India's AI Law: Market Access Over Safety
India's new AI law is a market-access play, not a safety framework
Model Diplomat9 min readSouth Asia

India's Standalone AI Law Is No Longer About Safety — It's About Market Access
India is drafting a standalone artificial intelligence law with its own liability architecture, a senior government official confirmed to The Indian Express on July 22, 2026. The Ministry of Electronics and Information Technology (MeitY) is not amending the Information Technology Act, 2000. It is writing a new statute. The draft law imposes consent requirements on synthetically-generated content, sets hard limits on the autonomy of agentic AI systems, and creates regulatory sandboxes for high-risk applications. Two unnamed legal experts have been separately commissioned to submit draft liability frameworks for AI models. This is not a consultation paper or a white paper. It is the final stage before a Bill.
The pivot breaks with the government's own stated doctrine. For three years, MeitY Secretary S. Krishnan publicly insisted India would not "rush headlong into any tight regulation on AI" because existing frameworks were sufficient CSIS, January 2026. The chair of the AI Governance drafting committee told
The Hindu BusinessLine the government had "chosen to guide AI development and not regulate it." That line is dead.
The law is not about whether AI is safe. It is about who pays for compliance and who gets priced out of the Indian market.
The Arc from Hands-Off to Hard Law
India's regulatory trajectory has been one of incremental tightening disguised as restraint. In April 2023, MeitY told Parliament it was not considering any AI legislation. By March 2024, after the Google Gemini controversy over a query about Prime Minister Modi, the ministry issued an advisory requiring government approval before launching "unreliable" or "under-tested" generative AI tools Al Jazeera, March 2024. The advisory was non-binding, but non-compliance could trigger prosecution under the IT Act.
The next phase was infrastructural. The DPDP Act, passed in August 2023, established a consent-centric data protection regime. The DPDP Rules, notified on November 14, 2025, after a consultation that drew 6,915 inputs, gave the Act teeth — an 18-month phased compliance timeline, mandatory standalone consent notices, a digital Data Protection Board, and the requirement that Consent Managers be Indian companies PIB, November 2025. The nationality clause was the first signal that data governance was also market governance.
Then came the synthetic-content crackdown. Draft amendments to the IT Rules, published in October 2025, defined "synthetically generated information" for the first time and required labeling, metadata embedding, and a minimum 10% visual or initial audio duration mark on AI-generated content PRS India, October 2025. The final rules, notified on February 10, 2026, went further: intermediaries must deploy "reasonable technical measures" to prevent creation of unlawful synthetic content, remove it within three hours of a government order, and ensure users are aware of legal consequences
PIB, February 2026.
One week later, on February 15, 2026, the government released its India AI Governance Guidelines — seven guiding Sutras, six governance pillars, and proposals for a new institutional architecture: the AI Governance Group (AIGG), the Technology and Policy Expert Committee (TPEC), and an AI Safety Institute PIB, February 2026. At the India AI Impact Summit on February 19, Prime Minister Modi unveiled the MANAV framework — Moral and Ethical Systems, Accountable Governance, National Sovereignty, Accessible and Inclusive AI, Valid and Legitimate Systems
PIB, February 2026. Ninety-one countries endorsed the Delhi Declaration, including the United States and China.
Yet even as the institutional scaffolding went up, Secretary Krishnan maintained the line: "We are not going to rush headlong into trying to put crimps on the way that AI would develop" CSIS. That line held for five months.
The Standing Committee on Communications and Information Technology broke the spell. In its March 30, 2026 report, the committee — chaired by BJP MP Nishikant Dubey — explicitly recommended "exploring the possibility of a comprehensive legislation to prevent misuse of AI" alongside a "Digital India Act" to replace the aging IT Act PRS India, March 2026. Parliamentary pressure, not ministerial preference, forced the government's hand.
What the Law Actually Targets
The July 22 Indian Express report reveals the law's architecture. The cyber laws division of MeitY has been ordered to conduct a regulatory gap analysis of the IT Act and its subordinate rules. Two independent legal experts are drafting separate liability frameworks for AI models — a competitive commission format, suggesting the government wants options rather than consensus.
Three provisions are already taking shape:
1. Consent-based framework for synthetic content. This is the logical extension of the DPDP Act. If your likeness, voice, or biometric data can be used to generate synthetic media, the law would require explicit prior consent — modeled on the DPDP's consent-manager architecture. The February 2026 IT Rules amendments already mandate labeling of synthetic content; the new law would criminalize its creation without consent, moving beyond platform obligations to individual and developer liability. The UK's experience with the Data (Use and Access) Act 2025 — which criminalized the creation of non-consensual intimate deepfakes but left the provision unenforced for over a year — is a cautionary tale India appears determined to avoid BBC, July 2026.
2. Curbs on agentic AI autonomy. This is the novel part. Neither the IT Act nor any existing Indian statute contemplates a software agent that can authenticate, transact, and make decisions without human intermediation. The proposed law would define autonomy limits — likely a mandatory human-in-the-loop requirement for decisions above a risk threshold — and establish a liability chain that traces agent actions back to developers, deployers, or users depending on where control was relinquished. As the Brookings Institution noted in its 2026 analysis of anthropomorphic AI terminology, "when a policy reads 'AI makes a decision,' the wording can blur the distinction between the output generation and the decision to use the model's output" — a gap the Indian law intends to close by naming specific actors in the supply chain Brookings, April 2026.
3. Regulatory sandboxes for high-risk applications. The concept, already deployed by the Reserve Bank of India for fintech, would allow controlled testing of AI deployments in sectors like healthcare, finance, and critical infrastructure before full-scale rollout.
Who Wins, Who Pays
The economic context makes the stakes visible. NASSCOM's Strategic Review pegs India's technology sector at $315 billion in fiscal year 2026, with Global Capability Centers employing 2.36 million people and on track to exceed 3 million by 2030 ORF, July 2026. Agentic AI compresses the very service workflows — compliance processing, KYC, customer support — that built India's IT-BPO export engine. A consent-and-liability architecture that raises the cost of deploying autonomous agents in India acts as a friction tax on foreign AI providers while giving domestic firms time to adapt.
The winners are easy to name. Indian Consent Managers — the entities mandated by the DPDP Rules to be Indian companies — gain a second vertical: AI consent management. Domestic AI startups get a regulatory sandbox that foreign competitors cannot easily access without local incorporation and compliance infrastructure. The Observer Research Foundation argues that "countries establishing clear data protection frameworks can turn regulatory oversight into a lucrative export" ORF. India is building that export framework now.
The losers are foreign model providers — OpenAI, Anthropic, Google DeepMind, xAI — who face a new compliance layer for any deployment in India, including consent verification for training data and liability exposure for agentic outputs. The Takshashila Institution's recent analysis notes that India's AI investment is concentrated at the application layer, and "India is not substantially exposed to the infrastructure layer" — meaning the compliance burden falls on foreign providers while domestic firms escape the capital costs of model training Takshashila, July 2026.
There is a sovereignty dimension. The Brookings Institution's February 2026 report on AI sovereignty concluded that "full-stack AI sovereignty is structurally infeasible for almost any country" and proposed "managed interdependence" as the practical alternative Brookings, February 2026. India's approach — building governance infrastructure rather than competing on compute — fits that model precisely. The Council on Foreign Relations recently described India as "a democratic tech power" whose "representative institutions, independent judiciary, active civil society, and constitutionally enshrined rights provide a foundation for its normative claims that authoritarian competitors cannot replicate"
CFR, 2026. The standalone AI law operationalizes that normative claim into a regulatory framework that other Global South nations can adopt — and that Indian firms can help implement.
The timing is also strategic. The DPDP Rules' 18-month phase-in ends in mid-2027. An AI law drafted now, debated in the 2027 Budget Session, could become effective just as the data protection regime fully materializes — creating a whole-of-law compliance architecture that no other major jurisdiction has yet assembled. The EU AI Act's high-risk requirements take full effect in August 2026; China's amended Cybersecurity Law became enforceable in January 2026. India is not leading the race, but it is timing its entry to avoid the early mistakes.
Diplomat View
The standalone AI law is not primarily a safety intervention. It is a market-structuring instrument, designed to create compliance costs that foreign AI providers must bear while domestic firms navigate sandboxes and consent-manager architectures built for them. The consent-to-synthetic-content framework extends the DPDP's logic — consent as a tradeable, manageable asset — into the generative AI domain, creating a new regulated industry (AI consent management) that is, by statutory design, Indian. The agent-autonomy curbs function as a speed governor on a technology that threatens India's $315 billion IT services sector, buying time for workforce reskilling and for Global Capability Centers to pivot from execution to governance-as-a-service.
The liability frameworks being drafted by the two commissioned experts are the critical variable. If they allocate liability primarily to developers, foreign model providers face exposure they will litigate or exit over. If they spread liability across the supply chain — developer, deployer, user — the regime becomes more politically durable but harder to enforce. The more likely outcome is a tiered model: strict liability for developers of high-risk systems, fault-based liability for deployers, and a safe harbor for users who follow prescribed guardrails. That would be consistent with the EU AI Act's risk-tiering but would add India-specific consent requirements that the EU framework lacks.
The forecast: A draft Bill surfaces in the winter session of Parliament (November-December 2026), with passage in 2027. The DPDP Rules' full compliance deadline in mid-2027 will accelerate the legislative timeline. The government will not want a gap between data protection and AI governance. Enforcement will be the real test: the law's extraterritorial reach over foreign AI providers will depend on India's ability to block access to its market, a power it has already demonstrated through the IT Rules' takedown provisions and the Sahyog portal.
What would change the forecast: (1) If the liability frameworks diverge too sharply, the government may delay to reconcile them — watch for a consolidated draft by October 2026. (2) If the US or EU retaliates against Indian consent requirements as a trade barrier, New Delhi may soften the nationality clauses. (3) If a major AI-related incident — a deepfake-driven financial fraud at scale or an autonomous agent failure causing fatalities — occurs before the Bill is tabled, the law will become more restrictive, with criminal penalties and mandatory licensing, not just liability allocation. The window for a balanced framework is open now; it will not stay open long.
Key Takeaways
- India is preparing a standalone AI law — not an IT Act amendment — with consent requirements for synthetic content, autonomy limits on agentic AI, and regulatory sandboxes for high-risk applications.
- The pivot from "no rush to regulate" to a new statute was forced partly by a parliamentary committee recommendation in March 2026, not by ministerial initiative.
- Two independent legal experts have been commissioned to submit competing draft liability frameworks for AI models; their recommendations will shape whether foreign model providers face prohibitive compliance costs.
- The law's architecture extends the DPDP Act's consent-centric model into AI, creating a new regulated industry for AI consent management that, by statutory design, will be Indian.
- The economic stakes are massive: India's $315 billion technology sector faces disruption from agentic AI; the law functions as a speed governor that buys time for workforce adaptation while positioning Indian governance frameworks as an export.
What to Watch
- October-November 2026: Expected completion of the two commissioned draft liability frameworks; their consolidation into a single government position will signal the law's direction.
- Winter Session 2026 (November-December): Likely window for a draft AI Bill to be introduced in Parliament; the DPDP Rules' mid-2027 full-compliance deadline creates pressure to move.
- DPDP Rules full compliance (mid-2027): The consent-manager infrastructure will be operational; its capacity to absorb AI-specific consent workflows will test the law's implementability.
The Bottom Line
India's standalone AI law, now taking shape inside MeitY, is a market-access play dressed as a safety framework. The consent requirements for synthetic content and the curbs on agentic autonomy will raise compliance costs for foreign AI providers while creating a protected domestic industry for AI governance and consent management. The law does not ban foreign models. It licenses them, and the license is expensive.
Discover more

India
Delhi CM Rekha Gupta Blasts Opposition's Delm
Delhi CM Rekha Gupta's remarks on women's quota defeat reveal BJP's strategy for the 2029 Lok Sabha elections, focusing on delimitation.

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

Economics
US Tariffs on Brazil: A Political Play
US imposes 25% tariff on Brazil but exempts 66% of exports, targeting manufactured goods ahead of Brazil's October election. Analysis of the political calculus, exemptions, and Brazil's response options.