The (MeitY) is drafting a standalone law to regulate Artificial Intelligence (AI), moving away from earlier statements that existing laws were sufficient. The proposed legislation focuses on creating a consent-based framework for synthetically-generated content (like deepfakes), regulating autonomous 'agentic AI', and establishing regulatory sandboxes for high-risk applications, marking a significant shift in India's approach to technology governance.
The proposed AI law highlights a critical governance challenge: transitioning from ex-post regulation (reacting to harms after they occur) to ex-ante regulation (anticipating and preventing harms). Currently, tech regulation heavily relies on the Information Technology Act, 2000, which was designed for the internet era, not the AI age. The shift toward a standalone AI law indicates the government recognizes that traditional concepts like Safe Harbour (where platforms are immune from liability for user-generated content under Section 79 of the IT Act) may not apply to AI models that actively 'editorialize' or synthesize responses rather than merely hosting them. This raises complex questions about platform liability and requires a new legal framework that balances innovation with accountability, particularly regarding deepfakes and misinformation.
The intersection of AI regulation and privacy rights touches upon the fundamental right to privacy guaranteed under Article 21 (as established in the Puttaswamy judgment). The article notes that the Digital Personal Data Protection Act, 2023 (DPDP Act) exempts publicly available personal data from its protection. This creates a regulatory gap: AI models can scrape public social media data without oversight, potentially violating the principle of informed consent. The proposed AI law aims to address this by mandating a 'consent-based framework' for synthetically generated media. This forces policymakers to navigate the tension between data utility for AI training and the protection of an individual's digital persona, highlighting the need for dynamic, technology-specific privacy safeguards beyond the broader DPDP framework.
The government's plan to establish regulatory sandboxes (controlled environments where new technologies can be tested with relaxed regulatory constraints) in collaboration with the Reserve Bank of India and the Securities and Exchange Board of India is a strategic economic move. High-impact sectors like finance are vulnerable to the risks of Agentic AI (autonomous systems capable of independent planning and action), which could disrupt markets or compromise data if left unchecked. By creating sandboxes, regulators can observe AI behavior in real-world scenarios, identify systemic risks, and develop appropriate safeguards without stifling innovation. This approach ensures that India can harness AI for economic growth while maintaining financial stability and consumer protection, reflecting a mature approach to tech-driven economic development.