Regulations · India
AI REGULATION

India

DEVELOPING

India lacks dedicated AI legislation but is developing governance frameworks through NITI Aayog's responsible AI principles and the Digital India Act's AI provisions.

KEY LEGISLATION 4 laws
Digital India Act (proposed) PROPOSED
2024-01
Planned comprehensive digital legislation expected to include AI-specific governance provisions replacing the IT Act 2000
NITI Aayog Responsible AI Principles ENACTED
2021-07
Government think-tank principles covering fairness, reliability, safety, privacy, inclusiveness, transparency, and accountability in AI
Digital Personal Data Protection Act ENACTED
2023-08
Data protection law with implications for AI systems processing personal data of Indian citizens
MeitY Advisory on AI (withdrawn) DRAFT
2024-03
Short-lived advisory requiring government approval for AI model deployment, withdrawn after industry backlash
ANALYSIS

Regulatory Landscape

India’s approach to AI regulation has been characterized by ambiguity and shifting signals, reflecting tension between the government’s desire to position India as a global AI power and concerns about AI’s societal impacts in a country of 1.4 billion people. Despite being one of the world’s largest markets for AI deployment, India has no dedicated AI legislation, relying instead on a patchwork of existing laws and voluntary principles.

The government’s stated position has oscillated between embracing light-touch regulation to attract investment and considering more interventionist approaches. A March 2024 advisory from MeitY requiring government approval before deploying AI models in India was withdrawn within weeks after intense industry opposition, illustrating the volatility of India’s AI policy environment.

Current Framework

In the absence of AI-specific law, governance relies on several instruments. The Digital Personal Data Protection Act (DPDPA), enacted in August 2023, establishes data protection requirements affecting AI systems that process personal data of Indian residents. NITI Aayog’s Responsible AI principles, while non-binding, provide a normative framework referenced by government agencies and industry.

Sector-specific regulators exercise authority over AI applications within their domains. The Reserve Bank of India governs AI in financial services, SEBI regulates algorithmic trading, and the CDSCO oversees AI medical devices. This sectoral approach provides coverage for specific use cases but leaves gaps for cross-cutting AI governance.

IndiaAI Mission

The government’s IndiaAI Mission, launched with a budget of approximately $1.25 billion, focuses on building AI infrastructure (compute capacity), developing indigenous AI models, and fostering an AI startup ecosystem. The mission’s governance components include an AI safety framework and institutional mechanisms for responsible AI deployment, though these remain advisory rather than regulatory.

Industry Impact

India’s AI sector is among the world’s fastest-growing, with strengths in AI services, enterprise AI deployment, and a massive developer talent pool. Global companies from Google to Microsoft operate significant AI operations in India, while domestic companies like Reliance Jio, Infosys, and TCS are major AI deployers. The absence of heavy regulation is viewed by industry as a competitive advantage, though it creates uncertainty for companies building AI products for export to regulated markets.

What Comes Next

The Digital India Act, when finalized, is expected to include AI-specific provisions addressing high-risk deployments, deepfakes, and algorithmic transparency. However, the legislation’s timeline remains unclear. India is more likely to pursue a phased approach — beginning with voluntary guidelines and sector-specific measures before considering comprehensive legislation. The country’s participation in G20 AI governance discussions and bilateral technology agreements with the US and EU will influence the direction and pace of domestic regulation.