By: Amuthalakshmi.N
Assistant professor VISTAS UNIVERSITY
B.B.A.LL.B (HONS) VISTAS UNIVERSITY
I. INTRODUCTION
India has taken a deliberate and, in comparative terms, unusual regulatory stance on artificial intelligence: it has chosen not to legislate. Where the European Union has enacted a comprehensive, risk-tiered statute in the Artificial Intelligence Act, and several other jurisdictions are moving toward binding AI-specific legislation, the Government of India has opted for a lighter, principle-based architecture built on existing law, sectoral regulation and voluntary compliance.1 This position was formalised on 5 November 2025, when the Ministry of Electronics and Information Technology ("MeitY") released the India AI Governance Guidelines, the product of a multi-year, multi-stakeholder consultation that began with a 2023 sub-committee report and a January 2025 draft that drew more than 2,500 public submissions.
The Guidelines rest on a single, explicit premise: that a 'substantial portion' of AI-related risk can be managed within India's existing legal framework the Information Technology Act 2000, the Digital Personal Data Protection Act 2023, the Copyright Act 1957, and sectoral regulation by the Reserve Bank of India ("RBI") and the Securities and Exchange Board of India ("SEBI") with targeted amendments only where genuine gaps are found.2 This article evaluates that premise. It argues that India's innovation-first, techno-legal approach is coherent and defensible at this stage of AI adoption, but leaves at least three areas copyright and AI training, synthetic media, and cross-sectoral accountability for algorithmic harm in continuing legal uncertainty that recent judicial and regulatory developments have only partially resolved.
II. THE ARCHITECTURE OF INDIA'S AI GOVERNANCE FRAMEWORK
India's approach to AI governance is best understood as an overlay on four pre-existing regulatory pillars rather than a freestanding regime. The first pillar is the India AI Governance Guidelines themselves, organised into four parts of principles, issues and recommendations, an action plan, and practical guidance that built around seven foundational 'sutras': trust, people-first design, innovation over restraint, fairness and equity, accountability, understandability by design, and safety and resilience.3 The Guidelines propose a light institutional architecture of an AI Governance Group, a Technology and Policy Expert Committee, and an AI Safety Institute to coordinate, rather than displace, existing sectoral regulators.
The second pillar is sector-specific regulation. The RBI's Framework for Responsible and Ethical Enablement of Artificial Intelligence, submitted by an RBI-constituted committee on 13 August 2025, sets out twenty-six recommendations across six pillars such as infrastructure, policy, capacity, governance, protection and assurance for the specifically for AI use in banking and financial services.4 SEBI has issued a parallel framework governing the use of AI and machine-learning tools by market infrastructure institutions and intermediaries, requiring disclosure, model testing and accountability for algorithmic trading, robo-advisory and compliance systems that a framework of direct relevance to Naveen's own area of specialisation in banking, corporate and securities law.
The third pillar is data protection. The Digital Personal Data Protection Act 2023 establishes a consent-based regime for processing personal data, with penalties of up to ₹250 crore for a data fiduciary's failure to maintain reasonable security safeguards.5 The Digital Personal Data Protection Rules, 2025 were notified in November 2025, with a staggered three-stage enforcement timeline running to 14 May 2027, when the substantive consent, notice and security obligations finally take full effect.6 Until then, algorithmic harms arising from personal data processing are addressed principally through Sections 43A and 72A of the Information Technology Act 2000 a transitional gap of real significance for AI systems trained on personal data today.
The fourth pillar is general law contract, tort, consumer protection and intellectual property applied to AI-specific fact patterns as they arise. It is this fourth pillar that has produced the most consequential judicial development to date, discussed in Part III.
III. ANI v OPENAI: INDIA'S FIRST JUDICIAL PRONOUNCEMENT ON AI AND COPYRIGHT
On 24 July 2026, the Delhi High Court delivered the first substantive Indian judicial ruling on the intersection of copyright law and generative artificial intelligence, in ANI Media Pvt Ltd v OpenAI OpCo LLC.7 ANI, one of India's principal news agencies, had sued OpenAI alleging two distinct infringements: that ChatGPT had been trained on ANI's copyrighted news content without authorisation (the 'training claim'), and that ChatGPT's outputs sometimes reproduced or fabricated content falsely attributed to ANI (the 'output claim'). ANI sought an interim injunction restraining OpenAI from continuing to use its content pending trial.
Justice Amit Bansal declined to grant the injunction. On the training claim, the Court held, at the prima facie stage, that OpenAI's storage of ANI's articles for the purpose of training its large language models fell within the fair dealing exception in Section 52(1)(a)(i) of the Copyright Act, 1957, which protects private or personal use, including research.8 The Court found that the training data was held in a closed, non-public environment, that ANI had not established memorisation or verbatim reproduction of its articles in ChatGPT's responses, and that the model's outputs were transformative rather than substitutive of ANI's own product a finding reinforced by ANI's inability to show any measurable loss of subscribers or revenue.
The ruling is significant for three reasons. First, it confirms Indian courts will assert territorial jurisdiction over disputes involving foreign AI platforms whose effects are felt in India, rejecting OpenAI's objection that training occurred entirely on servers outside the country. Second, it signals provisionally that Indian copyright law may accommodate AI training within its existing fair dealing framework without legislative amendment, consistent with the AI Governance Guidelines' premise that existing law is largely sufficient. Third, and most important for practitioners, the ruling is interim and prima facie only: the main suit remains pending, output-level reproduction in other fact patterns is left open, and the finding does not finally determine whether AI training on copyrighted works is lawful under Indian law.9 Until trial, ANI v OpenAI is persuasive rather than settled authority.
IV. DEEPFAKES AND SYNTHETIC MEDIA: THE AMENDED IT RULES
A second area of concentrated regulatory activity concerns synthetically generated content. Responding to a rising incidence of AI-generated financial fraud and non-consensual impersonation, MeitY released draft amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 on 22 October 2025, introducing a statutory definition of 'synthetically generated information' and extending existing intermediary due-diligence and grievance-redressal obligations to cover it.10 The October 2025 draft initially proposed a rigid labelling standard a visible watermark covering at least ten per cent of the screen for visual content, or a disclosure during the first ten per cent of an audio clip's duration.
Following public consultation, the final amendments notified on 10 February 2026 relaxed this fixed threshold. Rather than a prescribed size, synthetic content must now simply be 'clearly and prominently labelled', with permanent metadata or a unique identifier embedded where feasible to trace the originating tool.11 Significant social media intermediaries for those with more than five million registered users must additionally require users to declare whether uploaded content is synthetically generated and deploy reasonable and proportionate technical measures to verify such declarations.
Civil society response has been sharply divided. Proponents argue that upstream labelling obligations, placed on the tool providers who generate synthetic content rather than solely on downstream platforms that host it, target the point in the chain where harm can most effectively be prevented. Critics, including the Internet Freedom Foundation, argue that the definition of 'synthetically generated information' remains vague, that verification obligations push platforms toward a surveillance-heavy compliance posture, and that over-removal of borderline content risks a chilling effect on legitimate satire, art and political commentary.12 Detection technology itself remains imperfect, with independent estimates placing automated deepfake-detection accuracy at only 65 to 70 per cent, limiting how much genuine assurance any labelling regime can offer at scale.
V. CRITICAL ANALYSIS: THE LIMITS OF AN INNOVATION-FIRST APPROACH
India's decision not to enact a dedicated AI statute is defensible on its own terms. A prescriptive, EU-style risk classification regime, transplanted onto a jurisdiction still building its digital public infrastructure, could plausibly entrench compliance costs that only large incumbents can absorb, while adding little protection beyond what a well-enforced combination of the DPDP Act, the Copyright Act, and sectoral regulation can already deliver.13 The comparison the AI Governance Guidelines draw to Japan's lighter-touch Act on the Promotion of Research, Development and Utilisation of AI-Related Technologies, rather than to the EU's prescriptive model, reflects a considered not merely lazy policy choice.
That said, three structural gaps deserve closer scrutiny. First, corporate accountability for AI-driven decision-making remains under-theorised in Indian company law. Section 166 of the Companies Act 2013 and the board-oversight obligations under the SEBI Listing Obligations and Disclosure Requirements Regulations were not drafted with algorithmic decision-making in mind, and it remains unclear how a director's fiduciary duty of care applies where a material business decision is substantially delegated to an AI system.14 This is precisely the fiduciary-duty question that deserves sustained treatment in its own right, and one this author intends to examine in a companion piece within this series.
Second, the DPDP Act's staggered enforcement timeline with substantive obligations not fully binding until May 2027 leaves a multi-year window in which AI systems can be trained on and make inferences from personal data under a comparatively thin statutory floor, resting principally on Sections 43A and 72A of the Information Technology Act 2000.15 Given that the constitutional right to informational privacy recognised in Justice K S Puttaswamy (Retd) v Union of India is engaged precisely by this kind of large-scale automated processing, the transitional gap is not merely administrative; it is a period during which a recognised fundamental right rests on comparatively weak statutory implementation.
Third, the ANI v OpenAI ruling, however welcome for its jurisdictional clarity, leaves the central copyright question formally unresolved. A prima facie finding on an interim injunction application is not a final adjudication, and the reasoning that training use is 'private' because the training corpus sits in a closed environment may not translate easily to other AI training practices, particularly where models are fine-tuned on more narrowly sourced or more easily identifiable datasets. Until the suit is finally decided, or until Parliament clarifies the position through a text-and-data-mining exception of the kind found in the EU and the United Kingdom, Indian rights-holders and AI developers alike are operating under conditions of genuine legal uncertainty.
VI. THE WAY FORWARD
Four steps would meaningfully strengthen India's AI governance architecture without abandoning its innovation-first orientation. First, the proposed AI Safety Institute and Technology and Policy Expert Committee should be operationalised swiftly, with clear coordination protocols vis-à-vis RBI, SEBI and other sectoral regulators, so that overlapping AI use cases an AI-driven robo-advisory product, for instance, engaging both SEBI's framework and the DPDP Act are not left to conflicting or duplicative compliance regimes. Second, Parliament should consider a narrowly tailored text-and-data-mining provision within the Copyright Act, distinct from the general fair dealing exception, to give AI developers and rights-holders a clearer and more predictable rule than an interim, prima facie judicial finding can provide. Third, MeitY and the Data Protection Board should consider accelerating the DPDP Act's substantive provisions for AI-specific processing rather than waiting for the full May 2027 timeline, given the constitutional stakes involved. Fourth, corporate law regulators SEBI and the Ministry of Corporate Affairs should issue guidance clarifying how directors' fiduciary duties apply to AI-assisted governance decisions, an area presently governed by inference from general principles rather than settled doctrine.
VII. CONCLUSION
India's AI governance strategy reflects a coherent wager: that existing law, lightly amended and coordinated through new institutional architecture, can absorb the risks of AI adoption more efficiently than a dedicated statute could. The India AI Governance Guidelines, the RBI's FREE-AI framework, SEBI's AI/ML oversight, and the amended IT Rules on synthetic content together constitute a genuine, if fragmented, regulatory response. The Delhi High Court's ruling in ANI v OpenAI supplies the first judicial data point on how that existing law will actually apply to generative AI and, provisionally, suggests that Indian copyright law can accommodate AI training without legislative overhaul.[^16] But the wager remains untested at its edges: in the multi-year gap before the DPDP Act's substantive provisions bind, in the unresolved question of director liability for AI-assisted corporate decisions, and in a copyright ruling that is interim rather than final. Whether India's innovation-first model proves durable will depend on whether these gaps are closed by considered reform before they are instead closed by the next high-profile failure.
REFERENCES
Legislation and Regulatory Instruments
Companies Act 2013.
Constitution of India.
Copyright Act 1957.
Digital Personal Data Protection Act 2023.
Digital Personal Data Protection Rules 2025.
Information Technology Act 2000.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended in 2025 and 2026.
Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations 2015.
Regulation (EU) 2024/1689 (Artificial Intelligence Act).
Cases
ANI Media Pvt Ltd v OpenAI OpCo LLC, Neutral Citation 2026:DHC:5900 (Delhi High Court, 24 July 2026).
Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
Government and Regulatory Reports
Ministry of Electronics and Information Technology, India AI Governance Guidelines (5 November 2025).
Ministry of Electronics and Information Technology, AI Governance Guidelines Development Report (Draft, January 2025).
Reserve Bank of India, Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI Committee Report, 13 August 2025).
Securities and Exchange Board of India, Framework on Artificial Intelligence and Machine Learning in the Securities Market.
Secondary and Academic Sources
Internet Freedom Foundation, Submissions on the Draft Synthetic Information IT Rules, 2025.
Freshfields Bruckhaus Deringer, 'India targets deepfakes and AI-generated content: key changes under MeitY's 2026 amendments to the IT Rules' (2026).
Shardul Amarchand Mangaldas & Co, 'Enforcement of the DPDP Act and notification of the DPDP rules' (2025).
Footnotes
-
Ministry of Electronics and Information Technology, India AI Governance Guidelines (5 November 2025), Part I, Sutra 3 ('Innovation over Restraint'). ↩
-
Ministry of Electronics and Information Technology, India AI Governance Guidelines (5 November 2025) ('AI Governance Guidelines'), following the draft AI Governance Guidelines Development Report released for public consultation in January 2025, which received over 2,500 stakeholder submissions. ↩
-
AI Governance Guidelines (n 2), Part I. The Guidelines expressly record the drafting committee's conclusion that a substantial portion of AI-related risk can be managed within existing legislation, with targeted amendments where gaps are identified, rather than through a dedicated AI statute. ↩
-
Reserve Bank of India, Report of the Committee for developing a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI Committee Report, 13 August 2025), setting out seven guiding 'sutras' and twenty-six recommendations across six pillars — Infrastructure, Policy, Capacity, Governance, Protection and Assurance. ↩
-
Securities and Exchange Board of India, framework governing the use of Artificial Intelligence and Machine Learning tools by market infrastructure institutions, intermediaries and regulated entities, requiring disclosure, testing and accountability for AI/ML-based models used in trading, advisory and compliance functions. ↩
-
Digital Personal Data Protection Act 2023, ss 4-9 (consent-based processing), 8 (obligations of data fiduciaries) and s 33 (financial penalties up to ₹250 crore for failure to maintain reasonable security safeguards). ↩
-
Digital Personal Data Protection Rules 2025, notified on 13-14 November 2025 under s 40 of the DPDP Act 2023, with staggered enforcement: the Data Protection Board of India constituted with effect from 13 November 2025, consent-manager registration from 13 November 2026, and the substantive consent, notice and security obligations from 14 May 2027. ↩
-
the Information Technology Act 2000, s 43A (compensation for failure to protect sensitive personal data) and s 72A (penalty for disclosure of information in breach of a lawful contract) principal statutory anchors for algorithmic harm claims prior to the staggered coming into force of the DPDP Act ↩
-
SANI Media Pvt Ltd v OpenAI OpCo LLC, Neutral Citation 2026:DHC:5900 (Delhi High Court, order dated 24 July 2026, Bansal J). ↩
-
Copyright Act 1957, s 52(1)(a)(i) (fair dealing exception for private or personal use, including research). ↩
-
ANI Media Pvt Ltd v OpenAI OpCo LLC (n 9), holding at the interim stage that ANI had not established memorisation or verbatim reproduction of its articles in ChatGPT's outputs, and that the storage of its works for training purposes fell within the private/research limb of s 52(1)(a)(i) of the Copyright Act 1957. ↩
-
Copyright Act 1957, s 51 (what constitutes infringement); the Delhi High Court's finding that OpenAI's training use was prima facie non-infringing does not finally dispose of the suit, and the trial on merits - including the question of output-level reproduction in other contexts remains pending. ↩
-
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2025 and 2026, introducing r 2(1)(wa) (definition of 'synthetically generated information'), r3(1A) (extending existing due-diligence and grievance provisions to synthetic content) and r 3(3) (labelling obligations); the fixed ten-per-cent size threshold proposed in the October 2025 draft was replaced in the February 2026 final rules with a requirement that synthetic content be 'clearly and prominently labelled'. ↩
-
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended, requiring significant social media intermediaries to obtain user declarations on whether uploaded content is synthetically generated and to deploy reasonable and proportionate technical measures to verify such declarations. ↩
-
Internet Freedom Foundation, Submissions on the Draft Synthetic Information IT Rules, 2025, arguing that vague definitions of 'synthetically generated information' and broad intermediary due-diligence obligations risk a censorship-prone and surveillance-heavy compliance framework. ↩