
| PYQ Relevance [UPSC 2023] Introduce the concept of Artificial Intelligence (AI). How does AI help clinical diagnosis? Do you perceive any threat to privacy of the individual in the use of AI in healthcare? Linkage: The PYQ examines AI’s applications and its implications for privacy and individual rights. The EU AI Act shows how risk-based AI regulation can address privacy, safety and accountability concerns. |
Mentor’s Comment
The European Union Artificial Intelligence Act becoming applicable creates an opportunity for India’s technology services. Its compliance demands could generate work Indian firms can supply.
What is the EU AI Act?
- Risk-based law: The European Union Artificial Intelligence (AI) Act regulates AI systems by risk category.
- Applicability: It came into force in 2024 and its key obligations apply from 2 August 2026.
- High-risk systems: These require a conformity assessment before deployment.
- Extraterritorial reach: The Act can apply to entities outside the EU when their AI systems or models are placed on the EU market, used in the EU, or affect people in the EU.
Risk Categories
- Unacceptable risk: Systems like social scoring or manipulative/exploitative AI are completely banned.
- High risk: Critical sectors like biometrics, employment, and healthcare require rigorous data governance, logging, and conformity assessments.
- Transparency (Limited) risk: Chatbots and deepfakes must clearly disclose to users that they are interacting with AI or synthetic media.
- Minimal risk: Most everyday utilities like video games or spam filters face no mandatory rules.
Why does the EU regulate AI?
- Fundamental rights: Prevent discrimination, manipulation and unlawful surveillance.
- Safety: Ensure reliable and safe deployment of high-risk AI.
- Transparency: Help users distinguish AI-generated content from human-generated content.
- Trust: Create a predictable regulatory environment for responsible AI adoption.
Why does it challenge India’s IT model?
- Bespoke services: India’s IT-services firms build customised systems, and any “substantial modification” can trigger a fresh assessment.
- Compliance cost: Repeated conformity checks raise the cost of serving EU clients.
- Data governance: High-risk AI requires stronger data quality, traceability, record-keeping and governance, requiring firms to upgrade systems.
- Talent gap: Compliance requires professionals combining AI, law, cybersecurity, risk assessment and auditing skills.
- Shift in competitive advantage: India’s traditional cost-based IT model must evolve towards trusted, auditable and regulation-ready AI services.
Where is the opportunity?
- Compliance services: Demand rises for legal, technical, and audit services to meet the Act.
- Notified bodies: The India-EU Free Trade Agreement could let Indian conformity assessment bodies be recognised as EU “notified bodies”.
- First-mover edge: Early compliance capability positions India as a preferred AI-services partner.
- AI Assurance: Indian firms can offer AI risk assessment, algorithmic auditing, testing, documentation and certification support to global clients.
- Compliance-by-design: Indian IT companies can build EU-compliant AI systems from the development stage, turning regulatory expertise into a new export advantage.
What are the challenges to capturing the opportunity?
- Standards gap: India lacks a mature domestic AI conformity-assessment ecosystem.
- Mutual recognition: Recognition of Indian bodies depends on the FTA’s regulatory-cooperation terms.
- Talent: Specialised AI-audit skills are scarce.
- Regulatory clarity: India’s own AI governance framework is still evolving.
Conclusion
The Act raises compliance costs but also creates a services market India can serve. Capturing it depends on the India-EU FTA delivering mutual recognition of conformity assessment bodies.