Legal News
29 April 2026
IP & Technology

The AI Regulatory Dodge: Why the Government's Reliance on DPDP and IP Laws is a Drafting Minefield for Tech Lawyers

The End of the "Bespoke AI Law" Mirage If you were holding your breath for a comprehensive Artificial Intelligence Act in India, it is time to exhale and look at the statutes already sitting on your desk. In April 2026, MeitY Secretary S Krishnan mad...

The End of the "Bespoke AI Law" Mirage

If you were holding your breath for a comprehensive Artificial Intelligence Act in India, it is time to exhale and look at the statutes already sitting on your desk. In April 2026, MeitY Secretary S Krishnan made it unequivocally clear: the Indian government will not enact a separate AI law. Instead, the mandate is to govern AI and emerging tech through the Digital Personal Data Protection (DPDP) Act, 2023, and existing Intellectual Property frameworks.

For tech, IP, and corporate lawyers, this is a seismic shift in regulatory strategy. By refusing to draft a bespoke AI framework to "avoid stifling innovation," the government has effectively outsourced the heavy lifting of algorithmic governance to the newly notified DPDP Rules, 2025 (operationalized in November 2025) and the Copyright Act, 1957. What the government calls "fostering innovation," practicing lawyers should recognize as a massive regulatory gray area that we will have to draft our way out of.

The AI-IP-Privacy Collision Course

The intersection of AI, DPDP, and IP is where the most complex litigation and advisory work will emerge over the next two years. Large Language Models (LLMs) and generative AI systems require immense datasets for training—datasets that inevitably contain both copyrighted works and digital personal data.

Under existing IP law, scraping data to train commercial AI models sits uncomfortably outside the "fair dealing" exemptions of Section 52(1)(a) of the Copyright Act, 1957. But the DPDP Act introduces a harsher reality. Under Section 4 of the DPDPA, processing personal data requires explicit, granular consent or a strictly defined "certain legitimate use."

"You cannot get explicit, informed consent from a million data principals to use their personal data for training a black-box AI model. By defaulting AI regulation to the DPDPA, the government has inadvertently made the lawful training of indigenous AI models an absolute compliance nightmare."

For IP lawyers, this means advising tech clients that copyright clearance is no longer enough. If the dataset contains personal data, the algorithm itself becomes a privacy liability.

Significant Data Fiduciaries (SDFs) and Algorithmic Audits

With the DPDP Rules 2025 now active, the focal point for tech companies is the dreaded Significant Data Fiduciary (SDF) designation under Section 10 of the DPDPA. While the government committee is still finalizing the exact threshold criteria, any business deploying high-risk AI (such as fintech algorithms for credit scoring, or HR tech for automated hiring) should expect the SDF tag.

Why does this matter in practice? Because SDFs are required to conduct Data Protection Impact Assessments (DPIAs). In the context of AI, a DPIA isn't just a basic cybersecurity audit; it is an algorithmic audit. Litigators should anticipate a new wave of disputes where algorithmic bias or AI hallucinations that result in the misuse of personal data will be treated as statutory breaches under the DPDPA, attracting penalties of up to ₹250 crores.

Drafting in 2026: Boilerplates are Dead

If your firm is still using standard "compliance with Section 43A of the Information Technology Act, 2000 and SPDI Rules" clauses in SaaS agreements or IP licenses, you are committing malpractice. With the full enforcement of the DPDPA looming on May 13, 2027, commercial contracts must evolve immediately.

Here is what needs to change in your drafting practice today:

1. Consent Management Interfaces: The DPDP regime treats consent not as a one-time checkbox, but as an ongoing relationship. With Consent Manager provisions activating by November 2026 (under Section 6 and 7 of the Act), vendor agreements must explicitly assign technical liability for integrating with these managers. Who bears the cost if a Consent Manager revokes consent and the data processor fails to purge the data from an AI training set?

2. The Erasure vs. Retention Catch-22: Fintech and banking lawyers are currently staring at a massive statutory conflict. Section 8(7) of the DPDPA mandates the erasure of personal data once the purpose is served or consent is withdrawn. However, Section 12 of the Prevention of Money Laundering Act (PMLA), 2002, and various RBI Master Directions mandate strict data retention for five to ten years. Until the courts apply the doctrine of harmonious construction to resolve this, your contracts must clearly delineate between data held for commercial purposes (subject to immediate erasure) and data held for statutory compliance.

The Road to May 2027

The lack of specific AI regulation does not mean a lack of AI liability; it simply means the liability is hidden within the DPDP Act and the Copyright Act. As lawyers, the grace period is over. The November 2025 notification of the DPDP Rules fired the starting gun. Businesses are currently operating in a state of wary uncertainty regarding data localization and SDF designations, particularly startups participating in schemes like DLI 2.0 where IP residency restrictions clash with cross-border data flows.

Corporate counsel must stop viewing the DPDP Act merely as a "privacy law." It is now India’s de facto AI law, algorithmic governance law, and tech-diligence law. The time to audit tech architectures, revise data processing agreements, and prepare for the Consent Manager rollout is right now. By the time May 2027 arrives, the cost of non-compliance will be existential for your clients.

Published by AnrakLegal AI