India · AI governance

India AI Governance Guidelines
and the deepfake rules that do bind.

MeitY's November 2025 guidelines chose principles over a new law. The IT Rules amendment of February 2026 is binding. For companies selling into Europe, the EU AI Act is the third piece. What each asks, and how to meet all three with one programme.

Guidelines of 5 Nov 2025Seven sutrasIT Rules SGI, 20 Feb 2026EU AI Act Art. 50

Last updated Published by TryTrustableNot legal advice

01

What are the India AI Governance Guidelines?

The India AI Governance Guidelines are MeitY's framework for governing artificial intelligence, released on 5 November 2025 under the IndiaAI Mission. They set seven principles, recommendations across six pillars, an action plan and practical guidance, and deliberately stop short of proposing a new AI law.

The guidelines were drafted by a committee MeitY constituted in July 2025, chaired by Professor Balaraman Ravindran of IIT Madras, building on a 2025 draft from an earlier sub-committee that drew more than 2,500 public submissions. They come in four parts: key principles, key recommendations, an action plan, and practical guidelines for industry and regulators.

The seven principles, which the guidelines call sutras, were adapted from the Reserve Bank's FREE-AI committee report of August 2025: trust is the foundation; people first; innovation over restraint; fairness and equity; accountability; understandable by design; and safety, resilience and sustainability.

02

What do the guidelines recommend?

Recommendations are grouped into six pillars: infrastructure, capacity building, policy and regulation, risk mitigation, accountability and institutions. The ones with the most consequence for companies are a graded liability system, an India-specific risk framework, voluntary commitments backed by techno-legal measures, and new coordinating institutions.

PillarWhat it recommends
InfrastructureWider access to data and compute, and use of digital public infrastructure for AI adoption.
Capacity buildingEducation, skilling and awareness about AI's risks and uses.
Policy & regulationReview existing laws, find gaps, and fix them with targeted amendments rather than a new statute. Copyright and the classification of digital platforms are named.
Risk mitigationAn India-specific risk assessment framework based on evidence of real harm; voluntary measures supported by techno-legal tools; extra obligations for sensitive uses and vulnerable groups.
AccountabilityGraded liability by function, risk and whether due diligence was observed; transparency reports; grievance redressal proportionate to risk.
InstitutionsAn AI Governance Group supported by a Technology & Policy Expert Committee, a resourced AI Safety Institute, and sector regulators keeping their enforcement powers.

Summarised from Part 2 of the guidelines. The action plan also proposes a national AI incidents database and regulatory sandboxes over the medium term.

On law, the text is explicit: existing laws on information technology, data protection, consumer protection and the civil and criminal codes can govern AI applications, so a separate law to regulate AI is not needed given the current assessment of risk. The long-term action plan keeps open the option of drafting new laws as risks and capabilities change.

03

What do the IT Rules require for synthetically generated content?

Since 20 February 2026, intermediaries that enable synthetic audio, images or video must label it prominently, embed permanent metadata or other provenance where technically feasible, and stop the label being removed. Significant social media intermediaries must also collect a user declaration and verify it before publication. Unlawful content must come down within three hours of an order.

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 were notified as G.S.R. 120(E) dated 10 February 2026. They add three things to the 2021 IT Rules:

  • A definition. Rule 2(1)(wa): audio, visual or audio-visual information artificially or algorithmically created or altered so that it appears real and depicts a person or event in a way likely to be perceived as indistinguishable from reality. Routine or good-faith editing, document and presentation preparation, and accessibility, translation or search tools that do not alter the substance are excluded
  • Labelling and provenance. Synthetic content an intermediary's tools create must carry a prominent visual label, or a prefixed audio disclosure, and permanent metadata or a unique identifier tracing the computer resource used, which the intermediary must not let anyone strip. Some synthetic content, such as non-consensual intimate imagery or false documents, is prohibited outright
  • Verification by large platforms. Under rule 4(1A), a significant social media intermediary must require users to declare whether content is synthetic, deploy technical measures to verify the declaration, and label what is confirmed. Knowingly failing to act is a failure of due diligence, which puts safe harbour at risk

On 30 March 2026 MeitY published a draft Second Amendment that would require labels to stay visible for the whole duration of the content, and make compliance with MeitY's written advisories and SOPs part of an intermediary's due diligence. It was a draft for consultation when we last checked; confirm whether it has been notified before relying on either version.

04

Does the DPDP Act apply to AI training and inference?

Yes, wherever digital personal data is processed. Training on personal data, fine-tuning on customer records, and inference that produces decisions about people are all processing under the Act. The AI guidelines flag open questions but create no exemption.

The guidelines themselves list the questions: how far the Act's exemption for publicly available personal data reaches for model training, whether purpose limitation fits how modern AI systems work, and the role of consent managers in AI workflows. Until the Board or MeitY answers them, the safe assumption is the ordinary one: a purpose stated in a notice, consent or a section 7 legitimate use for each purpose, and erasure when the purpose ends. The DPDP guide covers the timetable, with substantive duties from 13 May 2027.

05

How does India's approach compare with the EU AI Act?

India regulates AI through existing laws, principles and a targeted rule on synthetic content. The EU AI Act is a horizontal statute that classifies AI systems by risk and attaches legal duties and fines to each tier. An Indian company that sells into Europe has to meet the EU rules regardless of the Indian position.

IndiaEU AI Act
Legal formGuidelines (not binding), plus the IT Rules amendment on synthetic content (binding on intermediaries)Regulation (EU) 2024/1689, directly binding, as amended by the Digital Omnibus
ApproachPrinciples, voluntary commitments, sector regulators, graded liabilityRisk tiers: prohibited, high-risk, transparency duties, minimal risk; separate rules for general-purpose models
Who carries the dutyFor synthetic content, intermediaries; otherwise whoever an existing law bindsProviders and deployers of AI systems, importers and distributors, GPAI model providers
Territorial reachServices offered in IndiaProviders placing systems on the EU market, and third-country providers and deployers whose output is used in the EU (Art. 2(1)(c))
Synthetic contentVisible label plus permanent metadata; declaration and verification on large platformsMachine-readable marking of synthetic output (Art. 50(2)); deepfake disclosure by deployers (Art. 50(4)); applying since 2 August 2026
High-risk systemsNo statutory category; sector regulators may impose extra dutiesStandalone Annex III systems from 2 December 2027; Annex I embedded systems from 2 August 2028
PenaltiesLoss of safe harbour and IT Act consequences for intermediariesFines by tier; see EU AI Act penalties

EU dates as amended by the Digital Omnibus, Regulation (EU) 2026/1744. The EU AI Act guide has the full timetable.

Two practical points for exporters. A provider established outside the EU that places a high-risk system on the EU market must appoint an authorised representative in the Union before it does so. And the Act is extra-territorial in the way GDPR is: selling a scoring model to a German bank puts you in scope as a provider even if nothing runs in Europe.

06

How can one programme meet India and the EU at once?

Build one inventory of AI systems, classify each against the EU risk tiers, label synthetic output to the stricter of the two standards, keep incident and grievance records, and anchor the whole programme in a management system such as ISO 42001 that both regimes recognise as evidence of diligence.

1. Inventory first. Name every system, its purpose, its provider, the data it uses and where its outputs go. The EU classification and India's graded-liability thinking both start from function and risk, and neither can be applied to a system nobody has recorded.

2. Label once, to both standards. A visible disclosure plus embedded provenance metadata that cannot be removed satisfies the core of India's rule and of Article 50(2). Decide it in the product, not in the terms of service.

3. Treat personal data as personal data. Training and inference on Indian users' data needs a DPDP basis per purpose. For EU users it needs a GDPR basis too. Neither AI regime changes that.

4. Keep an incident log now. India's action plan points to a national AI incidents database, and the EU requires serious-incident reporting for high-risk systems. A log kept from today is evidence either way.

5. Use a management system. ISO 42001 gives the policy, risk, impact-assessment and monitoring spine both regimes expect; how it maps to the EU AI Act is set out separately.

07

Where TryTrustable fits, and where it does not

The AI governance engine keeps a registry of the models, prompts and MCP servers you run, classifies each system against the EU AI Act risk tiers, runs judged evaluations and tracks drift, and evidences the results against ISO 42001, NIST AI RMF and the EU AI Act. It does not label or watermark content for you, and it is not a substitute for the intermediary duties in the IT Rules.

Questions

The things people ask us

Does India have an AI law?

Not a dedicated one. The India AI Governance Guidelines released by MeitY on 5 November 2025 concluded that a separate AI law is not needed at this stage and that existing laws on IT, data protection and consumer protection should be applied. The binding AI-specific rule so far is the February 2026 IT Rules amendment on synthetic content.

Are the India AI Governance Guidelines mandatory?

No. They are guidelines: principles, recommendations and an action plan for government, regulators and industry. They encourage voluntary commitments and techno-legal measures, and propose institutions such as an AI Governance Group. Obligations reach companies through existing laws and sector regulators, and through the IT Rules amendment on synthetically generated information.

What do the IT Rules require for AI-generated content?

Intermediaries that let users create synthetically generated audio, images or video must label it prominently, embed permanent metadata or another provenance mechanism where technically feasible, and not allow the label to be removed. Significant social media intermediaries must also take a user declaration and verify it with technical measures before the content is published.

Does the EU AI Act apply to Indian companies?

It can. The Act applies to providers placing AI systems on the EU market wherever they are established, and to providers and deployers outside the EU where the system's output is used in the EU. An Indian company selling an AI product to European customers, or whose model's outputs reach people in the EU, should assume it is in scope.

What is synthetically generated information under Indian law?

Audio, visual or audio-visual information created or altered by a computer resource so that it appears real and depicts a person or event in a way likely to be seen as indistinguishable from the real thing. Routine editing, document and presentation preparation, and accessibility or translation tools that do not alter the substance are excluded.

Can one label satisfy both India and the EU?

Largely. Both regimes want a label a person can see and a machine-readable marker that survives, so a visible disclosure plus embedded provenance metadata that cannot be stripped meets the core of both. The details differ: India's rule binds intermediaries, and the EU's binds providers and deployers of the AI system.

One inventory, three regimes

Know what AI you run before a regulator asks.

See how the registry records each model, prompt and MCP server, classifies it under the EU AI Act, and evidences it against ISO 42001 from live state.