Legal News
2 May 2026
IP & Technology

Shoehorning AI into the DPDP Act: Why the Government’s 'No New Laws' Stance is a Litigation Goldmine

For IP and technology lawyers, the government’s recent policy crystallization is a wake-up call: there will be no sui generis Artificial Intelligence legislation in India. Instead, the Ministry of Electronics and Information Technology (MeitY) has ma...

For IP and technology lawyers, the government’s recent policy crystallization is a wake-up call: there will be no sui generis Artificial Intelligence legislation in India. Instead, the Ministry of Electronics and Information Technology (MeitY) has made a calculated—and highly consequential—decision to govern the AI boom using the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology (IT) Act, 2000, and existing intellectual property frameworks.

While the State frames this as a pro-innovation move designed to avoid stifling a nascent industry, the reality on the ground for practicing advocates is starkly different. We are not looking at a deregulated utopia. Rather, we are staring down a labyrinth of cross-disciplinary compliance that will force lawyers to simultaneously master data privacy, copyright infringement, and intermediary liability.

The AI Training Data Conundrum: Privacy Meets Copyright

The notification of the DPDP Rules in November 2025 fundamentally altered the risk matrix for AI developers. MeitY’s strategy is clear: regulate the input (data scraping and training) rather than the output (the AI model itself). But this creates a massive headache for tech counsels.

Under the new DPDP Rules, AI firms acting as Data Fiduciaries are subjected to stringent standards of verifiable consent, purpose limitation, and data traceability. If an Indian AI startup scrapes the web to train its Large Language Model (LLM), how does it ensure that the personal data ingested is traceably linked to a valid consent artifact? Technically, it is nearly impossible. Legally, it is a ticking time bomb.

The intersection of the DPDP Act and the Copyright Act, 1957 is where the next decade of tech litigation will be fought. When an AI model scrapes a dataset containing both copyrighted works and personal data, a lawyer can no longer just argue 'fair dealing' under Section 52(1)(a) of the Copyright Act. You must now also prove 'purpose limitation' under the DPDP Act.

If your client cannot prove that the data principal explicitly consented to their data being used to train an algorithmic model, the fair dealing defense in copyright might become moot in the face of crippling DPDP penalties.

Deepfakes and the Erosion of Intermediary Safe Harbor

If the DPDP Act governs AI inputs, the amended IT Rules govern the outputs. The April 2026 directive from the Gujarat High Court regarding AI-generated deepfakes is a prime indicator of judicial impatience with intermediary platforms.

The High Court has ordered strict compliance with the IT Rules, 2026, issuing notices for time-bound takedowns via the SAHYOG portal. This directly implicates Section 79(3)(b) of the IT Act. The moment an intermediary receives "actual knowledge" of a deepfake, the clock starts ticking. Failure to act expeditiously strips the platform of its safe harbor immunity, exposing it to direct liability for offenses that could range from defamation (Section 499, BNS) to identity theft (Section 66C, IT Act).

For litigators advising social media platforms or AI generation tools, the practice shift is immediate: you must overhaul your clients' grievance redressal mechanisms. Automated takedown pipelines are no longer a luxury; they are a legal necessity to preserve Section 79 immunity.

Operationalizing the Rules: What Changes for Practitioners?

The phased rollout of the DPDP Rules (extending into 2026 and 2027) means corporate lawyers and in-house counsels must move from theoretical advisory to operational engineering. Here is what is changing in practice right now:

1. The Rise of Consent Managers: Effective November 2026, Consent Managers will become the crucial intermediaries between Data Principals and Fiduciaries. Lawyers will need to draft entirely new tripartite agreements regulating the flow of consent tokens, ensuring these managers operate strictly within the bounds of the DPDP Act.

2. Dual Breach Reporting: Sector-specific preps, particularly in banking and fintech, are exposing a dual-reporting nightmare. If a fintech firm suffers a breach involving an AI-driven credit scoring model, counsels must immediately navigate reporting to both the Data Protection Board (under DPDP) and the RBI/CERT-In, often with conflicting timelines and disclosure requirements.

3. Privacy-Enhancing Tech as Legal Defense: We are seeing tech integrations directly driven by legal compliance. The updated Aadhaar app, which allows for DPDP-compliant age verification without oversharing underlying demographic data, is a perfect example. Lawyers must now advise clients on adopting such "privacy by design" architectures to proactively mitigate DPDP liability.

The Verdict

The government’s preference to use existing laws to regulate AI is a pragmatic political choice, but it effectively outsources the regulatory heavy lifting to the judiciary and the legal profession. By forcing 21st-century machine learning paradigms into the frameworks of the IT Act and the DPDP Act, the State has guaranteed one thing: a surge in complex, high-stakes litigation.

For the Indian lawyer, the days of specializing strictly in "IP" or "Privacy" are over. To defend an AI company today, you must be a hybrid practitioner capable of arguing complex copyright doctrine in the morning and negotiating technical DPDP consent architectures in the afternoon. The law hasn't changed, but the practice of it just got infinitely more complicated.

Published by AnrakLegal AI