Why in the News
The European Union’s Artificial Intelligence (AI) Omnibus entered into force on 27 July 2026 and changes parts of the European Union Artificial Intelligence Act, 2024 (EU AI Act). It extends some deadlines, simplifies some compliance requirements and gives regulators and companies more time to prepare for the high-risk AI rules. The EU AI Act was presented as a landmark effort to regulate AI through a risk-based framework, and its implementation has proved difficult. The revision is not a retreat from regulation. It is an admission that AI is changing faster than laws can normally change. The question this poses for India is how to regulate AI without slowing innovation, at a point where India has not enacted a comprehensive AI law of its own.
What is the EU AI Act’s risk-based framework?
- The organising principle: The Act sorts AI systems by the level of risk they pose and attaches obligations to each tier. The regulatory burden rises with the potential for harm rather than with the technology used.
- The prohibited tier: Some AI practices are prohibited outright under the Act. No compliance route is available for a practice in this category.
- The high-risk tier: High-risk systems face strict obligations before and during deployment. These are the obligations whose preparation deadlines the Omnibus has extended.
- General-purpose models: General-purpose AI models, meaning models trained broadly and adaptable to many downstream tasks rather than built for one application, came under a specific set of rules. They are governed separately from the risk tiers that apply to particular deployments.
What does the AI Omnibus change, and why now?
- The instrument and its date: The AI Omnibus entered into force on 27 July 2026. It amends parts of the AI Act rather than replacing the framework.
- Deadlines extended: Some compliance deadlines under the Act have been pushed back. Regulators and companies have more time to prepare for the high-risk AI rules.
- Compliance simplified: Some compliance requirements have been simplified. The obligations themselves remain in place at their existing levels.
- The reason stated: Implementation of the original framework proved difficult in practice. The Omnibus is the EU’s response to that implementation experience rather than to a change in the risk assessment.
- How it is characterised: The change is an admission that AI is changing faster than laws can normally change. It demonstrates that even a carefully designed regulation must be capable of adjustment.
What are the five lessons for India?
- Regulation must be capable of learning: Technology changes and risks change, so regulators must have the ability to review and adjust rules. Regulation should be treated as a continuing process rather than a single enactment.
- Regulation needs an escape valve: Rules work only where regulators and companies have the capacity to implement them. India should consider regulatory sandboxes and regular reviews of AI rules, and sunset mechanisms could make regulation more responsive.
- Compliance cost decides who can compete: Large technology companies can hire lawyers, engineers and auditors, and start-ups cannot always do so. Excessive compliance costs could unintentionally favour large companies and reduce competition.
- Simplification must not mean deregulation: Reducing paperwork is different from reducing safeguards. AI can create serious risks involving privacy, discrimination, manipulation and opaque decision-making, and simpler regulation must not mean weaker protection.
- Institutional maturity is the fifth lesson: The EU has shown that even a major regulatory framework can be revised after enactment. Regulatory maturity means recognising when rules are not working and changing them.
Where does India’s AI governance currently stand?
- A different path so far: India has focused on responsible AI, innovation and sector-specific governance rather than creating a comprehensive AI law. Sectoral regulators apply existing mandates to AI within their own domains.
- Flexibility carries a cost: Flexibility can be useful and it should not become uncertainty. Businesses need clarity, citizens need protection and regulators need clear responsibilities.
- The proportionality principle India would need: The regulatory burden should depend on potential harm. The greater the risk to people and society, the stronger the safeguards should be.
- The assets India brings: India has a large digital population and experience with digital public infrastructure. It also has a growing technology sector and experience in deploying digital services at scale.
- The institutions available to build on: The IndiaAI Mission can play an important role in an adaptive Indian model of AI governance. Regulatory sandboxes, sectoral regulators, research institutions and industry bodies can carry the rest.
Is regulation genuinely a trade-off against innovation?
- The framing the debate defaults to: The debate over AI is often presented as a choice between regulation and innovation. That framing treats every safeguard as a cost to be traded away.
- Why the framing is wrong: The choice is false because unregulated deployment carries its own costs in privacy, discrimination and opaque decision-making. The challenge is to design regulation that makes innovation safer and more trusted.
- What the EU revision actually demonstrates: The EU relaxed timelines and paperwork and did not relax the substantive safeguards. The revision therefore tests the trade-off framing and does not confirm it.
- The asymmetry the framing hides: Compliance cost falls hardest on the smallest firms, so heavy regulation reduces competition and light regulation reduces protection. India must create a framework that protects citizens while allowing experimentation, and be capable of changing as technology changes.
Challenges to a risk-based AI law in India
- Risk tiers age faster than statutes: A fixed list of prohibited and high-risk uses is overtaken by capabilities that did not exist when the list was drawn. Eg. General-purpose models required a separate rule set in the EU Act after the original risk-tier design was settled. Fix. Place the risk classification in delegated rules subject to a mandatory periodic review rather than in the parent statute.
- Regulatory capacity is the binding constraint: Enforcement requires auditors and technical staff who can inspect model behaviour, and those skills are scarce in the public sector. Eg. Implementation difficulty is the stated reason the EU extended its own high-risk deadlines. Fix. Build a shared technical audit facility under the IndiaAI Safety Institute that sectoral regulators can draw on.
- Algorithmic bias reproduces existing exclusion: Models trained on historical data encode the patterns of that data, including patterns of discrimination. Eg. An automated recruitment system built at Amazon was found to downgrade applications from women. Fix. Mandate pre-deployment bias testing and published audit results for any system used in employment, credit or welfare decisions.
- The accountability gap in automated decisions: It is often unclear who is answerable for an AI-driven decision, the developer, the deployer or the administrator. Eg. A welfare eligibility system can deny a benefit without producing a reason the applicant can contest. Fix. Impose a statutory right to an explanation and to human review for any automated decision affecting a legal right or entitlement.
- Compute and data concentration: AI capability is concentrated in a few advanced economies, which leaves other countries as consumers rather than creators of the technology. Eg. India’s response has been a national compute grid of over 38,000 graphics processing units under the IndiaAI Mission. Fix. Treat compute, datasets and models as shared developmental resources with subsidised access for start-ups and researchers.
Conclusion
The EU has demonstrated that a comprehensive AI framework can be enacted and then revised when implementation shows it is not working, and the AI Omnibus of 27 July 2026 is that revision. Its lesson for India is not that regulation should be lighter but that it should be capable of learning, proportionate to harm, affordable for small firms and explicitly separate from deregulation. India has no comprehensive AI law and has the digital public infrastructure, the sectoral regulators and the IndiaAI Mission to build an adaptive one. What remains unresolved is whether India converts its current flexibility into a stated framework with clear responsibilities, or leaves it as uncertainty that businesses and citizens both bear.
Government Initiatives on Artificial Intelligence
- IndiaAI Mission, 2024: Approved with an outlay of ₹10,371 crore and implemented by IndiaAI under the Ministry of Electronics and Information Technology. Its stated vision is making AI in India and making AI work for India, delivered through seven pillars.
- IndiaAI Compute and AIKosh: The compute pillar operates a national AI compute grid with over 38,000 graphics processing units at up to 40 per cent lower cost for eligible users. AIKosh is the national dataset repository with over 3,000 datasets and 243 models across 20 sectors.
- IndiaAI Foundation Models and FutureSkills: The foundation models pillar supports indigenous multimodal models built by entities including Sarvam AI and Gnani AI. FutureSkills funds fellowships and AI labs with a focus on Tier-2 and Tier-3 cities.
- Safe and Trusted AI: This pillar covers bias mitigation, privacy, explainability and AI governance, and it established the IndiaAI Safety Institute as a national trust framework. NITI Aayog’s Responsible AI for All initiative runs alongside it on public discourse and ethical audits.
- Language and access platforms: Digital India Bhashini provides speech and translation tools across 22 Indian languages, and Project Vaani has assembled a 150,000 hour Indian speech dataset. India hosted the India AI Impact Summit 2026 at Bharat Mandapam, the first major global AI summit in the Global South.
Challenges in AI Governance
- The black box problem: Deep learning systems produce outputs without an auditable chain of reasoning, so a regulator cannot reconstruct how a result was reached. Eg. Credit scoring models return a score without disclosing which variables drove it. Fix. Require model cards and decision logs for any system deployed in public service delivery.
- Deepfakes and synthetic media: Generative models produce convincing audio and video of real people at negligible cost. Eg. Synthetic audio of political figures has circulated during Indian election campaigns. Fix. Mandate provenance watermarking at the point of generation and place takedown obligations on intermediaries within a fixed window.
- Data protection exemptions for the state: Broad state exemptions in the data protection framework weaken the consent architecture that AI governance depends on. Eg. The Digital Personal Data Protection Act, 2023 exempts instrumentalities of the state notified by the government from key obligations. Fix. Narrow the exemption to defined purposes with independent oversight by the Data Protection Board of India.
- Cross-border data flows outrun domestic enforcement: Models trained and hosted abroad process Indian data outside the reach of Indian regulators. Eg. Cross-border transfer rules under the draft data protection rules remain contested for exactly this reason. Fix. Require local processing for high-risk categories and negotiate mutual enforcement arrangements with major host jurisdictions.
- Talent and jobs displacement: AI adoption reallocates work faster than reskilling systems can absorb the displaced. Eg. 87 per cent of Indian enterprises are actively deploying AI solutions, with adoption concentrated in industrial, retail, financial and healthcare sectors. Fix. Tie public AI funding to sector-specific reskilling commitments delivered through FutureSkills PRIME.
Matching Previous Year Question
“[2026] Which of the following statements with regard to Large Language Models (LLMs) used in machine learning is/are correct? 1. LLMs assign probabilities to the next possible words and then pick the one with the highest probability. 2. LLMs process data through mathematical optimization to minimise prediction errors. 3. LLMs produce unbiased outputs. (a) 1 only (b) 1 and 2 only (c) 2 and 3 only (d) 1, 2 and 3 ANSWER: B”
