India does not have one AI Act as of 11 August 2026, but AI systems are already covered by binding digital, privacy, cyber, consumer and sector laws, while national guidelines and BIS standards set a wider safety framework.
AI safety in India: Key facts
- India has no single law called an AI Act.
- The India AI Governance Guidelines, released on 5 November 2025, are national policy guidance. They are not a statute.
- Binding rules for synthetically generated audio, images and video took effect on 20 February 2026 under the IT Rules.
- The Digital Personal Data Protection framework has started in phases. Most duties that affect personal data used by AI are due to start in May 2027.
- The government formed the AI Governance and Economic Group on 16 April 2026 and its expert committee on 18 April 2026.
- BIS has adopted standards on AI management, risk, trust, data quality, robustness and system life cycles. These are usually voluntary unless a law, regulator or contract makes them compulsory.
- RBI's FREE-AI report and SEBI's 2025 responsible AI paper are not final binding AI codes. Existing laws and issued circulars still apply.
- IndiaAI has approved 13 responsible AI projects, including work on bias, privacy, explanations, deepfake detection and risk assessment.
What are AI safety standards in India?
AI safety standards in India are not contained in one law or one regulator's rulebook. They come from several layers. The first layer is binding law. It includes the Information Technology Act and Rules, cyber incident directions, consumer law, criminal law, copyright law, sector rules and the phased Digital Personal Data Protection framework. The second layer is official guidance. This includes the India AI Governance Guidelines and documents issued for finance, health and other fields. The third layer is made up of technical standards published or adopted by the Bureau of Indian Standards, known as BIS. A fourth layer contains draft rules and consultation papers that may shape later obligations but are not law today.
This distinction matters. A company may break an existing law through an AI system even when it has not breached a separate AI Act. A deepfake may trigger platform, privacy or criminal rules. An AI lending tool may also face banking and consumer duties.
A health model may need data safeguards, human review and ethics approval. At the same time, following a voluntary standard such as IS/ISO/IEC 42001 can help a company show that it manages AI risks, but certification does not cancel its legal duties.
What changed in 2025 and 2026?
India moved from broad responsible AI principles to a more organised governance system between late 2025 and mid-2026.
On 5 November 2025, the government released the India AI Governance Guidelines. The report said that a separate AI law was not needed at that stage. It proposed an approach based on existing laws, sector regulators, technical standards, shared risk tools and new coordinating bodies.
The government then took three steps with direct effect on the framework:
- The Digital Personal Data Protection Rules, 2025 were notified in November 2025 with phased start dates.
- Amendments dealing with synthetically generated information were added to the Information Technology Rules on 10 February 2026 and took effect on 20 February 2026.
- MeitY created the AI Governance and Economic Group on 16 April 2026 and the Technology and Policy Expert Committee on 18 April 2026.
This did not create one AI regulator or one licence for every model. It created a system in which MeitY coordinates national policy, existing regulators handle their sectors, courts and enforcement agencies apply existing laws, and standards bodies provide testing and management methods.
India startup funding and AI investment in Q1 2026
What the India AI Governance Guidelines say
The India AI Governance Guidelines set out seven principles, called sutras in the report:
- Trust is the foundation.
- People come first.
- Innovation should be preferred over restraint where risks can be managed.
- Systems should support fairness and equity.
- Responsibility must be assigned.
- AI should be understandable by design.
- Systems should be safe, resilient and sustainable.
The report organises action under six pillars: infrastructure, capacity building, policy and regulation, risk mitigation, accountability, and institutions.
The guidelines favour regulation of AI use in context. A model used to suggest music does not create the same risk as a model used to approve a loan, diagnose disease, screen a worker or control infrastructure. The report therefore asks sector regulators to apply existing powers and develop rules for their fields.
India's AI governance system
India's national system now has four main parts.
1. AI Governance and Economic Group
The government constituted AIGEG on 16 April 2026. It is a high-level group of ministries that coordinates AI policy, economic issues and the effect of AI on work. It is the central policy body, not a court or a single enforcement regulator.
2. Technology and Policy Expert Committee
The TPEC was constituted on 18 April 2026. It is a standing advisory committee with technical, legal and policy knowledge. It provides advice to AIGEG on policy design, regulation and India's international work. Its role is to advise. The release does not give it independent penalty powers.
3. IndiaAI Safety Institute
The government is establishing the IndiaAI Safety Institute under the Safe and Trusted AI part of the IndiaAI Mission. Official updates describe a hub-and-spoke model that brings together government, universities, startups and industry. A government review of the IndiaAI Mission says 13 responsible AI projects have been selected and started.
The institute's intended work includes testing methods, risk assessment, privacy tools, bias controls, explanations, audits and deepfake detection. The available official material supports describing the institute as being established and building its work programme. It should not yet be described as India's AI licensing authority.
4. Existing regulators and standards bodies
RBI, SEBI, the Indian Council of Medical Research, the Telecom Engineering Centre, CERT-In, BIS, consumer authorities and other bodies continue to act within their existing powers. This sector model is central to India's approach.
BIS and ISO standards for AI safety
BIS is India's national standards body. Its Information Technology, Artificial Intelligence and Big Data committee, LITD 30, develops and adopts standards for AI and data systems.
Annexure 6 of the India AI Governance Guidelines lists 26 numbered AI and data standards, followed by more work under development. The list covers terminology, management systems, risk, trust, robustness, quality, governance, life cycles and data quality.
AI Standards that organisations should know
| Indian standard | Plain-English purpose | Practical use |
|---|---|---|
| IS/ISO/IEC 42001:2023 | Management system for organisations that develop or use AI | Sets roles, policy, risk review, controls, monitoring and improvement |
| IS/ISO/IEC 23894:2023 | Guidance on AI risk management | Helps identify, assess, treat and monitor AI risks |
| IS/ISO/IEC 22989:2022 | AI concepts and terms | Gives teams a shared vocabulary |
| IS/ISO/IEC 23053:2022 | Framework for AI systems using machine learning | Helps describe system parts and how they connect |
| IS/ISO/IEC/TR 24028:2020 | Overview of trust in AI | Covers reliability, safety, security, privacy, fairness and explanations |
| IS/ISO/IEC 24029-2:2023 | Formal methods to assess robustness | Supports testing of how a system handles changed or hostile inputs |
| IS/ISO/IEC 25059:2023 | Quality model for AI systems | Helps define and measure system quality |
| IS/ISO/IEC 38507:2022 | Governance implications of AI | Helps boards and senior managers oversee AI use |
| IS/ISO/IEC 5338:2023 | AI system life-cycle processes | Covers work from design through operation and retirement |
| IS/ISO/IEC 5259 series:2024 | Data quality for analytics and machine learning | Helps assess and manage training and testing data |
| IS/ISO/IEC 8183:2023 | Data life-cycle framework | Covers data creation, use, storage, sharing and disposal |
| IS/ISO/IEC/TR 5469:2024 | AI and functional safety | Helps analyse AI used in systems where failure can harm people or property |
The ISO page for ISO/IEC 42001 describes it as the first AI management system standard. It can be used for certification. BIS has also run a lead auditor course for the Indian adoption, as shown in the BIS training calendar.
UPI rules, limits and biometric changes in 2026
Are BIS AI standards mandatory?
Usually, no. A standard can become compulsory if it is cited in a law, regulator direction, licence, procurement condition or contract. A company may also promise compliance to a client. In those cases, failing to follow it can have legal or commercial effects.
Certification under IS/ISO/IEC 42001 does not prove that every model output is safe, fair or lawful. It shows that an organisation has a management system that meets the assessed requirements. Regulators, customers and courts can still examine the actual data, testing, decisions and harm.
How the DPDP framework applies to AI data
An AI system may handle personal data during collection, model training, testing, prompt processing, retrieval, personalisation, monitoring or output. The DPDP framework applies to digital personal data, not to every data point and not to AI as a technology.
The Digital Personal Data Protection Rules, 2025 were notified in November 2025. Their start is divided into stages.
| Stage | Main position | What an AI organisation should do |
|---|---|---|
| From notification in November 2025 | Preliminary provisions, the Data Protection Board framework and specified institutional rules started | Track Board procedure and identify which future duties apply |
| One year after Gazette publication, expected 13 November 2026 | The consent-manager rule is scheduled to start | Check whether the service will use a registered consent manager |
| Eighteen months after publication, expected 13 May 2027 | Most operating rules are scheduled to start, including notice, security, breach, rights and related duties | Finish data maps, notices, contracts, safeguards, response plans and rights handling before the date |
Sector-by-sector AI safety tracker
Banking and financial services
The RBI's FREE-AI Committee report, published in August 2025, proposes a framework for responsible and ethical AI in finance. It contains seven guiding ideas and 26 recommendations.
The report calls for measures such as:
- a board-approved AI policy;
- an inventory of AI systems;
- risk classification based on use and harm;
- customer disclosure where AI affects service;
- human review for higher-risk decisions;
- data quality and bias testing;
- supplier checks;
- system testing before and after release;
- incident reporting;
- audit records; and
- a complaint route for customers.
This is a committee report. It is not an RBI master direction or circular merely because it appears on the RBI website. Banks, non-bank lenders, payment firms and other regulated entities must continue to follow binding RBI directions that apply to their activity.
The practical lesson is still important. A lender should know whether an AI tool sets a credit limit, detects fraud, writes a customer message or merely helps an employee search a manual. The first two can affect money and access to service, so they need closer review than an office search tool.
For the wider payments context, read News4Bharat's UPI rules tracker for 2026 and CKYC 2.0 explainer.
Securities markets
SEBI published a consultation paper on responsible AI and machine learning use on 20 June 2025. As of 11 August 2026, the paper remains listed as a consultation rather than a final circular.
The proposal discusses governance, fairness, privacy, explainability, security, testing, third-party risk and responsibility for AI use. Firms should prepare for these areas but should not cite the consultation itself as a final legal duty.
SEBI already has issued reporting circulars that remain relevant:
- January 2019 AI and machine learning reporting circular for market intermediaries
- January 2019 reporting circular for market infrastructure institutions
- May 2019 AI and machine learning reporting circular for mutual funds
This is why the date and document type matter. A consultation explains a possible future position. A circular communicates an issued regulatory requirement.
Health and biomedical research
The Indian Council of Medical Research published Ethical Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare in 2023.
The guidance covers ethics review, informed consent, privacy, data quality, fairness, explanations, safety, human oversight and the roles of developers and health professionals. In practice, an AI health project may also face clinical, research, medical-device, hospital, contract and data rules, depending on what it does.
A hospital chatbot that gives general appointment information is not the same as a model that recommends treatment. A research model tested on patient scans is not the same as a consumer fitness tool. The intended use, evidence, person supervising it and effect of a wrong result must be documented.
Telecom and digital infrastructure
The Telecom Engineering Centre has published TEC 57050:2023, Fairness Assessment and Rating of Artificial Intelligence Systems. TEC describes the standard as available for voluntary use.
The TEC convergence and broadcasting division page also lists a November 2025 document on the schema and taxonomy of an AI incident database for telecommunications and digital infrastructure. Work on a robustness assessment and rating standard remains in progress on the TEC AI robustness page.
Telecom operators and infrastructure providers must still apply binding security, licence and incident requirements. A voluntary fairness standard does not replace them.
Elections and political communication
The Election Commission has directed political actors to use social platforms in line with existing law and to label synthetic campaign material. In April 2026, the government reported that misleading or unlawful AI-altered election content must be acted on within three hours after notice to platforms. Political parties and candidates were also required to label covered content as AI-generated, digitally enhanced or synthetic and identify the originating entity.
Election directions operate alongside the IT Act, IT Rules and Model Code of Conduct. Requirements can also depend on whether an election period and specific direction apply.
CKYC 2.0 and the proposed single customer ID
Practical AI safety checklist for organisations
1. Create an AI register
Record every model and AI-enabled service in use, including free tools used by staff. Note the owner, supplier, purpose, data, users, location and date introduced.
2. Classify the use by possible harm
Consider effects on life, health, money, rights, work, access to a public or essential service, children, security and elections. Give higher-risk uses stronger controls.
3. Map the legal duties
List the laws, regulator directions, licences, contracts and policies that apply. Mark each item as binding, phased, voluntary or draft.
4. Check the data
Record the source, permission, quality, age and limits of training, testing and live data. Check personal data, children's data, confidential data, copyrighted material and data transferred to a supplier.
5. Test before release
Use cases should include normal inputs, regional languages, different user groups, incomplete information, misleading prompts, attacks and system outages. Record the test method, result, accepted limit and person who approved release.
6. Keep a human responsible
Name an owner who can review results, pause the system and correct harm. Human review must be real. A person who lacks time, authority or information is not an effective safeguard.
7. Control suppliers
Ask what model is used, where data goes, whether prompts train the model, how changes are announced, what logs exist, how incidents are reported and how data is deleted. Put required answers in the contract.
8. Tell users what matters
Disclose AI use when it affects a person or when a rule requires a label. Explain the system's role, main limits, data use, complaint route and how to seek human review. Do not claim that a system is error-free.
9. Monitor after launch
Track errors, complaints, different outcomes across groups, security events, supplier changes and workarounds by users. Retest after a model or data change.
10. Prepare one incident process
The process should route cyber incidents to the CERT-In team, data breaches to the DPDP response team when those duties apply, sector events to the regulator, harmful content to the platform team and physical or customer harm to the responsible business owner.
11. Keep evidence
Save approvals, data records, tests, model versions, prompts used in control tests, complaints, changes and incident decisions. A policy without evidence will be hard to defend.
12. Use standards to organise the work
IS/ISO/IEC 42001 can organise governance. IS/ISO/IEC 23894 can structure risk work. The 5259 series can support data-quality controls. The selected standard should match the system and should not be treated as a substitute for law.
AI safety regulation timeline in India
| Date | Development | Status on 11 August 2026 | Why it matters |
|---|---|---|---|
| 28 April 2022 | CERT-In cyber directions issued | Binding | Six-hour reporting for listed cyber incidents and 180-day log retention |
| March 2023 | ICMR AI ethics guidelines for health and research | Official guidance | Sets expectations for consent, privacy, fairness, safety and human oversight |
| 7 July 2023 | TEC fairness assessment standard released | Voluntary | Provides a method to assess and rate fairness |
| 11 August 2023 | DPDP Act received assent | Binding with phased commencement | Creates India's main digital personal data framework |
| March 2024 | IndiaAI Mission approved | Government programme | Funds compute, datasets, skills, startups, models and safe AI work |
| 20 June 2025 | SEBI responsible AI consultation published | Consultation | Proposes a securities-market AI governance framework |
| August 2025 | RBI FREE-AI Committee report published | Advisory report | Proposes 26 recommendations for finance |
| 5 November 2025 | India AI Governance Guidelines released | Official guidance | Sets the national model, principles, pillars and action plan |
| November 2025 | DPDP Rules notified | Binding in phases | Starts institutional rules and sets later dates for core duties |
| November 2025 | TEC AI incident taxonomy for telecom and digital infrastructure listed | Standardisation document | Supports common incident records in the sector |
| 10 February 2026 | SGI amendments to IT Rules notified | Binding | Adds labels, technical measures and due diligence for covered synthetic media |
| 20 February 2026 | SGI amendments took effect | Binding | Compliance duties became operative |
| 16 April 2026 | AIGEG constituted | In operation as a policy body | Creates a central inter-ministerial AI governance mechanism |
| 18 April 2026 | TPEC constituted | In operation as an advisory body | Gives AIGEG technical, legal and policy advice |
| 21 April 2026 | Further IT Rules amendments published | Draft | Not law at the cut-off date |
| Expected 13 November 2026 | DPDP consent-manager rule scheduled to start | Future binding phase | Affects registered consent-manager arrangements |
| Expected 13 May 2027 | Most DPDP operating rules scheduled to start | Future binding phase | Brings notice, security, breach and rights processes into the main compliance phase |
News4Bharat POV
India's framework has one benefit and one cost.
The benefit is that it can respond to the use, not just the name of the technology. RBI can focus on credit and payments. ICMR can focus on patients and research. SEBI can focus on markets. CERT-In can focus on cyber incidents. This avoids treating a photo filter and a medical decision system as if they create the same risk.
The cost is that a business or citizen has to assemble the answer from many documents. A national guideline may be mistaken for law. A consultation may be reported as a final rule. A voluntary standard may be sold as government approval. A phased Act may be described as fully in force. These errors create false comfort and false alarm.
The next test is not whether India can publish more principles. It is whether people can see which systems affect them, who approved those systems, what tests were run, where they can complain and what happens after failure. A useful AI safety system needs evidence from real deployments, not only policy statements.
The launch of more capable models also raises a question about evaluation before use in security, finance, health and government. News4Bharat's report on GPT-5.6 Sol and the security review before its release provides international context. India's own framework now has institutions that can study such model risks, but it does not yet create a general pre-release approval process for frontier models.
Sources & Disclaimer
This article was checked against documents available on government, regulator and standards-body websites through 11 August 2026. It gives preference to Gazette notifications, ministry pages, regulator circulars and official reports. It labels a document by legal status rather than by the authority's name alone.
India AI Governance Guidelines, 5 November 2025, AIGEG constitution announcement, 16 April 2026, TPEC constitution announcement, 18 April 2026, IndiaAI Mission review and 13 responsible AI projects, July 2026 update on responsible AI projects, MeitY IT Rules page with February 2026 SGI notification, updated rules, FAQ and corrigendum, MeitY DPDP Rules page and enforcement timeline, CERT-In directions and related documents, MeitY April 2026 draft IT Rules amendments


