Saturday, 12 September 2026
CADialogue
Home Markets Stocks & Indices IPO Watch Commodities Economy RBI Policy Inflation Banking PSU Banks Private Banks Personal Finance Tax Planning Insurance Mutual Funds Equity Funds ELSS / Tax Saving Tax & GST ITR Filing GST Updates Real Estate Startups Crypto Opinion
HomeAI & Technology › AI Regulation in India: What the Governance Guidelines…
AI & Technology

AI Regulation in India: What the Governance Guidelines Say

India has no standalone AI Act. MeitY's India AI Governance Guidelines rely on existing law, voluntary compliance and self-certification. What that means for your practice.

Bhavik Vaid September 1, 2026 7 min read
AI Regulation in India: What the Governance Guidelines Say

India’s AI governance guidelines favour voluntary compliance over a dedicated AI law, while leaving existing data, consumer protection and IT rules fully applicable. For investors assessing businesses using AI, ai regulation india means no licensing regime yet, but deployers remain liable for harms and are expected to follow self-certification, safeguards and oversight principles.

AI regulation in India runs through existing law, not a dedicated AI Act. The Ministry of Electronics and Information Technology (MeitY) published the India AI Governance Guidelines under the IndiaAI Mission, and its central conclusion was that a standalone AI statute is not needed at this stage — the IT Act, the Digital Personal Data Protection Act, the Consumer Protection Act and sector regulators already reach most of the harms. What the Guidelines add is a framework: seven governing principles, three new institutions, and a deliberate preference for voluntary compliance over prescriptive mandates.

For anyone deploying AI in a finance or accounting practice, that answer has a practical edge. There is no licence to apply for and no AI regulator to register with — but the absence of a new law does not mean the absence of liability. Existing obligations apply in full, and they were not written with model behaviour in mind.

What the India AI Governance Guidelines actually establish

MeitY set up a drafting committee in July 2025, ran a public consultation on its draft report, and had a second committee refine the result. The output is guidance rather than statute, and it is built around a “techno-legal” approach — the idea that technical safeguards and legal obligations should be designed together rather than layered on afterwards.

Three design choices define it:

  • Voluntary compliance and self-certification rather than pre-approval. Organisations assess and attest to their own AI systems.
  • Regulatory sandboxes so that supervised experimentation is possible without a full compliance burden up front.
  • Institutional capacity over new prohibitions — the framework creates bodies to coordinate, advise and monitor rather than a licensing gate.

The stated guiding principle is “Do No Harm”. That is a lower bar than the EU’s risk-tiering and a higher one than nothing, and it puts the burden of judgement on the deployer.

Why AI regulation in India took the light-touch route

The committee’s reasoning was coverage, not indifference. Work through where an AI harm would actually land in Indian law today:

  • Personal data — the DPDP Act governs processing, consent and breach obligations regardless of whether a model or a spreadsheet does the processing.
  • Misleading output or deficient service — the Consumer Protection Act reaches unfair trade practice and deficiency in service.
  • Intermediary liability and unlawful content — the IT Act and the intermediary rules.
  • Financial servicesRBI and SEBI conduct, outsourcing, model risk and audit requirements bind regulated entities whatever technology they use.

An AI system that leaks client data breaches DPDP. One that produces a materially wrong tax position breaches professional standards. One that discriminates in lending breaches fair-practice obligations. The mischief is already actionable; the Guidelines aim to make compliance legible rather than to invent new offences.

What this means for a finance or CA practice

This is where the light-touch framework gets uncomfortable. Voluntary self-certification means nobody tells you your deployment is acceptable, and nobody absolves you when it is not.

The obligations that already bite:

  • Client confidentiality. Pasting a client’s financials into a consumer AI tool is a disclosure. Whether it is a permitted one depends on your engagement terms, the tool’s data-retention policy and DPDP consent — not on whether the output was useful.
  • Data localisation and transfer. Most general-purpose models process outside India. Cross-border transfer of personal data carries its own conditions.
  • Professional responsibility is not delegable. ICAI sets the ethical and competence standards for members, and the auditor remains responsible for the integrity of the engagement whatever tools are used. AI assists a member’s judgement; it does not replace it. A wrong figure in a signed document is the member’s, regardless of what produced it.
  • Audit trail. If AI touches a deliverable, you should be able to say which tool, on what input, reviewed by whom. Self-certification is only meaningful if the record exists.

The practical rule for a practice: treat an AI tool exactly as you would treat an outsourced junior in another jurisdiction. You would check their work, limit what data they see, and keep a record. Nothing about the Guidelines relaxes any of that.

What is still unsettled

Several questions the Guidelines do not close:

  • Liability allocation between model developer, deployer and end user is not resolved. In practice it falls on the party the affected person can reach — usually the deployer.
  • Copyright in training data and in output remains contested, and Indian courts have not produced settled authority.
  • Sector rules may move faster than the centre. Financial regulators can issue binding direction on model use inside their perimeter without waiting for a general AI law.
  • Voluntary can become mandatory. Frameworks that begin as guidance frequently harden once harms accumulate. Building to the Guidelines now is cheaper than retrofitting later.

A working compliance checklist

For an Indian business deploying AI today, under current AI regulation in India:

  • Maintain an inventory of AI systems in use, including tools staff adopted informally.
  • Classify each by whether it touches personal data, client confidential data, or a regulated decision.
  • Check the DPDP position for anything touching personal data — lawful basis, retention, transfer, breach process.
  • Keep a human decision-maker of record for any output that reaches a client or a regulator.
  • Write down the review step. An undocumented review does not exist in an inspection.
  • Re-check when a vendor changes model versions or terms; your assessment was of a system that may no longer be the one running.

Frequently asked questions

Is there an AI law in India?

There is no standalone AI Act. MeitY’s India AI Governance Guidelines, issued under the IndiaAI Mission, provide a framework, and the committee concluded that existing legislation — the IT Act, DPDP Act, Consumer Protection Act and sector regulation — already covers the field.

Are the India AI Governance Guidelines legally binding?

They are guidance, built around voluntary compliance and self-certification rather than mandate. The underlying laws they rely on are binding, and that is where enforcement happens.

Can I use AI tools in my CA practice?

Yes, subject to client confidentiality, DPDP obligations where personal data is involved, and the principle that professional judgement and responsibility remain the member’s. Assistance is permitted; delegation of responsibility is not.

What are the seven principles?

The Guidelines set out seven governing principles anchored to a “Do No Harm” objective, supported by three new institutional bodies for coordination and oversight. MeitY publishes the full text through the IndiaAI Mission.

How does India’s approach compare with the EU AI Act?

The EU tiers AI systems by risk and imposes binding obligations with penalties. India has chosen guidance, self-certification and sandboxes over prohibition, on the view that existing law already reaches the harms. India’s route is lighter on process and heavier on the deployer’s own judgement.