Artificial intelligence is no longer a speculative frontier for Indian businesses; it is an operational reality. From credit underwriting algorithms and automated customer service to generative AI tools drafting contracts and marketing content, AI systems are embedded in the commercial mainstream. Yet India's legal framework for AI remains a work in progress — an evolving mosaic of existing statutes, subordinate legislation, regulatory guidelines, and judicial adaptation. For general counsel, compliance officers, and business leaders, the challenge is not waiting for a standalone AI statute, but navigating the current patchwork with foresight and agility.
I. The Regulatory Mosaic: No Standalone Law, But Plenty of Rules
India does not yet have a comprehensive, horizontal AI statute. However, this absence does not equate to an absence of regulation. The current framework is layered and sectoral, with significant developments in the past twelve months.
The IT Rules Amendment, 2026
Effective 20 February 2026, the Ministry of Electronics and Information Technology (MeitY) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026. These amendments introduce India's first set of binding, AI-specific compliance obligations — but they apply only to intermediaries, not to all AI deployers.
The amendments target "synthetically generated information" (SGI), defined as audio, visual, or audio-visual information that is artificially or algorithmically created, generated, modified, or altered using a computer resource in a manner that appears real, authentic, or true.
Key obligations include prominent labelling, provenance metadata, automated blocking of unlawful SGI, and enhanced obligations for Significant Social Media Intermediaries (SSMIs). Non-compliance exposes intermediaries to the loss of safe harbour protection under Section 79 of the IT Act.
The Digital Personal Data Protection Act, 2023 and Rules, 2025
The DPDP Act is arguably the most consequential indirect regulatory framework for AI in India. Most AI systems rely on personal data collection, training datasets, profiling, and automated processing.
Consent is the default gateway under the Act. Free, specific, informed, and unambiguous consent is required for processing personal data. Companies using AI for automated analytics, profiling, or algorithmic decision-making must disclose this to data principals. Large AI platforms may be designated as Significant Data Fiduciaries (SDFs), triggering additional obligations including data protection impact assessments and appointment of a Data Protection Officer.
Sectoral Regulators: RBI, SEBI, and Beyond
The RBI's FREE-AI Framework (August 2025) sets out governance principles for banks, NBFCs, and fintechs using AI in credit decisions, fraud detection, and customer service. SEBI has progressively mandated disclosure of AI and machine learning use by market intermediaries. The Indian Council of Medical Research has issued guidelines for AI in healthcare, focusing on clinical validation, patient consent, and liability frameworks for AI-assisted diagnosis.
The India AI Governance Guidelines, 2025
Published by MeitY in February 2026, the India AI Governance Guidelines articulate a risk-based, principles-driven approach. While non-binding, they signal the direction of future regulation. The Guidelines classify AI risks into six categories: malicious uses, bias and discrimination, transparency failures, systemic risks, loss of control, and national security.
The Guidelines recommend an India-specific AI risk assessment framework, a national federated AI incident reporting mechanism, human oversight mandates in sensitive sectors, privacy-enhancing technologies, algorithmic auditing, and graded liability across the AI value chain.
II. Criminal and Civil Liability
The Bharatiya Nyaya Sanhita, 2023 and the Consumer Protection Act, 2019 provide additional, technology-neutral layers of accountability. AI-enabled cheating, deepfake investment scams, and AI-generated phishing fall under Section 318 of the BNS. Forgery involving AI-generated fake documents is covered under Sections 336–338. The CPA covers AI-driven products and services through unfair trade practices, misleading advertisements, and product liability provisions.
III. Strategic Imperatives for Businesses and Legal Advisers
For businesses deploying or integrating AI, the following strategic imperatives emerge: conduct AI risk assessments now against the DPDP Act, IT Rules 2026, and sectoral guidelines. Implement technical safeguards including labelling, metadata embedding, audit logs, and bias testing. Update contracts and terms of service to address AI-specific liabilities. Prepare for synthetic media compliance if your business operates a platform enabling content creation. Establish internal AI governance boards with cross-functional representation. Engage in policy consultations as the Digital India Act and future AI regulations continue to take shape.
Conclusion
India's approach to AI governance is pragmatic and evolutionary: leverage existing legal tools, embed governance by design, and scale responsibly. There is no single compliance checklist because there is no single AI law. Instead, businesses must navigate a layered regime where the IT Act, the DPDP Act, the Consumer Protection Act, the BNS, and sectoral regulations intersect. For legal practitioners, this complexity is an opportunity to add strategic value — by helping clients build AI systems that are not only innovative but also legally resilient.
The views expressed in this article are for informational purposes only and do not constitute legal advice. For specific guidance on how these developments affect your business, please contact the firm.