AI Regulation in India.
No, India does not currently have a standalone, cross-sector AI law or general AI licensing regime. Its main AI-specific binding rule is a 2026 amendment to the Information Technology Rules, which requires online intermediaries to prevent, label, trace the origin of, and remove realistic synthetic audio, video, and audiovisual content. Other AI uses are governed by general privacy, cybersecurity, consumer-protection, and sector-specific rules, while most operational duties under the Digital Personal Data Protection framework are not generally due until May 13, 2027.
In force today3 instruments
Get the remaining 1 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.
Already subscribed? Unlock →
- The core operational provisions of the Digital Personal Data Protection Act and Rules are scheduled to begin applying on May 13, 2027, with some additional provisions scheduled for November 13, 2026.
- MeitY's April 21, 2026 draft amendments to the IT Rules would expand intermediary and digital-media compliance obligations beyond the already effective synthetic-media amendments.
- There is still no notified general AI Act or cross-sector framework covering model safety, risk classification, foundation-model duties or general-purpose AI licensing.
Pending and recent legislation3 measures
Live from the Global AI Policy Radar.
Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?
India has no standalone, cross-sector AI law or general AI licensing regime in force. The main AI-specific binding rule is the 2026 amendment to the IT Rules, which covers realistic synthetic audio, visual and audiovisual content and imposes duties on relevant intermediaries.
Who are the key regulators for AI?
CERT-In is the specifically identified authority for cybersecurity obligations, incident reporting, information requests and investigations under the IT Act. AI oversight also involves the authorities responsible for administering the IT Rules and the Digital Personal Data Protection framework, depending on the system and its use.
Which rules apply to AI systems today?
The 2026 amendments to the IT Rules apply to intermediaries that enable users to create, upload or share realistic synthetic media, including duties on prevention, labelling, provenance and takedown. CERT-In Directions apply to covered entities operating AI infrastructure or products, including incident reporting, 180-day log retention, time synchronisation and cooperation with investigations. The DPDP framework applies where AI systems process digital personal data within its scope, but most substantive obligations are not generally due until May 13, 2027.
What is coming next, and when?
The main scheduled development is the start of most substantive operational obligations under the DPDP framework, including notice, consent, processing duties and data-principal rights. These obligations are scheduled to take effect on May 13, 2027, which is 18 months after November 13, 2025.
What are the enforcement and penalty risks?
Enforcement is active for online content and cybersecurity, so intermediaries and covered AI companies face practical compliance and investigation risk under the IT Rules and CERT-In Directions. Risks include failures involving synthetic-content prevention, labelling, provenance, takedown, incident reporting, log retention or cooperation with information requests. The source does not specify penalty amounts or particular sanctions.
Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.