Legal News
1 May 2026
IP & Technology

The AI Regulatory Mirage: Why India’s Reliance on the DPDP Act and IP Laws is a Goldmine for Tech Lawyers

The Illusion of "No New Regulations" If you were waiting for a bespoke Artificial Intelligence Act to guide your tech clients, you can stop holding your breath. In a definitive policy posture, the Ministry of Electronics and Information Technology (M...

The Illusion of "No New Regulations"

If you were waiting for a bespoke Artificial Intelligence Act to guide your tech clients, you can stop holding your breath. In a definitive policy posture, the Ministry of Electronics and Information Technology (MeitY) has made it clear: India will not legislate a separate AI law unless "absolutely necessary." Instead, the government is adopting a shoehorn approach—forcing the governance of generative AI, deepfakes, and algorithmic training into the existing frameworks of the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000, and the Copyright Act, 1957.

For tech policy purists, this might seem like a regulatory cop-out. But for practicing technology lawyers and in-house counsel, this "innovation-first" approach is a ticking compliance time bomb. By refusing to create a dedicated AI statute, the government has essentially outsourced the regulation of emerging tech to corporate compliance teams and the judiciary. We are about to see a massive surge in advisory and litigation work as businesses try to retrofit AI operations into laws that were drafted before ChatGPT even existed.

The DPDP Rules 2025: Consent is No Longer a Checkbox

The most immediate and aggressive compliance mandate stems from the newly notified Digital Personal Data Protection Rules, 2025 (November 13, 2025). With enforcement anticipated by May 2026, law firms and corporate privacy offices have less than 18 months to overhaul their clients' data architectures.

The biggest paradigm shift for practitioners to note is the evolution of consent. Under Section 43A of the old IT Act regime, consent was largely a transactional, clickwrap "I Agree" button. The DPDP Act, operationalized by the 2025 Rules, fundamentally alters this jurisprudence.

"Consent under the DPDP Act is not a one-off transaction; it is a continuing legal relationship between the Data Principal and the Data Fiduciary."

What does this mean in practice? Under Section 6 of the DPDP Act, the burden of proving that valid, informed, and unconditional consent was obtained—and maintained—rests entirely on the Data Fiduciary. If your client is a fintech startup or a bank using customer data to train an AI credit-scoring model, legacy consent mechanisms will fail the statutory test. Lawyers must immediately begin drafting multi-layered, granular notice frameworks that allow Data Principals to withdraw consent as easily as they gave it, without breaking the underlying service.

Deepfakes and the Shrinking Safe Harbour

While MeitY preaches a light-touch approach to AI, the judiciary is losing patience with generative AI's malicious byproducts. The Gujarat High Court’s recent directive demanding strict compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, signals a tightening noose around intermediary liability.

The Court has mandated that intermediaries implement strict due diligence obligations and integrate with the government's SAHYOG portal to tackle deepfakes. Here is the critical takeaway for litigation lawyers: Section 79 of the IT Act is no longer an absolute shield.

The conditional safe harbour provided to intermediaries is contingent on proactive compliance. If your client hosts user-generated content and fails to establish a rapid takedown mechanism for deepfakes as per the 2026 Rules, they will lose their safe harbour immunity. This exposes directors and key managerial personnel to direct criminal liability under the Bharatiya Nyaya Sanhita (BNS) and the IT Act. Practitioners must advise platforms to shift from reactive takedowns to proactive algorithmic filtering, despite the inherent free speech tensions.

Section 9 Compliance: The Aadhaar Loophole

One of the most heavily debated provisions of the DPDP Act has been Section 9, which mandates "verifiable parental consent" for processing the data of minors. For ed-tech, gaming, and social media clients, age-gating without collecting excessive personal data (which violates the principle of data minimization under Section 4) seemed technically impossible.

The government has ingeniously bypassed this paradox by amending the Aadhaar Authentication Rules. The new Aadhaar app allows for decentralized, tokenized age verification. Hotels, cinemas, and online platforms can now ping the UIDAI ecosystem to verify if a user is above 18 without extracting the user's actual date of birth or demographic data.

Practice Note: Privacy lawyers should immediately advise clients facing Section 9 compliance hurdles to integrate this new Aadhaar API. It serves as a statutory safe harbor for age verification, minimizing the Data Fiduciary's risk of holding toxic, heavily regulated children's data.

The Road Ahead for Practitioners

India’s strategy of regulating AI through the DPDP and IP Acts is a double-edged sword. It avoids the rigidity of the EU AI Act, fostering an environment where domestic AI models can train and scale. However, it requires legal practitioners to engage in creative statutory interpretation.

If an AI model scrapes personal data from the web, is it a violation of the DPDP Act, or does it fall under a "publicly available data" exemption? If it scrapes copyrighted text, does it qualify as "fair dealing" under Section 52 of the Copyright Act? Because Parliament has chosen not to answer these questions via a new AI Act, the answers will be written in the chambers of law firms and the halls of the High Courts over the next two years. Prepare your practice accordingly; the era of tech-regulatory convergence is here.

Published by AnrakLegal AI