India - AI Governance Guidelines (2025)
India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation
India
RAI-IN-NA-IAGGEXX-2025Issued in 2025 by MeitY under the IndiaAI Mission, this national AI governance framework is in force, effective 5 November 2025. It guides AI developers, industry actors, and sectoral regulators across India through non-binding principles and risk management measures. The guidelines establish institutional mechanisms to promote safe and trusted AI.
Summary
The India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation remain in force as India's primary national policy framework for artificial intelligence governance, having been officially published by the Ministry of Electronics and Information Technology (MeitY) under the IndiaAI Mission on 5 November 2025. The framework establishes a principle-based, techno-legal governance regime that prioritises safe and trusted AI innovation while deploying voluntary measures, Digital Public Infrastructure, and domain-specific regulatory oversight.
The guidelines are structured into four core parts: foundational principles, key recommendations, an operational action plan, and practical guidance for industry actors and regulators. The framework is anchored in seven guiding principles known as sutras: Trust as the Foundation, People First, Innovation over Restraint, Fairness & Equity, Accountability, Understandable by Design, and Safety, Resilience & Sustainability. These principles are technology-agnostic and designed for cross-sectoral application.
Under the proposed institutional framework, the guidelines recommend establishing a whole-of-government coordination architecture comprising an inter-agency AI Governance Group for strategic policy oversight, a Technology & Policy Expert Committee for expert advisory, and the AI Safety Institute for technical validation, testing, and safety research. Sectoral regulators continue to exercise domain-specific enforcement, leveraging existing statutes including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023.
Implementation is structured across short-, medium-, and long-term action plans. Initial priorities focus on constituting key advisory bodies, establishing national AI incident databases, and developing risk classification frameworks. Subsequent phases envisage regulatory sandboxes, integration into Digital Public Infrastructure, and targeted legislative amendments if sectoral regulatory gaps persist.
Full article
Read full text ↗Overview
The Ministry of Electronics & Information Technology (MeitY) published the "India AI Governance Guidelines" on 5 November 2025 as an official policy guideline under the IndiaAI Mission. The Guidelines are organised in four parts (Principles; Issues & Recommendations; Action Plan; Practical Guidelines) and are explicitly described as a techno-legal, pragmatic framework emphasising voluntary measures and the use of existing laws where feasible. The release date and publication are confirmed in the official press release. PIB press release (05 Nov 2025) and the full text is published as an official PDF by the Government of India. India AI Governance Guidelines — Full text (MeitY, 05 Nov 2025).
Separately, the Reserve Bank of India (RBI) released a sector-specific committee report titled "Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI)" on 13 August 2025, which addresses AI adoption, governance and risk management within the financial sector and sets out seven guiding "Sutras" and 26 recommendations across six pillars. The RBI report is an official committee publication and complements national guidance by recommending finance-sector specific governance, board-approved AI policies and practical measures such as AI inventories, incident reporting and governance frameworks. FREE-AI Committee Report (RBI, 13 Aug 2025).
Definitions
The MeitY Guidelines provide an operational glossary covering core terms such as "AI system", "deployers", "developers", "safety testing", and "risk classification", and anchor definitions for governance purposes in the document's Glossary and Annexures. For the recommended application of definitions and classifications the Guidelines refer to India-specific risk frameworks to be developed under the Action Plan. Glossary & Annexures (MeitY Guidelines).
The RBI FREE-AI Report includes a sector-focused glossary and terms relevant to financial supervision (e.g., Regulated Entity (RE), Model Risk Management (MRM), LLM, Model Context Protocol (MCP)) which are used to frame recommendations for banks, NBFCs and other regulated financial firms. RBI Publication (FREE-AI) — Glossary & Annexures.
Governance and Institutional Framework
The MeitY Guidelines propose a "whole-of-government" institutional architecture. Key recommended bodies are: (1) an AI Governance Group (AIGG) as a small, permanent inter-agency policy body to coordinate AI policy across ministries; (2) a Technology & Policy Expert Committee (TPEC) to advise the AIGG; and (3) the AI Safety Institute (AISI) as the technical body for research, testing and standards. The document recommends that sectoral regulators (e.g., RBI, SEBI, TRAI, CCI) continue to exercise domain-specific enforcement. AIGG / TPEC / AISI (MeitY Guidelines, Part 2 & Part 3).
The RBI FREE-AI Report recommends finance-sector institutional measures including board-approved AI policies for Regulated Entities (REs), strengthening internal and third-party audit frameworks for AI, and establishing incident reporting mechanisms and sector-wide repositories to monitor systemic AI vulnerabilities. It also proposes capacity building at board and regulator levels, and an AI innovation sandbox for finance. FREE-AI Committee Report (RBI, 13 Aug 2025).
Key Focus Areas
The MeitY Guidelines structure recommendations across six pillars within three domains: Enablement (Infrastructure; Capacity Building); Regulation (Policy & Regulation; Risk Mitigation); Oversight (Accountability; Institutions). They emphasise expanding compute and dataset access, embedding AI into Digital Public Infrastructure (DPI), capacity building, voluntary compliance tools, and India-specific risk assessment and incident reporting mechanisms. The seven guiding principles ("sutras") are stated as Trust; People First; Innovation over Restraint; Fairness & Equity; Accountability; Understandable by Design; Safety, Resilience & Sustainability. Seven sutras & pillars (MeitY Guidelines Preface / Part 2).
The RBI FREE-AI complementary framework targets financial-sector priorities: Infrastructure (shared data/compute), Policy (board policies and product approval processes), Capacity (board/regulator upskilling), Governance (model risk management, product approvals), Protection (consumer protections, explainability disclosures), and Assurance (internal inventories, audits, red-teaming). The RBI report specifies 26 recommendations across these six pillars. FREE-AI Committee Report — Executive Summary & Recommendations (RBI, 13 Aug 2025).
Implementation Framework
The MeitY Action Plan maps outcomes to short-, medium- and long-term timeframes. Short-term priorities include establishing the AIGG/TPEC, developing India-specific risk frameworks, conducting regulatory gap analyses, and promoting voluntary industry commitments. Medium- and long-term priorities include piloting regulatory sandboxes, resourcing the AISI for safety testing and standards, and considering targeted legal amendments if necessary. Action Plan (MeitY, Part 3, pp.38-41).
The RBI report aligns with this staged approach in the finance sector: immediate steps include board policy templates, inventories and incident reporting; medium-term measures include piloting sandboxes, shared infrastructure and indigenous model development; longer-term measures include statutory or regulator-level rulemaking if gaps persist. Implementation ownership in the RBI report is mapped to Regulated Entities, RBI FinTech/DoS, and industry bodies. FREE-AI — Actionable Recommendations & Implementation (RBI).
Monitoring and Evaluation
The MeitY Guidelines propose monitoring via the AIGG and sectoral regulators, periodic risk assessments by the AISI, and an India-specific AI incidents reporting mechanism to collect real-world evidence of harms and inform iterative policy change. The document envisages the AISI producing test suites, benchmarks and evaluation metrics to support oversight. Monitoring & AISI functions (MeitY, Part 2).
The RBI report specifies monitoring instruments for finance: AI inventories maintained by REs, a sectoral repository for systemic vulnerabilities, periodic internal & third‑party audits, red teaming and stress-testing of AI systems, and incident reporting with a "tolerant supervisory" stance for early errors to encourage disclosure. FREE-AI — Monitoring & Assurance (RBI).
Penalties, Liability, and Appeals
The MeitY Guidelines do not create new statutory criminal or administrative penalties within the document itself; they recommend a graded liability approach and note that existing statutory instruments (for example, the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023) and sectoral regulatory powers will continue to apply and may be used to enforce obligations. The text recommends suggesting targeted legal amendments where gaps are identified, rather than immediately creating a new standalone AI statute. Graded liability & reliance on existing laws (MeitY Guidelines, Part 2) and Digital Personal Data Protection Act, 2023 (IndiaCode) and Information Technology Act, 2000 (IndiaCode).
The RBI FREE-AI report similarly does not itself impose new statutory penalties but recommends RBI and sectoral regulators apply existing supervisory and enforcement powers and consider calibrated sanctions as part of a graded liability approach; it also recommends contractual safeguards and outsourcing guidelines for third-party AI providers. FREE-AI — Liability & Supervisory Recommendations (RBI).
Relationship to Other Instruments
The MeitY Guidelines explicitly position themselves to work alongside existing Indian statutes and sectoral regulation (e.g. DPDP Act 2023, IT Act 2000, consumer protection frameworks, financial-sector regulation). They recommend regulatory gap analyses and targeted amendments where required. Relationship & gap analysis (MeitY, Part 2).
RBI's FREE-AI Report is a finance-sector instrument that cross-references national guidance and calls for alignment with DPDP 2023 and sectoral regulator frameworks (e.g., SEBI, IRDAI), and with international standards (OECD, ISO). The two documents are complementary: MeitY provides cross-sectoral policy guidance while RBI provides finance-specific operational recommendations. FREE-AI (RBI) and MeitY Guidelines (IndiaAI).
International Alignment
The MeitY Guidelines explicitly recommend alignment with international best practices (OECD, UNESCO, G20) and encourage AISI to anchor India’s participation in global fora for standards and safety testing. International alignment (MeitY Guidelines).
The RBI report likewise references international instruments (FSB, OECD, ISO/IEC standards) and comparators (FCA, HKMA) and proposes benchmarking RBI and Regulated Entities against those references. FREE-AI — International references (RBI).
Implementation Timeline
| Date/Period | Milestone | Status |
|---|---|---|
| 05-Nov-2025 | Publication of India AI Governance Guidelines (MeitY release) | Published – official release. MeitY PDF |
| 13-Aug-2025 | RBI FREE-AI Committee Report published (Framework for Responsible and Ethical Enablement of AI in Financial Sector) | Published – committee report. RBI Publication (13 Aug 2025) |
| Q4 2025 (Short-term) | Establish AI Governance Group (AIGG) and constitute TPEC; resource AISI for initial functions. | Planned / recommended in MeitY Action Plan. Action Plan (MeitY) |
| 2026 (Medium-term) | Develop India-specific risk frameworks; pilot voluntary compliance and sandboxes; operationalise incident reporting mechanism. | Planned / recommended in MeitY Action Plan and RBI's sectoral recommendations. MeitY Action Plan and FREE-AI (RBI) |
| 2026 onwards (Long-term) | Consider targeted legal amendments where regulatory gaps persist; expand safety testing and standards. | Planned / contingent on gap analyses by AIGG / sectoral regulators and AISI. MeitY Guidelines (Part 3) |
Sources and References
| Document | Type | Link |
|---|---|---|
| India AI Governance Guidelines (Final) — MeitY / IndiaAI | Official Guidelines (PDF) | India AI Governance Guidelines — PDF (MeitY) |
| PIB Press Release — MeitY Unveils India AI Governance Guidelines (05 Nov 2025) | Government press release | PIB press release (05 Nov 2025) |
| IndiaAI Portal — Report on AI governance guidelines development | Official programme portal / consultation summary | IndiaAI — Report & consultation (IndiaAI) |
| FREE-AI Committee Report - Framework for Responsible and Ethical Enablement of Artificial Intelligence | RBI Committee Report (Publication, 13 Aug 2025) | RBI — FREE-AI Committee Report (13 Aug 2025) |
| Digital Personal Data Protection Act, 2023 | Statute (IndiaCode) | Digital Personal Data Protection Act, 2023 (IndiaCode) |
| Information Technology Act, 2000 | Statute (IndiaCode) | Information Technology Act, 2000 (IndiaCode) |
Requirements for a company
What an organisation has to do under India - AI Governance Guidelines (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
0Nothing in this category.
Must not do
0Nothing in this category.
Should do
7- Adopt a board-approved AI policy governing AI adoption, ethics, and risk management.Regulated entities and financial institutions using AI
- Maintain an internal inventory of all operational AI systems and models.Regulated entities and AI deployers
- Establish incident reporting mechanisms to capture and disclose AI safety incidents and systemic vulnerabilities.AI developers and deployers in regulated sectors
- Implement model risk management frameworks and formal product approval processes for AI applications.Regulated financial institutions deploying AI models
- Conduct regular internal and third-party audits, red-teaming, and stress-testing on deployed AI systems.Organizations deploying critical or financial AI systems
- Provide explainability disclosures and consumer protections for end users interacting with AI systems.Deployers of consumer-facing AI systems
- +1 more in the table below
Should not do
1- Do not deploy high-risk AI applications without prior safety testing, risk classification, and governance review.AI developers and deployers
Who must do what
The obligations under India - AI Governance Guidelines (2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Regulated entities and financial institutions using AI | Adopt a board-approved AI policy governing AI adoption, ethics, and risk management. “board-approved AI policies for Regulated Entities (REs)” | — | Governance and Institutional Framework | Recommended |
| 2 | Regulated entities and AI deployers | Maintain an internal inventory of all operational AI systems and models. “AI inventories maintained by REs” | — | Monitoring and Evaluation | Recommended |
| 3 | AI developers and deployers in regulated sectors | Establish incident reporting mechanisms to capture and disclose AI safety incidents and systemic vulnerabilities. “incident reporting mechanisms and sector-wide repositories to monitor systemic AI vulnerabilities” | — | Governance and Institutional Framework | Recommended |
| 4 | Regulated financial institutions deploying AI models | Implement model risk management frameworks and formal product approval processes for AI applications. “model risk management, product approvals” | — | Key Focus Areas | Recommended |
| 5 | Organizations deploying critical or financial AI systems | Conduct regular internal and third-party audits, red-teaming, and stress-testing on deployed AI systems. “periodic internal & third‑party audits, red teaming and stress-testing of AI systems” | — | Monitoring and Evaluation | Recommended |
| 6 | Deployers of consumer-facing AI systems | Provide explainability disclosures and consumer protections for end users interacting with AI systems. “consumer protections, explainability disclosures” | — | Key Focus Areas | Recommended |
| 7 | Organizations sourcing AI systems from third-party vendors | Establish contractual safeguards and outsourcing risk controls when integrating third-party AI solutions. “contractual safeguards and outsourcing guidelines for third-party AI providers” | — | Penalties, Liability, and Appeals | Recommended |
| 8 | AI developers and deployers | Do not deploy high-risk AI applications without prior safety testing, risk classification, and governance review. “safety testing, and risk classification” | — | Definitions | Recommended |
Related Regulations
FREE‑AI Framework — Framework for Responsible and Ethical Enablement of Artificial Intelligence (RBI FREE‑AI Committee Report)
India94% similar
India AI Regulation Overview
India93% similar
Artificial Intelligence (Ethics & Accountability) Bill, 2025
India93% similar
National Strategy for Artificial Intelligence (#AIforAll) - NITI Aayog
India93% similar
Report of the Committee on Platforms and Data on Artificial Intelligence (MeitY report)
India91% similar
© Regulations.AI · reviewed against official sources on 06-Sep-2026 using Gemini 3.6 Flash