Account subscription benefits alongside Premium Stories, Editorials,
Opinions and more. Unlock these with Subscription
The View From India
Looking at World Affairs from the Indian perspective.
First Day First Show
News and reviews from the world of cinema and streaming.
Today's Cache
Your download of the top 5 technology stories of the day.
Science For All
The weekly newsletter from science writers takes the jargon out of science and puts the fun in!
Data Point
Decoding the headlines with facts, figures, and numbers
THEdge
At the cutting edge of education and careers
Health Matters
Ramya Kannan writes to you on getting to good health, and staying there
Gender Agenda
Stories from beyond the binary.
The Hindu On Books
Books of the week, reviews, excerpts, new titles and features.
‘Europe has written itself a mountain of compliances and India has the capacity to perform recognised functions’
| Photo Credit: Reuters
The Government of India has recently indicated that it is considering a standalone legislation to govern Artificial Intelligence (AI). However, the pressure on the AI supply chain is already felt due to the European Union (EU)’s AI Act which was entered into force in August 2024 and became applicable on August 2, 2026. The Act has adopted a risk-based approach to artificial intelligence (“AI”) regulation — prohibiting certain AI systems, regulating high-risk ones, and imposing lighter checks for limited-risk use cases.
While most Indian firms are likely aware that the Act applies when their AI systems produce results in Europe, there is a more consequential story that goes beyond a compliance checklist.
The Act was drafted with a particular picture in mind, and that picture does not match how India’s technology industry actually works. This mismatch, more than the law’s long reach, is what Indian companies should be watching. The Act assumes that software, once built and approved, is sold as a finished product. India’s technology industry has never worked that way. The devil lies in the legal consequences when an AI is updated post-approval.
Before a ‘high-risk’ AI system, used for sensitive decisions such as hiring or education, can enter the European market, it must clear a ‘conformity assessment’ under Article 43: proof that it meets the law’s standards on testing, documentation and human oversight. For most such systems the provider assesses itself against the Act’s criteria and signs its own declaration; only a narrow set, mainly certain biometric tools, must be checked by an independent body. Either way, once the box is ticked, the system can run undisturbed. However, if the system is “substantially modified”, the process must be repeated. A substantial modification is a change not contemplated at the time of the original assessment, one that affects its compliance or alters its intended purpose.


