Legal News
18 April 2026
IP & Technology

The "Duct-Tape" Tech Law: Why Stretching the DPDP Act to Regulate AI is a Litigation Minefield

If you were holding your breath for a bespoke Indian Artificial Intelligence Act, you can exhale. The Ministry of Electronics and IT (MeitY) has made its stance unequivocally clear: innovation trumps regulation, and our existing legal framework is su...

If you were holding your breath for a bespoke Indian Artificial Intelligence Act, you can exhale. The Ministry of Electronics and IT (MeitY) has made its stance unequivocally clear: innovation trumps regulation, and our existing legal framework is supposedly robust enough to handle the AI revolution. According to recent statements from MeitY Secretary S Krishnan in April 2026, the government will rely on the Digital Personal Data Protection (DPDP) Act, 2023 and existing intellectual property laws to govern AI.

For practicing tech and IP lawyers, this "duct-tape" approach—shoehorning complex generative AI issues into a data privacy statute—should set off alarm bells. While the government prefers to avoid stifling innovation with heavy-handed AI regulations, leaving the heavy lifting to the DPDP Act and a patchwork of IP reforms is guaranteed to create a lucrative, albeit chaotic, litigation minefield.

The AI and DPDP Collision: A Consent Nightmare

The DPDP Rules, 2025 have finally been notified, setting the stage for strict enforcement by May 2027. Under this framework, consent is not a one-off checkbox; it is an ongoing relationship with an absolute right to easy withdrawal under Section 6 of the DPDP Act. But how does this square with Large Language Models (LLMs)?

When a Data Principal withdraws consent, Section 8(7) mandates the erasure of their personal data. For a traditional e-commerce platform, this means deleting a database entry. For an AI developer, personal data scraped from the web is already baked into the neural network's weights. "Machine unlearning" is technologically nascent. By relying on the DPDP Act to govern AI, the government has inadvertently set up a scenario where data fiduciaries will find it technically impossible to comply with statutory erasure requests, leaving them vulnerable to the DPDP Board's draconian penalties.

"Shoehorning generative AI into a data privacy statute designed for traditional web services is like trying to regulate a spaceship using the Motor Vehicles Act."

Virtual Designs: A Welcome IP Overhaul

While the DPDP Act struggles with AI, the Department for Promotion of Industry and Internal Trade (DPIIT) is taking a much more pragmatic approach to IP reform. The proposed amendments to the Designs Act, 2000 are a massive leap forward for tech lawyers.

Historically, Section 2(a) and 2(d) of the Designs Act restricted protection to physical "articles." The proposed reforms finally expand these definitions to protect virtual designs. This means animations, Graphical User Interfaces (GUIs), and immersive AR/VR experiences can now be registered. Furthermore, aligning with the Hague Agreement, the protection term is shifting to a '5+5+5' year structure.

Practice Note: IP practitioners should immediately begin auditing their tech clients' portfolios. Start identifying proprietary digital assets, UI/UX elements, and virtual metaverse products that were previously unregistrable. The moment this amendment passes, the race to the Patent Office for virtual design priority dates will be cutthroat.

The Delhi High Court on Privacy vs. Passing Off

We are already seeing how the DPDP Act is being weaponized in IP disputes. In early 2026, the Delhi High Court tackled a rising trend: trademark fraud via domain spoofing and phishing. When brand owners sued to unmask the cybersquatters, Domain Name Registries (DNRs) invoked the DPDP Act, refusing to disclose registrant data on the grounds of data privacy.

The High Court rightly struck a balance, ruling that the DPDP Act cannot function as a statutory shield for trademark infringement and economic fraud. Under Section 3(c)(ii), processing personal data for compliance with a court order is a clear exemption. For IP litigators, this ruling is a critical weapon. You must explicitly plead the Section 3(c) exemption in your John Doe (Ashok Kumar) injunction applications to compel DNRs to pierce the privacy veil.

The Fintech Friction: Dual Compliance and Deepfakes

For in-house counsel at banks and fintechs, the phased rollout of the DPDP Act is creating a severe regulatory friction. Sector-specific laws are colliding with privacy mandates. The DPDP’s data erasure obligations are fundamentally at odds with the strict data retention mandates under the Prevention of Money Laundering Act (PMLA), 2002 and income tax regulations. Furthermore, dual breach reporting—notifying both CERT-In under the IT Act and the new Data Protection Board—adds layers of bureaucratic liability.

Then there is the gaping hole regarding deepfakes. The DPDP Act covers the unauthorized processing of biometric data used to generate deepfakes, but it offers no civil remedy for the violation of personality rights or publicity rights. Lawyers are still forced to creatively combine Section 66C of the IT Act (identity theft) with common law torts of passing off to protect celebrities—a glaring gap that a dedicated AI law would have solved.

The Verdict for Practitioners

The message from the government is clear: make do with what we have. Corporate compliance courses, like those recently launched by MNLU Mumbai, are already pivoting to teach this intersectional reality.

For the Indian lawyer, the era of working in silos is over. You can no longer be "just" an IP lawyer or "just" a privacy lawyer. Advising a tech client today requires mapping the DPDP Act’s consent architectures onto the Designs Act’s new virtual protections, while keeping one eye on the IT Act. The laws may be old and patched together, but the litigation they are about to spawn will be entirely unprecedented.

Published by AnrakLegal AI