+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

The EU AI Act and Indian software exporters

AI By Mits Engineering Team 2 min read
The EU AI Act and Indian software exporters

Indian software companies tend to read the EU AI Act as somebody else's regulation. It is not. Like the GDPR before it, the Act reaches providers outside the Union when the system or its output is used within it. A Bengaluru firm shipping an AI feature inside a product sold to European customers is a provider under the Act, and the fact that no part of the company is in Europe changes nothing about that.

The dates matter more than the doctrine, because the Act arrived in stages rather than at once. It entered into force on 1 August 2024. Definitions, AI literacy obligations and the outright prohibitions began applying on 2 February 2025. Obligations for providers of general-purpose AI models took effect on 2 August 2025, along with the requirement for member states to designate competent authorities and set up penalty regimes.

The date that has just passed is the significant one for most product teams. On 2 August 2026 the majority of the Act's rules came into application, the transparency obligations under Article 50 started to apply, and enforcement began at both national and EU level for general-purpose AI models, the prohibitions, the transparency requirements and AI literacy. If you shipped an AI feature into Europe and have not looked at Article 50, that is the gap to close first — it governs disclosure, and disclosure is the cheapest obligation in the Act to satisfy and the most visible to miss.

Two further dates are already on the calendar. On 2 December 2026 new prohibitions concerning non-consensual sexual deepfakes and child sexual abuse material take effect, together with a transitional compliance deadline under Article 50(2) for providers of systems generating synthetic content that were already on the market before 2 August 2026. On 2 December 2027 the rules for high-risk systems listed in Annex III apply, and on 2 August 2028 those for high-risk AI embedded in regulated products under Annex I. Member states must have at least one regulatory sandbox operating by 2 August 2027.

The practical work for most Indian teams is classification, and it is duller than it sounds. Most features are not high-risk. Many are subject to transparency obligations. A few — anything touching employment screening, credit decisions, education access or biometric processing for European users — need looking at properly against Annex III before December 2027, because a system that turns out to be high-risk carries documentation, logging, human oversight and conformity obligations that cannot be retrofitted in a quarter.

The commercially useful point is that European buyers have begun asking about this in procurement, and an Indian supplier who can answer clearly is at an advantage over one who cannot. A short written classification of each AI feature, its Article 50 disclosure position, and the date any future obligation attaches, is a document worth having before a customer asks for it rather than after.

Need help with this? Explore our AI & Intelligent Automation services. Learn more Back to all news

Keep reading

More on AI