Yours in Law logo
YoursInLaw
Article

When Algorithms Decide: Who Is Responsible for AI-Driven Harm in India?

While its potential benefits are immense, the legal challenges associated with AI-driven harm cannot be ignored. Existing Indian laws provide partial protection, but they were not designed to address autonomous systems capable of making complex decisions with significant real-world consequences.

BRIGHT DUBE

28 August 2026

Introduction

Artificial Intelligence (AI) has rapidly moved from science fiction to everyday reality. Today, AI systems influence decisions about employment, healthcare, credit scoring, e-commerce, transportation, education, and even law enforcement. While these technologies promise efficiency and innovation, they also raise complex legal questions when things go wrong. If an AI-powered hiring tool discriminates against applicants, an autonomous vehicle causes an accident, or a medical algorithm recommends a harmful course of treatment, who should be held legally responsible?

This question has become increasingly important as governments and businesses integrate AI into critical decision-making processes. Unlike traditional tools, AI systems can learn, adapt, and operate with varying degrees of autonomy. As a result, establishing responsibility for harm becomes more difficult. Existing legal frameworks were designed around human actors and predictable machines, not self-learning algorithms capable of producing unforeseen outcomes.

In India, the rapid adoption of AI has outpaced the development of a dedicated legal framework governing AI liability. While statutes such as the Information Technology Act, 2000, the Consumer Protection Act, 2019, and the Digital Personal Data Protection Act, 2023 provide partial remedies, they do not fully address the unique challenges presented by AI-driven harm. This article examines the legal difficulties surrounding AI liability in India, analyses current laws, identifies regulatory gaps, and proposes a way forward for effective AI governance.

Understanding AI-Driven Harm

AI-driven harm can arise in numerous ways. In the employment sector, automated recruitment systems may unintentionally discriminate against qualified candidates due to biases embedded within training data. In healthcare, AI-assisted diagnostic tools may generate incorrect recommendations, resulting in delayed or improper treatment. Financial institutions increasingly rely on algorithms to assess creditworthiness, yet flawed systems may unfairly exclude individuals from accessing financial services.

Perhaps the most visible examples involve generative AI technologies. Deepfake videos, synthetic images, and AI-generated misinformation can damage reputations, influence public opinion, and facilitate fraud. Similarly, AI-powered surveillance systems may raise concerns regarding privacy, consent, and civil liberties.

The key challenge lies in the fact that harm may result not from a single human decision but from a chain of interactions involving developers, data providers, platform operators, and end users. In many cases, it becomes difficult to determine who should be responsible when an AI system produces a harmful outcome.

Traditional legal concepts assume a direct link between a human actor and a wrongful act. AI complicates this assumption because the system may reach conclusions that were neither specifically programmed nor anticipated by its creators. Consequently, courts and regulators around the world are struggling to adapt existing legal principles to emerging technological realities.

The Existing Legal Framework in India

India currently lacks a comprehensive statute specifically regulating artificial intelligence. Nevertheless, several laws may apply when AI systems cause harm.

Information Technology Act, 2000

The Information Technology Act, 2000 provides the foundation for India's cyber law regime. While the legislation predates modern AI technologies, certain provisions relating to electronic records, intermediary liability, and cybersecurity may become relevant when AI systems are involved in online misconduct.

However, the Act does not directly address algorithmic accountability, autonomous decision-making, or liability for AI-generated outcomes. Consequently, its usefulness in resolving complex AI disputes remains limited.

Consumer Protection Act, 2019

The Consumer Protection Act, 2019 offers stronger possibilities. The Act recognizes product liability and allows consumers to seek compensation for defects in products and services. If an AI-enabled product causes harm due to design flaws, inadequate instructions, or defective performance, manufacturers and service providers may potentially be held liable.

For example, a consumer injured by an AI-powered medical device or autonomous system could argue that the product failed to meet reasonable safety standards. Yet the legal position becomes less clear when harm results from continuous machine learning rather than an identifiable manufacturing defect.

Digital Personal Data Protection Act, 2023

AI systems frequently rely on enormous quantities of personal data. The Digital Personal Data Protection Act, 2023 seeks to establish safeguards regarding the collection, processing, and use of personal information.

Where an AI application processes personal data without consent or employs data in a manner that violates statutory obligations, affected individuals may have legal remedies. Nevertheless, the legislation primarily focuses on data protection rather than broader questions of algorithmic accountability or civil liability.

Constitutional Protections

The Indian Constitution also plays an important role in evaluating AI-related risks. In Justice K.S. Puttaswamy v. Union of India, the Supreme Court recognized privacy as a fundamental right under Article 21. The judgment has profound implications for AI systems that engage in large-scale data collection, profiling, or surveillance.

Similarly, Article 14 guarantees equality before the law. If an AI system produces discriminatory outcomes affecting employment, education, or access to public services, constitutional concerns may arise regarding fairness and non-arbitrariness.

The Central Question of Liability

The most significant legal challenge is determining who should bear responsibility when AI causes harm.

One approach is to place liability on developers who design and train AI systems. Developers influence the architecture, datasets, and operational parameters of the technology. If negligence occurs during development, assigning responsibility to developers appears reasonable.

However, this approach becomes problematic when a developer has little control over how an AI system is ultimately deployed. A product designed for legitimate purposes may later be used irresponsibly by another party.

A second possibility is imposing liability on companies that deploy AI systems. Businesses frequently decide where, when, and how AI technologies are used. Since they derive commercial benefits from such deployment, assigning responsibility to them reflects traditional principles of risk allocation.

Critics argue, however, that operators may be unable to predict every outcome generated by sophisticated machine-learning models. Holding them liable for all consequences could discourage innovation and technological advancement.

A third possibility involves end-user liability. Users who intentionally employ AI for unlawful purposes, such as fraud, harassment, or misinformation campaigns, should generally remain responsible for their actions. Nevertheless, user liability alone cannot adequately address situations where harm arises from algorithmic defects rather than deliberate misconduct.

These competing perspectives demonstrate why conventional legal principles struggle to address AI-related disputes effectively.

Comparative Approaches: Lessons from Other Jurisdictions

Several jurisdictions have begun developing regulatory responses to AI.

The European Union has emerged as a global leader through its AI regulatory framework. The EU adopts a risk-based approach that imposes stricter requirements on high-risk AI systems. Transparency obligations, documentation requirements, and compliance mechanisms seek to ensure accountability without prohibiting innovation altogether.

International organizations have also recognized the importance of responsible AI governance. The OECD AI Principles emphasize transparency, accountability, robustness, and human-centered values. Likewise, UNESCO's Recommendation on the Ethics of Artificial Intelligence advocates ethical safeguards and respect for fundamental rights.

In contrast, the United States has generally relied upon existing sector-specific regulations and liability principles rather than a single comprehensive AI statute. The United Kingdom has similarly favored a flexible framework emphasizing innovation alongside regulatory oversight.

These international developments suggest a growing global consensus that AI requires governance mechanisms specifically tailored to its unique characteristics.

Regulatory Gaps in India

Despite India's progress in digital governance, several significant gaps remain in relation to AI regulation.

First, there is no comprehensive legal definition of AI liability. Existing statutes address products, services, and personal data, but they do not clearly establish responsibility for autonomous decision-making systems.

Second, India lacks mandatory requirements for algorithmic transparency. Many AI systems function as "black boxes," making it difficult for affected individuals to understand how decisions are reached. Without transparency, proving discrimination, negligence, or causation becomes extremely challenging.

Third, current laws provide limited guidance regarding explainability. Citizens affected by automated decisions may find it difficult to challenge outcomes when neither users nor operators can adequately explain the reasoning behind them.

Fourth, enforcement mechanisms remain fragmented. Different aspects of AI may fall under consumer law, data protection law, constitutional law, cyber law, or sector-specific regulations. This fragmentation can create uncertainty for both businesses and individuals.

Finally, there is insufficient emphasis on proactive risk assessment. Harm is often addressed after it occurs rather than being prevented through audits, testing, and oversight requirements.

Critical Analysis

The debate surrounding AI liability reflects a broader tension between innovation and accountability. Excessive regulation could discourage investment and slow technological development. On the other hand, inadequate regulation may leave individuals without effective remedies when harm occurs.

In my view, the greatest weakness of existing legal frameworks is their assumption that decision-making remains fundamentally human. AI challenges this assumption. Modern algorithms can generate outputs that are difficult even for their creators to predict or explain. Consequently, assigning liability exclusively to one actor may oversimplify reality.

A more effective approach would recognize that responsibility is often shared. Developers, deployers, and users each contribute to the functioning of an AI system and should bear obligations proportional to their level of control. Such an approach would better reflect the collaborative nature of modern technological ecosystems.

Furthermore, transparency should not be viewed as a burden but as a cornerstone of accountability. Individuals affected by algorithmic decisions deserve to understand how those decisions were made, particularly when their rights, opportunities, or reputation are at stake.

Without meaningful safeguards, AI could reinforce existing social inequalities, amplify discriminatory practices, and undermine public trust in emerging technologies.

The Way Forward

India should adopt a dedicated AI governance framework based on risk classification and accountability.

First, high-risk AI systems used in sectors such as healthcare, employment, finance, and public administration should be subject to mandatory audits and compliance reviews.

Second, organizations deploying AI should maintain documentation explaining how systems function, how training data is obtained, and how risks are assessed.

Third, legal obligations relating to explainability and transparency should be strengthened. Individuals affected by significant automated decisions should have access to understandable explanations and effective avenues for appeal.

Fourth, policymakers should establish clear liability standards that allocate responsibility among developers, deployers, and users according to their respective roles.

Finally, India should create a specialized regulatory body or oversight mechanism equipped to monitor AI developments and respond to emerging challenges.

Such measures would help protect individual rights while ensuring that innovation continues in a responsible and sustainable manner.

Conclusion

Artificial intelligence is transforming society at an unprecedented pace. While its potential benefits are immense, the legal challenges associated with AI-driven harm cannot be ignored. Existing Indian laws provide partial protection, but they were not designed to address autonomous systems capable of making complex decisions with significant real-world consequences.

The central question is not whether AI should be permitted to drive innovation, but how society should allocate responsibility when that innovation causes harm. As AI becomes increasingly embedded within everyday life, legal accountability will become essential for maintaining public trust and protecting fundamental rights.

India stands at a critical moment in its technological development. By introducing clear liability standards, strengthening transparency obligations, and adopting a forward-looking regulatory framework, the country can establish a balanced approach that promotes innovation while ensuring justice and accountability. The future of AI governance in India will ultimately depend on whether lawmakers act before technological progress outpaces the law itself.

Footnotes

  1. Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1.
  2. Constitution of India, art 14.
  3. Constitution of India, art 21.
  4. Information Technology Act 2000.
  5. Consumer Protection Act 2019.
  6. Digital Personal Data Protection Act 2023.
  7. Organization for Economic Co-operation and Development, OECD Principles on Artificial Intelligence (2019).
  8. UNESCO, Recommendation on the Ethics of Artificial Intelligence (2021).
  9. Shreya Singhal v Union of India (2015) 5 SCC 1.
  10. European Union Artificial Intelligence Act (EU AI Act).

Bibliography

Cases

  • Justice K.S. Puttaswamy (Retd.) v Union of India (2017) 10 SCC 1.
  • Shreya Singhal v Union of India (2015) 5 SCC 1.

Legislation

  • Constitution of India.
  • Consumer Protection Act 2019.
  • Digital Personal Data Protection Act 2023.
  • Information Technology Act 2000.

International Materials

  • European Union Artificial Intelligence Act.
  • OECD Principles on Artificial Intelligence (2019).
  • UNESCO Recommendation on the Ethics of Artificial Intelligence (2021)