I. Introduction
Artificial intelligence (“AI”) has moved, within the span of a few years, from a laboratory curiosity to a general-purpose technology embedded in banking, healthcare, media, and the administration of justice itself. Regulators the world over have struggled to keep pace, but the contrast in approaches is instructive: the European Union has enacted the AI Act, a risk-tiered, horizontal statute; China has notified the Interim Measures for the Management of Generative Artificial Intelligence Services; and the United States continues to rely on executive orders and sectoral guidance in the absence of federal legislation.
India, notwithstanding its ambition to be a global leader in AI and the second-largest contributor to open-source AI projects worldwide, has, until very recently, had no AI-specific statute at all. This article maps the patchwork of existing law that has, faute de mieux, been pressed into service to govern AI in India, traces the first binding AI-specific rules notified in February 2026, situates India’s position against the regulatory choices made by other leading jurisdictions, considers what India might borrow from them in the way its Constitution-makers once borrowed from other constitutions, records what industry and civil-society voices are telling the government, and examines the government’s recently announced intention to draft a standalone AI law.
II. The Existing Patchwork
In the absence of a dedicated statute, AI-related harms in India continue to be addressed through general-purpose legislation never drafted with autonomous systems in mind. The Information Technology Act, 2000 remains the primary recourse: its provisions on identity theft, cheating by personation, violation of bodily privacy, and obscene or sexually explicit publication have been extended, awkwardly, to deepfakes and synthetic impersonation. The Bharatiya Nyaya Sanhita, 2023 supplements this with provisions on cheating, cheating by personation, public mischief, and defamation, while organised AI-enabled economic offences may attract section 111. The Digital Personal Data Protection Act, 2023 casts consent, security-safeguard, and breach-notification obligations on data fiduciaries, and requires “Significant Data Fiduciaries” to conduct algorithmic and data-protection impact assessments the closest India comes, today, to a bias-auditing mandate for automated systems.
A genuine, albeit narrow, advance came on 20 February 2026, when the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 entered into force. For the first time, Indian subordinate legislation defines “synthetically generated information,” imposes on intermediaries a due-diligence obligation to deploy automated tools against unlawful synthetic content, and mandates labelling and permanent provenance metadata for lawful synthetic content, on pain of losing safe-harbour protection. Significant, but the amendment binds only intermediaries dealing in synthetic media; it is not, and was never intended to be, a horizontal AI statute.
III. Copyright, and the First Judicial Word
The Copyright Act, 1957 does not recognise an artificial system as an “author,” leaving the ownership of AI-generated works in doubt, while its fair-dealing exception for private use and research has become the principal battleground for AI-training disputes. That battleground produced India’s first substantive judicial pronouncement on the question on 24 July 2026, when Bansal J of the Delhi High Court declined to grant ANI Media an interim injunction against OpenAI, holding, prima facie, that the temporary storage of ANI’s articles for the purpose of training ChatGPT fell within section 52(1)(a) of the Copyright Act. The Court found no evidence that the outputs in question predated the models’ training cut-offs or otherwise reproduced ANI’s protected expression, and expressly confined its findings to the interim stage, leaving the suit to be tried on merits. The ruling illustrates precisely the difficulty of regulation by judicial improvisation: a single Bench, applying a seventy-year-old exception never conceived with machine learning in view, has for now set the terms on which India’s courts will treat AI training — a question that, in the European Union, is answered by statute rather than by an interim order in a copyright suit.
IV. Soft Law and Sectoral Guidance
Filling the remaining space is a body of policy instruments that guide, but do not bind. NITI Aayog’s National Strategy for Artificial Intelligence (2018) and its Principles for Responsible AI (2021) articulate safety, fairness, and accountability norms grounded in constitutional values; the Ministry of Electronics and Information Technology’s India AI Governance Guidelines (November 2025) add a pro-innovation, seven-principle framework with phased implementation timelines. None of these carries the force of law. Certain sectoral regulators have moved further: the Reserve Bank of India’s FREE-AI Committee Report proposes twenty-six recommendations for AI use in banking and finance; the Competition Commission of India has published a study urging enterprises to self-audit AI systems for competition compliance; and the Supreme Court’s AI Committee released, for public consultation in June 2026, draft Regulations for Use of Artificial Intelligence in Courts, expressly prohibiting judicial outcomes based solely on algorithmic output. These are valuable but fragmentary interventions, each sui generis to its regulator, none interoperable with the others, and none capable of supplying the horizontal definitions of “high-risk” use or AI-specific liability that a general statute would provide.
V. Towards a Standalone Statute
The government’s position had, as recently as December 2025, been that the Information Technology Act and the Digital Personal Data Protection Act were adequate to the task. That position shifted on 3 July 2026, when the Secretary, MeitY, announced that multi-stakeholder consultations would commence towards a dedicated AI regulation, and again on 22 July 2026, when officials confirmed to the press that a standalone statute that is separate from the IT Act was being drafted, addressing consent for synthetic content, limits on the autonomy of agentic AI systems, regulatory sandboxes for high-risk applications developed in coordination with the Reserve Bank of India and the Securities and Exchange Board of India, and, critically, a liability framework for harms caused by AI models. No timeline for introduction of a Bill has been made public.
VI. How Other Leading Jurisdictions Are Responding
India’s hesitation is not universal. Four regulatory models are instructive. The European Union’s AI Act, the world’s first comprehensive horizontal AI statute, classifies systems by risk prohibiting social-scoring and manipulative AI outright, subjecting “high-risk” uses in healthcare, law enforcement, and critical infrastructure to documentation, human-oversight, and conformity-assessment obligations, and requiring general-purpose model developers to disclose training data summaries and testing results, with obligations placed principally on providers upstream in the value chain. China’s Interim Measures for the Management of Generative Artificial Intelligence Services take a licensing-and-content-control approach, requiring registration of generative-AI providers, alignment with “core socialist values,” and mandatory labelling of AI-generated content, reflecting a governance philosophy of centralised oversight. The United States, by contrast, has no federal AI statute at all; regulation proceeds through executive orders, agency guidance from bodies such as the Federal Trade Commission and the National Institute of Standards and Technology, and a growing patchwork of state legislation, producing a permissive, innovation-first but fragmented regime not unlike India’s own.
Two further examples sit closer to India’s own instincts. South Korea’s AI Basic Act, in force since 22 January 2026, became only the second comprehensive AI statute in the world; it imposes risk assessments and governance obligations on “high-impact” AI, mandatory watermarking of synthetic content, and enhanced obligations including compute-threshold triggers for the most powerful “high-performance” systems, while keeping penalties moderate during a one-year grace period so as not to reduce investment in the AI development. The United Kingdom, conversely, has deliberately declined to legislate a dedicated AI Act, choosing instead a non-statutory, principles-based framework in which existing sectoral regulators such as the Information Commissioner’s Office, the Financial Conduct Authority, Ofcom, and the Competition and Markets Authority among them apply five cross-sectoral principles (safety, transparency, fairness, accountability, and contestability) within their own remits, an approach expressly designed to avoid the compliance costs associated with the EU’s horizontal model. Between the EU’s codified maximalism and the UK’s regulator-led minimalism lies most of the available policy space; India, so far, has occupied ground closer to the UK’s, but without even the UK’s cross-sectoral “five principles” to bind its regulators together.
VII. What India Might Borrow: A Constitutional Analogy
India is, of course, no stranger to legislative borrowing. The Constituent Assembly did not draft the Constitution of India on a blank slate: it took fundamental rights from the American Bill of Rights, the parliamentary system of government from Westminster, and directive principles of state policy from the Irish Constitution, adapting each to Indian conditions rather than transplanting it wholesale. A standalone AI law could profitably be built the same way, not by adopting any single foreign model in full but by taking the provision best suited to each problem and fitting it into an Indian frame.
From the EU AI Act, India could borrow the risk-tiered taxonomy itself a horizontal classification of AI uses as prohibited, high-risk, limited-risk, and minimal-risk which would give the standalone statute a coherent spine that the present sector-by-sector approach lacks. From South Korea’s AI Basic Act, India could take the compute-threshold trigger for enhanced obligations on the most powerful “high-performance” systems, together with its calibrated, innovation-sparing penalty structure during an initial compliance window a model well suited to a jurisdiction, like India, anxious not to price domestic startups out of their own market. From the United Kingdom, India could take the discipline of binding cross-sectoral principles that every regulator such as the Reserve Bank of India, the Securities and Exchange Board of India, the Competition Commission of India, the Copyright Office would be statutorily required to apply within its own domain, which would cure the present problem of fragmentary, non-interoperable sectoral guidance identified in Part IV above. And from the regulatory-sandbox mechanisms already sketched in the RBI’s FREE-AI report and reportedly contemplated in MeitY’s own draft, India could formalise a single, statute-backed sandbox regime for high-risk applications, coordinated across financial, health, and public-sector use cases rather than left to individual regulators to each invent. What India need not import is China’s content-alignment and licensing model, which sits uneasily with the constitutional guarantee of free speech under Article 19(1)(a); nor the EU’s heaviest documentation burdens, which smaller Indian AI developers may struggle to absorb without the EU’s single-market scale to offset the cost.
VIII. Industry and Civil-Society Voices
The drafting exercise is not occurring in a vacuum; industry and civil society leaders have been vocal. At the India AI Impact Summit held in New Delhi in February 2026, OpenAI chief executive Sam Altman told assembled world leaders that the “world urgently needs” AI regulation and called for an international oversight body, warning that “centralisation of this technology in one company or country could lead to ruin.” Google DeepMind chief executive Demis Hassabis has separately proposed a FINRA-style, industry-led AI standards body, intended to let industry lock in self-regulatory norms before governments or the United Nations impose heavier rules from outside.
Domestic voices have pulled in a more cautious direction. Mishi Choudhary, founder of the Software Freedom Law Centre, India, has argued that India needs better regulatory oversight rather than a wholly new law, but that even a light-touch approach must impose concrete obligations on the developers to include safety and consumer-transparency measures, incident-reporting requirements, clarified privacy safeguards, protections for performers and deceased celebrities against unauthorised digital replication, election-integrity safeguards, and a bar on algorithmic discrimination against consumers on enumerated grounds. The government’s own IndiaAI Mission has, through its chief executive Abhishek Singh, repeatedly defended a “light-touch”, pro-innovation posture built around a non-binding “Seven Sutras” framework, aimed at preventing user harm without imposing ex-ante compliance burdens of the kind seen in the EU. The standalone statute now being drafted will have to reconcile these positions: global industry leaders asking for binding international coordination and liability clarity on one side, and a domestic ecosystem government and industry body alike anxious that anything resembling the EU’s compliance architecture could blunt India’s cost advantage in AI adoption on the other.
IX. Conclusion
India today governs artificial intelligence through improvisation: penal provisions drafted for a pre-AI time, a data-protection statute concerned chiefly with consent, a narrow deepfake-labelling rule, a seventy-year-old copyright exception stretched to cover model training, and a proliferating body of non-binding guidelines and sectoral advisories. That patchwork has, so far, functioned but at the cost of legal certainty for developers, deployers, and the individuals affected by AI-driven decisions alike, as the interim, provisional character of the ANI v OpenAI ruling itself demonstrates. The announcement of a dedicated AI statute is, therefore, a welcome and overdue development. Other jurisdictions have already made their choices the EU’s codified risk taxonomy, South Korea’s calibrated compute-threshold obligations, China’s licensing-and-content model, the UK’s regulator-led principles, the United States’ sectoral permissiveness and India, much as its Constitution-makers once did with foreign constitutional texts, is well placed to borrow selectively from each rather than copy any one wholesale. What remains to be seen is whether the legislation, when it arrives, will supply the horizontal risk-classification, accountability, and liability architecture that a general-purpose technology of this consequence demands, and will hold the balance industry leaders and domestic stakeholders alike are asking it to hold or whether it, too, will be confined to particular harms, leaving India’s courts and sectoral regulators to continue filling the gaps one interim order at a time.
Adv. Dhanajay shinde


