Stop Waiting for an "AI Act": MeitY's Reliance on DPDP and Existing IP Laws is a Wake-Up Call for Tech Lawyers
The Death of the "Wait and See" Approach to AI Law For the past two years, tech lawyers and in-house counsel have been advising clients on Generative AI with a standard, safe caveat: "The regulatory landscape is currently unsettled; we are awaiting d...
The Death of the "Wait and See" Approach to AI Law
For the past two years, tech lawyers and in-house counsel have been advising clients on Generative AI with a standard, safe caveat: "The regulatory landscape is currently unsettled; we are awaiting dedicated AI legislation."
It is time to retire that caveat. In a definitive policy posture for 2026, Electronics and IT Secretary S. Krishnan recently clarified that the Government of India will not introduce an AI-specific law unless "absolutely necessary." Instead, India will rely on the Digital Personal Data Protection (DPDP) Act, 2023, existing intellectual property frameworks, and the Information Technology Act to govern artificial intelligence.
For practicing lawyers, this "enabling" regulatory approach is not a green light for clients to operate in a legal vacuum. It is a mandate to creatively—and rigorously—apply legacy statutes to frontier technologies. If you are advising AI developers, fintechs, or digital platforms, the safety net of "upcoming regulation" is gone. The law is already here, and enforcement is knocking at the door.
The DPDP Act is Now India's De Facto AI Law
With the Centre notifying the administrative rules under the DPDP Act, privacy compliance is no longer a theoretical exercise. For AI companies whose foundational models rely on scraping vast oceans of personal data, the DPDP Act is now the primary regulatory hurdle.
A recent doctrinal analysis from SCC Online rightly points out that under Section 6 of the DPDP Act, consent is not a one-time checkbox—it is a continuous legal relationship. Data Fiduciaries must rethink their architecture. If a user withdraws consent, how does a tech company achieve "machine unlearning" to scrub that individual's data from a pre-trained Large Language Model (LLM)?
"The friction between a Data Principal's right to erasure (Section 12) and a fintech or AI platform's statutory retention obligations under PMLA or RBI guidelines is where the actual legal battles will be fought in 2026."
Furthermore, Section 9 of the DPDP Act mandates "verifiable parental consent" for processing children's data. This has been a logistical nightmare for platforms. However, MeitY's recent announcement that UIDAI's new Aadhaar app can be utilized for age verification without oversharing underlying demographic data is a game-changer. Tech lawyers must urgently update their clients' onboarding matrices to integrate this privacy-by-design Aadhaar architecture to avoid crippling penalties under the Act.
Intermediary Safe Harbour is Shrinking for AI Content
While the government avoids a standalone AI law, it is aggressively tweaking the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. The recent 2026 amendments targeting "synthetically generated information" (deepfakes) represent a massive shift in intermediary liability.
Historically, platforms relied on the safe harbour protection under Section 79 of the IT Act, 2000, acting as mere conduits. The new rules impose significantly lower takedown thresholds for AI-generated content. For lawyers, this means:
- Proactive Filtering vs. Safe Harbour: Advising social media and adtech intermediaries is becoming precarious. If a platform uses its own AI to recommend or alter user-generated content, it risks stepping out of its intermediary shoes and becoming a "publisher," thereby losing Section 79 immunity.
- Free Speech vs. Takedowns: As noted by LiveLaw, the constitutional scrutiny of these takedown mandates is inevitable. Lawyers will increasingly be drafting writ petitions challenging arbitrary takedowns under Article 19(1)(a), arguing that overzealous compliance by platforms is chilling legitimate digital expression.
The IP Conundrum: Forcing Square Pegs into Round Holes
By deferring to existing intellectual property laws, the government is leaving the heavy lifting to the courts. If a client asks, "Who owns the copyright to the code generated by our proprietary AI tool?", you must look to Section 2(d)(vi) of the Copyright Act, 1957, which confers authorship of a computer-generated work to "the person who causes the work to be created."
But who is that person? The prompt engineer? The LLM developer? The corporate entity? Because India has not introduced specific sui generis rights for AI outputs like the UK has, lawyers must rely on traditional work-for-hire doctrines and heavily customized terms of service (ToS) to secure IP rights for their clients. Your client's ToS is currently their only real shield against IP infringement claims arising from AI hallucinations or unauthorized scraping.
The Bottom Line for Practitioners
The government's message is loud and clear: innovate freely, but do so within the bounds of the DPDP Act and the IT Rules. The era of regulatory wait-and-see is over.
If your tech startup or fintech client does not have a dedicated Data Protection Officer (DPO), an Aadhaar-compliant age-gating mechanism, and a revised intermediary compliance strategy right now, they are operating on borrowed time. Stop looking to the horizon for an AI Act; the tools to regulate—and litigate—AI in India are already sitting on your desk.
Tags
Published by AnrakLegal AI