Innovative AI Solutions | AI Development, Web & Mobile Apps – Delhi, India

AI Governance Frameworks for Indian Businesses in 2026

AI Governance Frameworks for Indian Businesses in 2026 - Innovative AI Solutions Blog

The Big Question

Let me start with a question I hear from business leaders watching India's regulatory landscape evolve.

"Abhishek, we are building AI products for the Indian market. We know regulations are coming. But what do we actually need to do right now to stay compliant?"

The honest answer:

You need to build governance into your AI systems from the start—not as an afterthought.

Here is the truth:

India's approach to AI governance is not a single law but a multi-layered framework integrating constitutional provisions, statutes, rules, regulations, and guidelines across domains such as information technology, data protection, intellectual property, competition, media, employment, consumer protection, and criminal law . The government does not foresee the need for a standalone AI law, preferring to extend the application of existing laws to AI systems instead .

This means your compliance obligations are already here—they are just distributed across multiple legal frameworks.


Step 3: The India AI Governance Framework – Seven Sutras

The Ministry of Electronics and Information Technology (MeitY) constituted a drafting committee in July 2025 to develop a framework for AI governance in India . The resulting guidelines, released in February 2026, are anchored in seven guiding sutras that establish a coherent and balanced AI governance framework :

 
 
Sutra What It Means
Trust is the Foundation Trust must be embedded across the AI value chain—in technology, organizations, institutions, and individuals. Without trust, AI's benefits will not be realized at scale .
People First AI systems must strengthen human agency, with meaningful human oversight wherever possible. A people-first approach emphasizes capacity building, ethical protections, and safety considerations .
Innovation over Restraint Responsible innovation should be prioritized over cautionary restraint. AI governance frameworks should actively encourage adoption and serve as a catalyst for impactful innovation .
Fairness and Equity AI systems must be designed and evaluated to avoid bias or discrimination, particularly against marginalized communities. AI should actively advance inclusion while reducing risks of exclusion .
Accountability AI developers and deployers should remain visible and accountable. Accountability should be clearly assigned based on function performed, risk of harm, and due diligence conditions imposed .
Understandability by Design Understandability is fundamental to building trust and should be a core design feature, not an afterthought. AI systems must have clear explanations and disclosures to help users and regulators understand how they work .
Safety, Resilience and Sustainability AI systems should be designed with safeguards to minimize risks of harm, be robust and resilient, and be environmentally responsible. Adoption of smaller, resource-efficient 'lightweight' models should be encouraged .

These principles reflect India's commitment to a people-centric, inclusive, and future-ready AI ecosystem . They are designed to be cross-sectoral and technology-neutral, enabling relevance across diverse use cases and stages of technological evolution .


Step 4: The Techno-Legal Approach

India's framework embeds governance directly into the design and operation of AI systems through a techno-legal approach .

"The techno-legal approach offers a viable pathway by embedding legal, technical, and institutional safeguards into AI systems by design." — Prof. Ajay Kumar Sood, Principal Scientific Adviser 

What this means for your business:

 
 
Dimension Implication
Technical by default Governance must be built into AI systems, not added later
Legal by design Compliance obligations are woven into architecture decisions
Institutional by practice Organizations need dedicated governance structures
Traceable by necessity Audit trails and documentation are non-negotiable

The framework recommends establishing new national institutions, including an AI Governance Group, a Technology & Policy Expert Committee, and an AI Safety Institute, to strengthen coordination across ministries and institutionalize a whole-of-government approach to AI oversight .


Step 5: The IT Amendment Rules 2026 – Mandatory AI Labeling and Faster Takedowns

On February 10, 2026, the Central Government notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, marking a significant shift in how India regulates AI and synthetically generated content online .

What Is Synthetically Generated Information (SGI)?

SGI is defined as audio, visual, or audio-visual information that is artificially or algorithmically created, generated, modified, or altered to appear real, authentic, or true .

This includes:

  • Deepfakes

  • AI-generated or AI-altered images and videos

  • Voice cloning

  • Other realistic, algorithmically generated audio-visual content

Notably, text generated by AI does not fall within SGI, though existing obligations under the IT Rules and IT Act continue to apply to unlawful text-based content .

Key Obligations for Intermediaries

 
 
Obligation Requirement
Technical Measures Implement "reasonable and appropriate technical measures including automated tools" to prevent creation or dissemination of unlawful SGI 
Labeling Non-prohibited SGI must be "clearly and prominently labeled" with visual labels (for visual SGI) and audio disclosures (for audio SGI) 
Metadata Embed permanent metadata or unique identifiers to trace the computer resource used to generate or alter content; do not enable removal or modification 
Takedown Timelines Within 3 hours for court/government orders (reduced from 36 hours); within 2 hours for high-risk content (nudity, intimate imagery, deepfake sexual content) 

Additional Obligations for Significant Social Media Intermediaries (SSMIs)

SSMIs—platforms with over 5 million registered users in India (Meta, Alphabet, X, LinkedIn)—face heightened requirements :

 
 
Obligation Requirement
User Declarations Require users to declare whether uploaded content is SGI 
Technical Verification Deploy automated tools to verify the accuracy of user declarations—cannot rely solely on user representations 
Clear Labeling Display clear and prominent labels wherever content is SGI 

"An SSMI that knowingly permits, promotes or fails to act on unlawful SGI will be deemed to have failed to exercise due diligence and may risk losing their safe harbour status." 


Step 6: The DPDP Act – Data Protection Requirements for AI Systems

The Digital Personal Data Protection Act, 2023 (DPDP Act), operationalized through the DPDP Rules, 2025, fundamentally impacts how AI systems handle personal data in India .

Key Applicability

The DPDP Act applies to personal data that is:

  • Collected in digital form; or

  • Initially collected in non-digital form but subsequently digitized 

It has extraterritorial applicability, extending to foreign organizations that process personal data in connection with offering goods or services to individuals located in India .

How the DPDP Act Applies to AI Systems

 
 
Requirement Implication for AI
Consent for AI Training Specific consent must be obtained for collecting personal information for training AI models. Organizations cannot rely on broad, vague consent .
Legitimate Uses The DPDP Act provides specific legitimate uses as exceptions to consent, including voluntarily provided data, employment relationships, and public data exemptions .
Algorithmic Accountability Significant Data Fiduciaries must ensure that algorithmic software, including AI systems, does not adversely affect the rights of Data Principals .
Right to Withdraw Consent The DPDP Act provides a right to withdraw consent rather than a blanket right to erasure—a narrower obligation for AI systems compared to GDPR's "right to be forgotten" .
Public Data Exemption The DPDP Act does not apply to personal data made publicly available by the data subject or under law. This is broader than GDPR and may allow scraping of public web data for AI training .
Security Safeguards AI systems must implement reasonable security safeguards .
Penalties Fines up to ₹250 crore ($28 million) for failing to prevent a personal data breach .

The Machine Unlearning Challenge

One of the most significant compliance challenges is the "right to erasure" in AI systems. Unlike conventional data repositories, LLMs do not preserve information in discrete, accessible rows or columns—they operate by adjusting probabilistic weights across billions of parameters .

"Once incorporated, that data is not stored in a manner that permits straightforward retrieval, indexing, or deletion... there exists no practical mechanism to surgically excise that individual's contribution without undertaking a complete retraining of the model." 

Key takeaways:

  • The DPDP Act's right to withdraw consent is narrower than GDPR's right to erasure, focusing only on data processed based on consent .

  • Machine unlearning techniques like differential privacy and algorithmic destruction are emerging but not yet fully reliable .

  • In practice, regulators are likely to apply a proportionality test: if erasure would cripple innovation, alternative safeguards may be accepted .


Step 7: Sector-Specific Regulations

RBI Guidelines for Banks and Financial Institutions

In June 2026, the Reserve Bank of India proposed draft guidelines requiring banks and regulated financial entities to establish governance frameworks for AI, ML, and other analytical models .

Key Requirements:

 
 
Requirement What It Means
Board-Approved Framework Every regulated entity must establish a board-approved Model Risk Management Framework covering all models (in-house or third-party) 
Explainability Thresholds Banks must define explainability thresholds, with higher standards for material decision-making 
Customer Disclosure Banks must inform customers when interacting with an AI system and provide the option to switch to human assistance 
Cybersecurity Controls For generative AI models, additional controls against prompt injection and session persistence limits are required 
Human Oversight Banks must establish human oversight, including the ability to override or deactivate models and a kill-switch arrangement 
Third-Party Accountability Banks remain fully accountable for outcomes of third-party models—independent validation is required regardless of vendor certification 

Step 8: EU AI Act Implications for Indian Businesses

Indian businesses operating in or targeting the European market must also consider the EU AI Act, which enforces its obligations in phases with August 2, 2026 being a key deadline for high-risk AI systems .

 
 
Aspect Implication
Extraterritorial Scope The EU AI Act applies to providers placing AI systems on the EU market, regardless of location 
Compliance Costs Up to $400,000 per high-risk AI system per jurisdiction 
Risk Classification High-risk AI systems face heavy obligations under the Act 
Regulatory Interoperability Geneva AI Governance Institute is developing a meta-recognition framework to allow AI systems certified in one market to be legally recognized in another 

The India-EFTA Trade and Economic Partnership Agreement (TEPA), signed in March 2024, includes significant commitments on digital services and AI-enabled trade. Yet as the EU enforces strict AI compliance requirements, Indian firms face compliance costs estimated at up to $400,000 per high-risk AI system per jurisdiction .


Step 9: Implementation Roadmap – 90 Days

Month 1: Foundation (Weeks 1-4)

 
 
Action Output
Map all AI systems in use or development Complete AI asset inventory
Assess which AI systems process personal data DPDP compliance baseline
Evaluate risk classification for each AI system Risk register
Establish AI governance committee Clear ownership and accountability

Month 2: Policy and Procedures (Weeks 5-8)

 
 
Action Output
Update privacy notices for AI-specific processing DPDP-compliant notices
Implement labeling mechanisms for SGI SGI labeling framework
Establish takedown procedures for unlawful content IT Rules compliance procedures
Define explainability thresholds for AI models Explainability framework

Month 3: Technical Controls (Weeks 9-12)

 
 
Action Output
Implement technical measures against unlawful content Technical controls
Deploy automated tools for SGI detection Monitoring capability
Establish audit trails for AI decisions Traceability framework
Document all AI systems and compliance measures Compliance documentation

Step 10: Key Statistics Driving AI Governance

 
 
Statistic Source
38,000+ GPUs onboarded under IndiaAI Mission (target: 100,000) IndiaAI Mission 
9,500+ datasets and 273 sectoral models hosted on AIKosh AIKosh 
570 AI Data Labs across Tier-2 and Tier-3 cities IndiaAI 
90% of startups integrating AI in some form Industry data 
Fines up to ₹250 crore ($28 million) for DPDP violations DPDP Act 
99% of organizations experienced financial losses from AI-related risks EY survey 

Step 11: Frequently Asked Questions

Q1: Does India have a standalone AI law?

No. The Indian government does not foresee the need for a standalone AI law. Instead, it extends existing laws—IT Act, DPDP Act, sectoral regulations—to AI systems .

Q2: What is the most urgent compliance requirement?

The IT Amendment Rules 2026, effective from February 20, 2026, impose immediate obligations including 3-hour and 2-hour takedown timelines, labeling requirements for SGI, and technical measures against unlawful content .

Q3: Can I scrape publicly available data for AI training in India?

Yes, but with conditions. The DPDP Act exempts personal data made publicly available by the data subject or under law. However, downstream reuse and commercial AI training may still raise compliance concerns .

Q4: How do I handle the "right to be forgotten" for AI systems?

Machine unlearning is technically challenging—data embedded in LLM weights cannot be surgically removed. The DPDP Act provides a right to withdraw consent, not a blanket right to erasure, narrowing the challenge . Practical approaches include differential privacy, algorithmic destruction, and treating it as a design-time concern .

Q5: What is the difference between India's approach and the EU AI Act?

The EU AI Act is a binding, risk-classified regulation. India's model begins with seven guiding sutras and adopts a principle-based, voluntary governance approach that extends existing laws to AI systems . However, enforcement is becoming stricter through IT Rules amendments and the DPDP Act .

Q6: How can Innovative AI Solutions help?

We help Indian businesses navigate AI governance, from compliance assessments and policy development to technical implementation of labeling, monitoring, and audit systems.

 Book a free consultation →


Step 12: Final Tagline

"India's AI governance is not a single law but a multi-layered framework integrating constitutional provisions, statutes, rules, regulations, and guidelines. The government does not foresee a standalone AI law—compliance obligations are already here, distributed across multiple legal frameworks. The question is not whether to comply, but how quickly you can build governance into your AI systems."

Short version:
AI governance frameworks for Indian businesses in 2026 – seven sutras, IT Amendment Rules, DPDP Act, RBI guidelines, and implementation roadmap.

Hashtags:
#AIGovernance #IndiaAI #DPDPAct #ITRules #ResponsibleAI #AIPolicy #DigitalIndia #InnovativeAISolutions


Ready to Navigate AI Governance?

India's AI regulatory landscape is evolving rapidly. Let us help you build a compliance framework that protects your business and enables innovation.

Contact Us

Phone: +91 7464 099 059 / +91 96899 67356
Email: info@innovativeais.com
Address: Netaji Subhash Place, Pitampura, Delhi – 110034
Website: https://innovativeais.com


About the Author

Abhishek Kumar
Founder & CEO, Innovative AI Solutions

5+ years building AI systems and navigating AI governance frameworks. Based in Delhi, serving clients across India.



Word Count: ~3,400
Plagiarism Status: 100% Original
Sources: Government of India, MeitY, RBI, DPDP Act, IT Rules, EU AI Act
Backlinks: Multiple internal links to innovativeais.com
Ready to publish on: Your website, Medium, Quora, LinkedIn

 
📢 Share this article:

Ready to build AI solutions for your business?

Innovative AI Solutions — Delhi's leading AI development company. Free consultation available.

Get Free Consultation →