GainingSun
Current Affairs and GK
🔬
Science & TechEditorial Team
GS3

India's Standalone AI Law Explained: Agentic AI Autonomy, Deepfakes and Safe Harbour

Why in News?

The Ministry of Electronics and Information Technology is examining a separate, standalone law to regulate artificial intelligence in India, rather than continuing to govern AI through the Information Technology Act, 2000. Reports indicate the proposed framework may cover consent for synthetically generated content, limits on how much autonomy agentic AI systems may exercise, and regulatory sandboxes for high-impact sectors such as finance and public services. Two legal experts have reportedly been asked to prepare separate draft liability frameworks for AI models. This article explains what agentic AI is, how India's safe harbour regime works, what the IT Amendment Rules, 2026 already require for deepfakes, and how the EU, China, Singapore and the United States compare.

Key Points

  1. The Ministry of Electronics and Information Technology (MeitY) is reported to be exploring a consent-based framework for synthetically generated content, curbs on agentic AI autonomy, and regulatory sandboxes for high-risk applications, as part of a possible dedicated AI law.

  2. The proposed law is likely to be introduced as standalone legislation rather than as an amendment to, or subordinate rule under, the Information Technology Act, 2000.

  3. The cyber laws division of MeitY has been asked to conduct a regulatory analysis of the IT Act and the rules framed under it, to identify existing legal gaps in dealing with AI.

  4. In the case of agentic AI, the government is examining how much autonomy such systems should be permitted, and whether they should be allowed to retain and reuse data.

  5. MeitY is expected to consult the Reserve Bank of India and the Securities and Exchange Board of India to set up a regulatory sandbox for AI applications in high-impact areas such as finance and public services.

  6. Two legal experts from the private sector have reportedly been asked to submit separate draft liability frameworks for AI models.

  7. A second major policy question is platform liability — whether safe harbour, which protects intermediaries from liability for user-generated content, can logically extend to content that a platform's own AI model generates.

  8. Officials have flagged that the Digital Personal Data Protection Act, 2023 addresses broader privacy questions but does not settle consent and data-ownership issues specific to AI systems.

  9. India's data protection law exempts personal data voluntarily made public by an individual, which means scraping of publicly visible social media profiles for AI training may fall outside its protections.

  10. This marks a shift from the government's earlier position. In the India AI Governance Guidelines released in November 2025, MeitY had held that a separate AI law was not required and that existing laws were largely adequate.

  11. IT Secretary S. Krishnan stated in early July 2026 that while existing provisions had so far been adequate for deepfakes and synthetic content, "additional regulation or law may be needed", and that the time to examine AI regulation was approaching.

  12. The rethink follows growing instances of high-quality deepfakes, the misuse of AI image tools on social media platforms, and government anxieties about autonomous agentic systems.

  13. India has so far legislated in a piecemeal manner — in February 2026 it notified the IT Amendment Rules, 2026 for synthetically generated information, and in April 2026 proposed that large platforms display AI labels continuously through the duration of the content.

  14. MeitY has also examined the governance approach adopted by Singapore for agentic AI, announced in updated form in May 2026, and has noted that some jurisdictions that followed a lighter-touch approach are re-examining their positions.

Explained

What exactly is the government considering, and why is a separate AI law being weighed now?

  • The core proposal: MeitY is examining whether artificial intelligence needs its own dedicated statute instead of being governed indirectly through the Information Technology Act, 2000. The elements reported to be under consideration are a consent-based framework for synthetically generated media, restrictions on the degree of autonomy that agentic AI systems may exercise, rules on whether such systems may retain and reuse user data, and regulatory sandboxes for high-impact deployments.

  • Why the IT Act is seen as inadequate: The IT Act was enacted in the year 2000, in an era of email, e-commerce and digital signatures. Its central architecture is built around three ideas — the "intermediary" who passively transmits or hosts information, the "originator" who creates it, and the "computer resource" through which it passes. A generative AI model does not fit neatly into any of these categories. It is not a passive conduit, because it produces the content itself; it is not exactly an originator in the human sense, because it responds to a user prompt; and it is not a mere computer resource, because it exercises probabilistic judgment. This conceptual mismatch is the single most important reason a fresh statute is being examined.

  • The trigger: Two developments have accelerated the rethink. First, the rapid spread of realistic deepfakes, including non-consensual sexualised imagery of women generated through platform-integrated AI tools. Second, the arrival of agentic AI, which acts in the world rather than merely producing text, and therefore raises questions of legal responsibility that content-focused rules cannot answer.

What is agentic AI, and why does it create a regulatory problem that generative AI did not?

  • Definition: Agentic AI refers to autonomous AI systems that go beyond simply generating text or images. Given a high-level goal, such a system independently plans a sequence of steps, calls upon external tools and software, executes actions, observes the results, and revises its strategy in real time — all with minimal human supervision. The India AI Governance Guidelines describe AI systems as being probabilistic, generative, adaptive and agentic.

  • How it differs from generative AI: A generative model answers a question. An agentic system completes a task. If a user asks a chatbot how to book a flight, it explains the process. If a user instructs an agent to book the cheapest flight for next week, the agent searches airline sites, compares fares, enters payment details and confirms the booking. The output of the first is speech; the output of the second is action with real-world legal and financial consequences.

  • The causal chain problem: In a simple software failure, the chain of causation is short — the code did something, and the developer wrote the code. With an agentic system, the chain becomes long, branching and opaque. The developer built the model, a platform provider hosted it, an application developer wrapped it into a product, a deployer configured its permissions, and the end-user issued a broad instruction. When the agent transfers money to the wrong account or executes an unlawful transaction, existing law offers no clear rule on who bears the loss. This is precisely why separate draft liability frameworks have reportedly been commissioned.

  • The memory and data question: Agentic systems typically maintain persistent memory so they can carry context across tasks. This is what makes them useful, but it also means they accumulate personal and financial information over time. The government's reported examination of whether agents should be permitted to retain and reuse data goes to the heart of this design feature.

  • Systemic risks: Where multiple agents interact, regulators internationally have flagged additional risks — uncontrolled proliferation of agents without central management, miscoordination or conflict between agents optimising different objectives, and emergent behaviours that could not have been predicted by testing each agent individually.

What is "safe harbour" under Indian law, and why is it difficult to apply to AI-generated content?

  • The statutory basis: Section 79 of the Information Technology Act, 2000 grants intermediaries conditional immunity from liability for third-party information hosted or transmitted on their platforms. The logic is practical: a platform cannot pre-screen every post before it is published, and holding it liable for every unlawful user post would either shut down user-generated content entirely or force platforms into aggressive private censorship.

  • The conditions: Immunity is not unconditional. Under Section 79(2), the intermediary must not initiate the transmission, select the receiver, or select or modify the information transmitted. Under Section 79(3)(b), immunity is lost if the intermediary, upon receiving actual knowledge, fails to expeditiously remove the unlawful material. It must also observe the due diligence obligations prescribed under the IT Rules.

  • The judicial gloss: In Shreya Singhal v. Union of India (2015), the Supreme Court struck down Section 66A of the IT Act and simultaneously read down Section 79(3)(b). The Court held that "actual knowledge" must be understood to mean knowledge conveyed through a court order or a notification by the appropriate government or its agency, and that the unlawfulness must relate to the grounds contained in Article 19(2) of the Constitution. The reasoning was that intermediaries cannot realistically be asked to adjudicate the legality of millions of private complaints.

  • Why AI breaks the logic: Safe harbour rests on the premise that the platform did not create the content and could not have anticipated it. When a platform's own model generates the offending image or text in response to a prompt, that premise collapses. The platform is no longer a passive host — its system is the producer. At the same time, holding a model absolutely liable is difficult because models are trained on vast internet corpora, respond probabilistically, and cannot reliably trace a specific output back to a specific training source. Keyword-based content matching, which platforms use for text moderation, does not transfer well because a model can rephrase or editorialise the same underlying idea in endless ways.

  • The related loss-of-immunity risk: Non-compliance with due diligence obligations under the IT Rules can itself result in loss of safe harbour. In its January 2026 notice to X Corp over the misuse of an integrated AI image tool to generate obscene depictions of women, MeitY expressly warned that failure to comply with the IT Act and IT Rules could invite strict legal consequences.

What is "synthetically generated information", and what does the existing framework already require?

  • The regulatory definition: MeitY notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 on 10 February 2026, which came into force on 20 February 2026. These Rules introduced the concept of synthetically generated information (SGI) — information that is artificially or algorithmically created, generated, modified or altered using a computer resource in a manner that appears authentic or true. It covers deepfakes, AI-generated or AI-altered images and video, voice cloning and similar realistic audio-visual content.

  • Labelling obligations: Intermediaries offering tools that enable the creation or modification of SGI must ensure that such content is prominently and clearly labelled, so that a user can immediately identify it as synthetically generated. Visual SGI must carry a visual label and audio SGI an audio disclosure. Where technically feasible, permanent metadata or a unique identifier must be embedded so that the content can be traced back to the computer resource that generated it, and platforms must not enable the modification, suppression or removal of such labels or metadata.

  • Evolution of the labelling standard: The draft rules circulated in October 2025 had proposed a fixed quantitative standard — the label covering at least 10 per cent of the surface area of visual content, or appearing in the first 10 per cent of the duration of audio content. This fixed threshold was dropped in the notified Rules in favour of a qualitative "clear and prominent" standard. In April 2026, MeitY circulated a further proposal to amend Rule 3(3)(a)(ii) to require a continuous and clearly visible label throughout the duration of visual content, rather than a one-time watermark or opening disclaimer.

  • Obligations on large platforms: Significant Social Media Intermediaries (SSMIs) — platforms with more than 50 lakh registered users in India — carry heightened duties. They must require users to declare whether uploaded content is synthetically generated, verify such declarations using reasonable and appropriate automated tools, and ensure prominent labelling where the declaration is confirmed. Failure to act on wrongly labelled synthetic content is treated as a breach of due diligence.

  • Takedown timelines: The window for removing or disabling access to unlawful content upon receipt of a court or government order was compressed from 36 hours to 3 hours, a change intended to enable faster action against harmful deepfakes but also criticised by digital rights groups on grounds of due process and feasibility.

  • Exemptions: Not all machine-assisted content is SGI. Good-faith editing or enhancement that does not misrepresent, routine preparation of documents, and the use of tools purely for accessibility or clarity are excluded from the definition.

What is a regulatory sandbox, and why are the RBI and SEBI being consulted?

  • The concept: A regulatory sandbox is a controlled testing environment in which a firm may pilot a new product or technology on a limited set of real users, for a limited period, under close supervisory observation, with certain regulatory requirements relaxed or waived. It allows the regulator to observe real-world behaviour and risks before framing permanent rules, and allows the innovator to test without the immediate threat of enforcement.

  • Why finance is the priority sector: Financial services is where AI is already making consequential decisions — credit underwriting, fraud detection, algorithmic trading, customer onboarding and collections. Errors here translate directly into denial of credit, wrongful account freezes or market disruption. The RBI's survey of regulated entities, cited in its FREE-AI report, found that roughly 20.8 per cent of surveyed regulated entities were already deploying AI in production, while about 67 per cent expressed interest in exploring AI use cases.

  • The RBI framework: On 13 August 2025, the RBI released the report of the committee on a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI), chaired by Prof. Pushpak Bhattacharyya of IIT Bombay and constituted in December 2024. The framework rests on seven guiding "sutras" and makes 26 recommendations across six strategic pillars — Infrastructure, Policy, Capacity, Governance, Protection and Assurance. It recommends board-approved AI policies, AI-specific consumer protection and audit mechanisms, AI innovation sandboxes, and contractual safeguards for third-party AI vendors.

  • The SEBI framework: SEBI notified the SEBI (Intermediaries) (Amendment) Regulations, 2025, effective 10 February 2025, inserting a new chapter on the usage of artificial intelligence. Under Regulation 16C, any person regulated by SEBI who uses AI or machine learning tools — whether developed in-house or procured from a third-party technology service provider, and irrespective of the scale of adoption — is solely responsible for the privacy, security and integrity of investor and stakeholder data, for the outputs arising from such tools, and for compliance with applicable laws. Critics have noted that this places the entire burden on the intermediary while imposing no parallel duty on the AI vendor.

  • The sandbox link: Both regulators already operate innovation sandboxes, which makes them the natural institutional partners for a horizontal AI sandbox in high-impact sectors.

How do India's existing laws currently govern AI?

  • Information Technology Act, 2000: The foundational statute. It supplies the intermediary liability architecture (Section 79), the government's blocking power (Section 69A), interception and monitoring powers (Section 69), and offences relating to obscene and sexually explicit electronic material (Sections 67, 67A and 67B).

  • IT Rules, 2021 and the 2026 Amendment: These prescribe due diligence obligations, grievance redressal machinery, the SSMI category with its additional compliance officers, and now the SGI labelling and traceability regime.

  • Digital Personal Data Protection Act, 2023: Regulates the processing of digital personal data through a consent-based architecture. It creates the roles of Data Fiduciary and Data Principal, imposes purpose limitation and data minimisation duties, and establishes the Data Protection Board of India as the enforcement body. Crucially, Section 3(c)(ii) provides that the Act does not apply to personal data that a data principal has voluntarily made publicly available, or that any other person is legally obliged to make public. On a plain reading, this places self-published social media posts, court records and parliamentary proceedings outside the Act's scope — which is why officials have observed that scraping publicly visible profiles for AI training is unlikely to face meaningful guardrails under the data protection law. Industry bodies have separately urged clarity, arguing that verifying whether every publicly accessible item was voluntarily made public by the individual concerned is practically unworkable.

  • Bharatiya Nyaya Sanhita, 2023: Provisions on defamation, cheating by personation, forgery and criminal intimidation apply to deepfake-enabled offences, alongside the IT Act.

  • Copyright Act, 1957: Governs the use of copyrighted material in model training and the authorship of AI-generated works — an unsettled area that the India AI Governance Guidelines expressly flagged for legislative review.

  • Sectoral regulation: The RBI's FREE-AI framework and SEBI's Regulation 16C govern financial applications; the IRDAI covers insurance; CERT-In, I4C, NCIIPC and the NCCC handle cyber incident response and critical infrastructure protection.

Why has India's stated position shifted?

  • The earlier position: On 5 November 2025, MeitY released the India AI Governance Guidelines, drafted by a committee constituted in July 2025. The Guidelines adopted a principle-based, techno-legal approach and concluded that many AI-related risks could be addressed under existing laws. They were advisory, not legally binding, and carried no penalties for non-compliance.

  • The seven sutras: The Guidelines are anchored in seven principles — Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; and Safety, Resilience and Sustainability. These were adapted from the RBI's FREE-AI framework.

  • The six pillars and institutions: Recommendations were organised across six pillars — Infrastructure, Capacity Building, Policy and Regulation, Risk Mitigation, Accountability and Institutions. The Guidelines recommended three new bodies: an AI Governance Group (AIGG) for whole-of-government policy coordination, a Technology and Policy Expert Committee (TPEC) to supply technical and strategic inputs, and an AI Safety Institute (AISI) for testing, standards, evaluation metrics and international collaboration.

  • Where the Guidelines themselves anticipated new law: Even while advising against immediate legislation, the Guidelines called for a comprehensive review of existing law to identify gaps relating to classification and liability across the AI value chain, application of data protection principles to AI development, content authentication and provenance, and use of copyrighted material in training. Their long-term action plan expressly listed the adoption of new laws to account for emerging risks and capabilities, and the medium-term plan listed piloting regulatory sandboxes in high-risk domains. The current move is therefore better understood as an acceleration of a phased roadmap than a reversal of policy.

  • The stated reasoning for the change: IT Secretary S. Krishnan indicated in early July 2026 that although existing provisions had sufficed for the first wave of concerns, an additional regulation or law may now be needed. The Union Minister for Electronics and IT had earlier noted that the IT law was framed long before the rapid emergence of AI, and that consultations with industry were under way to balance innovation and regulation.

How does India's approach compare with other jurisdictions?

  • European Union — comprehensive and prescriptive: The EU Artificial Intelligence Act (Regulation 2024/1689) entered into force on 1 August 2024 and is the world's first horizontal AI regulation. It classifies AI systems into four tiers — unacceptable, high, limited and minimal risk — with obligations scaling by tier. Prohibited practices, including social scoring and untargeted facial image scraping, have been banned since 2 February 2025; obligations for general-purpose AI models applied from 2 August 2025. Penalties under Article 99 reach up to €35 million or 7 per cent of global annual turnover for prohibited practices, €15 million or 3 per cent for high-risk violations, and lower amounts for supplying incorrect information to authorities. A "Digital Omnibus" package provisionally agreed in May 2026 would defer certain high-risk obligations.

  • China — the first dedicated agent rules: On 8 May 2026, the Cyberspace Administration of China, the National Development and Reform Commission and the Ministry of Industry and Information Technology jointly issued Implementation Opinions on the standardised application and innovative development of intelligent agents, which took effect on 15 July 2026. This is the first national framework to treat AI agents as a distinct regulatory category. It defines an AI agent as an intelligent system capable of autonomous perception, memory, decision-making, interaction and execution, and requires that an agent's decision authority be sorted before deployment into three tiers — decisions reserved for humans, decisions requiring prior user approval, and decisions the agent may take autonomously. Agents deployed in healthcare, finance, transport and public safety face mandatory filing, compliance testing and product recall provisions, and users retain the final decision-making power.

  • Singapore — soft-law and agent-specific: The Infocomm Media Development Authority launched a Model AI Governance Framework for Agentic AI in January 2026 and published an updated version on 20 May 2026, alongside a discussion paper on legal responsibility for AI agents. The framework is voluntary and structured around four pillars — assessing and bounding risks upfront, ensuring meaningful human accountability, implementing technical controls and processes, and enabling end-user responsibility. It emphasises designing checkpoints and action boundaries requiring human approval.

  • United States — fragmented: There is no comprehensive federal AI statute. Governance operates through agency guidance, procurement standards and an expanding patchwork of state legislation, some of which imposes obligations such as independent safety audits on large frontier model developers.

  • India's positioning: India has so far occupied a middle position — no horizontal statute, but binding subordinate legislation on synthetic media, binding sectoral regulation in finance, and non-binding national guidelines. A standalone law would move India closer to the EU and Chinese models on structure, while its stated philosophy of "innovation over restraint" would push it towards lighter obligations than the EU on substance.

What are the main arguments on both sides of a standalone AI law?

  • Arguments advanced in favour: Existing statutes were drafted for a pre-AI world and cannot classify AI actors or allocate liability across the value chain. Piecemeal rulemaking creates compliance uncertainty and regulatory arbitrage across sectors. Voluntary frameworks lack enforceability and give regulators no visibility into organisational practice. Agentic systems that act autonomously require ex ante duties, not merely ex post takedown remedies. Legal certainty on liability may in fact encourage investment by telling firms exactly what risks they carry.

  • Arguments advanced against: A horizontal statute risks freezing definitions in a field where capability changes faster than legislation can be amended, repeating the obsolescence problem of the IT Act. Compliance-heavy obligations disproportionately burden MSMEs and startups relative to large global firms. Regulatory capacity is limited, and enforcement without technical expertise may become arbitrary. Overlapping mandates across MeitY, the RBI, SEBI and the proposed AI institutions could create duplication. Broad content-labelling and traceability duties raise questions of compelled speech and prior restraint, and detection tools remain empirically unreliable.

  • The middle path being discussed: A graded, risk-based statute that imposes minimal obligations on low-risk applications, stricter duties on high-risk deployments in banking, health and critical infrastructure, and emergency powers over dangerous systems — combined with sandboxes to test rules before hardening them, and an institutional layer of AIGG, TPEC and AISI to keep the framework technically informed.

Data Crunch

  • The IndiaAI Mission was approved by the Union Cabinet in March 2024 with an outlay of ₹10,371.92 crore over five years.

  • Within this outlay, Compute Capacity received the largest allocation at ₹4,563.36 crore, followed by Foundation Models at ₹1,971.37 crore and Startup Financing at ₹1,942.5 crore, while Safe and Trusted AI received ₹20.46 crore.

  • More than 38,000 GPUs have been onboarded under the IndiaAI Mission against a target of 1,00,000, with subsidised access through the IndiaAI Compute Portal.

  • AIKosh hosts more than 9,500 datasets and 273 sectoral models.

  • The National Supercomputing Mission has operationalised over 40 petaflop-class systems, including AIRAWAT and PARAM Siddhi-AI.

  • IndiaAI and FutureSkills initiatives support 500 PhDs, 5,000 postgraduates and 8,000 undergraduates; 570 AI Data Labs operate across Tier-2 and Tier-3 cities; 27 IndiaAI Data and AI Labs have been established and 174 ITIs approved across 27 States and Union Territories.

  • Nearly 90 per cent of Indian startups are reported to be integrating AI in some form.

  • The RBI's survey of regulated entities found about 20.8 per cent already deploying AI in production and about 67 per cent interested in exploring AI use cases.

  • The RBI FREE-AI framework comprises 7 sutras, 6 pillars and 26 recommendations.

  • The Twenty-Seventh Report of the Parliamentary Standing Committee on Communications and Information Technology, presented to the Lok Sabha on 30 March 2026, cited estimates that AI could add about $967 billion to India's economy by 2035.

  • The same report noted that AI adoption within Indian firms rose from about 8 per cent in 2023 to about 25 per cent in 2024.

  • The threshold for classification as a Significant Social Media Intermediary is 50 lakh registered users in India.

  • The takedown window for unlawful content upon a court or government order was reduced from 36 hours to 3 hours under the IT Amendment Rules, 2026.

  • Maximum penalties under the EU AI Act are €35 million or 7 per cent of global annual turnover for prohibited practices, against a GDPR maximum of €20 million or 4 per cent.

  • India's Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023; the India AI Governance Guidelines were released on 5 November 2025; the IT Amendment Rules, 2026 were notified on 10 February 2026 and came into force on 20 February 2026.

Way Forward

  • Define the AI value chain in statute. Any new law must first classify actors — model developer, platform provider, application developer, deployer and end-user — because liability cannot be allocated until roles are legally defined. This was explicitly identified as a gap in the India AI Governance Guidelines.

  • Adopt graded, risk-proportionate obligations. Minimal duties for low-risk applications and stricter duties for high-risk deployments in credit, health, employment and critical infrastructure would preserve the "innovation over restraint" principle while protecting against real harm.

  • Resolve the safe harbour question explicitly. The law should state whether immunity under Section 79 extends to content generated by a platform's own model, and if a modified immunity is granted, it should be conditional on demonstrable safeguards such as provenance marking, prompt filtering and incident logging.

  • Operationalise the institutional architecture. Notifying the AI Governance Group and the Technology and Policy Expert Committee, and adequately resourcing the AI Safety Institute, is a precondition for competent enforcement. The current allocation to the Safe and Trusted AI pillar suggests capacity is the binding constraint.

  • Use sandboxes before hardening rules. Piloting AI applications in RBI- and SEBI-supervised sandboxes would allow rules to be calibrated against observed behaviour rather than assumed risk.

  • Clarify the data protection interface. The ambiguity around Section 3(c)(ii) of the DPDP Act needs authoritative guidance on what counts as data "made publicly available", and whether scraped, cached or republished data falls within the exemption.

  • Invest in techno-legal enforcement tools. Provenance standards, watermarking, machine unlearning, algorithmic auditing and automated bias detection are what make labelling and traceability duties enforceable in practice; without them, obligations remain symbolic.

  • Build a national AI incident database. A federated incident-reporting mechanism with incentives for disclosure would let regulation be grounded in empirical evidence of Indian harms rather than imported risk grids.

  • Protect constitutional values. Broad labelling, traceability and rapid takedown duties must be tested against Article 19(1)(a) and the reasonable restrictions in Article 19(2), and against the privacy standard laid down in K.S. Puttaswamy v. Union of India (2017), so that the cure does not become a mechanism of prior restraint.

  • Engage internationally on standards. Given the extraterritorial reach of the EU AI Act and the divergence between the Chinese, Singaporean and American models, India's interest lies in shaping interoperable global standards rather than accepting rules made elsewhere.

UPSC Prelims Facts

  • Agentic AI — autonomous AI systems that independently plan multi-step actions, use external tools and adjust strategy to achieve a goal with minimal human supervision.

  • Synthetically Generated Information (SGI) — regulatory term introduced by the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 for AI-created or AI-altered content that appears authentic.

  • IT Amendment Rules, 2026 — notified 10 February 2026, in force from 20 February 2026; require prominent labelling, embedded permanent metadata and traceability of SGI.

  • Section 79, IT Act, 2000 — safe harbour; conditional exemption of intermediaries from liability for third-party information.

  • Section 79(3)(b) — safe harbour lost if unlawful content is not expeditiously removed upon actual knowledge.

  • Shreya Singhal v. Union of India (2015) — struck down Section 66A; read down Section 79(3)(b) so that "actual knowledge" means a court order or government notification, limited to Article 19(2) grounds; upheld Section 69A.

  • Section 69A, IT Act — Central Government's power to block public access to information.

  • Significant Social Media Intermediary — platform with more than 50 lakh registered users in India.

  • Takedown timeline for unlawful content on court or government order — reduced from 36 hours to 3 hours.

  • Digital Personal Data Protection Act, 2023 — enacted 11 August 2023; creates Data Fiduciary and Data Principal; establishes the Data Protection Board of India.

  • Section 3(c)(ii), DPDP Act — Act does not apply to personal data voluntarily made publicly available by the data principal or made public under a legal obligation.

  • Section 17(2)(b), DPDP Act — conditional exemption for processing for research, archiving or statistical purposes.

  • India AI Governance Guidelines — released by MeitY on 5 November 2025; drafting committee constituted July 2025; advisory and non-binding.

  • Seven Sutras — Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; Safety, Resilience and Sustainability.

  • Six Pillars of the Guidelines — Infrastructure; Capacity Building; Policy and Regulation; Risk Mitigation; Accountability; Institutions.

  • Three recommended institutions — AI Governance Group (AIGG), Technology and Policy Expert Committee (TPEC) and AI Safety Institute (AISI).

  • FREE-AI — RBI's Framework for Responsible and Ethical Enablement of Artificial Intelligence; committee constituted December 2024, chaired by Prof. Pushpak Bhattacharyya (IIT Bombay); report released 13 August 2025; 7 sutras, 6 pillars, 26 recommendations.

  • FREE-AI six pillars — Infrastructure, Policy, Capacity, Governance, Protection, Assurance.

  • Regulation 16C, SEBI (Intermediaries) Regulations, 2008 — inserted by the 2025 Amendment effective 10 February 2025; SEBI-regulated entities are solely responsible for data privacy, AI outputs and legal compliance.

  • IndiaAI Mission — approved March 2024; outlay ₹10,371.92 crore over five years; nodal ministry MeitY; pillars include Compute Capacity, Innovation Centre, Datasets Platform, Application Development, FutureSkills, Startup Financing and Safe & Trusted AI.

  • AIKosh — national repository of datasets and AI models under the IndiaAI Mission.

  • AIRAWAT and PARAM Siddhi-AI — AI supercomputers under the National Supercomputing Mission.

  • EU AI Act (Regulation 2024/1689) — world's first horizontal AI law; four risk tiers; maximum penalty €35 million or 7 per cent of global turnover.

  • China's Implementation Opinions on intelligent agents — issued 8 May 2026 by CAC, NDRC and MIIT; effective 15 July 2026; first dedicated national framework for AI agents; three-tier decision authority.

  • Singapore's Model AI Governance Framework for Agentic AI — issued by IMDA; launched January 2026, updated 20 May 2026; four pillars; voluntary.

  • Cyber and AI-risk institutions in India — CERT-In (incident response), I4C (cybercrime coordination), NCIIPC (critical information infrastructure), NCCC (threat monitoring), Data Protection Board of India (data protection enforcement).

  • Nodal ministry for AI policy in India — Ministry of Electronics and Information Technology (MeitY); NITI Aayog authored the National Strategy for Artificial Intelligence (#AIforAll, 2018).

UPSC Previous Year Questions (PYQs)

  1. Introduce the concept of Artificial Intelligence (AI). How does AI help clinical diagnosis? Do you perceive any threat to privacy of the individual in the use of AI in healthcare?UPSC Mains 2023, GS Paper 3, 150 words, 10 marks

  2. Data security has assumed significant importance in the digitized world due to rising cyber crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space?UPSC Mains 2018, GS Paper 3, 250 words, 15 marks

UPSC Mains Practice Questions

  1. India's regulatory response to artificial intelligence has so far relied on subordinate legislation under the Information Technology Act, 2000, sectoral regulation and non-binding national guidelines. In the light of the emergence of agentic AI and synthetically generated content, critically examine whether India requires a dedicated standalone AI statute, and discuss the principles on which liability should be allocated across the AI value chain. (250 words, 15 marks)

UPSC Prelims Practice MCQs

  1. The Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) is associated with which one of the following institutions?
    22 Jul 2026
  2. Consider the following statements regarding the India AI Governance Guidelines:
    1.They were released by the Ministry of Electronics and Information Technology.
    2.They are anchored in seven guiding principles known as sutras.
    3.They recommend the establishment of an AI Governance Group, a Technology and Policy Expert Committee and an AI Safety Institute.
    4.They are legally binding and provide for penalties for non-compliance.
    Which of the statements given above are correct?
    22 Jul 2026
  3. The judgment in Shreya Singhal v. Union of India (2015) is significant for which of the following reasons?
    1.It struck down Section 66A of the Information Technology Act, 2000.
    2.It read down Section 79(3)(b) so that "actual knowledge" means a court order or a government notification.
    3.It struck down Section 69A of the Information Technology Act, 2000.
    Select the correct answer using the code given below:
    22 Jul 2026
  4. In the context of Indian law, the term "safe harbour" is most closely associated with which one of the following?
    22 Jul 2026
  5. With reference to "agentic AI", consider the following statements:
    1.It refers to AI systems that can independently plan multi-step actions and use external tools to achieve a given goal.
    2.The India AI Governance Guidelines describe AI systems as probabilistic, generative, adaptive and agentic.
    3.Agentic AI systems, by definition, operate without any human-defined objective.
    Which of the statements given above is/are correct?
    22 Jul 2026

Sources

  • Press Information Bureau — India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation

  • India AI Governance Guidelines, MeitY (full document)

  • Business Standard — Time has come to look at separate AI legislation, says IT Secretary S Krishnan

  • Deccan Herald — India to consider separate regulatory framework for AI: IT Secretary S Krishnan

  • Khaitan & Co — MeitY notifies the IT Amendment Rules, 2026

  • Freshfields — India targets deepfakes and AI-generated content: key changes under MeitY's 2026 amendments to the IT Rules

  • S.S. Rana & Co. — India Tightens Oversight on AI-Generated Content Under IT Rules

  • Internet Freedom Foundation — IT Intermediary Amendment Rules, 2026 contradict their purpose

  • Supreme Court Observer — X relies on Shreya Singhal in arbitrary content-blocking case in Karnataka High Court

  • Future of Privacy Forum — Five ways in which the DPDPA could shape the development of AI in India

  • IAPP — Scraping public data in India: Innovation enabler or privacy threat?

  • Dvara Research — Summary of the RBI FREE-AI Committee Report

  • KPMG India — RBI's FREE-AI Committee report in the financial sector

  • SCC Online — SEBI introduces the concept of AI via amendment in Intermediaries Regulations

  • MediaNama — India directs X to curb AI-generated sexual content

  • Baker McKenzie — Singapore: IMDA updates Model AI Governance Framework for Agentic AI

  • NYU Shanghai RITS — China Issues First National Policy Framework Dedicated to AI Agents

  • MediaNama — IndiaAI Mission: Only Rs 400 crore released in two years

  • The Indian Express — AI law may cover agent autonomy, deepfakes (Soumyarendra Barik, 21 July 2026)

Share this Article