Subject: Current Affairs | Published: 25 November 2025
Eu Al Code of Practice on General Purpose Gpai
Recommended UPSC Book List
Access the curated list of standard books and resources used by top aspirants for all subjects.
In a move poised to reshape the global digital landscape, the European Union formally adopted the EU AI Act in May 2024, establishing the world’s first comprehensive and legally binding framework for Artificial Intelligence. This landmark legislation represents a pivotal moment in the governance of emerging technologies, seeking to strike a delicate balance between fostering innovation and safeguarding fundamental rights, safety, and democratic values. The Act is not merely a regional policy; it is a bold declaration of regulatory philosophy, designed to export its principles globally and set a new gold standard for how societies manage the profound opportunities and existential risks associated with AI. For nations like India, a rising AI powerhouse, understanding the intricacies of this Act is not just an academic exercise but a strategic imperative, with significant implications for its burgeoning tech industry, its regulatory ambitions, and its economic future.
The Core Philosophy: A Risk-Based Regulatory Pyramid
The foundational principle of the EU AI Act is its risk-based approach, a pragmatic and proportionate regulatory model that categorizes AI systems based on their potential to cause harm. This tiered structure avoids the pitfalls of a one-size-fits-all regulation, which could stifle innovation in low-risk applications while failing to adequately police high-stakes systems. The framework can be visualized as a pyramid, with the most stringent rules applied to the smallest category of AI systems at the top, and the lightest touch reserved for the broad base of minimal-risk applications.
Analogy: The AI Act’s risk-based approach is akin to how we regulate vehicles. A child’s bicycle (minimal risk) requires virtually no regulation. A family car (limited risk) has transparency and safety requirements. A public bus (high-risk) is subject to stringent licensing, maintenance, and operational rules. Finally, certain vehicle modifications designed for harm (unacceptable risk) are banned outright.
This nuanced classification ensures that regulatory resources are focused where they are needed most, protecting citizens from the most significant threats while allowing innovation to flourish in less sensitive domains.
| Risk Level | Description & Examples | Regulatory Obligations |
|---|---|---|
| Unacceptable Risk | AI systems considered a clear threat to the safety, livelihoods, and rights of people. These are banned outright. Examples include: Social scoring by governments; real-time remote biometric identification in publicly accessible spaces by law enforcement (with very narrow exceptions); AI that uses subliminal or manipulative techniques to distort behavior; and emotion recognition in the workplace and educational institutions. | Complete prohibition on development, deployment, and use within the EU. |
| High-Risk | AI systems that can have a significant adverse impact on fundamental rights or safety. This category is extensive and includes AI used in: Critical infrastructure (e.g., water, gas, electricity management); Medical devices; Education and vocational training (e.g., scoring exams); Employment and workforce management (e.g., CV-sorting software); Access to essential services (e.g., credit scoring); Law enforcement (e.g., evaluating evidence); and Justice and democratic processes. | Strict obligations before and after market placement: mandatory conformity assessments, robust risk management systems, high-quality data governance, detailed technical documentation, transparency and provision of information to users, ensuring human oversight, and a high level of accuracy, robustness, and cybersecurity. |
| Limited Risk | AI systems that pose a specific risk of manipulation or deception. This category primarily involves systems that interact with humans. Examples include: Chatbots, deepfakes, and other AI-generated content. | The primary obligation is transparency. Users must be clearly informed that they are interacting with an AI system or that content is artificially generated or manipulated. This allows individuals to make informed decisions. |
| Minimal or No Risk | This is the vast majority of AI systems currently in use in the EU. Examples include: AI-enabled video games, spam filters, or inventory management systems. | No specific legal obligations under the Act. The legislation allows the free use of such applications, and developers can voluntarily adhere to codes of conduct. |
To help remember the core categories of prohibited, unacceptable-risk AI, one can use the following mnemonic:
Mnemonic for Prohibited AI: “S.C.A.R.S.”
- Social Scoring
- Cognitive manipulation (subliminal/exploitative)
- All-purpose remote biometrics (real-time)
- Reckless scraping of facial images
- Sensitive characteristic categorization (e.g., emotion in workplace)
The 2024 Game Changer: Regulating General-Purpose AI (GPAI)
The most significant and debated addition to the final AI Act was the creation of a dedicated regulatory tier for General-Purpose AI (GPAI) models. These are powerful, flexible models, like the ones powering ChatGPT or Google’s , that can be adapted to a wide range of downstream tasks. Lawmakers recognized that regulating only the final high-risk application was insufficient; the foundational models themselves could harbor systemic risks. The Act introduces a two-tier approach for GPAI, a direct response to the rapid advancements of late 2023 and early 2024.
* Performing state-of-the-art **model evaluation** and adversarial testing to identify and mitigate potential systemic risks.
* Assessing and mitigating potential risks at the Union level, such as those related to disinformation, cybersecurity, or negative effects on fundamental rights.
* Reporting serious incidents to the AI Office and national authorities.
* Ensuring a high level of cybersecurity protection for the model and its infrastructure.
This tiered approach to GPAI is a novel piece of regulatory architecture, attempting to place guardrails on the core technology without stifling the open-source ecosystem or overburdening smaller developers.
Governance, Enforcement, and the ‘AI Pact’
Fun Fact: The penalties for non-compliance with the EU AI Act are among the highest for any tech regulation globally. Fines for deploying a prohibited AI system can reach up to €35 million or 7% of a company’s total worldwide annual turnover, whichever is higher. For other violations, fines can go up to €15 million or 3%. This is even higher than the GDPR’s famous 4% ceiling, signaling the EU’s immense seriousness.
Recognizing that the Act’s full implementation will take time, the European Commission launched the AI Pact in late 2023. This is a voluntary initiative that encourages companies from the EU and beyond to start complying with the Act’s requirements ahead of the legal deadlines. By joining the Pact, companies can share best practices, prepare for the new rules, and publicly signal their commitment to trustworthy AI. Major global players like Microsoft, Google, IBM, and Nvidia have joined, indicating a broad industry consensus on the need for early alignment with these emerging global standards.
The ‘Brussels Effect’ and Critical Implications for India
The AI Act is explicitly designed to have extraterritorial reach. Any AI system placed on the EU market or whose output is used in the EU will fall under its purview, regardless of where the developer is based. This phenomenon is known as the ‘Brussels Effect’: when EU laws and regulations set global standards because multinational companies find it more efficient to adopt the EU’s stringent rules across all their operations rather than creating different products for different regulatory environments. We saw this with the General Data Protection Regulation (GDPR), and the AI Act is poised to have an even more profound impact.
For India, this has several critical implications:
-
Market Access for the IT Sector: India’s vibrant IT and software-as-a-service (SaaS) industry is a major exporter to the European market. To continue operating in the EU, these companies will have to ensure their AI-enabled products and services are fully compliant with the Act. This will require significant investment in compliance, data governance, risk management, and technical documentation. Companies developing or using high-risk AI systems will face the most substantial burden.
-
Pressure on India’s Regulatory Stance: India’s official approach to AI regulation has, to date, been markedly different from the EU’s. The Ministry of Electronics and Information Technology (MeitY) has repeatedly advocated for a “light-touch” regulatory framework, viewing AI as a “kinetic enabler” of the digital economy and expressing concerns that premature, heavy-handed regulation could stifle innovation. India has preferred to act as a user and promoter of AI, focusing on harnessing its economic potential rather than preemptively regulating its risks. The EU AI Act challenges this stance directly. As the ‘Brussels Effect’ takes hold, India will face increasing pressure to align its domestic standards with the global benchmark to ensure interoperability and competitiveness.
-
A Strategic Choice: India is at a crossroads. It can either:
- Adopt a similar framework: Develop its own comprehensive, rights-based AI legislation inspired by the EU model. This would ensure Indian companies are “compliant by design” and could position India as a leader in trustworthy AI.
- Maintain its ‘light-touch’ approach: Carve its own path, focusing on sector-specific guidelines and voluntary codes of conduct. This might foster faster short-term innovation but could lead to regulatory fragmentation and create trade barriers with the EU.
- Pursue a hybrid model: Create a unique Indian framework that incorporates elements of risk-based regulation but is tailored to India’s specific socio-economic context and priorities, such as leveraging AI for financial inclusion and agricultural productivity.
Critical Policy Appraisal
| Challenges / Criticisms | Opportunities / Successes / Way Forward |
|---|---|
| Stifling Innovation: Critics argue the high compliance costs and strict rules for high-risk AI could slow down research and development, particularly for startups and SMEs. | Building Trust: By creating a clear and predictable legal framework, the Act can increase public trust in AI, which is essential for its widespread adoption and long-term success. |
| Complexity and Ambiguity: The definitions of AI, risk categories, and obligations are complex and may be difficult to interpret and apply consistently across 27 member states. | Global Standard-Setter: The Act establishes the EU as a first-mover and leader in tech regulation, creating a ‘Brussels Effect’ that exports its values and provides a competitive advantage to EU-compliant firms. |
| Pace of Enforcement: The phased implementation over 2-3 years means some of the most significant risks may remain unregulated in the immediate future. | Protecting Fundamental Rights: The Act provides robust protection against the most harmful applications of AI, safeguarding democracy, the rule of law, and individual freedoms. |
| Geopolitical Competition: A strict regulatory environment in the EU could potentially put it at a disadvantage compared to the more laissez-faire approaches of the US and China, at least in terms of raw innovation speed. | Fostering a Market for Trustworthy AI: The Act creates a premium market for AI systems that are safe, transparent, and ethical, encouraging a “race to the top” among developers. |
Analytical Lens: UPSC Focus (Mains & Prelims)
Conceptual Basis: The philosophical and legal backbone of the EU AI Act is the Charter of Fundamental Rights of the European Union. The entire risk-based framework is designed to uphold core principles enshrined in the Charter, such as human dignity (Article 1), respect for private and family life (Article 7), protection of personal data (Article 8), non-discrimination (Article 21), and the right to an effective remedy (Article 47). This contrasts with a purely market-driven or state-centric approach and firmly grounds the regulation in a human-centric, rights-based tradition, much like how the Fundamental Rights in Part III of the Indian Constitution serve as the ultimate check on legislative and executive action in India.
UPSC Integration: Connecting the Dots:
- GS Paper 2 (Polity, Governance & International Relations): The AI Act is a prime case study in extra-territorial legislation and its impact on national sovereignty. It demonstrates the growing importance of regulatory diplomacy and the role of normative power in international relations. It also raises questions for Indian governance regarding the balance between innovation and regulation.
- GS Paper 3 (Science & Tech, Economy): This topic is central to understanding the governance of emerging technologies. It directly relates to the impact of AI on the Indian economy, the future of the IT and ITeS sectors, and the challenges of building a competitive and responsible AI ecosystem. It also connects to issues of data protection and cybersecurity.
- GS Paper 4 (Ethics, Integrity, and Aptitude): The Act is fundamentally about AI ethics. It provides a concrete framework for discussing concepts like algorithmic bias, transparency, accountability, and the ethical responsibilities of corporations and governments in deploying powerful technologies. The dilemmas presented by high-risk AI systems make for excellent ethics case studies.
Future Impact & Policy Relevance: The long-term impact of the EU AI Act will be profound. It will likely catalyze a global wave of AI regulation, forcing countries to articulate their own positions. For India, the Act serves as both a challenge and an opportunity. It challenges the current ‘light-touch’ approach but also provides a comprehensive blueprint for developing a robust regulatory framework that can build trust and ensure that AI development aligns with democratic values. The key policy question for India is not if it should regulate AI, but how. The EU AI Act will be the central reference point in that critical national debate for the next decade.
Prelims Practice Question (MCQ):
Under the EU AI Act, which of the following AI applications would be strictly prohibited due to being classified as an ‘unacceptable risk’?
a) AI-powered chatbots used for customer service. b) AI software used by banks for credit scoring applications. c) AI systems used by a government for real-time social scoring of its citizens. d) AI-generated ‘deepfake’ videos used in a political campaign.
Answer and Explanation: c) AI systems used by a government for real-time social scoring of its citizens. The EU AI Act explicitly bans AI systems that lead to social scoring by public authorities, as this is considered a grave threat to fundamental rights and democratic principles. Chatbots (a) are limited risk, requiring transparency. Credit scoring (b) is high-risk, subject to strict obligations but not banned. Deepfakes (d) are also limited risk, requiring clear labeling but are not prohibited outright.
Mains Sample Question:
“The EU’s AI Act prioritizes a rights-based regulatory model, while India has so far advocated for a more innovation-centric, ‘light-touch’ approach. Critically analyze the potential advantages and disadvantages of both models for shaping India’s digital future and its ambition to become a global AI leader.” (15 Marks, 250 Words)
Mind Map Outline (Revision Structure)
- EU AI Act: A Global Benchmark
- Core Identity: World’s first comprehensive, legally binding AI framework.
- Adoption Timeline:
- Proposal: April 2021
- GPAI Debate: 2023
- Final Adoption: May 2024
- Dual Objectives:
- Foster Innovation & Investment
- Protect Fundamental Rights & Safety
- The Risk-Based Regulatory Framework (Pyramid)
- Level 1: Unacceptable Risk (Banned)
- Social Scoring
- Real-time Remote Biometric Identification (with exceptions)
- Manipulative Techniques
- Emotion Recognition (Workplace/Education)
- Mnemonic: “S.C.A.R.S.”
- Level 2: High-Risk (Strict Obligations)
- Sectors: Critical Infrastructure, Medical, Employment, Law Enforcement, Justice.
- Obligations:
- Conformity Assessments
- Risk Management Systems
- Data Governance
- Human Oversight
- Cybersecurity
- Level 3: Limited Risk (Transparency)
- Examples: Chatbots, Deepfakes
- Obligation: Inform users they are interacting with AI.
- Level 4: Minimal Risk (Free Use)
- Examples: Spam filters, Video games.
- Level 1: Unacceptable Risk (Banned)
- Regulation of General-Purpose AI (GPAI)
- Baseline for all GPAI:
- Technical Documentation
- Training Data Summaries
- GPAI with Systemic Risk (>10^25 FLOPs):
- Stricter Obligations:
- Model Evaluation & Adversarial Testing
- Systemic Risk Mitigation
- Incident Reporting
- Stricter Obligations:
- Baseline for all GPAI:
- Governance and Enforcement
- Key Bodies:
- European AI Office (Supervises GPAI)
- AI Board (Member State Representatives)
- National Competent Authorities
- Penalties: Up to €35 million or 7% of global turnover.
- AI Pact: Voluntary initiative for early compliance.
- Key Bodies:
- Global Impact & India’s Position
- The ‘Brussels Effect’: EU rules becoming de facto global standards.
- Implications for India:
- Market access for IT/SaaS companies.
- Challenge to India’s ‘light-touch’ regulatory stance.
- Strategic choice: Adopt, Reject, or Hybridize.
- UPSC Analytical Focus
- Conceptual Basis: EU Charter of Fundamental Rights.
- Inter-Topic Linkages:
- GS-2: IR, Governance
- GS-3: S&T, Economy
- GS-4: Ethics
- Practice Questions: Prelims (Prohibited AI) & Mains (India’s Regulatory Dilemma).