India - AI Regulation Overview
India AI Regulation Overview
India
RAI-IN-NA-SUMMARY-2026India follows a principle-based, techno-legal AI framework centered on the 2025 Governance Guidelines and the DPDP Act 2023. This approach emphasizes 'AI for All,' balancing rapid innovation with safety through a hybrid model of horizontal principles and sectoral oversight by bodies like the RBI and the new AI Safety Institute.
Overview
India’s approach to Artificial Intelligence (AI) regulation has evolved from a purely strategic and promotional stance to a comprehensive, principle-based 'techno-legal' framework. Initially guided by NITI Aayog’s 2018 'National Strategy for Artificial Intelligence (#AIforAll),' the country's philosophy focuses on leveraging AI for social empowerment and inclusive growth. By 2025, this matured into the 'India AI Governance Guidelines,' published by the Ministry of Electronics & Information Technology (MeitY). This framework establishes a 'whole-of-government' architecture, positioning India as a global leader in balancing the promotion of innovation with the necessity of 'Safe and Trusted AI.' The current landscape is characterized by the integration of AI governance into India’s broader Digital Public Infrastructure (DPI) and the use of existing statutes to enforce accountability. The government has committed significant resources through the 'IndiaAI Mission,' a national program with a budget of over INR 10,372 crore aimed at building sovereign compute capacity, high-quality datasets, and indigenous AI models. Central to this vision is the belief that AI should be 'Understandable by Design' and 'People First,' ensuring that the benefits of automation reach all segments of society, particularly in priority sectors like healthcare, agriculture, and education. As of early 2026, the focus has shifted toward operationalizing technical standards through the newly established AI Safety Institute (AISI), which works to ensure that frontier models are tested against rigorous safety benchmarks before widespread deployment.
Regulatory Approach
India utilizes a hybrid regulatory model that combines horizontal principles with sectoral enforcement. The horizontal layer is defined by seven guiding principles, or 'Sutras': Trust, People First, Innovation over Restraint, Fairness & Equity, Accountability, Understandable by Design, and Safety, Resilience & Sustainability. These Sutras provide a normative foundation for all AI development and deployment within the country. Rather than creating a standalone AI regulator, the government empowers existing sectoral authorities—such as the Reserve Bank of India (RBI) for finance and the Telecom Regulatory Authority of India (TRAI)—to issue domain-specific rules that align with the national guidelines. This ensures that regulation is context-specific and does not stifle innovation in low-risk applications. The approach is explicitly risk-based and 'techno-legal.' It distinguishes between different levels of risk, recommending 'regulatory-lite' postures for low-risk AI uses while mandating rigorous safety testing, red-teaming, and impact assessments for high-risk systems. For instance, the RBI’s 'FREE-AI Framework' (2025) provides a template for how sectoral regulators can convert national principles into binding supervisory expectations. Furthermore, India emphasizes 'Innovation over Restraint,' meaning that regulatory interventions are typically triggered by evidence of harm or high-risk potential rather than preemptive bans. This strategy is designed to foster a vibrant startup ecosystem while maintaining a 'safety net' through voluntary industry commitments and standardized technical toolkits provided by the government. The government also promotes the use of regulatory sandboxes to allow startups to test innovative AI solutions in a controlled environment under the supervision of sectoral regulators.
Key AI Legislation
While India does not have a single 'AI Act,' several key legislative and policy instruments form the bedrock of its AI regulatory regime. The 'India AI Governance Guidelines (2025)' serve as the primary national framework, providing a techno-legal roadmap for AI oversight, institutional mechanisms, and a graded liability approach. This is complemented by the 'Digital Personal Data Protection (DPDP) Act, 2023,' which is the statutory centerpiece for data privacy. The DPDP Act regulates how AI systems collect and process personal data, emphasizing informed consent and the obligations of 'Data Fiduciaries.' Another critical piece of legislation is the 'Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021,' which imposes due diligence on social media platforms and AI intermediaries, including requirements for grievance redressal and the removal of harmful AI-generated content like deepfakes. For the financial sector, the 'FREE-AI Framework (RBI, 2025)' outlines 26 specific recommendations for responsible AI adoption in banking and fintech, focusing on model risk management and algorithmic transparency. Finally, the 'National Strategy for AI (2018)' remains the foundational policy document that established the '#AIforAll' vision and identified priority sectors for AI intervention. Together, these laws and policies create a multi-layered legal environment where AI is governed by a mix of data protection rules, intermediary liability standards, and sector-specific mandates.
Governance & Enforcement Bodies
The governance of AI in India is distributed across several key institutions, with the Ministry of Electronics & Information Technology (MeitY) serving as the nodal agency. Under the 2025 Guidelines, the 'AI Governance Group (AIGG)' acts as the permanent inter-agency body responsible for coordinating policy across different ministries. It is supported by the 'Technology & Policy Expert Committee (TPEC),' which provides technical advice on emerging AI risks and standards. A critical new addition is the 'AI Safety Institute (AISI),' which serves as the technical arm for research, safety testing, and the development of benchmarks for AI models. The AISI is tasked with creating 'India-specific' risk frameworks and conducting audits of high-risk AI systems to ensure they do not exhibit bias or pose security threats. Enforcement is handled through a combination of administrative and sectoral authorities. The 'Data Protection Board of India (DPB),' established under the DPDP Act 2023, has the power to inquire into data breaches caused by AI systems and levy significant penalties. Sectoral regulators like the 'Reserve Bank of India (RBI)' and the 'Securities and Exchange Board of India (SEBI)' exercise domain-specific oversight, ensuring that AI use in financial markets adheres to prudential norms and consumer protection standards. Additionally, 'NITI Aayog' continues to play a strategic role in monitoring the socio-economic impact of AI and advising the government on long-term policy shifts. This multi-stakeholder architecture is designed to prevent regulatory gaps while avoiding the bottlenecks of a single, centralized enforcement agency, allowing for a more agile response to technological changes.
Penalties & Enforcement
Enforcement in the Indian AI context is primarily driven by the underlying statutes that AI systems must comply with, most notably the DPDP Act 2023 and the IT Act 2000. Under the 'DPDP Act,' entities (Data Fiduciaries) found in breach of data protection obligations—such as failing to implement reasonable security safeguards for AI training data—can face administrative penalties of up to 'INR 250 crore (approx. USD 30 million)' per instance. The Act provides the Data Protection Board with powers analogous to a civil court, allowing it to summon witnesses, inspect documents, and issue binding directions. Penalties are structured based on the nature, gravity, and duration of the breach, with higher tiers for 'Significant Data Fiduciaries.' Beyond data-related fines, the 2025 AI Governance Guidelines propose a 'graded liability approach.' This means that liability for AI-generated harms is distributed among developers, deployers, and users based on their level of control over the system. Intermediaries that fail to comply with the 'IT Rules 2021' risk losing their 'safe harbor' protection, making them legally liable for third-party content generated or hosted by their AI systems. This is particularly relevant for generative AI platforms that may produce defamatory or illegal content. Sectoral regulators also have the power to revoke licenses or impose business restrictions on regulated entities (like banks or insurance companies) that deploy AI in a manner that violates consumer protection or financial stability norms. Appeals against these enforcement actions typically lie with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) or the High Courts, ensuring a layer of judicial oversight over administrative decisions.
Data Protection Framework
The 'Digital Personal Data Protection (DPDP) Act, 2023' is the cornerstone of India’s data protection regime and significantly impacts AI development. The Act adopts a 'consent-first' architecture, requiring AI developers to obtain clear, granular consent from individuals (Data Principals) before processing their digital personal data. It introduces the concept of 'Data Fiduciaries'—entities that determine the purpose and means of data processing—and mandates that they implement 'Privacy by Design' and purpose limitation. For AI, this means that data collected for one model cannot be reused for another without fresh consent or a valid legal basis. The Act also provides for 'Significant Data Fiduciaries' (SDFs), who face enhanced obligations such as appointing a Data Protection Officer and conducting periodic Data Protection Impact Assessments (DPIAs). In addition to personal data, India is developing a framework for 'Non-Personal Data (NPD).' Based on the 2020 Gopalakrishnan Committee report and the 2022 Draft National Data Governance Framework Policy, the government aims to unlock the value of anonymized datasets for AI training. The proposed 'India Data Management Office (IDMO)' will oversee the 'India Datasets' platform, providing startups and researchers with access to high-quality, non-personal government data. This framework emphasizes that while NPD should be shared for the public good, it must be done through secure 'data enclaves' to prevent re-identification. Together, these laws ensure that India’s AI ecosystem is fueled by data that is both accessible for innovation and protected by robust statutory safeguards, creating a balanced environment for data-driven growth.
Sector-Specific Rules
India’s AI regulation is increasingly granular at the sectoral level, with the financial services sector leading the way. The 'RBI’s FREE-AI Framework (2025)' mandates that all regulated financial entities (banks, NBFCs) have a board-approved AI policy. It requires formal model approval processes, independent validation of AI algorithms used in credit scoring or fraud detection, and strict 'human-in-the-loop' requirements for high-impact decisions. The framework also introduces specific 'Model Risk Management' (MRM) standards to mitigate algorithmic bias and ensure that AI-driven financial products do not lead to systemic instability. Similar efforts are underway in the securities market, where SEBI has consulted on guidelines for the responsible use of AI/ML in trading and advisory services. In the 'healthcare and agriculture' sectors, regulation is currently more policy-driven than statutory. NITI Aayog has pioneered 'Responsible AI' pilots, such as AI-based diagnostic tools for diabetic retinopathy and precision agriculture models for crop yield prediction. These sectors follow the 'Towards Responsible AI for All' principles, which emphasize clinical validation and the prevention of exclusionary biases. In the 'transportation' sector, the government is exploring frameworks for autonomous vehicles and drone traffic management, focusing on safety certifications and liability in the event of accidents. Across all sectors, the 2025 National Guidelines encourage regulators to conduct 'gap analyses' to determine if existing laws are sufficient to handle AI-specific risks or if new, domain-specific circulars are required. This decentralized approach allows for specialized oversight that matches the unique risk profile of each industry.
International Alignment
India actively aligns its AI governance with international standards while maintaining a 'Global South' perspective. As a founding member and former chair of the 'Global Partnership on Artificial Intelligence (GPAI),' India has been instrumental in promoting the 'New Delhi Declaration,' which emphasizes the need for inclusive AI that benefits developing nations. The 2025 Governance Guidelines are explicitly designed to be compatible with the 'OECD Principles on AI' and the 'G20 AI Principles,' particularly regarding transparency, accountability, and robustness. While India has not adopted the prescriptive 'product safety' logic of the EU AI Act, it shares the EU's focus on risk-based classification and the protection of fundamental rights. Bilateral cooperation is also a key pillar of India’s international strategy. Through the 'India-EU Trade and Technology Council (TTC)' and the 'Initiative on Critical and Emerging Technology (iCET)' with the United States, India is working on harmonizing AI standards, safety testing protocols, and ethical guidelines. The establishment of the Indian 'AI Safety Institute (AISI)' is a direct response to global trends, mirroring similar institutes in the UK and US to facilitate cross-border collaboration on 'frontier model' safety. By participating in these international forums, India ensures that its domestic regulations remain interoperable with global markets, allowing Indian AI startups to scale internationally while adhering to a globally recognized 'Safe and Trusted' baseline. This alignment helps attract foreign investment and ensures that Indian AI products are competitive and trusted on the world stage.
Future Developments
The next 12 to 24 months will see the full operationalization of India’s AI governance architecture. A primary focus is the notification of the 'DPDP Rules 2025,' which will provide the specific procedural details—such as breach notification timelines and registration requirements for Significant Data Fiduciaries—needed to make the Data Protection Act fully functional. Simultaneously, the 'AI Safety Institute (AISI)' is expected to release its first set of technical standards for 'Safety Testing and Evaluation,' providing developers with a clear toolkit for compliance. The government is also expected to finalize the 'National Data Governance Framework Policy,' which will launch the 'India Datasets' platform and formalize the role of the India Data Management Office (IDMO). Looking further ahead, there is ongoing debate regarding the need for a dedicated 'Digital India Act' (DIA) to succeed the aging Information Technology Act of 2000. The DIA is expected to address modern digital challenges, including advanced AI harms like deepfakes, algorithmic discrimination, and the liability of 'General Purpose AI' models. The 2025 Action Plan also outlines 'medium-term' goals, such as the piloting of 'regulatory sandboxes' across various sectors to allow for the controlled testing of high-risk AI applications. As these initiatives converge, India’s regulatory landscape will likely become more structured, moving from advisory guidelines toward a more formal, though still flexible, techno-legal statutory regime that can sustain long-term innovation while protecting citizen rights.
Key Regulations
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| Ministry of Electronics & Information Technology (MeitY) | Nodal ministry for AI policy, IT Act enforcement, and Digital India initiatives. | Rule-making, issuing guidelines, and overseeing the IndiaAI Mission. | https://www.meity.gov.in |
| Reserve Bank of India (RBI) | Regulating the financial sector and ensuring responsible AI adoption in banking. | Issuing Master Directions, auditing regulated entities, and setting capital norms. | https://www.rbi.org.in |
| Data Protection Board of India (DPB) | Enforcement of the Digital Personal Data Protection Act, 2023. | Inquiry into breaches, issuing directions, and levying administrative penalties. | https://www.meity.gov.in |
| NITI Aayog | Strategic policy think-tank for the Government of India. | Policy formulation, strategy development, and cross-sectoral coordination. | https://niti.gov.in |
Real enforcement actions
4 actions recordedPublic enforcement actions where regulators cited India - AI Regulation Overview. Helps you see how the law is actually applied in practice.
- Enforcement orderDec 22, 2025
High Court of Delhi vs Infringing sellers (Jr NTR personality rights)
In CS(COMM) 1305/2025 the Delhi High Court took up actor Jr NTR's suit for misappropriation of his personality and publicity rights, addressing unauthorized AI/machine-learning-generated deepfake and GIF content using his persona.
Source ↗ - Enforcement orderMay 30, 2025
High Court of Delhi vs Igor Isakov & Ors (Sadhguru deepfake personality rights)
In CS(COMM) 578/2025 the Delhi High Court passed an ex-parte interim injunction protecting Sadhguru's name, likeness, image, voice and persona against AI-generated deepfake content used by rogue websites to run scams.
Source ↗ - Jul 26, 2024
High Court of Bombay vs Codible Ventures LLP (Arijit Singh voice cloning)
In COM IPR Suit (L) No. 23443 of 2024 the Bombay High Court granted singer Arijit Singh an ad-interim injunction against AI platforms synthesizing his voice and exploiting his name, image and likeness without authorization — India's first AI voice-cloning personality-rights ruling.
Source ↗ - OtherDec 26, 2023
Ministry of Electronics and Information Technology (MeitY) vs All social media / online intermediaries
MeitY issued an advisory directing intermediaries to comply with IT Rules on deepfakes and AI-driven misinformation, requiring them to clearly inform users of prohibited content under Rule 3(1)(b) and applicable penal provisions.
Source ↗
Related Regulations
© Regulations.AI — created on 06-Jan-2026 using Gemini 3 Flash Preview