Countries / India
India
India has no AI-specific statute; it governs AI through principle-based MeitY guidelines, binding deepfake-labelling duties in the IT Rules, the phased DPDP privacy regime and sector regulators (RBI, SEBI, ICMR).
Latest developments in India
In force (8)
-
AI Governance Guidelines
Principle-based national framework built on seven 'sutras' (e.g. trust, people first, innovation over restraint) that relies on existing laws rather than a new AI statute. It recommends new institutions (an AI Governance Group, a Technology & Policy Expert Committee and an AI Safety Institute), voluntary industry measures, techno-legal tools and a national AI incident database.
In forceEffective 5 Nov 2025 -
IT Rules SGI/deepfake amendment
Defines 'synthetically generated information' (AI-made or altered audio/visual content that appears real) and requires intermediaries that enable its creation or sharing to prevent unlawful SGI, label it prominently and embed permanent metadata/unique identifiers. Significant social media intermediaries must collect user declarations on whether content is synthetic, verify them technically and label before publication; takedown timelines were cut (3 hours on government/court orders, 2 hours for non-consensual intimate imagery).
In forceEffective 20 Feb 2026 -
DPDP Act & Rules
India's horizontal data protection law, governing how 'data fiduciaries' (including AI developers and deployers) collect and process digital personal data, with consent, notice, security, breach-notification and data-principal rights. The DPDP Rules 2025 (notified 13/14 Nov 2025) operationalise it in phases: Data Protection Board provisions immediately, Consent Managers after 12 months and the main obligations after 18 months.
Partly in forceEffective 13 Nov 2025 -
RBI FREE-AI Framework
RBI committee report setting 7 'sutras' and 26 recommendations under six pillars for AI use by banks, NBFCs and other regulated entities, including board-approved AI policies, AI incident reporting, disclosure to customers and an AI innovation sandbox. It is a framework report, not binding directions.
In forceAdopted 13 Aug 2025 -
SEBI Reg 16C (AI responsibility)
Makes every SEBI-regulated person that uses AI/ML tools – whether built in-house or bought from third parties – solely responsible for investor data privacy and security, for the outputs of those tools, and for compliance with applicable law. Parallel amendments apply to stock exchanges/clearing corporations and depositories.
In forceEffective 10 Feb 2025 -
ICMR AI health ethics guidelines
Ethical principles and stakeholder responsibilities for developing, validating, deploying and adopting AI in biomedical research and healthcare in India, including ethics-committee review processes and informed-consent requirements for AI-based research.
In force -
IndiaAI Mission
National programme approved by the Union Cabinet with an outlay of ₹10,371.92 crore to build AI compute (subsidised GPU access via public-private partnership), datasets (AIKosh), foundation models, skills and 'Safe & Trusted AI' projects. By Feb 2026 the government reported over 38,000 GPUs onboarded.
In forceAdopted 7 Mar 2024 -
ANI v OpenAI (interim ruling)
The Delhi High Court refused ANI's application for an interim injunction against OpenAI, holding prima facie that storing ANI's articles to train the LLMs behind ChatGPT falls within the fair-dealing exception in Section 52(1)(a) of the Copyright Act and that ChatGPT's RAG-based outputs were not substantially similar to ANI's works. The findings are expressly prima facie; the substantive questions go to trial.
In forceEffective 24 Jul 2026
Proposed or in consultation (2)
-
Draft IT Rules Second Amendment
Draft rules that would make compliance with MeitY clarifications, advisories, directions, SOPs and codes of practice part of intermediaries' due-diligence duties (new Rule 3(4)), tied to safe-harbour. A revised draft of 21 Apr 2026 added a requirement for a continuous, clearly visible label on synthetically generated visual content for its full duration.
In consultationProposed 30 Mar 2026 -
RBI draft Model Risk Management guidance
Draft RBI guidance covering governance of all models, including AI/ML and generative AI, used by commercial and co-operative banks, NBFCs, all-India financial institutions, ARCs and credit information companies. It builds on the 2024 draft on credit-model risk and the FREE-AI report, addressing explainability, bias, drift, hallucination, human oversight and customer disclosure of AI use.
In consultationProposed 24 Jun 2026
What the rules require
Obligation types found across India's instruments. Filled dot: imposed by a binding instrument. Ring: guidance only.
Timeline
- ANI v OpenAI (interim ruling)Ruling issued
- RBI draft Model Risk Management guidanceOpened for consultation
- Draft IT Rules Second AmendmentOpened for consultation
- IT Rules SGI/deepfake amendmentTook effect
- DPDP Act & RulesTook effect
- AI Governance GuidelinesAdopted and took effect
- IT Rules SGI/deepfake amendmentProposed
- RBI FREE-AI FrameworkAdopted
- SEBI Reg 16C (AI responsibility)Took effect
- IndiaAI MissionAdopted
- DPDP Act & RulesAdopted