Skip links
AI regulations in India

AI Regulation in India: A Business Guide to MeitY’s 2026 Framework

As far as AI regulation in India is concerned, India now has an official government position on how artificial intelligence should be governed. The Ministry of Electronics and Information Technology (MeitY) has released the India AI Governance Guidelines, laying out ethical principles, safety standards and coordination mechanisms for AI use across sectors. The timing is not incidental — the release forms part of the government’s preparations for the AI Impact Summit 2026, which India is hosting in New Delhi, and comes as the country has become the second-largest user base globally for consumer AI tools like ChatGPT, behind only the United States.

For a corporate law practice advising founders, boards and compliance teams, the practical question is simple: what does “AI governance guidelines” actually require a business to do differently? The honest answer is that India has chosen a layered, non-statutory approach rather than a single sweeping AI law — which means the real compliance obligations are scattered across several existing instruments that the new guidelines now tie together.

Is there an AI law in India?

Not in the sense of one consolidated statute. India has not passed an EU AI Act-style horizontal law. Instead, AI regulation in India for business currently operates through a layered framework: MeitY’s advisories on self-certification and content labelling, the DPDP Act’s data-processing obligations, the IT Act and IT Rules’ platform-liability provisions, and sector-specific rules from regulators such as the RBI and SEBI. The AI Governance Guidelines discussed in this post function as the connective principles tying that framework together, rather than a new standalone offence-creating law. For businesses, that means “is this legal under Indian AI law” is rarely a single-instrument question — it’s a mapping exercise across several regulators at once, covered in detail below.

Unlike the EU’s AI Act, India has not passed one consolidated AI statute. Instead, the regulatory architecture rests on several pillars operating in parallel: MeitY’s advisories (including a March 2024 advisory requiring self-certification and content labelling for AI platforms), the Digital Personal Data Protection (DPDP) Act’s data-processing obligations, provisions of the IT Act and IT Intermediary Rules governing platform liability, and sector-specific rules layered on by regulators such as the RBI and SEBI. The new AI Governance Guidelines function as the connective tissue across this patchwork — a declared set of principles (safety, transparency, accountability, inclusiveness) that sector regulators and future rule-making are expected to align with, rather than a fresh set of standalone offences.

Commentators tracking the space describe 2026 as the year India’s “digital state infrastructure” formally aligned with the AI era: alongside the AI Governance framework itself, the year has also brought the finalisation of DPDP rules, a Competition Commission of India (CCI) market study on AI, an RBI framework for AI in financial services, and a DPIIT working group report specifically addressing the intersection of copyright and AI. Taken individually, none of these is a single “AI law.” Taken together, they represent a genuinely comprehensive — if fragmented — compliance surface.

What businesses are actually on the hook for?

Stripped of the policy language, three concrete obligations matter most to companies building or deploying AI in India today. Here are some AI regulations in India that businesses must deploy:

  • Labelling and self-certification: MeitY’s advisory framework requires AI platforms to self-certify compliance and, in defined circumstances, label AI-generated content — a direct response to the deepfake and synthetic-media harms discussed elsewhere in this series. Any product that generates images, audio or video needs a documented position on how (and whether) it labels synthetic output.
  • Data protection obligations under the DPDP Act: The DPDP Act imposes consent, purpose-limitation and security obligations on any processing of personal data — including data used to train or fine-tune AI models — with penalties that can run up to ₹250 crore for serious breaches. A live and still-unsettled tension here is that India’s consent-based model was not designed with large-scale AI training or text-and-data mining in mind, and policy experts have flagged this as an area likely to see further clarification.
  • Safe harbour is conditional: Under the IT Act, intermediaries generally enjoy safe harbour — protection from liability for user-generated content they merely host. But that protection is not unconditional: platforms that generate content, rather than simply hosting content created by users, risk losing Section 79 safe harbour protection altogether. For any business running a generative AI feature inside a broader platform, this is one of the more consequential — and least understood — compliance questions in the current framework.

Sector Regulators are Moving Independently & Faster

Two developments are worth flagging specifically because they show regulation arriving sector-by-sector rather than waiting for a horizontal AI law. The RBI’s FREE-AI framework — the Framework for Responsible and Ethical Enablement of Artificial Intelligence — was produced by a committee the central bank constituted in December 2024 and released its report in August 2025, setting out seven guiding principles and 26 recommendations spanning infrastructure, policy, skills, governance and consumer protection for AI use in banking and financial services. Separately, the CCI’s market study on AI signals that competition regulators are beginning to examine how AI-driven pricing, personalisation and platform dominance interact with existing competition law — a question that, until recently, had no regulatory home in India at all.

The IndiaAI Mission for Funding Alongside Regulation

It’s worth noting that India’s AI policy is not purely restrictive. The IndiaAI Mission is the government’s parallel push to build domestic AI capacity — the Union Budget for 2026-27 allocated ₹1,000 crore specifically toward developing sovereign foundational AI models, supporting AI startups, and building compute capacity, with a stated shift in focus from establishing new institutions to diffusing AI technology across sectors including data centres and education. For AI startups and founders, this dual posture — funding and capacity-building on one hand, layered compliance obligations on the other — is the defining feature of the current Indian approach: pro-innovation, but not laissez-faire.

Advice for Businesses

Given the absence of a single statute, we are advising AI-adjacent clients to treat compliance as a mapping exercise rather than a checklist against one law. That means: identifying every instrument that could apply to a given product (MeitY advisories, DPDP, IT Act/Rules, and any relevant sector regulator such as RBI or SEBI); documenting a defensible position on content labelling and data provenance before launch, not after a complaint; and building in a genuine legal review step whenever a product’s outputs could plausibly touch a real person’s identity, given the personality rights litigation trend covered elsewhere in this series. India’s AI governance approach remains, in the words of commentators tracking it, “far from settled” — which for businesses means the compliance bar is likely to keep moving, not stay fixed at today’s guidelines.

One area regulators and industry bodies are actively flagging as unresolved deserves particular attention from any business planning to train or fine-tune AI models on Indian user data: the DPDP Act’s consent-based architecture was drafted around conventional data processing, not the large-scale text-and-data mining that model training typically requires. Policy experts tracking this space have specifically warned that a strict, purpose-limited consent model sits awkwardly with how AI training data is actually sourced and reused. Until this tension is resolved through further rule-making or guidance, businesses building or fine-tuning models on Indian personal data should treat this as an active legal risk area, document the specific legal basis relied on for each training dataset, and avoid assuming that data lawfully collected for one purpose can be freely repurposed for model training without a fresh consent or a clearly applicable exemption.

What “Pro-Innovation but not Laissez-Faire” Looks Like in Enforcement Terms

It is worth being precise about what India’s current regulatory posture actually permits versus restricts. The government has explicitly chosen not to freeze AI development behind a horizontal licensing regime, and the IndiaAI Mission’s funding commitments make clear that capacity-building remains a policy priority. But “pro-innovation” has not meant hands-off: the deepfake-specific IT Rules amendment covered elsewhere in this series shows regulators are willing to move quickly and prescriptively the moment a concrete, demonstrable harm (as opposed to a theoretical one) is identified. For businesses, the practical reading is that broad AI experimentation remains permitted, but any feature touching identity, biometric data, or safety-critical decisions should be built assuming targeted, sector-specific rules will arrive faster than a general AI statute ever will.