India's AI Governance Guidelines and the DPDP Act: What the Seven Sutras Mean for Data Fiduciaries
India chose voluntary AI governance and binding data protection. The AI Governance Guidelines released at the AI Impact Summit 2026 set seven principles and three new institutions — but the enforceable obligations on AI systems still come from the DPDP Act. Here is how the two fit together, and what a data fiduciary should actually do.
Short answer: India's AI Governance Guidelines, released at the AI Impact Summit 2026, set out seven principles and create three new institutions, but rely on voluntary compliance, self-certification, and regulatory sandboxes rather than mandates. They are not enforceable law. The binding obligations on any AI system that processes personal data come from the DPDP Act 2023, which becomes fully enforceable on 13 May 2027.
India Picked a Different Model
The EU wrote a risk-tiered statute with prohibited practices and conformity assessments. India did not. The AI Governance Guidelines adopt what MeitY calls a techno-legal approach: principles, institutions, and technical tooling first; prescriptive obligations later, and only where existing law proves inadequate.
That choice is coherent, because India already has the instrument that matters most for AI harms involving individuals. Almost every consequential AI system processes personal data, and personal data processing is already governed by the DPDP Act with penalties up to ₹250 crore. Regulating AI-and-personal-data twice would have created conflicting duties.
| AI Governance Guidelines | DPDP Act 2023 + Rules 2025 | |
|---|---|---|
| Legal status | Guidance — voluntary, self-certification | Statute — binding, enforceable |
| Enforcement body | AI Governance Group (coordination) | Data Protection Board of India (adjudication) |
| Penalties | None directly | Up to ₹250 crore |
| Scope | All AI systems | Any processing of digital personal data, AI or not |
| Key date | Released 2026, iterative | Full enforceability 13 May 2027 |
Key insight: if your AI system touches personal data, the Guidelines describe how you should behave and the DPDP Act determines what you will be penalised for. Compliance planning should be anchored to the second while designing to the first.
The Seven Sutras
The Guidelines are anchored by seven governing principles. Read as engineering requirements rather than slogans, each maps onto something concrete a data fiduciary can build or document.
| Sutra | What it asks for | Nearest DPDP obligation |
|---|---|---|
| Trust | AI deployed in ways that maintain public confidence | Notice and transparency obligations |
| Human-centricity | Systems serve people, with humans in the loop on consequential decisions | Data Principal rights, grievance redressal |
| Fairness & equity | No discriminatory outcomes across groups | No direct analogue — this is genuinely new territory |
| Accountability | A named entity answerable for outcomes | Data Fiduciary accountability; DPO for SDFs |
| Understandable by design | Explainability appropriate to the stakes | Notice in clear and plain language |
| Safety & robustness | Systems resist failure and misuse | Reasonable security safeguards (₹250 crore exposure) |
| Inclusive & sustainable innovation | Benefits reach across languages, regions, and income levels | Notice availability in 22 Scheduled languages |
The one with no data-protection analogue — fairness and equity — is the one Indian companies have the least infrastructure for. Nothing in the DPDP Act requires you to test whether your credit model rejects applicants from one state at a higher rate. The Guidelines do ask.
Three New Institutions
- AI Governance Group — the coordinating body across ministries, intended to prevent each sectoral regulator inventing its own incompatible AI rules.
- Technology and Policy Expert Committee — technical advisory, tracking capability and risk as the field moves.
- AI Safety Institute — evaluation and standards work, aligned with the international network of AI safety institutes.
None of the three has adjudicatory power over a private company today. Their significance is directional: they are the machinery through which voluntary guidance becomes sectoral rules, and eventually statute, if self-governance underdelivers.
Where the Two Frameworks Actually Bite
Automated decision-making
The Guidelines want human oversight of consequential decisions. The DPDP Act does not contain a GDPR Article 22-style right against solely automated decisions — a notable gap. But it does give Data Principals the right to correction and to grievance redressal, which in practice means an AI-driven rejection must be contestable by a human who can look at and fix the underlying data.
Training data
The Guidelines say little that binds. The DPDP Act says a great deal: consent for the specific purpose, no legitimate-interests fallback, purpose limitation, and erasure on withdrawal. This is where most Indian AI programmes have real exposure — see our guide to AI training data under the DPDP Act.
Transparency
"Understandable by design" is a Guidelines principle. Under the Act, the enforceable version is the notice: users must be told, in clear and plain language, what personal data is collected and for what purpose. If an AI feature processes personal data in a way a user would not expect from your existing notice, the notice is wrong.
Deepfakes and synthetic content
Labelling of AI-generated content has been an active regulatory workstream in India separately from the Guidelines, driven by IT Rules amendments and intermediary obligations. Organisations generating synthetic media should track that thread independently — it is moving faster than the Guidelines and carries intermediary-liability consequences.
The Sectoral Regulators Will Move First
The most likely route from voluntary principle to binding obligation in India is not new AI legislation. It is your existing regulator issuing a circular.
This is how Indian regulation has historically worked in adjacent areas — outsourcing, cloud adoption, digital lending — and there is no reason AI will differ. A bank does not wait for an AI Act; it waits for the RBI. An insurer watches IRDAI. A broker watches SEBI. Healthcare providers watch the health ministry and NABH accreditation requirements.
| Sector | Likely AI-adjacent pressure | Practical effect |
|---|---|---|
| Banking & NBFC | Model governance, explainability for credit decisions, outsourcing rules for AI vendors | Documented model inventory and human review of adverse decisions |
| Insurance | Fairness in underwriting and claims automation | Disparity testing on rating and claims models |
| Capital markets | Algorithmic accountability, disclosure of AI-driven advice | Audit trails for automated recommendations |
| Healthcare | Clinical validation, patient consent for AI-assisted diagnosis | Consent granularity beyond DPDP baseline |
| Intermediaries & platforms | Synthetic-media labelling, traceability obligations under IT Rules | Provenance marking on generated content |
The AI Governance Group exists precisely to keep these from fragmenting into five incompatible regimes. For a regulated entity, the planning assumption should be: DPDP obligations are the floor, your sectoral regulator sets the ceiling, and the Guidelines describe the vocabulary both will use.
Synthetic Media and Labelling
One thread is moving faster than the Guidelines and deserves separate tracking. Obligations around AI-generated and synthetically altered content — labelling, provenance metadata, traceability, and takedown timelines — have been advanced through intermediary rules rather than through the AI framework.
That matters because the consequences are different in kind. Data protection failures produce Board proceedings and monetary penalties. Intermediary failures can affect safe-harbour protection, which for a platform is an existential rather than financial risk. If your product generates or hosts synthetic media, that workstream should not sit inside your DPDP programme — it needs its own owner.
What a Data Fiduciary Should Do Now
- Inventory your AI systems the way you inventory data systems. For each: what personal data goes in, what decision comes out, who is accountable, and what happens when it is wrong.
- Map each system to a lawful basis. If the answer is "we had the data already," that is not a basis. Fix it before May 2027.
- Add AI processing to your notice as a distinct purpose with its own toggle, rather than folding it into service improvement.
- Build a human-review path for any AI decision that materially affects a person — credit, employment, pricing, access. It satisfies the Guidelines and gives your grievance-redressal officer something to actually do.
- Run a fairness test at least once. Even a basic disparity check across the attributes you hold is more than most Indian deployments have done, and it produces the documentation self-certification will eventually ask for.
- Keep provenance records — dataset, consent purpose, notice version, date. This artefact answers both a Board query and a self-certification questionnaire.
Frequently Asked Questions
Are India's AI Governance Guidelines legally binding?
No. The Guidelines rely on voluntary compliance, self-certification, and regulatory sandboxes rather than mandates. They carry no penalties of their own. Binding obligations on AI systems that process personal data come from the DPDP Act 2023, enforceable from 13 May 2027.
What are the seven sutras of India's AI Governance Guidelines?
Trust, human-centricity, fairness and equity, accountability, understandable by design, safety and robustness, and inclusive and sustainable innovation. They function as design principles for AI systems rather than as enforceable duties.
Does India have an AI Act like the EU?
No. India deliberately chose a techno-legal, principles-first approach instead of a risk-tiered statute. The stated view is that existing laws — the DPDP Act foremost among them — already cover most AI harms involving individuals, and that prescriptive AI legislation can follow if gaps appear.
Do the Guidelines change my DPDP Act obligations?
No. They sit alongside the Act without altering it. Your DPDP obligations — itemised notice, valid consent, security safeguards, breach notification, Data Principal rights, retention limits — are unchanged whether or not AI is involved in the processing.
Does the DPDP Act give Indians a right to contest automated decisions?
Not explicitly. Unlike GDPR Article 22, the Act contains no standalone right against solely automated decision-making. The nearest levers are the rights to correction and to grievance redressal, which together mean an affected person can require a human to review and fix the data behind an automated outcome.
Is there an AI Safety Institute in India?
Yes — the Guidelines establish one, alongside an AI Governance Group for cross-ministry coordination and a Technology and Policy Expert Committee for technical advice. The AI Safety Institute's role is evaluation and standards work rather than enforcement, and it aligns India with the international network of comparable institutes. None of the three bodies currently exercises adjudicatory power over private companies.
Do the Guidelines require companies to disclose that content is AI-generated?
The Guidelines articulate transparency as a principle. The enforceable obligations around labelling AI-generated and synthetically altered content have advanced separately, through intermediary rules rather than the AI framework. Platforms that generate or host synthetic media should track that workstream independently, since the consequences there touch safe-harbour protection rather than data-protection penalties.
Which applies first if I am building an AI product in India today?
The DPDP Act, because it carries penalties and a fixed deadline of 13 May 2027. Design to the Guidelines' principles — they are a reasonable articulation of good practice and will shape future sectoral rules — but plan compliance work against the Act.
Where Consently Fits
Most of what both frameworks demand of an AI programme reduces to one capability: knowing, for any individual and any purpose, whether you were permitted to process their data — and being able to prove it. Consently provides itemised per-purpose consent with AI processing as its own toggle, notices in all 22 Scheduled languages, immutable zero-PII consent records tied to notice versions, Data Principal rights workflows including grievance redressal, and audit trails built for regulator queries rather than dashboards. Talk to us about your AI governance stack.