Contributed By ANA Law Group
India does not presently have a consolidated statute to govern or regulate AI. The proposed Digital India Act 2023 (DIA) has been in draft status since 2023. Once enforced, it is set to replace the Information Technology Act 2000 (the “IT Act) and broadly regulate internet and digital technology, including AI. Currently, AI systems are regulated through the existing laws, based on the nature of the AI system involved, including predictive AI, generative AI (GenAI), and fully autonomous agentic AI.
From a contractual perspective, AI involvement is governed by the Indian Contract Act 1872 (the “Contract Act”), through technology contracts, software licences, software-as-a-service (SaaS) agreements, commercial contracts, and data processing agreements. For predictive AI systems, disputes generally relate to accuracy parameters, liability, and performance obligations. GenAI introduces additional complexities around ownership, use of training data, confidentiality, and third-party intellectual property claims. Agentic AI systems, especially those that are autonomous, require testing with traditional principles relating to authority, attribution, and infringement risks.
Product liability and safety issues would be governed under the Indian Consumer Protection Act 2019 (CPA) and general negligence principles. When AI systems malfunction, generate unsafe outputs, or operate without safeguards, developers may face exposure. The potential risks become more evident with generative and agentic systems due to the unpredictability of outputs and minimal human oversight.
Privacy and data protection remain central concerns, particularly under the Digital Personal Data Protection Act 2023 (the “DPDP Act”). AI systems frequently rely on large-scale processing of personal data for training, profiling, and optimisation. GenAI is likely to face intense scrutiny around lawful basis for data use, transparency, retention practices, and inadvertent disclosure of personal or confidential information through prompts and outputs.
AI also presents unresolved intellectual property issues under the Indian Copyright Act 1957. GenAI systems may produce outputs resembling protected works, while the legality of using copyrighted material for model training remains unsettled in India. Questions also arise regarding the ownership and enforceability of rights in the AI-generated content, given the human authorship requirement within the existing IP protection and enforcement framework.
In the employment context, AI-enabled or -assisted recruitment, employee monitoring, and automated decision-making may attract scrutiny where such systems operate without transparency or produce discriminatory outputs. Agentic systems capable of independently implementing workplace decisions are likely to raise additional accountability concerns.
Consumer protection and criminal law considerations are also critical. Misleading AI-generated content, deepfakes, impersonation, automated fraud, and AI-enabled cyber-offences may attract liability under the CPA, the IT Act, and general criminal law principles. Although predictive AI systems are relatively easier to supervise, generative and autonomous agentic AI materially increase risks relating to misinformation, impersonation, and autonomous negative or harmful conduct.
Therefore, Indian law addresses AI primarily by extending established and conventional legal principles. However, increasing regulatory attention suggests that more AI-specific obligations and governance standards are likely to emerge over time.
AI technologies are deployed across a wide range of industries in India, including healthcare, finance, e-commerce, retail, logistics, telecommunications, manufacturing, advertising, legal, and public sector initiatives.
Conventional machine learning systems continue to be widely used for analytics, including fraud detection, credit scoring, and insurance risk assessment. Indian banks, fintech platforms, and e-commerce companies have been increasingly relying on such systems to improve operational efficiency and customer targeting.
Foundation models and large language models (LLMs) are increasingly deployed for customer support, communication, document review, coding assistance, and enterprise productivity tools. In India, a key area of innovation has been the development of AI systems capable of operating across Indian languages and regional datasets. Retrieval-augmented generation (RAG) systems are gaining increasing traction in sectors such as legal services, healthcare, financial compliance, and enterprise knowledge management, to help reduce inaccuracies and improve reliability in regulated environments. Autonomous agentic AI systems are still at an emerging stage in India, but are currently being explored for workflow automation, autonomous IT operations, and logistics. These systems are designed to independently execute tasks with limited human intervention, thereby moving beyond conventional assistive AI models.
Cross-sector adoption is also supported through broader digital infrastructure initiatives, including India Stack, Aadhaar-enabled services, Open Network for Digital Commerce (ONDC), and government-backed AI programmes. As AI systems become more autonomous and integrated into commercial operations, businesses are increasingly required to address issues relating to governance, accountability, data protection, and sector-specific regulatory compliance.
AI systems have transformed key functions across industries by automating complex tasks, predicting outcomes, and improving the overall operations of individual businesses. By integrating AI into core day-to-day functions, businesses are now able to ensure strategic decision-making, promote innovation, and improve customer experience. A few AI use cases are discussed below.
Healthcare
AI technologies such as machine learning, deep learning, natural language processing, and robotic process automation have been in use in India. AI-enabled systems analyse patient data to provide accurate diagnoses and treatment plans, examine medical reports to identify and detect diseases, and automate scheduling and billing functions. Further, AI is also used in the research and development of drugs and medications, and improves the precision in surgical techniques.
E-commerce
AI systems integrate machine learning and natural language processing to analyse browsing data, purchase histories, and other relevant information, and provide personalised recommendations. AI models are also used to detect suspicious transactions and mitigate any potential risk of fraud. Further, AI-enabled voice search options and chatbots enhance customer experience.
Manufacturing
AI systems using predictive analytics, convolutional neural networks (CNN), and robotic process automation are widely used in the manufacturing sector. By analysing historical data, such systems inspect and detect defects or potential risks to machinery, and identify maintenance requirements.
Transportation and Logistics
AI systems are used to optimise delivery routes, improve transit timelines, predict maintenance needs, and assist in inventory management. Further, agentic AI systems are being used to enable automation across different stages of the supply chain.
Federal and state governments in India have been taking an active role in promoting the adoption and advancement of AI for industrial use. Considering AI’s potential, governments are keen to invest and prioritise the development and deployment of AI systems. Globally, governments are facilitating AI innovation by funding research for developing new techniques, architecture, and solutions.
The Ministry of Electronics and Information Technology (MeitY) has launched the “IndiaAI Mission”, an initiative under India’s AI strategy, which aims to build a robust AI ecosystem in the country. Various federal departments in India began formulating initial frameworks and roadmaps to guide the government policy and regulation of AI, including the Principles for Responsible AI, Operationalizing Principles for Responsible AI, and India AI Governance Guidelines.
India’s regulatory approach towards AI is based on an “innovation-first” philosophy to promote responsible innovation with necessary safeguards in place. In 2024, MeitY launched the “IndiaAI Mission”, an initiative under the broad AI strategy that focuses on building a comprehensive AI ecosystem. This initiative supports capacity building, improving infrastructure, providing access to datasets, and ensuring the development of indigenous foundational models.
In July 2025, the MeitY constituted a committee to develop an AI governance framework. Accordingly, at the India AI Impact Summit in February 2026, the India AI Governance Guidelines (the “AI Guidelines”) were introduced. The AI Guidelines are built on the following seven key principles:
Additionally, the AI Guidelines provide practical guidance for industry players while deploying AI systems, and recommend adopting voluntary measures to ensure accountability and fairness within the AI systems.
Currently, there are no specific laws or regulations in India that directly govern or regulate AI. At present, use of AI is governed by related violations as stipulated in conventional legislation and regulations, including the IT Act, the DPDP Act, the Bharatiya Nyaya Sanhita 2023 (BNS), as well as the amended Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 (the “IT Rules”). Further, the Copyright Act 1957 (the “Copyright Act”) and the CPA also broadly govern relevant issues in the adoption and use of AI systems.
In India, the proposed Digital India Act is another significant piece of legislation, intended to replace the existing IT Act and to govern the use of high-risk, sophisticated emerging technologies, including AI. Recently, the Artificial Intelligence (Ethics and Accountability) Bill 2025 was also introduced to develop ethical guidelines and standards in the use of AI technologies and systems.
Sector-specific policies and guidelines, published by statutory bodies, including the Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), and the Indian Computer Emergency Response Team (CERT-In), address AI-related concerns.
The MeitY’s AI Guidelines provide a principle-based framework to ensure continuous responsible innovation in AI. With reference to copyright and AI, the Department of Promotion of Industry and Internal Trade (DPIIT) under the Ministry of Commerce and Industry published a paper analysing the existing copyright law and its intersection with AI, and proposed solutions for the use of copyrighted works in AI training data.
Besides MeitY’s “IndiaAI Mission”, an initiative aiming to build a robust AI ecosystem in the country, various federal departments have released roadmaps to guide the government policy and regulation of AI, including the following:
In India, various high courts have also developed policies and guidelines in relation to the use of AI by lawyers and judges, and prescribed provisions mandating disclosures, verifications, and consequences for violations.
In 2024, the European Commission enacted the EU AI Act. The EU AI Act is the first comprehensive law governing the use of AI, including providing a risk-based framework. It also imposes disclosure and labelling requirements on GenAI tools. Due to its extra-territorial nature, the EU AI Act requires entities that are providing/deploying AI systems in Europe to comply with certain requirements, depending on the risk posed by the systems. AI systems that fall under the unacceptable risk category are prohibited from entering the EU market.
Indian AI providers deploying systems to EU-based users or whose AI outputs are used in the EU will fall within the scope of the EU AI Act. For instance, Indian companies in fintech, health-tech, legal tech, and enterprise SaaS with EU customers must classify their AI systems, conduct conformity assessments for high-risk systems, and maintain EU-facing technical documentation.
There are no plans to transpose the EU AI Act into Indian law. However, India has indicated that it will pursue its own regulatory framework tailored to domestic innovation priorities and digital infrastructure.
As the EU AI Act is not applicable in India, no competent authorities or notified bodies have been designated for the purposes of compliance with the EU AI Act. Currently, AI-related issues remain regulated by the MeitY, sectoral regulators, and, once operational, the data protection authorities under the DPDP Act. Likewise, India has not introduced domestic legislation corresponding to the EU AI Act. Instead, policy initiatives such as the IndiaAI Mission and responsible AI Guidelines focus on promoting innovation, ethical AI development, and ecosystem capacity building. While India does not operate EU-style AI regulatory sandboxes, government initiatives under the IndiaAI Mission aim to provide shared compute infrastructure, datasets, and testing environments for start-ups and research institutions.
Overall, India’s approach remains policy-led and innovation-oriented, with AI governance continuing to evolve through incremental regulatory and institutional measures rather than direct adoption of the EU AI Act model.
At present, India does not have state-level legislation specifically regulating AI. AI governance largely falls within the federal legislative competence through federal laws governing information technology, data protection, intellectual property, consumer protection, and criminal liability. Accordingly, most legal obligations relevant to AI systems arise from federal statutes such as the IT Act and the DPDP Act.
However, several Indian states have introduced AI policies, innovation strategies, and programmes intended to promote AI adoption and ecosystem development, although these are economic and innovation-focused rather than regulatory.
For instance, the Government of Telangana (in Hyderabad) has launched dedicated AI initiatives, including the establishment of AI-focused innovation hubs and partnerships with academic and industry participants. Similarly, the government of Karnataka has promoted AI development through its technology innovation policies and support for AI research clusters in Bengaluru. Tamil Nadu and Maharashtra states have also incorporated AI development within broader digital economy and innovation strategies.
Although comprehensive AI legislation has not been enacted in India, nor have direct AI-specific amendments to copyright, data protection, or content laws been introduced, various amendments and policies have been discussed a few significant legal issues in AI. The IT Rules introduced amendments to address the misuse of deepfake technology by defining “synthetically generated information”, mandated labelling requirements for such information, and provided enhanced due diligence by intermediaries.
Besides this, several AI-related issues, such as AI-based processing, web scraping, and the text and data mining (TDM) exception in copyright law, are either regulated through existing legislation or are being proposed at the policy level. For instance, the DPDP Act’s compliance requirements cover AI-based processing, and web-scraping for AI training is governed by the IT Act and IT Rules, which prohibit unauthorised access to a computer system. In terms of policy, incorporating a TDM exception into copyright law was proposed by the DPIIT in 2025. The legal position regarding large-scale data scraping or dataset creation for AI training remains unsettled and may ultimately require judicial clarification or legislative reform.
Currently, there is no proposed AI-specific legislation in India.
Jurisprudence on AI is currently developing in India. A few judicial decisions that have addressed AI-related legal concerns in India are discussed below.
Copyright and Training Data
The ongoing case of ANI Media Pvt Ltd v OpenAI Inc & Anr. (CS(COMM) 1028/2024) is related to copyright law and the use of copyrighted content in training data. ANI Media, a news agency, filed a suit against Open AI alleging that its copyrighted news content has been used to train ChatGPT without authorisation and is in violation of the Copyright Act. OpenAI justified the use by claiming that it falls under “fair dealing”, similar to fair use in the United States. The primary issue to determine is whether the use of such training data amounts to copyright infringement. Currently, the judgment is reserved; however, the decision will impact future conversations pertaining to the use of copyrighted material by various GenAI systems.
Personality Rights
In Arijit Singh v Codible Ventures LLP (2024 SCC OnLine Bom 2445), the case involved the use of the plaintiff’s (a famous singer) voice and other personal attributes without authorisation. The plaintiff’s audio works were uploaded to real-voice cloning AI tools to generate new audio files imitating the plaintiff’s voice. The Court held that such commercial exploitation is a violation of an individual’s personality rights.
Similarly, in the case of Aishwarya Rai Bachchan v Aishwaryaworld.com & Ors. (2025 SCC OnLine Del 5943), the plaintiff’s (a world-renowned actor) images were used for creating deepfake inappropriate imagery. The Court passed an order, granting an injunction in the plaintiff’s favour. The Court held that creating such content using AI tools is a misuse of the plaintiff’s personality rights, causes financial detriment, and causes harm to her dignity, reputation, and goodwill.
In the past year, there have been several judicial decisions that discuss the unauthorised use of a celebrity’s persona for commercial purposes and personality rights.
Authorship in Copyright
Raghav, an AI system, co-created an AI-generated artwork titled “Suryast”. While applying for copyright protection, Raghav was listed as a co-author. However, the Indian Copyright Office issued an objection, requiring clarification on the legal status of Raghav. While this matter is not a judicial decision, it indirectly established that AI systems do not fall under the concept of an “author” in India.
Currently, India does not have a single regulatory authority specifically responsible for dealing with issues involving AI. However, AI-related issues are governed by existing sectoral regulators in India, depending on the sector in which the AI system is deployed.
At the federal level, MeitY plays the most prominent role in governing AI. MeitY introduces AI policies and ensures the ethical deployment of AI systems. Further, the Data Protection Board of India (DPBI) regulates the protection and processing of personal data, which includes the use and processing by AI systems. The Central Consumer Protection Authority (CCPA) regulates misleading advertisements, dark patterns, and other AI-related consumer harms. As regards AI-enabled medical devices, the Central Drugs Standard Control Organisation (CDSCO) is the regulatory authority.
Sector-specific regulatory bodies also play a key role in AI policy. The RBI oversees AI adoption in the financial sector by the regulated entities (including banks, NBFCs) and fintechs, and also addresses associated challenges. SEBI oversees the adoption of AI and machine learning technologies by SEBI-regulated entities, including stock exchanges, clearing corporations, depositories, and intermediaries. Further, CERT-In regulates AI-specific cybersecurity incidents.
In 2025, the RBI released a framework titled Framework for Responsible and Ethical Enablement of Artificial Intelligence (the “FREE-AI Report”). This was also a primary reference for the AI Guidelines released in 2026. SEBI’s consultation paper provides guidelines for responsible usage of AI and machine learning in Indian securities and introduced a five-point regulatory framework. CERT-In regularly provides advisories in connection with AI-related cybersecurity concerns.
Given the increasing use of AI across industries and the potential risks associated with such use, regulatory authorities have prescribed enforcement actions for any contravention of the relevant laws. However, India has not as yet witnessed a significant volume of AI-specific enforcement actions, particularly in relation to agentic AI systems.
Further, in the event of a breach of any of the DPDP Act’s provisions, the DPBI may impose monetary penalties depending on the violations. The DPDP Act also imposes mandatory reporting obligations on the data fiduciary in the event of a personal data breach, requiring them to report such breaches without delay and provide an updated report within 72 hours. The CCPA imposes fines, as well as imprisonment, depending on the violation, including the use of dark patterns.
Additionally, as discussed in 4.1 Precedent-Setting Judicial Decisions, various Indian courts have granted injunctions in cases of AI-based unauthorised use of a celebrity’s persona for commercial purposes and AI-based personality rights violations.
AI systems are governed through existing legislation and policies. They are also required to comply with certain technical requirements.
The Bureau of Indian Standards (BIS) is the primary authority that develops technical standards, certification systems, and conformity assessments for various industries. Such technical standards ensure AI systems are safe and transparent. With the emergence of sophisticated AI systems, BIS has developed standards that align with existing international standards for AI. The AI Guidelines provide an extensive list of international standards developed by BIS in relation to the use of AI for Indian entities for adoption by Indian entities.
Further, the Telecom Engineering Centre (TEC), under the Department of Telecommunications (DOT), recently developed a new standard involving a three-step process for assessing and rating the robustness and fairness of AI systems. It has also developed a standard, TEC 57070:2025, to identify vulnerabilities within AI systems and propose mitigation strategies.
Standards developed by the International Organization for Standardization (‘ISO’) and the International Electrotechnical Commission (‘IEC’), including ISO/IEC 42001 (AI management systems), ISO/IEC 23894 (AI risk management), and ISO/IEC 22989 (AI terminology and concepts), are increasingly referenced by Indian enterprises building AI governance programmes.
Although these international standards are not legally binding in India, they generally align with emerging domestic policy principles around responsible and trustworthy AI. Companies frequently adopt such frameworks to demonstrate compliance with broader regulatory obligations under Indian law, including data protection, cybersecurity, and consumer protection regimes. From a practical perspective, international AI standards operate as de facto governance and regulatory benchmarks, helping Indian organisations structure internal controls and anticipate future regulatory requirements.
Government agencies in India have been increasingly deploying AI systems to improve public service delivery, administrative efficiency, and regulatory oversight.
For instance, the Unique Identification Authority of India (UIDAI) integrated AI-based document metadata extraction and verification in the Aadhar (a national ID card) ecosystem. The Ministry of Housing and Urban Affairs (‘MOHUA’) developed India Urban Data Exchange (IUDX), an open-source platform to exchange data in relation to urban cities for the purpose of planning and improving public services. The Ministry of Agriculture and Farmers Welfare launched ‘Kisan e-Mitra’, a voice-based AI chatbot, to assist farmers with queries on government schemes.
Further, the MeitY has introduced various AI tools, including an AI-powered language translation platform called ‘Bhashini’, which provides access to digital services through multiple languages, ‘AIRAWAT’, which is an integrated platform to provide tools and resources for the development of software, and ‘Digidhan Mitra’, an AI-powered chatbot, to provide information in relation to digital payment transactions in India.
At present, there are no landmark judicial decisions that involve the use of AI by government agencies.
With the rise of modern conflicts, the Indian government is placing AI-powered innovations at the forefront to fulfil its national security objectives. In 2022, the Ministry of Defence organised the “Artificial Intelligence in Defence” symposium and exhibition to showcase 72 AI-enabled solutions for use in the defence sector.
The use of AI is also seen in the form of autonomous surface and aerial vehicles. The Centre for Artificial Intelligence and Robotics (CAIR), under the Department of Research and Development Organisation (DRDO), is currently developing military robotics, drones, and other surveillance technologies. The government has also integrated AI tools for policing and law enforcement, primarily for crime detection, enhanced surveillance, and assistance in criminal investigations.
GenAI is a subset of AI that is capable of generating text, images, audio/video, or other forms of media/content. The GenAI systems analyse existing data and patterns to generate novel information. Depending on the model, the GenAI systems vary between foundation models, large-language models (LLMs), general-purpose AI models, coding tools, etc.
The AI Guidelines define foundation models as “large AI models trained on vast datasets for general tasks”. Due to the large amounts of data utilised by such models, which may include personal data, the obligations under the DPDP Act apply. Once an entity processes personal data for the purpose of training AI models, it will be required to prove a lawful basis for such processing and ensure reasonable security safeguards to prevent any breaches. Further, the amended IT Rules may also apply in case such models are deployed through intermediaries.
In comparison to other AI models, GenAI models introduce significant legal concerns. In terms of input, the training data may contain copyrighted works as well as personal or confidential information, may include incorrect/incomplete/low-quality datasets, etc. In terms of output, the AI-generated works may potentially infringe upon existing works, may be biased, or may contain portions of copyrighted content/personal or confidential information. There is a lack of clarity regarding the ownership/authorship of the AI-generated works. The uncertainty regarding authorship/ownership also creates more issues in terms of liability.
Please see 16. Intellectual Property and 17. Data Protection for a detailed analysis of the copyright and data protection laws applicable to AI-generated works.
The adoption of AI in the legal profession in India has been increasing over the past couple of years. AI-driven technologies are being developed and integrated into the legal system to assist judges as well as lawyers. AI tools aid in conducting legal research, analysing case law and generating summaries, reviewing documents, predicting outcomes, assessing risk, providing translations, etc. Although the primary purpose of using AI-driven technologies is to streamline complicated or monotonous processes, such use must require caution, oversight, and accountability.
The Supreme Court of India launched the eCourts Project to transform the judicial system to increase efficiency and enhance productivity. Since its conception, the project has been implemented in phases, and the proposed Phase III specifies the deployment of AI technologies to improve the e-filing systems, legal research databases, service of summons, etc. Therefore, AI tools are integrated to support the existing systems of the judiciary, including digital filings, reviewing and identifying defects, improving case management systems, and providing real-time and accurate transcriptions/translations.
With the increasing reliance on AI technologies by the legal fraternity, several challenges, such as confidentiality breaches, fabricated legal precedents in pleadings, and algorithmic biases in generative AI tools, exist. There are already instances of lawyers relying on non-existent case law in their pleadings or filing petitions with AI-generated arguments, which highlight the need to exercise caution while using such technologies. At times, a client’s confidential information is fed into AI platforms for the purpose of document analysis or other tasks. However, the lack of sufficient safeguards may potentially pose a huge risk to the client in case of a breach.
The courts in Kerala, Punjab and Haryana, as well as the Gujarat High Court, have introduced policies to address the misuse of AI technologies. These policies prescribe permissible and prohibited uses of AI tools, confidentiality requirements, human verification of automated processes, and consequences for violations.
In India, liability for harm caused by AI systems is addressed through existing tort, product liability, and statutory frameworks, rather than AI-specific legislation.
Product Liability
Under the CPA, liability may arise where an AI-enabled product or service is defective or unsafe. A defect may stem from flawed design, biased or inadequate training data, or failure to implement safeguards or warnings.
Negligence
Developers and deployers may face negligence claims where harm results from failure to exercise reasonable care in designing, testing, or supervising AI systems. Liability may arise where organisations deploy AI tools without adequate validation, oversight, or risk mitigation.
Strict Liability
Although no AI-specific strict liability regime exists, Indian courts have historically applied strict and absolute liability doctrines to hazardous activities. Similar reasoning may be invoked where autonomous systems create inherently dangerous risks.
Vicarious Liability
Organisations may be held responsible for the acts of employees or agents using AI systems within the scope of their employment, particularly where automated tools inform operational decisions.
AI-Generated Content
Liability may arise where AI outputs infringe intellectual property rights, contain defamatory material, or disseminate unlawful content. Responsibility may attach to developers, deployers, or users depending on control over the system and publication of the output.
Evidentiary Challenges
AI disputes often involve attribution difficulties due to the non-transparent nature and uncertain outputs. These issues complicate fault determination and are likely to be discussed in future judicial precedents.
Although there are no specific provisions related to AI under the CPA, AI-enabled products may fall within the scope of product liability provisions. Additionally, concepts such as negligence, vicarious liability, and strict liability, under tort law, may also be interpreted to bring AI-enabled products under their ambit. However, their practical application is not as yet determined by a judicial decision or authority. It is anticipated that the proposed DIA may discuss liability and related issues for AI products.
In India, the term “agent” is defined under the Indian Contract Act 1987, but it does not apply to AI systems. Currently, India does not recognise agentic AI systems as independent legal actors. Actions taken by such systems, such as entering transactions, executing tasks, or generating outputs, are legally attributed to the human or organisation deploying the system. To that end, the liability would be assessed under existing frameworks such as contract law, tort, product liability, and consumer protection law.
Accountability in agentic AI deployments is likely to extend to all the persons/entities involved, including developers, deployers, and service providers, depending on control over system design and operation. Emerging governance frameworks stress logging, auditability, and explainability to enable oversight and attribution of responsibility. Autonomous systems used in high-risk sectors such as finance, healthcare, or public administration may face stricter scrutiny under sector-specific regulation, although India does not yet have a dedicated legal framework for agentic or multi-agent AI systems.
In relation to harm caused by AI agents, please refer to the liability concerns discussed in 8.1 Generative AI: Key Legal Issues and Regulatory Approaches.
AI systems built on unreliable or prejudiced datasets, or with a lack of appropriate representation, generate content with biases related to gender, religion, or economic status. Biased outcomes also cause greater harm to marginalised communities. Therefore, the algorithmic bias problem is rooted in the use of unreliable, prejudiced data.
Liability for harm caused by AI systems is addressed through existing frameworks, including tort law, product liability under the CPA, contractual liability, and sectoral regulation. Responsibility is typically assessed based on the role of actors in the AI lifecycle. Developers may face claims arising from defective design or inadequate safeguards. Similarly, operators may incur liability for negligent deployment or lack of supervision. Likewise, users may be responsible for harm resulting from misuse or reliance on AI outputs.
From a practical standpoint, liability is often allocated contractually between developers, vendors, and enterprise users through indemnities, limitation clauses, and risk allocation provisions. However, disputes involving autonomous systems may raise evidentiary and causation challenges, particularly where decisions are produced through non-transparent behaviour or complex AI supply chains. These difficulties may increase in AI systems when multiple agents are involved, especially when autonomous systems can create failures or harm, complicating the attribution of fault under existing legal doctrines.
A few ways to eliminate algorithmic bias in AI tools include conducting regular audits of the AI systems, evaluating the diversity parameters in data collection, and other safeguards. The AI Guidelines have recommended the use of techno-legal solutions to mitigate the risks of AI and automated bias detection mechanisms to overcome such issues.
Biometric data comprises facial patterns, fingerprints, iris scans, etc, and is inexplicably linked to the individual. Due to the nature of the data, issues arising from the use of biometric technologies are particularly alarming. A potential breach of biometric data leaves an individual susceptible to the risk of fraud or identity theft. The Supreme Court, in its landmark decision regarding the Aadhar system (Justice K.S. Puttaswamy (Retd.) v Union of India, AIR 2018 SC (SUPP) 1841), has discussed the use of biometric data.
Further, the DPDP Act treats biometric information as personal data and requires lawful processing, notice to individuals, and valid consent, subject to limited exemptions. Processing must comply with purpose limitation, security safeguards, and data minimisation principles.
Although there are currently no specific statutory prohibitions on emotion recognition or biometric categorisation technologies, their use would still be subject to privacy, discrimination, and data protection principles. Organisations using biometric AI are expected to provide clear notice and obtain consent where personal data is processed, and implement adequate security and access controls. Sectoral regulators may impose additional safeguards where biometric authentication is used in financial services or digital identity systems.
Niti Aayog, an Indian think tank, published a paper titled ‟Responsible AI for All”, and discussed the application and issues arising due to facial recognition technologies, gathering of biometric data through the air travel portal “Digi Yatra”, which verifies an individual’s biometric data for air travel, and provides recommendations for the responsible use of such technologies.
In 2026, the IT Rules were amended to incorporate relevant provisions to address the unrestrained distribution of deepfake and synthetically generated content (SGI) on social media or other platforms. The amended IT Rules define SGI and also specify certain categories that do not fall within the scope of SGI. The amended provisions also impose due diligence requirements on the intermediaries, which include obtaining a user declaration of SGI, verifying the content using technical safeguards, as well as appropriate labelling of content in cases involving SGI. The amendments also prescribe reduced timelines for intermediaries to take down unlawful SGI and grievance redressal. These amendments provide a regulatory framework to protect users from manipulated and false content.
Further, deepfakes that impersonate individuals, spread misinformation, or cause reputational harm may attract liability under the ITA, the BNS (Indian Penal Code), and intermediary rules requiring online platforms to remove unlawful content upon notice. Additionally, the BNS contains provisions that address the spread of false information using electronic means that may cause fear or alarm to the public. Platforms hosting synthetic media may face intermediary liability exposure if they fail to act on takedown requests relating to impersonation, defamation, fraud, or non-consensual content.
Affected individuals may pursue civil remedies, including defamation, passing off, privacy violations, and injunctions against the circulation of manipulated media. Although India does not yet mandate labelling or disclosure of AI-generated content, policymakers and regulators have increasingly emphasised transparency obligations and platform due diligence. Emerging policy discussions also highlight the role of authentication technologies and stricter safeguards in sensitive contexts, including elections, financial fraud, and non-consensual intimate imagery.
Transparency and disclosure requirements need AI systems to disclose that the user is interacting with or using a system that incorporates AI, especially in cases where AI is used for creating content, interacting with users, or providing advice/opinion.
The AI Guidelines highlight the adoption of voluntary measures to ensure transparency and fairness while deploying AI systems. As regards disclosure requirements, the Gujarat High Court’s policy regarding AI use also requires legal assistants, research associates, and judicial assistants to disclose any use of AI tools. Further, the Guidelines for Influencer Advertising in Digital Media 2023 require virtual influencers to prominently disclose that users are not interacting with a human being. Similarly, SEBI also released guidelines for research analysts and investment advisors to disclose their use of AI tools.
AI procurement in India is typically governed through technology licensing, SaaS, or services agreements, with contractual frameworks adapted to address risks specific to AI systems. Contracts commonly address risk allocation between the AI supply chain components, including developers, vendors, and enterprise deployers, including responsibility for the AI model’s performance, training data compliance, and regulatory obligations. Service level agreements (SLAs) may cover system availability, model performance thresholds, response times, and incident management. Agreements also define data rights and usage, particularly whether customer data may be used for model training or improvement, and the treatment of outputs generated by the system.
Contracts typically address intellectual property ownership, including rights in models, training data, and generated outputs. Vendors may provide compliance warranties and indemnities relating to data protection, IP infringement, or regulatory compliance. Enterprise customers often negotiate audit rights to verify security and data-handling practices.
Additionally, procurement agreements frequently include exit and portability provisions to enable migration of data or models to alternative providers, together with negotiated liability caps, limitation clauses, and insurance requirements reflecting the potential risks associated with AI deployment.
The AI Guidelines recommend the implementation of obligations and due diligence requirements for AI actors. The AI Guidelines highlight that the IT Act does not define or specify the role of the different actors involved in the AI value chain (deployers, developers, users, etc) and does not specify the issue of liability who fail to observe due diligence obligations.
However, responsibility for AI systems is generally assessed through existing principles of contractual liability, negligence, product liability, and regulatory compliance.
Using AI in hiring and recruitment processes has increased efficiency and streamlined each stage of the process. AI systems or AI agents oversee the identification of candidates, interview processes, and communications. These systems handle the recruitment process and carry out resume screening, schedule interviews/follow-ups, automate candidate sourcing, review employee performance, etc. However, there is no AI-specific statute governing automated hiring or termination decisions. Instead, the HR practices are generally assessed under existing employment, data protection, and anti-discrimination frameworks.
In addition to the practices outlined in 14.1 Hiring and Termination Practices, several AI tools review employees’ performances at the workplace. Such tools analyse employees’ performance over a defined period and provide insights, without the need to conduct routine appraisals. The tools also track the employees’ progress by reviewing data on their emails or other relevant company-specific applications.
While there is no AI-specific regulation governing workplace monitoring, such practices must comply with data protection, labour, and privacy principles. Employers are generally expected to provide notice regarding monitoring practices and limit data collection to legitimate business purposes. Processing of employee data, including biometric information, may attract obligations under the DPDP Act, including security safeguards and responsible data handling.
Liability risks may arise where monitoring technologies result in unlawful surveillance, discriminatory outcomes, or improper data handling, particularly if employers rely exclusively on automated outputs without appropriate human review.
Digital platform companies use AI-based infrastructure to conduct their business operations, which may include e-commerce platforms, social media platforms, and platforms offering various services. In such platforms, AI technologies may be integrated into workflows to facilitate their business processes. Therefore, regulation of digital platforms is multi-layered and is governed by various legislation and regulatory authorities, including the IT Act and the IT Rules, 2021, which impose due diligence obligations on intermediaries.
For instance, if the platforms deploy AI systems to generate content, these platforms will be subject to the due diligence and labelling requirements under the IT Rules to regulate the AI-generated content. Further, if the platforms use AI technologies to analyse market trends and apply pricing strategies, anti-competitive practices will be regulated by the CCI. Additionally, the AI Guidelines also emphasise the principles of trust, fairness, and accountability to ensure the responsible adoption of AI in the digital ecosystem.
In the financial services industry, AI technologies such as predictive analytics and deep learning are used in India. Such technologies assist in the automation of tasks. Further, chatbots are used for customer support, as well as to identify and detect fraud.
In India, AI-driven credit decisioning is adopted by many major banks to facilitate their lending functions. It allows such entities to analyse data faster and more efficiently. To encourage the responsible and ethical adoption of AI in the financial sector, RBI’s FREE-AI Committee report provides guiding principles. In 2024, the RBI also released a draft circular that introduces a Model Risk Management framework that covers the development, validation, implementation, and monitoring of credit risk models.
To address the issue of algorithmic trading, SEBI released a circular to regulate retail investors’ involvement in algorithmic trading. In this sector, SEBI also imposes reporting obligations on certain regulated entities that use AI or machine learning technologies in their product offerings.
In the healthcare industry, AI technologies are applied in clinical decision-making and other administrative functions. However, its application in diagnostic tools and other medical functions requires a comprehensive and ethical framework that prescribes safeguards and ensures accountability. AI is also increasingly used in India’s healthcare sector for diagnostic imaging, patient data processing, drug identification, and hospital administration.
Regulation primarily arises through existing medical device, health data, and professional liability frameworks. AI-based diagnostic tools may fall within the scope of CDSCO’s medical device regime where the software performs a clinical function, requiring regulatory approval and safety compliance. Healthcare providers deploying AI systems remain responsible for ensuring that clinical decisions are made under qualified medical supervision, and AI outputs are generally treated as decision-support rather than autonomous medical judgments.
During the India AI Summit, the Strategy for AI in Healthcare in India (SAHI), which focuses on ethical and evidence-based AI adoption in the healthcare industry, was introduced. Additionally, the Benchmarking Open Data Platform for Health AI (BODH) was also introduced during the same summit, providing a structured mechanism for testing and validating AI solutions before deployment at scale.
The Indian Council of Medical Research (ICMR) introduced guidelines that apply to AI-based tools created for biomedical and health research. These guidelines apply to developers, hospitals, health professionals, etc, using health data for biomedical research and healthcare systems using AI technology and techniques. Further, the CDSCO regulates AI-enabled medical devices in India. The Medical Devices Rules, 2017, provide technical documentation requirements for high-risk medical devices.
The AI deployment in autonomous or semi-autonomous vehicles in India remains limited and is largely confined to advanced driver-assistance systems (ADAS) such as automated braking, lane assistance, and driver monitoring. These systems rely on machine learning models that process sensor and camera data to support driving decisions, but Indian law currently requires a human driver to remain in control of the vehicle.
Regulation primarily arises under the Motor Vehicles Act, 1988, and related automotive safety standards administered by the Ministry of Road Transport and Highways. Vehicles must comply with prescribed safety and certification requirements before being sold or operated. Fully autonomous vehicles are not presently authorised for commercial road use in India, and policymakers have expressed caution regarding their deployment due to concerns relating to road safety and employment impacts.
Manufacturers introducing AI-enabled driving features must also comply with product safety and consumer protection laws, including obligations relating to misleading claims and defective products. Liability for accidents involving AI-assisted systems generally continues to rest with the driver and vehicle manufacturer, depending on the circumstances. India has not witnessed significant enforcement actions specifically involving autonomous vehicle AI as of yet. However, regulatory scrutiny is expected to increase as automated driving technologies evolve.
AI technologies are widely used in the retail and consumer sector in India, such as conversational chatbots for customer service, personalised recommendations, virtual try-on options, and inventory management. In India, several e-commerce companies have adopted AI-powered technologies to improve customer experience and business operations. However, the use of AI raises concerns related to algorithmic bias, the collection of personal data/biometric data, misleading advertisements, etc. These concerns can be addressed under the existing laws.
The use of such systems is primarily governed by consumer protection, data protection, and digital commerce regulations. The CPA and the Central Consumer Protection Authority framework prohibit misleading advertisements, dark patterns, and unfair trade practices, which may arise where AI-driven recommendation or pricing systems manipulate consumer choices. Processing of consumer data through AI systems must also comply with obligations under the DPDP Act, including lawful processing and reasonable security safeguards.
In this regard, the CCPA issued the Guidelines for Prevention and Regulation of Dark Patterns, 2023, to prohibit the use of such deceptive practices and mandate self-audits. The guidelines identified a few dark patterns, such as false urgency, basket sneaking, confirm shaming, subscription trap, and disguised advertisements, and required e-commerce platforms to restrict/eliminate such use.
Retail platforms deploying AI may also face regulatory scrutiny where automated systems enable deceptive marketing, discriminatory pricing, or misuse of consumer data. While enforcement actions specifically targeting AI remain limited, regulators have shown increasing interest in algorithmic transparency and platform accountability, particularly in the context of digital commerce and targeted advertising practices.
The research, development, and application of robotics in India have extensively increased in the recent past. The World Robotics Report, 2025, by the International Federation of Robotics, placed India in sixth position globally in connection with robotic installations. Further, the MeitY’s National Strategy on Robotics discussed the use of AI in robotics to enhance decision-making processes and performance of tasks. The adoption of AI-assisted robotic technologies is being considered in various industries, such as healthcare, manufacturing, agriculture, and hospitality.
AI-assisted robotic technologies pose the standard challenges of legal personhood, liability, data protection, algorithmic bias, etc. However, there is no law addressing these concerns in the context of robotics. While MeitY is the primary agency governing robotics in India, the Technology Advisory Group, under the Principal Scientific Adviser (PSA), BIS, and CAIR, are relevant bodies for regulating robotics in India.
Additionally, industrial robots and automated machinery must comply with safety and equipment standards administered by authorities such as the BIS, while workplace safety obligations under the Occupational Safety, Health and Working Conditions Code, 2020, require employers to ensure safe operation of automated machinery and adequate worker protection. Where AI-enabled robotics cause injury or malfunction, liability may arise under product liability provisions of the CPA, or under general tort principles.
AI system components may be protected under multiple IP regimes in India, depending on the nature of the output or asset created, by the Patents Act, 1970 (the “Patents Act”) and the Copyright Act.
Under the Patents Act, the provision governing patentability, ie, Section 3 of the Patents Act, excludes mathematical methods, business methods, computer programs per se, as well as algorithms. However, judicial decisions over time clarified that the Section does not entirely bar computer programs themselves, and if a computer-related invention demonstrates “technical effect”, it would be patentable. Further, the draft Computer Related Guidelines (2025) specifically address emerging technologies such as AI, by clarifying that AI-based inventions may be patentable where they are tied to specific technical applications.
Under the Copyright Act, software code is protectable as a “literary work”. Further, databases are also protected as literary works if a sufficient level of the author’s creativity and originality exists. Although AI-generated works are being considered under copyright law, there are several legal challenges to the copyrightability of such works. AI developers also frequently rely on trade secret protection for model weights, training methodologies, and proprietary datasets, particularly where patent disclosure is undesirable.
Ownership and control of AI assets are often governed by contractual arrangements, including licences, data-use agreements, and deployment terms. These agreements typically address rights in training data, inputs, and generated outputs. AI systems also present IP infringement risks, particularly where training datasets include copyrighted material or where generated outputs reproduce protected works or trade marks. These issues remain an evolving area of law in India, and disputes are likely to be resolved under existing copyright, trade mark, and passing-off principles.
Currently, India does not recognise AI as an inventor/author of AI-generated inventions or works. The Patents Act only considers a “natural person” as an inventor, whereas the Copyright Act considers the “person” who created the work to be an author. Notably, in India, an AI system was granted the status of a co-author of an artistic work titled “Suryast”. However, the Indian Copyright Office issued a withdrawal notice, requesting a clarification of the legal status of the AI system. This indicates that the Copyright Office may not consider an AI system to be an actual “author”.
Similarly, the Patent Office rejected the patent application filed in the name of DABUS, an AI system, as the inventor. The Patent Act stipulates the various requirements of filing a patent application, but an AI system does not meet the statutory requirements, and therefore, it cannot be considered the true and first inventor.
Various landmark judicial decisions in India, such as the R.G. Anand v Deluxe Films (AIR 1978 SC 1613) case and the Eastern Book Company v D.B. Modak ((2008) 1 SCC 1), have extensively discussed the significance of human skill and judgement to determine the copyrightability of a work. Therefore, works should be independently created by the author and should possess a minimal degree of creativity. Relying on these principles, AI-generated content does not possess the required level of human skill and judgement and cannot be considered to be an author under the present copyright law in India.
India’s current legal framework does not establish guidelines on the permissible use of copyrighted materials for AI training. However, the ongoing case of ANI v OpenAI, which focuses on whether copyrighted material can be used to train AI, will be a decisive precedent.
In 2025, the DPIIT proposed a hybrid model requiring AI developers to receive a blanket licence for the use of “lawfully accessed” content for training AI models. There are also discussions about AI-generated content being protected as a “derivative work”. As a derivative work is based on an existing, copyright-protected work and may qualify for intellectual property protection if it introduces significant variations from the original, AI-generated works could be interpreted as a derivative work.
However, as GenAI systems create content based on training data containing copyright material, the AI-generated content is also alleged to be an infringing copy of the original works. In the United States, various GenAI systems have been under legal scrutiny as authors and other related parties have initiated legal proceedings against such AI systems for the unauthorised use of their data in large volumes for training.
Artworks are created using AI tools based on user-generated prompts. However, the data fed into the AI tools as training data may contain copyrighted material. Therefore, the AI-generated artworks, ie, the output, ultimately resemble or contain copyrighted material. Since the popularity of GenAI tools has increased, platforms such as GitHub, Stability AI, Midjourney, etc, have been involved in legal proceedings on allegations of copyright infringement globally. The works generated by these platforms violate the intellectual property rights of several original artists and incorporate their works without consent. In the same manner, some platforms generate audio content that uses the original artist’s voice for the same.
Ownership may also be governed by contractual arrangements, including platform terms governing generative AI tools. Moral rights, including the rights of attribution and integrity recognised under the Copyright Act, are linked to human authors and therefore do not comfortably apply to works generated autonomously by AI systems. As a result, many AI-generated artworks currently fall into a grey area in Indian copyright law, and related policy discussions are ongoing.
Foundation models train on large datasets to perform tasks. As part of India’s AI strategy, one of its main objectives is to promote and invest in indigenous foundational models. Developing indigenous foundational models with diverse datasets and adopting such models can help in making sure that the risk of bias is reduced. The AI Guidelines recommend building ethical models that reflect India’s linguistic, cultural, and social diversity. Further, the Advancing Indigenous Foundation Models Report, 2026, details the initiatives taken in India to support this, which includes the AIKosh Platform, the IndiaAI compute portal, and multiple public-private partnerships that are already in the process of developing sovereign models.
Fine-tuning, model merging, and distillation may create derivative works or adaptations, depending on the underlying licence. Open-source AI licences may impose obligations relating to attribution, disclosure of modifications, or restrictions on certain uses. Their enforceability will be assessed through contract and copyright principles under the Copyright Act.
While there has been steady progress in the development of indigenous foundation models, there are existing intellectual property risks associated with these models. As the models are trained on large-scale datasets, there is a risk of infringing upon copyright-protected works. Therefore, the input of copyright-protected content may generate output that may potentially infringe upon the same copyrighted content. Many jurisdictions have incorporated relevant exceptions to permit the use of copyrighted works for AI training.
Moreover, AI models are typically released to the public under licences, such as proprietary, open-source, or open-weight licences. If the AI models trained on datasets with potentially infringing content are released on open-source/open-weight licences, then such models that are publicly available further complicate the ethical and legal challenges.
Under the DPDP Act, organisations that process personal data are considered to be data fiduciaries and are subject to several compliance requirements. AI systems that process large amounts of training data, which may include personal data, are required to provide transparent and specific disclosures in connection with the data processing, obtain informed consent, inform individuals if their data is being used for training purposes, assess the quality of data to prevent algorithmic bias, and ensure the data is used only for the specific purpose.
The DPDP Act also provides rights to the data subject in relation to the processing of such data for AI training, such as the right to access information, correction, and erasure of personal data, as well as the right to grievance redressal.
Although AI-specific provisions are not explicitly included in the DPDP Act, the provisions related to the lawful basis for processing, the requirement of consent, and data subjects’ rights are all covered and applicable to entities using AI systems. Specifically, the right to explanation and right to automated decisions under the EU’s General Data Protection Regulation (GDPR) are not included in the DPDP Act. However, the AI Guidelines specify the need for AI systems to provide clear explanations and disclosures to understand the workings of the AI systems.
As regards children’s data, the DPDP Act places strict safeguards to process children’s personal data by obtaining verifiable parental consent, age verification measures, and other requirements. It also prohibits the processing of children’s data in cases where it is used for monitoring purposes. Further, the AI Guidelines highlight that children fall within vulnerable groups, and therefore, AI systems require a structured mechanism of risk assessment and appropriate safeguards to prevent any AI-related harms.
In India, the DPDP Act provides for cross-border data transfers, unless explicitly restricted by the government. While the DPDP Act does not address Data Protection Impact Assessments (DPIAs) specifically for AI systems, it prescribes DPIAs for Significant Data Fiduciaries (SDFs) handling high-risk processing. Therefore, this mechanism applies to AI systems. These DPIAs assist in identifying and mitigating risks before the deployment of AI systems.
In 2025, the Competition Commission of India published a market study analysing the effects of AI on competition dynamics in India. The study highlighted the rise of several anti-competitive issues, primarily due to the use of AI.
For instance, the use of algorithms that independently analyse market data and accordingly adopt pricing strategies without any human intervention is a form of tacit collusion that is not covered under the existing framework.
There is also a trend of tech companies bundling their AI-related offerings with existing products and services. In 2024, the CCI reportedly reviewed both Google and Microsoft for potential anti-competitive practices arising from the integration of their AI solutions into their existing products. Given the position of both players in the market and their bundled services, such practices inevitably make it difficult for smaller companies to operate in the market.
Further, big players in the AI market also tend to acquire smaller competitors to prevent further competition in the market. Another relevant aspect is when these players offer products and solutions at all levels of the AI value chain, which again may create a self-preferencing structure, whereby consumers may end up purchasing solutions from the same company. This may reduce the likelihood of competition from smaller companies.
The cybersecurity framework in India is governed by the IT Act, the IT Rules, and the DPDP Act. Additionally, cybersecurity regulations include CERT-In’s binding directions and guidelines. The CERT-In Directions 2022 also address cybersecurity incidents involving AI systems, such as AI model compromise, unauthorised access to AI training data, or AI-enabled system failures, and impose reporting guidelines. If such incidents involve personal data, reporting obligations under the DPDP Act also apply.
Additionally, MeitY has addressed concerns such as AI-specific security threats like data poisoning, adversarial attacks, and model extraction attacks. MeitY recommended adopting global standards such as the ISO/IEC 42001, the NIST AI Risk Management Framework, and the OWASP Top 10 for LLM applications. In April 2026, CERT-In also released a high-risk advisory against frontier AI systems that are equipped with advanced cyber capabilities. Such capabilities allow the AI systems to discover vulnerabilities, analyse source code, and stage attacks.
While AI is introducing innovative solutions for the environment, the technologies are consuming large amounts of energy resources. Larger AI models also require higher energy consumption, compared to smaller models.
It is recommended that AI systems utilise AI-driven technologies to track their energy consumption and, accordingly, monitor electronic waste and reduce their carbon footprint. By regularly monitoring such parameters, coupled with adopting renewable energy resources and conducting impact assessments, AI systems can reduce their environmental impact.
AI governance in India is primarily under MeitY, the Niti Aayog (National Institution for Transforming India), as well as specific regulatory bodies. These authorities oversee the development of AI-related policies and strategies, as well as the adoption of AI systems. The AI Guidelines have recommended a “whole-of-government approach”, requiring the relevant ministries, regulators, and public institutions to oversee the regulation of AI. Further, the AI Guidelines have also suggested establishing the following authorities:
7th Floor, Keshava
Bandra Kurla Complex
Bandra East
Mumbai - 400 051
India
+91 22 6112 8484
mailbox@anaassociates.com www.anaassociates.com