India’s AI Governance at a Crossroads: Lessons from the EU AI Act
Bismillah Bee cannot fathom owning a car. She is a 67-year-old widow living in a confined three-room home with a family of 12, subsisting on an income from peeling garlic for a local business. Despite Bee’s family being listed as “below the poverty line”, the Telangana government’s algorithmic system “Samagra Vedika” deprived her family of subsidised food because of an algorithmic error identifying her late husband as a car owner. When Bee sought to overturn the decision, officials trusted the algorithm over her testimony. Eventually, her plight did reach the Supreme Court of India, yet after seven years, Bee remains without a resolution.
To assume that Bee’s story is an aberration is simply reductive. In the span of five years, 2014 to 2019, around 1.86 million food security cards were cancelled, along with 142,086 new applications rejected by Telangana’s faulty data and obscure algorithmic decisions.
This is how unregulated artificial intelligence looks in practice. Despite India emerging as the world’s most prolific adopter of AI, it remains among the least accountable. The central problem of this article is examining this asymmetry. The European Union’s Artificial Intelligence Act, enacted in 2024, provides a governance framework that offers a reference point India could draw on while curating its own legislative infrastructure.
The Cost of Inaction
Along with Samagra Vedika, other operational and looming systems also persist within India’s public infrastructure. The National Crime Records Bureau’s Automated Facial Recognition System tendered in 2019 was deployed incrementally across law enforcement agencies with no legislation authorising its use. The Right to Information data revealed that most police authorities in Punjab and Mumbai decline to respond to questions about personnel overseeing the system, how it operates, or what happens when the system misidentifies.
The consequences of such systems have real-world implications. In January 2023, a resident of Telangana, Mohammed Khadeer, was mistakenly identified as a suspect by facial recognition software in a chain-snatching incident. After being held in illegal custody and enduring custodial torture for five days, he succumbed to his injuries at Gandhi Hospital in Hyderabad.
Most recently, Delhi’s Safe City Project is aiming to deploy “10,000 AI-enabled cameras with facial recognition and distress detection” by 2026. Again, no legal framework is set in place to govern how data will be accessed, stored or even challenged.
India’s AI governance infrastructure alarmingly lags. In November 2025, at the launch of India’s AI Governance Guidelines, IT Secretary S. Krishnan stated that “India has consciously chosen not to lead with regulation but to encourage innovation while studying global approaches. Wherever possible, we will rely on existing laws and frameworks rather than rush into new legislation.” However, existing laws or frameworks do not address AI risks. None can determine whether a facial recognition system or a welfare algorithm should be assessed before deployment. This task requires an AI risk classification framework, which isn’t yet developed in India.
India’s Current Standing in AI Governance
India’s commitment to building an AI governance foundation is both credible and well-established. In March 2024, the Cabinet approved a five-year budget of ₹10,371.92 crore for the IndiaAI Mission. The mission proliferated GPU access to 38,000 units and built three centres of excellence across agriculture, healthcare and sustainable cities. As a founding member of the Global Partnership on Artificial Intelligence, established in 2020, India hosted the Global IndiaAI summit in New Delhi as the lead chair in 2024 to advance a safer, more secure, and more trustworthy AI for global public policy.
Moreover, in February 2026, Prime Minister Modi chaired the AI Impact Summit, securing adoption from 89 countries (the highest consensus achieved in the global AI summit series) on human-centric AI, data governance, workforce transitions, and equitable AI access across emerging economies.
However, the current governance infrastructure has not kept pace. Instruments such as the India AI Governance Guidelines 2025 and the RBI’s AI Framework 2025 remain voluntary alongside the Digital Personal Data Protection Act 2023, with limited AI-specific provisions (still under Supreme Court challenge). There are a few sectoral exceptions, including SEBI’s mandatory AI/ML reporting algorithmic trading framework 2025 and the IT rules amendment 2026 covering synthetic content, both of which are binding. Lastly, the AI Ethics and Accountability and the three proposed institutions, i.e. the AI Safety Institute, the AI Governance Group and the Technology and Policy Expert Committee, are recommended but not yet established.
This gap between ambition and accountability is structural. Recommendations arrive before enforcement, and instruments largely remain voluntary even where risks are already documented.
The EU Artificial Intelligence Act
The European Union’s Artificial Intelligence Act is the first-ever legal framework which entered into force on the 1st of August 2024. The goal of this act was not to regulate technology but to foster trustworthy AI and regulate harm. Built on the principle that the greater the harm, the more stringent the obligation, the act formulates a four-tier framework classifying AI according to its risks:
1) Prohibited:
Unacceptable risks. Eight practices are banned under Article 5 – Prohibited AI Practices, including social scoring, mass biometric surveillance, and predictive criminal profiling.
2) High-Risk:
Subjected to stringent regulations. Areas include Welfare and benefit eligibility, Employment and hiring decisions, Border and migration control (Annex III of the EU AI Act)
3) Limited Risk:
Subjected to transparency obligations. Examples include chatbots/visual assistants, AI-generated text, images, audio and video, deepfakes (Article 50)
4) Minimum Risk:
Unregulated, no mandatory obligations. For example, AI-powered autocorrect, Netflix recommendation engine (transparency risk under Article 50)
Distinctly, the Act also established obligations for General Purpose AI models. Providers are required to publish evidence for building their foundation model, including the data used for training, compliance with the Copyright Directive, technical records, a user manual, and systemic risk assessments. (applicable since August 2025). Non-compliance with GPAI obligations can cost firms up to €15 million or 3% of their global turnover.
The Artificial Intelligence Act offers the most valuable lesson for India, which is accountability before deployment. Currently, India is doing the opposite; it has no mechanism in place to differentiate which AI systems require strict regulation, transparency, or an outright ban. Currently, all systems operate in an ungoverned realm, irrespective of the harm they pose.
India’s Algorithmic Systems Through the EU AI Act’s Lens
Firstly, the NCRB’s Automated Facial Recognition System would have instantly violated Article 5 of the AI Act. Real-time biometric identification is prohibited, except for cases such as locating missing persons, identifying suspects in a serious criminal offence, or preventing an imminent threat to life or a terrorist attack, each of which requires prior judicial authorisation. The chain-snatching incident leading to Mohammed Khadeer’s death falls under the ‘serious criminal offence‘ exception, meaning such use is not categorically banned in Europe. It would, however, require prior judicial authorisation, a safeguard that is not sought in India. For India, the lesson is not about a ban but about ensuring that no system should have the capability, or the judicial authorisation, to deprive an individual of their liberty.
Secondly, algorithms such as the Samagra Vedika fall under the high-risk category of the EU AI Act. The framework specifically highlights that all consequential AIs must pass through mandatory bias audits, demonstrate accuracy and accountability before deployment and maintain human oversight mechanisms.
Bismillah Bee’s ordeal has already occurred. With a risk classification framework and audit mechanism in place, similar cases could be subjected to independent review on the grounds of auditability, accuracy, and contestability.
Thirdly, the 2024 general election showed similar gaps. More than 75 per cent of Indians were exposed to political deepfakes, and one in four believed AI-generated content was real. Even a falsified video of Home Minister Amit Shah spread across the nation with no label or authorisation. Election deepfakes automatically fall under the minimum risk category under Article 50 of the EU AI Act. It is not banned, but they require minimum obligations, such as displaying a clear label before distribution. Even though India’s IT rules, enacted in February 2026, included a labelling requirement, it was at the cost of an already compromised national election. As a result, India must not only acknowledge the importance of formulating a softer governance obligation than the EU’s risk-tiered model but also act promptly before the harm occurs, not after.
For India, a government notification can itself resolve the first two issues without passing new legislation. For the third, it will require a new law, but India has passed laws before and faster when required.
The Lessons That Do Not Travel
These lessons are adaptable, but the EU’s AI architecture is not. India cannot import the model in its entirety, as adoption without adaptation would create compliance burdens disproportionate to India’s current enforcement capacity
Some elements of the Act’s guidelines have limited transferability, for example, the outright ban. The EU’s prohibition of the existing eight practices is backed by enforcement infrastructure capable of giving it substance. Clearview AI amassed over €95 million in fines across multiple European jurisdictions for violating the ban. The fine subsequently created a market correction wherein companies changed course, and prohibition pivoted from a declaration to a deterrent.
The Omnibus retreat cuts both ways. On one hand, it substantiates the argument against adopting the EU’s architecture, since the EU itself has deemed it overly burdensome with regulatory infrastructure built over almost three decades. On the other hand, it does come across as lending credence to the current position the piece has argued, which is that innovation should precede restraint. India’s own AI Impact Summit articulated a parallel position, championing flexible guardrails over rigid compliance for the Global South. This is not a matter of choosing flexibility over rigidity, but whether it is accompanied by enforcement or stands in for its absence.
India currently does not have a designated authority, enforcement mechanism, or penalty structure needed to implement an outright ban. The only penalty proposed is about ₹5 crore under a Private Member’s Bill in 2025, which has not yet been enacted. For India, it is not about whether they should have these systems but whether they should run without any accountability.
For India, it can develop a solid foundation by using the EU Act’s risk classification logic as a first step and by adding its own enforcement structure, based on its documented recent failures. A basic public register, human oversight, and a grievance mechanism designed for affected individuals, rather than algorithmic outputs, remain absent from India’s current framework.
An India-fit enforcement model necessitates a federated, rather than centralised, approach. It requires a national AI coordination body empowered to establish minimum standards, risk tiers and technical reporting protocols. Concurrently, ministries or state departments could govern deployment decisions through mandatory technical assessments, particularly before the launch of high-risk systems, with the outcome recorded in a public register to ensure that the system’s purpose, existence, and audit status remain documented rather than assumed. For public-sector use, the review can be channelled through independent technical panels and procurement rules, with the Comptroller and Auditor General serving a verificatory role rather than providing direct approval. India does not need a super-regulator but an enforceable checkpoint comprising audit, procurement and domain-specific oversight
Moreover, the existing grievance bodies must remit beyond data handling to cover algorithmic harm. The Data Protection Board could broaden its scope to assess how algorithmic errors produce wrongful outcomes, with Grievance Appellate Committees extended to cover deployer-side algorithmic decisions. Given India’s substantial informal workforce, such services would need to be delivered through existing infrastructure already in use, such as Common Service Centres or the Public Distribution System. These channels, however, would first need to surpass their current efficiency levels before they could assume any additional functionality.
Strategic Outlook
Moving forward, India’s AI trajectory is more likely to converge, driven by judicial pressure and market compliance requirements. India’s European export market wouldn’t wait for parliamentary consensus. It comes with a deadline. According to the Indian Brand Equity Foundation, India’s IT sector generates over $58.8 billion annually from European markets. From 2026, Indian firms catering to the European market must comply with the EU AI Act’s transparency obligations. For high-risk compliances, including credit, employment, healthcare and consumer-facing AI, Indian firms must complete their conformity assessment by December 2027.
It is likely (60-75%) that external pressure from the EU could fast-track India’s domestic governance discussion, not through new legislation but by prompting firms to build their own internal AI governance to satisfy their EU clients. The government will face significant pressure to align with what Indian firms are practising to remain compliant and what the country’s domestic system would expect from government AI.
The forecast for India’s AI landscape is incremental.
India has the constitutional values, the judicial principles, and the evidence to construct a conditional framework, but lacks the legislative requirements to connect these into an enforceable architecture.
India is not only the second-largest GenAI startup hub; it is also the pioneer of Digital Public Infrastructure, the author of the ‘AI for All’ doctrine, the GPAI Lead Chair, and a signatory to the EU-India Free Trade Agreement (2026). India’s governance choice reverberates far beyond its borders. For developing democracies, it poses a pressing question of whether responsible AI governance is possible on their own terms without following the EU’s AI path. India has proven, through programmes such as the Unified Payment Interface (UPI) and Aadhaar, that democratic governance can operate at a population scale. Whether that holds for democratic AI governance grounded in transparency and accountability is the question India must answer now.