AI Applications
How Is AI Regulated? A Straight Answer for 2026
AI is not governed by one law. It is regulated through existing general law, sector regulators, new AI-specific statutes like the EU AI Act, and voluntary standards such as ISO 42001 and the NIST AI Risk Management Framework. This article explains how each layer works, how the EU, US, China and India differ, what applies to Indian companies today, and what you should actually do if you build or buy AI at work.
Admin ·
AI is not governed by one law. It is regulated through existing general law, sector regulators, new AI-specific statutes like the EU AI Act, and voluntary standards such as ISO 42001 and the NIST AI Risk Management Framework. This article explains how each layer works, how the EU, US, China and India differ, what applies to Indian companies today, and what you should actually do if you build or buy AI at work.
The short answer: in layers, not by one law
No country regulates AI with a single statute that covers everything. Regulation happens in four layers stacked on top of each other, and most of what binds you today was written before ChatGPT existed.
The first layer is ordinary law that never mentions AI. If your model discriminates in hiring, that is employment law. If your chatbot lies about a refund policy, that is consumer protection. If your training data was scraped from paywalled books, that is copyright. Courts have been applying these rules to AI for years without needing new ones.
The second layer is sector regulators. Banking, insurance, health, medical devices, elections, aviation. These bodies already license what you can deploy in their domain, and several have issued AI-specific guidance.
The third layer is new horizontal AI law. The EU AI Act is the big one. Colorado passed a state AI act. China has a set of them.
The fourth layer is voluntary standards that become effectively mandatory through procurement. ISO/IEC 42001 and the NIST AI Risk Management Framework are the two that enterprise buyers now ask for.
Four models, four very different philosophies
Where a country lands depends on what it is most afraid of. Europe fears harm to individuals. The US fears losing the race. China fears loss of information control. India is trying to regulate outcomes without slowing adoption.
That difference matters commercially. A product that ships in Bengaluru with a light disclosure banner may need conformity assessment documentation, a registered EU representative and post-market monitoring before it can be sold in Frankfurt.
| Jurisdiction | Main instrument | Approach | Practical effect |
|---|---|---|---|
| EU | AI Act (in force since August 2024) | Risk tiers applied to the use case, not the technology | Heavy documentation for high-risk uses; bans on a small set of practices |
| US | No federal AI statute; state laws and sector rules | Sectoral and fragmented | Colorado, California, Illinois and NYC rules bite; federal posture shifted pro-innovation in 2025 |
| China | Generative AI Interim Measures (2023), deep synthesis and labelling rules | Content control plus filing with the regulator | Public-facing models must be filed with the CAC; AI-generated content must be labelled |
| India | DPDP Act 2023, IT Act and IT Rules, MeitY guidelines | Light-touch, existing law first, sector regulators second | No AI licensing today; privacy, intermediary and deepfake rules already apply |
The EU AI Act, because it sets the global default
The Act sorts systems by risk. A handful of practices are prohibited outright, including social scoring by public authorities and untargeted scraping of facial images to build recognition databases. Those bans applied from February 2025.
High-risk is the category that actually costs money. It covers AI used in recruitment, credit scoring, education admissions and grading, essential public services, law enforcement and medical devices. If your system lands there, you need a risk management process, data governance records, technical documentation, human oversight, logging and a conformity assessment before you go to market. Those obligations phase in through 2026 and 2027.
Below that sits a transparency tier. Users must be told they are talking to a machine, and synthetic media must be machine-readably marked. General purpose model providers picked up their own set of duties from August 2025, including training-data summaries and copyright policies.
Penalties run up to 35 million euros or 7 percent of global turnover for prohibited uses. And the Act applies extraterritorially: if your output is used in the EU, you are in scope even if your entire team sits in Pune.
What actually applies in India right now
There is no AI licensing regime in India, and nobody needs approval to deploy a model. That is a deliberate choice, not an oversight.
What does apply is real, though. The Digital Personal Data Protection Act, 2023 governs any personal data you feed into a model, which quietly covers most enterprise AI projects: consent, purpose limitation, notice, breach reporting, and obligations on the data fiduciary that do not disappear because a vendor's API did the processing. The IT Act and the 2021 intermediary rules cover platforms hosting AI-generated content, and MeitY has pushed hard on labelling synthetically generated media after the deepfake cases of 2024 and 2025.
MeitY published India AI Governance Guidelines in late 2025, setting out principles, an institutional structure and a preference for using existing regulators rather than creating a new AI authority. It is guidance, not statute. Treat it as a signal of what enforcement will look like.
Sector regulators are moving faster than Parliament. The RBI's FREE-AI committee laid out expectations for responsible AI in financial services, and SEBI has rules for market intermediaries using AI, including accountability for outputs regardless of who built the model. If you work in a regulated sector, your regulator's circular is more relevant to you than any AI bill.
What this means if you build or buy AI at work
Most people asking how AI is regulated are really asking a narrower question: am I about to get my company in trouble. Usually the answer is no, but the gaps are predictable. Vendor contracts that say nothing about training data. Nobody who can produce a list of AI systems currently in production. HR running a resume screener that nobody has audited for adverse impact.
Compliance for a mid-sized Indian company is not a legal department problem. It is an operations problem, and the work is boring rather than difficult.
This is also the fastest-growing non-technical AI job family. AI governance leads, model risk analysts and audit specialists are being hired by banks, IT services firms and consultancies, and the qualification is mostly demonstrated fluency in both the technology and the frameworks. If you want that fluency without a law degree, a structured, mentor-led AI Masterclass that puts you inside real AI workflows will teach you more than reading the Act clause by clause, because you cannot govern a system whose failure modes you have never seen up close.
Regulation is not the thing that will stop you from using AI. Not knowing what you have deployed is.
- Build an inventory. Every AI system in use, what it decides, whose data it touches.
- Classify by consequence, not by how clever the model is. A tool that ranks job applicants is high stakes. A tool that drafts social captions is not.
- Fix the contracts. Ask vendors about training data, indemnities, data residency and whether your prompts train their models.
- Keep a human in the loop wherever a decision affects a person's money, job, health or education, and record that the human actually reviewed it.
- Log outputs and incidents from day one. Retrofitting an audit trail after a complaint is the expensive path.
FAQs
1. Does the EU AI Act apply to Indian companies?
Yes, if the output of your AI system is used inside the EU, or if you sell or supply the system there. An Indian SaaS firm with European customers is in scope, and high-risk systems require an authorised representative in the EU.
2. Is there a dedicated AI law in India?
Not as of early 2026. India regulates AI through the Digital Personal Data Protection Act 2023, the IT Act and its rules, MeitY's India AI Governance Guidelines, and sector regulators like the RBI and SEBI.
3. Do I have to disclose that content was made with AI?
In the EU, yes for synthetic media and chatbots under the AI Act's transparency rules. In China, AI-generated content must carry labels. India has been tightening labelling requirements for synthetically generated information under the IT rules, and most large platforms now require creator disclosure regardless of law.
4. What is ISO 42001 and do I need it?
ISO/IEC 42001 is an international standard for an AI management system, similar in spirit to ISO 27001 for information security. It is voluntary, but enterprise and government buyers increasingly ask for it in procurement, which makes it commercially close to mandatory for AI vendors.
5. Who is liable when an AI system causes harm?
Generally the organisation that deployed it, not the model provider, unless the contract shifts that risk. Regulators in finance and healthcare have been explicit that accountability stays with the licensed entity even when the model is third-party.
6. Is AI governance a real career path?
Yes, and it is growing fastest in banks, insurers, IT services firms and consultancies that serve EU clients. The roles blend technical understanding of model behaviour with knowledge of frameworks like the EU AI Act, NIST AI RMF and ISO 42001, and they do not require a law degree.