Toplum REHBERİ

India's AI Governance and the DPDP Act

India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines.

  • 4 dakikalık okuma
  • Son güncelleme
Bu sayfada4 dakikalık okuma
  1. Genel Bakış
  2. Derin Dalış
  3. Stratejik Etki
  4. The Future of India's AI Governance and the DPDP Act
  5. Gerçek Dünya Uygulaması
  6. Riskler ve Korkuluklar
  7. Uygulama Yol Haritası
  8. Keşfetmeye Devam Edin
  9. Sık sorulan sorular

Genel Bakış

The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.

Derin Dalış

The DPDP Act was passed in August 2023 as India's first comprehensive personal data law, and the government notified its implementing rules in November 2025 with phased timelines. It applies to digital personal data processed in India and to processing abroad connected with offering goods or services to people in India. Organizations, called data fiduciaries, need valid consent or a listed 'legitimate use', must give notice, keep data secure, report breaches and erase data when its purpose ends. Individuals, called data principals, get rights to access, correction, erasure and grievance redress. A Data Protection Board adjudicates breaches, with penalties that can reach 250 crore rupees for certain failures. Importantly for AI, the Act does not apply to personal data that the individual has made publicly available, which affects web-scraped training data. For content harms, the government uses the Information Technology Act 2000 and the IT Rules 2021, which require intermediaries to exercise due diligence and remove unlawful content, including impersonation. In March 2024 the Ministry of Electronics and Information Technology (MeitY) issued an advisory on AI that initially suggested platforms get permission before launching untested models; after criticism, a revised version dropped that requirement and focused on labeling and not enabling unlawful content. MeitY later moved to amend the IT Rules to define 'synthetically generated information' and require labels on it. On promotion, the cabinet approved the IndiaAI Mission in March 2024, funding shared GPU compute, datasets, foundation models, skills and startups. In November 2025 MeitY released India AI Governance Guidelines recommending a principle-based, largely voluntary approach and concluding that a separate AI law was not needed for now. A misconception is that India is unregulated; many AI uses are already covered by data, IT, consumer and sectoral rules.

Stratejik Etki

Risk ve güvenlik

Yıkıcı ve günlük yapay zeka zararları, kimin riskleri anladığı ve kimin harekete geçebileceğine bağlıdır.

Daha net kararlar

Kamu ve profesyonel okuryazarlık, güçlü bir güvenlik politikasının politik olarak mümkün olup olmadığını şekillendirir.

Heyecanı aşmak

Açık açıklamalar abartılı reklamların, laboratuvar halkla ilişkiler uygulamalarının ve belirsiz etik tiyatrosunun etkisi altına girmeyi azaltır.

The Future of India's AI Governance and the DPDP Act

India's near-term path is incremental: phased DPDP enforcement, implementation of IT Rules changes on synthetic content labeling, and sector guidance from regulators such as the Reserve Bank of India. The governance guidelines propose institutions to coordinate policy and monitor risks, and how quickly these are set up will shape practice. A broader Digital India Act to replace the IT Act has been discussed for years but its timing is unclear. The IndiaAI Mission's success will be judged by whether subsidized compute and datasets produce widely used Indian-language models.

Gerçek Dünya Uygulaması

An Indian health app training a symptom-checker model on user records must obtain clear consent under the DPDP Act for that specific purpose and let users withdraw consent as easily as they gave it.

A social media platform that receives complaints about a deepfake video of a public figure must act under the IT Rules' due diligence obligations to remove unlawful content within required timelines or risk losing safe harbour protection.

A startup developing an Indian-language model applies for subsidized GPU compute made available through the IndiaAI Mission's shared compute program.

A company scraping web data for training checks whether the personal data involved was made publicly available by the individual, since the DPDP Act excludes such data from much of its scope.

Riskler ve Korkuluklar

  • Yetenekleri artırırken varoluşsal riski bilim kurgu olarak ele almak.

  • Yüzey ürün güvenliğini yüksek özerklik altında hizalamayla karıştırmak.

  • İngilizce olmayan ve uzman olmayan izleyici kitlesini yalnızca düşük kaliteli kaynaklarla bırakmak.

Uygulama Yol Haritası

  1. Ürün zararları, yanlış kullanım ve kontrol kaybı/yanlış hizalama risklerini ayırın.

  2. Hangi kanıtların zaman çizelgeleri ve ciddiyet konusundaki görüşünüzü değiştireceğini sorun.

  3. Pazarlama iddiaları yerine birincil kaynakları ve somut değerlendirmeleri tercih edin.

  4. Tek bir eylem yolu belirleyin: kariyer, politika, finansman veya beceriler; yalnızca farkındalık değil.

Keşfetmeye Devam Edin

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the India's AI Governance and the DPDP Act quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Testi başlat

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Sık sorulan sorular

What is India's AI Governance and the DPDP Act?

India has no dedicated AI law; instead it governs AI through the Digital Personal Data Protection (DPDP) Act 2023, the IT Act and IT Rules, government advisories on deepfakes, and non-binding national AI governance guidelines. The approach favors innovation and state-backed capacity building through the IndiaAI Mission while using existing laws to address harms. It matters because India is one of the world's largest online populations and a major AI talent and deployment market.

Does India have a dedicated, standalone AI law?

India relies on the DPDP Act, IT Act and IT Rules, advisories and non-binding guidelines rather than an AI-specific statute.

What does the DPDP Act call organizations that decide how personal data is processed?

India uses the term data fiduciary, emphasizing a duty of trust toward data principals.

Which data is excluded from much of the DPDP Act's scope, relevant to web-scraped AI training?

Personal data made publicly available by the data principal falls outside the Act's main obligations.

What happened to MeitY's March 2024 AI advisory after criticism?

The revision removed the permission requirement and focused on labeling and preventing unlawful content.

What is a key goal of the IndiaAI Mission approved in March 2024?

The Mission funds compute capacity, datasets, foundation models, skills and startups.