The "No New AI Law" Strategy: How the Operationalized DPDP Act and Amended IT Rules Just Became India's De Facto AI Code
The Illusion of a Regulatory Vacuum If you were holding your breath for a dedicated Indian equivalent to the EU AI Act, you can finally exhale. In May 2026, the Ministry of Electronics and IT (MeitY) Secretary S. Krishnan made the government’s stance...
The Illusion of a Regulatory Vacuum
If you were holding your breath for a dedicated Indian equivalent to the EU AI Act, you can finally exhale. In May 2026, the Ministry of Electronics and IT (MeitY) Secretary S. Krishnan made the government’s stance explicitly clear: India will avoid enacting new AI-specific laws unless "absolutely necessary." Instead, the state will lean on existing legal architecture to tame the AI beast.
For tech and IP practitioners, this is the most consequential policy signal of the year. The absence of a standalone AI statute does not mean a regulatory vacuum. Instead, the government is engaging in aggressive regulatory reuse. By operationalizing the Digital Personal Data Protection (DPDP) Act, 2023, and quietly tightening the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Centre has effectively woven a decentralized AI compliance web.
If your clients are building, deploying, or utilizing AI models, the legal goalposts haven't just moved—they've been fundamentally restructured under laws you thought you already understood.
The DPDP Administrative Rules: The Death of the "Checkbox"
The Centre has finally notified the administrative rules for the DPDP Act, dragging the statute from a theoretical framework into a regime of actionable enforcement. For the AI and tech sector, this is where the rubber meets the road regarding training data.
Recent commentary highlights a critical judicial and regulatory shift in interpreting Section 6 of the DPDP Act. Consent is no longer being viewed as a procedural checkbox. It must be strictly free, specific, informed, unconditional, and unambiguous. More importantly, Section 6(2) places the evidentiary burden squarely on the Data Fiduciary to prove that consent and notice (under Section 5) were validly administered.
"For AI developers scraping the Indian web or SaaS platforms utilizing client data to train proprietary LLMs, the operationalized DPDP Act is a ticking time bomb. You cannot rely on broad 'service improvement' clauses buried in a Terms of Service agreement anymore."
Practice Point: Corporate lawyers need to immediately audit their clients' data pipelines. If an Indian AI startup is ingesting personal data to train models, relying on broad, bundled consent will likely attract the draconian financial penalties (up to ₹250 crore) under the Schedule to the Act. Data Processing Agreements (DPAs) must be redrafted to explicitly delineate between processing for service delivery versus processing for algorithmic training.
The 2026 IT Rule Amendments: A Chokehold on Synthetic Content
While the DPDP Act handles the input (data), the newly amended IT Rules handle the output (generative AI content). The February 2026 amendments to the IT Rules, 2021, have fundamentally altered intermediary liability concerning synthetically generated information and deepfakes.
The amendment drastically lowers the threshold for content takedowns and compresses the response timelines for intermediaries. Platforms are now mandated to implement specific verification measures when dealing with flagged synthetic media.
Why does this matter? Because it directly threatens the Section 79 Safe Harbor of the Information Technology Act, 2000. If a social media platform, a generative AI wrapper, or a hosting service fails to meet these compressed timelines for AI-generated deepfakes, they lose their immunity. This exposes the intermediary and its officers to direct liability under Section 66D (cheating by personation) and Section 67 (publishing obscene material) of the IT Act.
Practice Point: Technology counsels must advise intermediaries to architect automated flagging systems. Manual review will no longer suffice within the compressed statutory timelines. Furthermore, grievance redressal officers (GROs) must be trained specifically on the evidentiary standards required to identify "synthetically generated information" under the new rules.
IP Law Fills the Remaining Gaps
With no AI-specific law, the Copyright Act, 1957, remains the sole arbiter for intellectual property disputes regarding generative AI. The government’s stance implies that the traditional doctrines of Section 13 (works in which copyright subsists) and Section 14 (meaning of copyright) will govern AI training.
Expect aggressive litigation around Section 52 (fair dealing). Tech companies will inevitably argue that ingesting copyrighted works for machine learning constitutes temporary, transformative use. However, without a specific text-and-data-mining (TDM) exception in Indian copyright law, the courts are likely to lean heavily in favor of original rights holders. The "No New AI Law" policy means we will have to wait for the judiciary to interpret whether a prompt-generated image possesses the necessary "modicum of creativity" to warrant copyright protection for the prompter.
The Verdict for Practitioners
The MeitY Secretary’s announcement is a wake-up call. The era of waiting for a neatly packaged "Digital India Bill" or "AI Act" to tell us how to regulate technology is over. The regulation is already here.
As practicing lawyers, our mandate has shifted. We must stop looking for the word "Artificial Intelligence" in the statute books and start applying traditional privacy, intermediary, and copyright frameworks to non-traditional technologies. The DPDP Act and the IT Rules are the new AI cops on the beat. Advise your clients accordingly—before the Data Protection Board makes an example out of them.
Tags
Published by AnrakLegal AI