How India Regulates Artificial Intelligence Without an AI Act
- Abhinav Goyal

- 6 hours ago
- 10 min read
India regulates artificial intelligence under existing technology and data-protection law, sectoral regulation and the general law applicable to the activity. The requirements for a particular system depend on what it does, the company's legal role, the data involved and the sector in which it is used.

An artificial intelligence ('AI') product can place the same company in more than one legal role. A developer may act as an intermediary for hosted user material, as a data fiduciary where it determines why and how account or usage data is processed, and as a technology vendor when supplying a system to a regulated business.
The applicable legal regime is identified from the activity carried out through the feature. The Information Technology Act, 2000 ('IT Act') and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ('IT Rules') govern intermediary functions and specified online content. Section 43A of the IT Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ('SPDI Rules') continue to govern specified personal-data processing during the transition to the Digital Personal Data Protection Act, 2023 ('DPDP Act'). Sector-specific requirements apply when the system is used in a regulated activity.
Government guidelines and advisories can inform governance design, but their legal effect depends on the authority under which each instrument is issued. The India AI Governance Guidelines ('Guidelines') and the March 2024 advisory issued by the Ministry of Electronics and Information Technology ('MeitY') are therefore addressed separately from the statutes and notified rules discussed below.
At a July 2026 industry event, MeitY Secretary S. Krishnan said that the Government intended to begin stakeholder consultations on a separate legal framework for AI.
How existing Indian law applies to AI systems
Product classification should be carried out feature by feature and recorded against the applicable legal trigger.
A service that receives, stores or transmits electronic records on another person's behalf, or provides a service in relation to those records, may perform an intermediary function under the IT Act. The classification is based on the particular records and the function performed for the other person.
A service that enables the creation, publication or distribution of realistic synthetic audio, images or video may also attract the synthetically generated information ('SGI') provisions introduced into the IT Rules in February 2026. Their scope depends on the notified definition and the service's role in creating, altering, publishing or disseminating the material.
For digital personal data, the analysis must identify who determines the purpose and means of processing. That classification informs both the present SPDI analysis and the DPDP duties that will apply when the relevant provisions commence.
Use in banking, securities, insurance, telecommunications, healthcare or another regulated activity requires a separate review of the applicable sectoral requirements. The review should also identify which responsibilities remain with the regulated entity and which are allocated contractually to a vendor.
The legal analysis also covers the underlying content, decision or transaction under consumer protection, contract, intellectual-property, criminal and civil law.
Legal issues arising from common AI activities
The table below summarises the first legal issue raised by several common product activities:
Product activity | First legal issue to examine | Scope |
Hosting, transmitting or providing a service in relation to third-party electronic records | IT Act intermediary definition and IT Rules due diligence | Intermediary status attaches to the relevant function and records |
Enabling realistic synthetic audio, images or video | IT Rules on synthetically generated information | Labelling and provenance duties apply within the notified SGI definition |
Using identifiable individuals' data for training, testing, personalisation or decisions | Present IT Act/SPDI regime and the staged DPDP framework | The applicable duties depend on commencement, role, purpose and data |
Supplying AI to a regulated business | Relevant regulator's directions, circulars and outsourcing or governance requirements | Responsibility is allocated between the regulated entity and its vendor under the applicable framework and contract |
Creating or using protected content, a person's likeness or misleading commercial material | Copyright, personality rights, consumer and other applicable law | Intermediary compliance and the legality of the underlying material are separate questions |
Intermediary status of AI services
Section 2(1)(w) of the IT Act defines an intermediary, in relation to particular electronic records, as a person who receives, stores or transmits the record on behalf of another person or provides a service with respect to it. The definition includes internet service providers, web-hosting providers, search engines, online marketplaces and online payment sites, among other categories.
Section 2(1)(w) must be applied to the particular records and service under review. An AI business may perform an intermediary function when it hosts or transmits user material on another person's behalf. Content created or controlled by the provider requires a separate assessment.
Section 79 provides a conditional exemption from liability for third-party information. The conditions in section 79(2) address the intermediary's role in the transmission and its compliance with prescribed due diligence. Section 79(3) identifies circumstances in which the protection is unavailable, including participation in the unlawful act and failure to act following legally recognised actual knowledge.
The current consolidated IT Rules prescribe intermediary due diligence. Among other requirements, intermediaries must publish applicable rules, privacy policies and user agreements; inform users about prohibited information; maintain a grievance mechanism; cooperate with lawfully authorised requests; preserve specified records; and comply with valid removal directions and prescribed complaint timelines. Significant social media intermediaries are subject to additional personnel, reporting and technical requirements.
Relevant facts include the source of the input, who decides whether the material is published, the extent to which the provider shapes the record and whether the disputed material is third-party information. A provider's role may therefore differ between, for example, a user-upload feature and content generated or curated by the provider.
Amendments to the IT Rules in 2025 and 2026
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025 ('October 2025 Amendment Rules') revised rule 3(1)(d), which governs legally recognised actual knowledge of unlawful information. It specified two routes: an order of a competent court, or a reasoned written intimation from a properly authorised senior government officer. A government intimation must identify the legal basis, the unlawful act and the specific electronic location to be removed or disabled. The October 2025 Amendment Rules also introduced periodic senior-level review of such intimations and took effect on 15 November 2025.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 ('February 2026 Amendment Rules'), read with the 26 February 2026 corrigendum, reduced the response period under rule 3(1)(d) from 36 hours to three hours. They also reduced the complaint period for specified intimate or impersonation material from 24 hours to two hours and amended other grievance timelines. These periods apply after the court order, authorised government intimation or qualifying complaint specified in the IT Rules.
The February 2026 Amendment Rules also introduced notified provisions for SGI. They define SGI as artificially or algorithmically created or altered audio, visual or audio-visual information that appears real, authentic or true and depicts an individual or event in a manner that is, or is likely to be perceived as, indistinguishable from a natural person or real-world event.
The definition is directed to realistic synthetic media. Text generated by an AI system falls outside the SGI definition on that basis alone. The definition also contains exclusions for specified routine or good-faith editing and for certain document, educational, training, research and accessibility uses, subject to the stated conditions.
The amendments allocate SGI obligations according to the service provided:
An intermediary offering a computer resource that may enable or facilitate the creation, alteration, publication or dissemination of SGI must deploy reasonable and appropriate technical measures to prevent users from creating or distributing SGI that violates the law, including the categories specified in rule 3(3).
Other SGI within rule 3(3) must carry a prominent and noticeable visual label or a prominently prefixed audio disclosure. To the extent technically feasible, it must also contain permanent metadata or another provenance mechanism, including a unique identifier capable of identifying the intermediary's computer resource used to create or alter it. The design of the resource must preserve the label and provenance marker.
A significant social media intermediary that enables users to display, upload or publish information must obtain a pre-publication declaration on whether the information is SGI, use appropriate technical measures to verify the declaration and label confirmed SGI. The standard is one of reasonable and proportionate steps, which requires the intermediary to use both the declaration and the prescribed technical measures.
The February 2026 Amendment Rules came into force on 20 February 2026. In April 2026, MeitY published a further set of draft amendments to the IT Rules proposing, among other matters, continuous visual labels and the incorporation of specified MeitY clarifications, advisories and guidelines into intermediary due diligence. As at 16 August 2026, those draft amendments remain under consultation, while the notified IT Rules continue to govern.
Application of the DPDP Act to algorithmic processing
The DPDP Act applies to the processing of digital personal data. For an AI system, the principal questions are whether personal data is processed, who determines the purpose and means of processing, and whether the relevant application or exemption provisions apply.
Once section 3 commences, the DPDP Act will cover digital personal data processed in India where the data was collected digitally or collected non-digitally and digitised later. It will also cover processing outside India where that processing relates to offering goods or services to individuals in India. Section 3(c) excludes personal or domestic processing and personal data made publicly available by the individual concerned or by another person under a legal obligation to publish it. The public-availability exclusion is confined to those circumstances.
The DPDP Act commencement notification dated 13 November 2025 brought the definitions and institutional provisions, including the provisions establishing the Data Protection Board, into force. Consent Manager-related provisions are scheduled to commence on 13 November 2026. Most operational provisions, including sections 3 to 17, are scheduled to commence on 13 May 2027.
The Digital Personal Data Protection Rules, 2025 ('DPDP Rules') follow the same broad stages for commencement. Rule 4 commences after one year, while rules 3, 5 to 16, 22 and 23 commence after eighteen months. Section 43A of the IT Act and the SPDI Rules continued to apply during the transition because the DPDP provision omitting section 43A was also scheduled for the eighteen-month stage.
Once the relevant DPDP provisions commence, a data fiduciary will remain responsible for processing carried out on its behalf by a processor. Section 8(3) will require completeness, accuracy and consistency where personal data is likely to be used to make a decision affecting the individual or disclosed to another data fiduciary. The statutory security, breach-intimation, erasure and grievance requirements will apply according to their terms.
Section 10 and rule 13 contain an additional framework for entities notified as Significant Data Fiduciaries. It includes a data protection officer, an independent audit, a periodic impact assessment and annual due diligence concerning technical measures, including algorithmic software used to process personal data. The algorithmic due-diligence requirement will apply after the relevant provisions commence and where the Central Government has designated the entity as a Significant Data Fiduciary.
Sigma Chambers' article on privacy laws for drone companies illustrates how identifiability, fiduciary and processor roles, present SPDI requirements and scheduled DPDP duties can vary across an operational workflow.
Legal status of the India AI Governance Guidelines
MeitY released the India AI Governance Guidelines on 5 November 2025. They set out seven principles: Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; and Safety, Resilience and Sustainability. Their recommendations cover infrastructure, capacity building, policy and regulation, risk mitigation, accountability and institutions.
The Guidelines are a government policy document with advisory legal effect. They recommend a principle-based, risk-sensitive approach that draws on existing law and sectoral regulation, together with institutional coordination, standards, incident-response measures and regulatory-gap analysis. They do not create generally applicable duties for private businesses. Any control presented internally as legally mandatory should therefore be tied to its statutory, regulatory or contractual basis.
The Guidelines recommended an AI Governance Group supported by a Technology and Policy Expert Committee. MeitY subsequently constituted the AI Governance and Economic Group by an office memorandum dated 13 April 2026. The memorandum assigns the Group responsibility for policy coordination, compliance with Indian law, regulatory-gap analysis and India's AI-governance strategy. Its terms concern governmental coordination.
For businesses, the Guidelines are most useful as a governance reference for accountability, human oversight, testing, incident escalation and explainability. The appropriate controls will depend on the product's function, affected persons and applicable law.
Legal status of the March 2024 advisory
MeitY issued a revised advisory to intermediaries and platforms on 15 March 2024, superseding its advisory of 1 March 2024. It addressed unlawful content generated or disseminated through AI systems, bias and discrimination, and threats to electoral integrity. It also covered disclosures for under-tested or unreliable models, information provided to users, and labelling or provenance measures for synthetic material capable of being used as misinformation or a deepfake.
The advisory records MeitY's executive expectations for intermediaries and platforms. Its legal form is distinct from rules notified in the Gazette under section 87 of the IT Act. Any enforcement consequence must therefore be traced to the applicable provision of the IT Act, the IT Rules or another law.
The February 2026 amendments subsequently introduced express SGI obligations within the notified IT Rules. Those rules now provide the operative definition, scope and requirements for SGI.
Compliance priorities for AI companies
Companies building, deploying or procuring AI in India should organise their review around the following areas:
Map the system's functions. Record what each feature creates, receives, changes, ranks, recommends, publishes or decides. A product with several functions may require different legal treatment for each feature.
Identify the company's role in each workflow. Determine whether it acts for itself, as an intermediary for third-party records, as a data fiduciary, as a processor or as a vendor to a regulated entity. Record the facts supporting each classification.
Inventory the content and data involved. Distinguish realistic synthetic audio-visual content from other outputs, personal data from non-personal data, and current SPDI requirements from scheduled DPDP duties. Cover training, testing, prompts, outputs, telemetry and support datasets.
Review sectoral and subject-matter requirements. Identify the financial, telecom, health, consumer, employment, intellectual-property, criminal and other laws applicable to the use case. Assess intermediary status alongside the legality of the underlying content or decision.
Maintain governance records. Keep approvals, evaluations, provenance decisions, incident routes, vendor responsibilities, human-review points and reasons for consequential automated decisions. Calibrate the evidence and controls to the legal and operational risk.
Track commencement dates and regulatory updates. Prepare separately for the DPDP stages scheduled for 13 November 2026 and 13 May 2027. Record consultation drafts and policy recommendations according to their legal status, and incorporate them into mandatory controls if they become operative or otherwise acquire legal effect.
Frequently asked questions
Does India currently have a dedicated AI Act?
As at 16 August 2026, India regulates AI through existing statutes and rules, sector-specific requirements and general law. The applicable requirements depend on the activity, legal role, data and sector. Parliament has not enacted a generally applicable statute for AI as a single category. Government guidelines and advisories retain their policy or executive status according to their terms.
Which AI-generated outputs require labels under the IT Rules?
The notified SGI rules apply to artificially or algorithmically created or altered audio, visual or audio-visual information that falls within the statutory definition. The definition is directed to realistic depictions of an individual or event and contains specified exclusions. Text generated by an AI system is outside the SGI definition on that basis alone. Other legal or regulatory requirements may require disclosure in a particular context, including misleading advertising or regulated communications.
About the authors
![]() Abhinav Goyal Partner | ![]() Saumya Asthana Senior Associate |

Delhi: 100, Ground Floor, Uday Park – 110049
Hyderabad: 21, Prashasan Nagar, Jubilee Hills – 500033
office@sigmachambers.in · www.sigmachambers.in
Disclaimer: This publication is intended solely for informational and educational purposes. It summarises legal and policy developments from publicly available sources and does not constitute legal advice, opinion or endorsement by Sigma Chambers. The legal position is stated as at 16 August 2026 and may change. All sources are hyperlinked.



Comments