India's AI governance framework as of April 2026 is a multi-layered architecture of voluntary guidelines, sector-specific regulator action, implicit horizontal statutes, and hard enforcement anchors — but no omnibus AI Act. The Ministry of Electronics and Information Technology leads through the IndiaAI Mission's voluntary framework (seven sutras, November 2025), while SEBI, RBI, and IRDAI regulate AI in their respective domains. Three binding instruments — the IT Rules 2021 Synthetic Media Amendment (G.S.R. 120(E), February 2026), the Digital Personal Data Protection Act, 2023, and CERT-In Directions (April 2022) — create enforceable AI obligations today. The newly constituted AI Governance and Economic Group (AIGEG), announced April 2026, is the apex inter-ministerial coordination body. India's path to a standalone AI law runs through the pending Digital India Act, for which no parliamentary introduction date has been set.
TL;DR for founders and practitioners
India's AI governance has three operational realities as of April 2026:
- Binding today: Synthetic-media labelling and three-hour takedown under Rule 3(1)(d) and Rule 3(3) of the IT Rules 2021 (G.S.R. 120(E), effective 20 February 2026); DPDP Act obligations for AI systems that process personal data; CERT-In 6-hour incident-reporting for AI-related cyber incidents.
- Regulatory in progress: SEBI's AI accountability framework for securities markets (sole-accountability principle adopted December 2024; responsible AI/ML guidelines consultation June 2025); RBI FREE-AI Committee framework for banking AI (report published August 2025, implementation expected).
- Horizon watch: AIGEG (inter-ministerial coordination, April 2026); Digital India Act (no parliamentary date yet); DPDP Rules tranche 2 notifications (expected 2026–2027) that may designate AI platforms as Significant Data Fiduciaries.
India's AI Governance Architecture: Four Layers
India's AI governance cannot be read as a single instrument. It is a layered architecture in which each tier performs a distinct function:
| Layer | What It Contains | Legal Form | Who Enforces |
|---|---|---|---|
| Layer 1 — Voluntary horizontal framework | India AI Governance Guidelines (Nov 2025); MeitY AI Advisories (Mar 2024); NITI Aayog Responsible AI Principles (2021) | Advisory; executive guidance; policy documents | No direct enforcement; shapes due-diligence inquiry under Section 79 IT Act |
| Layer 2 — Sector-specific binding rules | SEBI AI/ML circulars (2019, 2024–2025); RBI FREE-AI framework (Aug 2025); IRDAI InsurTech + cybersecurity guidelines | SEBI circulars; RBI directions; IRDAI guidelines | SEBI, RBI, IRDAI respectively under their parent statutes |
| Layer 3 — Implicit horizontal statutes | DPDP Act 2023; IT Act 2000 Sections 67/67A/67B; IT Rules 2021 (Synthetic Media Amendment, G.S.R. 120(E)) | Statute; gazette-notified rules | MeitY; Data Protection Board of India (once constituted); criminal courts |
| Layer 4 — Hard enforcement anchors | CERT-In Directions (28 April 2022) under Section 70B IT Act; Section 69A IT Act blocking; Section 70A Critical Information Infrastructure protection | Directions under statute | CERT-In; NCIIPC; courts |
This four-layer architecture is not accidental. It reflects a deliberate policy choice to regulate AI through existing legal frameworks, sector-specific regulators, and voluntary guidelines rather than through a comprehensive AI statute — at least during the current "nascent ecosystem" phase. The EU AI Act took the opposite path; India explicitly rejected that model.
The architecture has one acknowledged weakness: coordination gaps across the four layers. An AI system that operates across financial services, personal data, and critical infrastructure simultaneously must navigate SEBI, RBI, IRDAI, MeitY, CERT-In, and the Data Protection Board without a single competent authority. The AIGEG was constituted precisely to address this gap.
Layer 1: MeitY/IndiaAI Voluntary Framework
The Advisory Phase (March 2024) and its Course Correction
India's AI-specific governance journey began in earnest with the MeitY Advisory dated 1 March 2024. That Advisory — issued under the supervisory powers MeitY exercises over intermediaries under Section 79 of the Information Technology Act, 2000 ('IT Act') — initially required "explicit permission of the Government of India" before deploying under-tested AI models to Indian users. Industry response was swift and critical; the permission requirement was withdrawn within fourteen days by the revised Advisory of 15 March 2024. What was retained became the policy backbone of the current framework: labelling of unreliable AI output, consent before user interaction, and originator metadata for deepfake content.
The March 2024 Advisory was never a rule. Its legal significance is indirect: non-compliance weakens an intermediary's Section 79(2)(c) IT Act safe-harbour posture by indicating failure of "due diligence." The Advisory has since been absorbed into binding form through Rule 3(1)(d) and Rule 3(3) of the IT Rules 2021, as substituted by the Synthetic Media Amendment Rules, 2026 (G.S.R. 120(E), notified 10 February 2026, effective 20 February 2026).
The India AI Governance Guidelines (November 5, 2025)
The India AI Governance Guidelines, released by MeitY under the IndiaAI Mission on 5 November 2025, mark the most substantive articulation of India's AI governance philosophy to date. They were drafted by a committee chaired by Prof. Balaraman Ravindran (IIT Madras), constituted by MeitY in July 2025 after receipt of more than 2,500 public submissions. The Guidelines were released at the India AI Impact Summit 2026, held at Bharat Mandapam, New Delhi on 16–21 February 2026, where India hosted heads of state from more than 100 countries.
The Guidelines are structured across four parts:
- Seven guiding sutras — the principled core, adapted from the RBI FREE-AI Committee report (August 2025): Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; Safety, Resilience and Sustainability.
- Issues and recommendations — covering data management, algorithmic transparency, risk classification, responsible generative AI use, safety testing, and grievance redressal.
- Action plan — short, medium, and long-term phased roadmap.
- Practical guidelines for industry and regulators — directed at "any person involved in developing or deploying AI systems in India", including foreign entities.
Three structural conclusions follow from the Guidelines for practitioners:
First, no pre-approval requirement. The Guidelines explicitly reject mandatory pre-approval for AI models. This is a direct reversal of the 1 March 2024 Advisory position.
Second, voluntary-to-mandatory pathway. The Guidelines state that voluntary measures may be converted into mandatory baseline requirements enforced by sectoral regulators as the ecosystem matures. MeitY is expected to publish a schedule for this conversion within 9–12 months of the Guidelines' release — meaning by approximately November 2026.
Third, existing law is sufficient — for now. The Guidelines' position, endorsed by the drafting committee, is that a separate AI law is not needed at this stage. AI harms can be governed through the IT Act, DPDP Act, BNS 2023, and Consumer Protection Act 2019.
The AIGEG — New Apex Coordination Body (April 2026)
In April 2026, the Government of India constituted the AI Governance and Economic Group (AIGEG), described as the "apex inter-ministerial body" for AI governance policy development and coordination. The AIGEG gives institutional effect to the "whole-of-government" recommendation in the India AI Governance Guidelines and the Economic Survey 2026. It is supported by the Technology and Policy Expert Committee (TPEC), chaired by the Secretary of MeitY, which provides expert advisory on global AI developments, emerging technologies, risks, and regulation.
The significance of the AIGEG is architectural rather than immediately operational: it creates, for the first time, a formal inter-ministerial coordination mechanism whose mandate spans all four layers of the AI governance architecture.
IndiaAI Mission Infrastructure Context
The IndiaAI Mission, approved by the Union Cabinet on 7 March 2024 (PIB PRID 2012355) with an outlay of Rs. 10,371.92 crore over five years, provides the institutional infrastructure for voluntary AI governance. As of the India AI Impact Summit 2026 (February 2026), the Mission's compute facility had more than 38,000 GPUs available at subsidised rates under Rs. 100 per hour, with an additional 20,000 GPUs announced at the Summit. AIKosh carries 1,500+ datasets. The IndiaAI Safety Institute (AISI), announced 30 January 2025 under the Safe and Trusted AI pillar, is the research-and-standards body tasked with AI safety evaluation methodologies; it is not the regulator.
Layer 2: Sector Regulators — SEBI, RBI, IRDAI
The sector-regulator layer is where AI governance has moved furthest from advisory toward binding obligation. Three regulators have distinct and increasingly concrete frameworks.
SEBI — AI/ML Governance in Securities Markets
SEBI has the most developed AI regulatory architecture of India's three principal financial regulators. Its progression:
2019 — Reporting mandates. SEBI issued three circulars requiring Market Infrastructure Institutions (MIIs), market intermediaries, and mutual funds to report AI/ML applications in use. These are the earliest binding AI-specific obligations in the Indian financial sector.
November 2024 — Accountability consultation. SEBI released a consultation paper proposing amendments to assign responsibility for AI tool usage. The core principle: a SEBI-regulated entity is solely accountable for AI outcomes, regardless of whether the AI tool was built internally or procured from a third-party vendor. This "sole accountability" principle is a materially higher standard than most AI governance frameworks impose, because it forecloses any "the vendor is responsible" defence.
December 2024 — Board adoption. The SEBI Board adopted the accountability framework at its December 2024 meeting, moving toward codification in the Securities and Exchange Board of India (Intermediaries) Regulations, 2008. The Regulations were last amended on 5 December 2024 in this context.
June 2025 — Responsible AI/ML guidelines consultation. SEBI released a consultation paper on guidelines for responsible usage of AI/ML across Indian securities markets. This paper is expected to produce comprehensive AI governance requirements covering model risk management, algorithmic transparency, bias detection, and investor protection obligations. As of April 2026, the consultation paper is pending finalisation as binding guidelines.
SEBI's AI governance interacts with the broader Cybersecurity and Cyber Resilience Framework (CSCRF), notified in August 2024, which covers AI-related cyber risks for SEBI-regulated entities and was technically clarified in August 2025. The CSCRF includes obligations under Section 70B of the IT Act relating to CERT-In reporting that apply to SEBI-regulated entities deploying AI systems that constitute Critical Information Infrastructure.
RBI — FREE-AI Framework for Banking
The Reserve Bank of India moved from AI-inclusive monetary-policy thinking to dedicated AI risk governance through the FREE-AI Committee. Constituted pursuant to the Statement on Developmental and Regulatory Policies of 6 December 2024, the Committee for Developing a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector ('FREE-AI Committee') was tasked with producing a framework to govern AI in high-stakes banking applications — credit approvals, fraud detection, compliance, and risk modelling.
The FREE-AI Committee's report was published on 13 August 2025. Its seven sutras — Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; Safety, Resilience and Sustainability — were subsequently adapted by the India AI Governance Guidelines (November 2025), making the RBI framework the intellectual ancestor of India's national AI governance architecture.
For banks and non-banking financial companies under RBI supervision, the FREE-AI framework's recommendations represent the anticipated direction of RBI circulars and master directions on AI deployment. Key themes include model risk management for credit AI, algorithmic transparency requirements for automated lending decisions, bias testing across demographic categories, and human-oversight mandates for high-stakes AI outputs. Implementation guidance in the form of RBI circulars is expected over 2026–2027.
IRDAI — Insurance AI Governance
IRDAI has not yet issued a standalone AI-specific guideline as of April 2026. However, three instruments create implicit AI governance obligations for insurers:
First, the IRDAI (Regulatory Sandbox) Regulations, 2025 — providing a controlled testing framework for AI-driven InsurTech solutions. Insurers piloting AI underwriting, AI claims processing, or AI fraud detection models must operate within the Sandbox framework.
Second, the IRDAI Information and Cybersecurity Guidelines, 2026 — released in early 2026, these guidelines address AI-related cybersecurity risks in insurance operations, including third-party AI vendor risk management.
Third, the Insurance Fraud Monitoring Framework Guidelines, 2025 — directly AI-relevant because fraud detection in insurance is predominantly AI-driven. The Guidelines create obligations on insurers to operate fraud monitoring systems meeting regulatory standards.
The Sabka Bima Sabki Raksha (Amendment of Insurance Laws) Act, 2025 aligned insurance data handling with the DPDP Act 2023, creating an indirect AI governance obligation: AI systems that process personal data of policyholders are now subject to DPDP Act consent and accuracy standards enforced through the insurance regulatory channel.
Veritect Legal AI — India AI Governance Intelligence This article is a 20–30% preview of Veritect's full analysis of India's AI governance framework. The Veritect Legal AI corpus contains the complete SEBI AI/ML guidelines consultation paper analysis (June 2025), verbatim FREE-AI Committee report recommendations mapped to RBI's existing Master Directions, the IRDAI Regulatory Sandbox compliance playbook for AI-driven InsurTech, CERT-In's AI-specific incident classification guidance, and the complete AIGEG institutional framework with TPEC composition. Also in corpus: sector-by-sector compliance checklists for AI deployments in healthcare (CDSCO + ICMR), education (UGC + Section 9 DPDP), and government procurement (GFR 2017 AI procurement rules). Access Veritect Legal AI →
Layer 3: Implicit Horizontal Laws
The third layer consists of statutes not enacted specifically for AI but which impose binding obligations on AI systems as a consequence of their design. Three instruments are central.
The DPDP Act 2023 as Implicit AI Governance
The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023, Gazette CG-DL-E-12082023-248045) is the single most consequential implicit AI governance statute in India. It applies wherever an AI system processes "personal data" — defined in Section 2(t) as any data about an individual who is identifiable by or in relation to that data.
Five DPDP obligations directly govern AI deployments:
Section 6 — Consent. AI systems that collect or process personal data must obtain specific, informed, and voluntary consent from the data principal before processing. Blanket consent at sign-up is insufficient where AI applies data to purposes the user could not have anticipated. The DPDP Rules 2025 (G.S.R. 846(E), November 2025) prescribe consent notice standards.
Section 8(4) — Accuracy. Data fiduciaries must ensure the accuracy of personal data they process. AI systems making automated decisions — credit scoring, risk classification, medical triage, hiring — that rely on inaccurate personal data violate this obligation. Monetary penalties for breach reach Rs. 150 crore per instance under the Schedule to the DPDP Act.
Section 8(5) — Security safeguards. Reasonable security practices must be implemented for personal data in AI systems. For an AI system, "reasonable security" means at minimum: access controls on training data, model output logging, and incident detection — aligned with CERT-In Directions under Section 70B of the IT Act.
Section 8(7) — No unlawful use. Personal data may not be used for any purpose other than those for which it was collected and for which consent was obtained. An AI model fine-tuned on user data for "product improvement" and then deployed for targeted profiling or political advertising is in breach.
Section 9 — Children's data. AI systems targeting users under 18 must obtain verifiable parental consent, must not track children, and must not serve behavioural advertising to children. This is directly applicable to recommendation engines, AI-driven gaming, and educational AI products.
Significant Data Fiduciary (SDF) designation under Section 10 adds a further layer: SDFs must conduct periodic Data Protection Impact Assessments covering AI systems, submit to periodic audits, and appoint a Data Protection Officer. The Central Government's SDF notifications under the DPDP Rules 2025 are expected in tranches through 2026–2027 and may designate major AI platforms serving Indian users.
IT Act Sections 67, 67A, 67B — AI-Generated Content Liability
Sections 67, 67A, and 67B of the Information Technology Act, 2000 ('IT Act') create criminal liability for publishing obscene, sexually explicit, and child sexual abuse material transmitted through electronic media. These provisions apply to AI-generated content as well as human-created content. An AI image-generation product that outputs non-consensual intimate imagery or child sexual abuse material engages Section 67A and Section 67B respectively, with penalties of up to five years' imprisonment and Rs. 10 lakh fine under Section 67A, and up to seven years' imprisonment under Section 67B.
The IT Rules 2021 Synthetic Media Amendment (G.S.R. 120(E), 10 February 2026) operationalises the IT Act's content provisions in the AI context. Rule 3(1)(d) as amended requires intermediaries to remove within three hours any content notified as illegal under Rule 3(1)(b) categories — which include obscene content, content that violates privacy, and content that impersonates a person. Rule 3(3) requires visible labelling and machine-readable provenance metadata on synthetically generated audio, video, and audio-visual content. Non-compliance triggers loss of Section 79 IT Act safe harbour, converting the intermediary from a neutral carrier into a primary obligor.
Deepfake Liability Under BNS 2023
The Bharatiya Nyaya Sanhita, 2023 ('BNS 2023') — which replaced the Indian Penal Code, 1860 — contains provisions that reach AI-generated deepfake content:
- Section 319(2) BNS 2023 — cheating by personation: using AI to impersonate another person for fraudulent purposes attracts imprisonment of up to five years and fine.
- Section 316(3) BNS 2023 — criminal breach of trust: an AI platform that processes personal data of users in breach of its fiduciary duty may attract this provision.
- Section 356(3) BNS 2023 — defamation: AI-generated content that makes a false statement about a person to harm their reputation is actionable.
The combination of BNS 2023 criminal liability, Section 67A IT Act obscenity provisions, Rule 3(1)(d) three-hour takedown obligation, and DPDP Act personal-data obligations creates a comprehensive legal exposure stack for AI content platforms operating in India.
PROG Act 2025 — AI in Online Gaming
The Online Gaming (Protection and Regulation) Act, 2025 (Act 32 of 2025, 'PROG Act 2025') establishes a dedicated regulatory framework for online gaming, including AI-driven games. The Act creates the Online Gaming Authority of India (OGAI), which has the power to prescribe technical standards for AI-driven game mechanics, including algorithmic transparency obligations for pay-to-win mechanics and loot boxes.
The Missing Piece: Why India Has Not Enacted an AI Act
India's decision not to enact an omnibus AI Act is deliberate and argued on five grounds in the India AI Governance Guidelines.
First, existing law is sufficient. The IT Act, DPDP Act, BNS 2023, and Consumer Protection Act 2019 together cover the principal categories of AI harm — misinformation, deepfakes, bias-driven discrimination, privacy violations, and fraud. India does not currently identify an "enforcement gap" that would require new primary legislation.
Second, the ecosystem is nascent. The India AI Governance Guidelines frame India as having a "nascent AI ecosystem" in which heavy mandatory regulation risks stifling the infrastructure being built — the 38,000+ GPU compute base, the foundation model startups, the IndiaAI Safety Institute research programme. The EU AI Act's compliance cost (estimated at EUR 6,000 to EUR 7,500 per high-risk AI system for conformity assessment alone) is viewed as prohibitive at India's current AI development stage.
Third, sectoral regulation is more efficient. AI in banking is most efficiently regulated by the RBI, which understands the financial-stability risk. AI in securities is most efficiently regulated by SEBI. An omnibus AI Act would create jurisdictional overlap or require an entirely new AI regulator, neither of which India is currently willing to do.
Fourth, international comparison. India notes that its approach aligns with Japan's Act on the Promotion of AI-Related Technologies (May 2025), which similarly avoids mandatory pre-approval and relies on voluntary standards plus existing law. Both India and Japan position themselves as counterweights to the EU's prescriptive model, and both are significant Global South or middle-power voices in the AI governance debate.
Fifth, the Digital India Act as the eventual vehicle. MeitY has signalled that the Digital India Act — which will replace the IT Act, consolidate intermediary and AI obligations, and update India's digital law for the 2020s — is the appropriate legislative vehicle for any AI-specific mandatory requirements. The DIA has not been introduced in Parliament as at April 2026. MeitY continues to legislate AI obligations through IT Rules amendments, most recently the Synthetic Media Amendment (February 2026) and a further amendment circulated for public consultation in March 2026.
The EU AI Act comparison is instructive precisely for what India is not doing. The EU AI Act prohibits certain AI applications entirely (social scoring, real-time biometric identification in public spaces) and requires conformity assessment for high-risk AI (healthcare, critical infrastructure, law enforcement). India has no equivalent prohibitions and no mandatory conformity assessment regime. The closest India comes to the EU's "unacceptable risk" category is the IT Rules 2021 prohibition on generating content that violates Rule 3(1)(b) — but this applies to all digital content, not specifically to AI.
AI Safety and High-Risk Systems
India AI Safety Institute
The IndiaAI Safety Institute (AISI), announced by the Minister for Electronics and Information Technology on 30 January 2025 under the Safe and Trusted AI pillar of the IndiaAI Mission, is India's designated AI safety research and evaluation body. It operates on a hub-and-spoke model, engaging academia, startups, industry, and line ministries. Its mandate covers AI safety research, evaluation methodologies calibrated to Indian datasets and languages, responsible-AI framework development, and sector-specific risk assessment.
The AISI is not a regulator. It does not have the power to approve, prohibit, or impose conditions on AI systems. Its outputs — testing protocols, self-assessment checklists, risk taxonomies — operate as recommended practice. They become binding only when adopted by MeitY in an advisory or incorporated into IT Rules, or when adopted by a sectoral regulator such as SEBI, RBI, or IRDAI in a circular.
The India AI Governance Guidelines recommend that the AISI maintain a register of high-risk AI categories and publish sector-specific guidance on safety testing methodologies. Expected deliverables over 2026–2027 include: a model-card standard for Indian AI systems, an AI Use-Case Risk Assessment Matrix tailored to Indian social and linguistic contexts, and an audit methodology for bias detection in Hindi, Tamil, Bengali, Telugu, and other Scheduled Eighth languages.
The CII-AI Intersection: Section 70A IT Act
Section 70A of the Information Technology Act, 2000 empowers the Central Government to declare any computer resource, data, database, or communication infrastructure as Critical Information Infrastructure ('CII'). Disruption of CII attracts imprisonment of up to ten years under Section 70(3) IT Act. The National Critical Information Infrastructure Protection Centre (NCIIPC), established under Section 70A, is the designated agency for CII protection.
As AI systems are progressively embedded in CII sectors — electricity grid management, aviation control systems, banking core infrastructure, railway signalling — they become subject to the CII framework. An AI system embedded in a power grid, for instance, is not merely subject to the general IT Act safe-harbour regime; its security vulnerabilities can trigger Section 70(3) criminal liability if disruption results.
CERT-In's Directions of 28 April 2022 under Section 70B IT Act add a parallel cyber-incident reporting layer: any cyber incident involving an AI system that constitutes or supports CII must be reported to CERT-In within 6 hours of detection. ICT logs must be retained for 180 days. These obligations apply regardless of whether the AI system is itself the target or merely the vector.
What's Coming in H2 2026
India's AI regulatory pipeline for the second half of 2026 has four identifiable workstreams:
1. AIGEG operational framework. The AI Governance and Economic Group, constituted in April 2026, is expected to publish its first policy positions and cross-sectoral coordination protocols in H2 2026. The TPEC's advisory outputs will shape the AIGEG's initial work programme, likely including a master circular mapping applicable regulations to AI use cases — a deliverable the India AI Governance Guidelines recommended within 9–12 months of November 2025.
2. SEBI AI/ML guidelines finalisation. The June 2025 consultation paper on responsible usage of AI/ML in Indian securities markets is expected to produce binding SEBI guidelines in H2 2026. The guidelines are likely to address: model risk management obligations for algorithmic trading; AI accountability requirements for investment advisers and portfolio managers; bias testing mandates for AI-driven credit and investment products; and human-oversight requirements for automated order-routing systems.
3. DPDP Rules tranche 2 — SDF designations. The DPDP Rules 2025 (G.S.R. 846(E)) are Tranche 1 of India's data-protection delegated framework. The Central Government is expected to issue further notifications under Section 10 of the DPDP Act designating Significant Data Fiduciaries. Major AI platforms serving Indian users — including large-scale generative AI products, recommendation-engine platforms, and AI-driven social media services — are candidates for SDF designation. SDF status triggers additional obligations: Data Protection Impact Assessments, periodic algorithmic audits, and annual filings with the Data Protection Board of India.
4. MeitY IT Rules second amendment. MeitY circulated draft amendments to the IT Rules 2021 for public consultation in March 2026, signalling a further round of rule-making on intermediary obligations. The expected scope includes updates to Rule 3(3) provenance metadata standards (C2PA alignment) and clarification of the Rule 3(1)(d) three-hour takedown SLA for AI-generated content discovery.
The Digital India Act remains the horizon instrument — consolidating AI, intermediary, and harm-based obligations in a single statute — but with no parliamentary introduction date, it is not the near-term operational focus for compliance planning.
Compliance Matrix for AI Deployments
The following matrix maps the most common AI deployment types to the applicable Indian regulatory instruments as of April 2026:
| AI Use Case | Applicable Regulation | Key Obligation | Regulator | Status |
|---|---|---|---|---|
| Generative AI / LLM platform serving Indian users | IT Rules 2021, Rule 3(3) (G.S.R. 120(E)) | Visible label + machine-readable provenance metadata on synthetic output; three-hour takedown | MeitY | Binding from 20 Feb 2026 |
| AI model trained on or processing personal data | DPDP Act 2023, Sections 6, 8(4), 8(5), 8(7) | Specific consent; accuracy; security safeguards; no-unlawful-use | Data Protection Board of India | Binding (Act in force; Rules from Nov 2025) |
| AI recommendation / personalisation engine for children | DPDP Act 2023, Section 9 | Verifiable parental consent; no tracking; no targeted advertising | Data Protection Board of India | Binding |
| Algorithmic trading / robo-advisory / AI credit scoring (SEBI-regulated) | SEBI AI/ML circulars (2019); SEBI Intermediaries Regulations (Dec 2024 amendment); SEBI CSCRF (Aug 2024) | Reporting; sole accountability for AI tool outcomes; cyber-resilience | SEBI | Reporting binding; responsible AI guidelines pending |
| AI in banking / NBFC (credit, fraud detection, KYC) | RBI FREE-AI Framework (Aug 2025); RBI Master Directions on IT | Model risk management; human oversight expectations | RBI | FREE-AI implementation guidance expected 2026–2027 |
| AI in insurance (underwriting, claims, fraud) | IRDAI Regulatory Sandbox Regs 2025; IRDAI Cybersecurity Guidelines 2026; Insurance Act 1938 | Sandbox compliance for novel AI; vendor risk management | IRDAI | Binding for sandbox; general guidelines pending |
| Deepfake / synthetic media generation | IT Rules 2021 Rule 3(1)(d) + Rule 3(3); BNS 2023 Sections 319(2), 356(3); IT Act Sections 67A, 67B | Takedown (3 hrs); labelling; metadata; criminal liability for CSAM / non-consensual intimate imagery | MeitY; criminal courts | Binding from 20 Feb 2026 |
| AI in online gaming | PROG Act 2025; IT Rules 2021 | Algorithmic transparency for pay-to-win/loot box mechanics; content compliance | OGAI | Binding under PROG Act 2025 |
| AI for Critical Information Infrastructure | IT Act Section 70A; CERT-In Directions (28 April 2022) | 6-hour incident reporting; 180-day log retention | CERT-In; NCIIPC | Binding |
Veritect Legal AI — India AI Governance Intelligence The Veritect Legal AI corpus contains the complete practitioner-depth analysis of India's AI governance framework: verbatim MeitY advisory text mapped to IT Rules 2021 obligations; SEBI AI/ML circular archive (2019 to present) with implementation checklists for algorithmic trading and robo-advisory; RBI FREE-AI Committee full-report analysis with RBI Master Direction cross-mapping; DPDP Act Sections 6–10 annotated for AI use cases with penalty exposure tables (per-breach maxima from Rs. 50 crore to Rs. 250 crore); CERT-In AI-incident classification guide; and the India AI Governance Guidelines full-text analysis including Part 3 action-plan timeline and Part 4 industry obligations. Access Veritect Legal AI →
Frequently Asked Questions
Does India have an AI Act as of April 2026? No. India has not enacted an omnibus AI Act. The India AI Governance Guidelines (MeitY/IndiaAI Mission, 5 November 2025) are explicitly advisory and voluntary. India's stated position is that existing laws — the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, the Bharatiya Nyaya Sanhita, 2023, and the Consumer Protection Act, 2019 — are sufficient to govern current AI risks. An AI-specific chapter may arrive through the pending Digital India Act, which has not yet been introduced in Parliament as at April 2026.
Which regulator is responsible for AI governance in India? There is no single AI regulator. MeitY is the nodal ministry under the Information Technology Act, 2000 and the DPDP Act 2023. The newly constituted AI Governance and Economic Group (AIGEG), announced in April 2026, serves as the apex inter-ministerial coordination body. Sectoral regulators retain domain-specific authority: SEBI governs AI/ML in securities markets, RBI has the FREE-AI Committee framework for banking AI, IRDAI oversees AI in insurance, and CERT-In handles AI-related cybersecurity incident reporting.
What are the binding AI obligations on intermediaries in India today? Three binding layers apply as of April 2026. First, Rule 3(1)(d) and Rule 3(3) of the IT Rules 2021, as substituted by the Synthetic Media Amendment Rules, 2026 (G.S.R. 120(E), notified 10 February 2026, effective 20 February 2026): three-hour takedown for illegal content, visible labelling of AI-generated content, and machine-readable provenance metadata on synthetic output. Second, Section 70B IT Act read with CERT-In Directions of 28 April 2022: 6-hour cyber-incident reporting and 180-day log retention. Third, the Digital Personal Data Protection Act, 2023: consent, accuracy, and no-unlawful-use obligations apply wherever an AI system processes personal data.
How does the DPDP Act 2023 regulate AI systems? The Digital Personal Data Protection Act, 2023 applies to every AI system that processes personal data within the meaning of Section 2(t) — any data about an individual who is identifiable by or in relation to that data. Key obligations: Section 6 requires specific, informed, voluntary consent; Section 8(5) mandates reasonable security safeguards and accuracy; Section 8(7) prohibits use beyond consented purposes; Section 9 restricts processing of children's data to verifiable parental consent and prohibits tracking or targeting. Penalties for breach reach Rs. 250 crore per instance under the Schedule to the Act.
What is SEBI's current approach to AI in securities markets? SEBI has followed a three-stage progression. In January and May 2019, SEBI issued reporting circulars for AI/ML applications across Market Infrastructure Institutions, market intermediaries, and mutual funds. In November 2024, SEBI released a consultation paper on assigning responsibility for AI tools, with the core principle that SEBI-regulated entities are solely accountable for AI outcomes even when tools are procured from third parties — adopted at the SEBI Board meeting in December 2024. In June 2025, SEBI released a consultation paper on responsible AI/ML guidelines across Indian securities markets, expected to produce binding obligations in H2 2026.
What is the RBI FREE-AI Committee and what does it recommend? The RBI constituted the FREE-AI Committee — Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector — pursuant to its Statement on Developmental and Regulatory Policies of 6 December 2024. The Committee's report, published on 13 August 2025, articulated seven sutras for responsible AI in finance that were subsequently adapted by the India AI Governance Guidelines. Key themes include model risk management for credit AI, algorithmic transparency for automated lending decisions, bias testing, and human-oversight mandates for high-stakes AI outputs.
When will the Digital India Act be enacted, and what will it say about AI? The Digital India Act, which MeitY has signalled will replace the Information Technology Act, 2000 and consolidate AI, intermediary, and harm-based obligations, has not yet been introduced in Parliament as at April 2026. MeitY continues to legislate AI obligations through IT Rules 2021 amendments. The IndiaAI Safety Institute's governance outputs and the AIGEG's policy recommendations are expected to inform the DIA's AI chapter when eventually tabled. Compliance planning should be calibrated to the current IT Rules 2021 + DPDP Act framework, not to the anticipated DIA.
How does India's approach compare with the EU AI Act? The EU AI Act (Regulation (EU) 2024/1689, in force 1 August 2024) imposes mandatory risk-tiered requirements: prohibited AI, high-risk AI requiring conformity assessment, limited-risk transparency obligations, and minimal-risk voluntary measures. India's approach is structurally different: no mandatory risk classification, no pre-approval requirements, and voluntary guidelines as the primary framework. India's philosophy is "responsible innovation over cautionary restraint". The closest international analogue is Japan's Act on the Promotion of AI-Related Technologies (May 2025), which similarly emphasises voluntary compliance and existing-law application rather than a prescriptive new statute.
Primary Sources
- Ministry of Electronics and Information Technology / IndiaAI Mission — India AI Governance Guidelines (5 November 2025): https://www.pib.gov.in/PressReleasePage.aspx?PRID=2186639
- India AI Governance Guidelines — Full Document PDF: https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf
- IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 — Synthetic Media Amendment (G.S.R. 120(E), notified 10 February 2026, effective 20 February 2026): https://www.meity.gov.in/
- Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) — India Code: https://www.indiacode.nic.in/handle/123456789/2002
- Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E), 13 November 2025 — PIB: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
- RBI FREE-AI Committee Report (13 August 2025): https://rbidocs.rbi.org.in/rdocs/PublicationReport/Pdfs/FREEAIR130820250A24FF2D4578453F824C72ED9F5D5851.PDF
- SEBI — Consultation Paper on Guidelines for Responsible Usage of AI/ML in Indian Securities Markets (20 June 2025): https://www.sebi.gov.in/reports-and-statistics/reports/jun-2025/consultation-paper-on-guidelines-for-responsible-usage-of-ai-ml-in-indian-securities-markets_94687.html
- SEBI — Proposed amendments on AI tool responsibility (November 2024): https://www.sebi.gov.in/reports-and-statistics/reports/nov-2024/proposed-amendments-with-respect-to-assigning-responsibility-for-the-use-of-artificial-intelligence-tools-by-market-infrastructure-institutions-registered-intermediaries-and-other-persons-regulated-b-_88470.html
- SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF), August 2024: https://www.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
- Government of India Constitutes AIGEG — IndiaAI (April 2026): https://indiaai.gov.in/article/government-of-india-constitutes-ai-governance-and-economic-group-aigeg-to-steer-national-ai-policy
- PIB — AIGEG constitution (April 2026): https://www.pib.gov.in/PressReleasePage.aspx?PRID=2252739
- IndiaAI Mission — Cabinet Approval, PIB PRID 2012355 (7 March 2024): https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2012355
- India AI Impact Summit 2026 — Declaration and Major Outcomes (21 February 2026): https://www.pib.gov.in/PressReleasePage.aspx?PRID=2234343
- IndiaAI Safety Institute — Announcement (30 January 2025): https://indiaai.gov.in/news/meity-hosts-consultation-for-establishing-india-ai-safety-institute-under-indiaai-mission-s-safe-and-trusted-pillar
- CERT-In Directions under Section 70B IT Act (28 April 2022): https://www.cert-in.org.in/
- NITI Aayog — Responsible AI for All Approach Document, Part 1 (25 February 2021): https://www.niti.gov.in/sites/default/files/2021-02/Responsible-AI-22022021.pdf
- Information Technology Act, 2000 — India Code: https://www.indiacode.nic.in/bitstream/123456789/1999/3/A2000-21.pdf
- IRDAI (Regulatory Sandbox) Regulations, 2025: https://irdai.gov.in/document-detail?documentId=6541188
This deep-dive is part of Veritect's Digital, Data & AI Law vertical. It is an original analysis prepared from Tier 1 government and regulator sources — MeitY, IndiaAI, PIB, RBI, SEBI, IRDAI, CERT-In, IndiaCode — and does not reproduce or paraphrase any third-party commentary. All statutory citations are to current-in-force instruments; the DPDP Act and Rules are cited as of their notified effective dates.