wordsPolityS&TIR

The EU AI Act's 'finished product' assumption is at odds with India's iterative software industry model. Critically analyse the compliance challenges and economic opportunities this creates for India.

In this answer
  1. The core mismatch
  2. Compliance challenges
  3. Economic opportunities

The EU AI Act (Regulation 2024/1689), in force from 1 August 2024 and generally applicable from 2 August 2026, treats an AI system as a conformity-assessed finished product cleared before market entry [1][2]. India's exporters, however, ship continuously updated models — making the clash both a compliance burden and a commercial opening.

The core mismatch

  • The Act mandates ex-ante conformity assessment, technical documentation, EU database registration and CE-marking for high-risk systems — essentially a point-in-time snapshot [1].
  • Indian firms follow iterative CI/CD releases; each substantial modification can re-trigger assessment, creating a post-approval compliance gap.
  • Its extraterritorial scope covers non-EU providers whose system outputs are used in the EU — the "Brussels Effect" seen earlier with GDPR [1].

Compliance challenges

  • Recurring documentation and audit costs fall disproportionately on startups, unlike IT majors with existing governance-risk-compliance capacity.
  • High-risk Annex III areas — employment, education, biometrics, credit — are precisely where Indian HR-tech, ed-tech and fintech export [1].
  • Lifecycle obligations (risk management, post-market monitoring, logging) must be sustained across every model version.
  • Regulatory divergence: India relies on the techno-legal India AI Governance Guidelines and amended IT Rules, 2021 (effective 20 February 2026) rather than a standalone statute, forcing firms to run dual compliance stacks [3][4].

Economic opportunities

  • A niche "AI compliance-as-a-service" industry — conformity documentation, audit trails, assurance testing — extends India's proven BPM and GRC strengths.
  • Early compliance becomes a quality signal and market-access moat, as data-protection services became post-GDPR.
  • The Omnibus deferral of high-risk deadlines to December 2027 grants a preparation window [2].
  • The proposed AI Safety Institute and AI Governance Group can build interoperable domestic assurance capacity [3].

The mismatch is therefore a transitional cost, not a structural barrier. India should negotiate mutual recognition of conformity assessments, invest in indigenous AI audit and standards capacity, and use the India–AI Impact Summit to champion lifecycle-based global norms — converting a rule-taker's burden into a standard-setter's advantage.

Sources

  1. 1Regulation (EU) 2024/1689 — Artificial Intelligence Act, EUR-Lexrisk-based tiers, ex-ante conformity assessment and registration for high-risk systems, Annex III categories, extraterritorial application
  2. 2European Commission, Regulatory framework on AI (AI Act timeline)entry into force 1 August 2024, general applicability 2 August 2026, Omnibus deferral of high-risk deadlines to December 2027
  3. 3MeitY Unveils India AI Governance Guidelines under IndiaAI Mission — PIBtechno-legal, sutra-based approach; AI Governance Group, Technology & Policy Expert Committee and AI Safety Institute
  4. 4IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 — MeitY notification, G.S.R. 120(E)India regulating AI-generated content through amended IT Rules, in force 20 February 2026
Practice
11 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

More from this note

More on Polity