The Phantom AI Act: Why MeitY’s Reliance on DPDP and the 2026 IT Rules is a Wake-Up Call for Tech Lawyers
The Death of the Indian AI Act For the last three years, Indian tech lawyers and policy wonks have been waiting for a monolithic, EU-style Artificial Intelligence Act to drop from the legislative heavens. This week, the Ministry of Electronics and IT...
The Death of the Indian AI Act
For the last three years, Indian tech lawyers and policy wonks have been waiting for a monolithic, EU-style Artificial Intelligence Act to drop from the legislative heavens. This week, the Ministry of Electronics and IT (MeitY) officially burst that bubble. MeitY Secretary S. Krishnan confirmed that the Centre has no immediate plans to draft an AI-specific statute, opting instead to govern the AI ecosystem through the Digital Personal Data Protection (DPDP) Act, 2023, existing Intellectual Property laws, and targeted amendments to the IT Rules.
Let us be clear about what this means: the legislature is punting the complexities of generative AI onto existing statutes that were never designed for neural networks. For practicing lawyers, the "wait and see" era is over. AI litigation will not wait for a new law; it will be shoehorned into the statutory frameworks we already have. If you advise tech startups, data fiduciaries, or content platforms, your compliance matrix just got significantly more complicated.
DPDP Rules 2026: The AI Training Data Trap
The Centre’s recent notification of the administrative rules for the DPDP Act signals the shift from statutory theory to operational enforcement. By declaring the DPDP Act as the primary vehicle for AI governance, the government has inadvertently set up a massive hurdle for domestic Large Language Model (LLM) developers.
Under Section 6 of the DPDP Act, consent for processing personal data must be free, specific, informed, unconditional, and unambiguous. The 2025/2026 Rules reinforce this high threshold, leaving absolutely no room for the "implied consent" arguments historically favored by web-scraping tech giants.
"If an AI model is trained on scraped datasets containing Indian users' personal data without explicit, affirmative consent, the entire model is potentially poisoned fruit under the DPDP Act."
Unlike the EU’s GDPR, the DPDP Act notoriously lacks a "legitimate interest" exemption for data fiduciaries. Section 7 (Certain legitimate uses) is narrowly tailored. Therefore, if your client is building or fine-tuning AI models using public internet data that includes personally identifiable information (PII), they are operating in a legal minefield. Data Protection Board (DPB) penalties are steep, and practitioners must immediately audit their clients' data pipelines. The defense that "everyone scrapes the internet" will not survive a DPB inquiry.
The 2026 IT Rules Amendment: Regulating AI Through the Backdoor
Perhaps the most alarming development for digital rights and intermediary liability is the 2026 amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. By avoiding a parliamentary debate on a primary AI law, the Centre is effectively regulating synthetic media and deepfakes through delegated legislation.
The 2026 amendment introduces crippling new obligations for intermediaries:
1. Lower Takedown Thresholds: Platforms must now aggressively police "synthetically generated information."
2. Truncated Timelines: Takedown windows for AI-generated deepfakes have been slashed, demanding near-instantaneous compliance.
3. Mandatory Tech Verification: Platforms are now forced to deploy automated, technology-based verification measures to detect AI content.
This is a fundamental dilution of the safe harbour protections guaranteed under Section 79 of the Information Technology Act, 2000. By mandating proactive, algorithmic filtering, the 2026 Rules force intermediaries to become arbiters of truth. For litigation lawyers, this is a constitutional challenge waiting to happen. The mandatory use of automated filtering directly offends the Supreme Court’s ratio in Shreya Singhal v. Union of India, which held that intermediaries should not be forced to adjudicate the legality of content without a court or government order.
If you are representing social media platforms or AI-generation tools, you must prepare for a surge of writ petitions under Article 19(1)(a) (freedom of speech) and Article 19(1)(g) (right to carry on trade), challenging the vires of these new Rules.
The IP Conundrum: Square Pegs, Round Holes
Secretary Krishnan’s reliance on "existing IP laws" to govern AI outputs is equally optimistic. The Copyright Act, 1957 is woefully ill-equipped to handle generative AI.
Under Section 2(d)(vi) of the Copyright Act, the author of a computer-generated work is "the person who causes the work to be created." But who is that? The user writing the prompt, or the developer of the AI? Furthermore, the Act's "fair dealing" exceptions under Section 52 are exhaustive and do not expressly cover Text and Data Mining (TDM) for commercial AI training.
We are going to see aggressive copyright infringement suits filed by Indian publishers and artists against AI platforms. Without a statutory safe harbour for TDM, defendants will be forced to argue that algorithmic ingestion does not constitute "reproduction" under Section 14—a highly precarious legal argument.
The Bottom Line for Practitioners
The government has shown its hand: there is no AI Act coming to save you. The regulatory burden has been decentralized. To successfully navigate the AI economy in India today, a lawyer can no longer be just a "privacy expert" or a "copyright lawyer." You must master the vicious intersection of Section 6 of the DPDP Act, Section 79 of the IT Act, and Section 52 of the Copyright Act. Start advising your clients to build compliance architecture today, because the litigation wave of 2026 has already begun.
Tags
Published by AnrakLegal AI