Governance · 2 July 2026 · 6 min read

The EU AI Act reaches your Indian software company

You do not need an EU office to be inside its scope. You need an EU customer.

The most common misreading of the EU AI Act among Indian suppliers is jurisdictional: the belief that a company registered in Haryana and taxed in India is outside a European regulation. The Act is written to follow the output, not the entity. If a system's results are used inside the Union, the obligations travel with it — and they land on your customer, who will pass them to you as contract terms long before any regulator writes to you directly.

That is the practical mechanism to plan around. You will meet this regulation as a procurement questionnaire, not as an inspection.

The only classification question that matters first

The Act sorts systems by risk, and the entire cost of compliance depends on which bucket a use case falls into. Practically, three matter:

  • Prohibited — a short list, but worth reading once so you can recognise a request you should decline.
  • High-risk — the expensive tier. Includes systems used in employment decisions, creditworthiness, education access, essential private and public services, and safety components. This is where documentation, risk management, human oversight, logging and post-market monitoring obligations bite.
  • Limited and minimal risk — transparency duties mostly: telling people they are interacting with an AI system, labelling synthetic content.

A great deal of enterprise AI work is not high-risk and the classification exercise ends cheaply. But a recruitment screening tool, a credit decisioning assistant or anything touching access to services is high-risk regardless of how simple the implementation is. Classification is a half-day of work and it changes the budget by an order of magnitude, which makes doing it first the highest-return hour in the project.

What a high-risk classification actually demands

Stripped of the legal language, the obligations are a familiar engineering list: a documented risk management process that runs continuously rather than once; data governance covering the training and reference data, including how bias was examined; technical documentation sufficient for someone else to assess the system; automatic logging of operation; instructions for use written for the deploying organisation; meaningful human oversight designed in rather than asserted; and accuracy, robustness and cybersecurity claims you can evidence.

None of that is unreasonable. All of it is dramatically cheaper to build in than to reconstruct.

Why ISO 42001 is the efficient route

ISO/IEC 42001 is an AI management system standard, and its structure maps closely onto the Act's governance expectations. Building the management system once gives you an auditable answer to a European procurement questionnaire, a Japanese one, and a large Indian enterprise's vendor review — rather than answering each in a bespoke document. For a small firm, that leverage is the whole argument.

The sequencing that costs least, in our experience of the certification market: ISO 27001 first, because information security controls underpin everything and European RFPs ask for it almost universally. Then ISO 42001, which reuses a large share of that groundwork. SOC 2 only if a specific US enterprise deal requires it — roughly 70–80% of its controls overlap with ISO 27001, so it is far cheaper second than first.

AI governance is currently the rare combination of high and rising demand with genuinely scarce supply. For a small consultancy that is not a compliance cost. It is the moat.

The four things to do this quarter

  1. Inventory every AI system you build or operate, and classify each one under the Act. Half a day, and it tells you where the money is.
  2. For anything high-risk, start the technical documentation now, from the current design, while the people who made the decisions still remember why.
  3. Add an AI-specific schedule to your MSA covering classification, logging, oversight and who holds which obligation between you and your customer.
  4. Decide your certification order and put a date on ISO 27001. It is roughly ₹2–4 lakh and twelve to sixteen weeks, and it is the credential that unblocks European RFPs.

The firms that treat this as paperwork will do it twice. The ones that treat it as architecture will do it once and quote it in sales calls.

If this was useful

The assessment is the same thinking, applied to your systems.

Two to three weeks, a scope agreed in writing before it starts, and a document you can act on whether or not you hire us for the build.