The EU AI Act's four-tier risk system already reaches Indian companies: if your GCC processes EU user data or your exported product touches hiring, credit, or healthcare decisions for EU clients, "high-risk" obligations under Annex III apply regardless of where your engineering team sits. Map exposure before the mid-2026 enforcement deadline, not after an EU client audit.
This is not a Brussels-only problem. Indian GCCs building HR, credit, or health-adjacent features for EU parent companies, and SaaS exporters selling into the EU, inherit the same Annex III duties as an EU-headquartered vendor — with penalties up to €35 million or 7% of global turnover for the most serious violations.
What Changed
- The AI Act's phased rollout hits its biggest milestone in mid-2026: full application for High-Risk systems under Annex III.
- GPAI (foundation model) documentation and copyright-summary duties have applied since mid-2025 — relevant if you fine-tune or resell EU-origin foundation models.
- Enforcement sits with national authorities and the EU AI Office, with penalties scaled by violation tier.
- "High-risk" is defined by use case (Annex III: HR, credit, education, critical infrastructure, law enforcement), not by where the company that builds it is headquartered.
The Details
The era of unregulated artificial intelligence is officially over. With the European Parliament's formal adoption of the Artificial Intelligence Act in March 2024, the EU has established the world's first comprehensive legal framework for AI. Much like the GDPR redefined data privacy, the AI Act is poised to become the de facto global standard for AI governance, creating a "Brussels Effect" that will ripple through boardrooms far beyond Europe.
For enterprises, the AI Act is not merely a compliance hurdle; it is a market reality. It fundamentally categorizes AI systems based on risk, imposing strict obligations on "high-risk" applications while banning certain "unacceptable" practices entirely.
The Risk-Based Approach: A Pyramid of Liability
The core philosophy of the EU AI Act is that not all AI is created equal. The regulation applies a sliding scale of rules proportional to the threat an AI system poses to fundamental rights and safety.
1. Unacceptable Risk: Banned Outright. Certain AI applications are deemed so detrimental to civil liberties that they are prohibited under Article 5, including social scoring systems, real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions), emotion recognition in workplaces or schools, predictive policing based solely on profiling, and untargeted scraping of facial images to build recognition databases. Companies developing these technologies must exit the EU market or pivot, as violations allow for penalties up to €35 million or 7% of global turnover.
2. High-Risk AI: The Compliance Heavyweight. This is where the bulk of enterprise compliance work lies. "High-Risk" AI systems, defined in Annex III, are permitted but subject to rigorous obligations before they can enter the market — covering critical infrastructure, education and vocational training, employment processes (CV-sorting algorithms), essential private and public services (credit scoring, healthcare triage), and law enforcement and border control tools.
Mandatory Requirements (Article 8-15):
| Requirement | Description |
|---|---|
| Risk Management System | Continuous iterative process throughout the AI lifecycle. |
| Data Governance | Training/validation data must be relevant, representative, and error-free to prevent bias (Article 10). |
| Technical Documentation | Detailed record-keeping of system architecture for authorities. |
| Transparency | Instructions for use must be clear enough for human oversight. |
| Human Oversight | Measures to allow human intervention (e.g., "stop" button). |
| Accuracy & Robustness | Resilience against errors and adversarial attacks. |
3. Limited Risk: Transparency First. This category covers AI systems where the primary risk is manipulation or confusion. Users must be informed they are interacting with an AI (Article 50), and AI-generated content such as deepfakes must be clearly labeled as artificially manipulated.
4. Minimal Risk: The Green Lane. The vast majority of AI systems — spam filters, video games, inventory optimization tools — fall here and can operate freely with no new obligations.
General Purpose AI (GPAI): The 'Foundation Model' Rules
Initially, the AI Act focused on specific use cases. However, the generative AI boom forced a late rewrite to include rules for General Purpose AI (GPAI) models.
- Tier 1: All GPAI Models must maintain detailed technical documentation, comply with EU copyright law, and publish a detailed summary of the content used for training.
- Tier 2: Systemic Risk Models — defined as models requiring >10^25 FLOPS for training — face extra obligations: adversarial testing ("red teaming"), systemic risk assessments, serious incident reporting to the AI Office, and strict cybersecurity protections.
The Timeline: When Does It Bite?
The AI Act is a phased rollout. Enterprises must prepare now to meet these deadlines:
| Date | Milestone |
|---|---|
| Mid-2024 | Entry into force (20 days after publication). |
| Late 2024 | Bans on "Unacceptable Risk" AI apply (6 months). |
| Mid-2025 | Rules for GPAI/Foundation Models apply (12 months). |
| Mid-2026 | Full application for High-Risk systems in Annex III (24 months). |
| Mid-2027 | High-Risk systems under other EU product safety laws (36 months). |
Penalties: The Cost of Non-Compliance
Enforcement is handled by national authorities and the European AI Office. The penalties are steeper than GDPR: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% of turnover for violating High-Risk or GPAI obligations, and up to €7.5 million or 1.5% of turnover for supplying incorrect information.
What This Means for Indian Founders and CTOs
- If your GCC builds or maintains HR screening, credit scoring, or healthcare triage features for an EU parent or client, you inherit Annex III High-Risk duties — technical documentation, human oversight, data governance — even though your team sits in Bengaluru or Pune.
- Exporters selling SaaS into the EU should audit contracts now: EU enterprise buyers are already asking vendors for AI Act risk classifications in procurement questionnaires.
- If you fine-tune or deploy an EU-flagged "systemic risk" foundation model, expect your EU customer to push red-teaming and incident-reporting obligations down into your contract.
- Build one control set that satisfies both the EU AI Act's documentation requirements and India's own emerging expectations under DPDP and MeitY advisories — duplicating compliance programs per region wastes runway.
- Budget realistically: EU AI Act compliance work (data governance, technical documentation, vendor review) is a multi-quarter project, not a one-time audit before a deal closes.
Frequently Asked Questions
Does the EU AI Act apply to Indian companies that don't have an EU office?
Yes, if you place an AI system on the EU market or its output is used in the EU — including via a GCC serving an EU parent or a SaaS product sold to EU customers.
What counts as "high-risk" AI under the EU AI Act for an Indian GCC?
Annex III lists the categories: hiring and HR screening tools, credit scoring, healthcare triage, education assessment, and critical infrastructure systems, among others. If your GCC builds any of these for an EU entity, High-Risk duties apply.
When do Indian exporters need to be fully compliant with the EU AI Act?
High-Risk systems under Annex III face full application in mid-2026. GPAI documentation duties for foundation models have applied since mid-2025 — check both dates against your product roadmap.
Can Indian companies rely on the EU AI Act's "open source" exemptions?
Only narrowly. Most open-weight model exemptions apply to non-commercial research use; commercial deployment of high-risk features generally does not qualify, regardless of whether the underlying model is open-weight.
For the US's contrasting approach, see US AI Governance. For India's own regulatory stack, read AI Regulation in India: A Business Guide and How India's DPDP Act Affects AI Training Data. Operational teams can pair this with the AI Compliance Starter Kit and AI in India Statistics 2026.



