A founder in Bengaluru is building a voice-based credit-scoring assistant for small retailers in Tamil Nadu. The product listens to a shopkeeper describe their business in Tamil, transcribes it, scores their creditworthiness against transaction history pulled from UPI records, and hands that score to a partner NBFC that decides whether to lend. Before writing a line of production code, the founder needs answers to four separate legal questions that have nothing to do with each other: Can this NBFC's transaction data be used to train the scoring model, and under what consent regime? Where can the model be trained cheaply enough that a seed-stage startup can afford the GPU-hours? Does the chatbot have to tell the shopkeeper it's talking to an AI, and does the credit decision itself have to be explained? And if the score is wrong and someone is denied a loan unfairly, which regulator do they complain to?
In the European Union, one statute would answer all four questions at once, because a credit-scoring AI is explicitly named a "high-risk" system under Annex III of the EU AI Act and inherits a single bundle of obligations: conformity assessment, a risk-management system, human oversight, technical documentation. In India, the founder gets four different answers from four different instruments, none of which was written with AI specifically in mind except one. That difference, a single horizontal statute that classifies AI systems before they're deployed, versus a stack of pre-existing, harm-specific laws that AI activity happens to trigger, is the actual subject of this chapter. India's "AI policy" is not a document you can point to. It is an architecture, and understanding it means tracing which instrument governs which stage of an AI system's life.
Three things a government can regulate, and two ways to sequence it
Strip away the acronyms and every AI governance regime is really regulating three distinct objects. First, the data an AI system is built on: who collected it, under what consent, and whether it can cross a border. Second, the model itself as an artifact: what it was trained on (a copyright and IP question), how it behaves, and whether it can be audited. Third, the deployment: what the system does in the world, who it affects, and what recourse they have when it fails.
Two design philosophies exist for sequencing this. The EU's is ex-ante and horizontal: Regulation (EU) 2024/1689, in force since 1 August 2024, sorts every AI system into one of four risk tiers before it ever reaches a user, unacceptable (banned outright: social scoring, real-time biometric identification in public spaces, manipulative subliminal techniques), high-risk (employment, credit, law enforcement, critical infrastructure: conformity assessment required), limited risk (chatbots, deepfakes: must disclose they're AI-generated), and minimal risk (spam filters, game AI: no obligations). Prohibited practices became enforceable from 2 February 2025, general-purpose model obligations from 2 August 2025, and most high-risk duties phase in from 2 August 2026. One law, one classification exercise, before launch.
India's is ex-post and instrument-specific: there is no single "AI Act." Instead, whichever pre-existing law already covers a given harm, data misuse, deceptive content, financial loss, copyright infringement, is the law that applies, triggered only once that harm is plausible. A dedicated AI-specific due-diligence obligation exists, but it is narrow (content labeling) and sits inside an existing intermediary-liability framework rather than replacing it. This is not an oversight waiting to be corrected. It is a stated policy choice, and understanding why India chose it is the core of this chapter.
The instrument stack, pillar by pillar
NITI Aayog's National Strategy for AI (2018). India's first AI policy document, "#AIforAll," released by the government's policy think tank in June 2018, was not a law at all but a strategy paper: it named five priority sectors (healthcare, agriculture, education, smart cities and infrastructure, and smart mobility) and argued India should pursue AI as a growth and inclusion lever rather than rush to regulate it defensively. It set the tone that persists six years later: build capacity first, legislate narrowly and only where harm is concrete.
The IndiaAI Mission (2024): the implementation vehicle. The Union Cabinet approved the IndiaAI Mission on 7 March 2024 with a five-year outlay of ₹10,372 crore (roughly $1.25 billion), organized into seven pillars. This is not a regulatory instrument, it is industrial policy: the government's answer to "how do we build sovereign AI capacity" rather than "how do we constrain AI harms."
| Pillar | Budget (₹ crore) | Purpose |
|---|---|---|
| Compute Capacity | 4,563.36 | Public-private partnership to empanel >10,000 GPUs at subsidized rates |
| IndiaAI Innovation Centre | 1,971.37 | R&D hub for foundation models in Indian languages |
| Startup Financing | 1,942.50 | Deep-tech AI startup capital |
| FutureSkills | 882.94 | AI education and workforce skilling |
| Datasets Platform | 199.55 | High-quality public-sector datasets for training |
| Application Development | 689.05 | Sector-specific AI applications and deployment support |
| Safe & Trusted AI | 20.46 | Safety tooling, evaluation benchmarks, and an AI Safety Institute |
| Overheads & Contingency | 102.69 | Mission administration (not a technical pillar) |
| Total | 10,371.92 |
Notice what this pillar structure implies about the Compute Capacity line: nearly 44% of the entire mission's budget goes toward making GPUs cheap, because the binding constraint on Indian AI research was never talent or ideas, it was the dollar-denominated cost of training hardware. We return to the arithmetic of this subsidy below.
MeitY's AI advisory (March 2024): the only India-specific, AI-specific rule. On 1 March 2024, the Ministry of Electronics and IT issued an advisory under the IT Rules, 2021 requiring platforms to label "under-testing" or "unreliable" AI models and to obtain government approval before deploying them in India, plus unique-metadata labeling of AI-generated content that could be mistaken for real (deepfakes). Industry pushback over the prior-approval clause, which would have forced every chatbot update through a government sign-off, was swift, and MeitY revised the advisory on 15 March 2024: it dropped the approval requirement and the mandatory status reports, but extended the labeling due-diligence obligation to all AI intermediaries, not just large platforms. Structurally, this advisory is not a standalone penalty regime. It is a condition attached to the "safe harbor" that Section 79 of the IT Act gives intermediaries against liability for user content; an AI platform that ignores the labeling duty doesn't get fined directly, it risks losing the legal shield that lets it operate as a neutral platform at all. That's a meaningfully softer lever than the EU's conformity-assessment regime, and it's deliberately so.
The Digital Personal Data Protection Act, 2023, and its Rules (2025): the data layer. DPDPA governs the input side of any AI system trained on personal data. It defines a "Data Fiduciary" (anyone processing personal data) with obligations to a "Data Principal" (the individual), requires purpose-limited consent, and imposes extra duties, data protection impact assessments, independent audits, on "Significant Data Fiduciaries" designated by government. Its most consequential design choice for AI companies is cross-border data transfer: where the EU's GDPR uses an "adequacy" model (a whitelist of approved destination countries), the DPDP Rules, notified 13 November 2025, use a "negative list" (Rule 15): data can flow to any country by default, unless that country is expressly blacklisted by the central government. This is the opposite default from GDPR and it is not an accident, it lowers friction for Indian companies buying foreign cloud compute or using foreign model APIs, at the cost of the case-by-case assurance GDPR's whitelist provides. Implementation is phased over 12 to 18 months from notification, so most operational obligations were still coming into force through 2026 and 2027.
Sector regulators: harm-triggered oversight. Once an AI system operates inside a regulated sector, that sector's existing regulator, not a horizontal AI law, takes over. The clearest example: the Reserve Bank of India constituted the FREE-AI committee (Framework for Responsible and Ethical Enablement of AI) in December 2024, chaired by the IIT Bombay computer scientist Pushpak Bhattacharyya, which released its report in August 2025 with seven guiding principles and 26 recommendations for banks, NBFCs, and fintechs, including mandatory AI-related disclosures in annual reports and AI-model inventories. SEBI has issued parallel guidance for AI use by market intermediaries. Neither of these is "AI law" in the abstract; each is the existing financial regulator extending its existing mandate to cover a new kind of decision-making tool.
Copyright: litigated, not legislated. India's Copyright Act, 1957 predates machine learning by decades and contains no explicit text-and-data-mining exception of the kind the EU (2019 Copyright Directive) or the UK grant for research use. Section 52's "fair dealing" defense is narrower and was written for human research and criticism, not for training a language model on millions of scraped articles. This ambiguity is now being resolved in court rather than in Parliament: ANI Media, one of India's largest news agencies, sued OpenAI in the Delhi High Court alleging ChatGPT was trained on its copyrighted reporting without authorization and could reproduce or fabricate content attributed to it. On 24 July 2026 the Court delivered an interim ruling refusing to injunct OpenAI, holding that the training use qualified as fair dealing under Section 52 while affirming ANI's underlying copyright ownership. The suit itself remains pending, and ANI retains a 60-day appeal window to a Division Bench, so this is a first data point, not a settled doctrine. But it illustrates the ex-post pattern precisely: India didn't write a TDM exception in advance; a court is deciding, case by case, whether an existing 1957 doctrine stretches to cover a 2024 technology.
Two blueprints, side by side
The diagram below puts both designs on one canvas: the EU's pyramid, where a system's obligations are fixed by which risk tier it's classified into before deployment, against India's pipeline, where each stage of an AI system's life triggers a different pre-existing law only once that stage produces a specific kind of harm.
India on the world stage
India's instrument-specific approach is also its declared negotiating position internationally. On 1 November 2023, India was among 28 governments, alongside the US, UK, EU members, and China, that signed the Bletchley Declaration at the UK's AI Safety Summit, the first multilateral statement committing signatories to cooperate on frontier-AI safety risks. India's Minister of State Rajeev Chandrasekhar framed India's position there around "safety and trust for users, and accountability for platforms" rather than pre-emptive classification. A month later, New Delhi hosted the Global Partnership on AI (GPAI) Summit in December 2023, and India took over GPAI's lead chairmanship for 2024, giving it a seat shaping how the OECD-adjacent GPAI defines responsible-AI norms globally. The G20 New Delhi Leaders' Declaration of September 2023, under India's G20 presidency, folded AI language into its communique, endorsing the existing OECD AI Principles rather than proposing a new binding framework. Read together, these three moments show a consistent posture: India participates actively in setting international norms and safety commitments, while resisting binding domestic pre-classification of AI systems at home. The IndiaAI Mission's Safe & Trusted AI pillar, at just ₹20.46 crore of the ₹10,372 crore mission total (about 0.2%), is the domestic institution meant to eventually house India's own AI safety evaluation capacity, echoing the AI Safety Institute network several Bletchley signatories committed to building, though a budget line that thin undercuts any equivalence with those better-funded national efforts.
The misconception: "no AI law" does not mean "no AI governance"
The most common error a student makes reading India's AI landscape is concluding that because there is no single "India AI Act," AI in India is a legal vacuum, unregulated until Parliament eventually catches up. That's backwards. Every one of the instruments above already applies to AI activity today: a company training on personal data without consent is liable under DPDPA regardless of whether a model is involved; a platform that fails to label a deepfake loses its IT Rules safe harbor today, not in some future AI-specific statute; a bank deploying a biased credit model already answers to the RBI. MeitY officials have said this explicitly and repeatedly since 2023: India does not intend to legislate ahead of observed harm, preferring what amounts to a "test, learn, calibrate" posture over the EU's ex-ante risk classification. The absence of a horizontal AI statute is the policy, not a gap in it. The one place India has moved ex-ante, ahead of demonstrated harm, is exactly the place a harm was judged fast-moving and hard to reverse: synthetic and deceptive content, hence the March 2024 labeling advisory arriving well before any comparable general AI statute. That's the tell that the sequencing is deliberate rather than accidental: India legislates early only where waiting for the harm to materialize would be too late to matter.
Worked example: pricing a compute subsidy
The Compute Capacity pillar is the largest single line in the IndiaAI Mission because GPU-hours, not talent, were the binding constraint on Indian AI research. As of the empanelment rounds through 2024 to 2026, MeitY reported an H100 GPU subsidized rate of ₹92 per GPU-hour for eligible researchers and startups, against an unsubsidized H100 rate from the same empanelled providers (Jio, Tata Communications, Yotta, E2E Networks and others among 14 empanelled firms) of ₹150 per GPU-hour (standard, non-H100 GPUs from the same providers bid as low as ₹115.85 per GPU-hour), itself already reported as 40 to 60% cheaper than commercial global cloud rates. We can use those two verified figures, the ₹150 unsubsidized H100 rate and a 40 to 60% discount versus global, to back-calculate a plausible global commercial benchmark: if ₹150 is roughly 50% cheaper than the global rate, the global rate is near ₹150 / 0.5 = ₹300 per GPU-hour (about $3.6 at ₹83/$1), consistent with commercial on-demand H100 pricing reported elsewhere. Note this ₹300 figure is our own back-calculated estimate, not a directly disclosed number, and is labeled as such.
Consider a startup fine-tuning a model on 8 H100 GPUs for 500 hours, 4,000 GPU-hours total.
# IndiaAI Mission compute economics: a 4,000 GPU-hour fine-tuning run
subsidized_rate = 92 # Rs per H100 GPU-hour, IndiaAI Mission empanelled + subsidised
unsubsidized_rate = 150 # Rs per H100 GPU-hour, same empanelled provider, no subsidy
global_rate = 300 # Rs per H100 GPU-hour, back-calculated commercial benchmark
gpu_hours = 8 * 500 # 8 GPUs x 500 hours each
cost_subsidized = gpu_hours * subsidized_rate
cost_unsubsidized = gpu_hours * unsubsidized_rate
cost_global = gpu_hours * global_rate
subsidy_per_run = cost_unsubsidized - cost_subsidized
savings_vs_global = cost_global - cost_subsidized
savings_pct = savings_vs_global / cost_global * 100
print(cost_subsidized, cost_unsubsidized, cost_global)
print(subsidy_per_run, savings_vs_global, round(savings_pct, 1))
Tracing it by hand: gpu_hours = 8 x 500 = 4,000. cost_subsidized = 4,000 x 92 = 368,000. cost_unsubsidized = 4,000 x 150 = 600,000. cost_global = 4,000 x 300 = 1,200,000. subsidy_per_run = 600,000 minus 368,000 = 232,000. savings_vs_global = 1,200,000 minus 368,000 = 832,000. savings_pct = 832,000 / 1,200,000 x 100 = 69.33..., which rounds to 69.3. So the two print statements output exactly 368000 600000 1200000 and 232000 832000 69.3: the subsidized run costs ₹3.68 lakh instead of an estimated ₹12 lakh on global commercial cloud, a saving of roughly 69%.
Now scale this to the whole Compute Capacity pillar. If the mission's full 10,000-GPU target ran at 60% utilization (a modeling assumption, not an official figure) across a year: 8,760 hours/year x 0.6 = 5,256 billable hours per GPU per year. The government's per-hour subsidy is ₹150 minus ₹92 = ₹58. Annual subsidy outlay = 10,000 GPUs x 5,256 hours x ₹58 = ₹3,048,480,000, or ₹304.85 crore per year. Over the mission's five-year window, that's roughly ₹1,524.24 crore, about 33% of the ₹4,563.36 crore Compute Capacity budget, leaving the remaining two-thirds to fund the capex and margin of the private empanelled partners who actually own the hardware. This is why the mission is structured as a public-private partnership rather than the government buying GPUs outright: the subsidy is a demand-side lever, cheaper per rupee of budget than taking on the capital risk and depreciation of owning tens of thousands of rapidly-obsoleting chips directly.
Active recall
Attempt each question before reading the worked answers that follow.
- Why does India use a sectoral, instrument-specific approach to AI governance instead of a single horizontal AI Act like the EU's? Is this an oversight or a stated design choice?
- The credit-scoring assistant from the opening scenario collects UPI transaction data, trains a scoring model, deploys via a WhatsApp chatbot, and issues automated lending decisions. Name the specific Indian instrument that governs each of those four stages.
- Explain the structural difference between the EU's "adequacy" model for cross-border data transfer and India's "negative list" model under DPDP Rule 15. What tradeoff does each represent?
- Using the code in the worked example, compute the total cost and subsidy for a 12-GPU, 800-hour training run (9,600 GPU-hours) at the same rates.
- Suppose MeitY raises the subsidized H100 rate from ₹92 to ₹115 per hour (matching the low end of the unsubsidized band), while the unsubsidized rate and the 10,000-GPU, 60%-utilization assumptions stay fixed. Recompute: (a) the cost of the original 4,000 GPU-hour run, (b) the subsidy per run, (c) the annual mission-wide subsidy outlay, and (d) what share of the five-year Compute Capacity budget that outlay represents.
- Given that the Delhi High Court's July 2026 interim ruling in ANI Media v. OpenAI found AI training to be "fair dealing" under Section 52 of the Copyright Act, how does this differ from the EU's approach of an explicit, legislated text-and-data-mining exception, and why might this matter for how confidently an Indian AI startup can plan around it?
Worked answers
1. It is a stated design choice, articulated repeatedly by MeitY since 2023: rather than classify AI systems by risk before deployment (as the EU does), India lets existing harm-specific laws, DPDPA for data misuse, IT Rules for deceptive content, sector regulators for financial or health harm, the Copyright Act for infringement, apply once a concrete harm is plausible. The single exception is the March 2024 labeling advisory, adopted ex-ante specifically because synthetic/deceptive content was judged too fast-moving to regulate only after harm occurred.
2. Data collection (UPI transaction history used for training): DPDPA 2023 and DPDP Rules 2025, consent and purpose limitation. Model development: Copyright Act, 1957, Section 52, if any third-party content was used in training or fine-tuning. Deployment via WhatsApp chatbot: MeitY's IT Rules due-diligence advisory, disclosure that the shopkeeper is talking to an AI system. Lending decision outcome: the sector regulator, here the RBI, via the FREE-AI framework's disclosure and accountability expectations for the partner NBFC, since the NBFC, not the AI vendor, is the RBI-regulated entity.
3. GDPR's adequacy model is a whitelist: personal data may leave the EU only to countries the European Commission has pre-approved as offering "adequate" protection, an affirmative, case-by-case determination. India's DPDP Rule 15 negative list flips the default: data may flow to any country unless the central government has expressly blacklisted it. The adequacy model trades away ease of data flow for stronger upfront assurance; India's negative list trades away that case-by-case assurance for lower friction on cross-border AI training pipelines and cloud usage, a choice that favors a country still building out its own hyperscale compute capacity and therefore reliant on foreign infrastructure.
4. gpu_hours = 12 x 800 = 9,600. cost_subsidized = 9,600 x 92 = 883,200. cost_unsubsidized = 9,600 x 150 = 1,440,000. cost_global = 9,600 x 300 = 2,880,000. subsidy_per_run = 1,440,000 minus 883,200 = 556,800. savings_vs_global = 2,880,000 minus 883,200 = 1,996,800, which is 1,996,800 / 2,880,000 x 100 = 69.33%, the same percentage as before, because the discount rates themselves didn't change, only the volume of GPU-hours scaled linearly.
5. (a) cost_subsidized_new = 4,000 x 115 = ₹460,000 (up from ₹368,000). (b) subsidy_per_run_new = (150 minus 115) x 4,000 = 35 x 4,000 = ₹140,000 (down from ₹232,000, a 39.7% cut in per-run subsidy). (c) Annual outlay = 10,000 GPUs x 5,256 hours x (150 minus 115) = 10,000 x 5,256 x 35 = ₹1,839,600,000 = ₹183.96 crore/year (down from ₹304.85 crore/year). (d) Over five years that's ₹919.80 crore against the fixed ₹4,563.36 crore pillar budget, about 20.2% (down from 33.4%). The ripple is not confined to the headline subsidy number: raising the subsidized rate by ₹23/hour shifts roughly ₹604 crore of budget headroom over five years away from covering researcher access and toward funding additional GPU procurement or capex, while simultaneously raising the effective compute cost every subsidized startup and lab faces by about 25% (92 to 115), a direct tradeoff between fiscal sustainability of the pillar and the affordability that justified creating it.
6. The EU's TDM exception is legislated: any AI developer training on copyrighted text or data in the EU can rely on a codified statutory right, subject to an opt-out rights holders can exercise, giving developers predictable, ex-ante legal certainty before they start training. India's fair-dealing finding in ANI v. OpenAI is a single interim ruling in a still-pending suit, with an open appeal window and no equivalent statutory footing; it signals how one bench is currently leaning, not a rule any future court or future case is bound to follow the same way. An Indian AI startup training on copyrighted news or literary content today is relying on judicial interpretation of a 1957 statute never written with machine learning in mind, which is a materially weaker and more reversible foundation to plan a business on than the EU's explicit legislative exception, even though both currently permit similar training activity in practice.
Think About It
Think about this: How would you explain ai governance: india's ai policy framework to a friend who has never seen a computer? What real-world analogy would you use? Imagine you had to build a system using these concepts — what would be your first step? Try this: before moving on, write down three things you learned and one question you still have.
Key Takeaways — Summary and Recap
Let us recap what we covered: the core ideas behind ai governance: india's ai policy framework, how they connect to real-world applications, and why they matter for your journey in computer science. Remember these key points as you move forward. For competitive exam preparation (CBSE, JEE, BITSAT), focus on understanding the WHY behind each concept, not just the WHAT.