Legal News
3 May 2026
IP & Technology

Stop Waiting for an 'AI Act': How the DPDP and IT Rules Just Became India's De Facto AI Law

If your technology, media, and telecommunications (TMT) practice has been idling in neutral, waiting for a shiny, standalone "Artificial Intelligence Act" to drop from the legislative heavens, it is time to wake up. The regulatory landscape for AI in...

If your technology, media, and telecommunications (TMT) practice has been idling in neutral, waiting for a shiny, standalone "Artificial Intelligence Act" to drop from the legislative heavens, it is time to wake up. The regulatory landscape for AI in India has officially crystallized in 2026—not through new legislation, but through the aggressive, combined weaponization of the Digital Personal Data Protection (DPDP) Act, 2023, the IT Act, 2000, and existing intellectual property frameworks.

The writing is on the wall. Speaking at Assocham’s AI Leadership Meet in April 2026, Ministry of Electronics and IT (MeitY) Secretary S Krishnan bluntly stated that new AI regulations are unnecessary "unless absolutely necessary." The government’s clear directive to the industry and the bar is this: stop looking for a silver bullet. The tools to govern AI data scraping, algorithmic training, and deepfakes are already at your disposal.

The DPDP Act is Now India's AI Training Law

For IP and tech lawyers, the notification of the DPDP Rules has fundamentally altered how we must advise clients building or deploying generative AI models. An LLM (Large Language Model) is only as good as its training data, and in India, a massive chunk of that data is now heavily guarded by the DPDP Act.

The DPDP Rules raise the compliance bar to punitive heights for AI firms. The days of indiscriminate web scraping under the guise of "fair dealing" or implied consent are over. Under Section 6(1) and Section 6(5) of the DPDP Act, consent is not a one-and-done checkbox; it has been interpreted by authorities in early 2026 as a "continuing legal relationship."

"When an AI firm scrapes data to train a model, they are functioning as a Data Fiduciary. If that dataset includes personal data, they must ensure traceable consent, stringent purpose limitation, and maintain auditable datasets. Non-compliant models are simply no longer viable in the Indian market."

Furthermore, do not attempt to shoehorn AI data scraping into Section 7(a) (certain legitimate uses for "voluntarily provided" data). Recent 2026 interpretations hold that "voluntarily provided" must be construed strictly in the context of the DPDP Rules. If a user uploads a photo to a social media site, they provided it to interact with friends—not to train a commercial image-generation algorithm. This creates a fascinating intersection with copyright and personality rights, forcing AI developers to negotiate licensing agreements rather than relying on legal loopholes.

Deepfakes, Safe Harbours, and the Gujarat High Court

While MeitY takes a policy stance, the judiciary is actively enforcing this duct-taped regulatory regime. In April 2026, a Division Bench of the Gujarat High Court (Sunita Agarwal and D.N. Ray, JJ.) heard a crucial PIL regarding AI deepfakes threatening public order.

Instead of lamenting the absence of a specific deepfake statute, the Court pivoted directly to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026. The Bench issued notices mandating strict adherence to time-bound takedowns under Section 79(3)(b) of the IT Act, leveraging the newly onboarded SAHYOG portal.

Why this matters for your practice: If you represent an intermediary (a social platform, a generative AI interface, or a cloud provider), your client's Section 79 safe harbour is hanging by a thread. The Gujarat High Court is making it clear that due diligence under the IT Rules is not a mere formality. When a deepfake violates an individual's personality rights (a tort of passing off well-established by the Delhi High Court in cases involving Bollywood celebrities), the platform must execute a takedown with ruthless efficiency under the statutory framework, or face primary liability.

Actionable Changes for the 2026 Practitioner

The "wait-and-see" era is dead. Here is how your practice must adapt immediately:

1. Overhaul Data Processing Agreements (DPAs): With Consent Managers phasing in by November 2026, your client's DPAs must account for dynamic consent withdrawal. If a user withdraws consent via a Consent Manager, your AI-client must have the technical architecture to scrub that user's personal data from the training weights—a technical nightmare known as "machine unlearning." If they cannot do this, they are in breach of the DPDP Act.

2. Age-Gating via Aadhaar: The DPDP Act's stringent rules on children's data have terrified tech platforms. However, the April 2026 launch of the UIDAI Aadhaar app, amending the Aadhaar Authentication for Good Governance Rules, 2020, provides a lifeline. Advise your clients to integrate this specific API for age verification—it satisfies DPDP requirements without triggering illegal data oversharing or retention liabilities.

3. IP Due Diligence in M&A: When conducting due diligence on an AI startup in 2026, looking at their patent portfolio is no longer enough. You must audit their training data. If the dataset lacks DPDP-compliant consent or infringes on third-party copyrights without a license, the IP is inherently tainted, and the valuation of the target company should plummet.

India is forging its own path on AI governance. We are not adopting the EU’s rigid, top-down AI Act, nor are we embracing the USA’s laissez-faire chaos. We are forcing emerging technologies to bend to existing data protection and intermediary liability laws. As lawyers, our job is no longer to wait for new laws, but to master the art of applying the DPDP Act and IT Rules to the algorithms of tomorrow.

Published by AnrakLegal AI