Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomeAI laws › DPDP Act 2023 + IT Rules + CERT-In
AI governance law · India

๐Ÿ‡ฎ๐Ÿ‡ณ DPDP Act 2023 + IT Rules + CERT-In

India has no standalone AI statute, so the binding duties come from existing law. Two hooks bite now: the IT (Intermediary Guidelines) Amendment Rules 2026 require labelling and provenance for synthetic media from 20 February 2026, and the CERT-In Directions 2022 require reporting cyber incidents within six hours. The Digital Personal Data Protection Act 2023 adds the heavier duties, but its substantive obligations are phased to 13 May 2027, and the SPDI Rules 2011 stay live until then.

Cited to primary sources
DPDP Act 2023 (phased) + IT Rules 2026
Governing framework
Data Protection Board of India; CERT-In; MeitY
Supervisory authority
2
Controls this market requires
7
Required or strongly expected
Good to know: the DPDP Act's substantive duties - impact assessments, audits and algorithmic due-diligence for significant data fiduciaries - are Phase-3 and expected from 13 May 2027, so they are not yet in force. The India AI Governance Guidelines (November 2025) are non-binding. Plan around the two duties that are genuinely live today: synthetic-media labelling and 6-hour incident reporting.
Status: provisional overview (v0.1), reviewed against primary sources dated 24 Aug 2026; not legal advice.

What India expects of you

All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.

Required mandated by binding law Expected near-mandatory / guidance-backed Prudent advisable Optional emerging n/a not applicable
AI TransparencyRequired

Transparency & disclosure

Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. IT (Intermediary Guidelines) Amendment Rules 2026 - synthetic-media labelling, live 20 February 2026.

Closes with: AI transparency + disclosure notices
AI IncidentRequired

AI incident response & serious-incident reporting

Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. CERT-In Directions 2022 - report incidents within 6 hours; 180-day India-resident logs.

Closes with: AI incident-response plan + reporting templates
AI RiskExpected

AI risk classification & impact assessment

Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). DPDP significant-data-fiduciary DPIA under section 10 - expected from 13 May 2027.

Closes with: AI risk classification + impact assessment (AIA/FRIA)
AI DataExpected

Data governance for AI

Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. DPDP data-governance duties expected once Phase-3 is in force.

Closes with: AI data-governance standard
AI SecurityExpected

Security of AI systems

AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. DPDP Rule 6 security plus SPDI Rules 2011 (live until DPDP Phase-3).

Closes with: AI security controls statement
AI Supply ChainExpected

Third-party / vendor AI & foundation models

Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments. Vendor and foundation-model diligence expected under DPDP processor duties.

Closes with: Vendor AI due-diligence + model cards
AI AssuranceExpected

Record-keeping, logging & conformity

Keeping the logs, technical documentation and conformity evidence regulators expect. DPDP audit and record duties expected from 2027; CERT-In logging live now.

Closes with: AI logging + technical-documentation pack
AI GovernancePrudent

AI governance ownership & policy

A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI governance prudent; the India AI Governance Guidelines are non-binding.

Closes with: AI policy + governance charter
AI InventoryPrudent

AI system inventory / register

A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.

Closes with: AI system register
AI OversightPrudent

Human oversight & automated decisions

Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. No statutory automated-decision right in India.

Closes with: Human-oversight + automated-decision safeguards note
AI AssurancePrudent

Accuracy, robustness & drift monitoring

Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.

Closes with: Model monitoring + drift-review plan
AI UsePrudent

Acceptable use of AI by staff

An internal policy governing employees' use of generative AI: approved tools, data rules, output review. Staff generative-AI policy is prudent; no binding rule yet.

Closes with: Acceptable-use policy for generative AI

Get India-ready for the duties that bite now

PrivMatrix separates what is live today - synthetic-media labelling and 6-hour CERT-In reporting - from the DPDP duties arriving in 2027, then generates the policies, notices and logs that close each gap.

Other markets

See all AI laws →
๐Ÿ‡ช๐Ÿ‡บ EU๐Ÿ‡ฌ๐Ÿ‡ง UK๐Ÿ‡ฆ๐Ÿ‡ช UAE๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia๐Ÿ‡ถ๐Ÿ‡ฆ Qatar