Legal News
4 June 2026
IP & Technology

The Government's AI Gamble: Why Relying on the DPDP Act and Legacy IP Laws Changes the Game for Tech Lawyers

The "No New AI Law" Doctrine: A Paradigm Shift for Tech Practice For the past year, Indian technology lawyers have been waiting for the other shoe to drop. As the European Union marched forward with its draconian AI Act, practitioners in India antici...

The "No New AI Law" Doctrine: A Paradigm Shift for Tech Practice

For the past year, Indian technology lawyers have been waiting for the other shoe to drop. As the European Union marched forward with its draconian AI Act, practitioners in India anticipated a similar, heavy-handed regulatory framework from New Delhi. We finally have our answer, and it is a fascinating pivot: the Indian government is leaning entirely on existing statutes to govern Artificial Intelligence.

Recent statements from MeitY Secretary S. Krishnan confirm that the Centre prefers not to enact an AI-specific statute unless absolutely necessary. Instead, the government is betting that the Digital Personal Data Protection (DPDP) Act, 2023 and our existing intellectual property regime are elastic enough to capture the complexities of Generative AI, algorithmic bias, and automated decision-making.

Make no mistake: by refusing to draft an AI-specific statute, the government hasn't deregulated AI. It has simply outsourced the regulatory burden to tech lawyers, who must now creatively stretch legacy IP doctrines and untested data protection rules to advise clients building or deploying GenAI models.

For practicing advocates and in-house counsels, this is a clarion call. The "wait-and-watch" era of AI compliance is over. The regulatory framework is already here—it is just hiding in plain sight.

The DPDP Rules are Live: The 18-Month Countdown Begins

The Centre’s notification of the administrative rules for the DPDP Act marks the transition of India's privacy regime from a theoretical debate to an enforcement-ready reality. Legal commentary confirms that the DPDP Rules, 2025 chart a phased compliance timeline, granting Data Fiduciaries an 18-month transition period before major substantive provisions bite.

However, treating this 18-month window as a grace period is a strategic blunder. The DPDP framework fundamentally alters how Data Fiduciaries handle Data Principals' information, treating consent not merely as a contractual formality, but as a strict, ongoing governance obligation.

Under Section 6 of the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous with a clear affirmative action. For tech clients—especially those scraping the internet to train Large Language Models (LLMs)—this poses an existential threat. If your client's AI model is trained on datasets containing personal data without explicit, itemized consent as required by Section 5 (Notice), that model is legally compromised. The burden of proof for lawful consent rests entirely on the Data Fiduciary. When the 18-month clock runs out, models trained on unlawfully scraped personal data could face injunctions or massive financial penalties (up to ₹250 crores under the Schedule).

Children’s Data: The Intermediary Minefield

The notified rules also show the government’s uncompromising stance on minors. Platforms acting as social media, e-commerce, or gaming intermediaries are facing severe obligations under Section 9 of the DPDP Act. The requirement for "verifiable parental consent" before processing any data of a user under 18 is going to break current UI/UX paradigms.

For lawyers advising gaming startups or ed-tech platforms, standard "clickwrap" age-gating (e.g., ticking a box stating "I am over 18") is now legally dead. You must advise clients to build robust, cryptographically secure, or Aadhaar-linked age-verification architectures immediately. The intersection of these rules with the existing Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 means non-compliance won't just result in privacy fines—it could strip clients of their safe harbour protection under Section 79 of the IT Act.

Stretching the Copyright Act to Govern Generative AI

The most academically thrilling, yet practically terrifying, aspect of the government's stance is the reliance on existing IP laws to govern AI. Can the Copyright Act, 1957 truly handle the nuances of GenAI?

When an AI model generates an image or a line of code, who owns it? Section 2(d)(vi) of the Copyright Act defines the author of a "computer-generated work" as the person who causes the work to be created. But does this mean the prompt engineer, the software developer, or the corporate entity? Without a new AI law to clarify this, IP litigators will be fighting turf wars over authorship for the next decade.

Furthermore, the ingestion of copyrighted works to train AI models will inevitably trigger infringement lawsuits. Tech companies will attempt to shield themselves using the "fair dealing" exception under Section 52(1)(a) of the Copyright Act. But our fair dealing doctrine is notoriously narrow compared to the US "fair use" doctrine. It is strictly limited to private or personal use, research, criticism, or review. Commercial LLM training arguably fits none of these. Advising a tech company that their AI scraping is protected by Section 52 is a high-risk gamble.

The Bottom Line for Legal Practice

The government’s strategy to regulate AI through the DPDP Act and the Copyright Act is a pragmatic choice to foster innovation without chilling the tech sector. But for the legal fraternity, it demands immediate action:

  • M&A Due Diligence: IP and data privacy audits during acquisitions of AI startups must become brutal. If the target company cannot prove the provenance of its training data or demonstrate verifiable parental consent mechanisms, its valuation must be adjusted for DPDP penalty risks.
  • Contract Drafting: Tech lawyers must aggressively update vendor agreements, Terms of Service, and Data Processing Agreements (DPAs). You need robust indemnities protecting your clients from third-party AI tools that might hallucinate copyrighted material or ingest personal data unlawfully.
  • Compliance Architecture: Do not wait for month 17 to start DPDP compliance. Re-architecting data lakes to ensure a Data Principal can exercise their right to withdraw consent (and have their data purged) takes months of engineering.

India’s tech-law landscape is no longer waiting for a futuristic AI bill. The rules of the game have been notified, the laws are on the books, and the countdown to enforcement has begun. It is time for lawyers to stop speculating about what the law might be, and start litigating and structuring around what it is.

Published by AnrakLegal AI