India has no standalone AI statute, so the binding duties come from existing law. Two hooks bite now: the IT (Intermediary Guidelines) Amendment Rules 2026 require labelling and provenance for synthetic media from 20 February 2026, and the CERT-In Directions 2022 require reporting cyber incidents within six hours. The Digital Personal Data Protection Act 2023 adds the heavier duties, but its substantive obligations are phased to 13 May 2027, and the SPDI Rules 2011 stay live until then.
All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.
Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. IT (Intermediary Guidelines) Amendment Rules 2026 - synthetic-media labelling, live 20 February 2026.
Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. CERT-In Directions 2022 - report incidents within 6 hours; 180-day India-resident logs.
Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). DPDP significant-data-fiduciary DPIA under section 10 - expected from 13 May 2027.
Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. DPDP data-governance duties expected once Phase-3 is in force.
AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. DPDP Rule 6 security plus SPDI Rules 2011 (live until DPDP Phase-3).
Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments. Vendor and foundation-model diligence expected under DPDP processor duties.
Keeping the logs, technical documentation and conformity evidence regulators expect. DPDP audit and record duties expected from 2027; CERT-In logging live now.
A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI governance prudent; the India AI Governance Guidelines are non-binding.
A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.
Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. No statutory automated-decision right in India.
Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.
An internal policy governing employees' use of generative AI: approved tools, data rules, output review. Staff generative-AI policy is prudent; no binding rule yet.
PrivMatrix separates what is live today - synthetic-media labelling and 6-hour CERT-In reporting - from the DPDP duties arriving in 2027, then generates the policies, notices and logs that close each gap.