India Plans Separate AI Law to Tackle Deepfakes, Agent Autonomy
The Ministry of Electronics and Information Technology (MeitY) is weighing a standalone law to regulate artificial intelligence (AI), with provisions for a consent-based framework for synthetically-generated content, curbs on agentic AI autonomy, and regulatory sandboxes for high-risk applications, sources have said.
Synthetically-generated content refers to digital media created or altered by AI rather than humans. The proposed law is expected to be a separate piece of legislation, not an amendment to the Information Technology Act, 2000, a senior government official told The Indian Express.
The cyber laws division of MeitY, which formulates laws and policies affecting tech companies, has been asked to analyse the IT Act and its rules to identify regulatory gaps. In the case of agentic AI—autonomous systems that can plan multi-step actions, use external tools, and adapt in real time with minimal human supervision—the government is considering how much autonomy such systems should have and whether they should be allowed to retain and reuse data.
The ministry is also expected to consult the Reserve Bank of India (RBI) and the Securities and Exchange Board of India (SEBI) to set up a regulatory sandbox for AI applications in high-impact areas such as finance and public services.
A major area of discussion is the liability of AI platforms and developers for content generated by their models. In the consumer internet world, social media platforms enjoy 'safe harbour'—legal immunity from hosting user-generated content—based on the premise that platforms cannot preempt user posts. However, this logic does not directly apply to AI models, which are trained on internet content and may produce responses that cannot be traced back to a specific source. The government has asked two legal experts from the private sector to submit separate draft liability frameworks for AI models.
“Building a consent-based framework for synthetically generated media would be one of the key requirements for an AI law. We have seen the rapid proliferation of deepfakes on the Internet, and most of them, if not all, are generated by using pictures or videos of individuals whose consent has not been sought,” a senior government official said on condition of anonymity.
Though the Digital Personal Data Protection Act, 2023 addresses broader privacy issues, the official noted that questions of consent and data ownership in the AI age need further examination. India’s data protection law exempts personal data voluntarily made public by an individual, meaning that if an AI platform scrapes pictures from a public social media profile, such processing may lack guardrails under the current law.
The government’s move comes after it previously stated that existing laws were sufficient to handle AI-related challenges. Queries sent to MeitY remained unanswered until publication.