Published On: 20th August 2026
Authored By: Nirmal Kaur
SRM University
I. INTRODUCTION
Generative artificial intelligence (“generative AI”) encompasses a family of increasingly sophisticated machine-learning systems capable of producing text, imagery, audio, video, and computer code as output. Such systems have seen rapid adoption as tools for search, productivity, journalism, and creative expression, fueling India’s ambitions to be a global AI pioneer. However, the rise of generative AI has outrun attempts to grapple with its regulatory implications. As a technology that facilitates unprecedented levels of automation and replication, generative AI sits at the intersection of several contentious policy issues, including intellectual property rights, personal data privacy, and free speech, none of which have straightforward answers in Indian law. India’s current legal framework consists of a mix of reactive and ad-hoc measures, including sector-specific statutes, subordinate rules and guidelines, and ongoing litigation, none of which fully address the challenges raised by generative AI.[1]
This article argues that India’s existing legal framework is ill-equipped to address the challenges posed by generative AI, particularly in the areas of copyright, data privacy, and free speech. At the same time, purely voluntary industry self-regulation and broad command-and-control legislation fail to consider the nuanced policy trade-offs off different regulatory approaches. India needs a hybrid approach that combines technology-neutral, privacy-preserving obligations with more flexible, sector-specific rules that take into account the dynamic nature of AI technologies and India’s innovation-led growth trajectory. The following section provides an overview of generative AI, while the ensuing sections outline the legal and policy challenges posed by this technology.
II. CONCEPT AND SCOPE OF GENERATIVE AI
At a technical level, generative AI refers to a class of machine-learning systems that employ large-scale neural networks and are trained on extensive data sets in order to produce desired outputs. These systems can take various forms, including but not limited to chatbots that employ language-models, AI image-generators that use diffusion mechanisms, and voice-cloning software. At a conceptual level, generative AI presents unique challenges compared to conventional computer software. While traditional programming is based on human-authored algorithms that produce deterministic outputs, generative AI employs self-learning neural networks that yield probabilistic outcomes that are difficult to predict and control.[2]
Three characteristics of generative AI systems are particularly pertinent to their regulatory challenges in India. First, these systems facilitate the creation of intellectual property (IP), including language-model training data, computer code, and other copyrightable expressions. Second, generative AI systems typically rely on extensive training data sets, often containing information extracted from publicly available digital resources without the consent of the data subjects. Third, the outputs of generative AI systems can range from highly original creations to precise replications of existing material, blurring the lines between authentic and artificially generated content. All three characteristics present regulatory challenges in India, where copyright laws, data privacy rules, and liability regimes were not designed with self-learning technologies in mind.[3]
III. INDIAN LAW AND POLICY FRAMEWORK
India does not possess a comprehensive legal framework for regulating generative AI, with relevant rules emanating from various statutes and policy instruments. The Information Technology Act 2000 (“IT Act”), which governs electronic communication and commerce, contains limited but important provisions pertaining to generative AI. Section 66A of the IT Act, which criminalized the publication of “offensive” content, was invalidated in Shreya Singhal v Union of India on free speech grounds.[4] Consequently, any laws regulating generative AI must conform to India’s constitutional freedom of expression jurisprudence. At the same time, Section 79 of the IT Act grants “safe harbor” to online platforms for third-party content, so long as they follow due diligence procedures. This liability-limiting provision has been further elaborated upon by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 (“IT Rules”). Notably, the October 2025 amendments to the IT Rules contain specific references to “synthetically generated information,” including requirements pertaning to disclosure and traceability of content generated using AI.[5]
The Digital Personal Data Protection Act 2023 (“DPDP Act”) governs the processing of personal data, imposing certain obligations on data controllers and processors. The DPDP Act adopts a consent-based framework but contains limited provisions pertaining to the application of AI technologies.[6] The Copyright Act 1957 contains a number of exceptions and limitations in Section 52 that may apply to the training data sets used by generative AI systems, but the applicability of Section 52 to such use is unclear. Indian copyright law also grants copyright protection only to natural persons, raising additional questions regarding the IP ownership of AI-generated content.[7] In practice, these questions have yet to be answered, as ANI Media Pvt Ltd v OpenAI Inc, India’s first copyright litigation concerning generative AI, is yet to deliver a verdict.[8]
Several advisory-guidance documents from government agencies touch upon issues pertaining to generative AI. Notably, the Ministry of Electronics and Information Technology (“MeitY”) has issued advisories, including in December 2023 and March 2024, that encouraged platforms to disclose “under-tested” and “unreliable” AI tools. However, these advisories lack force of law and have been withdrawn within months of issuance due to industry backlash.[9]
Overall, India’s legal and policy framework concerning generative AI is built upon a set of disparate and inconsistently applied rules. A combination of statutes, subordinate legislation, and advisory documents provide limited guidance on issues of copyright, data privacy, and liability but have failed to keep pace with the rapid developments in the underlying technology. With the next steps in India’s generative AI regulatory process likely to emanate from litigation and sector-specific guidelines, several pressing legal and policy questions remain.
IV. LEGAL AND POLICY CHALLENGES POSED BY GENERATIVE AI
(a) Copyright in training data and output
The training data sets used by generative AI systems often consist of copyrighted material, the use of which raises complex legal questions. If such material is used without the consent of the rights-holder, it constitutes copyright infringement under Section 14 of the Copyright Act. There is no analogous exception in Indian law to the European Union’s text and data-mining exception under the Digital Single Market Directive.[10] At the same time, if the output of a generative AI system constitutes a “work,” it would be protected under Section 13 of the Copyright Act and the “author” of such work would be entitled to protection under Section 17. However, Indian copyright law only recognizes natural persons as authors, and the use of generative AI in the production process may raise additional questions under the “work made for hire” doctrine.[11]
(b) Privacy in data collection and training
Generative AI systems typically rely on data sets collected from publicly available digital sources. However, such data sets often contain personal data processed without the consent of the data subject. Although the DPDP Act follows a consent-based approach to data processing, it does not explicitly address the collection of personal data for the purposes of training AI models. This gap in India’s data privacy framework creates uncertainty concerning the legality of such data collection practices and the rights of data subjects in this context.[12]
(c) Liability for harmful or false output
If a generative AI system produces false or defamatory output, it raises difficult questions of liability in tort and criminal law. Under Indian tort law, a defendant can be held liable on the basis of negligence or wilful misconduct. While a company deploying an AI system may be held strictly liable for damages caused by its products or services under Section 18 of the Consumer Protection Act 1986, a finding of negligence requires the plaintiff to establish a duty of care between the defendant and the plaintiff. Section 66 of the IT Act criminalizes the publication of false digital information, but its application to generative AI systems is unclear, as such systems are incapable of intention or mens rea.[13]
(d) Deepfakes, misinformation, and reputational harm
Synthetic audio-visual content produced with the help of generative AI can damage the reputation of individuals and organizations, giving rise to defamation and privacy law claims. The issue of deepfakes has already seen judicial attention in India, with the spiritual leader Jaggi Vasudev petitioning the Delhi High Court against AI-generated deepfake videos and endorsements published without his consent. The matter has since prompted several authorities to take action, including the blocking of the relevant social media accounts and websites.[14] The October 2025 amendments to the IT Rules address this issue by imposing disclosure and traceability obligations upon entities publishing synthetic content. However, the vague language of the amendments as well as the reliance on notice-and-takedown procedures have resulted in criticism from privacy and free speech activists, who argue that such measures fail to account for the complexities of AI governance.[15]
(e) Bias, discrimination, and fairness
Generative AI systems typically rely upon training data sets that reflect historical patterns of human behaviour. As a result, such systems may perpetuate social inequities and discrimination on the basis of caste, gender, religion, and other grounds. Such issues are particularly pertinent to India, where social prejudices often remain deeply ingrained in society. At present, India does not possess a comprehensive anti-discrimination framework that would explicitly apply to AI systems and their outputs.[16]
(f) Transparency and explainability
The opacity of AI decision-making presents serious governance and accountability concerns. A generative AI system’s “black box” nature makes it challenging to determine the factors influencing a particular output. Such difficulty in auditing AI systems has implications for several areas of Indian law, including tort law, privacy law, and contract law, all of which require the involvement of a human agent who possesses mens rea or informed consent.[17]
V. CONSTITUTIONAL DIMENSIONS
Several of the legal and policy challenges posed by generative AI touch upon fundamental rights guaranteed by the Constitution of India. In particular, the collection of personal data for the training of AI systems without the consent of the data subject may violate the right to privacy, which was recognized by the Supreme Court in Justice K S Puttaswamy v Union of India as a fundamental right under Article 21 of the Constitution. The collection of such data without the data subject’s consent is subject to the legality, necessity, and proportionality tests laid down by the Supreme Court in Puttaswamy.[18]
The right to free speech and expression under Article 19(1)(a) was similarly interpreted by the Supreme Court in Shreya Singhal v Union of India. Section 66A of the IT Act, which was invalidated by the Supreme Court, placed excessive restrictions on free speech by restricting the publication of “offensive” content. Similar concerns have been raised in relation to the disclosure and traceability requirements imposed upon synthetic information contained in the October 2025 amendments to the IT Rules. Under Shreya Singhal , restrictions upon free speech must be narrowly tailored, and overly broad restrictions, as applied to Section 66A, are unconstitutional.[19]
The harms caused by deepfakes and synthetic media may intersect with the right to life and personal liberty under Article 21, and the fundamental right to privacy. As articulated by the Supreme Court in the ongoing litigation concerning the deepfake videos of Jaggi Vasudev, synthetic media may constitute an affront to a person’s dignity and reputation that falls within the realm of privacy. Similarly, the harms caused by algorithmically perpetuated discrimination may implicate the Right to Equality under Article 14. Given that both deepfakes and algorithmic discrimination inflict severe harms upon individuals, states must take active measures to prevent such harms, including the adoption of appropriate regulatory frameworks.[20]
VI. HYBRID REGULATORY APPROACH: A CASE FOR TECHNOLOGY-NEUTRAL OBLIGATIONS
The EU and United States possess well-developed legal frameworks for regulating AI systems, which serve as useful benchmarks for policymakers in other jurisdictions. The EU’s proposed AI Act, which has been adopted in 2024, employs a risk-based approach to AI regulation. Under the AI Act, AI systems are classified on the basis of their risk, with “high-risk” AI systems subject to stricter requirements, including extensive conformity assessment procedures. At the same time, the AI Act contains certain disclosure obligations for providers of “general-purpose” AI systems.[21]
The United States regulates AI through a sectoral approach that relies heavily on voluntary measures as well as sector-specific litigation and legislation. Notably, President Biden issued an Executive Order on AI in 2023 that mandated certain safety and disclosure requirements for AI developers. However, the US lacks comprehensive legislation governing the development and use of AI systems. The issues of copyright and authorship in relation to AI-generated works and training data have been addressed in court through First Amendment litigation concerning copyright’s fair use doctrine.[22]
India finds itself in between the EU and the US in terms of AI regulation. On the one hand, India’s existing measures, including the advisories issued by MeitY and recent amendments to the IT Act, bear resemblance to the US-first approach, in which regulation is driven by market forces and litigation. On the other hand, India does not possess the same legal and policy infrastructure as the US for addressing complex issues concerning AI regulation. Meanwhile, the EU’s risk-based approach offers several attractive policy considerations for India, including the flexibility to adopt different disclosure and regulatory requirements on the basis of the risks posed by different AI applications. However, the EU’s approach may prove too prescriptive for India’s emerging AI ecosystem, which consists of a large number of small and medium enterprises.[23]
VII. POLICY RECOMMENDATIONS
Based on the foregoing analysis, the following reform recommendations pertain to India’s regulation of generative AI:
- First, mandatory disclosure of synthetically generated information must be enshrined in law as a matter of priority. The October 2025 amendments to the IT Rules, which require disclosure of synthetic information in visual media and impose traceability obligations upon social media platforms, should be strengthened and expanded to all forms of AI-generated content. This disclosure requirement must be accompanied by grievance redressal mechanisms to ensure compliance.[24]
- Second, it is necessary to clarify the legal framework concerning the liability for the harms arising from generative AI. Such a framework should explicitly outline the responsibilities of developers, deployers, and users of AI systems, taking into account their role in the chain of causation and the control exerted by each actor over the AI system. By doing so, courts can avoid having to apply outdated or inconvenient tort doctrines to rapidly evolving technologies. Ideally, such a legal framework should have been formulated by the Indian Parliament through amendments to the IT Act. Alternatively, such a framework can be developed by the Supreme Court through judicial pronouncements, possibly in ANI Media Pvt Ltd v OpenAI Inc.[25]
- Third, it is necessary to amend the DPDP Act and its Rules in order to explicitly address the processing of personal data for AI training purposes. The application of the DPDP Act to personal data processed from publicly available sources requires clarification, with special consideration given to the collection of such data for training AI systems.[26]
- Fourth, it is necessary to adopt risk-based disclosure, audit, and transparency requirements for generative AI. This recommendation builds upon the findings of the previous sections, which highlight the necessity of ensuring accountability of AI developers and deployers. A risk-based approach would allow India to adopt disclosure and auditing requirements on the basis of the potential harms inflicted by specific AI applications, rather than adopting uniform requirements for all AI systems. The AI Act provides an attractive policy framework in this regard, although India must adapt it on the basis of its local policy and developmental needs.[27]
- Fifth and finally, it is necessary to establish accessible remedies for individuals and entities harmed by AI-generated harms, including but not limited to deepfakes, synthetic media, algorithmic discrimination, and liability issues. Ideally, such remedies should take the form of a dedicated grievance redressal mechanism administered by the Data Protection Board or another relevant authority, which would be significantly more efficient than lengthy court proceedings.[28]
VIII. CONCLUSION
Generative AI brings a challenge to India that cannot be solved by using current legal rules only. The technology touches areas like copyright, privacy, constitutional rights, liability for intermediaries, consumer protection and controlling harmful digital content. As the analysis shows Indias current legal system has some good bases for handling the risks from generative AI but it is still broken up and not fully ready for the special features of systems that can make their own content and synthetic content.[29]
The main problem for decision makers is to find the right balance between encouraging new ideas and setting rules. If the rules are too strict they might stop technology growth. Stop Indian companies and researchers from taking advantage of the chances that generative AI offers. At the time if there are no real rules people might face serious problems like privacy issues, copyright violations, fake videos, false information, unfair treatment and damage to reputation. The goal of the rules should not be to stop AI technology from developing but to make sure that its development and use follow values and legal responsibility.[30]
A mix of rules is the way for India. General laws that do not favor any technology can set standards about privacy, openness, responsibility and stopping harm while rules made for specific areas can handle the special dangers of different uses of generative AI. This way the law can stay flexible enough to deal with technology without losing the clarity needed by people, companies and those who enforce the laws.[31]
Building this kind of system must also match Indias promises in the constitution. The rights to privacy equal treatment, respect and free speech are important for checking if AI rules are legal. Any limits on how AI content’s made, used or shared must meet the constitutions rules about being legal, needed and fair.[32]
In the end regulating AI in India should be seen as something that keeps happening instead of one time job. Courts, the government, the people who make the rules the people who build technology and groups that work for the public will all help shape the rules to come. Indias goal should be to make a rule system that keeps people safe from the problems of generative AI while still letting new technology grow so that the economy and society can develop. A well thought out mix of rules with solutions and updated often as technology changes can give India a good way, between no rules and too many rules.[33]
IX. REFERENCES
[1]Ministry of Electronics and Information Technology, IndiaAI Mission (Government of India); Information Technology Act 2000; Digital Personal Data Protection Act 2023; Copyright Act 1957. For the broader regulatory framework governing AI in India, see also Ministry of Electronics and Information Technology, IndiaAI: The National Programme on Artificial Intelligence.
[2]Ian Goodfellow and others, ‘Generative Adversarial Nets’ in Zoubin Ghahramani and others (eds), Advances in Neural Information Processing Systems 27 (2014); Ian J Goodfellow, Yoshua Bengio and Aaron Courville, Deep Learning (MIT Press 2016).
[3]World Intellectual Property Organization, Generative Artificial Intelligence: Patent and Copyright (WIPO 2024); Copyright Act 1957; Digital Personal Data Protection Act 2023.
[4]Shreya Singhal v Union of India (2015) 5 SCC 1.
[5]Information Technology Act 2000, s 79; Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021. The October 2025 material concerned amendments relating to Synthetically Generated Information and was followed by the 10 February 2026 amendment to the IT Rules concerning Synthetically Generated Information. Ministry of Electronics and Information Technology, ‘Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021’ (updated 10 February 2026).
[6]Digital Personal Data Protection Act 2023, ss 4–8.
[7]Copyright Act 1957, ss 13 and 17.
[8]ANI Media Pvt Ltd v OpenAI Inc, CS(COMM) 1028/2024, Delhi High Court. The proceedings remained pending in the orders available in 2025, including the order dated 12 December 2025 listing the matter for further proceedings.
[9]Ministry of Electronics and Information Technology, ‘Advisory dated 26 December 2023’; Ministry of Electronics and Information Technology, ‘Advisory dated 1 March 2024’.
[10]Copyright Act 1957, s 14; Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market [2019] OJ L130/92, arts 3–4.
[11]Copyright Act 1957, ss 13, 17 and 52.
[12]Digital Personal Data Protection Act 2023, ss 4–8; Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
[13]Information Technology Act 2000, s 66; Consumer Protection Act 2019. The Consumer Protection Act 1986 referred to in the original text was repealed and replaced by the Consumer Protection Act 2019
[14]Sadhguru Jagadish Vasudev v Igor Isakov, CS(COMM) 578/2025, Delhi High Court, order dated 30 May 2025. The proceedings concerned alleged misuse of personality, publicity and related rights and included allegations concerning deepfake content; the Court issued directions concerning blocking and takedown of infringing material
[15]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended by the notification dated 10 February 2026 concerning Synthetically Generated Information. Ministry of Electronics and Information Technology, ‘Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021’.
[16]Constitution of India, arts 14, 15 and 16; National Legal Services Authority v Union of India (2014) 5 SCC 438; Navtej Singh Johar v Union of India (2018) 10 SCC 1.
[17]Frank Pasquale, The Black Box Society: The Secret Algorithms That Control Money and Information (Harvard University Press 2015).
[18]Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1; Justice K S Puttaswamy (Retd) v Union of India (2019) 1 SCC 1.
[19]Shreya Singhal v Union of India (2015) 5 SCC 1
[20]Constitution of India, arts 14 and 21; Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1; Subramanian Swamy v Union of India (2016) 7 SCC 221; Sadhguru Jagadish Vasudev v Igor Isakov, CS(COMM) 578/2025, Delhi High Court.
[21]Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence [2024] OJ L, 2024/1689.
[22]Executive Order 14110, ‘Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence’, 88 Fed Reg 75191 (2023); Thaler v Perlmutter, 687 F Supp 3d 140 (DDC 2023); Authors Guild v Google Inc, 804 F 3d 202 (2d Cir 2015).
[23]Regulation (EU) 2024/1689; NITI Aayog, National Strategy for Artificial Intelligence (2018).
[24]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended by the notification dated 10 February 2026 concerning Synthetically Generated Information.
[25]ANI Media Pvt Ltd v OpenAI Inc, CS(COMM) 1028/2024, Delhi High Court. The proceedings were continuing in the orders available in 2025, including the order dated 12 December 2025.
[26]Digital Personal Data Protection Act 2023.
[27]Regulation (EU) 2024/1689.
[28]Digital Personal Data Protection Act 2023, provisions concerning the Data Protection Board of India; Information Technology Act 2000; Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021.
[29]Information Technology Act 2000; Copyright Act 1957; Digital Personal Data Protection Act 2023; Constitution of India, arts 14, 19 and 21.
[30]Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1; Shreya Singhal v Union of India (2015) 5 SCC 1.
[31]Regulation (EU) 2024/1689; NITI Aayog, National Strategy for Artificial Intelligence (2018).
[32]Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1; Modern Dental College and Research Centre v State of Madhya Pradesh (2016) 7 SCC 353; Shreya Singhal v Union of India (2015) 5 SCC 1.
[33]Information Technology Act 2000; Digital Personal Data Protection Act 2023; Regulation (EU) 2024/1689.




