Rules, risk, and governance

AI policy and regulation in India

India does not yet have a single horizontal AI law. The policy landscape is a stack of data protection, platform obligations, sector rules, responsible AI work, procurement norms, and mission-led standards.

Key takeaways

  • India's AI governance is currently sectoral and layered rather than one single AI Act.
  • DPDP matters whenever AI systems collect, process, infer, or expose personal data.
  • MeitY governance guidelines, IndiaAI safety work, and sector regulators can change deployment expectations quickly.
  • Track institutional signals such as AI governance groups, expert committees, safety institutes, and sector regulator guidance.
  • For compliance decisions, use this site as orientation and verify with official/legal sources.

The policy stack

AI policy in India is best understood as a stack. At the base are data and privacy rules such as the Digital Personal Data Protection Act. Above that sit platform obligations, cyber safety requirements, sectoral rules for finance/health/telecom, and government procurement norms.

The IndiaAI Mission adds a strategic layer: safe and trusted AI, datasets, compute, skilling, and ecosystem financing. Together, these signals shape how AI systems are built and deployed.

Recent governance materials also point toward a more institutional layer: inter-agency coordination, expert committees, safety testing capacity, and sector regulator involvement. Treat those materials as important signals, then verify the current status on MeitY, PIB, IndiaAI, and regulator sources.

What builders should care about

Builders should care about consent, data minimisation, model risk, content labelling, grievance workflows, security, logging, and sector-specific requirements. The exact burden depends on the product, data, user base, and regulated sector.

A consumer chatbot, medical diagnostic tool, fintech underwriting model, school assessment product, and internal HR assistant all face different risk surfaces.

How to read policy signals

Separate binding law from advisories, drafts, consultation papers, speeches, and media commentary. Each can matter, but they do not carry the same weight.

Look for dates, issuing authority, affected entities, required action, penalty or enforcement path, and whether a later clarification changed the meaning.

Questions this page answers

Does India have a dedicated AI law?

India does not currently operate through one dedicated AI law comparable to a single AI Act. AI is governed through data protection, platform rules, sectoral regulators, advisories, and mission-led responsible AI work.

Is DPDP relevant to AI?

Yes. DPDP is relevant when AI systems process personal data, including training, inference, profiling, personalisation, analytics, or user-facing outputs that depend on personal information.

Primary sources to verify

Related reading