Legal News
15 August 2026
IP & Technology

Stop Waiting for an AI Act: India’s "Frankenstein" Tech Regulation is Already Here (and the Clock is Ticking)

The Myth of the Upcoming AI Law For the past three years, the Indian tech bar has been holding its breath, waiting for the Ministry of Electronics and Information Technology (MeitY) to drop a bespoke Artificial Intelligence Act. Lawyers have been adv...

The Myth of the Upcoming AI Law

For the past three years, the Indian tech bar has been holding its breath, waiting for the Ministry of Electronics and Information Technology (MeitY) to drop a bespoke Artificial Intelligence Act. Lawyers have been advising clients to "wait and see" how the regulatory dust settles before overhauling their data scraping and algorithmic training pipelines. In 2026, that waiting period is officially over—and the reality is far more complex than a single, unified AI statute.

MeitY Secretary S. Krishnan recently made the government’s position abundantly clear: India will not enact new AI-specific regulations unless absolutely necessary. Instead, the government is treating the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and existing Intellectual Property laws as the de facto governance framework for AI.

"We prefer using existing laws rather than creating new AI-specific regulation... the DPDP Act and the IP Act already cover many AI-related issues." — MeitY

For practicing lawyers, this means the regulatory regime for AI isn't coming in the future. It is already here, stitched together like a Frankenstein monster from disparate statutes. If you are advising tech companies, LLM developers, or digital intermediaries, your compliance strategy needs to pivot immediately.

The DPDP Act is Now India’s Default AI Law

The most significant shift in practice is recognizing the DPDP Act as an AI regulation. AI models are built on massive datasets, much of which constitutes "personal data" under Section 2(t) of the Act. With the Supreme Court recently refusing to stay the operation of the DPDP Act—despite issuing notice on pleas challenging its contentious amendments to Section 8(1)(j) of the RTI Act—the law is fully in motion.

The compliance runway is rapidly shortening. With key transition dates extending only into May 2027 (an 18-month window for substantive organizational obligations and 12 months for consent managers), the grace period is effectively over.

The biggest landmine for AI developers? Consent. Recent enforcement commentary emphasizes that under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous. How does an AI company obtain "specific" and "informed" consent to scrape a user's data to train a black-box neural network whose future outputs are entirely unpredictable? The short answer is: they likely can't.

Tech lawyers must immediately audit their clients' data ingestion pipelines. Relying on broad, bundled Terms of Service (ToS) agreements to train AI models is a direct violation of the DPDP Act. Furthermore, the Act mandates that withdrawing consent must be as easy as giving it. If a user withdraws consent, how do you mathematically "unlearn" their data from a trained LLM? This is no longer just a technical problem; it is an urgent legal liability.

The 3-Hour Guillotine for Intermediaries

If the DPDP Act governs the input (training data), the amended IT Rules govern the output (AI-generated content). The latest amendments have quietly introduced one of the most draconian intermediary liabilities in the world.

Under the revised IT Rules, the takedown response window for specific notices—particularly those involving synthetically generated information, deepfakes, and AI-manipulated media—has been slashed from 72 hours to a staggering 3 hours.

From a practice perspective, this is an operational impossibility for most mid-tier intermediaries. It forces platforms to abandon human-in-the-loop legal review in favor of automated, shoot-first-ask-questions-later algorithmic takedowns to preserve their safe harbor under Section 79 of the IT Act. If you represent social media platforms, content aggregators, or generative AI apps, you must draft rapid-response protocols and integrate automated hashing/takedown mechanisms immediately. Failing to meet the 3-hour window strips the intermediary of its immunity, exposing directors to criminal liability under the Bharatiya Nyaya Sanhita (BNS) and the IT Act.

The IP Collision: Copyright in the Age of Generative AI

Finally, we cannot ignore the IP fallout. With AI and IP now a formal focus of tech governance in 2026, the traditional boundaries of the Copyright Act, 1957 are being pushed to breaking point.

The core issues litigators are gearing up for include:

  • Authorship: Under Section 2(d)(vi) of the Copyright Act, the author of a computer-generated work is the "person who causes the work to be created." Is that the prompter, the AI developer, or neither?
  • Fair Dealing: Does ingesting copyrighted works to train an AI model fall under the "fair dealing" exception of Section 52(1)(a)? Given that AI models often produce outputs that compete directly with the original human authors, Indian courts are highly unlikely to view this as fair dealing.

The Bottom Line

The era of regulatory ambiguity is over. India has chosen its path for technology and AI governance: strict data protection, hyper-aggressive intermediary rules, and reliance on traditional IP frameworks.

Corporate and tech lawyers can no longer hide behind the absence of an "AI Act." You must master the intersection of the DPDP Act's consent architecture, the IT Rules' takedown timelines, and the Copyright Act's authorship constraints. The Supreme Court has signaled it will not halt this machinery. The 18-month compliance clock is ticking. Advise your clients to build compliance into their code today, or prepare for brutal enforcement tomorrow.

Published by AnrakLegal AI