GUIDE DE LA SOCIÉTÉ

India's AI Governance and the DPDP Act

India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines.

  • 4 minutes de lecture
  • Dernière mise à jour
Sur cette page4 minutes de lecture
  1. Aperçu
  2. Plongée profonde
  3. Impact stratégique
  4. The Future of India's AI Governance and the DPDP Act
  5. Mise en œuvre dans le monde réel
  6. Risques et garde-fous
  7. Feuille de route de mise en œuvre
  8. Continuez à explorer
  9. Questions fréquemment posées

Aperçu

The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.

Plongée profonde

The DPDP Act was passed in August 2023 as India's first comprehensive personal data law, and the government notified its implementing rules in November 2025 with phased timelines. It applies to digital personal data processed in India and to processing abroad connected with offering goods or services to people in India. Organizations, called data fiduciaries, need valid consent or a listed 'legitimate use', must give notice, keep data secure, report breaches and erase data when its purpose ends. Individuals, called data principals, get rights to access, correction, erasure and grievance redress. A Data Protection Board adjudicates breaches, with penalties that can reach 250 crore rupees for certain failures. Importantly for AI, the Act does not apply to personal data that the individual has made publicly available, which affects web-scraped training data. For content harms, the government uses the Information Technology Act 2000 and the IT Rules 2021, which require intermediaries to exercise due diligence and remove unlawful content, including impersonation. In March 2024 the Ministry of Electronics and Information Technology (MeitY) issued an advisory on AI that initially suggested platforms get permission before launching untested models; after criticism, a revised version dropped that requirement and focused on labeling and not enabling unlawful content. MeitY later moved to amend the IT Rules to define 'synthetically generated information' and require labels on it. On promotion, the cabinet approved the IndiaAI Mission in March 2024, funding shared GPU compute, datasets, foundation models, skills and startups. In November 2025 MeitY released India AI Governance Guidelines recommending a principle-based, largely voluntary approach and concluding that a separate AI law was not needed for now. A misconception is that India is unregulated; many AI uses are already covered by data, IT, consumer and sectoral rules.

Impact stratégique

Risques et sécurité

Les dommages catastrophiques et quotidiens causés par l’IA dépendent tous deux de la personne qui comprend les risques et qui peut agir.

Décisions plus claires

Les connaissances du public et des professionnels déterminent si une politique de sécurité forte est politiquement possible.

Passer à travers le battage médiatique

Des explications claires réduisent la capture par le battage médiatique, les relations publiques en laboratoire et le théâtre d'éthique vague.

The Future of India's AI Governance and the DPDP Act

India's near-term path is incremental: phased DPDP enforcement, implementation of IT Rules changes on synthetic content labeling, and sector guidance from regulators such as the Reserve Bank of India. The governance guidelines propose institutions to coordinate policy and monitor risks, and how quickly these are set up will shape practice. A broader Digital India Act to replace the IT Act has been discussed for years but its timing is unclear. The IndiaAI Mission's success will be judged by whether subsidized compute and datasets produce widely used Indian-language models.

Mise en œuvre dans le monde réel

An Indian health app training a symptom-checker model on user records must obtain clear consent under the DPDP Act for that specific purpose and let users withdraw consent as easily as they gave it.

A social media platform that receives complaints about a deepfake video of a public figure must act under the IT Rules' due diligence obligations to remove unlawful content within required timelines or risk losing safe harbour protection.

A startup developing an Indian-language model applies for subsidized GPU compute made available through the IndiaAI Mission's shared compute program.

A company scraping web data for training checks whether the personal data involved was made publicly available by the individual, since the DPDP Act excludes such data from much of its scope.

Risques et garde-fous

  • Traiter le risque existentiel comme de la science-fiction alors que les capacités s’accroissent.

  • Confondre sécurité des produits de surface et alignement sous haute autonomie.

  • Laisser le public non anglophone et non expert avec uniquement des sources de mauvaise qualité.

Feuille de route de mise en œuvre

  1. Séparez les dommages causés aux produits, leur mauvaise utilisation et les risques de perte de contrôle/désalignement.

  2. Demandez quelles preuves pourraient changer votre point de vue sur les délais et la gravité.

  3. Préférez les sources primaires et les évaluations concrètes aux allégations marketing.

  4. Identifiez une voie d’action : carrière, politique, financement ou compétences – et pas seulement la sensibilisation.

Continuez à explorer

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the India's AI Governance and the DPDP Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Démarrer le quiz

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Questions fréquemment posées

What is India's AI Governance and the DPDP Act?

India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines. The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.

Does India have a dedicated, standalone AI law?

India relies on the DPDP Act, IT Act and IT Rules, advisories and non-binding guidelines rather than an AI-specific statute.

What does the DPDP Act call organizations that decide how personal data is processed?

India uses the term data fiduciary, emphasizing a duty of trust toward data principals.

Which data is excluded from much of the DPDP Act's scope, relevant to web-scraped AI training?

Personal data made publicly available by the data principal falls outside the Act's main obligations.

What happened to MeitY's March 2024 AI advisory after criticism?

The revision removed the permission requirement and focused on labeling and preventing unlawful content.

What is a key goal of the IndiaAI Mission approved in March 2024?

The Mission funds compute capacity, datasets, foundation models, skills and startups.