Legal News
2 June 2026
IP & Technology

The Great AI Punt: Why Shoehorning Generative Tech into the DPDP Act and Legacy IP Laws is a Litigation Timebomb

For India’s technology, media, and telecommunications (TMT) lawyers, the regulatory holding pattern has finally broken. In a dual development that will define digital compliance for the next decade, the Centre has officially notified the administrati...

For India’s technology, media, and telecommunications (TMT) lawyers, the regulatory holding pattern has finally broken. In a dual development that will define digital compliance for the next decade, the Centre has officially notified the administrative rules for the Digital Personal Data Protection (DPDP) Act, 2023. But perhaps more consequential than what the government did enact is what it has chosen not to.

According to MeitY Secretary S. Krishnan, the government is officially stepping back from drafting a bespoke Artificial Intelligence statute. The official stance? The state prefers not to introduce new AI laws unless "absolutely necessary," opting instead to regulate the explosive growth of generative AI through the newly operational DPDP framework, the Information Technology (IT) Rules, and existing Intellectual Property (IP) laws.

From a policy standpoint, this is a classic "wait and watch" approach to foster innovation. From a legal practice standpoint, it is a recipe for jurisdictional chaos, aggressive litigation, and a massive surge in compliance mandates. Here is why relying on legacy laws to govern frontier technology matters for your practice right now.

The DPDP Rules Are Here: The 18-Month Countdown Begins

The notification of the DPDP Rules transitions India’s privacy regime from a theoretical debate into an enforcement reality. While reports indicate an 18-month transition window for substantive compliance, corporate counsels and privacy practitioners need to treat this as a sprint, not a marathon.

The Rules finally provide the operational scaffolding for Section 6 (Consent) and Section 9 (Processing of personal data of children) of the DPDP Act. For practitioners advising Data Fiduciaries, the era of pre-ticked boxes and bundled consent is officially dead. Consent must now be "free, specific, informed, unconditional, and unambiguous."

"If your client is still relying on a 40-page monolithic privacy policy drafted in 2011, they are standing in the crosshairs of the Data Protection Board."

What changes in practice?

First, you must completely overhaul your clients' notice and consent architecture. The introduction of Consent Managers—interoperable platforms allowing Data Principals to manage, review, and withdraw consent—means technical architecture must now mirror legal requirements. If withdrawal of consent is not as operationally workable as giving it, your client is non-compliant.

Second, the rules around Verifiable Parental Consent will force EdTech, gaming, and social media clients to implement hard age-gating. Advising clients to rely on self-declaration ("I am over 18") will no longer shield them from liability. Furthermore, identifying and advising entities that will be classified as Significant Data Fiduciaries (SDFs) under Section 10—who face enhanced obligations like appointing an India-based Data Protection Officer and conducting periodic Data Protection Impact Assessments (DPIAs)—should be your immediate priority.

Shoehorning AI into the DPDP and IP Frameworks

The government's assertion that AI issues are "partly covered" by the DPDP and IP frameworks is legally precarious. Let’s look at the intersection of AI training and the DPDP Act. Large Language Models (LLMs) are trained by scraping massive datasets from the internet, which inevitably include digital personal data.

Under Section 4 of the DPDP Act, a Data Fiduciary can only process personal data for a lawful purpose for which the Data Principal has given consent, or for certain "legitimate uses." Web scraping personal data for algorithmic training does not cleanly fit into either. Taking the government at its word—that DPDP will regulate AI—means Indian AI startups face an existential threat if an individual demands the deletion of their personal data (the right to erasure under Section 12) that has already been baked into a neural network's weights. "Machine unlearning" is a technical nightmare; legally, it is entirely untested.

On the IP front, relying on the Copyright Act, 1957 to resolve generative AI disputes is equally fraught. IP litigators should prepare for an influx of infringement suits from authors, artists, and publishers against AI developers.

The defense will inevitably rely on the "fair dealing" exception under Section 52(1)(a) (private or personal use, including research). However, commercial LLM training arguably fails the four-factor test for fair dealing, primarily because it affects the potential market for the copyrighted work. Until India gets its own equivalent of the New York Times v. OpenAI litigation to set binding precedent, advising AI developers on copyright risk will require high-risk, conservative drafting.

The Backdoor Regulation: Intermediary Liability

If the government is reluctant to regulate AI directly, it is aggressively regulating its output. Recent amendments to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 represent a tightening noose around synthetically generated information and deepfakes.

The lowering of takedown timelines for deepfakes and the strengthening of platform obligations mean that the Section 79 safe harbour under the Information Technology Act, 2000, is more fragile than ever. For lawyers representing intermediaries (social media platforms, hosting services), the advice must be stark: automated content moderation systems must be upgraded to detect synthetic media, and grievance redressal mechanisms must operate at breakneck speed. Failure to comply doesn't just mean a fine; it means the loss of safe harbour, exposing the platform's executives to direct criminal liability under the Bharatiya Nyaya Sanhita (BNS) and the IT Act.

The Verdict

The Centre’s refusal to draft a specific AI law is a calculated gamble that existing statutory frameworks can stretch to accommodate 21st-century technology. For the legal fraternity, this is a lucrative, if chaotic, development.

The notification of the DPDP Rules provides the immediate battleground. TMT and corporate lawyers have 18 months to drag their clients into compliance. Simultaneously, litigators must sharpen their arguments on how 1950s copyright principles and brand-new privacy mandates apply to neural networks. The law may be playing catch-up, but the practice of law is about to accelerate.

Published by AnrakLegal AI