Skip to main content
Industry Insights
AI Governance
MeitY
DPDPA
AI Regulation
India
Compliance Strategy

India's AI Governance Guidelines and the DPDP Act: What the Seven Sutras Mean for Data Fiduciaries

India chose voluntary AI governance and binding data protection. The AI Governance Guidelines released at the AI Impact Summit 2026 set seven principles and three new institutions — but the enforceable obligations on AI systems still come from the DPDP Act. Here is how the two fit together, and what a data fiduciary should actually do.

Consently Team
30 June 2026
9 min read

Short answer: India's AI Governance Guidelines, released at the AI Impact Summit 2026, set out seven principles and create three new institutions, but rely on voluntary compliance, self-certification, and regulatory sandboxes rather than mandates. They are not enforceable law. The binding obligations on any AI system that processes personal data come from the DPDP Act 2023, which becomes fully enforceable on 13 May 2027.

India Picked a Different Model

The EU wrote a risk-tiered statute with prohibited practices and conformity assessments. India did not. The AI Governance Guidelines adopt what MeitY calls a techno-legal approach: principles, institutions, and technical tooling first; prescriptive obligations later, and only where existing law proves inadequate.

That choice is coherent, because India already has the instrument that matters most for AI harms involving individuals. Almost every consequential AI system processes personal data, and personal data processing is already governed by the DPDP Act with penalties up to ₹250 crore. Regulating AI-and-personal-data twice would have created conflicting duties.

AI Governance GuidelinesDPDP Act 2023 + Rules 2025
Legal statusGuidance — voluntary, self-certificationStatute — binding, enforceable
Enforcement bodyAI Governance Group (coordination)Data Protection Board of India (adjudication)
PenaltiesNone directlyUp to ₹250 crore
ScopeAll AI systemsAny processing of digital personal data, AI or not
Key dateReleased 2026, iterativeFull enforceability 13 May 2027

Key insight: if your AI system touches personal data, the Guidelines describe how you should behave and the DPDP Act determines what you will be penalised for. Compliance planning should be anchored to the second while designing to the first.

The Seven Sutras

The Guidelines are anchored by seven governing principles. Read as engineering requirements rather than slogans, each maps onto something concrete a data fiduciary can build or document.

SutraWhat it asks forNearest DPDP obligation
TrustAI deployed in ways that maintain public confidenceNotice and transparency obligations
Human-centricitySystems serve people, with humans in the loop on consequential decisionsData Principal rights, grievance redressal
Fairness & equityNo discriminatory outcomes across groupsNo direct analogue — this is genuinely new territory
AccountabilityA named entity answerable for outcomesData Fiduciary accountability; DPO for SDFs
Understandable by designExplainability appropriate to the stakesNotice in clear and plain language
Safety & robustnessSystems resist failure and misuseReasonable security safeguards (₹250 crore exposure)
Inclusive & sustainable innovationBenefits reach across languages, regions, and income levelsNotice availability in 22 Scheduled languages

The one with no data-protection analogue — fairness and equity — is the one Indian companies have the least infrastructure for. Nothing in the DPDP Act requires you to test whether your credit model rejects applicants from one state at a higher rate. The Guidelines do ask.

Three New Institutions

  • AI Governance Group — the coordinating body across ministries, intended to prevent each sectoral regulator inventing its own incompatible AI rules.
  • Technology and Policy Expert Committee — technical advisory, tracking capability and risk as the field moves.
  • AI Safety Institute — evaluation and standards work, aligned with the international network of AI safety institutes.

None of the three has adjudicatory power over a private company today. Their significance is directional: they are the machinery through which voluntary guidance becomes sectoral rules, and eventually statute, if self-governance underdelivers.

Where the Two Frameworks Actually Bite

Automated decision-making

The Guidelines want human oversight of consequential decisions. The DPDP Act does not contain a GDPR Article 22-style right against solely automated decisions — a notable gap. But it does give Data Principals the right to correction and to grievance redressal, which in practice means an AI-driven rejection must be contestable by a human who can look at and fix the underlying data.

Training data

The Guidelines say little that binds. The DPDP Act says a great deal: consent for the specific purpose, no legitimate-interests fallback, purpose limitation, and erasure on withdrawal. This is where most Indian AI programmes have real exposure — see our guide to AI training data under the DPDP Act.

Transparency

"Understandable by design" is a Guidelines principle. Under the Act, the enforceable version is the notice: users must be told, in clear and plain language, what personal data is collected and for what purpose. If an AI feature processes personal data in a way a user would not expect from your existing notice, the notice is wrong.

Deepfakes and synthetic content

Labelling of AI-generated content has been an active regulatory workstream in India separately from the Guidelines, driven by IT Rules amendments and intermediary obligations. Organisations generating synthetic media should track that thread independently — it is moving faster than the Guidelines and carries intermediary-liability consequences.

The Sectoral Regulators Will Move First

The most likely route from voluntary principle to binding obligation in India is not new AI legislation. It is your existing regulator issuing a circular.

This is how Indian regulation has historically worked in adjacent areas — outsourcing, cloud adoption, digital lending — and there is no reason AI will differ. A bank does not wait for an AI Act; it waits for the RBI. An insurer watches IRDAI. A broker watches SEBI. Healthcare providers watch the health ministry and NABH accreditation requirements.

SectorLikely AI-adjacent pressurePractical effect
Banking & NBFCModel governance, explainability for credit decisions, outsourcing rules for AI vendorsDocumented model inventory and human review of adverse decisions
InsuranceFairness in underwriting and claims automationDisparity testing on rating and claims models
Capital marketsAlgorithmic accountability, disclosure of AI-driven adviceAudit trails for automated recommendations
HealthcareClinical validation, patient consent for AI-assisted diagnosisConsent granularity beyond DPDP baseline
Intermediaries & platformsSynthetic-media labelling, traceability obligations under IT RulesProvenance marking on generated content

The AI Governance Group exists precisely to keep these from fragmenting into five incompatible regimes. For a regulated entity, the planning assumption should be: DPDP obligations are the floor, your sectoral regulator sets the ceiling, and the Guidelines describe the vocabulary both will use.

Synthetic Media and Labelling

One thread is moving faster than the Guidelines and deserves separate tracking. Obligations around AI-generated and synthetically altered content — labelling, provenance metadata, traceability, and takedown timelines — have been advanced through intermediary rules rather than through the AI framework.

That matters because the consequences are different in kind. Data protection failures produce Board proceedings and monetary penalties. Intermediary failures can affect safe-harbour protection, which for a platform is an existential rather than financial risk. If your product generates or hosts synthetic media, that workstream should not sit inside your DPDP programme — it needs its own owner.

What a Data Fiduciary Should Do Now

  1. Inventory your AI systems the way you inventory data systems. For each: what personal data goes in, what decision comes out, who is accountable, and what happens when it is wrong.
  2. Map each system to a lawful basis. If the answer is "we had the data already," that is not a basis. Fix it before May 2027.
  3. Add AI processing to your notice as a distinct purpose with its own toggle, rather than folding it into service improvement.
  4. Build a human-review path for any AI decision that materially affects a person — credit, employment, pricing, access. It satisfies the Guidelines and gives your grievance-redressal officer something to actually do.
  5. Run a fairness test at least once. Even a basic disparity check across the attributes you hold is more than most Indian deployments have done, and it produces the documentation self-certification will eventually ask for.
  6. Keep provenance records — dataset, consent purpose, notice version, date. This artefact answers both a Board query and a self-certification questionnaire.

Frequently Asked Questions

Are India's AI Governance Guidelines legally binding?

No. The Guidelines rely on voluntary compliance, self-certification, and regulatory sandboxes rather than mandates. They carry no penalties of their own. Binding obligations on AI systems that process personal data come from the DPDP Act 2023, enforceable from 13 May 2027.

What are the seven sutras of India's AI Governance Guidelines?

Trust, human-centricity, fairness and equity, accountability, understandable by design, safety and robustness, and inclusive and sustainable innovation. They function as design principles for AI systems rather than as enforceable duties.

Does India have an AI Act like the EU?

No. India deliberately chose a techno-legal, principles-first approach instead of a risk-tiered statute. The stated view is that existing laws — the DPDP Act foremost among them — already cover most AI harms involving individuals, and that prescriptive AI legislation can follow if gaps appear.

Do the Guidelines change my DPDP Act obligations?

No. They sit alongside the Act without altering it. Your DPDP obligations — itemised notice, valid consent, security safeguards, breach notification, Data Principal rights, retention limits — are unchanged whether or not AI is involved in the processing.

Does the DPDP Act give Indians a right to contest automated decisions?

Not explicitly. Unlike GDPR Article 22, the Act contains no standalone right against solely automated decision-making. The nearest levers are the rights to correction and to grievance redressal, which together mean an affected person can require a human to review and fix the data behind an automated outcome.

Is there an AI Safety Institute in India?

Yes — the Guidelines establish one, alongside an AI Governance Group for cross-ministry coordination and a Technology and Policy Expert Committee for technical advice. The AI Safety Institute's role is evaluation and standards work rather than enforcement, and it aligns India with the international network of comparable institutes. None of the three bodies currently exercises adjudicatory power over private companies.

Do the Guidelines require companies to disclose that content is AI-generated?

The Guidelines articulate transparency as a principle. The enforceable obligations around labelling AI-generated and synthetically altered content have advanced separately, through intermediary rules rather than the AI framework. Platforms that generate or host synthetic media should track that workstream independently, since the consequences there touch safe-harbour protection rather than data-protection penalties.

Which applies first if I am building an AI product in India today?

The DPDP Act, because it carries penalties and a fixed deadline of 13 May 2027. Design to the Guidelines' principles — they are a reasonable articulation of good practice and will shape future sectoral rules — but plan compliance work against the Act.

Where Consently Fits

Most of what both frameworks demand of an AI programme reduces to one capability: knowing, for any individual and any purpose, whether you were permitted to process their data — and being able to prove it. Consently provides itemised per-purpose consent with AI processing as its own toggle, notices in all 22 Scheduled languages, immutable zero-PII consent records tied to notice versions, Data Principal rights workflows including grievance redressal, and audit trails built for regulator queries rather than dashboards. Talk to us about your AI governance stack.

Share this article

Related Articles

Industry Insights

DPDPA 360°: Why DPDPA Compliance Fails When Legal, Technology, and Advisory Work in Silos

Most Indian organisations are buying DPDPA compliance in pieces — a law firm for the opinion, a vendor for the banner, a consultant for the gap report. The pieces don't talk to each other, and the gaps between them are exactly where penalties live. Here's the case for an integrated approach — and a live webinar where we demonstrate it.

5 Jun 20267 min
Industry Insights

Get Started with Consently: 1 Month Free Trial - No Credit Card Required

Start your DPDPA 2023 compliance journey with Consently's exclusive 1 month free trial. No credit card required. Get full access to all features including automated cookie scanning, consent management, and compliance reporting.

14 Nov 20258 min