<p><em>The AI Reality Check is an IMA India research series examining how artificial intelligence is changing the operational reality of Indian enterprises. It is based on in-depth interviews with CXOs and senior operational leaders from IMA member companies, supplemented by secondary research. </em></p><p><em>This is the <strong>fourth of five papers.</strong></em></p>.<p><strong>Executive Summary</strong></p><ul><li><p><strong>The DPDP Act and Rules</strong> create a binding data-rights framework but no AI-specific statute exists and sector regulators are moving at very different speeds.</p></li><li><p>India <strong>lacks settled cross-sector standards for model explainability, algorithmic accountability, liability for AI outputs</strong> and lawful use of personal data for model training.</p></li><li><p><strong>Large regulated enterprises are governing themselves ahead of the law.</strong></p></li><li><p><strong>In regulated sectors, the compliance burden is being externalised.</strong></p></li><li><p>MeitY's AI Governance Guidelines confirmed a sectoral, innovation-first approach, with <strong>existing laws amended rather than a new AI Act.</strong></p></li><li><p><strong>Regulatory lag is both feature and liability as </strong>it accelerates low-stakes AI deployment but creates asymmetric risk in high-stakes domains.</p></li></ul>.<p>India has been deploying AI at pace without rules designed for it. The DPDP Act has established data-principal rights and breach-notification obligations, but no AI-specific statute exists, and the gaps it leaves are not uniform. Where the absence of rules is genuinely enabling and where it is storing up risk depends on the sector, the firm size and the use case. Regulation is arriving in pieces, at different speeds, with different levels of rigour. India is not ungoverned, but it is not consistent either.</p>.<h2><strong>A Framework Built in Pieces</strong></h2><p>Currently, India's AI regulatory architecture rests largely on laws and regulations governing data privacy. The Digital Personal Data Protection (DPDP) Act of 2023, with its implementing Rules notified by MeitY in November 2025, clearly defines digital rights with respect to consent, purpose limitation, data-principal rights and breach notification. Full enforcement is expected from May 2027 and penalties for major breaches can reach Rs 2.5bn per violation. What the DPDP framework <em>does not do</em> is regulate AI as a category. Instead, it governs the personal data that AI systems consume and produce while saying nothing about model explainability (the ability of a system to account for how it reached a decision), algorithmic fairness, audit requirements or acceptable use boundaries.</p><p>MeitY's position on these issues is summarised in its November 2025 <em>India AI Governance Guidelines. </em>The guidelines confirm that India will not enact a cross sectoral AI statute in the near term, and that the overarching aim is to drive innovation while aligning with global standards. In short, existing laws will be amended where necessary, and sector regulators will incorporate AI governance into their domain frameworks. An AI Safety Institute, operating on a hub-and-spoke model, is expected to advise regulators and test AI systems, though it is not yet operational. All of this goes to say that India’s AI compliance framework remains incomplete, and highly uneven across sectors.</p><p><em><strong>Financial services</strong></em></p><p>The RBI has the most developed AI-adjacent framework of any Indian sector-regulator. Its Master Direction on IT Governance, Risk, Controls and Assurance Practices requires regulated entities to maintain model risk management, audit trails and board-level accountability for algorithmic decisions. In August 2025, the RBI's FREE-AI Committee published a framework of 7 principles for responsible AI adoption in the financial sector. Regulated entities will be accountable for model outcomes, regardless of whether the model was built in-house or procured from a vendor. SEBI has moved in a similar direction, requiring auditability, cloud accountability and vendor oversight from market intermediaries. IRDAI's 2026 Cybersecurity Guidelines, meanwhile, contain relatively modest technology governance requirements for insurers. What none of these frameworks specify are AI-specific benchmarks for liability, fairness testing or model validation in consumer-facing decisions. In credit scoring, insurance pricing and hiring, algorithms are starting to influence decisions in material ways, but there is no clear oversight on governance in this regard. While firms <em>know</em> they will be held responsible if something goes wrong, they <em>do not know </em> what degree of control a regulator or court may later treat as ‘sufficient’.</p><p><em><strong>Healthcare and pharma</strong></em></p><p>The Central Drugs Standard Control Organisation's (CDSCO) 2025 draft guidance on Software as a Medical Device (SaMD) creates a pathway for AI-enabled medical devices. However, there is no equivalent yet for AI in drug development submissions. The pharmaceutical sector's response has been to self-impose boundaries. A leading pharma company is taking a deliberately bounded approach. It uses AI to organise and analyse regulatory submission data while ensuring robust human review, but keeps experiments and clinical inferences firmly in human hands. As their leadership put it, the company simply cannot risk an AI engine generating output that drives clinical inferences, because <em>everything</em> it does is centred on patient safety. Regulatory agencies have taken a similar stance: rather than mandating specific approval pathways, they are working with industry to identify places where AI output can reduce unnecessary manual workloads/delays, especially at the experimentation stage.</p><p><em><strong>Other sectors</strong></em></p><p>Outside finance and healthcare, firms must currently supply their own frameworks. AI for insurance underwriting at non-bank lenders; credit scoring outside regulated banking; content moderation; back-office automation and a range of other applications all sit in territory where no regulator has yet set a floor. There is considerable ambiguity around the use of personal data to train or fine-tune AI models. Neither the DPDP Act nor its Rules clarifies the relationship between original data consent and subsequent model training – a point flagged by NASSCOM and the Internet and Mobile Association of India (IAMAI) in recent submissions. Nor does India have an AI liability statute in place. Legal exposure for AI-generated output – whether a flawed credit assessment, a misdiagnosis-contributing tool or a defamatory piece of generated content – cannot be quantified with any confidence.</p>.<h2><strong>How Businesses are Filling the Vacuum</strong></h2><p>In the absence of binding rules, firms are self-regulating their use of AI through three sets of mechanisms: internal frameworks, vendor contracts and borrowed international standards. However, the quality of governance varies sharply by firm sophistication and sector exposure.</p><p><em><strong>Internal governance</strong></em></p><p>A leading global bank's AI deployment model is a good example of enterprise-level governance running well ahead of regulation. Each of its AI initiatives follow a staged progression: proof of concept (POC), pilot, production. At the POC stage, the bank evaluates model, cyber and resilience risks, process controls, human oversight and the extent of subject-matter expert engagement. The process is not a straight line: a POC can be turned back; a pilot can fail to reach production. A group-wide approval committee monitors each stage throughout. For generative AI specifically, the bank operates with effectively 100% human review in the loop. To an extent, the bank's robust internal controls reflect the sheer resources that large MNCs can leverage: it has over 750 AI professionals alone on its rolls. However, this is also a function of it operating in a tightly-regulated sector whose governance standards are set by the Financial Conduct Authority and the Basel Committee on Banking Supervision, both considerably more demanding than what any domestic regulations may specify. The case demonstrates how large the gap really is between what a sophisticated regulated operator does voluntarily, and what the regulatory floor requires of everyone else.</p><p><em><strong>Vendor contracts</strong></em></p><p>Since regulators continue to hold business entities accountable, regardless of whether the AI was built or bought, procurement has become a governance mechanism in its own right. Contracts with AI vendors must now address audit rights, model change notifications, logging obligations, data use restrictions, security testing requirements, exit rights and indemnity provisions. In sectors where regulators have explicit outsourcing rules (primarily banking and insurance), these requirements have teeth. Outside these sectors, though, the quality of contract governance varies considerably, and for many enterprises, there is no external pressure to ‘get it right’ before something goes wrong.</p><p><em><strong>Borrow standards</strong></em></p>.<p>The EU AI Act is the outlier in this group: the only horizontal statute with real legal teeth, it creates business certainty, but at the expense of compliance overheads that may disadvantage smaller firms. India's approach most closely resembles a combination of the UK's regulator-led model and the US's innovation-first posture. The November 2025 AI Guidelines explicitly acknowledge alignment with Japan's 2025 AI law, which relies on non-binding guidelines and an AI Strategy Centre rather than a statute.</p>.<h2>Feature or Liability: The Case on Both Sides</h2><p>India's advisory-first approach to AI governance is driving experimentation across domains. Internal copilots, coding assistants, document summarisation tools and knowledge management applications face no ex-ante conformity requirements. A firm that wants to deploy a generative AI assistant for its sales team does not <em>need</em> to conduct a conformity assessment, register a high-risk system or publish technical documentation, as it would under the EU AI Act. The <em>IndiaAI Mission's</em> compute subsidy program, which has made over 38,000 GPUs available at subsidised rates, reduces infrastructure barriers for AI builders without attaching heavy regulatory conditions. The DPDP framework's relatively permissive cross-border transfer rules, a negative list rather than an approved-country whitelist, mean that cloud-based AI services hosted outside India remain generally accessible.</p><p>On the other side of the equation, the absence of AI-specific rules does not reduce firm-level accountability, but rather, shifts the burden of having adequate governance entirely onto firms, with no regulatory safe harbour. An organisation that deploys an AI credit-scoring model without a clear regulatory minimum for validation, documentation and fairness testing cannot <em>know</em> whether its governance is sufficient until something goes wrong.</p><p>More subtly, regulatory ambiguity can breed an over-cautious, more so even than explicit rules. Several of the firms we interviewed described holding AI deployments back, not because of specific prohibitions, but because they could not quantify their legal exposure. The absence of a rule does not always mean freedom to act; for risk-averse regulated entities, it can mean the opposite. India has not eliminated the cost of governing AI. It has simply transferred a chunk of that cost to enterprises. </p>.<h2><strong>What This Means for Your Organisation</strong></h2><p>India's regulatory architecture is unlikely to stay in its current shape. The likeliest trajectory is a layered hybrid, where the DPDP acts as the foundation, MeitY and IndiaAI as soft-law standard setters, sector regulators as operational enforcers and enterprises as the governance layer for everything in between. That model can work, but three things need to happen for it to work well:</p><ul><li><p>Clarity on accountability for high-impact AI systems</p></li><li><p>A settled position on the lawful use of personal data for AI training, which neither the Act nor the Rules currently provide</p></li><li><p>Sector-specific AI controls in finance and healthcare that go beyond technology risk management to address the specific properties of machine-learning models, including drift, opacity and generative unpredictability.</p></li></ul><p> Whether other regulators follow the RBI's lead, or leave enterprises to fill the gap indefinitely, is an open question. But BSV's Sanjiv Navangul, reflecting on whether Indian regulation can keep pace with AI deployment, offered a characteristically direct assessment: ‘India tends to regulate in the extreme and then taper down according to need.’</p><p>For senior leaders, there are four practical takeaways:</p><ul><li><p><strong>The regulatory floor is not a guide to adequate governance.</strong> In sectors where AI outputs affect people, and especially personal wellbeing, what the law currently requires and what prudent governance actually demands are not the same thing. The firms that are managing this well are not waiting for rules to close that gap.</p></li><li><p><strong>Map your exposure now.</strong> The three greatest areas of ambiguity – algorithmic accountability, the lawful use of personal data for model training and liability for AI outputs – are also the three likeliest to attract regulatory attention first. Knowing where your deployments sit relative to each is a basic risk management step.</p></li><li><p><strong>Vendor contracts are governance.</strong> In the absence of a regulatory floor, the contract with your AI vendor is often the only document that specifies what happens when something goes wrong. Audit rights, model change notifications, logging obligations and exit provisions are not procurement details, but governance instruments.</p></li><li><p><strong>Borrowed standards have a shelf life.</strong> NIST AI RMF, ISO/IEC 42001 and Singapore's framework are useful scaffolding. They are also imported frameworks designed for different regulatory contexts. As sector regulators develop their own requirements, the alignment between imported standards and domestic obligations will need to be reviewed.</p></li></ul>
<p><em>The AI Reality Check is an IMA India research series examining how artificial intelligence is changing the operational reality of Indian enterprises. It is based on in-depth interviews with CXOs and senior operational leaders from IMA member companies, supplemented by secondary research. </em></p><p><em>This is the <strong>fourth of five papers.</strong></em></p>.<p><strong>Executive Summary</strong></p><ul><li><p><strong>The DPDP Act and Rules</strong> create a binding data-rights framework but no AI-specific statute exists and sector regulators are moving at very different speeds.</p></li><li><p>India <strong>lacks settled cross-sector standards for model explainability, algorithmic accountability, liability for AI outputs</strong> and lawful use of personal data for model training.</p></li><li><p><strong>Large regulated enterprises are governing themselves ahead of the law.</strong></p></li><li><p><strong>In regulated sectors, the compliance burden is being externalised.</strong></p></li><li><p>MeitY's AI Governance Guidelines confirmed a sectoral, innovation-first approach, with <strong>existing laws amended rather than a new AI Act.</strong></p></li><li><p><strong>Regulatory lag is both feature and liability as </strong>it accelerates low-stakes AI deployment but creates asymmetric risk in high-stakes domains.</p></li></ul>.<p>India has been deploying AI at pace without rules designed for it. The DPDP Act has established data-principal rights and breach-notification obligations, but no AI-specific statute exists, and the gaps it leaves are not uniform. Where the absence of rules is genuinely enabling and where it is storing up risk depends on the sector, the firm size and the use case. Regulation is arriving in pieces, at different speeds, with different levels of rigour. India is not ungoverned, but it is not consistent either.</p>.<h2><strong>A Framework Built in Pieces</strong></h2><p>Currently, India's AI regulatory architecture rests largely on laws and regulations governing data privacy. The Digital Personal Data Protection (DPDP) Act of 2023, with its implementing Rules notified by MeitY in November 2025, clearly defines digital rights with respect to consent, purpose limitation, data-principal rights and breach notification. Full enforcement is expected from May 2027 and penalties for major breaches can reach Rs 2.5bn per violation. What the DPDP framework <em>does not do</em> is regulate AI as a category. Instead, it governs the personal data that AI systems consume and produce while saying nothing about model explainability (the ability of a system to account for how it reached a decision), algorithmic fairness, audit requirements or acceptable use boundaries.</p><p>MeitY's position on these issues is summarised in its November 2025 <em>India AI Governance Guidelines. </em>The guidelines confirm that India will not enact a cross sectoral AI statute in the near term, and that the overarching aim is to drive innovation while aligning with global standards. In short, existing laws will be amended where necessary, and sector regulators will incorporate AI governance into their domain frameworks. An AI Safety Institute, operating on a hub-and-spoke model, is expected to advise regulators and test AI systems, though it is not yet operational. All of this goes to say that India’s AI compliance framework remains incomplete, and highly uneven across sectors.</p><p><em><strong>Financial services</strong></em></p><p>The RBI has the most developed AI-adjacent framework of any Indian sector-regulator. Its Master Direction on IT Governance, Risk, Controls and Assurance Practices requires regulated entities to maintain model risk management, audit trails and board-level accountability for algorithmic decisions. In August 2025, the RBI's FREE-AI Committee published a framework of 7 principles for responsible AI adoption in the financial sector. Regulated entities will be accountable for model outcomes, regardless of whether the model was built in-house or procured from a vendor. SEBI has moved in a similar direction, requiring auditability, cloud accountability and vendor oversight from market intermediaries. IRDAI's 2026 Cybersecurity Guidelines, meanwhile, contain relatively modest technology governance requirements for insurers. What none of these frameworks specify are AI-specific benchmarks for liability, fairness testing or model validation in consumer-facing decisions. In credit scoring, insurance pricing and hiring, algorithms are starting to influence decisions in material ways, but there is no clear oversight on governance in this regard. While firms <em>know</em> they will be held responsible if something goes wrong, they <em>do not know </em> what degree of control a regulator or court may later treat as ‘sufficient’.</p><p><em><strong>Healthcare and pharma</strong></em></p><p>The Central Drugs Standard Control Organisation's (CDSCO) 2025 draft guidance on Software as a Medical Device (SaMD) creates a pathway for AI-enabled medical devices. However, there is no equivalent yet for AI in drug development submissions. The pharmaceutical sector's response has been to self-impose boundaries. A leading pharma company is taking a deliberately bounded approach. It uses AI to organise and analyse regulatory submission data while ensuring robust human review, but keeps experiments and clinical inferences firmly in human hands. As their leadership put it, the company simply cannot risk an AI engine generating output that drives clinical inferences, because <em>everything</em> it does is centred on patient safety. Regulatory agencies have taken a similar stance: rather than mandating specific approval pathways, they are working with industry to identify places where AI output can reduce unnecessary manual workloads/delays, especially at the experimentation stage.</p><p><em><strong>Other sectors</strong></em></p><p>Outside finance and healthcare, firms must currently supply their own frameworks. AI for insurance underwriting at non-bank lenders; credit scoring outside regulated banking; content moderation; back-office automation and a range of other applications all sit in territory where no regulator has yet set a floor. There is considerable ambiguity around the use of personal data to train or fine-tune AI models. Neither the DPDP Act nor its Rules clarifies the relationship between original data consent and subsequent model training – a point flagged by NASSCOM and the Internet and Mobile Association of India (IAMAI) in recent submissions. Nor does India have an AI liability statute in place. Legal exposure for AI-generated output – whether a flawed credit assessment, a misdiagnosis-contributing tool or a defamatory piece of generated content – cannot be quantified with any confidence.</p>.<h2><strong>How Businesses are Filling the Vacuum</strong></h2><p>In the absence of binding rules, firms are self-regulating their use of AI through three sets of mechanisms: internal frameworks, vendor contracts and borrowed international standards. However, the quality of governance varies sharply by firm sophistication and sector exposure.</p><p><em><strong>Internal governance</strong></em></p><p>A leading global bank's AI deployment model is a good example of enterprise-level governance running well ahead of regulation. Each of its AI initiatives follow a staged progression: proof of concept (POC), pilot, production. At the POC stage, the bank evaluates model, cyber and resilience risks, process controls, human oversight and the extent of subject-matter expert engagement. The process is not a straight line: a POC can be turned back; a pilot can fail to reach production. A group-wide approval committee monitors each stage throughout. For generative AI specifically, the bank operates with effectively 100% human review in the loop. To an extent, the bank's robust internal controls reflect the sheer resources that large MNCs can leverage: it has over 750 AI professionals alone on its rolls. However, this is also a function of it operating in a tightly-regulated sector whose governance standards are set by the Financial Conduct Authority and the Basel Committee on Banking Supervision, both considerably more demanding than what any domestic regulations may specify. The case demonstrates how large the gap really is between what a sophisticated regulated operator does voluntarily, and what the regulatory floor requires of everyone else.</p><p><em><strong>Vendor contracts</strong></em></p><p>Since regulators continue to hold business entities accountable, regardless of whether the AI was built or bought, procurement has become a governance mechanism in its own right. Contracts with AI vendors must now address audit rights, model change notifications, logging obligations, data use restrictions, security testing requirements, exit rights and indemnity provisions. In sectors where regulators have explicit outsourcing rules (primarily banking and insurance), these requirements have teeth. Outside these sectors, though, the quality of contract governance varies considerably, and for many enterprises, there is no external pressure to ‘get it right’ before something goes wrong.</p><p><em><strong>Borrow standards</strong></em></p>.<p>The EU AI Act is the outlier in this group: the only horizontal statute with real legal teeth, it creates business certainty, but at the expense of compliance overheads that may disadvantage smaller firms. India's approach most closely resembles a combination of the UK's regulator-led model and the US's innovation-first posture. The November 2025 AI Guidelines explicitly acknowledge alignment with Japan's 2025 AI law, which relies on non-binding guidelines and an AI Strategy Centre rather than a statute.</p>.<h2>Feature or Liability: The Case on Both Sides</h2><p>India's advisory-first approach to AI governance is driving experimentation across domains. Internal copilots, coding assistants, document summarisation tools and knowledge management applications face no ex-ante conformity requirements. A firm that wants to deploy a generative AI assistant for its sales team does not <em>need</em> to conduct a conformity assessment, register a high-risk system or publish technical documentation, as it would under the EU AI Act. The <em>IndiaAI Mission's</em> compute subsidy program, which has made over 38,000 GPUs available at subsidised rates, reduces infrastructure barriers for AI builders without attaching heavy regulatory conditions. The DPDP framework's relatively permissive cross-border transfer rules, a negative list rather than an approved-country whitelist, mean that cloud-based AI services hosted outside India remain generally accessible.</p><p>On the other side of the equation, the absence of AI-specific rules does not reduce firm-level accountability, but rather, shifts the burden of having adequate governance entirely onto firms, with no regulatory safe harbour. An organisation that deploys an AI credit-scoring model without a clear regulatory minimum for validation, documentation and fairness testing cannot <em>know</em> whether its governance is sufficient until something goes wrong.</p><p>More subtly, regulatory ambiguity can breed an over-cautious, more so even than explicit rules. Several of the firms we interviewed described holding AI deployments back, not because of specific prohibitions, but because they could not quantify their legal exposure. The absence of a rule does not always mean freedom to act; for risk-averse regulated entities, it can mean the opposite. India has not eliminated the cost of governing AI. It has simply transferred a chunk of that cost to enterprises. </p>.<h2><strong>What This Means for Your Organisation</strong></h2><p>India's regulatory architecture is unlikely to stay in its current shape. The likeliest trajectory is a layered hybrid, where the DPDP acts as the foundation, MeitY and IndiaAI as soft-law standard setters, sector regulators as operational enforcers and enterprises as the governance layer for everything in between. That model can work, but three things need to happen for it to work well:</p><ul><li><p>Clarity on accountability for high-impact AI systems</p></li><li><p>A settled position on the lawful use of personal data for AI training, which neither the Act nor the Rules currently provide</p></li><li><p>Sector-specific AI controls in finance and healthcare that go beyond technology risk management to address the specific properties of machine-learning models, including drift, opacity and generative unpredictability.</p></li></ul><p> Whether other regulators follow the RBI's lead, or leave enterprises to fill the gap indefinitely, is an open question. But BSV's Sanjiv Navangul, reflecting on whether Indian regulation can keep pace with AI deployment, offered a characteristically direct assessment: ‘India tends to regulate in the extreme and then taper down according to need.’</p><p>For senior leaders, there are four practical takeaways:</p><ul><li><p><strong>The regulatory floor is not a guide to adequate governance.</strong> In sectors where AI outputs affect people, and especially personal wellbeing, what the law currently requires and what prudent governance actually demands are not the same thing. The firms that are managing this well are not waiting for rules to close that gap.</p></li><li><p><strong>Map your exposure now.</strong> The three greatest areas of ambiguity – algorithmic accountability, the lawful use of personal data for model training and liability for AI outputs – are also the three likeliest to attract regulatory attention first. Knowing where your deployments sit relative to each is a basic risk management step.</p></li><li><p><strong>Vendor contracts are governance.</strong> In the absence of a regulatory floor, the contract with your AI vendor is often the only document that specifies what happens when something goes wrong. Audit rights, model change notifications, logging obligations and exit provisions are not procurement details, but governance instruments.</p></li><li><p><strong>Borrowed standards have a shelf life.</strong> NIST AI RMF, ISO/IEC 42001 and Singapore's framework are useful scaffolding. They are also imported frameworks designed for different regulatory contexts. As sector regulators develop their own requirements, the alignment between imported standards and domestic obligations will need to be reviewed.</p></li></ul>