Legal News
20 May 2026
IP & Technology

The AI Law That Wasn't: Why India’s ‘Patchwork’ Approach to AI is a Compliance Minefield for Tech Lawyers

The Illusion of Deregulation If you were holding your breath for an Indian equivalent to the European Union’s sweeping AI Act, it is time to exhale. On May 19, 2026, Ministry of Electronics and IT (MeitY) Secretary S. Krishnan made it unequivocally c...

The Illusion of Deregulation

If you were holding your breath for an Indian equivalent to the European Union’s sweeping AI Act, it is time to exhale. On May 19, 2026, Ministry of Electronics and IT (MeitY) Secretary S. Krishnan made it unequivocally clear: the Indian government will avoid enacting new AI-specific regulations unless "absolutely necessary." Instead, India will govern artificial intelligence through existing legal frameworks, primarily the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000, and traditional intellectual property laws.

Make no mistake—this is not deregulation. It is decentralized regulation. By refusing to create a unified AI statute, the government is forcing practicing lawyers to play a high-stakes game of legal Twister, stretching legacy statutes and brand-new privacy rules to cover generative AI, deepfakes, and algorithmic bias. For corporate counsels, IP litigators, and tech advisors, this "patchwork" approach is about to fundamentally change how you practice law.

The DPDP Act: AI’s Data Hunger Meets "Consent as Governance"

The most immediate hurdle for AI developers operating in India lies in the newly operationalized DPDP Act. With the Centre recently notifying the administrative rules and the DPDP Rules, 2025 firmly in play, the theoretical debates about privacy have collapsed into strict compliance mandates.

Generative AI models are fundamentally incompatible with traditional privacy frameworks. Large Language Models (LLMs) are trained on massive datasets scraped from the internet, often containing personal data. However, under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous.

How does a Data Fiduciary obtain "specific and informed" consent to scrape a user's publicly available blog post to train an AI model whose outputs are entirely unpredictable? The short answer: they probably can't.

The DPDP framework has framed consent not just as a tick-box, but as a continuous governance architecture. For lawyers advising tech startups, the days of drafting broad, catch-all "Terms of Service" are over. You must now architect consent mechanisms that account for AI training, establish robust notice procedures under Section 5, and prepare for the reality that users can revoke consent at any time, theoretically requiring the "unlearning" of their data from an already trained model—a technical nightmare. The severe financial penalties under the DPDP Act mean that non-compliance is no longer just a cost of doing business; it is an existential threat to startups.

The February 2026 IT Rules Amendment: The End of Passive Safe Harbor

While the government claims it is relying on "existing" laws, it is quietly weaponizing them through executive rule-making. The February 10, 2026 amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 is the prime example.

Targeting Synthetically Generated Information (SGI)—the bureaucratic term for AI-generated content and deepfakes—the amendment imposes aggressive takedown obligations on intermediaries. Platforms are now subjected to drastically shortened timelines to remove harmful SGI once flagged.

Why does this matter for your practice? It effectively neuters the Safe Harbor protection under Section 79 of the IT Act. Historically, intermediaries enjoyed immunity provided they acted as passive conduits and adhered to standard due diligence. Now, the burden has shifted. Platforms must proactively assess whether content is a malicious deepfake or legitimate satire, navigating the murky waters of "good faith" assessments.

The practical shift: Tech lawyers must immediately revise intermediary compliance manuals. You need to build rapid-response legal frameworks for content moderation teams. A failure to take down a deepfake within the new statutory window won't just result in a warning; it strips the platform of its Section 79 immunity, exposing executives to direct criminal liability under the Bharatiya Nyaya Sanhita (BNS) and the IT Act.

Stretching the Copyright Act to the Breaking Point

By leaving AI copyright issues to "existing IP law," the government has essentially passed the buck to the judiciary. The Copyright Act, 1957 is ill-equipped to handle generative AI. Under Section 2(d)(vi), the author of a computer-generated work is "the person who causes the work to be created."

But who causes a Midjourney image to be created? Is it the user who inputs the prompt? The developers who wrote the algorithm? Or the original artists whose scraped works trained the model? Without legislative clarity, IP lawyers must prepare for aggressive, test-case litigation. We will likely see an explosion of copyright infringement suits against AI platforms, mirroring global trends, as Indian rightsholders test the limits of the "fair dealing" exceptions under Section 52 of the Copyright Act.

The Bottom Line

The Indian government's "wait and watch" approach to a standalone AI law might foster innovation in the short term, but it shifts the entire burden of regulatory friction onto the legal profession.

For Indian lawyers, siloed practice areas are dead. You can no longer be "just" an IP lawyer or "just" a privacy lawyer. Advising a tech client in 2026 requires harmonizing the aggressive data restrictions of the DPDP Act, the strict intermediary liabilities of the amended IT Rules, and the archaic authorship principles of the Copyright Act. The law may not have changed its name, but its application has mutated entirely. Adapt your practice accordingly.

Published by AnrakLegal AI