AI Computer Institute
Expert-curated CS & AI curriculum aligned to CBSE standards. A bharath.ai initiative. About Us

India's AI Regulation Path: Building Frameworks for AI

📚 AI Policy⏱️ 27 min read🎓 Grade 12
✍️ AI Computer Institute Editorial Team Updated: September 2026 CBSE-aligned · Peer-reviewed · 27 min read
Content curated by subject matter experts with IIT/NIT backgrounds. All chapters are fact-checked against official CBSE/NCERT syllabi.

A chatbot that does not know if it is allowed to answer

A fintech company running on the UPI rails wants to add a generative AI assistant inside its app. A user's Direct Benefit Transfer payment failed last night, and instead of routing her to a call centre queue, the assistant should explain why in plain Hindi or Kannada, using the transaction logs and the bank's failure codes. The underlying model is a fine-tuned open-weights LLM the company trained six weeks ago. It still hallucinates roughly one answer in twenty, invents plausible-sounding RBI clause numbers, and occasionally tells a user her money will arrive "within 2 hours" when the actual settlement window is T+1. The product team asks the obvious question: what law governs this?

There is no single answer, because India has not passed an "AI Act." A student who stops there concludes India simply has not gotten around to regulating AI yet. That conclusion is wrong, and it is wrong in an instructive way. India's approach is not the absence of a framework — it is a different kind of framework, built by attaching new AI-specific duties onto statutes that already exist, rather than writing one new statute that classifies every AI system by risk tier. Understanding how those attachments work, and where a real AI system like the DBT chatbot actually lands, is the subject of this chapter.

Two ways to build a regulatory framework

Compare two architectural choices a lawmaker can make when a new technology needs rules.

The vertical, single-instrument model. The European Union's Regulation (EU) 2024/1689, commonly called the AI Act, entered into force on 1 August 2024. It sorts every AI system into one of four tiers by what the system does: unacceptable-risk uses (such as social scoring by governments) are banned outright; high-risk uses (such as AI in hiring, credit scoring, or critical infrastructure) require a conformity assessment, a documented risk-management system, and human oversight before deployment; limited-risk uses (such as a chatbot) carry a transparency duty — tell the user they are talking to a machine; minimal-risk uses carry no obligation at all. One law, one classification test, one regulator's rulebook to satisfy per tier.

The horizontal, patchwork model. India instead reaches AI harms through statutes that were not written with AI in mind, plus a small number of AI-specific advisories layered on top. The Information Technology Act, 2000 already conditions an online platform's legal shield on due diligence. The Digital Personal Data Protection Act, 2023 (DPDPA) already regulates anyone processing personal data, regardless of whether a model is involved. The Ministry of Electronics and Information Technology (MeitY) then adds AI-specific tripwires by advisory rather than by a new Act of Parliament, because an advisory can be issued and revised in weeks, while a statute takes years. The tradeoff is exactly what you would expect: the EU's pyramid gives a company one test and legal certainty once it clears that test; India's patchwork gives regulators speed and sector-fit, at the cost of a company having to check several doors instead of one, and of the AI-specific rules carrying weaker legal force than a notified statute.

The rest of this chapter builds the actual patchwork — the specific doors — and shows how to work out, for a real system, which ones it walks through.

Gate 1: the safe-harbor due-diligence test

Section 79 of the IT Act gives an "intermediary" — any platform that hosts content supplied by someone else, which includes an app that displays AI-generated text to a user — a conditional exemption from liability for that content. The condition is due diligence, defined by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Rule 3(1)(b) lists categories of content a platform must make reasonable efforts to keep users from hosting, and several of these categories catch AI harms without ever using the word "AI": content that impersonates another person, content that is patently false and misleading, content that threatens public order. The original 2021 notification already included, in Rule 3(2)(b), a strict 24-hour takedown duty specifically for artificially morphed images of a person — a category that maps almost exactly onto deepfakes, in force from February 2021, years before "deepfake" was a headline word in India.

This gate is not static. In April 2023, an amendment added a government-run Fact Check Unit with power to flag government-related content as false, which platforms would then have to remove to keep their safe harbor. Comedian Kunal Kamra challenged the amendment, and in September 2024 the Bombay High Court struck it down as a violation of the free-speech guarantee in Article 19(1)(a). The episode is worth sitting with: it shows the patchwork model's real character. The executive can add a new due-diligence category to Rule 3 in weeks, without a parliamentary bill — that is the agility the model is designed for. But that same category can be tested and removed by a court in months, because it was built as a rule under a statute rather than as the statute itself. Speed and revisability come paired.

Gate 2: the AI-specific advisory

Gate 1 predates generative AI and only reaches it indirectly. MeitY closed part of that gap directly. On 1 March 2024, it issued an advisory requiring platforms to obtain the government's explicit permission before deploying an AI model in India that was still "under testing" or otherwise "unreliable," and to label such outputs and embed a traceable identifier. Industry pushed back — a permission requirement for every beta model would have throttled routine iteration — and on 15 March 2024 MeitY revised the advisory, dropping the permission requirement but keeping the core obligations: visibly label an under-testing or unreliable AI model's outputs, obtain the user's informed consent through a pop-up before they rely on it, and embed metadata that lets synthetic or AI-generated content be traced back to the tool that produced it.

Notice the legal texture here. Rule 3 is subordinate legislation notified under a statute — breaching it can cost a platform its Section 79 safe harbor, which is a real legal consequence. The March 2024 document is an advisory, not a notified rule; it has no penalty clause of its own. Its teeth come from the same mechanism as Gate 1: MeitY frames "did the platform follow the advisory" as evidence of whether it exercised due diligence under Rule 3, so ignoring the advisory becomes a Gate-1 problem even though the advisory itself is soft law. This is a second recurring feature of the patchwork: a fast, revisable instrument (advisory) is made enforceable by wiring it to a slower, harder one (the Rules) rather than by giving it independent force.

Gate 3: the data-fiduciary escalation

Most AI systems worth regulating also process personal data, so the DPDPA, 2023 attaches independently of what Gates 1 and 2 decide. Every entity that determines the purpose and means of processing personal data is a "Data Fiduciary" and owes baseline duties — collect only what is necessary, get consent, do not repurpose data silently. Section 10 lets the Central Government notify a Data Fiduciary, or a class of them, as a "Significant Data Fiduciary" (SDF), and the Act lists the factors that inform that decision: the volume and sensitivity of personal data processed, the risk to a data principal's rights, the potential impact on India's sovereignty and integrity, risk to electoral democracy, security of the State, and public order. An SDF carries heavier obligations than an ordinary fiduciary — appointing a India-based Data Protection Officer, appointing an independent data auditor, and periodically running a Data Protection Impact Assessment. Notice what the Act does not do: it does not fix a single numeric threshold (say, "10 million users") in the statute itself. It names the factors and leaves the government to designate fiduciaries or classes against them. That is the DPDPA choosing the same horizontal, factor-based design philosophy Gates 1 and 2 use, rather than importing the EU's bright-line tiering.

Gate 4: the sectoral regulator

The three gates above are horizontal — they apply regardless of what industry an AI system sits in. A fourth gate is vertical: if the deployer is already a regulated entity, its sectoral regulator's existing model-risk and IT-governance obligations attach on top, independently of MeitY or the DPDPA. A bank running an internal fraud-scoring model answers to the Reserve Bank of India's IT-governance and model-risk-management expectations for regulated entities, whether or not the model uses AI at all — the same way a stockbroker's algorithmic trading system answers to SEBI. This gate rarely shows up in "AI policy" discussions because it is not AI-specific; but for a very large share of consequential AI deployments in India — banking, insurance, telecom, capital markets — it is the gate that actually bites hardest, because it comes with board-level accountability and an established supervisory relationship, not just a labeling duty.

Mapping the four gates

How one AI system picks up regulatory obligations in India Four independent attachment gates, not one risk pyramid AI SYSTEM (chatbot, scorer, generator, ranker) GATE 1 · SAFE HARBOR IT Act Section 79 + IT Rules 2021, R.3(1)(b) Trigger: platform hosts AI-generated or user content (misinfo, impersonation, deepfakes) GATE 2 · AI ADVISORY MeitY Advisory, 1 & 15 Mar 2024 Trigger: generative AI model still under testing or flagged unreliable, used by the public GATE 3 · DATA FIDUCIARY DPDP Act 2023, Section 10 (SDF) Trigger: processes personal data; scale / sensitivity crosses Significant-Fiduciary factors GATE 4 · SECTOR RULES RBI / SEBI / sectoral IT & model-risk norms Trigger: deployed by a regulated entity (bank, broker, insurer, telecom, etc.) OBLIGATIONS IF TRIGGERED Takedown on actual knowledge / court order; safe harbor conditional OBLIGATIONS IF TRIGGERED Visible unreliable / AI-generated label + consent pop-up, metadata OBLIGATIONS IF TRIGGERED Baseline: consent, purpose limitation If SDF: DPO, DPIA, audit OBLIGATIONS IF TRIGGERED Model-risk management, board sign-off, sectoral circular reporting COMBINED OBLIGATION SET = union of every gate this specific system triggers Illustrative risk-tiering score R for three deployments (0-10 scale) (a compliance-team triage heuristic, not a government formula) A · Bank fraud model 6.85 B · Govt scheme chatbot 6.15 C · Deepfake video app 6.55 0 2 4 6 8 10 R (weighted risk-tiering score)

Worked example: scoring three Indian AI deployments

A compliance team at a company running several AI products cannot manually walk every product through all four gates every week. In practice, teams like this build an internal triage heuristic — a rough score that decides which products get a full legal review first. This is not any government's formula; India has no statute that scores AI systems this way. It is exactly the kind of practical tool the patchwork model forces companies to invent for themselves, because no single official classification exists to lean on. Building one, and then testing where it breaks, teaches the patchwork's real shape better than reading about it does.

Score four inputs, each 0 to 10: Scale (how many people the system reaches), Data sensitivity (how sensitive the personal data it touches is), Harm potential (how bad a wrong or malicious output could be), and Immaturity (how far the underlying model is from validated and stable — 0 is a mature production model, 10 is an untested experimental one). Combine them with weights that reflect a simple judgment: scale and data sensitivity matter most because they set the ceiling on how many people a failure touches, harm potential matters next, and model immaturity matters least on its own, since a mature model behind a low-scale, low-sensitivity product is still low risk.

def regulatory_score(scale, data_sensitivity, harm_potential, immaturity):
    """
    Each input is 0-10. Returns a single triage number R, 0-10.
    Internal heuristic only -- not a government formula.
    """
    weights = (0.35, 0.30, 0.25, 0.10)
    values = (scale, data_sensitivity, harm_potential, immaturity)
    return round(sum(w * v for w, v in zip(weights, values)), 2)

def tier(r):
    if r < 3:
        return "minimal"
    elif r < 6:
        return "moderate"
    elif r < 8:
        return "elevated"
    else:
        return "significant"

cases = {
    "A: bank fraud-scoring model": (9, 9, 4, 0),
    "B: govt scheme chatbot":      (6, 5, 7, 8),
    "C: deepfake video app":       (8, 3, 9, 6),
}

for name, params in cases.items():
    r = regulatory_score(*params)
    print(name, r, tier(r))

Trace it by hand before trusting the print statement. Case A, the bank's internal fraud-scoring model: scale 9 (it screens transactions for a bank with a nationwide UPI footprint), data sensitivity 9 (Aadhaar-linked identity and financial data), harm potential 4 (a false positive blocks a transaction, unpleasant but not a misinformation harm), immaturity 0 (years in production, extensively validated). 0.35(9) + 0.30(9) + 0.25(4) + 0.10(0) = 3.15 + 2.70 + 1.00 + 0.00 = 6.85. Case B, the government welfare chatbot from the opening scenario, generalised: scale 6 (state-wide reach), data sensitivity 5 (personal but not biometric), harm potential 7 (wrong eligibility information hurts vulnerable citizens directly), immaturity 8 (explicitly a beta foundation model). 0.35(6) + 0.30(5) + 0.25(7) + 0.10(8) = 2.10 + 1.50 + 1.75 + 0.80 = 6.15. Case C, a consumer face-swap app: scale 8 (viral consumer reach), data sensitivity 3 (mostly voluntarily uploaded photos), harm potential 9 (non-consensual synthetic content, impersonation, electoral misuse), immaturity 6 (a maturing product on a still-evolving model). 0.35(8) + 0.30(3) + 0.25(9) + 0.10(6) = 2.80 + 0.90 + 2.25 + 0.60 = 6.55. The loop prints exactly these three totals, each tagged "elevated," since all three fall between 6 and 8.

Now check the heuristic against the actual gates, and this is the point of the exercise: the score alone does not tell you which obligations attach. Case A never touches Gate 2, because it is not generative and not user-facing — its "elevated" score routes it to Gate 4 (RBI model-risk norms) and Gate 3 (DPDPA, likely SDF-adjacent given the identity and financial data), never to a MeitY labeling duty. Case C sits squarely inside Gate 1's impersonation and morphed-image categories and Gate 2's synthetic-content labeling, but barely touches Gate 3, since it holds little sensitive data. Two systems with nearly identical scores face almost entirely different rulebooks, because India's gates trigger on what a system is, not on where it lands on a single axis. That is the load-bearing difference between a patchwork and a pyramid, made concrete.

DimensionEU AI Act (vertical pyramid)India's patchwork (horizontal)
Classification basisSingle risk tier per use case, fixed by the ActIndependent triggers per statute: content-hosting, model reliability, data volume/sensitivity, sector
Primary instrumentOne regulation, Parliament-levelIT Act 2000 sections + Rules + advisories + DPDPA + sector circulars
Update mechanismAmend the Regulation (slow)Revise an advisory or Rule (fast; MeitY revised its own advisory in two weeks in March 2024)
Legal force of the newest AI-specific layerStatutory, penalties defined in the ActAdvisory (soft law), enforced indirectly via safe-harbor conditionality
Judicial check demonstratedCourt challenges to specific Article provisions, ongoingBombay HC struck down the Rule 3 Fact Check Unit amendment, Sept 2024

Correcting a misconception

The misconception worth naming directly: "India has no AI regulation because it has not passed an AI Act." This is the mistake of judging a framework by whether it looks like the one instrument you already know. India regulates a meaningful share of AI harms today, through mechanisms that predate the phrase "generative AI" — a platform can lose its Section 79 safe harbor over AI-generated impersonation content right now, and a data fiduciary training on personal data owes DPDPA obligations right now, with no new statute required for either. What is actually true, and more useful than "no regulation," is a narrower and more defensible criticism: the patchwork is fragmented. A compliance team must check four separate doors instead of one, the newest and most AI-specific layer (the MeitY advisory) carries weaker legal force than the older layers it depends on, and a system that slips between all four gates — reaching real people, doing real harm, but not quite an "intermediary," not quite processing "personal" data, not quite reaching SDF-scale, not quite in a regulated sector — currently faces no dedicated AI obligation at all. That gap, not a blanket absence of law, is the honest critique to raise.

Active recall

Attempt each question before reading its answer.

1. Why does India's approach condition an AI-generative platform's legal shield on due diligence under Section 79 and Rule 3(1)(b), rather than banning or licensing high-risk AI uses outright the way the EU Act does for its top tier?

2. A cricket-analytics app generates AI player-form predictions and injects them into live match commentary, tagged "beta." It collects no personal data beyond anonymous app-usage stats, but reaches tens of millions of users during IPL matches, and a wrong prediction could shape betting behaviour. Score it: scale 7, data sensitivity 1, harm potential 5, immaturity 9. Compute R and its tier, and say which gates plausibly apply.

3. What is the practical legal difference between the IT Rules 2021 (notified under Section 79(2)(c)) and the March 2024 MeitY advisory, given that both concern AI-adjacent content?

4. The state government scales up the welfare chatbot from Case B nationwide, integrating it with Aadhaar-linked bank accounts for direct benefit transfer, after six months of testing during which the model is formally validated. New inputs: scale 9, data sensitivity 8, harm potential 7, immaturity 1. Recompute R and trace, gate by gate, exactly which obligations lift and which tighten.

5. In September 2024 the Bombay High Court struck down the 2023 amendment that gave a government Fact Check Unit power to flag content about the government as false under Rule 3. What does that episode reveal about the tradeoffs of building a framework through subordinate rules rather than a parliamentary statute?

6. Case A (the bank fraud-scoring model, R = 6.85) and Case C (the deepfake app, R = 6.55) score almost identically, yet face almost entirely different rulebooks in practice. Why doesn't the numeric score alone determine which obligations attach, in a way that it more nearly would under the EU's tiered system?

Answers

1. An outright ban or licensing regime requires the regulator to enumerate every high-risk use case in advance, which a fast-moving technology quickly outruns. Conditioning the safe harbor on due diligence instead lets the same rule reach any new AI-generated harm that fits an existing category — impersonation, misinformation, morphed images — without Parliament naming "AI" at all. The cost is that the rule was never designed around AI's specific failure modes (hallucination, scale of automated generation), so it catches AI harms only when they happen to resemble harms the Rules already named for human-posted content.

2. R = 0.35(7) + 0.30(1) + 0.25(5) + 0.10(9) = 2.45 + 0.30 + 1.25 + 0.90 = 4.90, tier "moderate." Gate 1 applies at baseline, since the app generates and hosts AI content viewed by users, and a materially wrong prediction stated as fact could be read as "patently false and misleading" information. Gate 2 applies because immaturity is high (9) and the model is explicitly beta and public-facing, so the labeling and consent-pop-up duties attach even though the overall score is only "moderate." Gate 3 does not meaningfully apply, since data sensitivity is 1 — no personal data of consequence is processed. Gate 4 does not apply; a cricket app is not a regulated financial or sectoral entity. The score, correctly read, does not by itself decide Gate 2's applicability — immaturity alone does, which is worth noticing.

3. The IT Rules 2021 are subordinate legislation notified under Section 79(2)(c) of the IT Act; failing to comply can cost a platform its Section 79 safe harbor, a concrete legal consequence tested in court (as the Fact Check Unit litigation shows). The March 2024 document is an advisory: MeitY issued and revised it without notifying it as a Rule, so it carries no independent penalty clause. Its practical force comes only from MeitY treating compliance with it as evidence of Rule 3 due diligence — soft law riding on the back of hard law, not an independent source of liability.

4. R = 0.35(9) + 0.30(8) + 0.25(7) + 0.10(1) = 3.15 + 2.40 + 1.75 + 0.10 = 7.40, still "elevated," in fact higher than before (6.15 to 7.40) despite the model becoming far more mature. Trace it gate by gate rather than trusting the aggregate number: Gate 2's specific triggers (under-testing / unreliable) actually weaken, since immaturity fell from 8 to 1 — the mandatory "may be unreliable" label and consent pop-up are no longer clearly warranted on reliability grounds alone. Gate 1 still applies unchanged, since the platform still hosts AI-generated content reaching the public. Gate 3 tightens sharply: adding Aadhaar-linked bank-account data for DBT pushes data sensitivity from 5 to 8 (identity plus financial data) and scale from 6 to 9 (national reach), both squarely inside the DPDPA Section 10 factors for Significant Data Fiduciary designation, so DPO appointment, an independent audit, and a formal DPIA become the live question, not model reliability. The aggregate score rising is almost coincidental; what matters for compliance is that the reason for the elevated score shifted entirely from one gate to another, and a team that only tracked "R went up" without re-checking each gate would keep the wrong obligation (the labeling duty) and miss the one that now actually applies (the DPDPA audit duty).

5. It shows both halves of the patchwork's design in one episode. The speed half: the executive added an entirely new due-diligence category (a government fact-checking gate) to Rule 3 through a routine amendment, without needing a parliamentary bill — exactly the agility the horizontal model is built for. The accountability half: because that category was added as a rule under a statute rather than as primary legislation carrying its own constitutional insulation, it was vulnerable to a straightforward Article 19(1)(a) challenge, and a High Court removed it within about a year and a half of notification. A framework built this way is genuinely faster to extend than a single Act would be, and genuinely easier to correct when an extension overreaches — the same structural feature produces both properties.

6. Because India's gates are triggered by what kind of activity a system performs, not by where a single continuous score places it. Case A is an internal decisioning tool inside a regulated bank: it does not host content to the public (so Gate 1 is largely irrelevant), it is not generative or user-facing (so Gate 2 does not apply), and its dominant gate is Gate 4, the RBI's sectoral model-risk regime, plus Gate 3 given the sensitive data involved. Case C is a public consumer app that manufactures synthetic likenesses of real people: it sits inside Gate 1's impersonation and morphed-image categories and Gate 2's synthetic-content labeling almost by definition, while barely touching Gate 3 or Gate 4. A single EU-style tier would flatten that distinction into one number and one rulebook; India's gate-by-gate design keeps the distinction, at the cost of requiring a compliance team to check every gate individually rather than reading one classification off a table. The numeric heuristic built earlier in this chapter is a useful triage tool for deciding which gates to check first — it is not, and cannot be, a substitute for checking them.

Think About It

Think about this: How would you explain india's ai regulation path: building frameworks for ai to a friend who has never seen a computer? What real-world analogy would you use? Imagine you had to build a system using these concepts — what would be your first step? Try this: before moving on, write down three things you learned and one question you still have.

Key Takeaways — Summary and Recap

Let us recap what we covered: the core ideas behind india's ai regulation path: building frameworks for ai, how they connect to real-world applications, and why they matter for your journey in computer science. Remember these key points as you move forward. For competitive exam preparation (CBSE, JEE, BITSAT), focus on understanding the WHY behind each concept, not just the WHAT.

← EU AI Act: Europe's Comprehensive AI RegulationResponsible AI Deployment: From Research to Production →

Found this useful? Share it!

📱 WhatsApp 🐦 Twitter 💼 LinkedIn