Are you need IT Support Engineer? Free Consultant

AI Regulation in India: Legal Compliance Guide for AI Companies (2026)

  • August 14, 2026

Quick Answer

India does not yet have a standalone AI law, but multiple existing statutes including the Digital Personal Data Protection Act 2023, the IT Act 2000, and the Copyright Act 1957 already impose binding obligations on AI companies. MeitY’s AI Governance Guidelines (November 2025) and the proposed AI (Ethics and Accountability) Bill 2025 signal where enforcement is heading. Companies that build compliance frameworks now will be better positioned as regulation matures.

India’s approach to AI regulation is evolving rapidly. The government has invested USD 1.25 billion through the IndiaAI Mission, established the IndiaAI Safety Institute, and published structured AI governance guidelines in November 2025. At the same time, India’s existing legal framework already creates enforceable obligations for AI companies across data protection, intellectual property, consumer protection, and platform liability.

This guide is written for AI startup founders, heads of AI product development, and legal heads at companies deploying AI products or using AI in services. We cover what laws apply right now, what the MeitY AI Governance Guidelines require, what the proposed AI (Ethics and Accountability) Bill 2025 proposes, how the EU AI Act’s extraterritorial reach may affect Indian companies, and what practical compliance steps you should take in 2026.

AI compliance in India is not a future concern. It is a current operational requirement.

India's Current Approach to AI Regulation

India has chosen a principle-based, sectoral approach to AI governance rather than a single comprehensive AI statute. This is a deliberate policy position. The government’s view, reflected in MeitY’s advisory framework and the IndiaAI Mission, is that innovation should not be front-loaded with compliance costs before use cases and risks are fully understood.

That does not mean AI companies operate in a regulatory vacuum. It means that the obligations that apply today arise from existing legislation designed for data protection, intellectual property, consumer rights, and platform liability, not from an AI-specific law.

The IndiaAI Safety Institute, established in 2024, is tasked with evaluating AI risks, developing safety benchmarks, and advising the government on AI-specific regulatory interventions. Its work is ongoing. The USD 1.25 billion IndiaAI Mission funds compute infrastructure, datasets, and AI application development, including in healthcare, agriculture, and governance sectors where AI risk is elevated.

Indian AI companies should track three regulatory tracks simultaneously: existing law obligations that apply now, MeitY’s governance guidelines that set expected standards of conduct, and the legislative pipeline that will define the compliance architecture of the next three to five years.

IT Act 2000: Section 43A (Data Security) and Section 72A

DPDP Act 2023 and DPDP Rules 2025: AI Training Data and User Data

The Digital Personal Data Protection Act 2023 applies directly to AI companies that process personal data of Indian residents. The DPDP Rules 2025, notified on November 13, 2025, have triggered a phased compliance rollout with Phase I obligations active now and full enforcement beginning May 2027.

For AI companies, the most significant obligations concern training data and inference pipelines. If personal data is used to train a model, that processing requires a lawful basis under the DPDP Act typically, consent from the Data Principal. Consent must be granular, specific to the purpose of processing, and withdrawable. Scraping publicly available data that includes personal information does not automatically constitute lawful processing under the DPDP Act.

Where AI systems generate outputs about identifiable individuals in recommendation engines, credit scoring systems, HR tools, or diagnostic applications the data processed at inference is also subject to the DPDP Act’s obligations.

Companies designated as Significant Data Fiduciaries (SDFs) face additional requirements, including mandatory Data Protection Impact Assessments, algorithmic accountability policies, and annual audits. AI companies processing personal data at scale should proactively assess whether SDF designation is likely. For a detailed compliance programme, refer to our DPDP Act Compliance Guide for IT and Tech Companies.

Penalties for non-compliance reach up to INR 250 crore per breach.

IT Act 2000: Deepfakes and Platform Liability

The Information Technology Act 2000, as amended by the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, creates two categories of obligation relevant to AI companies.

First, AI companies that operate platforms on which users generate or share content including AI-generated synthetic media may be classified as intermediaries. Platform liability protection under Section 79 of the IT Act is conditional on intermediaries meeting due diligence obligations, including publishing and enforcing terms of service that prohibit unlawful content.

Second, the IT Rules 2021 impose mandatory takedown timelines for harmful content. Deepfake content that violates an individual’s dignity or constitutes non-consensual intimate imagery must be removed within 24 hours of receipt of a complaint. AI-generated synthetic media that constitutes misinformation or impersonation carries similar removal obligations within 36 hours.

AI companies that generate synthetic video, audio, or image content must ensure their platforms and products have functioning complaint mechanisms and content moderation workflows calibrated to these statutory timelines.

Copyright Act 1957: AI-Generated Content

Under the Copyright Act 1957, copyright subsists in original works created by human authors. Indian copyright law does not recognize AI as an author. This is the current legal position and it has not been modified by any amendment or judicial decision as of 2026. For a detailed analysis of how this affects AI product companies, refer to our Copyright in India guide.

The practical consequence for AI companies is significant. Content generated autonomously by an AI system, without sufficient human creative input and direction, may not be protectable by copyright. The company deploying the AI may not hold an exclusive copyright in the output.

Where a human author exercises sufficient creative control over the direction, selection, and arrangement of AI-generated content, copyright may vest in that human author. The threshold of human creative contribution required to establish authorship remains unsettled in Indian law.

AI companies should review their product documentation, terms of service, and IP ownership representations to ensure they accurately reflect this legal position. Overclaiming copyright in purely AI-generated outputs creates contractual and regulatory risk.

Patents Act 1970: AI as Inventor

The Patents Act 1970 requires that an inventor be a natural person. AI systems cannot be named as inventors on Indian patent applications. This position is consistent with the approach taken by patent offices in the United States, the United Kingdom, and the European Patent Office. For guidance on structuring patent claims for AI-related software inventions under the CRI Guidelines, refer to our Software Patents in India: CRI Guidelines guide.

For AI companies developing technology through AI-assisted R&D pipelines, the inventorship question is practically important. Where a human inventor cannot be identified who made a genuine and substantive inventive contribution to the claimed invention, the patent application is at risk.

AI companies using AI tools in their innovation process should document human inventive contributions carefully at every stage of the development process to preserve patentability of genuinely human-directed inventions.

Consumer Protection Act 2019: AI Product Liability

The Consumer Protection Act 2019 applies to AI products and AI-powered services. Where an AI system causes harm to a consumer through a defective recommendation, a biased output, or a system failure the company deploying that AI product may be liable under the Act’s product liability provisions.

The Consumer Protection (E-Commerce) Rules 2020 impose additional disclosure and grievance obligations on AI companies selling products or services online. These include clear disclosure of return, refund, and grievance redressal mechanisms.

AI companies deploying consumer-facing products must ensure their terms of service, product documentation, and grievance mechanisms meet the standards set by the Consumer Protection Act 2019. AI-generated outputs that cause financial or personal harm to consumers carry direct liability exposure.

Sector-Specific AI Regulations

Several Indian regulators have issued or are developing sector-specific AI guidance that applies to companies deploying AI in regulated industries.

The Reserve Bank of India (RBI) has issued guidance on algorithmic lending, model risk management, and the use of alternative data in credit underwriting. AI companies in the financial services space are subject to RBI’s existing regulatory framework for non-banking financial companies, payment system operators, and account aggregators.

The Insurance Regulatory and Development Authority of India (IRDAI) has addressed the use of AI in underwriting and claims processing. The Securities and Exchange Board of India (SEBI) has issued guidance on algorithmic trading and the use of AI in investment advisory services.

The Central Drugs Standard Control Organisation (CDSCO) applies the Medical Devices Rules 2017 to certain AI-based diagnostic and clinical decision support tools. Where an AI system meets the definition of a medical device, it requires regulatory clearance before deployment.

MeitY AI Governance Guidelines: November 2025

The Ministry of Electronics and Information Technology published AI Governance Guidelines in November 2025. These guidelines are not legally binding in the manner of an Act or a set of Rules notified under an Act. They represent MeitY’s articulated framework for responsible AI development and deployment in India, and they signal the standards against which future regulation and government procurement are likely to be assessed.

The MeitY AI Governance Guidelines are organized around seven principles, referred to as “sutras.” These are:

  1. Safety and Reliability: AI systems must operate safely and produce reliable outputs, particularly in high-stakes applications.
  2. Equality and Non-Discrimination: AI systems must not produce outputs that discriminate on grounds prohibited by Indian law.
  3. Inclusivity and Non-Harm: AI development and deployment must account for marginalized populations and avoid causing harm.
  4. Privacy and Security: AI systems must comply with applicable data protection law and implement appropriate security controls.
  5. Transparency: AI companies must be transparent about AI system capabilities, limitations, and the fact of AI involvement in decisions affecting individuals.
  6. Accountability: Clear accountability structures must exist for AI system design, deployment, and output.
  7. Protection and Reinforcement of Positive Societal Values: AI systems must be designed and deployed in a manner consistent with constitutional values.

For AI companies, the MeitY guidelines create a de facto compliance standard. Government clients and large enterprise clients are increasingly incorporating these principles into procurement criteria and vendor due diligence processes. Companies that can demonstrate alignment with the seven sutras have a material advantage in regulated and public sector markets.

AI (Ethics and Accountability) Bill 2025: What It Proposes

The AI (Ethics and Accountability) Bill 2025 is a Private Member’s Bill introduced in the Indian Parliament. It has not been enacted into law. Its provisions are not currently in force.

We include it in this guide because it sets out the most concrete legislative proposal for an AI-specific statute in India to date, and because its framework is likely to influence any future government bill on the same subject.

The Bill proposes the following key elements:

  • Mandatory registration of AI systems classified as “high-risk” with a designated regulatory authority
  • Algorithmic impact assessments before deployment of high-risk AI systems
  • Transparency obligations requiring disclosure to users when they are interacting with an AI system
  • Right to explanation for individuals subjected to automated decisions with significant effects
  • Penalties of up to INR 5 crore for violations of the Bill’s provisions
  • Prohibition on AI systems that pose unacceptable risks to health, safety, or fundamental rights

The Bill’s risk classification framework broadly mirrors the EU AI Act’s tiered approach, distinguishing between unacceptable risk, high-risk, limited risk, and minimal risk AI systems.

AI companies building compliance frameworks now should assess their product portfolio against the Bill’s proposed high-risk categories. The effort invested in AI risk classification today will reduce the cost and disruption of compliance if and when a statutory framework is enacted.

EU AI Act: Does It Apply to Indian AI Companies?

The EU AI Act came into force on August 1, 2024, with obligations applying in phases through 2027. Its extraterritorial reach is designed to capture AI companies outside the European Union whose systems affect EU residents.

The EU AI Act applies to an Indian AI company if:

  • The company places an AI system on the EU market, regardless of where the company is incorporated
  • The company deploys an AI system that affects individuals located in the EU
  • Outputs generated by the company’s AI system are used within the EU

In practice, this means Indian AI companies serving EU enterprise clients, European consumers, or global markets where EU residents are users must assess EU AI Act compliance obligations alongside Indian regulatory requirements.

The most immediate obligations for high-risk AI systems under the EU AI Act include conformity assessments, technical documentation, human oversight mechanisms, and registration in the EU AI database. For general-purpose AI (GPAI) models with systemic risk, additional obligations include model evaluation, adversarial testing, and incident reporting to the European AI Office.

Indian AI companies with EU market exposure cannot treat EU AI Act compliance as a European legal team’s responsibility. Product design, training data governance, and output monitoring decisions made in India directly affect EU Act compliance status. Legal and product teams must work together from the design stage.

High-Risk AI Applications in India: Areas of Heightened Scrutiny

Healthcare AI: Diagnostic and Prescriptive Systems

AI systems used in medical diagnosis, treatment recommendation, and clinical decision support operate in an area of heightened regulatory and legal scrutiny in India. Where the AI system meets the definition of a medical device under the Medical Devices Rules 2017, CDSCO registration and clearance are required before deployment.

Beyond regulatory clearance, healthcare AI companies face product liability exposure under the Consumer Protection Act 2019 and professional liability considerations where AI systems support or replace clinical judgment. Companies should ensure clear human oversight mechanisms are embedded in product design and that clinical validation studies are conducted and documented before deployment.

Credit Scoring and Financial AI

AI systems used in credit underwriting, loan origination, and risk scoring are subject to RBI’s model risk management guidance and the DPDP Act’s obligations on automated decision-making that affects individuals. The DPDP Act’s proposed right to explanation (reflected also in the AI Ethics and Accountability Bill) creates a forward-looking compliance requirement that AI companies in the financial services sector should anticipate now.

Credit scoring AI that produces discriminatory outcomes on grounds of religion, caste, gender, or other protected characteristics creates exposure under both the Consumer Protection Act 2019 and the constitutional framework.

Hiring and HR AI

AI systems used in candidate screening, interview assessment, and performance evaluation process personal data of job applicants and employees. These systems carry DPDP Act obligations around consent, purpose limitation, and data minimization. Where AI-generated outputs significantly affect hiring decisions, the transparency and explanation obligations proposed in the AI Ethics and Accountability Bill reflect a compliance direction that is already a best practice standard in Indian corporate governance.

HR AI companies should conduct bias audits of their models, document the human review process applied before AI-informed decisions are acted upon, and maintain clear records of how AI outputs are weighted in final decisions.

Law Enforcement and Surveillance AI

AI systems used in facial recognition, predictive policing, and mass surveillance operate in the most sensitive area of India’s regulatory environment. Constitutional challenges to disproportionate surveillance have been brought before Indian courts, and the Supreme Court’s privacy jurisprudence, established in K.S. Puttaswamy v. Union of India (2017), provides the foundational framework within which surveillance AI must operate.

AI companies supplying law enforcement or public safety systems to government clients must conduct thorough legal due diligence on the terms of deployment. Commercial agreements with government agencies should clearly delineate the permitted scope of use. Both the MeitY AI Governance Guidelines and the AI Ethics and Accountability Bill identify law enforcement AI as a high-risk category subject to the most stringent oversight requirements.

Practical Compliance Steps for AI Companies in India Right Now

The following steps reflect Altacit Global’s recommended compliance approach for AI companies operating in India in 2026. Our teams in Bangalore and Hyderabad work with AI startups and established technology companies to build compliance frameworks that are legally sound and operationally practical.

Step 1: Conduct an AI System Inventory and Risk Classification
Map every AI system your company develops or deploys. For each system, identify the data processed, the decision or output produced, the individuals affected, and the sector in which it operates. Classify each system by risk level using the MeitY guidelines and the EU AI Act categories as dual frameworks.

Step 2: Audit Training Data for DPDP Act Compliance
Identify all personal data used in training pipelines. Assess whether processing is supported by a lawful basis under the DPDP Act. Where consent is required and not obtained, the training data set carries legal risk. Document all data sources, licensing terms, and consent frameworks.

Step 3: Implement Transparency Mechanisms
Ensure users of AI-powered products are clearly informed when they are interacting with or being assessed by an AI system. This applies to chatbots, recommendation engines, automated content moderation, and decision-support tools. Transparency is both a MeitY governance principle and a proposed statutory obligation under the AI Ethics and Accountability Bill.

Step 4: Build Complaint and Redressal Workflows
All AI products deployed to consumers in India require grievance redressal mechanisms under the Consumer Protection Act 2019. The DPDP Act requires a separate grievance mechanism for personal data-related complaints. These obligations overlap and should be integrated into a single, well-documented customer support infrastructure.

Step 5: Review IP Ownership Representations
Audit all product documentation, terms of service, client contracts, and marketing materials for representations about copyright ownership of AI-generated outputs. Ensure that no representations of copyright ownership are made in respect of purely AI-generated content, consistent with the Copyright Act 1957 position.

Step 6: Establish an AI Governance Committee
Designate internal accountability for AI governance. This does not require a large team. It requires a defined decision-making structure, a documented policy for model development and deployment, a regular review cycle for AI system performance and bias monitoring, and a named individual accountable to senior leadership.

Step 7: Monitor the Legislative Pipeline
Assign responsibility for tracking developments in the AI Ethics and Accountability Bill, MeitY guidance updates, sector regulator AI advisories (RBI, SEBI, IRDAI, CDSCO), and EU AI Act implementation timelines for Indian market companies. Regulatory developments in this space are moving on a quarterly basis, and compliance frameworks built today must be designed for amendment.

Your Next Step in AI Compliance

AI regulation in India is building in layers. Existing law creates binding obligations right now. MeitY’s governance guidelines define the expected standard of conduct. The AI Ethics and Accountability Bill and the EU AI Act define the direction of travel. Companies that treat compliance as a structured programme rather than a reactive response to enforcement will be better positioned competitively and legally as the regulatory framework matures.

Altacit Global advises AI companies across India on regulatory compliance, data protection, intellectual property, and technology law. Our teams in Bangalore and Hyderabad work with AI startups, product companies, and enterprises to build compliance programmes that are practical and legally defensible.

If you would like a structured assessment of your AI company’s current compliance position under Indian law, contact Altacit Global to schedule a consultation.

Frequently Asked Questions: AI Regulation India

There is no standalone AI statute in force in India as of 2026. The AI (Ethics and Accountability) Bill 2025 is a Private Member’s Bill and has not been enacted. AI companies in India are regulated under existing legislation, including the DPDP Act 2023, the IT Act 2000, the Copyright Act 1957, the Patents Act 1970, and the Consumer Protection Act 2019, supported by MeitY’s AI Governance Guidelines (November 2025).

MeitY published AI Governance Guidelines in November 2025, organized around seven principles (sutras): safety and reliability, equality and non-discrimination, inclusivity and non-harm, privacy and security, transparency, accountability, and protection of societal values. The guidelines are not legally binding as a statute, but they represent the government’s articulated standard for responsible AI. They are increasingly incorporated into government procurement requirements and enterprise due diligence processes.

The EU AI Act applies to Indian AI companies if they place AI systems on the EU market, deploy AI systems that affect individuals located in the EU, or if their AI system outputs are used within the EU. Indian AI companies serving EU enterprise clients or global consumer markets with EU users must conduct an EU AI Act compliance assessment. Full obligations for high-risk AI systems are phased in through 2027.

Under the Copyright Act 1957, copyright subsists in original works created by human authors. AI systems are not recognized as authors under Indian law. Content generated autonomously by an AI system, without sufficient human creative direction and input, may not be protectable by copyright in India. AI companies should not represent ownership of copyright in purely AI-generated outputs in product documentation or client contracts.

No. The Patents Act 1970 requires that an inventor be a natural person. AI systems cannot be named as inventors. AI companies using AI tools in R&D processes must identify human inventors who made a genuine and substantive inventive contribution to each claimed invention.

The AI (Ethics and Accountability) Bill 2025 proposes penalties of up to INR 5 crore for violations of its provisions. The Bill has not been enacted and its provisions are not currently in force. However, the penalty framework provides a useful benchmark for the seriousness with which India’s legislature is approaching AI accountability obligations.

Based on the MeitY AI Governance Guidelines and the AI Ethics and Accountability Bill 2025, areas of heightened scrutiny in India include healthcare AI (diagnostic and prescriptive systems), credit scoring and financial AI, hiring and HR AI, and law enforcement and surveillance AI. Sector-specific regulations from the RBI, SEBI, IRDAI, and CDSCO apply additional obligations in their respective domains.

The IndiaAI Safety Institute was established as part of India’s AI governance infrastructure to evaluate AI risks, develop safety benchmarks, and advise the government on AI-specific regulatory interventions. It operates alongside the USD 1.25 billion IndiaAI Mission, which funds computer infrastructure, AI datasets, and AI application development across priority sectors.

This Web site is not intended to be a source of advertising or solicitation and the contents of the web site should not be construed as legal advice. The reader should not consider this information to be an invitation for a client relationship.