Legal News
3 June 2026
IP & Technology

No Standalone AI Law: Why India’s Plan to Regulate AI via the DPDP Act and Existing IP Laws is a Wake-Up Call for Practitioners

Stop waiting for the Great Indian AI Act. It isn’t happening anytime soon, and frankly, that changes everything about how tech and IP lawyers need to advise their clients today. In a watershed policy signal, the Ministry of Electronics and Informatio...

Stop waiting for the Great Indian AI Act. It isn’t happening anytime soon, and frankly, that changes everything about how tech and IP lawyers need to advise their clients today.

In a watershed policy signal, the Ministry of Electronics and Information Technology (MeitY) has made it clear that the government has no appetite for rushing a standalone AI statute. Instead, according to the MeitY Secretary, the state will rely on the existing intellectual property regime and the freshly operationalized Digital Personal Data Protection (DPDP) Act, 2023 to govern artificial intelligence. Unless it becomes "absolutely necessary," India is choosing a patchwork regulatory approach over a unified code.

For legal practitioners, this is not a "wait and watch" moment. It is a call to arms. The government’s reluctance to draft new AI laws means we are about to witness an era of intense legal gymnastics, where courts and lawyers will be forced to stretch the Copyright Act, 1957 and the newly minted DPDP Rules, 2025 to fit the unprecedented realities of generative AI.

The DPDP Rules 2025: India’s Backdoor AI Regulator

On 14 November 2025, the government notified the much-anticipated DPDP Rules, operationalizing the DPDP Act. While mainstream media frames this purely as a privacy update tightening rules for major tech firms, sharp practitioners should recognize it for what it truly is: India’s first de facto AI regulation.

AI models are built on mass data scraping. By enforcing strict purpose limitation and data minimization under the DPDP Rules, the government has essentially put a chokehold on how Large Language Models (LLMs) can be trained on Indian data. Under Section 5 (Notice) and Section 6 (Consent) of the DPDP Act, a Data Fiduciary must obtain clear, affirmative consent for a specific purpose.

How do you provide a granular notice or obtain specific, withdrawable consent from millions of users whose personal data is scraped from the open web to train a generative AI model? The short answer is: you can't.

The new rules mandate that companies can only collect "essential data" for specific purposes and must provide users with a clear mechanism to decline or withdraw consent. This severely disrupts the "scrape-first, ask-forgiveness-later" model of AI development. Tech lawyers advising AI startups or legacy tech giants must immediately pivot from hypothetical AI risk assessments to hardcore DPDP compliance audits. If your client is scraping the web without filtering out personally identifiable information (PII), they are walking into a regulatory minefield.

Stretching the Copyright Act: A Square Peg in a Round Hole

The government's stance that existing IP laws cover "a fair amount of issues" arising from AI is, to put it mildly, highly optimistic. Relying on the Copyright Act, 1957 to resolve AI disputes is going to create a litigator's paradise and an advisor's nightmare.

When an AI model generates a piece of code or artwork, who is the author? Section 2(d)(vi) of the Copyright Act grants authorship of a computer-generated work to the person who "causes the work to be created." But in the age of prompt engineering, is the user the author, or the AI developer? The statute is completely silent on the nuances of autonomous generative outputs.

Furthermore, we are bound to see massive litigation surrounding Section 52(1)(a)—the "fair dealing" exception. AI companies will inevitably argue that training their models on copyrighted Indian works constitutes fair dealing for research. Rights holders will argue it is blatant commercial infringement. Without a specific AI statute to clarify the boundaries of text and data mining (TDM), Indian courts will have to rely on archaic precedents to decide the future of the domestic AI industry. IP lawyers need to stop expecting statutory clarity and start preparing aggressive, creative arguments based on first principles of copyright law.

The IT Rules 2026 Amendment: The War on "Synthetically Generated Information"

While MeitY is avoiding a comprehensive AI law, they are quietly weaponizing the Information Technology Act, 2000. The February 2026 amendments to the IT Rules have drastically tightened takedown obligations for "synthetically generated information"—the government’s catch-all phrase for deepfakes and AI-generated misinformation.

This fundamentally alters the intermediary liability landscape. The safe harbour protection under Section 79 of the IT Act is now highly conditional. Social media platforms and AI hosts are no longer passive conduits; they are expected to act as proactive content police. If platforms fail to rapidly take down synthetically generated content upon receiving a grievance, they risk losing their safe harbour status entirely.

For media and technology counsel, the advice to clients must change overnight. Intermediaries must now implement robust, AI-driven detection mechanisms to identify and remove deepfakes before they escalate into legal notices. The threshold for compliance has moved from reactive takedowns to proactive policing.

The Practitioner's Takeaway

The message from the government is clear: do not look to the legislature to solve your AI problems. The regulation of artificial intelligence in India will not happen through a shiny new "AI Act." Instead, it will be forged in the fire of DPDP compliance notices, copyright infringement suits, and Section 79 safe harbour disputes.

Lawyers who master the intersection of the DPDP Rules 2025, the IT Rules 2026 amendments, and traditional IP enforcement will dominate the next decade of tech law in India. Those still waiting for a standalone AI statute will be left behind in the dust.

Published by AnrakLegal AI