Skip to Content
OPINION

Notes from the Asia-Pacific region: India weighs AI legislation

India appears to be moving closer to a dedicated AI law as the government initiates stakeholder consultations and drafting work.

Published
Subscribe to IAPP newsletters

Contributors:

Shivangi Nadkarni

Senior Corporate Vice President - Digital Trust

Persistent Systems

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

As I write this, the monsoon is in full flow across much of India, and the country is preparing to celebrate its 80th Independence Day 15 Aug. For those of us tracking digital trust and governance, however, the past month has been less about reveling in the aroma of freshly wet earth that is the hallmark of this season and more about trying to keep pace with a rapidly evolving digital landscape.

The most consequential development has been the increasingly clear indication that India may be moving toward a dedicated law for artificial intelligence. I mentioned last month that Union Minister for Electronics and Information Technology Ashwini Vaishnaw signaled the possible need for fresh AI-specific legislation. What looked like an important statement of intent is beginning to see concrete action.

On 9 July, Ministry of Electronics and Information Technology Secretary S. Krishnan said the government would initiate discussions with different stakeholder groups and begin drafting AI regulation. This is significant because, as recently as December 2025, the stated preference had been to rely as far as possible on existing legislations, including the Information Technology Act, the Digital Personal Data Protection Act and intellectual property law.

Krishnan's latest statement indicates more than a routine consultation. It suggests the government is testing whether India's existing, largely technology-neutral legal framework is sufficient for the unique risks and functions of AI systems. The immediate steps identified are stakeholder discussions, gathering views through different groups and commencing a drafting exercise. The precise form of the proposed instrument, its scope and its relationship with existing legislation remain to be seen.  

There is also a wider exercise underway. Krishnan said approximately 762 suggestions were received from ministries on where and how AI could be applied following the India AI Impact Summit 2026. While this exercise is primarily about AI adoption rather than regulation, it is important because India's eventual governance framework will have to operate alongside rapidly expanding public-sector use of AI.  

This emerging legislative work sits on top of an institutional architecture India had already begun to put in place. The government issued principle-based AI Governance Guidelines and, in April 2026, constituted the AI Governance and Economic Group as a high-level inter-ministerial coordination body supported by a Technology and Policy Expert Committee. Under the IndiaAI Mission, the IndiaAI Safety Institute was also established to advance indigenous AI-safety research and develop India-relevant technical tools, evaluation approaches, standards and risk-assessment frameworks.  

The question for India is, therefore, no longer simply whether AI should be governed. It is how a central law may help lend some structure and clarity to a growing collection of principles, various institutional mechanisms, requirements of specific sectors and actions by courts — all without slowing innovation.

The ongoing Monsoon Session of Parliament, which commenced 20 July and goes until 13 Aug., has also provided a window into the government's thinking. Usually, an indication of how various policy and regulatory winds blow, Parliamentary questions tend to reveal details that broader policy announcements sometimes leave unanswered.  

One particularly important question from Member of Parliament Manish Tewari concerned whether generative AI systems and chatbot-based services qualify as "intermediaries" under the Information Technology Act and can consequently receive safe harbor protection. In response, Minister of State for Electronics and Information Technology Jitin Prasada said the answer depends on the nature of the service, the functions performed by the AI system and the applicable provisions of the IT Act and IT Rules. He also said the IT Act is technology-neutral and applies to computer resources and intermediaries irrespective of the technology involved, including AI.

Parliament also received a detailed progress report on the IndiaAI Mission's Safe & Trusted AI pillar. According to information released by the government in late July:

  • Thirteen Responsible AI projects are being supported across areas such as bias mitigation, explainability, privacy-preserving AI, deepfake detection and AI risk assessment.
  • Twenty indigenous, sovereign model proposals have been identified, comprising 12 large language models and eight small language models.
  • The government has sanctioned 93 lakh GPU hours across 237 supported projects.
  • A total of 686 fellowships has been awarded across 178 institutions.
  • Twenty-seven India Data and AI Labs have been established with work continuing on another 188.
  • Fifty-eight AI Centres of Excellence are being established with state and Union Territory governments and industry partners.

These figures show India is not merely building a policy framework, but an AI ecosystem across key pillars of infrastructure, models, applications, skills, safety research and evaluation.  

All in all, the parliamentary proceedings showcase an interesting dichotomy: India is promoting AI adoption at scale while simultaneously having to answer foundational legal questions about responsibility, intermediary status, safety and redress. The proposed AI law will have to connect these two tracks.

Children's online safety is another topic that received notable cross-party attention during the Monsoon Session with three private members' bills placed on the parliamentary agenda. Baijayant Panda's Safeguarding Healthy Internet Environments for Little Digital-Natives Bill proposes parental authorization for children below 13 to open social media or online gaming accounts, together with age checks, parental oversight features and additional responsibilities for platforms. 

Tewari's Online Child Safety Bill would require platforms to anticipate and reduce risks to children through the design and operation of their services. His bill also proposes strengthening enforcement actions and provision of assistance for those affected by online harm. A third proposal, listed in the Rajya Sabha by Kartikeya Sharma, seeks default protective settings for younger users and restrictions on their access to social media during specified nighttime hours.

These are proposals by individual parliamentarians rather than government legislation, and none are expected to be taken up. However, they show India is beginning to debate beyond age verification and parental permissions to questions of safer platform design, default protections, access controls, accountability and remedies. 

As the DPDPA's provisions concerning children move toward implementation, policymakers will need to consider not only how platforms determine whether a user is a child, but also how their services protect children once they are online.

Another set of discussions that ensued was about the goings-on between social media company Meta and MeitY. First was around WhatsApp's username functionality. MeitY's notices on the topic raised concerns about impersonation, phishing and so-called "digital arrest" scams. On 9 July, Krishnan said the government was still awaiting responses from WhatsApp and other platforms. The episode also triggered questions about whether intermediary safe-harbor provisions are being used, in effect, as a prelaunch product-approval mechanism.  

More serious concerns arose from investigations into paid advertisements involving child sexual abuse material on Meta's platforms. MeitY issued a notice to Meta. Subsequent research reported that AI-generated abusive advertisements continued to appear on Meta services even after the initial India-focused investigation. 

Meta's Chief Global Affairs Officer Joel Kaplan later conveyed the company's regret to IT Minister Vaishnaw. There were also reports in the media that Mark Zuckerberg had expressed regret over concerns involving child sexual abuse material, deepfakes and failures in the operation of Meta's platforms.

Meanwhile, WhatsApp has reportedly begun testing prompts, asking some Indian users to provide their birth date as it explores privacy-protective methods of confirming age. The test is occurring ahead of the full implementation of the DPDPA's requirements concerning children's personal data and verifiable parental consent.  

While the executive and legislative wings of the government consider future regulation, Indian courts continue to confront immediate questions involving AI training, copyright, synthetic media and platform responsibility. 

On 24 July, the Delhi High Court declined to grant Asian News International interim relief in its copyright proceedings against OpenAI. At this preliminary stage, the court found OpenAI's storage of ANI's literary works for training large language models was covered by the fair-dealing exception of the Copyright Act. It also found that ANI had not demonstrated that ChatGPT's outputs substantially reproduced its reports. 

The topic of deepfakes also returned to the Bombay High Court. On 5 Aug., the court directed social media platforms to remove identified deepfake and AI-generated material that falsely linked Union Minister Nitin Gadkari and his family with alleged impropriety surrounding an ethanol-blending program. 

The court also questioned why platforms lacked effective processes for addressing clearly abusive material without requiring affected individuals to seek judicial relief. The order adds to a growing body of cases in which courts are using existing protections relating to reputation, dignity, personality and intermediary responsibility to address synthetic-media harms in the absence of a dedicated deepfake statute.

And, finally, some numbers worth watching.

The past month produced data that brings out not only the promise but also the risks accompanying India's rapid adoption of AI. IBM's 2026 Cost of a Data Breach Report stated that the average organizational cost of a breach in India is at a record INR255 million. This is an increase of 15.9% over the previous year, with an average of 39,500 records compromised in each incident. 

Particularly strikingly, IBM classified 26% of malicious breaches in India as AI-generated. Yet only 32% of the Indian organizations surveyed reported extensive deployment of AI and security automation. Those without such automation incurred average breach costs of INR316 million, compared with INR213 million for organizations using it extensively.  

A different dimension of readiness emerges from Nasscom's first AI-Native Talent Index. Its study classified nearly 70% of India's early-career technology workforce as AI-proficient, but only around 23% as AI-native. The distinction deserves some attention: that widespread use of AI tools is not necessarily accompanied by the technical judgement, orchestration capabilities, independence and responsible-use practices required effectively to build and supervise AI systems.

Finally, privacy risks are also becoming embedded in everyday digital journeys. In a LocalCircles survey published in August, 77% of respondents to a question on online insurance said they had encountered interfaces that pushed them to disclose more personal information than intended. The same study reported high levels of repeated prompting, compulsory data submission, pricing discrepancies and cancellation difficulties. These are survey findings, but they underline why the discussion around dark patterns increasingly overlaps with privacy, consent and accountable product design.

And now I shall get back to that hot cup of chai that tastes extra special when sipped amid rains in the background.

This article originally appeared in the Asia-Pacific Dashboard Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here.
CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Shivangi Nadkarni

Senior Corporate Vice President - Digital Trust

Persistent Systems

Tags:

AI and machine learningAI governance

Related Stories