PANDUAN Masyarakat

India's AI Governance and the DPDP Act

India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines.

  • 4 menit membaca
  • Terakhir diperbarui
Di halaman ini4 menit membaca
  1. Ikhtisar
  2. Menyelam Lebih Dalam
  3. Dampak Strategis
  4. The Future of India's AI Governance and the DPDP Act
  5. Implementasi Dunia Nyata
  6. Risiko & Pagar Pembatas
  7. Peta Jalan Implementasi
  8. Terus Menjelajah
  9. Pertanyaan yang sering diajukan

Ikhtisar

The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.

Menyelam Lebih Dalam

The DPDP Act was passed in August 2023 as India's first comprehensive personal data law, and the government notified its implementing rules in November 2025 with phased timelines. It applies to digital personal data processed in India and to processing abroad connected with offering goods or services to people in India. Organizations, called data fiduciaries, need valid consent or a listed 'legitimate use', must give notice, keep data secure, report breaches and erase data when its purpose ends. Individuals, called data principals, get rights to access, correction, erasure and grievance redress. A Data Protection Board adjudicates breaches, with penalties that can reach 250 crore rupees for certain failures. Importantly for AI, the Act does not apply to personal data that the individual has made publicly available, which affects web-scraped training data. For content harms, the government uses the Information Technology Act 2000 and the IT Rules 2021, which require intermediaries to exercise due diligence and remove unlawful content, including impersonation. In March 2024 the Ministry of Electronics and Information Technology (MeitY) issued an advisory on AI that initially suggested platforms get permission before launching untested models; after criticism, a revised version dropped that requirement and focused on labeling and not enabling unlawful content. MeitY later moved to amend the IT Rules to define 'synthetically generated information' and require labels on it. On promotion, the cabinet approved the IndiaAI Mission in March 2024, funding shared GPU compute, datasets, foundation models, skills and startups. In November 2025 MeitY released India AI Governance Guidelines recommending a principle-based, largely voluntary approach and concluding that a separate AI law was not needed for now. A misconception is that India is unregulated; many AI uses are already covered by data, IT, consumer and sectoral rules.

Dampak Strategis

Risiko dan keselamatan

Kerugian akibat AI yang bersifat bencana dan sehari-hari bergantung pada siapa yang memahami risikonya dan siapa yang dapat bertindak.

Keputusan yang lebih jelas

Literasi masyarakat dan profesional menentukan apakah kebijakan keselamatan yang kuat memungkinkan secara politis.

Menembus hype

Penjelasan yang jelas mengurangi penangkapan oleh hype, PR laboratorium, dan teater etika yang tidak jelas.

The Future of India's AI Governance and the DPDP Act

India's near-term path is incremental: phased DPDP enforcement, implementation of IT Rules changes on synthetic content labeling, and sector guidance from regulators such as the Reserve Bank of India. The governance guidelines propose institutions to coordinate policy and monitor risks, and how quickly these are set up will shape practice. A broader Digital India Act to replace the IT Act has been discussed for years but its timing is unclear. The IndiaAI Mission's success will be judged by whether subsidized compute and datasets produce widely used Indian-language models.

Implementasi Dunia Nyata

An Indian health app training a symptom-checker model on user records must obtain clear consent under the DPDP Act for that specific purpose and let users withdraw consent as easily as they gave it.

A social media platform that receives complaints about a deepfake video of a public figure must act under the IT Rules' due diligence obligations to remove unlawful content within required timelines or risk losing safe harbour protection.

A startup developing an Indian-language model applies for subsidized GPU compute made available through the IndiaAI Mission's shared compute program.

A company scraping web data for training checks whether the personal data involved was made publicly available by the individual, since the DPDP Act excludes such data from much of its scope.

Risiko & Pagar Pembatas

  • Memperlakukan risiko eksistensial sebagai fiksi ilmiah sementara kemampuan bertambah.

  • Membingungkan keamanan produk permukaan dengan penyelarasan dalam otonomi tinggi.

  • Membiarkan audiens non-Inggris dan non-ahli hanya memiliki sumber berkualitas rendah.

Peta Jalan Implementasi

  1. Pisahkan risiko bahaya, penyalahgunaan, dan hilangnya kendali/ketidakselarasan produk.

  2. Tanyakan bukti apa yang akan mengubah pandangan Anda mengenai jangka waktu dan tingkat keparahannya.

  3. Lebih memilih sumber primer dan evaluasi konkrit dibandingkan klaim pemasaran.

  4. Identifikasi satu jalur tindakan: karier, kebijakan, pendanaan, atau keterampilan – bukan hanya kesadaran.

Terus Menjelajah

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the India's AI Governance and the DPDP Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Mulai kuis

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Pertanyaan yang sering diajukan

What is India's AI Governance and the DPDP Act?

India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines. The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.

Does India have a dedicated, standalone AI law?

India relies on the DPDP Act, IT Act and IT Rules, advisories and non-binding guidelines rather than an AI-specific statute.

What does the DPDP Act call organizations that decide how personal data is processed?

India uses the term data fiduciary, emphasizing a duty of trust toward data principals.

Which data is excluded from much of the DPDP Act's scope, relevant to web-scraped AI training?

Personal data made publicly available by the data principal falls outside the Act's main obligations.

What happened to MeitY's March 2024 AI advisory after criticism?

The revision removed the permission requirement and focused on labeling and preventing unlawful content.

What is a key goal of the IndiaAI Mission approved in March 2024?

The Mission funds compute capacity, datasets, foundation models, skills and startups.