All articles
News & Analysis 7 min read 23 September 2026 Primitra

The EU AI Act Deadline Just Moved to 2027 — Here's Why Indian AI Companies Shouldn't Relax

The EU's high-risk AI obligations were pushed from August 2026 to December 2027 under the new Digital Omnibus. Here's what actually changed, what didn't, and why Indian AI and SaaS companies still need to move on both EU AI Act readiness and DPDP compliance.

The EU AI Act Deadline Just Moved to 2027 — Here's Why Indian AI Companies Shouldn't Relax

If your product touches Europe, you've probably heard that the EU AI Act deadline for high-risk AI systems just got pushed back by sixteen months. That's true, and it's real relief for anyone racing toward an August 2026 cutoff. But treating this as a green light to stop working on AI governance would be a mistake, especially if you're an Indian company that also has the DPDP Act to answer to at home. Here's what actually changed, what didn't, and what it means for founders and compliance teams here.

What Actually Changed on July 27, 2026

The EU's "Digital Omnibus" package, formally Regulation (EU) 2026/1744, entered into force on 27 July 2026 after the European Parliament approved it on 16 June and the Council gave final sign-off on 29 June. The headline change: obligations for high-risk AI systems under Annex III (think biometric identification, credit scoring, employment screening, education platforms, and access to essential services) move from 2 August 2026 to 2 December 2027. AI embedded in products already covered by EU product-safety law, the Annex I category, gets pushed further still, to 2 August 2028.

For companies that were sprinting to finish conformity assessments, technical documentation, and CE marking by August, this buys real time. Several law firms and compliance trackers, including Gibson Dunn and DLA Piper, confirmed the same dates independently, so this isn't a rumor circulating on compliance forums.

What Didn't Move

Two things stayed on the original clock, and Indian companies selling AI tools into the EU market need to know both.

First, Article 50 transparency obligations, including the AI-content labeling and watermarking requirements for generative systems, still take effect on 2 December 2026. If your product generates synthetic text, images, audio, or video for EU users, you still need disclosure mechanisms working by that date.

Second, a new Article 5 prohibition banning AI systems that generate non-consensual intimate imagery also lands on 2 December 2026, with no delay attached. This one matters less for B2B SaaS but is worth knowing if your platform touches user-generated content or image synthesis at all.

Why This Matters for Indian AI and SaaS Companies

A fair number of Indian startups building AI features, from recruitment screening tools to lending-risk models to ed-tech platforms, have customers or users in the EU, even if that wasn't the original target market. The deadline push doesn't remove the underlying question: is what you've built a high-risk system under the Act's Annex III categories? That classification exercise is worth doing now, deadline or not, because retrofitting governance into a live product is far more expensive than designing it in from the start.

More importantly, the EU timeline shift changes nothing about your obligations back home. If your AI system processes personal data of Indian users, the DPDP Act applies regardless of what Brussels decides. And if the system does anything algorithmic with that data, profiling, automated scoring, personalization, you're already inside the scope of the due diligence conversations regulators expect from Significant Data Fiduciaries and increasingly from ordinary data fiduciaries too.

DPDP Compliance Doesn't Wait for Brussels

It's tempting to treat data protection as one global checklist, but the DPDP Act and the EU AI Act solve different problems. The DPDP Act governs how you collect, use, and safeguard personal data. The AI Act governs how your AI systems behave and what risks they pose regardless of whether personal data is involved. A model can be fully DPDP-compliant on data handling and still qualify as high-risk under EU rules because of what it decides, not what data it touches.

That said, the two frameworks overlap in practice. Both expect documented risk assessment before deployment, both expect a named person accountable for the system, and both expect you to be able to explain, on request, how the system reaches its outputs. A privacy impact assessment done properly for DPDP purposes will surface most of the same questions an EU AI Act risk classification exercise would ask. Doing one well makes the other considerably less painful.

A Practical Checklist for the Next Six Months

Indian companies with any EU exposure should use this breathing room deliberately rather than shelving the topic entirely.

Map which of your AI features, if any, could fall under Annex III categories, and document that reasoning even if the answer is "not applicable." Confirm your Article 50 transparency and labeling work is on track for the December 2026 date, since that one didn't move. Run or update a data protection impact assessment for any AI feature that processes personal data of Indian users, since DPDP obligations around notice, purpose limitation, and security safeguards apply now, not in some future phase. If you sell into both India and the EU, consider whether your compliance program can share infrastructure, a single risk register, a single DPO or accountable owner, rather than running two disconnected efforts.

Companies already working with a Data Protection Officer or compliance partner should raise this specifically in their next review rather than assuming it's covered by general "we'll deal with AI later" conversations.

Where This Leaves Indian SMEs

The practical takeaway is that a delayed deadline is not a canceled one, and regulators on both sides, India's Data Protection Board and the EU's AI Office, have signaled they intend to use this window for enforcement readiness rather than further delay. Companies that use the next sixteen months to build real documentation, rather than waiting for the next deadline scare, will be in a materially better position than those that treat this as permission to do nothing. If you're already working through GDPR compliance for EU customers, folding AI Act readiness into that same program now is far cheaper than bolting it on later.

This article is general guidance for informational purposes and is not legal advice. DPDP Act and EU AI Act obligations depend on your specific data processing and business context; consult a qualified professional before making compliance decisions.

Not sure where your company stands? Run through our DPDP compliance checklist or get in touch for a practical assessment.

Get help implementing this

Turn this reading into a compliance plan.

Book a free 30-minute consultation. We'll map your DPDP Act exposure and give you a prioritized 90-day action list — no obligation.

Book a free 30-minute consultation