HomeBlogGlobal Standards
Global Standards

EU AI Act 2024: What Indian Companies Need to Know

The EU AI Act is now in force and its extraterritorial reach means Indian companies serving European customers or deploying AI in Europe must comply — or face fines up to €35 million or 7% of global annual turnover.

8 min readPublished June 8, 2026By Anverith AI Compliance Team

In this guide

  1. 1Why the EU AI Act affects Indian companies
  2. 2The four risk tiers
  3. 3High-risk system obligations
  4. 4Compliance timeline: key dates
  5. 5India-EU data sharing implications
  6. 6Practical next steps for Indian companies

Why the EU AI Act affects Indian companies

The EU Artificial Intelligence Act, which entered into force in August 2024, applies to any organisation whose AI systems are used in the European Union — regardless of where that organisation is based. This extraterritorial scope is identical to GDPR and means that Indian IT services companies, AI SaaS vendors, and technology exporters serving European clients are subject to the Act. Indian companies providing AI systems to EU-based customers, deploying AI that processes data of EU residents, or embedding AI in products sold into European markets all fall within scope. The penalties are severe: up to €35 million or 7% of global annual turnover for prohibited AI violations, and up to €15 million or 3% for high-risk system violations.

The four risk tiers

The EU AI Act classifies AI systems into four risk categories. The classification determines the obligations — from no additional requirements to complete prohibition. Understanding which tier your AI systems fall into is the essential first step of compliance.

  • Unacceptable Risk (Prohibited) — AI systems that pose a clear threat to fundamental rights: real-time remote biometric surveillance in public spaces, social scoring by governments, exploitation of vulnerabilities (age, disability), subliminal manipulation. These are banned outright.
  • High Risk — AI in critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. Also: safety components of products regulated by EU sectoral legislation. Full compliance obligations apply.
  • Limited Risk — AI systems with specific transparency obligations: chatbots must disclose they are AI, deepfakes must be labelled, emotion recognition systems must inform users.
  • Minimal Risk — AI systems like spam filters, AI-enabled video games, and most recommendation systems. No mandatory requirements, but voluntary codes of practice are encouraged.

High-risk system obligations

If your AI system falls into the high-risk category — which includes AI used in hiring, credit scoring, medical diagnosis, education, and many IT infrastructure management tools — you face extensive obligations before placing the system on the EU market. These are not light-touch requirements: they require significant investment in governance, documentation, and technical controls.

  • Risk management system — documented and implemented throughout the AI system lifecycle
  • Data governance — training data must be relevant, representative, and free from bias
  • Technical documentation — detailed technical specifications available for regulators on request
  • Record-keeping — automatic logging of events to enable post-incident audits
  • Transparency — users must be informed they are interacting with a high-risk AI system
  • Human oversight — systems must be designed to allow effective human intervention and override
  • Accuracy, robustness, and cybersecurity — validated performance metrics and adversarial testing
  • EU conformity assessment and CE marking before market placement
  • Register in the EU database of high-risk AI systems (mandatory from August 2026)

Ready to automate your compliance?

Anverith AI covers ISO 42001, EU AI Act, DPDP, and 6 other frameworks — all in one platform.

Compliance timeline: key dates

The EU AI Act has a phased implementation timeline. Indian companies need to plan ahead — many compliance activities take 9–18 months to complete properly. Missing deadlines can result in market access being denied to your AI systems in Europe.

  • August 2024 — Act entered into force
  • February 2025 — Prohibited AI provisions apply (ban on unacceptable risk systems)
  • August 2025 — GPAI (General Purpose AI) model obligations apply, including for foundation model providers
  • August 2026 — High-risk AI system obligations fully apply; EU database registration mandatory
  • August 2027 — High-risk AI systems embedded in regulated products must comply
  • December 2030 — Obligations for certain high-risk AI systems in already-deployed products

India-EU data sharing implications

Indian companies transferring personal data from EU users to India for AI model training face a dual compliance challenge: GDPR rules on international data transfers AND EU AI Act data governance requirements. Standard Contractual Clauses (SCCs) remain the primary mechanism for legitimising data transfers from EU to India. However, the EU AI Act's data governance requirements add additional obligations on top: training data must be subject to appropriate governance, bias evaluation, and data quality assessments. Indian companies should not assume that GDPR compliance automatically satisfies EU AI Act data governance requirements — they are separate obligations.

Practical next steps for Indian companies

Indian companies with EU exposure should begin compliance work immediately for high-risk systems. The August 2026 deadline for high-risk AI may seem distant, but conformity assessments, technical documentation, and organisational changes take 12–18 months to implement properly.

  • Step 1: Inventory all AI systems and classify each by EU AI Act risk tier
  • Step 2: For high-risk systems, conduct a gap assessment against full obligations
  • Step 3: Implement a risk management system and data governance controls
  • Step 4: Develop technical documentation packages for each high-risk system
  • Step 5: Design human oversight mechanisms into your AI systems
  • Step 6: Engage an EU Notified Body for conformity assessment if required
  • Step 7: Register high-risk systems in the EU database before August 2026

About this guide

Written by the Anverith AI Compliance Team. Published June 8, 2026 · 8 min read. Anverith AI is India's AI Trust Platform — automating compliance across ISO 42001, DPDP 2023, RBI FREE-AI, EU AI Act, and 5 other frameworks.

Get compliant faster with Anverith AI

Automate ISO 42001, DPDP 2023, RBI FREE-AI, and EU AI Act compliance. First score in 48 hours. Trust Passport in days.