Back to Insights
AI & Technology | Governance

AI Governance in India: Preparing for the Regulatory Landscape

RevLaw Team July 3, 2026

Introduction

Artificial intelligence is transforming every sector of the Indian economy—from healthcare diagnostics to financial underwriting, from agricultural optimization to legal research. But with this transformation comes complex questions of accountability, transparency, and fairness.

While India does not yet have comprehensive AI legislation, a regulatory framework is emerging through sector-specific guidelines, judicial precedents, and international obligations. Organizations deploying AI must prepare now for the regulatory environment that is taking shape.

Current Regulatory Landscape

No Dedicated AI Law: Unlike the European Union's AI Act, India has not enacted comprehensive AI legislation. However, this does not mean AI deployment is unregulated.

Existing Applicable Laws:

Information Technology Act, 2000: Provisions on intermediary liability, data protection, and computer-related offenses apply to AI systems.

Digital Personal Data Protection Act, 2023: The DPDPA's requirements for consent, purpose limitation, and data minimization directly impact AI training and deployment.

Sector-Specific Regulations: RBI guidelines govern AI in banking. IRDAI regulates AI in insurance. SEBI oversees AI-driven investment advisory.

Competition Law: The Competition Commission examines algorithmic collusion and AI-enabled anti-competitive practices.

Emerging Principles

India's AI regulatory approach is coalescing around several principles:

Human-Centric AI: The government's AI strategy emphasizes that AI should augment human capabilities, not replace human judgment in critical decisions.

Responsible AI: NITI Aayog's Responsible AI guidelines promote principles of safety, inclusivity, equality, privacy, transparency, accountability, and positive human values.

Risk-Based Approach: Higher-risk AI applications (healthcare, criminal justice, employment) will likely face stricter scrutiny than lower-risk deployments.

Key Compliance Considerations

Algorithmic Transparency: Document your AI systems' decision-making processes. Maintain records of training data, model architecture, and validation procedures.

Bias Testing: Regularly audit AI outputs for discriminatory impact across protected categories including caste, religion, gender, and disability.

Human Oversight: Implement meaningful human review for high-stakes automated decisions. Consider "human-in-the-loop" versus "human-on-the-loop" approaches.

Data Governance: Ensure training data is lawfully collected, properly anonymized where required, and representative of the population on which the AI will operate.

Explainability: Where AI decisions affect individuals (credit scoring, hiring, insurance), provide mechanisms for explanation and contestation.

Sector-Specific Guidance

Financial Services: RBI has issued guidelines on AI/ML in credit underwriting, requiring model explainability and prohibition of certain discriminatory variables.

Healthcare: AI diagnostic tools require appropriate regulatory approvals. Liability for AI-assisted medical decisions remains with licensed practitioners.

Employment: AI hiring tools must not discriminate on protected grounds. Consider bias audits before deployment.

Government Services: Government AI deployments face additional scrutiny under fundamental rights jurisprudence. Right to explanation may be constitutionally required.

Contractual Considerations

AI Vendor Agreements: Address data ownership, model transparency, liability for AI errors, and compliance obligations.

Customer Disclosures: Determine when customers must be informed they are interacting with AI systems.

Insurance: Evaluate whether existing policies cover AI-related liabilities. Consider specialized AI insurance products.

Preparing for Future Regulation

Monitor Developments: Track MEITY announcements, parliamentary discussions, and sector regulator initiatives.

Adopt Best Practices Now: Voluntary compliance with responsible AI principles positions organizations favorably when regulation arrives.

Engage in Consultation: Participate in regulatory consultation processes to shape emerging frameworks.

Document Decisions: Maintain clear records of AI governance decisions, including risk assessments and mitigation measures.

Conclusion

The window for voluntary compliance is narrowing. Organizations deploying AI should establish governance frameworks now, before mandatory requirements arrive. This proactive approach reduces regulatory risk and builds the internal capabilities needed for ongoing compliance.

Our AI & Emerging Technology practice advises organizations on AI governance frameworks, algorithmic accountability, and responsible innovation strategies.

Share this article