Artificial Intelligence
EU AI Act for Indian Businesses: What Landed in August 2026
A lot of compliance marketing has the August 2026 deadline wrong. The transparency rules landed on schedule; most high-risk obligations were pushed to 2027 and 2028.
By Maya Iyer · Updated · 10 min read

Short answer
Does the EU AI Act apply to an Indian company?
From 2 August 2026 the EU AI Act's Article 50 transparency duties apply - disclosing that a user is talking to an AI system, marking AI-generated content, and labelling deepfakes - along with the AI Office's enforcement powers over general-purpose AI providers. The heavier high-risk obligations were deferred: standalone Annex III systems such as hiring, credit scoring and education to 2 December 2027, and high-risk AI embedded in already-regulated products to 2 August 2028. Penalties run to EUR 35 million or 7 percent of worldwide turnover for prohibited practices and EUR 15 million or 3 percent for other breaches including GPAI obligations. This page is orientation, not legal advice.
Our practical verdict
The most useful thing an Indian business can know about the EU AI Act in August 2026 is which parts actually came into force, because a good deal of compliance marketing has been describing obligations that were deferred.
What applied on 2 August 2026: the Article 50 transparency duties, and the AI Office's enforcement powers over general-purpose AI providers. In practice, Article 50 means disclosing to a person that they are interacting with an AI system where that is not otherwise obvious, marking AI-generated or manipulated content in a machine-readable format, and labelling deepfakes. These are engineering and product tasks more than legal ones.
What did not apply on that date: the heavy high-risk obligations. Standalone high-risk systems under Annex III - the hiring, credit scoring, education and critical infrastructure categories that most compliance decks lead with - were deferred to 2 December 2027. High-risk AI embedded in products already regulated under Annex I, such as medical devices, machinery and toys, moves to 2 August 2028. If a vendor is quoting you for Annex III conformity work as an August 2026 deadline, check the date they are working from.
Shortlist
Recommended options to compare
Use this as a starting list, then compare live India prices and warranty before buying.
Pick 1
What actually applied on 2 August 2026
Article 50 transparency duties and the AI Office's GPAI enforcement powers. If your product talks to a user as a chatbot, generates synthetic media, or produces AI content that could be mistaken for human, the disclosure and marking duties are live now.
Pick 2
What did not apply
Standalone high-risk obligations under Annex III - hiring, credit scoring, education, critical infrastructure - were deferred to 2 December 2027. High-risk AI embedded in regulated products such as medical devices and machinery moves to 2 August 2028. A vendor telling you these are due now is either mistaken or selling.
Pick 3
Why it reaches Indian companies at all
The Act applies by where the output is used, not by where the company sits. An Indian SaaS product or IT services engagement whose AI output is used in the EU can be in scope even with no EU entity.
Pick 4
The penalty tiers
Prohibited practices carry the top tier at up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher. Other breaches, including general-purpose AI obligations, run to EUR 15 million or 3 percent. Turnover-based means group turnover, not EU revenue.
Pick 5
Your realistic first three tasks
Inventory which of your systems use AI and what they output, add the chatbot and synthetic-content disclosures where Article 50 applies, and find out contractually whether you are a provider or a deployer for each system. That distinction sets which obligations are yours.
Pick 6
Where to spend on advice
Get qualified EU counsel on classification - provider versus deployer, and whether anything you run touches Annex III before December 2027. Classification is the expensive thing to get wrong; the transparency work is mostly engineering.
Which option should you choose?
What actually applied on 2 August 2026
Article 50 transparency duties and the AI Office's GPAI enforcement powers. If your product talks to a user as a chatbot, generates synthetic media, or produces AI content that could be mistaken for human, the disclosure and marking duties are live now.
What did not apply
Standalone high-risk obligations under Annex III - hiring, credit scoring, education, critical infrastructure - were deferred to 2 December 2027. High-risk AI embedded in regulated products such as medical devices and machinery moves to 2 August 2028. A vendor telling you these are due now is either mistaken or selling.
Why it reaches Indian companies at all
The Act applies by where the output is used, not by where the company sits. An Indian SaaS product or IT services engagement whose AI output is used in the EU can be in scope even with no EU entity.
The penalty tiers
Prohibited practices carry the top tier at up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher. Other breaches, including general-purpose AI obligations, run to EUR 15 million or 3 percent. Turnover-based means group turnover, not EU revenue.
Your realistic first three tasks
Inventory which of your systems use AI and what they output, add the chatbot and synthetic-content disclosures where Article 50 applies, and find out contractually whether you are a provider or a deployer for each system. That distinction sets which obligations are yours.
Where to spend on advice
Get qualified EU counsel on classification - provider versus deployer, and whether anything you run touches Annex III before December 2027. Classification is the expensive thing to get wrong; the transparency work is mostly engineering.
Choice IQ pick
Need the faster shortlist?
Start with our recommended options, then compare the tradeoffs that matter for your budget and workflow.
See top picksHow to decide
Pick the option around the job you need done. This is the fastest way to avoid paying for something that looks impressive but does not change your real workflow.
| Situation | Best starting point | Final check |
|---|---|---|
| What actually applied on 2 August 2026 | Article 50 transparency duties and the AI Office's GPAI enforcement powers. If your product talks to a user as a chatbot, generates synthetic media, or produces AI content that could be mistaken for human, the disclosure and marking duties are live now. | Use this as a shortlist, then verify the final details before committing. |
| What did not apply | Standalone high-risk obligations under Annex III - hiring, credit scoring, education, critical infrastructure - were deferred to 2 December 2027. High-risk AI embedded in regulated products such as medical devices and machinery moves to 2 August 2028. A vendor telling you these are due now is either mistaken or selling. | Use this as a shortlist, then verify the final details before committing. |
| Why it reaches Indian companies at all | The Act applies by where the output is used, not by where the company sits. An Indian SaaS product or IT services engagement whose AI output is used in the EU can be in scope even with no EU entity. | Use this as a shortlist, then verify the final details before committing. |
| The penalty tiers | Prohibited practices carry the top tier at up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher. Other breaches, including general-purpose AI obligations, run to EUR 15 million or 3 percent. Turnover-based means group turnover, not EU revenue. | Use this as a shortlist, then verify the final details before committing. |
Read the editorial notes
The reason any of this reaches India is extraterritorial scope. The Act attaches to systems whose output is used in the EU, not only to companies established there. An Indian SaaS product with EU customers, or an IT services engagement building an AI feature that will be deployed in the EU, can be in scope without any EU entity at all. Whether you are the provider or the deployer of a given system determines which obligations land on you, and that is usually set by contract - which makes it worth reading the customer agreements before commissioning any compliance work.
Penalties are tiered. Prohibited AI practices carry up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher. Other breaches, including the general-purpose AI model obligations the AI Office now enforces, run to EUR 15 million or 3 percent. Worldwide turnover is the base, so the exposure is not capped by how small the EU slice of your revenue is.
A sensible sequence for an Indian company with EU exposure: build an inventory of every system that uses AI and what it outputs; ship the Article 50 disclosures and content marking where they apply, since those are due now; establish for each system whether you are provider or deployer; and get qualified EU counsel specifically on classification and on whether anything you run will fall into Annex III before December 2027. Classification errors are the expensive kind. The transparency work is comparatively cheap and is already overdue.
This page is written to orient a buying and planning decision. It is not legal advice, the Act's implementation continues to move, and no compliance decision should rest on a buying guide.
Decision shortcut
Still comparing options?
Use the table above to shortlist your best fit, then check related picks, tools, and buying guides before you make the final call.
FAQ
Does the EU AI Act apply to an Indian company?
It can, because the Act reaches systems whose output is used within the EU regardless of where the provider is established. An Indian SaaS vendor with EU customers, or an IT services firm building AI features used in the EU, should assume potential scope and confirm classification with qualified EU counsel rather than assume exemption.
What was due on 2 August 2026?
The Article 50 transparency obligations - telling users they are interacting with an AI system, marking AI-generated content in a machine-readable way, and labelling deepfakes - plus the AI Office's enforcement powers over general-purpose AI models. These took effect on schedule and were not delayed.
What are the fines under the EU AI Act?
Up to EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher, for prohibited AI practices. Up to EUR 15 million or 3 percent for other breaches, including general-purpose AI model obligations. Because the percentage is calculated on worldwide group turnover, the exposure is not bounded by EU revenue.
Features, model access, limits, privacy controls, and India billing can change. Choice IQ evaluates practical workflow fit and recommends checking the provider's current official terms before paying.
AI Tools Editor
Maya reviews AI products, productivity systems, and automation workflows with a focus on practical adoption.
The best choice is rarely the product with the longest feature list. It is the one you will still trust and use six months from now.
How Choice IQ evaluated this guide
Choice IQ evaluated the August 2026 position by which obligations took effect on 2 August against which were deferred to December 2027 and August 2028, the extraterritorial trigger for Indian providers and deployers, the penalty tiers and the turnover base they are calculated on, and the practical sequence of inventory, disclosure, classification and qualified legal advice.
Weekly intelligence
Get smarter AI tool picks weekly.
One useful email with practical comparisons, refresh alerts, and decision frameworks for people who do not want another noisy newsletter.
