The policy stack
AI policy in India is best understood as a stack. At the base are data and privacy rules such as the Digital Personal Data Protection Act. Above that sit platform obligations, cyber safety requirements, sectoral rules for finance/health/telecom, and government procurement norms.
The IndiaAI Mission adds a strategic layer: safe and trusted AI, datasets, compute, skilling, and ecosystem financing. Together, these signals shape how AI systems are built and deployed.
Recent governance materials also point toward a more institutional layer: inter-agency coordination, expert committees, safety testing capacity, and sector regulator involvement. Treat those materials as important signals, then verify the current status on MeitY, PIB, IndiaAI, and regulator sources.
What builders should care about
Builders should care about consent, data minimisation, model risk, content labelling, grievance workflows, security, logging, and sector-specific requirements. The exact burden depends on the product, data, user base, and regulated sector.
A consumer chatbot, medical diagnostic tool, fintech underwriting model, school assessment product, and internal HR assistant all face different risk surfaces.
How to read policy signals
Separate binding law from advisories, drafts, consultation papers, speeches, and media commentary. Each can matter, but they do not carry the same weight.
Look for dates, issuing authority, affected entities, required action, penalty or enforcement path, and whether a later clarification changed the meaning.