The current legal framework for AI in India
AI systems in India operate under a patchwork of existing laws, not a unified AI statute:
- DPDPA 2023: governs all processing of personal data by AI systems—consent, purpose limitation, accuracy, security safeguards and erasure
- IT Act 2000 (Sections 43A, 72A): imposes liability for negligent data handling and unauthorised disclosure—still in force alongside the DPDPA
- Consumer Protection Act 2019: the Central Consumer Protection Authority’s 2023 Guidelines on Dark Patterns prohibit manipulative AI-driven interfaces
- Indian Penal Code / Bharatiya Nyaya Sanhita: deepfake-generated defamatory or obscene content engages criminal liability
- Sector-specific regulations: RBI guidelines on algorithmic lending, SEBI norms on AI-driven trading, IRDAI standards for AI in insurance underwriting
How the DPDPA applies to AI systems
Any entity that deploys an AI system processing personal data is a Data Fiduciary under Section 2(i). The AI vendor providing the model or API may be a Data Processor under Section 2(k) if it processes data on the Fiduciary’s instructions. Key DPDPA obligations for AI:
- Lawful basis (S.6/S.7): training an AI model on personal data requires consent or a legitimate-use ground; consent must state the AI-related purpose
- Purpose limitation (S.4): personal data collected for customer support cannot be repurposed for model training without fresh consent
- Accuracy (S.8(3)): the Data Fiduciary must ensure data completeness, correctness and consistency—critical for reducing AI bias
- Security safeguards (S.8(5)): model endpoints, training data stores and inference logs must be secured with reasonable safeguards
- Erasure (S.8(7)): when the processing purpose is fulfilled or consent is withdrawn, personal data must be erased—including data embedded in fine-tuned model weights if it is practically extractable
- No automated-decision right: unlike GDPR Article 22, the DPDPA does not grant individuals a right to contest purely automated decisions
Generative AI: ChatGPT, image generators and data privacy
Generative AI systems that process user prompts containing personal data—names, addresses, medical symptoms—are processing personal data under the DPDPA. The operator of the service (or the enterprise deploying it) is the Data Fiduciary; the model provider may be a Data Processor.
Key issues for generative AI under the DPDPA:
- Training data: if the model was trained on personal data of Indian individuals without consent, the training itself may be non-compliant
- Prompt data: user prompts entered into a generative AI system are personal data if they contain identifiable information
- Output accuracy: Section 8(3) requires data accuracy—hallucinated outputs that misattribute statements to real individuals create compliance risk
- Retention: Section 8(7) requires erasure upon purpose completion—prompt logs and conversation histories must have a defined retention period
Deepfakes and privacy law
India has no deepfake-specific statute. However, creating or distributing a deepfake that uses an individual’s likeness without consent engages multiple laws:
- DPDPA: processing an individual’s facial data (biometric personal data) to create a deepfake without consent violates Section 6
- IT Act 2000, Section 66D: impersonation using a computer resource carries imprisonment up to three years
- IT Act 2000, Section 67/67A: publishing obscene or sexually explicit deepfakes is a criminal offence
- Consumer Protection Act 2019: deepfake-based misleading advertisements are actionable under the CCPA Guidelines
The MeitY advisory of March 2024 directed intermediaries to identify and label AI-generated or deepfake content, but this is an advisory, not a binding regulation.
What comes next: the Digital India Act
The Ministry of Electronics and IT released a concept paper for the Digital India Act in March 2023. The paper proposed AI-specific governance measures—risk classification, high-risk AI system obligations, algorithmic accountability—but no Bill has been introduced in Parliament as of October 2026.
Until the Digital India Act (or an equivalent) is enacted, the DPDPA remains the primary personal-data governance framework for AI systems. Organisations deploying AI should build compliance programmes that satisfy the DPDPA today and remain adaptable to AI-specific regulation when it arrives.
How AMLEGALS advises on AI governance
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance. The firm assists organisations in mapping AI-system data flows to the DPDPA framework, structuring consent mechanisms for AI-related processing purposes, advising on generative AI deployment risks and designing governance programmes that anticipate future AI-specific regulation.

