Trackers
Trackers

AI Regulation in India: 2026 Update

AI regulation in India is taking shape through a combination of existing sector-specific laws, recent government advisories, and a forthcoming national framework. Unlike the European Union';s comprehensive AI Act, India has opted for a principles-based, innovation-friendly approach that places compliance obligations on high-risk use cases rather than on AI technology as a category. For international businesses deploying AI systems in India - or processing Indian users'; data with AI tools - understanding the current patchwork of rules and the direction of travel is essential to managing legal and reputational risk. This guide covers the regulatory architecture, key authorities, sector-specific requirements, compliance steps, and what the pipeline of legislation means for your operations.

The current regulatory architecture for AI in India

India does not yet have a single, consolidated AI statute. Instead, ai regulation india is built on a layered structure of existing legislation, ministry-level advisories, and self-regulatory guidance.

The Information Technology Act, 2000 (IT Act) and its associated rules remain the primary legal instrument governing digital services, data processing, and online intermediaries. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 - commonly called the IT Rules 2021 - impose due-diligence obligations on platforms and require them to take down unlawful content. These rules have been amended to address AI-generated content, including deepfakes, placing explicit obligations on social media intermediaries to prevent the spread of synthetic media that impersonates real individuals.

The Digital Personal Data Protection Act, 2023 (DPDPA) is the second pillar. It governs the collection, processing, and storage of personal data of Indian residents. Any AI system that ingests, analyses, or generates outputs based on personal data is subject to the DPDPA';s consent, purpose-limitation, and data-minimisation requirements. The Act establishes the Data Protection Board of India as the enforcement body for data-related complaints.

The third layer consists of sector-specific guidance from regulators such as the Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), and the Insurance Regulatory and Development Authority of India (IRDAI). Each has issued circulars or frameworks addressing algorithmic decision-making, model risk, and the use of AI in financial services.

Ministry of Electronics and Information Technology: the central policy actor

The Ministry of Electronics and Information Technology (MeitY) is the lead government body on AI policy. MeitY issued an advisory in March of a recent year requiring intermediaries to obtain government approval before deploying AI models that could be considered "unreliable" or that might generate unlawful content. The advisory was subsequently clarified to apply primarily to large platforms and to focus on labelling and traceability rather than pre-deployment approval for all AI products.

MeitY also oversees the IndiaAI Mission, a national programme that coordinates AI research, compute infrastructure, and governance. The IndiaAI Mission';s governance pillar is developing a responsible AI framework that is expected to inform future legislation. The framework draws on principles of safety, accountability, transparency, and fairness, and is being developed in consultation with industry, civil society, and international partners.

NITI Aayog, the government';s policy think tank, published a series of responsible AI principles and a national AI strategy that continue to guide regulatory thinking. While NITI Aayog documents are not legally binding, they signal the government';s priorities and have influenced sector regulators.

In practice, founders and compliance teams should monitor MeitY advisories closely. The ministry has shown a willingness to issue guidance quickly in response to specific incidents - such as the spread of AI-generated misinformation during elections - meaning the compliance landscape can shift faster than formal legislative cycles.

Sector-specific AI obligations businesses must meet

Financial services represent the most developed area of sector-specific AI regulation in India. The RBI has issued guidance on model risk management for banks and non-banking financial companies (NBFCs), requiring institutions to document AI and machine learning models used in credit scoring, fraud detection, and customer onboarding. Models must be validated, monitored for drift, and subject to explainability requirements when they affect customer outcomes.

SEBI has addressed algorithmic trading through its framework on algorithmic trading and co-location, which requires stockbrokers using AI-driven order-execution systems to register algorithms, maintain audit trails, and implement kill switches. Recent SEBI circulars have extended scrutiny to AI-based investment advisory tools, requiring fintechs and registered investment advisers to disclose when recommendations are generated by automated systems.

IRDAI has encouraged insurers to use AI for underwriting and claims processing but requires that decisions affecting policyholders be explainable and subject to human review on request. Insurers must also ensure that AI models do not result in discriminatory outcomes based on protected characteristics.

Healthcare AI is governed by the Medical Devices Rules, 2017 under the Drugs and Cosmetics Act. Software as a Medical Device (SaMD) - including AI-based diagnostic tools - requires registration with the Central Drugs Standard Control Organisation (CDSCO). The regulatory pathway for AI-based medical devices is still maturing, and CDSCO has issued draft guidance on the clinical evaluation of AI/ML-based SaMD.

For businesses operating across multiple sectors, a common mistake is assuming that compliance with one regulator';s AI guidance satisfies all obligations. In practice, a fintech using AI for both credit decisions and health-related insurance products may face overlapping requirements from the RBI, IRDAI, and the DPDPA simultaneously.

If your business operates AI systems in India across regulated sectors, reaching out to specialised counsel early can prevent costly retrofitting later. Contact info@vlolawfirm.com - we can help structure the compliance framework correctly the first time.

The Digital Personal Data Protection Act and AI compliance

The DPDPA is the most immediately actionable piece of legislation for most AI businesses operating in India. It applies to any entity - Indian or foreign - that processes the personal data of individuals located in India. This extraterritorial scope means that a company running AI inference on Indian user data from servers outside India is still subject to the Act.

Key obligations under the DPDPA that intersect with AI operations include:

  • Consent must be obtained before processing personal data, and the purpose of processing must be clearly stated. AI systems that repurpose data for model training beyond the original consent scope are in breach.
  • Data principals (individuals) have the right to access information about how their data is processed and to seek correction or erasure. AI systems must be designed to honour these rights technically, not just procedurally.
  • Significant data fiduciaries - a category of large or high-risk data processors to be notified by the government - face additional obligations including data protection impact assessments, appointment of a Data Protection Officer, and periodic audits.
  • Cross-border data transfers are permitted to countries notified by the government as having adequate protections. Businesses using global AI infrastructure must map data flows and ensure transfers comply with the approved country list.

The Data Protection Board of India, once fully constituted, will have the power to investigate complaints and impose financial penalties. The Act sets penalty tiers based on the severity of the breach, with the highest tier reserved for failures that affect large volumes of data or result in significant harm to individuals.

A non-obvious requirement is that the DPDPA';s consent framework applies to automated decision-making. If an AI system makes a decision that significantly affects an individual - such as denying a loan or flagging a user for account suspension - the data principal may have grounds to seek human review, depending on how implementing rules develop. Businesses should build human-in-the-loop mechanisms now rather than waiting for the rules to be finalised.

Upcoming legislation and the direction of AI regulation in India

India';s approach to AI regulation is deliberately iterative. The government has signalled that it does not intend to replicate the EU AI Act';s prescriptive, risk-tier classification system. Instead, the emerging framework is expected to rely on:

  • Sector regulators taking the lead in their domains, with MeitY providing overarching principles.
  • A voluntary accreditation or certification scheme for AI systems, particularly in high-risk applications such as healthcare, critical infrastructure, and public services.
  • Mandatory disclosure requirements for AI-generated content, building on the IT Rules 2021 amendments.
  • A national AI safety institute or equivalent body to conduct research on frontier AI risks and advise on standards.

The IndiaAI Mission';s governance workstream is expected to produce a draft AI governance framework for public consultation. Once published, this document is likely to accelerate the development of binding rules, particularly around high-risk AI applications.

International businesses should note that India is also engaging actively in multilateral AI governance forums, including the Global Partnership on AI and bilateral dialogues with the EU, the United States, and other major economies. These engagements may result in mutual recognition arrangements or interoperability standards that affect compliance obligations for cross-border AI deployments.

A practical scenario: a European company deploying a large language model-based customer service tool in India must currently comply with the DPDPA';s consent and data-minimisation requirements, the IT Rules 2021';s content obligations if it operates as an intermediary, and any sector-specific guidance relevant to its industry. It should also prepare for the possibility that a forthcoming AI governance framework will introduce additional registration or impact-assessment requirements for high-risk AI systems.

A second scenario: an Indian startup developing an AI-based hiring tool must consider the DPDPA';s rules on processing sensitive personal data (which may include inferences about candidates), SEBI requirements if it is listed or raises regulated capital, and emerging guidance from the Ministry of Labour on algorithmic management in employment. Many underestimate the breadth of existing law that already applies to AI systems before any dedicated AI statute is enacted.

Enforcement, penalties, and practical compliance steps

Enforcement of AI-related obligations in India currently flows through existing regulatory channels. The Data Protection Board of India will handle DPDPA complaints. Sector regulators - RBI, SEBI, IRDAI, CDSCO - enforce their own frameworks through inspections, show-cause notices, and financial penalties. MeitY can direct intermediaries to take down content or disable access to non-compliant services under the IT Act.

Penalties under the DPDPA can reach significant amounts for serious breaches, particularly those involving large-scale data processing or harm to data principals. Sector regulators have their own penalty regimes, and in financial services these can include licence suspension or revocation in addition to financial sanctions.

Practical compliance steps for businesses operating AI systems in India include:

  • Conduct an AI inventory mapping all systems that process personal data or make automated decisions affecting individuals.
  • Assess each system against the DPDPA';s consent, purpose-limitation, and data-minimisation requirements.
  • Review sector-specific guidance from the relevant regulator and implement model documentation, validation, and explainability measures.
  • Implement technical mechanisms to honour data principal rights, including access, correction, and erasure requests.
  • Establish a monitoring process for MeitY advisories and sector regulator circulars, given the pace of regulatory development.

A common mistake among foreign businesses is treating India as a single regulatory environment. In practice, the combination of federal legislation, sector regulators, and state-level rules creates a multi-layered compliance obligation that requires coordinated legal and technical responses.

For businesses navigating this complexity, early engagement with legal counsel familiar with both the DPDPA and sector-specific frameworks is the most efficient path. Contact info@vlolawfirm.com - we can assist with AI compliance mapping, regulatory filings, and structuring your India operations to meet current and anticipated requirements.

FAQ

What existing Indian laws apply to AI systems right now?

Several laws already govern AI operations in India without waiting for dedicated AI legislation. The IT Act and IT Rules 2021 apply to AI-generated content and intermediary obligations. The DPDPA governs any AI system processing personal data of Indian residents, including systems operated from outside India. Sector regulators - RBI, SEBI, IRDAI, and CDSCO - have issued binding guidance on AI use in their respective domains. Businesses should not assume that the absence of a single AI Act means the regulatory field is empty. Existing law already creates meaningful compliance obligations, and enforcement is active through established regulatory channels.

How long will it take for India to enact comprehensive AI legislation, and what should businesses do in the meantime?

A dedicated AI statute is unlikely to be enacted in the near term. The government';s stated preference is for a principles-based, sector-led approach that avoids premature regulatory lock-in. The IndiaAI Mission';s governance framework is expected to be published for consultation, but the path from consultation to binding legislation typically takes several years in India. In the meantime, businesses should treat the DPDPA as the primary compliance baseline, monitor MeitY advisories, and engage with sector-specific guidance from relevant regulators. Building flexible compliance architecture now - rather than waiting for a comprehensive law - reduces the cost of adaptation when formal rules arrive.

Does India';s AI regulatory approach differ significantly from the EU AI Act, and does that affect cross-border compliance?

India';s approach differs substantially from the EU AI Act. The EU framework uses a risk-tier classification system with prescriptive requirements for high-risk AI systems, mandatory conformity assessments, and a centralised enforcement structure. India';s current approach is sector-led, principles-based, and relies on existing legislation rather than a dedicated AI statute. For businesses operating in both jurisdictions, this means maintaining two distinct compliance frameworks. However, India is engaging in bilateral dialogues with the EU, and future mutual recognition arrangements could reduce duplication. For now, businesses should map their AI systems against both frameworks separately and identify where requirements overlap or conflict.

Conclusion

India';s AI regulatory environment is active, multi-layered, and evolving. The DPDPA, IT Rules 2021, and sector-specific frameworks from the RBI, SEBI, IRDAI, and CDSCO already impose concrete obligations on businesses deploying AI systems in India. A national AI governance framework is in development, and the direction of travel favours accountability, transparency, and human oversight in high-risk applications. Businesses that build compliance infrastructure now - rather than waiting for a single comprehensive law - will be better positioned to adapt as the framework matures.

VLO Law Firms advises international clients on AI regulation in India. We can assist with DPDPA compliance assessments, sector-specific regulatory mapping, AI governance documentation, and structuring cross-border AI deployments to meet Indian legal requirements. To request a consultation, contact: info@vlolawfirm.com