A Grace Period Just Ran Out
On 2 August 2026, a one-year grace period that had shielded the world's largest AI labs from active enforcement quietly expired. From that date, the European Commission's AI Office can demand a general-purpose AI model be evaluated before it ever reaches EU users, restrict or withdraw that model from the EU market entirely, and fine its provider up to €15 million or 3% of global annual turnover — whichever figure is larger. Anthropic, OpenAI, and Google are named explicitly among the firms now under this scrutiny, regardless of the fact that none of them are headquartered in Europe. The timing overlapped with something unrelated but telling: the Commission had separately pressed Anthropic to give the EU's cybersecurity agency, ENISA, direct access to one of its models after it was linked to attacks on real companies — a reminder that this isn't a hypothetical power being tested for the first time.
What Brussels Can Actually Do Now
It's worth being precise about what changed on 2 August, because "the EU is cracking down on AI" undersells the mechanics. The AI Office's powers, all now active, are:
- Pre-Release Evaluation: The Commission can demand technical access to a general-purpose model and evaluate it before it is made available in the EU.
- Market Restriction: It can restrict or withdraw a non-compliant model from the EU market outright, not just fine the company after the fact.
- Financial Penalties: Fines run up to €15 million or 3% of the provider's worldwide annual turnover, whichever is higher.
- Independent Grounds for Fines: Refusing a documentation request, obstructing an evaluation, or ignoring an ordered fix is each, on its own, enough to trigger a fine — a company doesn't need to have caused harm yet.
India Is Not the Small Market in This Story
The easy assumption is that the EU can do this because it's a large, wealthy bloc and other markets simply aren't big enough to matter to an AI lab. That assumption doesn't survive contact with India's actual numbers. Anthropic has said India is its second-largest market for Claude worldwide, after only the United States, and opened its first India office in Bengaluru this year. It has committed to a dedicated multi-month effort to improve Claude's performance across ten major Indian languages — Hindi, Bengali, Marathi, Telugu, Tamil, Punjabi, Gujarati, Kannada, Malayalam, and Urdu. India's population exceeds 1.4 billion against the EU's roughly 450 million, with more than 700 million smartphone users. By any measure of raw commercial weight, India is not the junior partner in this comparison.
What India Has Instead
India does not have a dedicated AI statute, and the government has been explicit that it does not currently see the need for one — its stated approach is to extend existing sectoral laws (IT rules, competition law, consumer protection) to AI rather than legislate a standalone regime. The closest thing to a binding foundation is the Digital Personal Data Protection Act of 2023, which governs how personal data is collected and processed — a real legal layer, but one aimed at data handling, not at evaluating or restricting a model's behavior. Earlier this year, the government unveiled AI Governance Guidelines at the India AI Summit 2026, explicitly describing them as a "light-touch" framework that prioritizes innovation and relies on voluntary adoption. Guidelines are not law. No Indian authority can currently do what the EU's AI Office did on 2 August: demand to evaluate a model before release, or fine a provider for refusing to comply.
The Gap Isn't Size. It's Architecture.
This is the point worth sitting with, because it cuts against the usual sovereignty narrative. The EU's AI Act wasn't a switch someone flipped this month — it passed in 2024, its General-Purpose AI Code of Practice was published in July 2025, GPAI obligations became binding that August, and enforcement was deliberately held back for a full year to let providers operationalize before the Commission would use its teeth. That's not luck or market size; it's four years of building a standing institution — the AI Office — with the specific technical capacity to inspect models and the specific legal authority to act on what it finds. India's guidelines emerged from a summit announcement, not a multi-year legislative and institutional build-out. Even if India passed an AI law tomorrow, it would still need years to stand up the equivalent of an AI Office before that law meant anything at model-inspection scale. Leverage, in other words, isn't a function of GDP or user count. It's a function of whether a government spent years building the specific machinery to convert its market size into enforceable terms — and the EU is currently the only jurisdiction that has.
Why India Shouldn't Just Copy Brussels
None of this is an argument for India to legislate a carbon copy of the EU AI Act. The EU can afford the compliance burden the Act places on providers because it is not trying to attract AI labs to build there — it is negotiating access to a market that AI labs already need. India, courting AI investment, a growing developer base, and firms like Anthropic that are actively localizing for it, has more to lose from a blanket, EU-style regime that raises the cost of operating in the market it's currently winning by being useful. The more defensible move is narrower: binding, inspectable rules specifically for high-stakes uses — financial services, healthcare, elections and deepfakes — rather than a general-purpose licensing regime for every model. That is also the piece BizTechLab's own "Digital Sovereignty" argued was missing on the infrastructure side: indigenous compute and local model capacity address dependency, but they don't, by themselves, give a government the authority to inspect or restrict a foreign model already operating in its market. Enforcement architecture is a separate lever from compute sovereignty, and India currently has neither fully built.
What This Actually Changes
Until India's AI governance moves from guidelines to a statute with real inspection and financial teeth behind it, every dispute with a foreign AI provider over safety, data use, or model behavior gets settled on terms set somewhere else — most likely Brussels, since it's currently the only jurisdiction that built the machinery to set terms at all. That won't change because India's market grows further; it will change only when India builds the institutional equivalent of the AI Office, which is a multi-year commitment, not a summit announcement.
EU: binding AI Act (2024) with a dedicated AI Office. India: voluntary guidelines from the 2026 AI Summit, no standalone statute.
EU: ~450M consumers. India: 1.4B+ people, 700M+ smartphones, Anthropic's #2 Claude market worldwide.
EU: pre-release model evaluation, market bans, fines up to 3% of global turnover. India: none of the above, currently.
EU: refusing documentation or evaluation is independently finable. India: compliance remains voluntary.
