Notes from the Asia-Pacific region: AI ambitions, DPDPA compliance and new digital governance frameworks

India's digital governance landscape is rapidly evolving, with regulators advancing AI oversight, cyber resilience and digital competition initiatives, while reaffirming DPDPA compliance timelines.

Contributors:
Shivangi Nadkarni
AIGP
Senior Corporate Vice President - Digital Trust
Persistent Systems
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
It is already September and the start of the festival season in India. As I pen this, in the western part of India where I come from, we are gearing up for one of our most awaited festivals — Ganesh Chaturthi, honoring a beloved god. Celebrated in homes as well as in public spaces, the 10-day celebration is marked by lots of art, color, music, food and families and friends visiting each other.
Meanwhile, this last month has been busy. Between the end of the Monsoon Session of Parliament, the prime minister's Independence Day address that squarely put artificial intelligence at the heart of India's development story, and a full inbox of regulator circulars, the digital trust and governance space has hardly paused to catch its breath.
Let us start with an update on where we are on India's Digital Personal Data Protection Act, which is at the heart of every privacy related conversation in India. Time and again, the question of whether the compliance deadline would be extended or not rears its head. Once again, Ministry of Electronics and Information Technology Secretary S. Krishnan 14 Aug. told a Bengaluru consultation organized by the Startup Policy Forum that the notified DPDPA timelines will hold and no extension is being considered, amply reiterating there will be no reprieve.
Startups at the meeting raised familiar concerns — consent fatigue, breach notification thresholds, the treatment of legacy data and the use of personal data for training AI models. Krishnan emphasized the government's principle-based, risk-driven design of the DPDPA framework, urging companies to begin work now rather than defer. Given that the consent manager registration window opens 13 Nov. and full applicability of the act follows 13 May 2027, this signal from MeitY is important: build now, and build well.
Another very interesting development was the AI callout in the 80th Independence Day address by Prime Minister Narendra Modi 15 Aug. Spoken from the ramparts of the Red Fort in New Delhi, this address is usually extremely significant for the country. This year, Modi announced his vision for a Viksit Bharat, or developed India, by 2047 in the form of the "Sapt Dhara," or seven "streams of strength."
One of the seven streams is technology and innovation, wherein PM Modi named AI, quantum, space, robotics and data centers as areas where India should stop being merely a global market and instead become an innovation hub. He also pledged AI skill training for one crore, or 10 million, young Indians over the coming year, and seven to eight new semiconductor plants that are expected to come online within the next two years. This youth-and-infrastructure lens is beginning to pull adjacent policy conversations along with it — from AI skilling curricula and safety literacy to sovereign data center capacity.
Predictably, financial sector regulators have kept up the pressure on cyber resilience and AI oversight.
On 24 Aug., the Securities and Exchange Board of India officially published the IT Resilience Index for Market Infrastructure Institutions — exchanges, clearing corporations and depositories. The ITRI is a quantitative, board-owned score built on nine parameters, with availability and security carrying the highest weightage of 20% each.
MIIs must operationalize the framework — including an early warning system and continuous service-delivery monitoring — by 28 Feb. 2027, with the first half-yearly submission for the period ending 31 March 2027. Analysts have described the ITRI as one of the earliest attempts globally by a regulator to convert operational resilience into a comparable, board-level number, akin to capital adequacy for banks.
Days later, 31 Aug., Whole-Time Member of the SEBI Kompella Venkata Ramana Murty, addressing a Confederation of Indian Industry Interactive Session on Board Members and Independent Directors, told listed-company boards to treat material AI deployments as a board-level governance matter, not something confined to the technology, risk or compliance teams. He asked directors to be able to answer why AI is being used, what data it relies on, where human review is required, how dependent the company is on external providers and — most importantly — who is accountable when things go wrong.
Insurance is not being left behind either. On 1 Sept., the Insurance Regulatory and Development Authority of India, through the Insurance Information Bureau, released a consultation paper proposing a Public Insurance Registry, a consent-driven digital public infrastructure for insurance. Comments have been invited until 30 Sept. The paper explicitly frames the registry against DPDPA principles and India's other digital public infrastructures — like Aadhaar, UPI, DigiLocker, Ayushman Bharat Digital Mission and others — and includes a dedicated section on privacy, data protection and commercial confidentiality. If it proceeds, it will bring another major consumer sector into the DPI conversation, and with it a fresh set of data governance questions.
Digital competition remains a live conversation. The Parliamentary Standing Committee on Finance 10 Aug. tabled its 37th action-taken report on the earlier review of the Competition Commission of India and the digital landscape. It urged the government to finalize the Digital Competition Bill, add virtual assistants and cloud services to its scope, and issue an e-commerce code of conduct covering platform neutrality, algorithmic transparency and nondiscriminatory data access for smaller businesses.
The Ministry of Corporate Affairs has since said its ongoing market study on qualitative and quantitative thresholds, core digital services and impact on startups and micro, small and medium enterprises will shape a "balanced and forward-looking" framework. Given the overlap between competition, privacy and AI, this remains an important space to watch.
While regulators build ex-ante frameworks, courts continue to reach for existing personality-rights, copyright and intermediary-liability doctrines to address AI-driven harms. The Bombay High Court 2 Sept. returned to the earlier interim order in favor of Union Minister for Road Transport and Highways Nitin Gadkari over deepfake content wrongly linking him to the E20 ethanol-blending policy and directed the social media platform X to comply with the takedown, questioning why platforms lacked working processes to act on clearly abusive material without a court intervention.
August alone saw multiple courts issue similar orders for public figures including actress Shruti Haasan, educator Alakh Pandey, actresses Janhvi and Khushi Kapoor, businessman Acharya Balkrishna, actress and member of Parliament Jaya Bachchan and her granddaughter Aaradhya Bachchan, together with a District Court Chandigarh order against a morphed video of politician Sukhpal Singh Khaira — a striking indication of just how routine such disputes have become.
To wrap up, some fresh data offers a useful reality check on where India actually is in its AI, infrastructure and digital payments story.
Autodesk's 2026 AI Pulse report, released 20 Aug. at its State of Design & Make Summit India in Mumbai, put India ahead of the pack on almost every enterprise AI metric it tracks. Ninety-one percent of Indian organizations surveyed reported increasing AI spending over the past year — against 85% across APAC and 81% globally — and 63% are using AI assistants and chatbots, the highest adoption rate in the region.
The friction points, however, were unmistakably regulatory: 50% flagged regulatory uncertainty as the biggest barrier to scaling AI, 49% flagged the AI skills shortage, and 69% expected their organizations to adopt agentic AI within the next year — a compressed window in which DPDPA implementation, the pending AI-governance conversation and enterprise deployment will all be running in parallel.
The infrastructure side of the same story was captured in JLL's India data centre 2026 mid-year report , out on 31 Aug., which projected India's data center capacity to almost quadruple from 1.6 gigawatts in mid-2026 to 6 gigawatts by 2029, requiring about USD110 billion in capital expenditures and drawing more than USD50 billion in committed hyperscaler investment on the back of the Union budget's 20-year tax holiday for foreign cloud providers. The report is unusual in that it walks straight from the capacity numbers into a dedicated section on the DPDPA and its penalty regime, reminding operators and users that the same infrastructure boom will have to sit inside a rapidly hardening data-protection perimeter.
And on the retail payments layer that increasingly sits under everything else, the National Payments Corporation of India's 1 Sept. release recorded a new monthly high for transactions — 24.51 billion worth INR29.82 trillion in August alone, up roughly 22% year-on-year in volume and 20% in value. It is a useful reminder that whatever framework India ends up building on data protection, dark patterns and AI oversight will apply not to a market that might one day scale, but to one already operating well over 800 million transactions a day.
As Lord Ganesha, the remover of obstacles, prepares to arrive in our homes, one hopes he lends a hand — because for those of us working in India's digital trust and governance space, the pace of change is only likely to accelerate.
This article originally appeared in the Asia-Pacific Dashboard Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Shivangi Nadkarni
AIGP
Senior Corporate Vice President - Digital Trust
Persistent Systems
