Data foundations Guide

AIKosh and IndiaAI: A CTO's Guide to Building Enterprise AI in India

India's AI mission has built the parts: a national catalogue of datasets and models, subsidized GPUs and a first set of Indian foundation models. Turning them into a system a business can run is still engineering work, done against a regulatory clock that starts in earnest in 2027.

For CTOs and engineering leaders building AI systems for Indian users or Indian data, deciding what to take from AIKosh and the IndiaAI Mission and what Indian law will ask of the result.

Published
Reviewed
Reading time
15 min

The short answer

AIKosh is India's national catalogue of AI datasets, models and toolkits, run by the IndiaAI Mission under MeitY and free to use. Treat it and the mission's subsidized GPUs and Indian models as parts. Check each item's license and personal data, measure model quality in every Indian language you serve, and design for the DPDP duties that start on May 13, 2027.

Key takeaways

  • AIKosh held 15,999+ datasets and 355 models on October 2, 2026. Contributors choose the license and AIKosh disclaims license compliance, so every item needs its own license, privacy and quality check before it enters a product.15
  • The IndiaAI Compute Portal lists more than 38,000 GPUs with a subsidy of up to 40%, for DPIIT-recognized startups, MSMEs, researchers and government bodies. A large private company is not a named category.151618
  • Sovereign describes who funded a model, not what you may do with it. Sarvam's 30B and 105B models are Apache 2.0; BharatGen's 2026 models need written permission for any commercial use.202224
  • Indian languages cost accuracy, tokens and safety. Scores trail English by 7 to 10 points on the same questions, Malayalam text needs 2.85 times the tokens of English, and safety judgements change with the language in nearly 90% of cases.303234
  • India has no AI Act. CERT-In reporting, the 2026 rules on AI-generated media and SEBI's accountability rule bind now, and the DPDP Rules' operating duties start on May 13, 2027.14373839

India has the builders. GitHub counts 21.9 million Indian developers, more than five million of them added in 2025.45 Indian enterprises have the intent, too: in EY's survey of more than 200 enterprise leaders, 47% had several generative AI use cases live in production. Only 10% had taken them enterprise-wide, and 78% named integration and data readiness as the main barrier.44 The IndiaAI Mission has spent two years building national parts for that work. This guide covers what each part is, how good it is in practice, and what Indian law asks of the system you build from them.

  • 15,999+datasets on AIKosh on October 2, 2026, alongside 355 models from 671 organizations1
  • 38,000+GPUs empanelled on the IndiaAI Compute Portal, with a subsidy of up to 40% for eligible users15
  • May 132027, the day the DPDP Rules' notice, security, breach and logging duties take effect14

What AIKosh is, and what it offers a builder

AIKosh, launched as AIKosha and often searched as AI Kosh, is the IndiaAI Mission's catalogue of datasets, models, use cases and toolkits. It opened on March 6, 2025 with more than 300 datasets and 80 models.2 MeitY's latest release counted more than 15,000 datasets, 300 models and 30 toolkits in August 2026,3 and on October 2 the live portal showed 15,999+ datasets, 355 models, 22 sectors and 671 contributing organizations.1 The IndiaAI Division under MeitY runs it, on ₹199.55 crore of the mission's ₹10,371.92 crore outlay, about 1.9%.4 Use has grown more slowly than supply; the latest official figure is 17,500 registered users in February 2026.11

What you findWhat it is good forWhat to check before use
Government dataRecords published nowhere else; the most downloaded include 2011 Census district boundaries, Kisan Call Centre query transcripts and ICMR medical imaging1The upstream source, the license and any residual personal data
Indian modelsThe official shelf for open Indian models, including Sarvam's and AI4Bharat's410The license on each model card, which varies by builder
Toolkits and APIs36 toolkits, among them the Presidio and ARX anonymizers, plus dataset APIs, an MCP server and a Python SDK that let AI tools search the catalogue67Rate limits and terms for automated access
Free notebooksQuick trials on a slice of an A100 GPU in four-hour sessions8Files are deleted when each session ends, so nothing persists
AIKosh's four kinds of material. Training and production belong on your own cloud or on the IndiaAI Compute Portal.

Access is easy. Anyone can browse, and downloading open items needs a free account made with a phone one-time password. Organizations register with a GST, PAN, CIN, UDYAM or TAN document.9 The terms are where a CTO should slow down. Contributors keep their IP and choose the license for each item, AIKosh disclaims responsibility for accuracy and license compliance, it may share a downloader's name and email with the contributor, and it forbids scraping.5 Quality varies widely. Much of the recent growth is bulk uploads from a few news accounts, one of them with more than 1,400 datasets, and critics noted at launch that MeitY never said how quality would be verified or how residual personal data would be removed.1012

How to use AIKosh data in a commercial system

  1. Register the company Use an organization account, not an employee's personal one, and assume contributors can see who downloaded their data.
  2. Record provenance For each item, keep the access level, the declared license, the upstream source, the version, the download date and a file hash.
  3. Read the license Flag share-alike and non-commercial terms before anything touches a client's IP. A share-alike license passes its terms to whatever you derive from the data.
  4. Assume personal data is present Scan health, identity and call-transcript data with an anonymizer such as Presidio or ARX before it enters a pipeline, whatever the dataset card says.
  5. Sample before you train Check content against the metadata through the preview API, and pull data through the API rather than by scraping, which the terms forbid.
  6. Ask early for restricted data Restricted items need the contributor's approval, and there is no published turnaround.

Personal data deserves the most care. The DPDP Act excludes only two kinds of public personal data from its scope: data a person made public about themselves, and data someone was legally required to publish.13 Data that others posted about a person is not clearly covered, and the Rules' research exemption, which applies from May 2027, does not open personal data to general AI training.14

IndiaAI compute: who gets subsidized GPUs

The IndiaAI Compute Portal lists capacity that approved providers offer through the mission. It passed 38,000 GPUs from 14 providers by March 2026, in data centers in Mumbai, Hyderabad, Bengaluru, Noida and Jamnagar, and a further 20,000 announced in February were still under process.15 The menu runs from inference cards to the newest training accelerators, on demand or reserved.16 The subsidy is a ceiling of 40%, subject to approval, and PIB put the subsidized rate at under ₹100 an hour, against global rates above ₹200.1617

Eligibility is the part most guides get wrong. The portal names DPIIT-recognized startups and MSMEs with AI experience and ₹50 lakh of annual revenue or ₹1 crore of funding, researchers who meet publication thresholds, students and fellows, early-stage startups with an official letter, and government bodies. It has no category for an ordinary large private company. Requests under 5,000 GPU-hours are approved automatically; larger ones go to a committee that takes applications from the 1st to the 25th of each month and publishes decisions on the 10th of the next. An approval lapses unless use starts within 30 days.18

Exhibit 1Who the subsidized compute went to
  • Government bodies78
  • Startups and MSMEs46
  • Early-stage startups30
  • Researchers and academics27
  • Students5
  • Early-stage researchers4
Projects approved for subsidized IndiaAI compute by March 2026, 190 in all. By August the total had reached 237 projects and 93.18 lakh (9.3 million) GPU-hours sanctioned. Sources: [19], [20]

Delivery is real and still small next to the headline. Hours sanctioned are not hours used, and no official utilization figure exists. PRS reports that the mission spent ₹19 crore in 2024-25 against a budget of ₹552 crore, and that utilization has stayed below half since launch.21 For an eligible startup, the portal is worth using when a job fits under the 5,000-hour line and can start within the month. A large company, a services firm or a foreign company should plan to buy from the same Indian providers, or its usual cloud, at commercial rates.

India's own models: read the license before the launch note

The mission backs 20 foundation-model proposals, 12 large models and eight small ones, and the builders keep the IP.20 That clause matters more than the word sovereign. Sovereign describes who funded a model; its license decides whether you can ship it. Sarvam's 30B and 105B models, released on March 3, 2026, are mixture-of-experts models covering 22 Indian languages under Apache 2.0, and the 30B, with 2.4 billion active parameters, is built for practical deployment, including voice agents.2223 BharatGen's 2026 models are a different case. Their license allows non-commercial research only and requires written permission from BharatGen even to serve a model through a free hosted API.24

Model or serviceBuilderLicenseCommercial use
Sarvam-30B, Sarvam-105BSarvam, IndiaAI granteeApache 2.0Yes; can be self-hosted in India2223
Param2-17B, Shrutam-2 speech, Sooktam-2 voiceBharatGen, IndiaAI granteeBharatGen Research LicenseOnly with written permission24
Speech-to-text and voice APIsGnani, IndiaAI granteeHosted API, no weightsThrough a vendor contract25
IndicTrans2, IndicConformer, Indic Parler-TTSAI4Bharat, IIT MadrasMIT or Apache 2.0, gatedYes, after accepting the gate terms26
indic-seamlessAI4BharatCC-BY-NC-4.0No26
Translation, speech and OCR pipelinesBhashini, MeitYNo published commercial termsGet terms and service levels in writing27
What the licenses say as of October 2026. Licenses change between releases, so read the one attached to the version you deploy.

Treat launch claims and independent tests separately. Sarvam reports strong results on its own Indic benchmark. The independent tester Artificial Analysis gave Sarvam-105B an Intelligence Index of 18, against 33 for an open-weight model of similar size from a global lab.28 An Indian model can still be the right choice when data residency, cost or Indian-language speech matter, which is why the choice should rest on your own evaluation set and not on either party's leaderboard.

How AI performs in Indian languages

The gap to English is measurable. On MILU, a benchmark built from Indian state and regional exam questions, the leading model in late 2024 scored 81.75% in English and about 70% in Tamil and Odia.29 On BhashaBench, which asks the same questions in English and Hindi across agriculture, finance, law and Ayurveda, the same model's Hindi accuracy trailed its English accuracy by 7 to 10 points in every domain.30 Romanized, code-mixed input is harder again. In a June 2026 study of 19 models, heavy code-mixing cut accuracy by up to 17.5 points, and one widely used open model replied in English to 99.7% of code-mixed prompts.31 An English reply to a customer who wrote in Hinglish is a product failure even when the facts are right.

Exhibit 2How many tokens Indian languages cost compared with English
  • English1.00×
  • Hindi1.34×
  • Bengali1.91×
  • Telugu2.49×
  • Tamil2.57×
  • Kannada2.72×
  • Malayalam2.85×
Tokens for the same text on GPT-4o's tokenizer, measured on FLORES-200 in July 2026. On the previous generation of tokenizer the Indian-language average was 8 times English. Price, latency and usable context all scale with these numbers. Source: [32]

Speech is where Indian conditions are hardest. Voice of India, a 2026 benchmark from IIT Madras and Josh Talks, tested 14 speech systems on 536 hours of real 8 kHz phone calls from 675 districts. Most systems exceeded a 20% word error rate, the authors' usability line, and none stayed under it in every language. Error rates by district ranged from about 4% to 44%, and models that scored well on clean public test sets often did substantially worse on real calls.33

Exhibit 3Speech recognition on Indian phone calls, best system per language
  • Hindi5.0%
  • Bengali6.1%
  • Marathi9.4%
  • Tamil14.2%
  • Telugu18.2%
  • Bhojpuri20.9%
  • Maithili24.8%
Word error rate of the best-performing system in each language on the Voice of India benchmark, 2026; lower is better. Most of the 14 systems tested did worse than these figures. Source: [33]

Safety does not carry across languages either. IndicSafe sent 6,000 prompts in 12 Indian languages to 10 models and found that the same prompt received a different safety judgement in nearly 90% of cases when the language changed. One model refused 61.6% of harmless Punjabi prompts.34 A guardrail tuned on English cannot be assumed to work on Hindi, Tamil or Hinglish traffic. Production use at scale exists, mostly where the domain is narrow and the content is grounded: Bhashini, the government's language platform, reported more than 4 billion language inferences by February 2026.35

The engineering standard for an Indian-language system

  • Keep a golden set of a few hundred real queries per language, in native script, romanized and code-mixed forms, scored by native speakers.
  • Calibrate any LLM judge against those human scores before trusting it, especially for lower-resource languages.
  • Detect script and language on every message, and enforce the reply language with a rule and a check on the output.
  • Measure token counts for your own language mix before you set budgets, context limits or prices.
  • Test speech on your own call audio, read back amounts and account numbers, and route low-confidence turns to people.
  • Red-team every language, including romanized variants, and track refusal rates by language.

What Indian law asks of an AI system

India has no AI Act. MeitY's AI Governance Guidelines of November 2025 conclude that a separate AI law is not needed for now, govern AI through existing law and sector regulators, and point toward graded liability that rewards documented due diligence.36 Several rules already bind, and the largest set of duties has a date.

InstrumentStatus on October 4, 2026What it means for an AI system
CERT-In directionsBinding since 2022Report listed incidents within 6 hours, including attacks on AI systems; keep 180 days of logs in India38
IT Rules on synthetic mediaBinding since February 20, 2026Label AI-generated images, video and audio and embed provenance where feasible; text alone is excluded37
SEBI Regulation 16CBinding since February 2025A regulated intermediary is solely responsible for its AI tools' output, bought or built39
RBI payment data rulesBinding since 2018Payment data stays in India; copies processed abroad are deleted within 24 hours41
DPDP Rules, operating dutiesNotified; in force May 13, 2027Itemized notices, security, one-year logs, 72-hour breach reports, children's data, audits for significant fiduciaries14
RBI model risk guidanceDraft, June 2026Board-approved model risk framework, kill switches, human oversight, telling users they are dealing with AI40
MeitY AI Governance GuidelinesVoluntaryGraded liability tied to due diligence36
Binding rules first, then scheduled duties, drafts and guidance. RBI's FREE-AI report of August 2025 is also guidance, with seven principles and 26 recommendations.46

The DPDP Rules were notified on November 13, 2025. Consent Manager registration opens on November 13, 2026, and the operating duties start on May 13, 2027.14 In January 2026 MeitY proposed pulling those duties forward to November 2026; no amendment had been notified by early October.42 For an AI system, the duties read like a specification. Notices must itemize the data and the purpose, and withdrawing consent must be as easy as giving it. Personal data and the logs of its processing must be kept for at least a year, which needs a deliberate policy for prompt and inference logs. A breach needs a detailed report to the Data Protection Board within 72 hours. Anyone under 18 is a child, and processing a child's data needs verifiable parental consent. A Significant Data Fiduciary must run a yearly impact assessment and audit, and check that its algorithmic software is not likely to put people's rights at risk.14

Penalties reach ₹250 crore for failing to protect personal data, and the Act covers processing outside India when it relates to offering goods or services to people in India, so a global company serving Indian users is in scope.13 The Data Protection Board had no appointed members as of August 1, 2026.43 A system launched today will still be running when the duties start, so the cheaper path is to build them in now.

Foreign model APIs are allowed. The DPDP Act lets the government restrict transfers to named countries, and no such list exists.13 The hard limits are sectoral. A payments business must keep payment data in India and delete anything processed abroad within 24 hours, and SEBI leaves liability for an AI tool's output with the regulated firm, never with the model vendor.4139 In practice, the regulator of your customer, more than any benchmark, sets the hosting envelope.

A build sequence that holds through May 2027

Exhibit 4From the data class to a system that passes review
  1. Data and regulatorClassify the data the system touches and name the regulator of each customer segment. Payment, securities and health data set the hosting envelope before any model is chosen.A written hosting decision per data class.
  2. Models per languageShortlist a frontier model, a commercially licensed Indian model and speech systems, and score each on your own golden set in every language you serve.Measured accuracy, reply-language compliance, token cost and latency per language.
  3. Mission assetsTake government data and Indian-language assets from AIKosh with provenance and personal-data checks, and use the compute subsidy if the company qualifies.Every dataset and model has a recorded license and source.
  4. DPDP machineryBuild itemized notices, one-step consent withdrawal, a 90-day rights process, 72-hour breach reporting and a log retention policy into the product.A dry run of a rights request and a breach report.
  5. Evidence trailKeep a model inventory, per-language evaluation results, red-team findings and incident logs, the records that graded liability will reward.Any decision the system made can be explained from its records.
The order matters: hosting and licenses constrain the model choice, and the evidence trail is what regulators and auditors will ask for first.

Data residency and evaluation decide more of an Indian AI system's success than the choice of model. The way an Indian-language system is tested is covered in LLM and AI agent evaluation, checking whether a dataset is fit for a use case in AI data readiness, and the EU's comparable rulebook in EU AI Act compliance.

Questions to settle before you build

  • Which of our data is payment, securities, health or children's data, and where may each be processed?
  • Does the company qualify for subsidized IndiaAI compute, and does the job fit under 5,000 GPU-hours?
  • For every AIKosh dataset and Indian model we use, what is the license, and is commercial use allowed?
  • What are our accuracy, reply-language and token-cost numbers in each language we serve?
  • Can we label AI-generated audio and video and report an incident within six hours today?
  • Will the product meet the DPDP notice, logging and breach duties on May 13, 2027, or earlier if the date moves?

We build these systems as part of our AI development work: Indian-language evaluation sets scored by native speakers, models chosen per language on measured results, hosting matched to the data class, and the DPDP and CERT-In records designed in from the first release.

Questions leaders ask

What is AIKosh?

AIKosh, launched in March 2025 as AIKosha and often searched as AI Kosh, is the IndiaAI Mission's national platform for AI datasets, models, use cases and toolkits, run by the IndiaAI Division under MeitY. In October 2026 it listed 15,999+ datasets and 355 models from 671 organizations. Browsing is open to anyone, and downloading open items needs a free account.129

Can a company use AIKosh datasets commercially?

Often, but it depends on each item. Contributors choose the license for their own data and AIKosh disclaims responsibility for license compliance, so read the license on every dataset, watch for share-alike and non-commercial terms, and check for residual personal data before use.5

Can private companies get subsidized IndiaAI GPUs?

Only if they fall into an eligible category. The portal names DPIIT-recognized startups and MSMEs meeting revenue or funding thresholds, researchers, students, early-stage startups with an official letter, and government bodies. A large private company is not a named category and would normally buy from the same providers at commercial rates.18

Are India's sovereign AI models open source?

Some are. Sarvam's 30B and 105B models are released under Apache 2.0 and can be used commercially. BharatGen's 2026 models carry a research license that bars commercial use without written permission, and Gnani offers hosted APIs without weights. Check the license of each model and version.222425

Does the DPDP Act allow sending personal data to a foreign AI API?

Yes, for now. The Act lets the government restrict transfers to named countries, and no list has been notified. Sector rules are stricter: RBI requires payment data to be stored only in India, and any copy processed abroad to be deleted within one business day or 24 hours, whichever is earlier.1341

When do the DPDP Rules apply to AI systems?

The Rules were notified on November 13, 2025. The operating duties, including notices, security, one-year logs and 72-hour breach reports, start on May 13, 2027. MeitY proposed bringing that forward to November 13, 2026, but no amendment had been notified by early October 2026.1442

Is there an AI law in India?

No. MeitY's AI Governance Guidelines of November 2025 say a separate AI law is not needed for now. AI is governed through the IT Act and its rules, the DPDP Act, CERT-In directions and sector regulators such as RBI and SEBI.36

Sources

  1. AIKosh: IndiaAI Datasets PlatformIndiaAI Mission, MeitY, as of October 2, 2026
  2. Release on the IndiaAI Mission anniversary and the launch of AIKoshaPress Information Bureau, March 6, 2025
  3. Release on the AIKosh workshopPress Information Bureau, August 20, 2026
  4. Unstarred Question 3246Rajya Sabha, answered March 20, 2026
  5. AIKosh Terms of UseIndiaAI Division, MeitY
  6. AIKosh ToolkitsIndiaAI Division, MeitY
  7. AIKosh User ManualIndiaAI Division, MeitY
  8. AIKosh NotebookIndiaAI Division, MeitY
  9. AIKosh FAQsIndiaAI Division, MeitY
  10. AIKosh contributor rankingsIndiaAI Division, MeitY
  11. AI Transforming Rural IndiaPress Information Bureau backgrounder, February 23, 2026
  12. Govt Clarifies Datasets Platform 'AIKosha' Not For MonetisingMediaNama, March 24, 2025
  13. The Digital Personal Data Protection Act, 2023Gazette of India, via MeitY
  14. Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))Gazette of India, November 13, 2025, via MeitY
  15. Release on the progress of the IndiaAI MissionPress Information Bureau, March 13, 2026
  16. IndiaAI Compute Portal price calculatorIndiaAI Mission
  17. India AI Stack: Powering Intelligence at ScalePress Information Bureau, February 4, 2026
  18. IndiaAI Compute Portal: eligibility and processIndiaAI Mission
  19. Reply in Parliament on IndiaAI compute projectsPress Information Bureau, March 25, 2026
  20. Govt backs 20 indigenous AI foundation models, 237 projects get subsidised compute supportANI, August 6, 2026
  21. Demand for Grants 2026-27 Analysis: Ministry of Electronics and Information TechnologyPRS Legislative Research, March 2026
  22. sarvam-105b model cardSarvam AI on Hugging Face, March 2026
  23. sarvam-30b model cardSarvam AI on Hugging Face, March 2026
  24. BharatGen Research License for Param2-17BBharatGen on Hugging Face, February 2026
  25. Gnani speech modelsGnani.ai on Hugging Face
  26. AI4Bharat modelsAI4Bharat, IIT Madras, on Hugging Face
  27. Bhashini API documentationDigital India Bhashini Division, MeitY
  28. Sarvam 105B and Sarvam 30B: India enters the open-weights raceArtificial Analysis, April 2026
  29. MILU: A Multi-task Indic Language Understanding BenchmarkarXiv 2411.02538
  30. BhashaBench V1: A Comprehensive Benchmark for the Quadrant of Indic DomainsarXiv 2510.25409, October 2025
  31. Indi-RomCoM: Code-Mixed Benchmark for Evaluating LLMs on Romanized Indic-English InstructionsarXiv 2606.30790, June 2026
  32. The Tokenizer Tax: Quantifying and Explaining the Cross-Lingual Cost of Subword Tokenization for Indian LanguagesarXiv 2607.24276, July 2026
  33. Voice of India: A Large-Scale Benchmark for Real-World Speech Recognition in IndiaIIT Madras and Josh Talks, arXiv 2604.19151, May 2026
  34. IndicSafe: A Benchmark for Evaluating Multilingual LLM Safety in South AsiaarXiv 2603.17915, 2026
  35. Backgrounder on BHASHINIPress Information Bureau, February 9, 2026
  36. India AI Governance GuidelinesMeitY, November 2025
  37. C&M E-Alert: MeitY notifies the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026Chandhiok & Mahajan, February 2026
  38. Directions under section 70B(6) of the IT Act, 2000CERT-In, April 28, 2022
  39. SEBI Amends Regulations on AI Usage by IntermediariesTaxGuru, February 2025
  40. Draft Guidance on Regulatory Principles for Model Risk Management, 2026Reserve Bank of India, June 2026
  41. Storage of Payment System Data: FAQsReserve Bank of India
  42. MeitY plans to cut short DPDP compliance timeline and notify cross-border restrictions for SDFsS.S. Rana & Co., February 13, 2026
  43. India's Data Protection Board: Established In Law, Absent In FactLiveLaw, August 1, 2026
  44. Is India ready for agentic AI? The AIdea of India: Outlook 2026EY India, November 2025
  45. Octoverse: A new developer joins GitHub every second as AI leads TypeScript to #1GitHub, October 2025
  46. Report of the Committee on the Framework for Responsible and Ethical Enablement of AI (FREE-AI)Reserve Bank of India, August 13, 2025

Written by DigyAi Engineering from the systems we build and run. Every figure links to its public source, and every link and figure was checked on October 4, 2026. No client data appears in our insights.

Read next

All insights
  • One walled estate of customer data has a gate for each AI use case, and each gate runs the same eight readiness checks: every lamp turns green for a churn model, which is built, while the freshness check turns red for a service agent, whose bar stays down and whose tower is still only drawn.

    Data foundations Checklist

    Is Your Data Ready for AI? A Use-Case Data Readiness Assessment

    For CTOs, chief data officers and CFOs deciding whether the data behind a proposed AI use case can carry it before the budget is committed.

    16 min read

  • Your own cases, stored in a golden-set archive, run through your system to a release gate whose board shows every segment against a threshold its owner signed in advance; one segment falls short and the gate holds, then the rerun clears the line and the release crosses a bridge to production.

    LLM and RAG engineering Guide

    LLM and AI Agent Evaluation: How to Prove a System Is Ready to Ship

    For CTOs, heads of AI and risk owners deciding whether an LLM application, RAG system or AI agent is ready to leave the pilot, and what evidence should back that decision.

    16 min read

  • An AI system with its disclosure screen live sends each release down a lane through a release gate, which holds back one failing release, and every release that passes adds a leaf to a tall technical file. A bridge carries the sealed file to a building on its own island, December 2, 2027, when the high-risk obligations begin.

    Security, risk and compliance Analysis

    EU AI Act Compliance in 2026: What the Omnibus Changed and What Is Due Now

    For CTOs, CISOs and general counsel deciding what their AI systems must do to be sold or used in the EU, and what has to be built before December 2027.

    17 min read

Get in touch

Tell us what you are building.

Write it as big as you imagine it.