The Government of India has recently indicated that it is considering a standalone legislation to govern Artificial Intelligence (AI). However, the pressure on the AI supply chain is already felt due to the European Union (EU)’s AI Act which was entered into force in August 2024 and became applicable on August 2, 2026. The Act has adopted a risk-based approach to artificial intelligence (“AI”) regulation — prohibiting certain AI systems, regulating high-risk ones, and imposing lighter checks for limited-risk use cases.

While most Indian firms are likely aware that the Act applies when their AI systems produce results in Europe, there is a more consequential story that goes beyond a compliance checklist.

A post-approval issue

The Act was drafted with a particular picture in mind, and that picture does not match how India’s technology industry actually works. This mismatch, more than the law’s long reach, is what Indian companies should be watching. The Act assumes that software, once built and approved, is sold as a finished product. India’s technology industry has never worked that way. The devil lies in the legal consequences when an AI is updated post-approval.

Before a ‘high-risk’ AI system, used for sensitive decisions such as hiring or education, can enter the European market, it must clear a ‘conformity assessment’ under Article 43: proof that it meets the law’s standards on testing, documentation and human oversight. For most such systems the provider assesses itself against the Act’s criteria and signs its own declaration; only a narrow set, mainly certain biometric tools, must be checked by an independent body. Either way, once the box is ticked, the system can run undisturbed. However, if the system is “substantially modified”, the process must be repeated. A substantial modification is a change not contemplated at the time of the original assessment, one that affects its compliance or alters its intended purpose.

In June 2026, the EU gave final approval to a package easing its own timelines, pushing the compliance deadline for these standalone high-risk AI systems to December 2027 and to August 2, 2028 for high-risk AI-embedded in regulated products. It retained a grandfathering clause under which systems already on the market before this date are exempted from the Act’s obligations until substantially modified. A foreseen change examined during the original conformity assessment does not trigger a fresh one, while an unanticipated change likely does.

This distinction is not just a technicality. It would likely favour business models built on predictable product road maps. Providers of standardised AI products can assess planned upgrades during the initial assessment. Businesses that rely on bespoke services, offering competitive adaptability to individual client needs, may find it harder to demonstrate that future changes fall within the scope of the original assessment.

Unplanned improvement and regulation

India’s technology industry, from the large IT services firms to the global capability centres in Bengaluru and Hyderabad, runs on exactly this kind of responsive adaptation. The Act also tethers liability to firms that substantially modify someone else’s high-risk system. Such firms may be treated as the provider of the modified system, inheriting every one of the original maker’s obligations. Thus, for an industry whose very promise is improvement on demand, an unplanned improvement that changes an AI system’s intended purpose may trigger a fresh regulatory exercise.

Yet, the Act also presents an opportunity. High-risk compliance is operationalised through paperwork and proof. Most providers will be permitted to carry out that conformity assessment themselves, but they will do so against harmonised technical standards still being drafted. The underlying work — governance measures, technical documentation, testing regimes — has to be done in volume. The scale of this obligation is likely to generate demand for quality legal and technical professionals, which India can provide. Indian professional services firms have supported clients across data protection, financial regulation and technical assurance. They can provide regulatory capability for the Act too.

Tap the trade agreement

A longer-term vision extends beyond compliance services. The Act creates a pathway for conformity assessment bodies established in third countries to be recognised and perform the functions of notified bodies, where the EU has concluded an appropriate agreement, and those bodies satisfy the requirements. This recognition is a question for treaty negotiation, and India has just signed a treaty capable of carrying it.

The India-EU Free Trade Agreement that was concluded in January includes standing machinery and regulatory cooperation provisions. If India can secure institutional arrangements as part of its partnership with the EU, it could become not just a supplier of AI compliance services but also a participant in the EU’s conformity assessment ecosystem. Going ahead, it would provide the legal gateway through which qualified Indian conformity assessment bodies could eventually perform functions recognised under the Act. Europe has written itself a mountain of compliances and India has the capacity to do it. There is a version of this where the rules India fears become the work it sells. Which version arrives is still being decided, and not for much longer.

Mustafa Rajkotwala and Dhruv Jadhav are lawyers based out of Mumbai who focus on the technology law space

Published - August 14, 2026 12:08 am IST