The Ministry of Electronics and Information Technology (“MeitY”) has released the “India AI Governance Guidelines” with the stated objective of enabling Artificial Intelligence (“AI”) innovation while mitigating societal risks. These Guidelines recognize the dual-use nature of AI and propose a governance approach that prioritizes trust, safety, and responsible deployment over prescriptive regulation at this stage. The key guidelines and recommendations are as follows:
No Standalone AI Legislation
From a legal standpoint, the most important clarification is that MeitY does not currently propose a standalone AI legislation. Instead, the Guidelines confirm that existing Indian laws will continue to apply to AI systems, use-cases, models and deployments. Timely and consistent enforcement of current legal frameworks (including IT Act, criminal law, consumer law, DPDP Act, intellectual property laws, sectoral regulatory codes, etc.) is emphasized as the primary mechanism to address AI related harms.
Stricter Enforcement and Targeted Amendments
At the same time, MeitY acknowledges that certain existing laws may require targeted amendments to enable innovation and address identified gaps. Illustratively, the Copyright Act, 1957 may require amendments to support large scale AI model training while preserving rights of copyright holders and data principals. Similarly, amendments to the IT Act (particularly classification, liability and due diligence obligations for AI developers / deployers) are likely to be taken up to reflect the unique characteristics of AI systems.
Recommendations to Adopt Voluntary Frameworks
The Guidelines further encourage adoption of voluntary frameworks by industry to build trust, signal risk mitigation readiness and avoid premature compliance-heavy regimes. Such voluntary frameworks may, over time, evolve into mandatory baseline expectations as the ecosystem matures.
Transparency Across the AI Technology Stack
Transparency across the AI value chain (including models, datasets, stack components and deployment workflows) is also a priority. This directionally signals that regulators may evaluate and require more granular disclosures going forward, including provenance, training data provenance, risk mitigation methods and guardrails.
Key Legal Impact Areas and Outlook
While these Guidelines are not themselves legally binding, they materially influence policy direction, future rulemaking, amendments, regulator expectations and enforcement strategy. The following themes may become legally significant in the near term:
- Existing law enforcement will intensify on AI harms (especially fraud, harm to women and children, cyber misuse, disinformation, deepfakes, etc.)
- Classification and attribution obligations under amended IT Act frameworks may create new due diligence and liability pathways for developers vs deployers vs users
- Voluntary frameworks could become de facto risk mitigation baselines and later convert to enforceable compliance standards.
Additionally, the Guidelines signal development of an AI incident reporting framework and a national database for AI harm. This may lead to mandatory reporting in specific sectors or contexts in future, particularly for high-risk, safety-critical or public impact use cases.
Finally, content authentication and provenance mechanisms (including watermarking) are highlighted as a priority to counter malicious deepfakes. This directionally indicates that companies distributing AI-generated audio-visual content in India should expect new disclosure / labelling obligations in future.
Entities globally which develop, deploy, distribute, scale or integrate AI systems touching India should therefore expect Indian regulators to increasingly use existing laws, targeted amendments, and techno-legal verification tools to operationalize trust and safety expectations.