Legal News
5 May 2026
IP & Technology

The AI Regulatory Mirage: Why MeitY’s Reliance on the DPDP and IP Acts is a Wake-Up Call for Tech Lawyers

The "No New Law" Bombshell for AI If you were holding your breath for a bespoke, European-style Artificial Intelligence Act in India, you can finally exhale. In early 2026, the Ministry of Electronics and Information Technology (MeitY) made its stanc...

The "No New Law" Bombshell for AI

If you were holding your breath for a bespoke, European-style Artificial Intelligence Act in India, you can finally exhale. In early 2026, the Ministry of Electronics and Information Technology (MeitY) made its stance unequivocally clear: India will not draft a lex specialis for AI. Instead, the government intends to govern the explosive growth of artificial intelligence by duct-taping together the newly operational Digital Personal Data Protection (DPDP) Act, 2023 and our legacy Intellectual Property (IP) laws.

From a policy standpoint, MeitY’s decision is designed to protect innovation. From a legal practice standpoint, it is a regulatory tightrope that shifts the entire burden of compliance—and liability—onto the shoulders of corporate counsel and tech lawyers.

"The government prefers using the DPDP Act alongside the IP Act to regulate AI, avoiding new laws to foster innovation unless essential." — MeitY Secretary S Krishnan

For Indian lawyers advising tech startups, LLM developers, or any enterprise deploying AI, this is the most critical development of the year. The grace period is over. With the DPDP Rules, 2025 officially notified on November 14, 2025, and phased enforcement rolling out through 2026, the era of scraping data with impunity has ended.

The IP-Privacy Collision in AI Training Pipelines

By forcing AI governance into the existing IP and data protection frameworks, the government has created a highly complex matrix for legal practitioners. Let’s break down what this means for your clients.

When an AI company trains a foundational model, it ingests massive datasets. Under the new regime, you must view every byte of training data through a dual lens:

1. The Privacy Lens (DPDP Act, 2023): If the dataset contains personal data, Section 6 of the DPDP Act kicks in. The 2025 Rules have elevated the compliance bar, mandating that consent is an ongoing relationship, not a static checkbox buried in a Terms of Service. AI firms are now legally required to ensure purpose limitation, data labeling, and traceability. If your client cannot prove exactly where a specific user's personal data sits in their neural network, and cannot delete it upon request under Section 8 (Right to Erasure), they are staring down the barrel of massive penalties.

2. The IP Lens (Copyright Act, 1957): If the dataset contains copyrighted works, we are heading for a judicial showdown. Can ingesting copyrighted material to train an AI model be defended under the "fair dealing" exceptions of Section 52 of the Copyright Act? The government's reliance on existing IP laws implies that courts will soon be tasked with stretching a 1957 statute to cover generative AI. We can expect heavy litigation around Section 14 (exclusive rights of the owner) versus text-and-data mining (TDM) practices.

The End of "Checkbox" Consent

One of the most profound shifts detailed in the recent 2026 analyses of the DPDP Rules is the operationalization of Consent Managers. Scheduled to become active by late 2026, these entities will serve as a bridge between the Data Principal and the Data Fiduciary.

For lawyers drafting privacy policies, the old copy-paste templates are now professional negligence. The rules demand granular, verifiable consent mechanisms. Furthermore, the integration of the DPDP rules with the Information Technology Act, 2000 means that cybersecurity mandates and data privacy obligations are now inextricably linked. AI firms must build transparent, auditable processes. If you are a general counsel, your immediate priority is a comprehensive audit of your company's data scraping and ingestion architecture.

The Sectoral Clash: Erasure vs. Retention

While tech lawyers grapple with AI, banking and fintech lawyers are facing their own existential crisis. The DPDP Act’s mandate for data erasure (Section 8) is on a direct collision course with sectoral data retention mandates.

Consider a fintech client: The DPDP Act demands they delete a user's financial data once the purpose is served or consent is withdrawn. However, Section 12 of the Prevention of Money Laundering Act (PMLA), 2002 and stringent RBI Master Directions mandate the retention of transaction records for up to five years. Which law prevails? While Section 38 of the DPDP Act states it is in addition to and not in derogation of other laws, the practical reconciliation of these conflicting mandates will require sophisticated legal maneuvering and highly specific internal data policies.

Interestingly, the government is offering some technological life rafts. The UIDAI’s updated Aadhaar app, modified via the Swik Rules, now allows for DPDP-compliant age verification without oversharing demographic data—a crucial tool for platforms needing to verify children's data under Section 9 of the DPDPA.

The Verdict: Adapt or Perish

MeitY’s decision to bypass an AI Act is not a reprieve; it is a complication. It forces Indian tech lawyers to become hybrid experts in both privacy and intellectual property. The staggered enforcement timelines into 2026 and 2027 offer a brief window for remediation.

Your action items as a practitioner are clear: Audit your clients' AI training pipelines for DPDP compliance, prepare for IP infringement claims if they rely on scraped data, and start drafting data retention policies that carefully navigate the tightrope between RBI guidelines and the DPDP Act. In 2026, the most valuable lawyers won't be those waiting for new laws—they will be the ones creatively applying the old ones to frontier technology.

Published by AnrakLegal AI