Legal News
9 August 2026
IP & Technology

The Government's "Make Do" AI Strategy: Why Relying on a Legally Embattled DPDP Act is a Risky Gamble for Tech Lawyers

The "Make Do" Approach to AI Regulation If you were holding your breath for a bespoke, sweeping Artificial Intelligence Act in India this year, it is time to exhale. MeitY Secretary S. Krishnan has made the government’s 2026 regulatory posture abunda...

The "Make Do" Approach to AI Regulation

If you were holding your breath for a bespoke, sweeping Artificial Intelligence Act in India this year, it is time to exhale. MeitY Secretary S. Krishnan has made the government’s 2026 regulatory posture abundantly clear: India will not legislate a new AI-specific statute unless it becomes "absolutely necessary." Instead, the Ministry is betting the house on existing intellectual property frameworks and the Digital Personal Data Protection (DPDP) Act, 2023 to corral the wild west of generative AI.

For the practicing technology lawyer, this is a clarion call. The government is effectively punting the complex nuances of AI regulation—algorithmic bias, deepfakes, and automated decision-making—down to the judiciary and to corporate legal departments. You are no longer waiting for a new rulebook; you are expected to stretch the Copyright Act, 1957 and a highly litigated data privacy statute over the massive, amorphous frame of artificial intelligence.

The DPDP Act: A Shaky Pillar for AI Governance?

MeitY’s reliance on the DPDP Act to handle AI-related data scraping and privacy issues is legally optimistic, to say the least. Why? Because the DPDP Act itself is currently fighting for its constitutional life. As of February 2026, both the Supreme Court and the Delhi High Court are entertaining fierce challenges to the vires of the Act.

On February 14, 2026, The Reporters’ Collective filed a fresh Supreme Court petition challenging key provisions of the DPDP Act and its Rules. Parallelly, a PIL in the Delhi High Court is attacking the sweeping government exemptions carved out under the Act. While the Supreme Court issued notice on February 16, it crucially declined to stay the operation of the Act.

"The Supreme Court’s refusal to grant a stay means compliance is not a future hypothetical—it is a present, immediate mandate. Corporate clients cannot use the pending constitutional litigation as a shield against the Data Protection Board."

This creates a paradoxical landscape for tech lawyers: you must rigorously enforce compliance with a statute that might be heavily read down or struck down in parts by a Constitutional Bench before the decade is out.

The RTI Amendment and Article 19: A Looming Constitutional Showdown

The most explosive legal battle currently sub judice is the DPDP Act’s backdoor amendment to the Right to Information (RTI) Act, 2005. Section 44(3) of the DPDP Act amended Section 8(1)(j) of the RTI Act. Previously, the RTI Act allowed the disclosure of personal information if the larger public interest justified it. The DPDP Act obliterated this public interest test, creating a blanket exemption for any "personal information."

From a constitutional standpoint, this is a massive friction point between the fundamental right to privacy (Article 21, post-Puttaswamy) and the fundamental right to information (Article 19(1)(a)). The petitioners rightly argue that this amendment effectively guts investigative journalism and public accountability. For litigators, how the Supreme Court balances this clash will set the precedent for how transparency interacts with data privacy for the next fifty years.

What This Means for Your Tech Practice Today

With the government explicitly pointing to the DPDP Act to govern AI, the focus for in-house counsel and law firms must hyper-pivot to Consent Management. Commentary flooding the legal space in March and April 2026 underscores that consent under Section 6 of the DPDP Act is the absolute nucleus of data processing.

The Act demands that consent be free, specific, informed, unconditional, and unambiguous. It also mandates that withdrawing consent must be as frictionless as giving it. Here is where the rubber meets the road for AI:

How do you obtain "specific and informed" consent to train a Large Language Model (LLM) when the output of that model is inherently unpredictable? If a user exercises their right to withdraw consent, how does your client "unlearn" that user's data from a neural network that has already been trained on it? The DPDP Act does not answer this. It relies on a Web 2.0 understanding of data deletion that simply does not map onto generative AI architectures.

Actionable Takeaways for Practitioners:

1. Draft Aggressive but Transparent Notices: Your Section 5 notices must explicitly mention if a Data Principal's information will be used for AI/ML training purposes. Vague clauses like "to improve our services" will not survive scrutiny by the Data Protection Board.

2. IP Audits for AI Scraping: Since MeitY is relying on existing IP law, re-evaluate your client's web-scraping practices. Section 52(1)(a) of the Copyright Act (fair dealing for research) was not designed to protect commercial LLM training. Relying on it is a high-risk strategy.

3. Prepare for Statutory Fluidity: Advise clients to build modular data compliance architectures. If the Supreme Court strikes down the government exemptions (Section 17) or alters the RTI interplay, your client's compliance framework must be agile enough to pivot without requiring a total systemic overhaul.

The government may be content to "wait and watch" on AI, but the legal market does not have that luxury. By forcing the square peg of AI into the round holes of 1957 copyright concepts and a constitutionally embattled 2023 privacy law, the state has made one thing clear: the real regulators of AI in India won't be lawmakers—they will be lawyers and judges.

Published by AnrakLegal AI