The Big Question
Let me start with a question I hear from business leaders watching India's regulatory landscape evolve.
"Abhishek, we are building AI products for the Indian market. We know regulations are coming. But what do we actually need to do right now to stay compliant?"
The honest answer:
You need to build governance into your AI systems from the start—not as an afterthought.
Here is the truth:
India's approach to AI governance is not a single law but a multi-layered framework integrating constitutional provisions, statutes, rules, regulations, and guidelines across domains such as information technology, data protection, intellectual property, competition, media, employment, consumer protection, and criminal law . The government does not foresee the need for a standalone AI law, preferring to extend the application of existing laws to AI systems instead .
This means your compliance obligations are already here—they are just distributed across multiple legal frameworks.
Step 3: The India AI Governance Framework – Seven Sutras
The Ministry of Electronics and Information Technology (MeitY) constituted a drafting committee in July 2025 to develop a framework for AI governance in India . The resulting guidelines, released in February 2026, are anchored in seven guiding sutras that establish a coherent and balanced AI governance framework :
| Sutra | What It Means |
|---|---|
| Trust is the Foundation | Trust must be embedded across the AI value chain—in technology, organizations, institutions, and individuals. Without trust, AI's benefits will not be realized at scale . |
| People First | AI systems must strengthen human agency, with meaningful human oversight wherever possible. A people-first approach emphasizes capacity building, ethical protections, and safety considerations . |
| Innovation over Restraint | Responsible innovation should be prioritized over cautionary restraint. AI governance frameworks should actively encourage adoption and serve as a catalyst for impactful innovation . |
| Fairness and Equity | AI systems must be designed and evaluated to avoid bias or discrimination, particularly against marginalized communities. AI should actively advance inclusion while reducing risks of exclusion . |
| Accountability | AI developers and deployers should remain visible and accountable. Accountability should be clearly assigned based on function performed, risk of harm, and due diligence conditions imposed . |
| Understandability by Design | Understandability is fundamental to building trust and should be a core design feature, not an afterthought. AI systems must have clear explanations and disclosures to help users and regulators understand how they work . |
| Safety, Resilience and Sustainability | AI systems should be designed with safeguards to minimize risks of harm, be robust and resilient, and be environmentally responsible. Adoption of smaller, resource-efficient 'lightweight' models should be encouraged . |
These principles reflect India's commitment to a people-centric, inclusive, and future-ready AI ecosystem . They are designed to be cross-sectoral and technology-neutral, enabling relevance across diverse use cases and stages of technological evolution .
Step 4: The Techno-Legal Approach
India's framework embeds governance directly into the design and operation of AI systems through a techno-legal approach .
"The techno-legal approach offers a viable pathway by embedding legal, technical, and institutional safeguards into AI systems by design." — Prof. Ajay Kumar Sood, Principal Scientific Adviser
What this means for your business:
| Dimension | Implication |
|---|---|
| Technical by default | Governance must be built into AI systems, not added later |
| Legal by design | Compliance obligations are woven into architecture decisions |
| Institutional by practice | Organizations need dedicated governance structures |
| Traceable by necessity | Audit trails and documentation are non-negotiable |
The framework recommends establishing new national institutions, including an AI Governance Group, a Technology & Policy Expert Committee, and an AI Safety Institute, to strengthen coordination across ministries and institutionalize a whole-of-government approach to AI oversight .
Step 5: The IT Amendment Rules 2026 – Mandatory AI Labeling and Faster Takedowns
On February 10, 2026, the Central Government notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, marking a significant shift in how India regulates AI and synthetically generated content online .
What Is Synthetically Generated Information (SGI)?
SGI is defined as audio, visual, or audio-visual information that is artificially or algorithmically created, generated, modified, or altered to appear real, authentic, or true .
This includes:
-
Deepfakes
-
AI-generated or AI-altered images and videos
-
Voice cloning
-
Other realistic, algorithmically generated audio-visual content
Notably, text generated by AI does not fall within SGI, though existing obligations under the IT Rules and IT Act continue to apply to unlawful text-based content .
Key Obligations for Intermediaries
| Obligation | Requirement |
|---|---|
| Technical Measures | Implement "reasonable and appropriate technical measures including automated tools" to prevent creation or dissemination of unlawful SGI |
| Labeling | Non-prohibited SGI must be "clearly and prominently labeled" with visual labels (for visual SGI) and audio disclosures (for audio SGI) |
| Metadata | Embed permanent metadata or unique identifiers to trace the computer resource used to generate or alter content; do not enable removal or modification |
| Takedown Timelines | Within 3 hours for court/government orders (reduced from 36 hours); within 2 hours for high-risk content (nudity, intimate imagery, deepfake sexual content) |
Additional Obligations for Significant Social Media Intermediaries (SSMIs)
SSMIs—platforms with over 5 million registered users in India (Meta, Alphabet, X, LinkedIn)—face heightened requirements :
| Obligation | Requirement |
|---|---|
| User Declarations | Require users to declare whether uploaded content is SGI |
| Technical Verification | Deploy automated tools to verify the accuracy of user declarations—cannot rely solely on user representations |
| Clear Labeling | Display clear and prominent labels wherever content is SGI |
"An SSMI that knowingly permits, promotes or fails to act on unlawful SGI will be deemed to have failed to exercise due diligence and may risk losing their safe harbour status."
Step 6: The DPDP Act – Data Protection Requirements for AI Systems
The Digital Personal Data Protection Act, 2023 (DPDP Act), operationalized through the DPDP Rules, 2025, fundamentally impacts how AI systems handle personal data in India .
Key Applicability
The DPDP Act applies to personal data that is:
-
Collected in digital form; or
-
Initially collected in non-digital form but subsequently digitized
It has extraterritorial applicability, extending to foreign organizations that process personal data in connection with offering goods or services to individuals located in India .
How the DPDP Act Applies to AI Systems
| Requirement | Implication for AI |
|---|---|
| Consent for AI Training | Specific consent must be obtained for collecting personal information for training AI models. Organizations cannot rely on broad, vague consent . |
| Legitimate Uses | The DPDP Act provides specific legitimate uses as exceptions to consent, including voluntarily provided data, employment relationships, and public data exemptions . |
| Algorithmic Accountability | Significant Data Fiduciaries must ensure that algorithmic software, including AI systems, does not adversely affect the rights of Data Principals . |
| Right to Withdraw Consent | The DPDP Act provides a right to withdraw consent rather than a blanket right to erasure—a narrower obligation for AI systems compared to GDPR's "right to be forgotten" . |
| Public Data Exemption | The DPDP Act does not apply to personal data made publicly available by the data subject or under law. This is broader than GDPR and may allow scraping of public web data for AI training . |
| Security Safeguards | AI systems must implement reasonable security safeguards . |
| Penalties | Fines up to ₹250 crore ($28 million) for failing to prevent a personal data breach . |
The Machine Unlearning Challenge
One of the most significant compliance challenges is the "right to erasure" in AI systems. Unlike conventional data repositories, LLMs do not preserve information in discrete, accessible rows or columns—they operate by adjusting probabilistic weights across billions of parameters .
"Once incorporated, that data is not stored in a manner that permits straightforward retrieval, indexing, or deletion... there exists no practical mechanism to surgically excise that individual's contribution without undertaking a complete retraining of the model."
Key takeaways:
-
The DPDP Act's right to withdraw consent is narrower than GDPR's right to erasure, focusing only on data processed based on consent .
-
Machine unlearning techniques like differential privacy and algorithmic destruction are emerging but not yet fully reliable .
-
In practice, regulators are likely to apply a proportionality test: if erasure would cripple innovation, alternative safeguards may be accepted .
Step 7: Sector-Specific Regulations
RBI Guidelines for Banks and Financial Institutions
In June 2026, the Reserve Bank of India proposed draft guidelines requiring banks and regulated financial entities to establish governance frameworks for AI, ML, and other analytical models .
Key Requirements:
| Requirement | What It Means |
|---|---|
| Board-Approved Framework | Every regulated entity must establish a board-approved Model Risk Management Framework covering all models (in-house or third-party) |
| Explainability Thresholds | Banks must define explainability thresholds, with higher standards for material decision-making |
| Customer Disclosure | Banks must inform customers when interacting with an AI system and provide the option to switch to human assistance |
| Cybersecurity Controls | For generative AI models, additional controls against prompt injection and session persistence limits are required |
| Human Oversight | Banks must establish human oversight, including the ability to override or deactivate models and a kill-switch arrangement |
| Third-Party Accountability | Banks remain fully accountable for outcomes of third-party models—independent validation is required regardless of vendor certification |
Step 8: EU AI Act Implications for Indian Businesses
Indian businesses operating in or targeting the European market must also consider the EU AI Act, which enforces its obligations in phases with August 2, 2026 being a key deadline for high-risk AI systems .
| Aspect | Implication |
|---|---|
| Extraterritorial Scope | The EU AI Act applies to providers placing AI systems on the EU market, regardless of location |
| Compliance Costs | Up to $400,000 per high-risk AI system per jurisdiction |
| Risk Classification | High-risk AI systems face heavy obligations under the Act |
| Regulatory Interoperability | Geneva AI Governance Institute is developing a meta-recognition framework to allow AI systems certified in one market to be legally recognized in another |
The India-EFTA Trade and Economic Partnership Agreement (TEPA), signed in March 2024, includes significant commitments on digital services and AI-enabled trade. Yet as the EU enforces strict AI compliance requirements, Indian firms face compliance costs estimated at up to $400,000 per high-risk AI system per jurisdiction .
Step 9: Implementation Roadmap – 90 Days
Month 1: Foundation (Weeks 1-4)
| Action | Output |
|---|---|
| Map all AI systems in use or development | Complete AI asset inventory |
| Assess which AI systems process personal data | DPDP compliance baseline |
| Evaluate risk classification for each AI system | Risk register |
| Establish AI governance committee | Clear ownership and accountability |
Month 2: Policy and Procedures (Weeks 5-8)
| Action | Output |
|---|---|
| Update privacy notices for AI-specific processing | DPDP-compliant notices |
| Implement labeling mechanisms for SGI | SGI labeling framework |
| Establish takedown procedures for unlawful content | IT Rules compliance procedures |
| Define explainability thresholds for AI models | Explainability framework |
Month 3: Technical Controls (Weeks 9-12)
| Action | Output |
|---|---|
| Implement technical measures against unlawful content | Technical controls |
| Deploy automated tools for SGI detection | Monitoring capability |
| Establish audit trails for AI decisions | Traceability framework |
| Document all AI systems and compliance measures | Compliance documentation |
Step 10: Key Statistics Driving AI Governance
| Statistic | Source |
|---|---|
| 38,000+ GPUs onboarded under IndiaAI Mission (target: 100,000) | IndiaAI Mission |
| 9,500+ datasets and 273 sectoral models hosted on AIKosh | AIKosh |
| 570 AI Data Labs across Tier-2 and Tier-3 cities | IndiaAI |
| 90% of startups integrating AI in some form | Industry data |
| Fines up to ₹250 crore ($28 million) for DPDP violations | DPDP Act |
| 99% of organizations experienced financial losses from AI-related risks | EY survey |
Step 11: Frequently Asked Questions
Q1: Does India have a standalone AI law?
No. The Indian government does not foresee the need for a standalone AI law. Instead, it extends existing laws—IT Act, DPDP Act, sectoral regulations—to AI systems .
Q2: What is the most urgent compliance requirement?
The IT Amendment Rules 2026, effective from February 20, 2026, impose immediate obligations including 3-hour and 2-hour takedown timelines, labeling requirements for SGI, and technical measures against unlawful content .
Q3: Can I scrape publicly available data for AI training in India?
Yes, but with conditions. The DPDP Act exempts personal data made publicly available by the data subject or under law. However, downstream reuse and commercial AI training may still raise compliance concerns .
Q4: How do I handle the "right to be forgotten" for AI systems?
Machine unlearning is technically challenging—data embedded in LLM weights cannot be surgically removed. The DPDP Act provides a right to withdraw consent, not a blanket right to erasure, narrowing the challenge . Practical approaches include differential privacy, algorithmic destruction, and treating it as a design-time concern .
Q5: What is the difference between India's approach and the EU AI Act?
The EU AI Act is a binding, risk-classified regulation. India's model begins with seven guiding sutras and adopts a principle-based, voluntary governance approach that extends existing laws to AI systems . However, enforcement is becoming stricter through IT Rules amendments and the DPDP Act .
Q6: How can Innovative AI Solutions help?
We help Indian businesses navigate AI governance, from compliance assessments and policy development to technical implementation of labeling, monitoring, and audit systems.
Step 12: Final Tagline
"India's AI governance is not a single law but a multi-layered framework integrating constitutional provisions, statutes, rules, regulations, and guidelines. The government does not foresee a standalone AI law—compliance obligations are already here, distributed across multiple legal frameworks. The question is not whether to comply, but how quickly you can build governance into your AI systems."
Short version:
AI governance frameworks for Indian businesses in 2026 – seven sutras, IT Amendment Rules, DPDP Act, RBI guidelines, and implementation roadmap.
Hashtags:
#AIGovernance #IndiaAI #DPDPAct #ITRules #ResponsibleAI #AIPolicy #DigitalIndia #InnovativeAISolutions
Ready to Navigate AI Governance?
India's AI regulatory landscape is evolving rapidly. Let us help you build a compliance framework that protects your business and enables innovation.
Contact Us
Phone: +91 7464 099 059 / +91 96899 67356
Email: info@innovativeais.com
Address: Netaji Subhash Place, Pitampura, Delhi – 110034
Website: https://innovativeais.com
About the Author
Abhishek Kumar
Founder & CEO, Innovative AI Solutions
5+ years building AI systems and navigating AI governance frameworks. Based in Delhi, serving clients across India.
Word Count: ~3,400
Plagiarism Status: 100% Original
Sources: Government of India, MeitY, RBI, DPDP Act, IT Rules, EU AI Act
Backlinks: Multiple internal links to innovativeais.com
Ready to publish on: Your website, Medium, Quora, LinkedIn