The EU AI Act applies to Indian companies in four situations, all of them turning on Article 2(1) of Regulation (EU) 2024/1689, and not one of them requires an office, a subsidiary or a single employee inside Europe. You’re caught if you place an AI system or a general-purpose AI model on the EU market, if you sit in India and the output your AI system produces is used in the Union, if you import or distribute AI or ship it inside your own branded product, or if a European client outsources a high-risk AI activity to you. So for most Indian firms with European clients, the real question isn’t whether the EU AI Act applies to Indian companies at all. It’s which of those four doors you already walked through, and what the role you landed in obliges you to do.
This article sets out when The EU AI Act Applies to Indian companies, which role you fall into, and what that role owes by which date.
One correction first, because it changes the whole compliance calendar. If you read up on this earlier in the year and wrote down 2 August 2026 as the high-risk deadline, that date is gone. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved stand-alone high-risk obligations to 2 December 2027. The transparency obligations, though, landed exactly on schedule.
When the EU AI Act applies to Indian companies
The EU AI Act applies to Indian companies through four routes. Three of them sit directly in Article 2(1) of Regulation (EU) 2024/1689. The fourth is that same Article 2(1)(c) output test applied to outsourced work, which Recital 22 spells out. Physical presence in Europe is not among them.
The first trigger is placing an AI system on the EU market or putting it into service there, or placing a general-purpose AI model on that market. Article 2(1)(a) catches providers doing this “irrespective of whether those providers are established or located within the Union or in a third country”. An Indian SaaS company with European enterprise customers is placing its system on that market, whether it sells through a reseller, a direct contract or an API.
The second trigger is wider, and it’s the one Indian firms miss. Article 2(1)(c) covers “providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union”. The system can sit on a server in Pune and the contract can be governed by Indian law, and the Act still bites if what it produces gets used in Europe, which is why data residency is no answer here, however often it gets offered as one.
Third, Article 2(1)(d) and (e) catch importers and distributors of AI systems, and product manufacturers who ship an AI system inside their own product under their own name or trademark.
Fourth, and most directly relevant to Indian IT services and business process work, Recital 22 closes the outsourcing route on purpose. It gives the worked example: a Union operator contracts an activity out to a third-country operator, that operator processes data lawfully collected in and transferred from the Union and returns the output to the contracting party, and the Regulation still reaches it as a provider or deployer. A recital creates no obligation by itself, so the operative hook stays Article 2(1)(c); Recital 22 settles how that hook is read. Subcontracting is not a shield. It was specifically anticipated.
So which door did you walk through? Put these four questions to every workstream that touches AI:
- Do European customers use this system, whether directly, through a reseller, or through an API? If yes, Article 2(1)(a) applies and you’re a provider.
- Does anything this system produces get used by a person or a process inside the EU, even if no European ever logs into it? If yes, Article 2(1)(c) applies.
- Does the system ship inside a product carrying your name or trademark? If yes, Article 2(1)(e) applies.
- Did a European client contract this activity out to you, with EU-origin data flowing to you and output flowing back? If yes, this is the scenario Recital 22 describes, and Article 2(1)(c) puts you in the provider or deployer role for it.
Now the part vendor pages skip, because they sell compliance services and this doesn’t help them. Plenty of Indian work is genuinely out of scope. Application support, infrastructure management, testing and maintenance with no AI component in the deliverable are not caught, because there is no AI system to bring into scope. Neither is an internal tool whose output never leaves India: an HR screening model used only on Indian applicants for Indian roles fails the Article 2(1)(c) output test.
It is worth knowing how much of the export book this question actually touches. Europe took US$ 73.26 billion of India’s software services exports in FY25, roughly 33% of the total, with the United Kingdom alone accounting for US$ 34.41 billion, or 15.50%, according to IBEF’s IT and BPM industry report citing NASSCOM figures. Read that with care, though: the United Kingdom is outside the EU and outside this Regulation, so the EU-facing share is the remaining 17.5% or so, still about one export dollar in six. European rules reaching Indian suppliers isn’t new ground either, as anyone who has built an Article 30 record of processing under the GDPR already knows.
Application support, infrastructure management, testing and maintenance with no AI component in the deliverable. No AI system, no scope.
Internal-only systems whose output never reaches the Union. An HR screening model used only on Indian applicants for Indian roles fails the Article 2(1)(c) output test.
Source: Regulation (EU) 2024/1689, Articles 2 and 5 and Recital 22, as amended by Regulation (EU) 2026/1744.
Provider and deployer roles under the EU AI Act
Being in scope tells an Indian company almost nothing about what it must actually do, because obligations under the EU AI Act attach to the role, not the company. Two firms caught by the same Article 2 trigger can owe completely different things.
A provider develops an AI system or a general-purpose AI model and puts it on the market under its own name. Where the system is high-risk, the provider carries the heavy end: technical documentation, conformity assessment, registration, post-market monitoring. A deployer uses an AI system under its own authority. Deployer duties are use-side and lighter, covering human oversight, input data quality and following the provider’s instructions.
Role is only half of it. Does knowing you’re a deployer tell you what to build? Not yet. The Act also sorts systems into tiers, and the real obligation is role multiplied by tier.
Prohibited practices under Chapter II are banned outright. High-risk systems under Article 6 and its annexes carry the documentation and conformity load. Article 50 sets transparency duties for a specific set of systems. Everything else carries no substantive obligation beyond the AI literacy duty in Article 4, leaving aside the separate general-purpose AI model regime in Chapter V.
Here is what most Indian firms get backwards. They read the high-risk chapter, panic about conformity assessment, and never notice that Article 50 is the tier they are actually in.
Article 50(1) requires providers of systems that interact directly with people to make sure those people know they’re dealing with an AI system, unless it’s obvious. Article 50(2) requires providers of generative systems to mark synthetic audio, image, video and text output in a machine-readable format. Article 50(3) and 50(4) push duties onto deployers: informing people exposed to emotion recognition or biometric categorisation, and disclosing deepfakes and AI-generated text published to inform the public on matters of public interest.
Read that list against an Indian content, marketing, customer support or BPM operation and the overlap is immediate. That is the tier to check first. Internally it usually lands with whoever already handles privacy compliance, which makes a data privacy consultant the natural owner rather than the engineering team.
When a deployer becomes a provider
A deployer becomes a provider by operation of law under Article 25(1), and it happens without any deliberate decision. Three triggers do it: putting your name or trademark on a high-risk AI system already on the market or in service, making a substantial modification that leaves it high-risk under Article 6, or changing a system’s intended purpose, including a general-purpose one, so that it becomes high-risk.
The first trigger is the one to sit with, because white-labelled delivery is how a great deal of Indian work is structured, and it cuts both ways. Ship an AI feature under a European client’s brand and it is their name on the system, so the provider obligations land on them by default. Put your own mark on a high-risk system you resell or rebadge and they land on you. Either way the default is only a default: Article 25(1)(a) operates without prejudice to contractual arrangements that allocate the obligations differently, so the contract is doing the allocating whether anyone read that clause or not.
Article 25(4) sits alongside it. Providers of high-risk systems and third parties supplying tools, services, components or processes used in them must agree in writing what information, capabilities and technical access the provider needs to comply. Releases under free and open-source licences are carved out. The practical reading is blunt: your master services agreement decides who carries the provider weight, so the AI clause gets read before signature, not during an audit.
Deadlines and duties for Indian companies under the EU AI Act
The deadlines and duties for Indian companies under the EU AI Act shifted on 27 July 2026, when Regulation (EU) 2026/1744 entered into force, three days after its publication in the Official Journal on 24 July. Here is the calendar as it now stands.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices (Chapter II), AI literacy (Article 4) |
| 2 August 2025 | General-purpose AI model obligations, governance, penalties (Article 101 fines for GPAI providers apply from 2 August 2026) |
| 2 August 2026 | General application, including Article 50 transparency |
| 2 December 2026 | Article 50(2) marking grace period ends for systems already on the market; the new Article 5 prohibition on AI-generated non-consensual intimate imagery and CSAM applies |
| 2 August 2027 | National regulatory sandboxes operational (moved from 2 August 2026) |
| 2 December 2027 | Stand-alone high-risk systems, Annex III (moved from 2 August 2026) |
| 2 August 2028 | High-risk systems embedded in regulated products, Annex I (moved from 2 August 2027) |
So does a deferral mean the whole file can be put down until December 2027? No, and reading it that way is the mistake worth naming. A deferral is not a repeal, and what moved was the high-risk timetable and the sandbox deadline, not the rest of the Act.
Prohibitions have been enforceable since February 2025, and the omnibus added one rather than lifting any: a new Article 5 ban on AI systems that generate non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026, subject to a carve-out for effective technical safeguards. And the Article 50 transparency duties that catch most Indian operations became applicable on 2 August 2026, which has already passed.
If you do end up in high-risk territory, Article 22 adds a structural requirement. Third-country providers must, “by written mandate, appoint an authorised representative which is established in the Union” before making a high-risk system available on the Union market. That representative verifies the declaration of conformity and technical documentation, keeps it for ten years after the system is placed on the market, supplies logs and information to authorities, cooperates on risk mitigation, and handles Article 49 registration. Because the duty hangs off the high-risk application date, Annex III providers now have until December 2027 rather than a deadline that has already gone.
One obligation ignores role and tier entirely. Article 4 requires AI literacy across staff and others dealing with these systems on your behalf. The omnibus softened it into a duty to take measures supporting that literacy, expressly not a duty to guarantee any level in any individual, but it has been live since February 2025. It is the cheapest item on the list and the one most often skipped, which is why building AI skills across a senior team has stopped being optional.
On penalties, Article 99 sets administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for most other obligations, and up to EUR 7.5 million or 1% for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities. For an undertaking each is whichever figure is higher, and it is turnover, note, not profit. Which sets up the detail reported wrong constantly: under Article 99(6), for SMEs including start-ups, each fine is capped at whichever of the two is lower.
And there is no domestic version to fall back on. MeitY released the India AI Governance Guidelines on 5 November 2025 under the IndiaAI Mission, built on seven principles and recommending industry codes of practice, technical standards and self-certification rather than compliance-heavy regulation. India has no umbrella AI statute, so existing law carries the load, much as the DPDP Act compliance checklist does for personal data. Which means the EU work has to be built rather than inherited from anything you already run at home.
That leaves a short list, every item with a date on it. Sort every AI-touching workstream through the four Article 2 questions, then check whatever survives against Article 50 before opening the high-risk chapter, because Article 50 is the tier already in force. Pull up the AI clause in each European contract and work out who Article 25(1)(a) has quietly made the provider. If anything lands in Annex III territory, the authorised representative under Article 22 is the one item with real lead time attached, and December 2027 is nearer than it looks.
Frequently asked questions
Does the EU AI Act apply if our AI tool is only used inside India?
No. Article 2(1)(c) turns on the output being used in the Union. A model that only processes Indian data for Indian users, with nothing reaching a person or process in Europe, sits outside the Act. But let an EU client receive the output and the answer flips.
Are small Indian companies and start-ups exempt from the EU AI Act?
There’s no size exemption. Obligations apply in full regardless of headcount or revenue, so a two-person start-up placing a high-risk system on the EU market carries the same duties as a large exporter. But exposure differs: Article 99(6) caps SME fines at whichever figure is lower.
Does India have its own AI law covering the same ground?
No umbrella statute exists. MeitY’s India AI Governance Guidelines of 5 November 2025 are voluntary and principles-based, recommending codes of practice and self-certification rather than binding duties. Existing law, including the DPDP Act, carries the load for now.
Does the EU AI Act apply to Indian firms that only supply data labelling or components?
Indirectly, through Article 25(4) rather than direct provider obligations. A third party supplying tools, services, components or processes for a high-risk system must agree in writing the information and technical access the provider needs to comply. Free and open-source releases are excluded.
References
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 2, 4, 5, 22, 25, 50 and 99, and Recital 22. https://artificialintelligenceact.eu/
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 2026/1744, 24 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- IBEF, IT and BPM industry report, India software services export figures citing NASSCOM. https://www.ibef.org/industry/information-technology-india
- Ministry of Electronics and Information Technology, India AI Governance Guidelines, 5 November 2025. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2228315
This article is general information about a regulation and its scope, current as of 18 August 2026. It is not legal advice on any specific AI system, contract or business. Whether a particular system falls inside the EU AI Act, and which role and tier attach to it, depends on facts this article cannot see. Consult a qualified professional before acting.



Allow notifications