A Comparative Analysis of Artificial Intelligence Regulatory Frameworks in India and European Union
In terms of day-to-day work, artificial intelligence has not only been an invaluable resource to working professionals, as it has become essential to be able to use such technology to deal with the constantly changing cyber world. However, an unmanaged or inadequately monitored technology-driven workspace can pose a significant risk to stakeholders. There is a significant risk of bias because AI can think as closely as a human. Instances where AI has impersonated a human during a call and obtained funds sent to an account without authorization demonstrate that AI has presented significant risks. One such case occurred at a British energy company in March 2019, in which a telephone call appeared to come from the chief executive of the parent company demanding the immediate transfer of approximately EUR 220,000. There are also cases of photographs of people altered by AI being shared on social media; in December 2025 the Bombay High Court ordered the removal of AI-generated images of the actor Shilpa Shetty. The swift growth of digital marketplaces and data-driven government has elevated the security of personal data to a fundamental constitutional, economic, and human rights issue. The first comprehensive, legally enforceable and AI-specific legislation in the world, the European Union Artificial Intelligence Act (2024), controls AI using a systematic, risk-based approach. It divides AI systems into unacceptable risk, high risk, limited risk and minimal risk categories. It also places stringent compliance requirements on high-risk systems, especially those employed in the healthcare, education, employment and law enforcement sectors. While simultaneously regulating sophisticated general-purpose AI models, the Act places a strong emphasis on responsibility, transparency, human oversight and the defence of fundamental rights. India's Digital Personal Data Protection Act, 2023 is the country's first complete regulatory framework managing digital personal data, adopting a digital-first, risk-based strategy adapted to India's governance circumstances. India nevertheless lacks a dedicated AI-specific statute. Although the Digital Personal Data Protection Act, 2023 addresses data privacy concerns, it does not comprehensively regulate AI systems, risk classification, algorithmic accountability, or systemic harms such as deep fakes and automated decision-making biases. Consequently, India's AI governance remains fragmented and largely policy-driven, revealing a significant regulatory gap when compared to the structured and rights-based framework adopted by the European Union. This study assesses whether India needs a specific AI law by comparing the advantages of the EU's comprehensive legislative approach with India's current legal framework. It concludes by offering suggestions for creating a fair, innovative and rights-protective AI regulatory framework that is in line with India's constitutional ideals, socioeconomic conditions and technical goals.