AI Regulation Tracker / Governance and liability
India Routes AI Oversight Through Existing Laws and Sets Graded Actor Liability
Recommendatory, not binding. On November 5, 2025, India's Ministry of Electronics and Information Technology released the India AI Governance Guidelines. Rather than pass a standalone AI statute, they steer oversight through laws already on the books and map who is accountable across the AI value chain.
India spent a long time signaling that it might follow the European Union and write a single, comprehensive AI law. The India AI Governance Guidelines, released by MeitY on November 5, 2025, are the clearest sign yet that it has chosen a different path. The document is India's first national framework for governing artificial intelligence, and the core decision it makes is to lean on laws that already exist rather than build a new one from scratch. In the Guidelines' own framing, "many of the risks arising from AI can be addressed through existing frameworks." That single sentence tells you most of what you need to know about the direction India is taking.
What did MeitY actually publish?
The Guidelines are a policy framework, not a statute. They set out guiding principles, they describe how India's current laws already reach AI harms, and they recommend targeted changes where the current laws fall short. The framework rests on a set of guiding principles the document calls sutras, starting with trust. As the Guidelines put it, "trust is foundational; without it, AI innovation and adoption cannot advance." The other principles run through people-first design, innovation over restraint, fairness, accountability, systems that are understandable by design, and safety and resilience. None of that is unusual on its own. What matters is the machinery underneath it.
How does India assign liability across the AI value chain?
This is the part that has real operational teeth for anyone doing business with India. The Guidelines set out a graded, proportionate liability approach. Instead of one blanket rule, responsibility scales with what an actor actually does. A developer that builds a model, a deployer that puts it into a product, and an end user that operates it each carry a different share of accountability, weighed against the risk of the activity and the diligence they can show. Higher-risk uses handled without care carry more exposure. Lower-risk uses handled responsibly carry less. The Guidelines are explicit that the existing definition of an intermediary under the IT Act does not map cleanly onto systems that generate or modify content, and they recommend that the IT Act be amended to define these roles properly. Read that as a signal: the graded-liability idea is the destination, and legislation is expected to follow.
Which existing laws is India relying on?
The Guidelines route AI oversight through a handful of instruments already in force. The Information Technology Act, 2000 covers intermediary duties and content. The Digital Personal Data Protection Act, 2023 governs the use of personal data, including personal data used to train models, which means consent and data-protection obligations attach to training pipelines. The Consumer Protection Act, 2019 reaches deceptive or unfair AI-driven practices aimed at consumers. The criminal code sits behind serious harms. The practical message to a company is that you do not get to wait for an Indian AI Act before you have duties. If your AI touches Indian users or Indian personal data, several existing laws already apply, and the Guidelines are telling regulators to use them.
How binding is this, really?
Here is where precision matters, because the headlines can mislead. The India AI Governance Guidelines are recommendatory. They are not a law, they were not passed by Parliament, and they do not create new enforceable duties on their own. What they do is state the government's intended approach and instruct how existing statutes should be interpreted and, in places, changed. That is meaningful, because Indian regulators and courts will read AI disputes against this stated direction, and because it tells you which way the coming legislation is likely to lean. But anyone claiming India has now "regulated AI" in a binding sense is overstating it. The binding duties still live in the older laws the Guidelines point to, not in the Guidelines themselves.
What should US executives and counsel do about it?
If you have Indian operations, Indian vendors, Indian users, or personal data flowing into India, treat this as the blueprint for how accountability will be assigned. Three moves are worth making now. First, look at your contracts across the AI value chain and check that they allocate responsibility in a way that survives a graded-liability regime, because vague indemnities will not hold up well if India codifies role-based duties. Second, confirm your training-data practices satisfy the DPDP Act, since consent for personal data used in model training is already a live obligation, not a future one. Third, watch for the IT Act amendments the Guidelines recommend, because that is where the soft framework will harden into enforceable rules. None of this is urgent in the sense of a deadline, but it is cheaper to align your India-facing AI governance to this map now than to retrofit it after the statute lands.
Questions professionals are asking
Is India's AI Governance Guidelines document a law?
No. The India AI Governance Guidelines, released by MeitY on November 5, 2025, are recommendatory and non-binding. They are a policy framework that states the government's approach and directs how existing laws should apply to AI. They do not create new statutory duties by themselves.
How does India plan to hold AI actors liable?
Through a graded, proportionate approach across the AI value chain. Developers, deployers, and end users each carry responsibility scaled to their role, the risk of the activity, and the due diligence shown. The Guidelines also recommend amending the IT Act so these roles are defined clearly in law.
Which existing Indian laws already apply to AI?
Chiefly the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, the Consumer Protection Act, 2019, and the criminal code. The DPDP Act is especially relevant because consent and data-protection duties attach to personal data used to train AI models.
What should a US company with India operations do now?
Align AI value-chain contracts so liability is allocated in a way that survives a role-based regime, confirm training-data practices meet DPDP Act consent rules, and watch for the recommended IT Act amendments, which are where the soft framework is likely to become enforceable.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any guideline or statute applies to your situation with qualified counsel in the relevant jurisdiction.