The EU AI Act entered into force in August 2024 and its obligations apply in stages. It matters to Indian businesses because it reaches beyond Europe's borders: if you place an AI system on the EU market, or its output is used in the EU, the Act can apply to you wherever you are based.
Four levels of risk
- Unacceptable risk: a short list of practices, such as manipulative techniques and social scoring, is banned outright.
- High risk: AI used in areas such as hiring, credit, education, critical infrastructure and safety components of products must meet strict requirements on data, documentation, human oversight and accuracy.
- Limited risk: systems such as chatbots must tell people they are dealing with AI, and AI-generated content must be identifiable.
- Minimal risk: most other AI, such as spam filters or recommendation features, has no new obligations.
What this means in practice
Most products built by Indian software and services firms fall into the limited or minimal tiers. But if you build HR screening tools, lending models or components for regulated machinery used in Europe, high-risk duties are likely. Clients in the EU will also start asking their Indian suppliers for documentation to support their own compliance.
The timetable has been adjusted before, so always check the current dates for the obligations that apply to you.
Where to start
- List your products and services that reach EU customers or EU users.
- Classify each one against the risk tiers, and record your reasoning.
- For limited-risk systems, add clear AI disclosure now. It is cheap and builds trust.
- For anything that may be high risk, begin the technical documentation early. It takes the longest.
