Legal News
4 May 2026
IP & Technology

No New AI Law: Why the Government's Reliance on the DPDP Act is a Compliance Minefield for Tech Lawyers

In a move that will fundamentally alter the practice of technology and intellectual property law in India, the government has made its stance clear for 2026: there will be no bespoke legislation to govern Artificial Intelligence. Instead, the Ministr...

In a move that will fundamentally alter the practice of technology and intellectual property law in India, the government has made its stance clear for 2026: there will be no bespoke legislation to govern Artificial Intelligence. Instead, the Ministry of Electronics and Information Technology (MeitY) is force-fitting AI regulation into the existing Digital Personal Data Protection (DPDP) Act, 2023 and our legacy intellectual property statutes.

For policymakers, this is framed as a pro-innovation strategy to boost the IndiaAI Mission. For practicing lawyers and in-house counsel, however, this "wait and watch" approach is a compliance minefield. By relying on a data privacy statute to regulate generative AI, the government has essentially outsourced the heavy lifting to the judiciary and corporate legal departments. If your practice involves IP enforcement, data privacy, or advising tech startups, the rules of the game have just been rewritten.

The AI Training Data Trap: Consent in the Age of LLMs

The newly notified DPDP Rules, 2025 have radically raised the compliance bar for AI firms. For years, the global AI industry has operated on a "scrape first, ask forgiveness later" model. Under the DPDP framework, that era is dead in India.

Because the government is using the DPDP Act as its primary AI regulator, the training pipelines of Large Language Models (LLMs) must now strictly adhere to the principles of purpose limitation and verifiable consent. Lawyers advising Data Fiduciaries (AI developers) must now ensure that their clients' datasets are entirely auditable.

"Consent under the DPDP Act is no longer a one-time checkbox; it is a continuing legal relationship. For AI companies, this means the inability to trace the origin and consent parameters of a training dataset is now a fatal operational liability."

Practically, this means tech lawyers must draft complex data-sharing agreements and revamp privacy notices under Section 5 of the DPDP Act to explicitly cover machine learning ingestion. If a client cannot prove lawful, consent-backed processing for their datasets, their domestic AI models are dead on arrival.

Delhi High Court Pierces the Privacy Shield in IP Litigation

One of the most immediate practical fallouts of the DPDP Act has been its weaponization by corporate infringers. Domain Name Registrars (DNRs) have increasingly cited data privacy obligations to refuse the disclosure of registrant details in trademark infringement cases, frustrating brand owners and stalling John Doe / Ashok Kumar injunctions.

In a crucial March 27, 2026 ruling, the Delhi High Court finally called their bluff. The Court addressed the acute friction between trademark enforcement and personal data protection, ruling that DNRs cannot use the DPDP Act as an absolute shield against IP enforcement.

Drawing on the proportionality test laid down in K.S. Puttaswamy v. Union of India (2017), the Court clarified that under Section 4 of the DPDP Act (processing for legitimate uses), DNRs are legally bound to disclose registrant data when directed by a judicial order. For IP litigators, this is a massive relief. When drafting infringement plaints involving domain name fraud, lawyers must now proactively plead Section 4 exemptions to compel DNR compliance, ensuring that privacy laws do not become a safe haven for cyber-squatters and counterfeiters.

Deepfakes and the Shrinking Safe Harbour

While the Delhi High Court balanced privacy and IP, the Gujarat High Court has taken a sledgehammer to intermediary safe harbours in the context of AI deepfakes. On April 18, 2026, the Court directed the strict enforcement of the newly amended IT Rules, 2026 against platforms hosting deepfakes.

The days of passive hosting are over. To maintain their safe harbour immunity under Section 79(3)(b) of the Information Technology Act, 2000, intermediaries must now integrate with the government's SAHYOG portal for time-bound takedowns. The Court's directive emphasizes that "due diligence" is an active, ongoing obligation.

For lawyers advising social media platforms and content aggregators, the Gujarat High Court order requires an immediate overhaul of intermediary compliance manuals. Failing to execute rapid, SAHYOG-coordinated takedowns of deepfakes will result in the immediate stripping of Section 79 immunity, opening executives to direct criminal liability.

The Road to May 2027: Practice Management Takeaways

With the phased rollout of the DPDP Act culminating in full enforcement by May 2027, the window for theoretical debate has closed. The activation of Consent Manager provisions by November 15, 2026, and the integration of DPDP-compliant age verification via UIDAI's updated Swik Rules, mean that implementation is now an urgent, sector-agnostic mandate.

Banks, fintechs, and tech startups are already establishing internal privacy offices and implementing dual breach-reporting protocols (to both CERT-In and the Data Protection Board). As legal professionals, our role is no longer just advising on the DPDP Act in isolation. We must now synthesize the IT Act, the DPDP Act, and the Trademarks/Copyright Acts into a cohesive compliance strategy.

The government may have opted out of drafting an AI-specific law, but they have inadvertently created something far more complex: a fragmented regulatory ecosystem where technology, privacy, and IP collide daily. For the sharp tech lawyer, there has never been a more lucrative—or perilous—time to practice.

Published by AnrakLegal AI