The "No New AI Law" Illusion: How DPDP, IP, and the IT Rules Just Became India's De Facto AI Framework
The Myth of the Indian AI Act For the past few years, Technology, Media, and Telecommunications (TMT) desks across Indian law firms have been bracing for a sweeping, European-style artificial intelligence statute. We can now officially stop holding o...
The Myth of the Indian AI Act
For the past few years, Technology, Media, and Telecommunications (TMT) desks across Indian law firms have been bracing for a sweeping, European-style artificial intelligence statute. We can now officially stop holding our breath. The latest signals from the Ministry of Electronics and Information Technology (MeitY) make the government’s regulatory posture abundantly clear: India will not rush to enact a bespoke AI law. Instead, we are retrofitting our existing digital and intellectual property jurisprudence to govern the generative AI boom.
According to recent statements by MeitY Secretary S. Krishnan, the government intends to rely heavily on the Digital Personal Data Protection (DPDP) Act, 2023 and the existing intellectual property framework to rein in rogue AI, preferring regulatory layering over statutory reinvention. For practicing lawyers and in-house counsel, this is a massive shift in the advisory landscape. If you are still advising clients to "wait and see what the AI regulations say," you are leaving them exposed to immediate, actionable liabilities under laws that are already on the books.
The DPDP Act: The Unintended AI Regulator
With the Centre finally notifying the administrative rules for the DPDP Act, the statute has moved from theoretical compliance to operational enforcement. But the real story is how the DPDP Act is being weaponized as India's primary AI governance tool.
Consider the training of Large Language Models (LLMs). Generative AI relies on scraping massive datasets, which inevitably include personally identifiable information (PII). Under Section 6 of the DPDP Act, consent must be "free, specific, informed, unconditional, and unambiguous with a clear affirmative action." Furthermore, Section 6(4) mandates that the withdrawal of consent must be as easy as giving it.
"How does an AI developer 'un-train' an LLM if an Indian data principal withdraws their consent? The technical reality of machine learning fundamentally clashes with the statutory right to withdraw consent. This friction is going to be the most heavily litigated tech issue of the next decade."
For lawyers, the practice pivot is immediate. You must now audit AI-driven clients for DPDP compliance. Websites and platforms deploying AI agents or scraping tools face stringent operational duties. If your client is classified as a Significant Data Fiduciary (SDF) under Section 10, the burden multiplies, requiring an India-based Data Protection Officer (DPO), independent data audits, and rigorous algorithmic impact assessments disguised as privacy audits.
Shrinking Safe Harbours: The IT Rules Amendment
While the DPDP handles the data input, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 are being sharpened to regulate the AI output. Recent amendments specifically target deepfakes and AI-generated content by introducing stringent obligations around "synthetically generated information."
Historically, intermediaries relied on the safe harbour protection under Section 79 of the IT Act. However, to maintain this immunity, platforms must strictly comply with the due diligence requirements of Rule 3. The new amendments lower the takedown threshold for AI-generated misinformation and dramatically shorten the notice-and-takedown timelines.
What does this mean for practice? Intermediary liability is no longer just about responding to grievance officer emails within 36 hours. Platforms must now proactively detect and moderate synthetically generated information without crossing the line into active editorial control, which would strip them of their Section 79 immunity. Lawyers must draft highly specific breach response policies and update Terms of Service to explicitly prohibit malicious deepfakes, shifting the contractual liability onto the user.
The Copyright Conundrum: Fair Dealing vs. Machine Learning
By explicitly stating that AI issues are "covered to a fair degree" by the IP Act, the government is punting the hardest questions of generative AI to the Copyright Act, 1957.
Currently, the unauthorized scraping of copyrighted works to train AI models constitutes a prima facie infringement of the author's exclusive rights under Section 14. AI developers inevitably argue that data scraping falls under the "fair dealing" exception in Section 52(1)(a) (research or private study). However, Indian jurisprudence does not currently recognize a specific "text and data mining" exception like the UK or Japan.
We are bound to see a surge in copyright infringement suits against generative AI platforms. The courts will be forced to interpret whether commercial AI training qualifies as "transformative use" or merely highly sophisticated plagiarism. For IP litigators, the strategy is clear: start aggressively enforcing copyright notices on behalf of content creators against AI scrapers, as the statutory ambiguity currently favors the copyright owner, not the tech platform.
The Verdict for Tech Lawyers
The Indian government’s approach is pragmatic but legally volatile. By forcing AI governance into the existing molds of the DPDP Act, the IT Rules, and the Copyright Act, they are relying on courts and compliance officers to bridge the gap between old laws and new tech.
For law students and practitioners, the era of siloed specialization is over. You cannot be just a "privacy lawyer" or an "IP lawyer" anymore. Advising a tech client today requires harmonizing the consent architecture of the DPDP, the intermediary safe harbours of the IT Act, and the fair dealing doctrines of copyright law. The AI law is already here—it’s just hiding in plain sight.
Tags
Published by AnrakLegal AI