Il prossimoProssima guida
TAKE IT DOWN Act and Non-Consensual Deepfake Laws
Società
GUIDA della Società
India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines.
The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.
The DPDP Act was passed in August 2023 as India's first comprehensive personal data law, and the government notified its implementing rules in November 2025 with phased timelines. It applies to digital personal data processed in India and to processing abroad connected with offering goods or services to people in India. Organizations, called data fiduciaries, need valid consent or a listed 'legitimate use', must give notice, keep data secure, report breaches and erase data when its purpose ends. Individuals, called data principals, get rights to access, correction, erasure and grievance redress. A Data Protection Board adjudicates breaches, with penalties that can reach 250 crore rupees for certain failures. Importantly for AI, the Act does not apply to personal data that the individual has made publicly available, which affects web-scraped training data. For content harms, the government uses the Information Technology Act 2000 and the IT Rules 2021, which require intermediaries to exercise due diligence and remove unlawful content, including impersonation. In March 2024 the Ministry of Electronics and Information Technology (MeitY) issued an advisory on AI that initially suggested platforms get permission before launching untested models; after criticism, a revised version dropped that requirement and focused on labeling and not enabling unlawful content. MeitY later moved to amend the IT Rules to define 'synthetically generated information' and require labels on it. On promotion, the cabinet approved the IndiaAI Mission in March 2024, funding shared GPU compute, datasets, foundation models, skills and startups. In November 2025 MeitY released India AI Governance Guidelines recommending a principle-based, largely voluntary approach and concluding that a separate AI law was not needed for now. A misconception is that India is unregulated; many AI uses are already covered by data, IT, consumer and sectoral rules.
I danni catastrofici e quotidiani dell’IA dipendono entrambi da chi comprende i rischi e da chi può agire.
L’alfabetizzazione pubblica e professionale determina la possibilità politica di una forte politica di sicurezza.
Spiegazioni chiare riducono la cattura da parte di montature pubblicitarie, PR di laboratorio e vaghi teatrini etici.
India's near-term path is incremental: phased DPDP enforcement, implementation of IT Rules changes on synthetic content labeling, and sector guidance from regulators such as the Reserve Bank of India. The governance guidelines propose institutions to coordinate policy and monitor risks, and how quickly these are set up will shape practice. A broader Digital India Act to replace the IT Act has been discussed for years but its timing is unclear. The IndiaAI Mission's success will be judged by whether subsidized compute and datasets produce widely used Indian-language models.
An Indian health app training a symptom-checker model on user records must obtain clear consent under the DPDP Act for that specific purpose and let users withdraw consent as easily as they gave it.
A social media platform that receives complaints about a deepfake video of a public figure must act under the IT Rules' due diligence obligations to remove unlawful content within required timelines or risk losing safe harbour protection.
A startup developing an Indian-language model applies for subsidized GPU compute made available through the IndiaAI Mission's shared compute program.
A company scraping web data for training checks whether the personal data involved was made publicly available by the individual, since the DPDP Act excludes such data from much of its scope.
Trattare il rischio esistenziale come fantascienza mentre le capacità si aggravano.
Confondere la sicurezza del prodotto superficiale con l'allineamento in condizioni di elevata autonomia.
Lasciando il pubblico non inglese e non esperto solo con fonti di bassa qualità.
Separare i rischi di danni al prodotto, uso improprio e perdita di controllo/disallineamento.
Chiedi quali prove cambierebbero la tua opinione sulle tempistiche e sulla gravità.
Preferire fonti primarie e valutazioni concrete alle affermazioni di marketing.
Identifica un percorso d’azione: carriera, politica, finanziamenti o competenze, non solo consapevolezza.
Free newsletter
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines. The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.
India relies on the DPDP Act, IT Act and IT Rules, advisories and non-binding guidelines rather than an AI-specific statute.
India uses the term data fiduciary, emphasizing a duty of trust toward data principals.
Personal data made publicly available by the data principal falls outside the Act's main obligations.
The revision removed the permission requirement and focused on labeling and preventing unlawful content.
The Mission funds compute capacity, datasets, foundation models, skills and startups.
Continua a imparare
Altre guide selezionate per questo argomento
Il prossimoProssima guida
TAKE IT DOWN Act and Non-Consensual Deepfake Laws
Società