Notes from the Asia-Pacific region: India weighs AI legislation

Notes from the Asia-Pacific region: India weighs AI legislation

As India embraces the monsoon season, a parallel storm of activity is brewing in its digital governance landscape. The past month has been characterized by intense legislative and technological developments, particularly concerning artificial intelligence, as the nation prepares to celebrate its 80th Independence Day. The aroma of freshly wet earth this season usually brings is, for digital trust and governance specialists, overshadowed by the rapid pace of change.

A significant shift is underway as India increasingly signals its intention to enact dedicated legislation for artificial intelligence. Union Minister for Electronics and Information Technology Ashwini Vaishnaw previously hinted at the potential need for fresh AI-specific laws, and this preliminary intent is now manifesting into concrete action. On July 9, Secretary for the Ministry of Electronics and Information Technology, S. Krishnan, announced plans for government-initiated discussions with various stakeholder groups to begin drafting AI regulations. This marks a notable departure from the government’s previous stance, as recently as December 2025, which favored leveraging existing legal frameworks like the Information Technology Act, the Digital Personal Data Protection Act, and intellectual property law to govern AI. Krishnan’s statement suggests a re-evaluation of whether India’s current technology-neutral legal framework adequately addresses the unique risks and functionalities presented by AI systems. The immediate steps include engaging in stakeholder discussions, gathering diverse perspectives, and initiating a drafting process, though the precise form, scope, and relationship with existing legislation of the proposed instrument remain to be determined.

Beyond regulation, a broader initiative is also in motion. Krishnan revealed that approximately 762 suggestions were received from ministries regarding potential applications of AI following the India AI Impact Summit 2026. While primarily focused on AI adoption, this exercise is crucial, as India’s eventual governance framework must coexist with the rapidly expanding public-sector use of AI. This emerging legislative work builds upon an institutional architecture already being established in India. The government previously issued principle-based AI Governance Guidelines and, in April 2026, established the AI Governance and Economic Group – a high-level inter-ministerial coordination body supported by a Technology and Policy Expert Committee. Furthermore, under the IndiaAI Mission, the IndiaAI Safety Institute was founded to spearhead indigenous AI-safety research, developing India-specific technical tools, evaluation methodologies, standards, and risk-assessment frameworks.

The central question for India is no longer whether AI should be governed, but rather how a central law can provide structure and clarity to the growing body of principles, institutional mechanisms, sector-specific requirements, and judicial actions, all while fostering innovation. Insights into the government’s perspective have also emerged from the ongoing Monsoon Session of Parliament, which commenced on July 20 and concludes on August 13. Parliamentary questions often illuminate policy nuances that broader announcements might omit. A particularly important question from Member of Parliament Manish Tewari inquired whether generative AI systems and chatbot services qualify as “intermediaries” under the Information Technology Act, thus potentially enjoying safe harbor protection. In response, Minister of State for Electronics and Information Technology Jitin Prasada clarified that the answer depends on the nature of the service, the functions performed by the AI system, and the applicable provisions of the IT Act and IT Rules. He reaffirmed the IT Act’s technology-neutral stance, asserting its applicability to computer resources and intermediaries irrespective of the technology, including AI.

Parliament also received a comprehensive progress report on the IndiaAI Mission’s Safe & Trusted AI pillar. According to information released by the government in late July, significant progress has been made:
* Thirteen Responsible AI projects are receiving support across areas like bias mitigation, explainability, privacy-preserving AI, deepfake detection, and AI risk assessment.
* Twenty indigenous, sovereign model proposals have been identified, including 12 large language models and eight small language models.
* The government has sanctioned 93 lakh GPU hours for 237 supported projects.
* A total of 686 fellowships have been awarded across 178 institutions.
* Twenty-seven India Data and AI Labs have been established, with work continuing on an additional 188.
* Fifty-eight AI Centres of Excellence are being established in collaboration with state and Union Territory governments and industry partners.

These figures demonstrate India’s commitment to building a comprehensive AI ecosystem encompassing infrastructure, models, applications, skills, safety research, and evaluation, rather than simply crafting a policy framework. The parliamentary proceedings reveal an interesting duality: India is aggressively promoting AI adoption while simultaneously grappling with fundamental legal questions concerning responsibility, intermediary status, safety, and redress. The proposed AI law will be crucial in bridging these two tracks.

Children’s online safety also garnered considerable cross-party attention during the Monsoon Session, with three private members’ bills tabled. Baijayant Panda’s Safeguarding Healthy Internet Environments for Little Digital-Natives Bill proposes parental authorization for children under 13 to open social media or online gaming accounts, alongside age checks, parental oversight features, and additional responsibilities for platforms. Tewari’s Online Child Safety Bill would compel platforms to proactively anticipate and mitigate risks to children through service design and operation, while also strengthening enforcement and providing assistance to those affected by online harm. A third proposal, introduced in the Rajya Sabha by Kartikeya Sharma, advocates for default protective settings for younger users and restrictions on their social media access during specified nighttime hours. While these are individual parliamentary proposals and not government legislation, they signify a growing debate in India that extends beyond age verification and parental permissions to encompass safer platform design, default protections, access controls, accountability, and remedies. As the Digital Personal Data Protection Act (DPDPA) provisions regarding children approach implementation, policymakers will need to address not only how platforms verify a user’s age but also how their services safeguard children once they are online.

Another series of discussions revolved around interactions between social media giant Meta and MeitY, particularly concerning WhatsApp’s username functionality. MeitY’s notices on this matter raised concerns about impersonation, phishing, and “digital arrest” scams. Krishnan stated on July 9 that the government awaited responses from WhatsApp and other platforms, triggering questions about whether intermediary safe-harbor provisions were being implicitly used as a pre-launch product-approval mechanism. More serious concerns emerged from investigations into paid advertisements promoting child sexual abuse material on Meta’s platforms. MeitY issued a notice to Meta, and subsequent research indicated that AI-generated abusive advertisements continued to appear on Meta services even after the initial India-focused investigation. Meta’s Chief Global Affairs Officer Joel Kaplan later conveyed the company’s regret to IT Minister Vaishnaw, with media reports also indicating Mark Zuckerberg’s regret over issues concerning child sexual abuse material, deepfakes, and operational failures on Meta’s platforms. Meanwhile, WhatsApp is reportedly testing prompts asking some Indian users for their birth dates, exploring privacy-protective age verification methods ahead of the full implementation of the DPDPA’s requirements concerning children’s personal data and verifiable parental consent.

While the executive and legislative branches contemplate future regulation, Indian courts continue to address immediate questions involving AI training, copyright, synthetic media, and platform responsibility. On July 24, the Delhi High Court denied Asian News International interim relief in its copyright lawsuit against OpenAI. At this preliminary stage, the court deemed OpenAI’s storage of ANI’s literary works for training large language models to be covered by the fair-dealing exception of the Copyright Act. It also concluded that ANI had not demonstrated that ChatGPT’s outputs substantially reproduced its reports. The issue of deepfakes also revisited the Bombay High Court. On August 5, the court instructed social media platforms to remove identified deepfake and AI-generated material falsely linking Union Minister Nitin Gadkari and his family to alleged impropriety concerning an ethanol-blending program. The court also questioned the lack of effective processes on platforms for addressing clearly abusive material without requiring affected individuals to seek judicial relief. This order adds to a growing body of cases where courts are utilizing existing protections related to reputation, dignity, personality, and intermediary responsibility to address synthetic-media harms in the absence of a dedicated deepfake statute.

Finally, some critical data points shed light on both the promise and risks associated with India’s rapid AI adoption. IBM’s 2026 Cost of a Data Breach Report revealed that the average organizational cost of a data breach in India has reached a record INR 255 million, a 15.9% increase over the previous year, with an average of 39,500 records compromised per incident. Strikingly, IBM classified 26% of malicious breaches in India as AI-generated. However, only 32% of Indian organizations surveyed reported extensive deployment of AI and security automation. Organizations without such automation incurred average breach costs of INR 316 million, significantly higher than the INR 213 million for those extensively using it.

A different aspect of readiness emerges from Nasscom’s inaugural AI-Native Talent Index. This study classified nearly 70% of India’s early-career technology workforce as AI-proficient, but only around 23% as AI-native. This distinction is important: widespread use of AI tools does not necessarily equate to the technical judgment, orchestration capabilities, independence, and responsible-use practices required to effectively build and supervise AI systems.

Lastly, privacy risks are increasingly integrated into everyday digital experiences. A LocalCircles survey published in August found that 77% of respondents regarding online insurance encountered interfaces that pressured them into disclosing more personal information than intended. The same study noted high levels of repeated prompting, compulsory data submission, pricing discrepancies, and difficulties in cancellation. While these are survey findings, they underscore how the discussion around dark patterns increasingly intersects with privacy, consent, and accountable product design.

With this whirlwind of digital governance and technological advancement, the prospect of a hot cup of chai, enjoyed amidst the monsoon rains, feels particularly well-deserved.

Leave a Reply

Your email address will not be published. Required fields are marked *