TL;DR for founders
There is no Indian AI Act to comply with. The India AI Governance Guidelines (MeitY / IndiaAI Mission, 5 November 2025) are policy, not law — 7 principles, a 6-category risk taxonomy, and a deliberately voluntary pathway with no mandatory pre-approval. What actually bites comes from elsewhere: the DPDP Act, 2023 on your training and inference data, with the Schedule reaching ₹250 crore for a security-safeguards breach; the synthetic-media labelling amendment to the IT Rules 2021 from 20 February 2026; Section 79 safe harbour if your system generates rather than hosts; and your sectoral regulator. This playbook is the clearance workflow for one AI feature.
This is the deployer's playbook — the workflow a legal, risk or security reviewer runs when a business unit wants to ship an AI feature into an Indian-facing product. For the policy framework itself see Veritect's India AI Governance Guidelines explainer; for financial-sector model risk specifically, see the RBI model risk management readiness playbook.
Step 1 — Inventory before you assess
You cannot clear what you cannot see. Build a register covering three populations that governance programmes routinely miss: systems built in-house, systems fine-tuned on a third-party base model, and systems procured and embedded by a vendor inside a wider product. Capture per entry: the accountable owner, the decision the system influences, whether personal data is involved at training or inference, whether output is customer-facing, and whether a human reviews output before it takes effect.
The Guidelines' emphasis on trust "embedded across the value chain" is the reason the vendor-embedded population matters. Procurement is where most enterprises acquire AI risk without recording that they have.
Step 2 — Triage against the six risk categories
Use the taxonomy as an intake filter, not an academic exercise. Ask which of the six the feature could plausibly touch:
- Malicious uses — deepfakes, model or data poisoning, adversarial inputs to critical infrastructure.
- Bias and discrimination — the canonical example is a recruitment tool trained on biased historical data producing loss of opportunity or livelihood.
- Transparency failures — personal data used to develop a system without consent.
- Systemic risks — dependence on concentrated compute, data or model supply.
- Loss of control — agentic systems that sense, respond and act toward goals, and multi-agent coordination, are specifically flagged.
- National security threats — disinformation at scale, attacks on critical infrastructure.
Add the cross-cutting check the Guidelines call out separately: does the feature reach children — where recommendation engines optimising for engagement over well-being are the identified harm — or expose women to deepfake abuse? Those two populations attract heightened expectations regardless of the feature's headline risk score.
Step 3 — Fix the classification and the safe-harbour position
Determine whether, for this feature, the business is an intermediary, a publisher, or neither under the IT Act, 2000. Where the system generates or materially modifies content rather than hosting a user's, the availability of Section 79 safe harbour is genuinely unsettled — the Guidelines themselves list classification and liability under the IT Act as an open legal gap.
Do not resolve this by optimism. Write the position down, with reasoning, before launch. A documented, defensible classification is worth far more in an enforcement conversation than a favourable assumption nobody recorded.
Step 4 — Map the DPDP obligations per pipeline
Treat training data, fine-tuning data and inference-time inputs as three separate processing activities under the Digital Personal Data Protection Act, 2023, each needing its own lawful basis under Section 6 consent or Section 7 legitimate uses.
The failure mode is purpose limitation: consent obtained to deliver a service does not silently extend to model training. Where the enterprise is or may become a Significant Data Fiduciary, the additional obligations under the DPDP Rules, 2025 — including the Data Protection Officer requirement — attach on top. And note the ceiling: under the Schedule to the DPDP Act, breach of the Section 8(5) obligation to take reasonable security safeguards may extend to ₹250 crore.
💡 Working out which obligations actually bind an AI feature, and which are advisory? The Veritect Legal AI platform holds the India AI Governance Guidelines alongside the DPDP Act 2023 and Rules 2025, the IT Act 2000, the IT Rules 2021 as amended for synthetic media, and the RBI, SEBI, ICMR and TEC AI instruments — so the binding layer is separable from the voluntary one. Explore Veritect Legal AI →
Step 5 — Design the human-oversight layer
Under the People First principle, humans should as far as possible retain final control, with oversight at critical decision points so outputs can be reviewed, overridden or supplemented before they cause harm.
Where genuine human review is infeasible at operating speed — the Guidelines use high-velocity algorithmic trading as the example — substitute engineered safeguards: circuit breakers, automated checks and system-level constraints, supported by monitoring, audit trails and reporting protocols that keep the system inside defined bounds. Record which of the two models applies per decision point, and why. "The model is too fast for a human" is an argument that must be paired with the compensating control, not offered alone.
Step 6 — Adopt the voluntary layer, deliberately
The Guidelines prefer voluntary instruments and set out four types: Responsible AI principles, voluntary commitments, technical standards — including BIS LITD 30 AI standards and the TEC voluntary standard for fairness assessment and rating of AI systems — and audits, whether self-assessment or third-party review with results disclosed.
Adopt proportionately. Low-risk features may need only transparency reporting and a grievance route; high-risk features in health or finance warrant algorithmic auditing, sector certification and impact assessments. Four incentives are recommended to drive uptake: regulatory-sandbox access, public recognition through certifications or ratings, technical assistance and toolkits, and venture capital directed to responsible-AI firms. The strategic point is that baseline voluntary measures may later be converted into mandatory requirements enforceable by sectoral regulators.
Step 7 — Red-team, then report
Red-teaming is treated as a key accountability mechanism. Build a transparency report covering red-teaming results, impact assessments and risk-mitigation steps. Where content is sensitive or proprietary, share it confidentially with the relevant regulator and publish the non-sensitive portions.
Pair it with a grievance mechanism that can actually receive AI-specific harm reports: accessible channels, visible in multiple languages, resolution within a reasonable time, and a loop back into product changes. The accountability set the Guidelines contemplate also includes self-certifications validated by auditors or standards bodies, internal policies updating service terms to reflect commitments, and techno-legal measures built into system design.
Step 8 — Run the sectoral overlay
The general framework is a floor. Check the regulator that owns your sector:
| Sector | Instrument to check |
|---|---|
| Finance | RBI's FREE-AI Committee recommendations (August 2025) — board-approved AI policies, lifecycle governance, vendor oversight, annual review, AI-specific threats such as adversarial attacks and model poisoning inside cyber protocols, tiered incident reporting for AI failures including bias and explainability gaps; SEBI's June 2025 consultation on responsible AI/ML use in securities markets |
| Healthcare | ICMR ethical guidelines for AI in biomedical research and healthcare — bias audits, independent ethics review, data-quality checks, allocation of responsibility between developer and provider |
| Telecom | TEC voluntary standard on fairness assessment and rating; work in progress on robustness rating and on an AI incident database schema |
| Critical infrastructure | CERT-In Directions of 28 April 2022 — six-hour incident reporting, 180-day in-India log retention; NCIIPC framework for critical information infrastructure |
Founder checklist
- Build the AI register first, and make sure it captures vendor-embedded AI — that is where unrecorded risk accumulates.
- Write down the intermediary-or-publisher position for any feature that generates content, before launch, with reasoning.
- Separate the three data pipelines. Training, fine-tuning and inference each need their own DPDP lawful basis; service consent is not training consent.
- Name the human in the loop, or name the circuit breaker. One or the other must exist at every critical decision point, and the choice must be documented.
- Adopt voluntary standards now, on the assumption they become mandatory later — that is the direction the Guidelines signal for sectoral regulators.
Frequently Asked Questions
Q1: Who is accountable when a vendor's model causes the harm?
Contractually and practically, the deploying enterprise remains answerable to its customers and to the regulator that licenses it. The Guidelines identify clear liability regimes across the AI value chain as an item still to be developed, which means the allocation is currently a matter of contract. Push model documentation, validation evidence, bias-testing results and change-notification duties into the procurement agreement rather than assuming a statutory allocation will arrive.
Q2: Is there any mandatory pre-approval or licensing for AI in India?
No. Under the Innovation over Restraint principle, the Guidelines expressly favour no mandatory pre-approval and no blanket bans absent clear evidence of harm, and instruct regulators to prefer the least burdensome instrument — industry codes, then technical standards, then advisories, then binding rules. Sector-specific approvals may still apply where the underlying activity is licensed.
Q3: What is the governance architecture being proposed?
A tiered inter-agency mechanism: an AI Governance Group at the apex, a Technology and Policy Expert Committee advising it, and an AI Safety Institute for technical evaluation, with sectoral regulators and standards bodies operating beneath, plus a national AI incidents database to build the empirical evidence base for a future India-specific risk-assessment framework. These are recommendations; track their constitution rather than assuming they are operational.
Q4: Does deepfake output create criminal exposure?
It can. Beyond the intermediary labelling duties introduced by the February 2026 synthetic-media amendment to the IT Rules 2021, misuse engages Section 66D of the IT Act, 2000 for cheating by personation using a computer resource, and provisions of the Bharatiya Nyaya Sanhita, 2023 including Sections 319(2), 336, 294, 296 and 356(1). The Guidelines acknowledge enforcement gaps in this area rather than an absence of law.
Q5: How does this interact with the RBI model risk guidance?
They operate at different levels. This playbook is the general enterprise clearance workflow under the MeitY Guidelines and adjacent statutes. The RBI draft Guidance on Regulatory Principles for Model Risk Management, on which the comment window closed on 24 July 2026, places AI/ML, generative-AI and third-party models inside a board-level model-governance perimeter for regulated entities. A bank or NBFC runs both; a technology vendor selling into one should expect the RBI expectations to arrive through procurement.
Q6: What should we do about copyright in training data?
Treat it as unresolved and document your position. The Guidelines identify a text-and-data-mining exception under the Copyright Act, 1957 as an open question, with a DPIIT committee constituted in April 2025 deliberating on it. Until there is an authoritative answer, record provenance for training corpora and preserve the ability to demonstrate what was used.
Beyond this brief Preview
Veritect Legal AI holds the full stack a deployment clearance touches: the India AI Governance Guidelines with the seven principles, six-category risk taxonomy and voluntary-measures annexure; the DPDP Act, 2023 with the Schedule and the DPDP Rules, 2025; the IT Act, 2000 and the IT Rules, 2021 through the February 2026 synthetic-media amendment; the BNS, 2023 offence set; and the RBI, SEBI, ICMR, TEC, CERT-In and NCIIPC sectoral instruments.
Practitioner-level content available on Veritect Legal AI:
- AI system register schema with the vendor-embedded population captured
- Risk-triage worksheet mapped to the six categories plus the children and women cross-check
- Intermediary-or-publisher classification memorandum template for generative features
- Per-pipeline DPDP lawful-basis assessment for training, fine-tuning and inference
- Human-oversight design note: review points versus circuit breakers, with documentation standards
- Sectoral overlay checklist across finance, healthcare, telecom and critical infrastructure
Primary Sources
- India AI Governance Guidelines (MeitY / IndiaAI Mission, 5 November 2025): https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf
- PIB — launch announcement: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2186639
- MeitY — AI governance guidelines consultation page: https://www.meity.gov.in/content/report-ai-governance-guidelines-development-public-consultation
- IndiaAI Mission: https://indiaai.gov.in/
- Digital Personal Data Protection Act, 2023 — India Code: https://www.indiacode.nic.in/handle/123456789/20168
- MeitY — Digital Personal Data Protection Rules, 2025: https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa
- Information Technology Act, 2000 — India Code: https://www.indiacode.nic.in/handle/123456789/1999
- Bharatiya Nyaya Sanhita, 2023 — India Code: https://www.indiacode.nic.in/
- CERT-In Directions dated 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf
- Telecom Engineering Centre: https://www.tec.gov.in/
- Reserve Bank of India: https://www.rbi.org.in/