The AI Illusion: Why Forcing the DPDP Act to Govern Artificial Intelligence is a Drafting Nightmare for Lawyers
“We won't regulate AI directly to protect innovation.” It sounds like a progressive, tech-forward policy for startups. But for the Indian legal fraternity, the Ministry of Electronics and IT’s (MeitY) latest stance—reaffirming that India will rely on...
“We won't regulate AI directly to protect innovation.” It sounds like a progressive, tech-forward policy for startups. But for the Indian legal fraternity, the Ministry of Electronics and IT’s (MeitY) latest stance—reaffirming that India will rely on the Digital Personal Data Protection (DPDP) Act, 2023 and existing Intellectual Property laws to govern Artificial Intelligence—is a ticking time bomb.
As we navigate the fallout of the newly notified 2025 DPDP Rules and look toward strict enforcement in 2026, the government’s refusal to draft a standalone AI law is transferring the entire burden of AI governance onto the shoulders of transactional lawyers and litigators. We are now being asked to force the square peg of generative AI into the round holes of a data privacy statute and a 1957 Copyright Act. Here is why this "wait and watch" regulatory approach is set to upend your practice this year.
The Death of Boilerplate: Rewriting the Commercial Contract
If your firm is still using pre-2024 boilerplate data protection clauses in SaaS agreements, you are exposing your clients to crippling liability. The 2025 DPDP Rules have fundamentally altered how we must draft commercial contracts, particularly for entities deploying AI tools.
Under Section 8(2) of the DPDP Act, the Data Fiduciary remains solely responsible for compliance, even when processing is outsourced to a Data Processor (like an enterprise AI vendor). Because AI models inherently ingest, retain, and process vast amounts of unstructured data, the concept of "purpose limitation" under Section 5 becomes a drafting nightmare. How do you draft a specific, clear, and itemized notice for an AI model whose outputs are inherently unpredictable?
The days of perpetual, blanket consent are over. The DPDP Act treats consent not as a one-time checkbox, but as an ongoing relationship. For lawyers drafting vendor agreements in 2026, this means embedding dynamic consent mechanisms directly into the operational covenants of the contract.
Furthermore, if your client is classified as a Significant Data Fiduciary (SDF) under Section 10, the compliance burden skyrockets. Contracts must now explicitly outline security schedules, algorithmic oversight mechanisms, and aggressive breach notification timelines. Indemnity clauses will no longer be standard; they will be heavily negotiated battlegrounds allocating risk for AI hallucination and unauthorized data scraping.
The Deepfake Vacuum: Where DPDP Meets IP
The intersection of the DPDP Act and IP law is perhaps the most glaring gap in the government's current strategy. MeitY suggests that existing frameworks will handle AI's rough edges. But do they?
Take personality rights and deepfakes. The DPDP Act governs personal data—defined as data about an individual who is identifiable by or in relation to such data. But a deepfake is synthetic media. It is artificially generated. If an AI generates a voice clone of a public figure, is it processing "personal data," or is it creating a new, infringing derivative work?
Currently, Indian law lacks statutory recognition of personality rights. We rely on the common law tort of passing off and Article 21 privacy rights, as seen in the Delhi High Court’s ad-interim injunctions protecting the personality rights of actors like Anil Kapoor and Amitabh Bachchan. Relying on the DPDP Act to govern deepfakes is legally flawed because the Act was designed to regulate corporate data processing, not to police synthetic identity theft. Until the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 are amended to mandate biometric consent specifically for AI, litigators will have to continue pleading creative, patchwork IP suits to protect their clients.
Sectoral Collisions: The Fintech and Banking Dilemma
For in-house counsel at banks and fintechs, the phased rollout of the DPDP Act in 2026 is creating a severe regulatory collision. The DPDP Act grants Data Principals the right to erasure under Section 9. However, financial institutions are bound by strict data retention mandates under the Prevention of Money Laundering Act, 2002 (PMLA) and Reserve Bank of India (RBI) guidelines.
While Section 17 of the DPDP Act provides exemptions when processing is necessary for enforcing legal rights or complying with other laws, the operational reality of untangling an individual's data from an AI-driven credit scoring model to honor an erasure request is monumental. Furthermore, lawyers must now prepare clients for dual breach reporting: notifying the CERT-In under the IT Act within 6 hours, while simultaneously navigating the new reporting thresholds to the Data Protection Board under the DPDP Rules.
The Bottom Line for Practitioners
The government’s "innovation-first" approach is a euphemism for regulatory abstention. By refusing to enact tailored AI legislation, the state has effectively outsourced AI regulation to private commercial contracts and the judiciary.
For Indian lawyers, the mandate is clear. You cannot wait for courts to interpret the 2025 Rules. You must proactively audit and amend every technology, vendor, and employment contract. You must draft AI acceptable use policies that straddle the line between the Copyright Act's fair dealing exceptions and the DPDP Act's data minimization mandates. The law may be lagging, but as of 2026, the liability is already here.
Tags
Published by AnrakLegal AI