Between 2023 and 2026 the global conversation on artificial intelligence flipped from what the technology can do to who writes its rules. Bletchley Park hosted the first frontier-risk table in November 2023, Seoul extracted corporate safety commitments in 2024, Paris reframed the agenda from safety to action in 2025, and New Delhi carried the baton with the India AI Impact Summit in February 2026 — the India AI Impact Summit explainer walks through that handoff in detail. Regulation is now a current-affairs staple, not a niche law paper.
- Why Generative AI Broke the Rulebook
- The Vocabulary Gate: GPAI, Frontier Models and Systemic Risk
- The EU AI Act: The World’s First Comprehensive Statute
- The Counter-Models: China, the United Kingdom and the United States
- The Summit Arc: Bletchley to Seoul to Paris to New Delhi
- India’s Third Way: Configure, Don’t Ban
- The Safety Layer: The IndiaAI Safety Institute
- The Crunch Points Ahead
- How Competitive Exams Probe This Topic
- Quick Revision: One-Glance Facts
- Conclusion: The Rule-Writing Decade
- Frequently Asked Questions
- What should you know about Why Generative AI Broke the Rulebook?
- What should you know about The Vocabulary Gate: GPAI, Frontier Models and Systemic Risk?
- What should you know about The EU AI Act: The World's First Comprehensive Statute?
- What should you know about The Counter-Models: China, the United Kingdom and the United States?
- What should you know about The Summit Arc: Bletchley to Seoul to Paris to New Delhi?
This card maps the rule-writing landscape for generative AI: the vocabulary examiners assume you know, the European Union’s risk-ladder statute as the global benchmark, the Chinese, British and American counter-models, the four-summit diplomatic arc, and India’s configure-don’t-ban third way that couples the IndiaAI capability mission with a light-touch compliance overlay.
Why Generative AI Broke the Rulebook
Older AI regulation was sectoral and sleepy; generative models forced a general rethink.
- The consumer leap. ChatGPT’s November 2022 arrival moved AI from invisible backend tooling to a consumer surface anyone could prompt — regulators could no longer treat it as a banking-automation detail.
- The dual-use knot. The same model that drafts code and summaries can draft misinformation and malware — regulation must govern capability, not use-case silos.
- Generality. Foundation models are trained once and deployed everywhere, so a single upstream provider decision cascades into thousands of downstream products — classic sectoral law cannot see that chain.
- The trust deficit. Hallucinated facts, training-data copyright trawling, bias and deepfakes made public trust, not just safety, the regulatory target.
- The sovereignty overlay. Compute, data and model talent sit concentrated in a few countries, so every AI rule is also industrial policy — the reason the debate splits along Brussels-Beijing-Washington lines.
The Vocabulary Gate: GPAI, Frontier Models and Systemic Risk
Examiners test the nouns before the arguments.
- General-Purpose AI (GPAI). Models trained for broad capability and integrated into many downstream systems — the EU AI Act’s central category for upstream providers.
- Frontier models. The Seoul 2024 definition: highly capable general-purpose models at the cutting edge, whose failure modes are not yet fully understood.
- Systemic-risk GPAI. The EU presumes systemic risk above a compute threshold of ten-to-the-power-twenty-five floating-point operations — triggering evaluation, red-teaming and incident-reporting duties.
- Provider versus deployer. The builder of a foundation model carries documentation duties; the deployer integrating it into a product carries transparency and use duties — a favourite statement-pair in exams.
- The compliance toolkit. Model cards, watermarking and provenance labelling of synthetic content, external red-teams and incident disclosure — the vocabulary every advisory and rule now leans on.
The EU AI Act: The World’s First Comprehensive Statute
The reference point every other regime is measured against.
- The timeline. Commission proposal April 2021, political deal December 2023, entry into force 1 August 2024, GPAI obligations from 2 August 2025, most high-risk duties phasing in through 2026 and 2027.
- The risk ladder. Unacceptable-risk practices banned outright — social scoring, manipulative systems, untargeted facial scraping; high-risk systems face conformity assessment; limited-risk uses carry transparency duties; minimal-risk uses stay free.
- GPAI duties. Technical documentation, a copyright-respect policy and a training-data summary for all providers; evaluation, adversarial testing and serious-incident reporting for systemic-risk models.
- The penalties. Up to 35 million euro or 7 percent of global turnover for banned practices; up to 15 million euro or 3 percent for GPAI breaches.
- Extraterritorial reach. The Act bites providers outside the EU whose systems’ output is used inside the Union — the Brussels effect in action.
- The critiques. Compliance costs squeezing European start-ups, a national-security carve-out and staggered phase-ins that confuse even compliance desks — regular essay ammunition.
The Counter-Models: China, the United Kingdom and the United States
Three different rooms, three different philosophies.
- China, the first mover. The Interim Measures for Generative AI Services, in force 15 August 2023 — the world’s first generative-AI statute — pairing licensing and security assessments with earlier algorithm-registration rules of March 2022.
- The United Kingdom, light touch. A pro-innovation white paper of 2023 set five principles for existing regulators, with no comprehensive statute; the AI Safety Institute (November 2023, renamed AI Security Institute in 2025) supplies technical statecraft instead.
- The United States, oscillating. Executive Order 14110 of October 2023 required safety-test reporting for frontier models — rescinded in January 2025 by a successor order prioritising American AI dominance; no federal statute exists, leaving a state patchwork that the Colorado AI Act of 2024 leads.
- The treaty layer. The Council of Europe Framework Convention on AI — adopted May 2024, opened for signature September 2024 — is the first legally binding international AI treaty; the EU, UK and US signed early; India is not a party.
- The ethics baseline. The UNESCO Recommendation on the Ethics of Artificial Intelligence, November 2021, endorsed by 193 states — soft law, but the common vocabulary of Global South positions.
- The pattern. Rights-first statute (EU), state-steered licensing (China), innovation-first executive action (US, swinging with administrations) — the triple frame for any comparative question.
The Summit Arc: Bletchley to Seoul to Paris to New Delhi
Diplomacy moved from shared concern to shared implementation.
- Bletchley Park, November 2023. Twenty-eight countries and the EU — the United States and China at one table — signed the Bletchley Declaration on frontier-AI risk.
- Seoul, May 2024. Sixteen companies signed the Frontier AI Safety Commitments alongside the Seoul Declaration, hardening industry thresholds and kill-switch expectations.
- Paris, February 2025. The AI Action Summit, co-chaired by Prime Minister Modi, produced a declaration on inclusive and sustainable AI signed by around sixty states; the US and UK declined to sign, and the Currents report set the public-interest agenda.
- The GPAI bridge. India hosted the Global Partnership on AI summit in New Delhi in December 2023, issuing the New Delhi Declaration and positioning itself as broker between North and South.
- New Delhi, February 2026. The India AI Impact Summit at Bharat Mandapam (16-21 February, about thirty-seven countries) — the first summit of the series hosted by a Global South country, carrying the Paris agenda into implementation.
- The trend line. Risk-awareness in 2023, action commitments in 2024-25, implementation and compute-sharing in 2026 — with national AI-safety institutes networking since their inaugural meeting in San Francisco in November 2024.
India’s Third Way: Configure, Don’t Ban
Neither the EU statute nor the American vacuum — a capability-plus-advisory stack.
- The strategy lineage. NITI Aayog’s National Strategy for Artificial Intelligence (June 2018) coined the #AIforAll framing; the Responsible AI approach documents of February and August 2021 set principles — RAI as guidance, not statute.
- Advisory law. The IT Act’s Section 79 safe-harbour shield pairs with the IT Rules 2021 due-diligence ladder; MeitY’s November 2023 deepfake advisories tightened takedown expectations, and the March 2024 advisory requiring government permission before launching untested generative platforms was softened after industry pushback.
- The 2025 turn. Amendments to the IT Rules require machine-readable labelling of AI-generated and synthetic content, alongside deepfake-specific takedown expectations — transparency over prohibition.
- Data first, models later. India legislated the data layer (the DPDP Act, 2023) before any model layer — regulating the fuel rather than licensing the engine.
- The compute wager. The IndiaAI Mission, approved 7 March 2024 at ₹10,371.92 crore, buys GPUs, datasets platforms and public-sector applications on the premise that building capability makes regulation credible — the IndiaAI Mission deep-dive maps that mission end to end.
- Institutional voice. Sectoral regulators issue cautious guidance while India’s summit diplomacy pushes a development-first Global South line — norm entrepreneurship without a comprehensive statute.
The Safety Layer: The IndiaAI Safety Institute
The technical spine beneath the soft-law overlay.
- Birth and mandate. Anchored under the IndiaAI umbrella in 2025, the Safety Institute tests frontier models before deployment, evaluates bias and hallucination behaviour, and builds incident-reporting practice for the Indian ecosystem.
- The method. Pre-deployment evaluations, red-teaming challenges and India-language benchmarking — deliberately technical work that complements MeitY’s legal instruments.
- The global mesh. It coordinates with peer safety institutes in the UK, US and elsewhere, plugging Indian evaluation capacity into the network that emerged from the summit arc.
- Standards work. Deepfake-detection challenges and responsible-AI benchmarks translate summit language into auditable tests — the bridge from declaration to compliance.
- Talent and audit. Hackfests, university partnerships and corporate responsible-AI programmes grow the evaluator pool the regime will eventually depend on.
The Crunch Points Ahead
Where the next set of rules will come from.
- Elections and misinformation. The 2024 general-election deepfake episodes pushed labelling into the IT Rules; the full story sits in the deepfakes-and-elections card.
- Agents that act. When generative systems move from answering to transacting, liability follows — our agentic-AI explainer maps the agentic future that regulators are only beginning to price.
- Copyright and the creative economy. News publishers and artists versus model trainers; licensing and levy debates are live on several continents with Indian ministries watching closely.
- Compute and jobs. The displacement-versus-dividend argument ties AI governance to the growth-agenda math of Viksit Bharat 2047 — governance and economics are now one paper.
How Competitive Exams Probe This Topic
Artificial intelligence governance is now standard GS-II, GS-III and interview material.
- Date pairs. Bletchley Declaration — November 2023; EU AI Act in force — 1 August 2024; China’s Interim Measures — 15 August 2023; New Delhi implementation summit — February 2026.
- Matching items. Instrument to author — risk ladder to the EU, licensing to China, safety commitments to Seoul, ethics baseline to UNESCO, labelling amendments to MeitY.
- Statement traps. “India has enacted a comprehensive AI statute” — false; “the EU AI Act applies only to EU-based providers” — false, it is extraterritorial; “Seoul produced a binding treaty” — false, corporate commitments.
- Chronology ordering. UNESCO 2021, Bletchley 2023, Seoul 2024, Paris 2025, New Delhi 2026 — order the arc, identify the shifting agenda at each stop.
- Essay and interview frames. Is India’s configure-don’t-ban approach a strength or a liability? Should compute thresholds define systemic risk? The Global South’s stakes in AI rule-writing.
Quick Revision: One-Glance Facts
The regulation landscape in ten lines.
- UNESCO. Recommendation on the Ethics of AI, November 2021 — 193 endorsing states, the soft-law baseline.
- Bletchley. Declaration of 1-2 November 2023 — 28 countries plus the EU, including the US and China.
- China. Interim Measures for Generative AI Services in force 15 August 2023 — the first generative-AI statute.
- EU AI Act. In force 1 August 2024; GPAI duties from 2 August 2025; bans social scoring and manipulative AI.
- EU fines. Up to 35 million euro or 7 percent of global turnover for banned practices.
- Seoul 2024. Frontier AI Safety Commitments signed by 16 companies at the May 2024 summit.
- Paris 2025. Modi co-chaired; about 60 states signed the declaration; the US and UK stayed out.
- India strategy. NITI Aayog National Strategy for AI, June 2018 — the #AIforAll doctrine.
- IndiaAI Mission. Approved 7 March 2024 at ₹10,371.92 crore; Safety Institute added in 2025.
- New Delhi 2026. India AI Impact Summit at Bharat Mandapam, 16-21 February — implementation baton with India.
Conclusion: The Rule-Writing Decade
Generative AI regulation is no longer a question of whether but of which model — statute, license or advisory — and at what pace. Europe wrote the reference law, China licensed first, America oscillates, and India has chosen a third way: build the compute, label the synthetic, protect the data, and shape the table rather than merely sit at it. For the exam-going reader, the winning grip is the arc — UNESCO to Bletchley to Seoul to Paris to New Delhi — plus the ability to defend or attack India’s light touch with the IndiaAI capability mission as its justification. The decade that decides how humanity governs its most general technology is already drafting; the summaries above are your seat in the room.
Frequently Asked Questions
What should you know about Why Generative AI Broke the Rulebook?
Older AI regulation was sectoral and sleepy; generative models forced a general rethink.
What should you know about The Vocabulary Gate: GPAI, Frontier Models and Systemic Risk?
Examiners test the nouns before the arguments.
What should you know about The EU AI Act: The World's First Comprehensive Statute?
The reference point every other regime is measured against.
What should you know about The Counter-Models: China, the United Kingdom and the United States?
Three different rooms, three different philosophies.
What should you know about The Summit Arc: Bletchley to Seoul to Paris to New Delhi?
Diplomacy moved from shared concern to shared implementation.
Quick revision
- The consumer leap.: ChatGPT’s November 2022 arrival moved AI from invisible backend tooling to a consumer surface anyone could prompt — regulators could no longer…
- The dual-use knot.: The same model that drafts code and summaries can draft misinformation and malware — regulation must govern capability, not use-case silos.
- Generality.: Foundation models are trained once and deployed everywhere, so a single upstream provider decision cascades into thousands of downstream products —…
- The trust deficit.: Hallucinated facts, training-data copyright trawling, bias and deepfakes made public trust, not just safety, the regulatory target.
- The sovereignty overlay.: Compute, data and model talent sit concentrated in a few countries, so every AI rule is also industrial policy — the reason the debate splits along…
- General-Purpose AI (GPAI).: Models trained for broad capability and integrated into many downstream systems — the EU AI Act’s central category for upstream providers.
Have a doubt on this topic?




