Adv. (Dr.) Prashant Mali advises on Artificial Intelligence (AI) law in India - AI governance, liability, deepfakes, AI-contract vetting, and compliance with the DPDP Act 2023 and the IT Rules - and is the author of book "Seven AI Laws: The Future of Mankind."
Artificial Intelligence has moved faster than any law made to govern it. Businesses are deploying AI for hiring, lending, medical triage, content generation and customer service - and discovering that when an algorithm makes a decision, the legal questions of liability, bias, privacy and intellectual property do not disappear; they multiply. This page explains the current state of AI law in India (2026), the legal risks organisations face, and how they can be managed. It is information, not legal advice.
India, as of 2026, has no single, dedicated AI statute. Instead, AI is governed by a patchwork of existing laws and evolving guidance:
The Information Technology Act, 2000 and the IT Rules - including amendments addressing synthetically generated information (deepfakes) and platform due-diligence obligations.
The Digital Personal Data Protection Act, 2023 (DPDPA) and DPDP Rules 2025 - which govern the personal data that trains and feeds AI systems.
The Bharatiya Nyaya Sanhita, 2023 (BNS) - for AI-enabled fraud, impersonation and obscenity.
MeitY advisories and the emerging India AI governance framework, promoting a risk-based, "safe and trusted AI" approach rather than a prescriptive one.
The EU AI Act, which - like the GDPR before it - has extra-territorial reach and already affects Indian companies serving EU users or building AI for EU deployment.
The result is a genuine governance gap: as the Supreme Court itself observed in Pune Bar Association v. Union of India (2026), "challenges to admissibility and probative value of electronic records are further accentuated with the advent of artificial intelligence and deepfake technology." Until dedicated legislation arrives, AI risk is managed by mapping existing laws onto new technology - which is precisely where specialist advice earns its keep.
If an AI system denies a loan wrongly, misdiagnoses, defames, or causes a driverless mishap, who is liable - the developer, the deployer, the data provider, or the user? Indian law currently answers through negligence, product liability (Consumer Protection Act, 2019), contract and vicarious liability principles. Allocating that risk in advance, through contracts and governance, is the single most important protective step.
AI-generated deepfakes and voice clones have triggered a wave of litigation. Through 2025–26 the Delhi and Bombay High Courts granted injunctions protecting the personality rights of public figures against unauthorised AI reproductions, anchoring the right in Article 21 of the Constitution. Deepfakes also raise criminal exposure under the BNS and IT Act, and thorny evidentiary questions under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023. See the Electronic Evidence blog
Can AI-generated content be copyrighted, and who owns it? Can models be lawfully trained on copyrighted data? These questions are unsettled in India and worldwide, and they matter for any business generating text, images, code or music with AI.
AI runs on personal data, so the DPDPA applies directly - consent, purpose limitation and data-principal rights all bite on training and inference. Automated decision-making also raises discrimination and fairness risks that can attract regulatory and reputational consequences.
AI vendor agreements routinely bury risk in the fine print - IP ownership, indemnities, data usage, model updates, hallucination disclaimers and liability caps. Vetting these before signing prevents expensive surprises.
AI governance frameworks for boards and management - policies, risk registers, and accountability structures.
AI contract drafting and vetting - development, deployment, SaaS and data-licensing agreements.
Deepfake and personality-rights protection - injunctions, takedowns, writs and criminal complaints.
DPDPA-for-AI compliance - lawful training data, consent, and DPIAs for AI systems.
AI liability and dispute strategy - risk allocation and representation.
EU AI Act readiness for Indian companies with EU exposure.
Training and advisory for corporates, regulators and law-enforcement on AI and the law.
There is no AI-specific liability statute yet, so liability is determined under existing negligence, product-liability, contract and consumer-protection law - usually falling on the deployer and/or developer depending on the facts and the contract. Clear contractual risk-allocation is the best protection. as per The IT Rules 2026 an intermediary not following the rules related to synthetic information labelling looses the safe harbour status and may be booked under laws of india
Creating or sharing malicious deepfakes can attract civil liability (personality/privacy rights) and criminal liability under the BNS and IT Act, and Indian courts have actively granted injunctions against unauthorised AI likenesses. The law targets the harm and deception, not the technology itself.
If you build, deploy, resell or heavily rely on AI - especially in hiring, lending, healthcare, content or customer data - then yes. The risks (liability, IP, data, bias, contracts) are real and largely preventable with the right governance and agreements.
It can. Like the GDPR, the EU AI Act reaches beyond Europe to cover AI systems whose output is used in the EU. Indian firms serving EU clients should assess their obligations early.
Adv. (Dr.) Prashant Mali writes and speaks widely on the law and philosophy of Artificial Intelligence.
In Seven AI Laws: The Future of Mankind, Dr. Prashant Mali distils the governance of Artificial Intelligence into seven foundational laws that policymakers, technologists, lawyers and citizens need in order to navigate an AI-driven world safely and ethically. Blending law, philosophy and real-world case studies, the book asks the questions defining our era: how should AI be regulated, who is liable when AI causes harm, and how do we protect human rights, privacy and dignity from autonomous systems and deepfakes. See all books by Prashant Mali
In his research paper "Right to Think," Dr. Prashant Mali argues for the recognition of cognitive liberty - the freedom of thought and mental self-determination - as a fundamental right in the age of AI, recommendation engines and neurotechnology. As algorithms increasingly shape what we see, believe and decide, the paper contends that the right to think, free from manipulation and surveillance of the mind, is the next frontier of privacy and human autonomy under Article 21. Read the research papers of Prashant Mali
For AI governance, contracts, deepfake protection or compliance, contact Adv. (Dr.) Prashant Mali consultations available online and in person at the Andheri and Bandra (Mumbai) offices, for clients across India and internationally.
Disclaimer: This page is for general information only and does not constitute legal advice or solicitation, nor does it create a lawyer–client relationship. AI law is evolving rapidly; provisions are summarised and may change. Please consult a qualified advocate about your specific situation. Last updated: July 2026.