The Ministry of Electronics and Information Technology released the India
AI Governance Guidelines on 5 November 2025, stating that there is no need
for a dedicated AI law in India as the existing laws address the risks of AI.
Five months later, the Delhi High Court reserved
judgment on the interim relief sought by Asian News International in its
copyright suit against OpenAI India’s first lawsuit testing whether training a
large language model on copyrighted news content without a licence is lawful.
The two events are not independent of each other, but are the same regulatory
experiment, just in two different rooms. India has taken a chance on a
‘techno-legal’ approach to accommodate the disruptive potential of foundation
models without a dedicated law. That bet is now getting tested in real time and
so far, the results where the patchwork has blind spots are exactly where AI
development is taking place, namely, in the data that nobody scraped with model
training in mind.
A clash between old
law and new machines in India.
Like all architectures, India’s privacy architecture starts with the
Supreme Court, in Justice K.S.
Puttaswamy (Retd.) v Union of India., which first recognized informational
privacy as a fundamental right to life and personal liberty. That judgment
provided the constitutional basis for the Digital Personal Data Protection Act,
2023, which was enacted by Parliament in August 2023, but has only been slowly
activated since the notification of the DPDP Rules, 2025,
on 13 November 2025, with compliance only coming into effect from 13 May 2027,
which covers approximately 800 million Indians online for the first time.
Concurrently, MeitY released the AI Governance Guidelines, based on seven
principles it calls “sutras” such as “Trust is the Foundation” and
“Innovation over Restraint”, to establish two new coordinating bodies, the AI
Governance Group and the Technology and Policy Expert Committee, as well as a
proposed India AI Safety Institute and the Bureau of Indian Standards’ adoption
of ISO/IEC 42001. MeitY had already taken a much firmer stance earlier in
October 2025, amending the IT Rules, 2021, which for the first time in Indian
legislation, explains what constitutes “synthetically generated
information” and mandates that
content platforms clearly label AI-generated material. It is a lesson that it’s
illuminating. India, which saw a tangible and immediate prejudice in the form
of fraud and impersonation through the use of deepfakes has acted selectively
and swiftly, laying down a clear and concise framework of labelling
requirements and a conditional safe harbour. Where the harm is diffuse, and “in
the day-to-day business of building AI products,” it has decided to depend on
non-binding guidelines and on courts to fill the gaps. The initial, high-stakes
battle is between ANI and OpenAI.
Consent Fiction at the
Heart of the DPDP Act
The DPDP Act was written for a relatively straightforward ‘transactional
model’ in which the data fiduciary gathers the data of a data principal for a
specific purpose, requests consent, and responds to the one data principal. The
Generative AI model is different. A foundation model is created using billions
of data points that are scraped randomly from the open web, with the majority
of them having no direct connection with any data fiduciary. The drafters of
the Act knew what they were doing and in the Section 3(c)(ii) it excludes
personal data that has been intentionally made public by a data principal, or
provided on condition of law. In theory, this appears to be a convenient
exception for training AI on open-web data. As a matter of fact, no one can
agree on what it actually encompasses. Is a public post that’s made for friends
and not crawlers “voluntarily made public” for the purpose of training a
commercial chatbot? The Internet
and Mobile Association of India has formally asked MeitY to broaden Section
3(c) (ii) or extend the five-year exemption period provided in Section 17(5) of
the current law itself to clarify that there is no real clarity in the law for
the industry at present. Legal
scholars have reached the opposite conclusion and contended that Section
3(c)(ii) is a fact-specific, narrow exception that does not afford a blanket
license for industrial-scale AI training and that the conditional research
exemption under Section 17(2)(b) was never intended to replace the exception.
There is a second fault line in the right to erasure. The Act implies that data
should be deleted if a data principal withdraws consent, yet a trained model
does not store up records (of any kind) for deletion the information is spread
throughout billions of parameters; “machine
unlearning” without retraining is, at best, a research question not a
compliance solution. What this means is that the final law will grant rights
that it currently lacks any good way to enforce after personal data is in a
model’s weights.
The current state of soft guidelines
and hard litigation.
The AI
Governance Guidelines tell developers that existing law is sufficient for now.
That claim hits a court record in ANI vs. OpenAI. ANI, India’s largest news
agency, filed
suit in November 2024, alleging that OpenAI scraped and reproduced its
copyrighted reporting to train and operate ChatGPT without a licence, and
sought both an injunction and roughly ₹2 crore in damages. OpenAI has also said
that the
Delhi High Court lacks jurisdiction over a company that has no servers in
India and, separately, copyright
protects only the expression in a news report rather than the underlying
facts which have an undeniable public interest for free circulation. Indian
digital newsrooms have spoken out against this, and in a letter to INW to the
Digital News Publishers Association, they stated that unlicensed training is
damaging the commercial motivation to create original journalism of all. The
Court reserved its order after proceeding through more than a year of
hearings and submissions from multiple intervenors, court-appointed amici
curiae, and more than a year of additional submissions. Structural issues
contribute to part of the challenge. The Delhi High Court, in Super Cassettes Industries v
Chintamani Rao, clarified that the concept of ‘fair dealing’ under section
52 of the Copyright Act, 1957 is exhaustive and cannot be extended to newer
technologies. This leaves a true void, and India lacks a statutory exception
for text-and-data-mining that would allow courts or regulators to determine the
distinction between research use of data and commercial use. The Commerce
Ministry has admitted the need to understand this gap, and it has convened
an expert panel under the DPIIT, which, again, reports after the event,
rather than before the battle of litigation that is already taking place on the
ground in the AI age. It is an unusual precedent for national policy to be
based on a single commercial lawsuit, particularly when the precedents that
would be formed by that decision would apply to all subsequent cases in the
future, whether or not the trade-offs were discussed in Parliament.
Learning from Abroad
India’s move to
adapt existing law as opposed to making new laws is not uncommon, as the AI
Governance Guidelines themselves reference this as being closer towards Japan
and the United States than the European Union. The more meaningful comparison,
however, is to the EU, where the copyright/privacy/AI training conundrum was
the same, but was instead solved through legislation, not courts. The EU
Copyright Directive of 2019 introduced a structured exception for
text-and-data-mining, which includes a machine-readable opt-out, allowing
rights-holders to reserve their works from being used for AI training without
having to take any actions after events. EU
AI Act then went further: From August 2025, it makes it a requirement for
providers of general-purpose AI models to adopt a policy to comply with that
opt-out regime and publish a reasonably detailed public summary of what it was
trained on, with a possible fine of up to 3 percent of global turnover for
non-compliance. Singapore provides a third model to consider that is less
onerous. Its data regulator has provided advisory
guidance clarifying, not a binding law, that allows organisations to use
the existing “legitimate interests” and research exceptions in the
Personal Data Protection Act to train their AI systems in providing
interpretive certainty, instead of waiting for case law to come in. So far,
India has adopted and adapted the institutional ambition of the EU; its
proposed AI Governance Group mirrors the EU’s AI Office but without the EU’s
accompanying statutory clarity on training data, and the soft-law instinct of
Singapore, with its comparatively rapid issuance of binding interpretive
guidance on the specific question of AI training. This is awkwardly sandwiched
between two more coherent approaches.
A Plan to Reform the Next 18 Months
As the compliance
deadline for the DPDP Act nears the approval date, four changes would help
narrow the gap without replacing the reliance on existing laws. Firstly, the
exemption under Section 3(c)(ii) should be restricted to content that is
accessible to the user in the context of the platform and its privacy settings
and not simply when it is technically possible for it to be used commercially,
as MeitY is doing currently. Secondly, Parliament should adopt a narrow and
opt-out approach to text-and-data-mining in the EU’s 2019 framework in the
Copyright Act, which allows publishers and creators to prevent their works from
being used for training without relying on litigation once they have been
ingested. Third, the AI Governance Guidelines must be anchored in a law. The AI
Governance Group and the Technology and Policy Expert Committee are only now
being proposed in policy, and have no rule-making authority nor requirement of
developers to interact with them; they should be set up by notification and given
similar enforcement powers to the Data Protection Board under the DPDP Act.
Fourth, India should mandate the disclosure of a summary of a training data
set’s categories and sources by providers of large foundation models when these
are used by Indian consumers, including the sectoral regulators already
identified in the AI Guidelines by the RBI, SEBI, TRAI, and the CCI, without
creating a new enforcement bureaucracy. None of these reforms involve setting
aside the philosophy of existing law, which MeitY has decided to embrace; it is
just the same philosophy with a new twist, in this case if it’s deepfakes
instead of training data, rather than the other way round.
Conclusion
The Delhi High
Court decision in ANI v OpenAI will decide one commercial dispute, not the
policy debate on the meaning of India’s consent-based privacy law and
exhaustive copyright exceptions to industrial scale training. That is a
legis-latice decision and not a decision any one litigant is in a position to
make on the people’s behalf. It was appropriate that India rejected the concept
of a hasty blanket law on AI, as rapid advancements in technology demand
flexibility over strict risk categorizations. However, adaptability is not
ambiguity, and the current ambiguity in the DPDP Act around training data, the
closed list of exceptions in the Copyright Act, and a set of guidelines are not
binding on AI are not adaptability. If a nation wishes to become a world leader
in AI and a legitimate force to protect digital rights, it can’t continue to
leave that decision up to the first lawsuit that gets to court.
Subscribe now to keep reading and get access to the full archive.
