Legal News
10 July 2026
IP & Technology

The Frankenstein Approach to AI: How the ‘No New AI Law’ Stance and the DPDP-RTI Clash Will Dictate Tech Practice in 2026

The Ministry of Electronics and Information Technology (MeitY) has officially shown its hand for the future of artificial intelligence in India, and it is a litigator's dream disguised as a compliance nightmare. By confirming that the Centre will avo...

The Ministry of Electronics and Information Technology (MeitY) has officially shown its hand for the future of artificial intelligence in India, and it is a litigator's dream disguised as a compliance nightmare. By confirming that the Centre will avoid drafting new AI regulations—relying instead on the existing Intellectual Property (IP) regime and the Digital Personal Data Protection (DPDP) Act—the government has opted for what can only be described as duct-tape jurisprudence.

For tech lawyers and in-house counsel, the waiting game for a bespoke "Indian AI Act" is over. The regulatory architecture for 2026 is already here. But by shoehorning generative AI into frameworks built for Web 2.0, the government has inadvertently created massive fault lines in intermediary liability, data consent, and constitutional transparency.

The IT Rules 2026 Amendment: The Death of the "Good Faith" Safe Harbour

The most immediate shockwave for practicing lawyers is the mandatory February 10, 2026 Amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Previously, intermediaries were merely required to make an "endeavour to deploy" technology to identify misinformation. The new amendment replaces this with a draconian "shall" obligation.

Platforms like Meta, YouTube, and even domestic aggregators must now technically verify and label AI-generated content (synthetically generated information) before it goes live. This is a fundamental shift in how we must advise clients on Section 79 of the IT Act, 2000.

"We are witnessing the quiet erosion of the intermediary safe harbour. By forcing platforms to actively verify and label AI content under a vague 'good faith' standard, the State is shifting the adjudicatory burden of policing deepfakes onto private intermediaries."

If your client fails to catch an AI-generated deepfake due to a technical lapse, they risk losing their Section 79 immunity, opening up directors and grievance officers to criminal liability under the Bharatiya Nyaya Sanhita (BNS) and the IT Act. Tech lawyers must immediately audit their clients' algorithmic moderation tools—"best efforts" will no longer hold up in court.

The DPDP Rules 2025: The Unsolvable AI "Unlearning" Paradox

MeitY’s claim that AI issues are "already covered" under the DPDP Act reveals a fundamental misunderstanding of how Large Language Models (LLMs) operate. With the Centre finally notifying the administrative rules for the DPDP Act (DPDP Rules 2025), the tension between privacy and machine learning is about to snap.

The Rules reinforce that consent under the DPDP Act must be free, specific, informed, and withdrawable. Crucially, erasure is mandatory upon withdrawal of consent. Here is the practical problem for lawyers advising AI startups: How do you force a neural network to "unlearn" a specific data principal's personal information?

Unlike a traditional database where a row can simply be deleted, an LLM bakes data into its weights and parameters. If a user withdraws consent for their data being used in a training set, Data Fiduciaries cannot simply "delete" it without retraining the entire model—a financially ruinous prospect. Because the DPDP Act lacks specific carve-outs for AI training data, tech lawyers will be forced to rely on broad, untested interpretations of "legitimate uses," likely leading to a deluge of complaints before the Data Protection Board.

The RTI Act Evisceration: A Constitutional Showdown

While the tech sector grapples with compliance, constitutional and media lawyers are fighting a different battle. The Supreme Court's February 16 decision to refer pleas challenging the DPDP Act’s amendment of the Right to Information (RTI) Act to a larger bench—while declining an interim stay—cements this as the most significant constitutional clash of the year.

The DPDP Act surgically amended Section 8(1)(j) of the RTI Act. Previously, this section exempted personal information from disclosure unless it served a larger public interest. The DPDP Act entirely removed the "public interest" caveat. Now, public information officers (PIOs) have a blanket mandate to deny any RTI request that involves personal data, irrespective of the corruption or public accountability at stake.

Coupled with the Delhi High Court issuing notice on a PIL challenging Sections 17–44 of the DPDP Act for violating Articles 14, 19, and 21, the judiciary is essentially being asked to reconcile Puttaswamy (the right to privacy) with Article 19(1)(a) (freedom of speech and the right to know).

For litigators, the lack of a Supreme Court stay means that for the foreseeable future, investigative journalism, corporate due diligence, and activist public scrutiny are severely crippled. State instrumentalities are already weaponizing the DPDP Act to reject RTI applications en masse.

The Bottom Line for Practitioners

The government’s 2026 tech posture is clear: regulate through enforcement of existing, albeit awkwardly fitting, statutes rather than legislative innovation.

For the Indian legal fraternity, this means the era of boilerplate privacy policies and lax intermediary compliance is dead. You cannot wait for a centralized AI law to advise your clients. You must immediately cross-reference your clients' AI deployment strategies against the strict liability of the amended IT Rules, the unyielding erasure mandates of the DPDP Rules 2025, and the ongoing constitutional volatility in the Supreme Court. The law hasn't caught up to the technology, but the liability certainly has.

Published by AnrakLegal AI