AI Safety Standards in India 2026: Laws, Rules, BIS Standards and Compliance Dates

India's AI framework now includes binding synthetic-content rules, phased data-protection duties, sector requirements and voluntary BIS standards. This tracker explains what applies, who is affected and which dates come next.

Srajan AgarwalSrajan AgarwalEditorial Desk14 Aug 2026 · 3:36 PM IST16 min read
AI safety standards in India covering laws, BIS standards, privacy rules and sector guidance
India's AI safety framework combines binding laws, phased data-protection duties, sector requirements, official guidance and voluntary standards.Source: News4Bharat Graphic

India does not have one AI Act as of 11 August 2026, but AI systems are already covered by binding digital, privacy, cyber, consumer and sector laws, while national guidelines and BIS standards set a wider safety framework.

AI safety in India: Key facts

  • India has no single law called an AI Act.
  • The India AI Governance Guidelines, released on 5 November 2025, are national policy guidance. They are not a statute.
  • Binding rules for synthetically generated audio, images and video took effect on 20 February 2026 under the IT Rules.
  • The Digital Personal Data Protection framework has started in phases. Most duties that affect personal data used by AI are due to start in May 2027.
  • The government formed the AI Governance and Economic Group on 16 April 2026 and its expert committee on 18 April 2026.
  • BIS has adopted standards on AI management, risk, trust, data quality, robustness and system life cycles. These are usually voluntary unless a law, regulator or contract makes them compulsory.
  • RBI's FREE-AI report and SEBI's 2025 responsible AI paper are not final binding AI codes. Existing laws and issued circulars still apply.
  • IndiaAI has approved 13 responsible AI projects, including work on bias, privacy, explanations, deepfake detection and risk assessment.

What are AI safety standards in India?

AI safety standards in India are not contained in one law or one regulator's rulebook. They come from several layers. The first layer is binding law. It includes the Information Technology Act and Rules, cyber incident directions, consumer law, criminal law, copyright law, sector rules and the phased Digital Personal Data Protection framework. The second layer is official guidance. This includes the India AI Governance Guidelines and documents issued for finance, health and other fields. The third layer is made up of technical standards published or adopted by the Bureau of Indian Standards, known as BIS. A fourth layer contains draft rules and consultation papers that may shape later obligations but are not law today.

This distinction matters. A company may break an existing law through an AI system even when it has not breached a separate AI Act. A deepfake may trigger platform, privacy or criminal rules. An AI lending tool may also face banking and consumer duties. 

A health model may need data safeguards, human review and ethics approval. At the same time, following a voluntary standard such as IS/ISO/IEC 42001 can help a company show that it manages AI risks, but certification does not cancel its legal duties.

What changed in 2025 and 2026?

India moved from broad responsible AI principles to a more organised governance system between late 2025 and mid-2026.

On 5 November 2025, the government released the India AI Governance Guidelines. The report said that a separate AI law was not needed at that stage. It proposed an approach based on existing laws, sector regulators, technical standards, shared risk tools and new coordinating bodies.

The government then took three steps with direct effect on the framework:

This did not create one AI regulator or one licence for every model. It created a system in which MeitY coordinates national policy, existing regulators handle their sectors, courts and enforcement agencies apply existing laws, and standards bodies provide testing and management methods.

India startup funding and AI investment in Q1 2026

What the India AI Governance Guidelines say

The India AI Governance Guidelines set out seven principles, called sutras in the report:

  • Trust is the foundation.
  • People come first.
  • Innovation should be preferred over restraint where risks can be managed.
  • Systems should support fairness and equity.
  • Responsibility must be assigned.
  • AI should be understandable by design.
  • Systems should be safe, resilient and sustainable.

The report organises action under six pillars: infrastructure, capacity building, policy and regulation, risk mitigation, accountability, and institutions.

The guidelines favour regulation of AI use in context. A model used to suggest music does not create the same risk as a model used to approve a loan, diagnose disease, screen a worker or control infrastructure. The report therefore asks sector regulators to apply existing powers and develop rules for their fields.

India's AI governance system

India's national system now has four main parts.

1. AI Governance and Economic Group

The government constituted AIGEG on 16 April 2026. It is a high-level group of ministries that coordinates AI policy, economic issues and the effect of AI on work. It is the central policy body, not a court or a single enforcement regulator.

2. Technology and Policy Expert Committee

The TPEC was constituted on 18 April 2026. It is a standing advisory committee with technical, legal and policy knowledge. It provides advice to AIGEG on policy design, regulation and India's international work. Its role is to advise. The release does not give it independent penalty powers.

3. IndiaAI Safety Institute

The government is establishing the IndiaAI Safety Institute under the Safe and Trusted AI part of the IndiaAI Mission. Official updates describe a hub-and-spoke model that brings together government, universities, startups and industry. A government review of the IndiaAI Mission says 13 responsible AI projects have been selected and started.

The institute's intended work includes testing methods, risk assessment, privacy tools, bias controls, explanations, audits and deepfake detection. The available official material supports describing the institute as being established and building its work programme. It should not yet be described as India's AI licensing authority.

4. Existing regulators and standards bodies

RBI, SEBI, the Indian Council of Medical Research, the Telecom Engineering Centre, CERT-In, BIS, consumer authorities and other bodies continue to act within their existing powers. This sector model is central to India's approach.

BIS and ISO standards for AI safety

BIS is India's national standards body. Its Information Technology, Artificial Intelligence and Big Data committee, LITD 30, develops and adopts standards for AI and data systems.

Annexure 6 of the India AI Governance Guidelines lists 26 numbered AI and data standards, followed by more work under development. The list covers terminology, management systems, risk, trust, robustness, quality, governance, life cycles and data quality.

AI Standards that organisations should know

Indian standardPlain-English purposePractical use
IS/ISO/IEC 42001:2023Management system for organisations that develop or use AISets roles, policy, risk review, controls, monitoring and improvement
IS/ISO/IEC 23894:2023Guidance on AI risk managementHelps identify, assess, treat and monitor AI risks
IS/ISO/IEC 22989:2022AI concepts and termsGives teams a shared vocabulary
IS/ISO/IEC 23053:2022Framework for AI systems using machine learningHelps describe system parts and how they connect
IS/ISO/IEC/TR 24028:2020Overview of trust in AICovers reliability, safety, security, privacy, fairness and explanations
IS/ISO/IEC 24029-2:2023Formal methods to assess robustnessSupports testing of how a system handles changed or hostile inputs
IS/ISO/IEC 25059:2023Quality model for AI systemsHelps define and measure system quality
IS/ISO/IEC 38507:2022Governance implications of AIHelps boards and senior managers oversee AI use
IS/ISO/IEC 5338:2023AI system life-cycle processesCovers work from design through operation and retirement
IS/ISO/IEC 5259 series:2024Data quality for analytics and machine learningHelps assess and manage training and testing data
IS/ISO/IEC 8183:2023Data life-cycle frameworkCovers data creation, use, storage, sharing and disposal
IS/ISO/IEC/TR 5469:2024AI and functional safetyHelps analyse AI used in systems where failure can harm people or property

The ISO page for ISO/IEC 42001 describes it as the first AI management system standard. It can be used for certification. BIS has also run a lead auditor course for the Indian adoption, as shown in the BIS training calendar.

UPI rules, limits and biometric changes in 2026

Are BIS AI standards mandatory?

Usually, no. A standard can become compulsory if it is cited in a law, regulator direction, licence, procurement condition or contract. A company may also promise compliance to a client. In those cases, failing to follow it can have legal or commercial effects.

Certification under IS/ISO/IEC 42001 does not prove that every model output is safe, fair or lawful. It shows that an organisation has a management system that meets the assessed requirements. Regulators, customers and courts can still examine the actual data, testing, decisions and harm.

How the DPDP framework applies to AI data

An AI system may handle personal data during collection, model training, testing, prompt processing, retrieval, personalisation, monitoring or output. The DPDP framework applies to digital personal data, not to every data point and not to AI as a technology.

The Digital Personal Data Protection Rules, 2025 were notified in November 2025. Their start is divided into stages.

StageMain positionWhat an AI organisation should do
From notification in November 2025Preliminary provisions, the Data Protection Board framework and specified institutional rules startedTrack Board procedure and identify which future duties apply
One year after Gazette publication, expected 13 November 2026The consent-manager rule is scheduled to startCheck whether the service will use a registered consent manager
Eighteen months after publication, expected 13 May 2027Most operating rules are scheduled to start, including notice, security, breach, rights and related dutiesFinish data maps, notices, contracts, safeguards, response plans and rights handling before the date

Sector-by-sector AI safety tracker

Banking and financial services

The RBI's FREE-AI Committee report, published in August 2025, proposes a framework for responsible and ethical AI in finance. It contains seven guiding ideas and 26 recommendations.

The report calls for measures such as:

  • a board-approved AI policy;
  • an inventory of AI systems;
  • risk classification based on use and harm;
  • customer disclosure where AI affects service;
  • human review for higher-risk decisions;
  • data quality and bias testing;
  • supplier checks;
  • system testing before and after release;
  • incident reporting;
  • audit records; and
  • a complaint route for customers.

This is a committee report. It is not an RBI master direction or circular merely because it appears on the RBI website. Banks, non-bank lenders, payment firms and other regulated entities must continue to follow binding RBI directions that apply to their activity.

The practical lesson is still important. A lender should know whether an AI tool sets a credit limit, detects fraud, writes a customer message or merely helps an employee search a manual. The first two can affect money and access to service, so they need closer review than an office search tool.

For the wider payments context, read News4Bharat's UPI rules tracker for 2026 and CKYC 2.0 explainer.

Securities markets

SEBI published a consultation paper on responsible AI and machine learning use on 20 June 2025. As of 11 August 2026, the paper remains listed as a consultation rather than a final circular.

The proposal discusses governance, fairness, privacy, explainability, security, testing, third-party risk and responsibility for AI use. Firms should prepare for these areas but should not cite the consultation itself as a final legal duty.

SEBI already has issued reporting circulars that remain relevant:

  • January 2019 AI and machine learning reporting circular for market intermediaries
  • January 2019 reporting circular for market infrastructure institutions
  • May 2019 AI and machine learning reporting circular for mutual funds

This is why the date and document type matter. A consultation explains a possible future position. A circular communicates an issued regulatory requirement.

Health and biomedical research

The Indian Council of Medical Research published Ethical Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare in 2023.

The guidance covers ethics review, informed consent, privacy, data quality, fairness, explanations, safety, human oversight and the roles of developers and health professionals. In practice, an AI health project may also face clinical, research, medical-device, hospital, contract and data rules, depending on what it does.

A hospital chatbot that gives general appointment information is not the same as a model that recommends treatment. A research model tested on patient scans is not the same as a consumer fitness tool. The intended use, evidence, person supervising it and effect of a wrong result must be documented.

Telecom and digital infrastructure

The Telecom Engineering Centre has published TEC 57050:2023, Fairness Assessment and Rating of Artificial Intelligence Systems. TEC describes the standard as available for voluntary use.

The TEC convergence and broadcasting division page also lists a November 2025 document on the schema and taxonomy of an AI incident database for telecommunications and digital infrastructure. Work on a robustness assessment and rating standard remains in progress on the TEC AI robustness page.

Telecom operators and infrastructure providers must still apply binding security, licence and incident requirements. A voluntary fairness standard does not replace them.

Elections and political communication

The Election Commission has directed political actors to use social platforms in line with existing law and to label synthetic campaign material. In April 2026, the government reported that misleading or unlawful AI-altered election content must be acted on within three hours after notice to platforms. Political parties and candidates were also required to label covered content as AI-generated, digitally enhanced or synthetic and identify the originating entity.

Election directions operate alongside the IT Act, IT Rules and Model Code of Conduct. Requirements can also depend on whether an election period and specific direction apply.

CKYC 2.0 and the proposed single customer ID

Practical AI safety checklist for organisations

1. Create an AI register

Record every model and AI-enabled service in use, including free tools used by staff. Note the owner, supplier, purpose, data, users, location and date introduced.

2. Classify the use by possible harm

Consider effects on life, health, money, rights, work, access to a public or essential service, children, security and elections. Give higher-risk uses stronger controls.

3. Map the legal duties

List the laws, regulator directions, licences, contracts and policies that apply. Mark each item as binding, phased, voluntary or draft.

4. Check the data

Record the source, permission, quality, age and limits of training, testing and live data. Check personal data, children's data, confidential data, copyrighted material and data transferred to a supplier.

5. Test before release

Use cases should include normal inputs, regional languages, different user groups, incomplete information, misleading prompts, attacks and system outages. Record the test method, result, accepted limit and person who approved release.

6. Keep a human responsible

Name an owner who can review results, pause the system and correct harm. Human review must be real. A person who lacks time, authority or information is not an effective safeguard.

7. Control suppliers

Ask what model is used, where data goes, whether prompts train the model, how changes are announced, what logs exist, how incidents are reported and how data is deleted. Put required answers in the contract.

8. Tell users what matters

Disclose AI use when it affects a person or when a rule requires a label. Explain the system's role, main limits, data use, complaint route and how to seek human review. Do not claim that a system is error-free.

9. Monitor after launch

Track errors, complaints, different outcomes across groups, security events, supplier changes and workarounds by users. Retest after a model or data change.

10. Prepare one incident process

The process should route cyber incidents to the CERT-In team, data breaches to the DPDP response team when those duties apply, sector events to the regulator, harmful content to the platform team and physical or customer harm to the responsible business owner.

11. Keep evidence

Save approvals, data records, tests, model versions, prompts used in control tests, complaints, changes and incident decisions. A policy without evidence will be hard to defend.

12. Use standards to organise the work

IS/ISO/IEC 42001 can organise governance. IS/ISO/IEC 23894 can structure risk work. The 5259 series can support data-quality controls. The selected standard should match the system and should not be treated as a substitute for law.

AI safety regulation timeline in India

DateDevelopmentStatus on 11 August 2026Why it matters
28 April 2022CERT-In cyber directions issuedBindingSix-hour reporting for listed cyber incidents and 180-day log retention
March 2023ICMR AI ethics guidelines for health and researchOfficial guidanceSets expectations for consent, privacy, fairness, safety and human oversight
7 July 2023TEC fairness assessment standard releasedVoluntaryProvides a method to assess and rate fairness
11 August 2023DPDP Act received assentBinding with phased commencementCreates India's main digital personal data framework
March 2024IndiaAI Mission approvedGovernment programmeFunds compute, datasets, skills, startups, models and safe AI work
20 June 2025SEBI responsible AI consultation publishedConsultationProposes a securities-market AI governance framework
August 2025RBI FREE-AI Committee report publishedAdvisory reportProposes 26 recommendations for finance
5 November 2025India AI Governance Guidelines releasedOfficial guidanceSets the national model, principles, pillars and action plan
November 2025DPDP Rules notifiedBinding in phasesStarts institutional rules and sets later dates for core duties
November 2025TEC AI incident taxonomy for telecom and digital infrastructure listedStandardisation documentSupports common incident records in the sector
10 February 2026SGI amendments to IT Rules notifiedBindingAdds labels, technical measures and due diligence for covered synthetic media
20 February 2026SGI amendments took effectBindingCompliance duties became operative
16 April 2026AIGEG constitutedIn operation as a policy bodyCreates a central inter-ministerial AI governance mechanism
18 April 2026TPEC constitutedIn operation as an advisory bodyGives AIGEG technical, legal and policy advice
21 April 2026Further IT Rules amendments publishedDraftNot law at the cut-off date
Expected 13 November 2026DPDP consent-manager rule scheduled to startFuture binding phaseAffects registered consent-manager arrangements
Expected 13 May 2027Most DPDP operating rules scheduled to startFuture binding phaseBrings notice, security, breach and rights processes into the main compliance phase

News4Bharat POV

India's framework has one benefit and one cost.

The benefit is that it can respond to the use, not just the name of the technology. RBI can focus on credit and payments. ICMR can focus on patients and research. SEBI can focus on markets. CERT-In can focus on cyber incidents. This avoids treating a photo filter and a medical decision system as if they create the same risk.

The cost is that a business or citizen has to assemble the answer from many documents. A national guideline may be mistaken for law. A consultation may be reported as a final rule. A voluntary standard may be sold as government approval. A phased Act may be described as fully in force. These errors create false comfort and false alarm.

The next test is not whether India can publish more principles. It is whether people can see which systems affect them, who approved those systems, what tests were run, where they can complain and what happens after failure. A useful AI safety system needs evidence from real deployments, not only policy statements.

The launch of more capable models also raises a question about evaluation before use in security, finance, health and government. News4Bharat's report on GPT-5.6 Sol and the security review before its release provides international context. India's own framework now has institutions that can study such model risks, but it does not yet create a general pre-release approval process for frontier models.

Sources & Disclaimer

This article was checked against documents available on government, regulator and standards-body websites through 11 August 2026. It gives preference to Gazette notifications, ministry pages, regulator circulars and official reports. It labels a document by legal status rather than by the authority's name alone.

India AI Governance Guidelines, 5 November 2025, AIGEG constitution announcement, 16 April 2026, TPEC constitution announcement, 18 April 2026, IndiaAI Mission review and 13 responsible AI projects, July 2026 update on responsible AI projects, MeitY IT Rules page with February 2026 SGI notification, updated rules, FAQ and corrigendum, MeitY DPDP Rules page and enforcement timeline, CERT-In directions and related documents, MeitY April 2026 draft IT Rules amendments

Frequently Asked Questions

Does India have an AI Act?

No. As of 11 August 2026, India has no single statute called an AI Act. AI is governed through existing laws, the 2026 synthetic-content rules, phased data-protection duties, sector requirements, official guidance and standards.

Are the India AI Governance Guidelines legally binding?

The November 2025 guidelines are official policy guidance, not an Act or rule. Existing laws and regulator directions referred to in the report can be binding.

Is ISO 42001 mandatory in India?

Not as a general rule for every organisation. It may become required through a law, regulator direction, licence, procurement term or contract. Certification does not replace legal compliance.

Are AI-generated images required to be labelled?

The 2026 IT Rules impose labelling and related duties for covered synthetically generated audio, visual and audio-visual information.

Is RBI's FREE-AI framework compulsory for banks?

The August 2025 publication is a committee report with recommendations. It is not, by itself, a final RBI direction. Banks must follow binding RBI rules that apply to their activity and watch for later implementation of the recommendations.

When do the main DPDP duties affecting AI start?

Most operating rules are scheduled to start 18 months after the November 2025 Gazette publication, expected on 13 May 2027

Related Topics

Srajan Agarwal

About the Author

Srajan Agarwal

Editorial Desk

Srajan Agarwal, an advertising, digital marketing, and content strategy professional driven by the idea that powerful storytelling can shape brands, influence decisions, and build lasting impact. As the Founder of News4Bharat and someone deeply involved in content-led initiatives, I work at the intersection of content marketing, digital growth, media strategy, and brand storytelling. My experience spans across building editorial ecosystems, executing high-performance digital campaigns, and crafting narratives that connect with the right audience at the right time. Over the years, I’ve worked on content strategy, SEO content writing, social media marketing, performance marketing, branding, and digital campaign execution, helping brands establish a strong and differentiated voice in competitive markets. I believe in blending creative storytelling with data-driven marketing, ensuring that every piece of content is not just engaging—but also delivers measurable results.

© Copyright 2026 News4Bharat - All Rights Reserved.