Artificial intelligence has moved from the periphery of regulatory attention to its centre with a speed that has tested the capacity of legal systems designed for slower-moving technologies. In India, no comprehensive AI statute is yet in force, and the regulatory response to AI deployment has emerged instead through sector-specific guidelines, advisory frameworks issued by regulators, and the application of existing instruments – the Digital Personal Data Protection Act, 2023 (DPDP Act); the Information Technology Act, 2000; the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 – to AI-generated content and AI-driven decision-making. This blog examines the current and emerging Indian AI regulatory framework, evaluates the principal sectoral guidance documents and advisories that have shaped AI obligations to date, and situates India's position within the comparative context of the European Union AI Act, the UK's principles-based AI governance model, and the People's Republic of China's algorithmic recommendation regulations. India's current regulatory architecture is insufficient to address the systemic risks posed by large-scale AI deployment in high-risk domains – credit, healthcare, criminal justice, and employment – and a risk-tiered AI governance framework modelled on the EU AI Act, adapted for India's developmental and regulatory context, represents the appropriate legislative direction.
India's Current AI Governance Architecture: A Patchwork Framework
India does not have an AI Act. The Ministry of Electronics and Information Technology (MeitY) has issued advisory guidelines on the responsible development and deployment of AI – most notably the MeitY Advisory on Responsible and Ethical AI (March 2024), which addressed AI platforms and intermediaries – and the SEBI, RBI, IRDAI, and TRAI have each issued sector-specific guidance on the use of AI within their respective regulated domains. This advisory and guidance-led approach to AI governance reflects India's preference, at least in the current period, for facilitating AI innovation through regulatory flexibility rather than pre-emptive statutory constraint.
The MeitY Advisory of March 2024, issued in the context of AI models deployed in India, initially required intermediaries to label AI-generated content and seek government permission before deploying AI models that could be used for deepfakes or disinformation.¹ The advisory generated significant industry pushback and was subsequently modified: the revised March 2024 advisory removed the prior government permission requirement and focused instead on due diligence obligations for AI model deployment, anti-disinformation labelling requirements, and obligations to ensure that AI outputs do not generate content that could harm the sovereignty and integrity of India or constitute misinformation. The modified advisory remains in force and represents the clearest current central government statement on AI governance obligations applicable to intermediaries.
The DPDP Act as an AI Governance Instrument
While the DPDP Act was not drafted as an AI governance statute, its provisions are directly applicable to AI systems that process personal data – which encompasses the majority of AI applications in consumer, financial, and healthcare contexts. The DPDP Act's consent framework requires that personal data be processed only for a specified and lawful purpose for which the Data Principal has given free, informed, specific, and unambiguous consent; AI training, inference, and model personalisation that are not within the contemplated purpose umbrella require separate consent.²
The DPDP Act's right to information provision – which entitles Data Principals to know the categories of personal data processed – and the right to correction and erasure are relevant to AI-generated profiles and automated decisions. However, the Act does not at present include a right to explanation for automated individual decisions analogous to Article 22 of the GDPR, which requires that individuals not be subject to solely automated decisions that produce legal or similarly significant effects without human review. The absence of an automated decision-making provision in the DPDP Act is a material gap in India's AI governance framework: credit scoring, insurance underwriting, employment screening, and judicial risk assessment tools in India routinely produce consequential individual decisions without meaningful human oversight, and the legal basis for challenging such decisions is presently uncertain.
The Significant Data Fiduciary (SDF) framework, examined in detail in a companion blog, provides a governance mechanism that partially addresses the AI risk concern: the mandatory Data Protection Impact Assessment (DPIA) required of SDFs must evaluate the risks of automated processing to Data Principals. For AI systems deployed at the scale typical of SDFs, the DPIA represents the closest current analogue to the EU AI Act's conformity assessment requirement, but the absence of AI-specific DPIA criteria means that the adequacy of this mechanism depends on the depth and rigour of the individual DPIA rather than on prescribed standards.
Sectoral AI Guidelines: RBI, SEBI, IRDAI, and TRAI
India's financial sector regulators have been the most active in developing sector-specific AI guidance, reflecting the concentration of AI deployment risk in financial decision-making.
The Reserve Bank of India issued its paper on AI governance in the financial sector in January 2024, setting out expectations for regulated entities (banks, NBFCs, payment system operators) on AI model risk management, model validation, explainability, bias testing, and board-level accountability for AI governance.³ The RBI's expectations align broadly with the model risk management frameworks developed by the US Federal Reserve's SR Letter 11-7 and the European Banking Authority's draft Guidelines on Internal Governance, which treat AI models as subject to the same validation, monitoring, and oversight requirements as traditional credit and risk models. The RBI's paper is advisory rather than mandatory, but regulated entities are expected to self-assess compliance and report on AI governance in their annual risk reports.
SEBI has addressed AI use in securities markets through its circular on algorithmic trading – which has been in force since 2012 in its original form and has been progressively amended – and through guidance on AI in research and investment advisory services issued in 2024.⁴ SEBI's principal concern is that AI tools used in research or investment advisory without appropriate human oversight and attribution may constitute unsolicited investment advice or create systemic market risk through correlated, AI-driven trading behaviour.
TRAI's 2024 recommendations on responsible AI address AI deployment by telecom operators and digital communication platforms, focusing on network traffic management, AI-driven customer service systems, and the use of AI for targeted advertising – recommendations that interact with both the DPDP Act's consent framework and the IT Rules 2021's provisions on targeted advertising to minors.
The EU AI Act: The Global High-Water Mark
The European Union AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies progressively from August 2024 through August 2027.⁵ The AI Act establishes a risk-tiered classification for AI systems: prohibited AI applications (rights-enumerated systems such as real-time biometric surveillance in public spaces, social scoring by public authorities, and manipulative AI that exploits vulnerabilities); high-risk AI applications (credit scoring, employment screening, biometric categorisation, criminal justice risk assessment, educational assessment, safety-critical systems) subject to mandatory conformity assessment, CE marking, and ongoing risk management obligations; and limited-risk and minimal-risk AI systems subject to lighter transparency obligations.
The AI Act's extraterritorial reach is analogous to the GDPR's: it applies to AI providers established in the EU and to providers established outside the EU whose AI systems are placed on the EU market or whose outputs affect EU users. Indian AI companies deploying systems in the EU – and Indian companies using AI models provided by EU-regulated suppliers – face direct exposure to the AI Act's conformity assessment and registration requirements for high-risk applications.
China's algorithm regulation framework – the Algorithmic Recommendation Management Provisions (2022) and the Generative AI Measures (2023) – provides an alternative model characterised by prescriptive content obligations, mandatory internet information service provider registration for algorithm operators, and prior security assessment for generative AI services provided to the public. The Chinese model prioritises information control and content safety in a manner that reflects a different regulatory philosophy from the EU's rights-centred risk-tiered approach.
The UK's Principles-Based Approach
The United Kingdom has adopted a sector-led, principles-based approach to AI governance, set out in the AI Regulation Policy Paper published by the Department for Science, Innovation and Technology in March 2023 and updated through policy documents in 2024 and 2025.⁶ The UK model designates existing regulators – the FCA, ICO, CMA, MHRA, and others – as responsible for AI governance within their respective sectors, guided by five cross-regulator principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. The UK approach is specifically designed to avoid the compliance costs of blanket AI legislation and to exploit the regulatory flexibility available to the UK post-Brexit.
India's regulatory architecture shares some structural similarities with the UK's sector-led model: India's regulatory agencies (RBI, SEBI, IRDAI, TRAI) have each addressed AI within their domains, and there is no cross-sectoral AI statute. The difference is that the UK's sector-led model operates against a background of strong and experienced sectoral regulators with broad statutory remits, whereas India's sectoral regulators have issued advisories of varying specificity and enforceability without the benefit of express AI statutory authority.
Conclusion
India's AI governance framework is in an early and incomplete state. This blog has argued that the DPDP Act's consent and purpose-limitation requirements provide a partial governance mechanism for AI systems processing personal data, that the absence of an automated decision-making provision is a material gap, and that India's sectoral regulatory guidance – while directionally correct – lacks the statutory authority and analytical depth necessary for high-risk AI applications. The EU AI Act's risk-tiered classification provides a structural model that India could adapt for its context, calibrating the conformity assessment requirements to India's regulatory capacity and developmental stage. The introduction of a dedicated AI governance framework – not necessarily legislation in the first instance, but a cross-sectoral advisory body with statutory underpinning – would provide the policy coherence and regulatory clarity that the current patchwork approach cannot deliver.
Endnotes
¹ Ministry of Electronics and Information Technology (India), 'Advisory for Intermediaries and Platforms on AI' (March 2024, revised March 2024).
² Digital Personal Data Protection Act 2023 (India), s 6 (conditions for valid consent).
³ Reserve Bank of India, 'Discussion Paper on Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector' (January 2024).
⁴ Securities and Exchange Board of India, 'Circular on Algorithmic Trading by Clients' (Circular No CIR/MRD/DP/09/2012, 13 March 2012, and subsequent amendments).
⁵ Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act) [2024] OJ L1689.
⁶ Department for Science, Innovation and Technology (UK), 'AI Regulation: A Pro-Innovation Approach' (Policy Paper, March 2023).
⁷ Regulation (EU) 2016/679 (GDPR), art 22 (automated individual decision-making and profiling).
⁸ National Institute for Transforming India (NITI Aayog), 'Responsible AI for All: Adopting the Framework–A Use Case Approach on Facial Recognition Technology' (2021).
⁹ Cyberspace Administration of China, 'Provisions on the Management of Algorithmic Recommendations' (effective 1 March 2022).
¹⁰ Board of Governors of the Federal Reserve System, 'SR Letter 11-7: Supervisory Guidance on Model Risk Management' (4 April 2011).
Authors

Related insights
View moreInfrastructure Investment Trusts in India: Structuring, SEBI Regulation, and the InvIT as a Capital Markets Instrument
Examining the InvIT structure, SEBI's 2026 amendments, NAMP pipeline asset monetisation, and debt financing dynamics under Indian trust laws.
ESG-Linked Fundraising in India: Regulatory Expectations, Investor Demands and Structuring Considerations
ESG considerations have moved from the margins of the alternative investment landscape to its center in India.
Foreign Direct Investment in Indian Real Estate: The Regulatory Framework, FDI Routes and Practical Structuring
An analysis of the FDI framework for Indian real estate in 2026, including automatic routes, restricted categories, and JVs.