Forget the AI Act: How the 2026 IT Rule Amendments and DPDP Rollout Force a Radical Shift in Tech Law Practice
For the past two years, the Indian tech law fraternity has been waiting for a sweeping, European-style legislative monolithic to govern Artificial Intelligence. We can now officially stop waiting. In May 2026, Ministry of Electronics and IT (MeitY) S...
For the past two years, the Indian tech law fraternity has been waiting for a sweeping, European-style legislative monolithic to govern Artificial Intelligence. We can now officially stop waiting. In May 2026, Ministry of Electronics and IT (MeitY) Secretary S. Krishnan made the government’s posture unequivocally clear: India will not introduce a standalone AI law unless "absolutely necessary." Instead, the state will regulate the AI boom through existing frameworks.
This is not a regulatory retreat; it is a tactical pivot. For practicing lawyers, this "patchwork" approach is arguably more complex than a unified AI statute. It demands that we stop looking for a silver bullet and start aggressively cross-applying the Digital Personal Data Protection (DPDP) Act, 2023, the Copyright Act, 1957, and the newly amended Information Technology Rules, 2021. Here is why this policy stance changes how you must advise your tech, media, and platform clients today.
The Death of "Endeavour": The February 2026 IT Rules Amendment
The most immediate operational threat to digital platforms is the February 10, 2026, amendment to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules. Previously, platforms were merely required to "endeavour" to deploy automated tools or mechanisms to identify and take down unlawful content. The 2026 amendment swaps the word "endeavour" for "shall" when dealing with "synthetically generated information" (deepfakes and AI-generated media) lacking a "good faith" standard.
This seemingly minor semantic shift is a legal earthquake. By making the deployment of verification tools mandatory, the government has effectively raised the threshold for maintaining safe harbor protection under Section 79 of the Information Technology Act, 2000.
"If your client operates a platform where users can upload generative AI content, relying on post-facto takedowns via grievance officers is no longer sufficient. Failing to proactively deploy verification tools now strips the platform of its Section 79 immunity, opening the door to direct criminal and civil liability."
Practitioners must immediately audit their intermediary clients. Terms of Service (ToS) must be updated not just to prohibit malicious deepfakes, but to explicitly outline the platform's proactive algorithmic filtering mechanisms. If a platform is hit with a notice for hosting a deepfake, the defense will no longer be "we took it down in 36 hours," but rather, "our mandatory verification tools failed despite reasonable diligence."
DPDP Rules Notified: Consent is a Relationship, Not a Checkbox
With the Centre finally notifying the administrative rules for the DPDP Act in 2026, the era of treating privacy compliance as a one-time "clickwrap" exercise is dead. The SCC Online consensus is clear: under the DPDP Act, consent is now a continuing legal relationship.
For lawyers advising AI developers and ad-tech firms, this fundamentally alters data ingestion strategies. When an AI company scrapes Indian data to train Large Language Models (LLMs), any personal data swept up in that scrape falls squarely under Section 6 (Consent) and Section 8 (Data Fiduciary Obligations) of the DPDP Act. Because the Act allows Data Principals to withdraw consent at any time, AI developers face a nightmare scenario: how do you "unlearn" a specific user's personal data from a fully trained neural network?
Practice Point: You must advise Data Fiduciary clients to shift from mere "notice and consent" to dynamic consent management systems. Contracts with third-party data processors (the entities doing the actual AI model training) need robust indemnification clauses covering the failure to execute a Data Principal's request for data erasure.
The IP Vacuum: Relying on Courts over Parliament
By explicitly stating that intellectual property issues arising from AI will be handled under the existing IP Act, the government is forcing lawyers to stretch vintage statutes over modern problems.
Can an AI be an author? Under Section 2(d)(vi) of the Copyright Act, 1957, the author of a computer-generated work is "the person who causes the work to be created." Until the courts clarify whether "causing" means writing the prompt or writing the underlying code, advising creators remains a game of risk assessment.
However, the real action is in personality rights. With the tightening of the IT Rules around synthetic content, we are going to see a massive spike in celebrities and public figures seeking quia timet injunctions against AI platforms. Following the precedent set by the Delhi High Court in the Anil Kapoor and Amitabh Bachchan cases, lawyers should aggressively utilize the tort of passing off, combined with moral rights under Section 57 of the Copyright Act, to protect clients from unauthorized AI cloning and deepfakes.
The Bottom Line
The Indian government has made its bet: incremental regulation through existing laws fosters innovation better than a restrictive AI Act. But for the legal practitioner, this means the silos of "Privacy Law," "IP Law," and "Media Law" no longer exist.
To protect a tech client in 2026, you cannot just draft a privacy policy. You must simultaneously ensure DPDP continuous-consent compliance, mandate systemic filtering to preserve Section 79 safe harbor under the new IT Rules, and secure IP assignments that explicitly account for synthetic generation. The law hasn't been unified, which means the lawyer's approach must be.
Tags
Published by AnrakLegal AI