Abstract
When the Ministry of Electronics and Information Technology released the India AI Governance Guidelines on 5 November 2025, it made a deliberate and consequential choice. India did not follow the European Union down the road of a comprehensive, prescriptive AI statute. It chose instead to govern artificial intelligence through existing law, animated by seven guiding principles and a graded-liability model that distributes responsibility across the AI value chain. For enterprises building, deploying, or procuring AI systems in India, this approach is both a relief and a trap. A relief, because there is no single new compliance regime to certify against. A trap, because governance obligations are now dispersed across data protection law, consumer protection, intermediary liability, sectoral regulation, and contract, and no single checklist captures them. This white paper decodes the 2025 Guidelines, explains the seven sutras and the developer-deployer distinction, and sets out a practical readiness agenda for enterprises that must govern AI responsibly without a single statute telling them how.
“The instinct after any AI announcement is to ask which certificate to obtain. India's Guidelines refuse to answer that question, and deliberately so. Governance here is not a certificate. It is a posture, built from data protection, consumer law, sectoral rules, and the contracts you sign across the AI supply chain. The enterprises that understand this are building AI governance into how they design and procure systems. The ones waiting for a statute to tell them what to do are waiting for a document that is not coming.”
Anandaday Misshra
Founder and Managing Partner
India's Deliberate Choice: Govern Through Existing Law
The India AI Governance Guidelines, released by MeitY on 5 November 2025, represent a philosophical decision as much as a regulatory one. Faced with the global regulatory divergence, the European Union's comprehensive and prescriptive AI Act at one pole, lighter-touch and sectoral approaches elsewhere, India chose to govern AI primarily through its existing legal framework rather than through a new omnibus statute.
This is not regulatory abdication. It is a considered bet that the harms associated with AI, discrimination, privacy violation, consumer deception, safety failures, are already addressable under laws that exist: the Digital Personal Data Protection Act, consumer protection law, information technology and intermediary rules, sectoral regulation in finance and health, and the general law of contract and tort. Rather than duplicate these regimes in a new statute, the Guidelines seek to orient them towards AI-specific risks.
For enterprises, this choice has a defining consequence: there is no single AI compliance regime to certify against, and therefore no single checklist that captures every obligation. AI governance in India is distributed. A single AI system may simultaneously engage data protection duties as it processes personal data, consumer protection duties as it makes representations to users, sectoral duties if it operates in a regulated industry, and contractual duties along the chain of developers, deployers, and users.
This distributed model rewards enterprises that think in terms of principles and risk rather than compliance line items. The organisation that asks what could go wrong with this AI system, and which existing legal duties address those risks is far better positioned than the one waiting for a definitive rulebook. The rulebook, by design, is the existing body of law, read through the lens of the Guidelines.
The Guidelines are principles-based and, at this stage, largely advisory in character, but they signal the direction of enforcement and the standard of conduct that regulators and courts will expect. Treating them as optional because they are not a binding statute misreads their significance. They articulate the governance posture that responsible AI deployment now requires in India.
The Seven Sutras: Principles That Structure the Approach
At the heart of the Guidelines are seven guiding principles, framed as sutras, that articulate the values the framework seeks to protect. While the precise formulation should be read in the source document, their thrust is clear and provides the interpretive backbone for the entire approach.
The principles emphasise trust as the foundation of AI adoption, the centrality of human oversight and accountability, fairness and the avoidance of discriminatory outcomes, transparency so that affected individuals understand when and how AI affects them, safety and resilience of AI systems, privacy consistent with the data protection framework, and the promotion of innovation in the public interest. Together they describe an AI ecosystem that is trustworthy, accountable, and human-centred.
The significance of framing these as principles rather than prescriptive rules is that they apply across contexts and technologies without becoming obsolete as the technology evolves. A prescriptive rule about a specific model architecture ages quickly. A principle requiring human oversight of consequential decisions endures. The Guidelines are built to remain relevant as AI capability advances.
For enterprises, the principles translate into design and governance questions. Does this AI system keep a human meaningfully in the loop for consequential decisions? Can we explain its outputs to those affected? Have we tested it for discriminatory outcomes across the populations it will affect? Is it robust against manipulation and failure? Does its data processing respect the DPDPA? These questions, asked at design time and revisited through the system's life, operationalise the sutras.
The principles also supply the standard against which conduct will be judged when something goes wrong. An enterprise that can demonstrate it took the principles seriously, documented its risk assessments, built in oversight, tested for fairness, will be far better placed, both legally and reputationally, than one that deployed a consequential AI system with no evident regard for them.
Graded Liability and the Developer-Deployer Distinction
Perhaps the most operationally important feature of the Guidelines is the graded-liability model and its distinction between developers and deployers of AI systems. This distinction determines who bears responsibility for what, and it maps directly onto the contractual relationships that structure the AI value chain.
A developer builds or trains the AI system, model, or component. A deployer integrates and uses that system to deliver a product or service to end users. The same enterprise may be both, building an in-house model and deploying it, or it may occupy only one role, deploying a third-party model, or building a model that others deploy. The graded-liability model recognises that responsibility should attach to the actor with the relevant control and knowledge.
This matters enormously for the many enterprises that do not build foundation models but procure and deploy them. A company deploying a third-party AI system is not absolved of responsibility simply because it did not build the model. As a deployer, it is responsible for how the system is used, the context of deployment, the representations made to users, the oversight applied, and the outcomes for affected individuals. But it is also entitled to expect that the developer has discharged the developer-level responsibilities, and this expectation must be secured contractually.
The practical consequence is that AI procurement contracts become central governance instruments. When an enterprise procures an AI system, the contract must allocate responsibility clearly: what the developer warrants about the model's training, testing, and limitations; what documentation and transparency the developer provides; how liability is apportioned if the system causes harm; and what ongoing support and updating the developer commits to. An AI procurement contract that ignores the developer-deployer allocation leaves the deployer exposed to liabilities it did not create and cannot control.
For enterprises building AI, the developer responsibilities, rigorous testing, documentation of limitations, transparency to deployers, and attention to the data on which models are trained, are not merely ethical commitments. They are the basis on which liability will be allocated and the terms on which deployers will be willing to contract. The graded-liability model, in effect, turns responsible development into a commercial necessity.
The DPDPA Intersection: Where AI Governance Meets Data Protection
No account of AI governance in India is complete without the Digital Personal Data Protection Act, because most consequential AI systems process personal data, and the moment they do, the full apparatus of the DPDPA applies. The intersection of AI governance and data protection is where much of the practical compliance work sits.
AI systems that process personal data are subject to the DPDPA's requirements around lawful basis, purpose limitation, and data minimisation. Training a model on personal data, using personal data as input to an AI-driven decision, or generating personal data as output all engage these duties. The convenient assumption that AI processing is somehow outside the data protection framework is wrong, and the enforcement of substantive DPDPA duties from 13 May 2027 will make the consequences concrete.
Automated decision-making deserves particular scrutiny. When an AI system makes or materially influences a decision that affects an individual, credit, employment, insurance, access to services, the intersection of AI governance principles and data protection duties is most acute. The principles of human oversight, transparency, and fairness converge with the data protection concern about consequential automated processing, and enterprises must be able to explain, justify, and, where appropriate, allow human review of such decisions.
Purpose limitation creates a specific tension with AI development. Personal data collected for one purpose cannot be freely repurposed to train an AI model for another. Enterprises that assume their accumulated customer data is available as training data may be mistaken, and the lawful basis for using personal data in model training must be established, not presumed. This is a live issue that many AI initiatives have not confronted.
The data protection impact assessment, already best practice under the DPDPA for high-risk processing, becomes the natural vehicle for documenting AI risk. An impact assessment that evaluates an AI system's data processing, its potential for discriminatory or harmful outcomes, and the safeguards applied produces exactly the record that both the data protection framework and the AI Guidelines expect. It is the single document that best demonstrates responsible AI governance.
Sectoral Overlays and Consumer-Facing AI
Because India governs AI through existing law, sectoral regulation and consumer protection law form an essential part of the governance picture, and their requirements vary sharply by industry and use case.
In regulated sectors, financial services, insurance, healthcare, the sectoral regulator's rules apply to AI systems used within that sector, often with specific requirements around explainability, fairness, and accountability. An AI-driven credit decision engages the expectations of the financial regulator; an AI diagnostic tool engages health and medical device frameworks. Enterprises operating in regulated sectors cannot govern their AI in isolation from their sectoral obligations, and the two must be read together.
Consumer protection law applies wherever AI systems interact with consumers, make representations, or shape purchasing decisions. AI that misleads consumers, whether through deceptive outputs, undisclosed automated interaction, or unfair practices, engages consumer protection duties independent of any AI-specific framework. The rise of AI-driven customer interaction, chatbots, recommendation engines, dynamic pricing, brings consumer protection squarely into AI governance.
Transparency to individuals is a recurring theme across these overlays. Whether under data protection, consumer protection, or the AI principles themselves, there is a consistent expectation that individuals should know when they are interacting with or being affected by an AI system, and should have meaningful recourse. Enterprises deploying consumer-facing AI should design for this transparency rather than retrofit it.
Content-generating AI raises its own cluster of issues, intellectual property in training data and outputs, liability for harmful or infringing content, and the intermediary liability framework where AI-generated content is disseminated through platforms. These issues sit at the intersection of technology law, IP, and intermediary regulation, and they are evolving rapidly. Enterprises deploying generative AI at scale should treat these as active legal risks, not settled questions.
The Enterprise Readiness Agenda
Governing AI through distributed existing law, rather than a single statute, demands that enterprises build an internal governance capability rather than pursue a single certification. The readiness agenda that follows is drawn from what we are implementing with clients now.
Establish an AI inventory. Just as data mapping underpins data protection, an inventory of the AI systems an enterprise builds, procures, and deploys underpins AI governance. You cannot govern AI you have not catalogued, and shadow AI, tools adopted by individual teams without central oversight, is a growing risk. The inventory should record each system's purpose, its role as developer or deployer, the data it processes, and the decisions it affects.
Build AI governance into procurement. Because so much enterprise AI is procured rather than built, the procurement contract is the primary governance instrument. Standard procurement processes must be upgraded to address the developer-deployer allocation, warranties about training and testing, transparency documentation, liability apportionment, and ongoing support. Legal and procurement functions must work together on this, and generic software contracts are inadequate to the task.
Institute risk assessment for consequential systems. For any AI system that makes or materially influences decisions affecting individuals, a structured risk assessment, ideally integrated with the data protection impact assessment, should evaluate fairness, transparency, human oversight, and potential harms before deployment and periodically thereafter. This assessment is both a governance tool and the documentary record that demonstrates diligence.
Assign accountability and engage the board. AI governance, like data protection, needs a named owner and executive oversight. The risks, discriminatory outcomes, privacy violations, consumer harm, safety failures, carry legal, financial, and reputational consequences that belong at the leadership level. An enterprise that deploys consequential AI without clear internal accountability is accepting risk it has not consciously evaluated.
The overarching message is that AI governance in India is a capability to be built, not a box to be ticked. The 2025 Guidelines, by choosing principles and existing law over a prescriptive statute, place the responsibility on enterprises to translate values into practice. The organisations that build this capability now, inventory, procurement discipline, risk assessment, and accountability, will deploy AI with confidence. The ones that wait for a statute will find that the standard of conduct arrived without one.
Key Takeaways
- 1MeitY released the India AI Governance Guidelines on 5 November 2025, choosing to govern AI through existing law rather than a comprehensive new statute
- 2The framework rests on seven guiding principles (sutras) emphasising trust, accountability, fairness, transparency, safety, privacy, and innovation in the public interest
- 3A graded-liability model distinguishes developers (who build or train AI) from deployers (who integrate and use it), making AI procurement contracts central governance instruments
- 4Most consequential AI systems process personal data, so the DPDPA applies in full, with automated decision-making and purpose limitation as acute pressure points ahead of the 13 May 2027 enforcement date
- 5Sectoral regulation and consumer protection law form essential overlays, varying by industry and especially significant for consumer-facing and generative AI
- 6Enterprises should build an AI governance capability, AI inventory, procurement discipline, risk assessment, and board-level accountability, rather than seek a single certification
