← Global AI Policy Radar · Methodology
Jurisdiction Baseline · AI × Policy

AI Regulation in India.

At a glance
AI-Specific Law
No standalone AI law or licensing regime
Synthetic Media
2026 rules require labels, provenance and takedowns
Data Protection
Core obligations begin applying May 13, 2027
Cybersecurity Duties
Report incidents and retain logs for 180 days

No, India does not currently have a standalone, cross-sector AI law or general AI licensing regime. Its main AI-specific binding rule is a 2026 amendment to the Information Technology Rules, which requires online intermediaries to prevent, label, trace the origin of, and remove realistic synthetic audio, video, and audiovisual content. Other AI uses are governed by general privacy, cybersecurity, consumer-protection, and sector-specific rules, while most operational duties under the Digital Personal Data Protection framework are not generally due until May 13, 2027.

In force today3 instruments
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended in 2026 in forceAI-specific
The February 20, 2026 amendments define synthetically generated information and impose AI-specific duties on intermediaries that enable users to create, upload or share realistic synthetic media. Relevant companies must use reasonable technical measures to prevent unlawful synthetic content, and significant social media intermediaries must obtain user declarations, verify them and display prominent labels and provenance information.
Content moderationDisclosureAI / automated decisions
Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 partially in force
The framework governs digital personal data used to train, fine-tune, operate or monitor AI systems where the processing falls within its scope. Institutional and certain administrative provisions are already effective, but most substantive obligations, including notice, consent, processing duties and data-principal rights, are scheduled to take effect 18 months after November 13, 2025, on May 13, 2027.
Data processingMinorsDisclosure
Unlock the full baseline

Get the remaining 1 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.

Already subscribed? Unlock →

CERT-In Directions under section 70B of the Information Technology Act, 2000 in force
The directions apply as relevant to companies, service providers, intermediaries, cloud providers and other covered entities operating AI infrastructure or products in India. They require incident reporting to CERT-In within prescribed timelines, retention of ICT logs for 180 days, time synchronisation, and cooperation with information requests and investigations.
Safety & securityData processing
Also worth noting
  • The core operational provisions of the Digital Personal Data Protection Act and Rules are scheduled to begin applying on May 13, 2027, with some additional provisions scheduled for November 13, 2026.
  • MeitY's April 21, 2026 draft amendments to the IT Rules would expand intermediary and digital-media compliance obligations beyond the already effective synthetic-media amendments.
  • There is still no notified general AI Act or cross-sector framework covering model safety, risk classification, foundation-model duties or general-purpose AI licensing.
Pending and recent legislation3 measures
IN constitution-of-ai-governance-and-economic-group-aigeg-reg Constitution of AI Governance and Economic Group (AIGEG)
Passed · 2026-04-16
A MeitY order establishes the AI Governance and Economic Group (AIGEG), a government body focused on AI governance and economic policy. The item is listed on MeitY’s Orders and Notices page.
IN eGazette 269993 Gazette Notification dated 10.02.2026, IT Rules 2021 Amendments, Synthetically Generated Information (SGI)
Passed · 2026-02-26
This MeitY notification amends India's Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, to regulate synthetically generated information, including intermediary obligations concerning synthetic or AI-generated content. The notified amendm
IN XIII/2026 The Artificial Intelligence (Human Health and Medical Education) Regulation Bill, 2026 (XIII/2026)
Introduced · 2026-02-06
A private member's bill proposing regulation of artificial intelligence in human health and medical education. It was introduced in the Rajya Sabha and is pending.

Live from the Global AI Policy Radar.

Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?

India has no standalone, cross-sector AI law or general AI licensing regime in force. The main AI-specific binding rule is the 2026 amendment to the IT Rules, which covers realistic synthetic audio, visual and audiovisual content and imposes duties on relevant intermediaries.

Who are the key regulators for AI?

CERT-In is the specifically identified authority for cybersecurity obligations, incident reporting, information requests and investigations under the IT Act. AI oversight also involves the authorities responsible for administering the IT Rules and the Digital Personal Data Protection framework, depending on the system and its use.

Which rules apply to AI systems today?

The 2026 amendments to the IT Rules apply to intermediaries that enable users to create, upload or share realistic synthetic media, including duties on prevention, labelling, provenance and takedown. CERT-In Directions apply to covered entities operating AI infrastructure or products, including incident reporting, 180-day log retention, time synchronisation and cooperation with investigations. The DPDP framework applies where AI systems process digital personal data within its scope, but most substantive obligations are not generally due until May 13, 2027.

What is coming next, and when?

The main scheduled development is the start of most substantive operational obligations under the DPDP framework, including notice, consent, processing duties and data-principal rights. These obligations are scheduled to take effect on May 13, 2027, which is 18 months after November 13, 2025.

What are the enforcement and penalty risks?

Enforcement is active for online content and cybersecurity, so intermediaries and covered AI companies face practical compliance and investigation risk under the IT Rules and CERT-In Directions. Risks include failures involving synthetic-content prevention, labelling, provenance, takedown, incident reporting, log retention or cooperation with information requests. The source does not specify penalty amounts or particular sanctions.

Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.

Need a company-specific assessment? Explore Nomos →