AI Regulation Is Here: What the EU AI Act and DPDP Act Mean for Your Business Insurance

AUTHOR
Trayi Ramakrishnan
DATE
August 11, 2026
CATEGORY
Business Insurance
Last updated on
READING TIME
MIN
Table of contents
SHARE
Cover 100% of your employees, from Day 1.
Woman and man smiling and shaking hands indoors in front of a window with green plants outside.
Key Takeaways

AI governance is becoming an important part of how businesses manage technology, data, and compliance. The EU AI Act is now entering its main implementation phase, while India's Digital Personal Data Protection Act (DPDP Act) and its accompanying Rules are being introduced through a phased timeline. For businesses using AI, these frameworks create new responsibilities around how systems are selected, deployed, monitored, and documented. They also raise questions about how existing insurance policies respond when an AI-related incident results in financial or legal consequences.

What "AI Governance" Actually Means for a Business

AI governance is the set of internal policies and processes a business uses to manage how it builds, buys, and uses AI. This can include deciding who approves a new AI tool, how its outputs are reviewed, what data it can access, and who is responsible for addressing problems when an AI system produces an incorrect or harmful result.

An effective AI governance framework is not a one-time compliance exercise. It involves ongoing oversight of the systems a business uses and the risks associated with them. For enterprises using AI across customer service, hiring, software development, finance, or other business functions, governance can help establish clear responsibilities and controls around those systems.

Why AI Regulation Matters for Businesses

AI regulation is developing across several jurisdictions, with different frameworks applying at different stages. The EU AI Act's transparency requirements became applicable on August 2, 2026, while other obligations will take effect later. In India, the DPDP Act and Rules are also being implemented in phases, with the main substantive provisions scheduled to take effect in May 2027.

For businesses, this means AI governance needs to account for both current requirements and upcoming obligations. Companies may need to document how AI systems are used, assess the risks associated with particular applications, review how personal data is processed, and establish appropriate human oversight.

The EU AI Act's Reach Goes Beyond Europe

The EU AI Act can apply to businesses outside the EU depending on how their AI systems are placed on the EU market or used in relation to people in the EU. A company's location alone does not determine whether the Act applies.

The Act's transparency requirements became applicable on August 2, 2026. These include obligations relating to certain AI-generated or manipulated content and requirements for transparency around particular AI systems. The rules governing high-risk AI systems have a later implementation timeline. Most of these obligations will apply from December 2, 2027, while certain high-risk AI systems embedded in regulated products will be subject to requirements from August 2, 2028.

For businesses with EU customers or operations, understanding which AI systems fall within the Act's scope is therefore an important part of building an appropriate AI governance framework.

India's DPDP Act and AI Risk

India does not currently have a single, standalone AI law. Instead, AI-related requirements are developing through existing regulatory frameworks, including the DPDP Act and the Information Technology Rules.

The DPDP framework applies to businesses processing the personal data of people in India, subject to the Act's scope. The DPDP Rules were notified in November 2025, with different provisions coming into effect at different times. The main substantive provisions are scheduled to take effect on May 13, 2027.

The Information Technology Rules also contain requirements relevant to AI-generated and synthetically generated information. These include obligations around labeling and related disclosures. These requirements are separate from the DPDP Act, but together they form part of the developing regulatory environment for businesses using AI in India.

For enterprises deploying AI systems that process personal data, this makes data governance an important part of responsible AI for enterprises. Businesses need to understand what data their AI systems use, how that data is processed, and what controls are in place to manage associated risks.

What AI Governance Means for Business Insurance

The regulatory requirements around AI can also affect how businesses approach insurance. An AI-related incident may result in regulatory investigations, defense costs, third-party claims, contractual disputes, or other financial losses. Whether an insurance policy responds will depend on the nature of the claim, the policy wording, and any exclusions or limitations relating to AI.

Businesses should therefore review their existing general liability, E&O, cyber, and other relevant policies to understand how they address AI-related risks. They should also consider whether their AI governance framework gives them a clear view of where AI is being used, what decisions it influences, what data it processes, and what could happen if the system produces an incorrect or harmful result.

Good governance does not replace insurance, and insurance does not replace governance. Together, they can form part of a broader approach to managing AI risk as regulation develops. To operationalize these rules, Plum AI Secure translates complex governance mandates into practical safeguards, keeping your AI deployments both compliant and covered.

FAQ

Does the EU AI Act apply to Indian companies?
It can, depending on the company's activities and how its AI systems are placed on or used in relation to the EU market. Being based outside the EU does not automatically put a company outside the Act's scope.

What does the DPDP Act have to do with AI risk?
The DPDP framework governs the processing of personal data in India. This is relevant to AI systems that collect, process, or use personal data, even though India does not currently have a standalone AI law.

Is AI governance the same as AI compliance?
No. Compliance refers to meeting specific legal and regulatory requirements. An AI governance framework is broader and includes the internal policies, processes, oversight, and controls a business uses to manage AI responsibly and meet applicable requirements.

Do businesses need an AI governance framework if they only use third-party AI tools?
Yes. Using a third-party AI system does not remove the need to understand how the tool is being used, what data it processes, and what risks it creates. Businesses should also review their contractual responsibilities and the requirements that apply to their particular use of the system.

Compare top insurers, save on premiums.
Get a free quote
Get a free quote
Get a free quote
Get your Quote
White right-pointing arrow on black background
Get your Quote
White right-pointing arrow on black background
Get your Quote
White right-pointing arrow on black background
Get a Quote for your team
Get your Quote
White right-pointing arrow on black background
Book a Demo
White right-pointing arrow on black background
Talk to an expert
White right-pointing arrow on black background

Heading

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.