Regulating Artificial Intelligence In India: The Case For a Risk-Based Legal Framework
Introduction
Artificial Intelligence (AI) has significantly reshaped public administration, commercial activity and legal decision-making, offering unprecedented opportunities while also creating significant regulatory challenges. As AI systems play an increasingly important role in decision-making affecting individuals and society, concerns relating to privacy, accountability, transparency, discrimination, and liability have become central to legal discourse. The Organisation for Economic Co-operation and Development (OECD) recognises that AI significantly affects economic activity, governance, and fundamental rights, underscoring the increasing need for an effective regulatory oversight (OECD, 2019).
In contrast to conventional technologies, AI systems can learn, adapt and make autonomous decisions, thereby reducing the extent of human intervention. Existing legal frameworks are not adequately equipped to regulate issues such as algorithmic bias, lack of transparency in automated decision-making, explainability and liability arising from AI-generated outcomes. Several scholars have argued that the absence of transparency in AI systems undermines accountability, and procedural fairness (Pasquale, 2015). Similarly, the European Union (EU) has introduced the EU AI Act, establishing a comprehensive risk-based regulatory model, with the object of balancing technological innovation with the protection of fundamental rights (European Union, 2024).
At present, India’s AI governance framework relies on a combination of existing legislation and policy initiatives rather than a dedicated regulatory statute. It regulates AI through a combination of the Information Technology Act, 2000 (IT Act), the Digital Personal Data Protection Act, 2023 (DPDP Act) and various policy initiatives. Although these measures encourage innovation, they do not establish a comprehensive legal framework specifically governing AI. As a result, significant regulatory gaps continue to exist in relation to algorithmic accountability, deepfakes, automated decision-making, and liability.
The central question addressed in this study is whether India should adopt a risk-based legal framework for regulating AI. It argues that India should implement a proportionate regulatory model that classifies AI systems. As per the level of risk they pose while safeguarding innovations, public safety and constitutional rights.
Concept of Risk-Based AI Regulation and its Underlying Rationale
A risk-based AI regulation approach categorises AI systems based on the degree of risk they prevent to individuals and society. Rather than regulating every AI application equally, legal obligations are imposed in proportion to the potential harm created by a system. The EU AI Act provides the leading example of this approach by establishing four categories of AI risk (European Union, 2024).
EU AI Act’s Four Risk Categories :
Unacceptable-Risk AI (Prohibited):
These AI systems are prohibited as they cause an unacceptable risk to fundamental rights, public safety or democratic values. Illustrative examples include AI systems used for social scoring by public authorities, certain forms of manipulative or exploitative AI and AI practices that exploit vulnerable persons or enable indiscriminate biometric surveillance in prohibited circumstances (European Union, 2024).
High-Risk AI:
Although high-risk AI systems are permitted, they are subject to strict regulatory obligations because they can significantly affect individuals, rights and safety. This category covers AI used in healthcare, education, employment, law enforcement, migration, critical infrastructure, and essential public services. Developers and providers of such systems are required to comply with obligations relating to risk management, high-quality data governance, technical documentation, transparency, human oversight, accuracy and cyber security requirements, confirm assessments and continuous post-market monitoring (European Union, 2024).
Limited-Risk AI:
Limited risk AI systems are subject primarily to transparency obligations. Individuals must be clearly informed whenever they interact with AI systems, such as chatbots, AI-generated content or deepfake technologies, thereby enabling individuals to make informed decisions about their interactions with such systems (European Union, 2024).
Minimal-Risk AI:
Minimal-risk AI systems pose little or no threat to individuals or society and therefore are not subject to additional regulatory obligations under the EU AI Act. Common examples include AI-enabled, spam filters, recommendation systems, grammar and spell-checking tools and AI used in video games. These applications may continue to operate with minimal regulatory intervention, thereby encouraging innovation (European Union, 2024).
The concept originated from traditional risk management models used in sectors such as finance, healthcare, and product safety before being adopted for AI governance. The European Commission's White Paper on Artificial Intelligence, followed by the enactment of the EU AI Act established the first comprehensive legislative framework based on proportional regulation. International organisations have subsequently supported comparable principles promoting trustworthy and responsible AI governance through the United Nations Educational, Scientific and Cultural Organization (UNESCO) and the OECD.
A risk-based framework enables regulators to focus their oversight on AI systems capable of causing significant harm while avoiding unnecessary compliance burdens for low-risk technologies. Consequently, it seeks to balance innovation with accountability by ensuring that regulatory obligations remain proportionate to the risk posed by different AI applications.
India’s current Legal and Policy Position
In contrast to jurisdictions such as the EU, India has not enacted dedicated legislation governing AI. Instead, AI regulation is based on a combination of existing statutes, policy initiatives and sector-specific guidelines. This approach prioritises innovation but leaves significant regulatory gaps concerning accountability, transparency, and liability (NITI Aayog, 2018).
The IT Act remains India’s primary legislation governing digital activities. However, since it was enacted before the emergence of modern AI technologies, it does not sufficiently regulate issues relating to algorithmic accountability, explainability, autonomous decision-making, or liability arising from AI-generated outcomes (Information Technology Act, 2000; NITI Aayog, 2021). Similarly, the DPDP Act strengthens privacy and data governance by regulating how personal data is processed. While it does indirectly regulate AI governance by ensuring lawful data processing, it does not impose specific obligations relating to AI, risk assessment, human oversight, algorithmic transparency or bias mitigation (Digital Personal Data Protection Act, 2023).
In addition, India has also introduced a number of policy initiatives, including NITI Aayog’s National Strategy for Artificial Intelligence: AI for All (2018), the Responsible AI for All Report (2021), and the IndiaAI Mission launched by the Ministry of Electronics and Information Technology (MeitY, 2024). These initiatives promote fairness, accountability, transparency, privacy and inclusivity, but they remain advisory in nature and do not provide legally enforceable compliance mechanisms (NITI Aayog, 2021).
The Indian AI Governance Guidelines (2025) reaffirm India’s preference for a balanced, innovation-oriented and principle-based AI governance framework rather than a standalone AI statute. The Guidelines recommend regulating AI primarily through existing sector-specific laws while addressing regulatory gaps through targeted legislative amendments. This approach seeks to encourage responsible innovation without imposing unnecessary compliance burdens (Committee on AI Governance Guidelines Development, 2025).
The guidelines further recommend the adoption of an India-specific AI risk assessment framework, greater transparency across the AI value chain and establishment of institutional mechanisms such as AI governance group (AIGG) and AI safety Institute (AISI) to coordinate policy development, monitor and provide technical guidance. Rather than introducing extensive compliance obligations at the outset, the proposed framework promotes voluntary government measures, sectoral regulation and continuous policy review to ensure that AI regulation remains adaptive to technological development (MeitY, 2025).
Although, the Reserve Bank of India (RBI), Securities and Exchange Board of India (SEBI) and the Insurance Regulatory and Development Authority of India (IRDAI) have issued technology-related guidelines, these remain fragmented and do not establish a uniform regulatory framework applicable across AI systems. Consequently, India’s existing AI governance framework reflects a strong commitment to innovation, but remains inadequate to address the legal and ethical challenges posed by high-risk AI systems. The lack of dedicated legislation continues to create uncertainty concerning accountability and the protection of constitutional rights. This concern becomes particularly significant in light of the Supreme Court recognition of privacy as a fundamental right in Justice K.S. Puttaswamy (Retd.) v. Union of India.
Comparative Analysis of India's position with International Approaches
AI governance has become a global regulatory priority. Although India’s existing approach is primarily policy-driven, international frameworks, such as the EU AI Act and the OECD Principles on AI offer valuable guidance for balancing technology innovation with the protection of fundamental rights.
The EU AI Act 2024 is recognised as the world's first comprehensive and legally enforceable AI legislation. The legislation categorises AI systems into four distinct levels of risk- unacceptable, high, limited, and minimal risk- and imposes obligations proportionate to the level of risk. High-risk AI systems used in sectors such as healthcare, education, employment, enforcement and critical infrastructure are required to comply with measures relating to transparency, risk management, human oversight, conformity assessment and post market monitoring (European Union, 2024).
By contrast, India’s AI governance framework remains largely policy-driven. Initiatives such as AI for All and the IndiaAI Mission encourage responsible AI development based on principles of fairness, transparency, accountability and privacy. However, these initiatives do not impose legally enforceable obligations or prescribe penalties for non-compliance (NITI Aayog, 2021; MeitY, 2024). As a result, India lacks a formal mechanism for classifying AI systems according to their level of risk.
The OECD AI Principles, 2019, provide internationally recognised standards for trustworthy AI, emphasising human-centred values, transparency, robustness, accountability and responsible stewardship. Although these principles have significantly influenced India’s policy initiatives, they remain voluntary in nature and therefore cannot substitute for a comprehensive statutory framework (OECD, 2019).
India’s innovation-first approach has undoubtedly accelerated digital but the absence of enforceable AI-specific obligations continues to create uncertainty regarding accountability and legal responsibility. Rather than replicating the European model entirely, India should adopt a context-specific risk-based framework that combines the enforceable risk classification of the EU AI Act with the flexibility reflected in the OECD Principles. Such an approach would promote innovation while ensuring constitutional safeguards and regulatory certainty.
Unlike the European Union’s AI act, which creates legally binding obligations through a comprehensive risk-based classification system, the draft India AI Governance Guidelines propose a principal-based governance framework supported by sector-lead governance model. The report recommends a whole-of-government approach through the establishment of an AI Governance Group (AIGG) supported by a Technology and Policy Expert Committee (TPEC) and AI Safety Institute (AISI) to coordinate policy development, undertake AI risk assessment and provide technical guidance while allowing sectoral regulators to retain enforcement powers. This institutional model reflects India’s preference for regulatory coordination and flexibility rather than a single overarching AI regulator (MeitY, 2025).
Comparative Analysis of AI Governance Models
The table below compares India’s evolving AI governance approach with the European Union’s AI Act and the OECD’s principle-based framework.
| Aspect | India | EU AI Act | OECD Principles |
|---|---|---|---|
| Legal Nature | Policy-driven framework | Binding legislation | Non-binding international principles |
| Regulatory Model | Principle-based and sectoral | Risk-based regulation | Ethical and principle-based |
| Scope | Sector-specific initiatives | Applies to AI systems placed on the EU market | General guidance for AI governance |
| Risk Classification | No formal classification | Four-tier risk classification | No formal risk categorisation |
| Binding Force | Limited legal enforceability | Legally enforceable with penalties | Voluntary adoption |
| Obligations Imposed | Transparency under existing sectoral laws | Risk management, documentation, transparency, human oversight, and conformity assessments | Responsible AI practices and accountability |
| Enforcement Mechanism | Existing regulations, including MeitY, RBI, SEBI, etc. | National supervisory authorities and the European AI Office | No enforcement mechanism |
| Institutional Structure | No dedicated AI regulator | Dedicated AI governance framework under the EU AI Act | No central regulatory authority |
| Protection of Fundamental Rights | Constitutional safeguards and DPDP Act | Explicit protection of fundamental rights | Human-centred AI principles |
| Innovation Approach | Innovation-focused | Balances innovation with safety | Encourages trustworthy innovation |
The comparison shows that India’s framework is still indirect and fragmented, while the EU AI Act translates risk categories into enforceable duties, and the OECD Principles provide ethical guidance without creating legal duties. Thus, the most appropriate approach for India is not direct replication of the EU Act but the development of a calibrated framework that combines formal risk classification with flexible and context-sensitive implementation.
Challenges in adopting a Risk-based Regulatory Framework
Despite its advantages, implementing a risk-based AI regulatory framework in India poses several legal, institutional and economic challenges. India’s expanding digital economy requires a regulatory model that protects fundamental rights while continuing to encourage technological innovation (NITI Aayog, 2018).
The principal regulatory challenge lies in maintaining an appropriate balance between encouraging technological innovation and safeguarding individuals against algorithmic harm. Excessive compliance requirements may increase costs and discourage AI research and start-ups, whereas inadequate regulation may result in algorithmic bias, opaque decision-making, and discrimination, particularly in sectors such as healthcare, finance, and employment (Cath et al., 2018; Floridi & Cowls, 2019).
Another significant challenge is the absence of legislation specifically governing AI. The current laws, which include the IT Act, 2000 and the DPDP Act, 2023, regulate digital governance and personal data, but do not adequately address algorithmic accountability, explainability, automated decision-making or liability for AI-generated outcomes. This fragmented framework therefore creates legal uncertainty for regulators, businesses, and consumers (NITI Aayog, 2021).
Institutional capacity also remains a significant concern. Effective implementation of a risk-based framework requires specialised regulatory bodies, equipped to conduct AI risk assessments, compliance audits and continuous monitoring of high-risk AI systems. India presently lacks a dedicated AI regulator with the technical expertise required for such oversight (MeitY, 2024; Yeung, 2018).
Data governance constitutes another significant challenge, given that AI systems rely extensively on large volumes of personal data. The Supreme Court’s judgement, Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) recognised privacy as a fundamental right, requiring AI governance to incorporate robust safeguards relating to privacy, transparency and accountability. Furthermore, India’s sectoral diversity necessitates a flexible regulatory framework capable of imposing proportionate obligation according to the level of risk posed by different AI applications (European Union, 2024; OECD, 2019).
Recommendations for an Innovation-Friendly AI Regulatory Framework
A dedicated, risk-based regulatory framework would significantly enhance India’s AI governance by categorising systems by the degree of harm they can cause and imposing tighter compliance requirements on higher-risk applications, taking inspiration from the EU AI Act’s tiered approach. (European Union,2024).
India should establish a central coordinating AI authority, rather than an entirely separate sectoral regulator. The authority would coordinate with existing regulators such as MeitY, RBI, SEBI, TRAI and the Ministry of Health to oversee compliance, issue sector-specific guidelines, conduct algorithmic audits and promote transparency and accountability. (Yeung, 2018)
Mandatory Algorithmic Impact Assessments should also be introduced for all AI systems deployed in high-risk sectors that include healthcare, finance, education, and law enforcement. Algorithmic Impact Assessments (AIAs) are pre-deployment evaluations conducted to notice and mitigate expected risks associated with AI systems. They assess factors such as bias, discrimination, privacy, transparency, accuracy and possible impacts on fundamental rights before an AI system is deployed. Mandatory AIAs should be required for AI systems used in high-risk sectors such as healthcare, finance, education and law enforcement. (Cath et al., 2018).
Finally, AI governance should be harmonised with the DPDP Act, and the constitutional principles recognised in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), ensuring that technological innovation advances without compromising privacy, equality, and other fundamental rights.
Conclusion
The transformative potential of AI and its long-term legitimacy depend upon the development of an effective legal framework, capable of ensuring accountability, transparency, and respect for constitutional rights. Although India has introduced several policy initiatives, promoting responsible AI, its existing legal framework remains fragmented and is insufficient to effectively regulate high-risk AI systems effectively (NITI Aayog, 2021).
India should adopt a context-specific risk-based regulatory framework, inspired by the European Union AI Act, that combines innovation with enforceable safeguards while also adapting to India’s constitutional and socio- economic realities, and offers the most balanced approach. Such a framework would ensure proportionate regulation, strengthen public trust, provide legal certainty and promote responsible innovation without unnecessarily restricting technological development (European Union, 2024; OECD, 2019). By integrating enforceable safeguards with existing data protection laws and constitutional principles, India can establish a robust AI governance framework that protects both innovation and fundamental rights.
REFERENCES
Burrell, J. (2016). How the machine "thinks": Understanding opacity in machine learning algorithms. Big Data & Society, 3(1). here
Cath, C., Wachter, S., Mittelstadt, B., Taddeo, M., & Floridi, L. (2018). Artificial intelligence and the "good society": The US, EU, and UK approach. Science and Engineering Ethics, 24(2), 505–528. here
Digital Personal Data Protection Act, 2023, No. 22 of 2023, India.
European Parliament and Council. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).Official Journal of the European Union.
Floridi, L., & Cowls, J. (2019). A unified framework of five principles for AI in society. Harvard Data Science Review, 1(1). here
Information Technology Act, 2000, No. 21 of 2000, India.
Justice K. S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).
Ministry of Electronics and Information Technology. (2024). IndiaAI Mission.
Ministry of Electronics and Information Technology. (2025). India AI Governance Guidelines. Government of India.
NITI Aayog. (2018). National strategy for artificial intelligence: AI for All.
NITI Aayog. (2021). Responsible AI for All: Operationalizing principles for responsible AI.
Organisation for Economic Co-operation and Development. (2019). OECD principles on artificial intelligence. here
Pasquale, F. (2015). The Black Box Society: The secret algorithms that control money and information. Harvard University Press.
UNESCO. (2021). Recommendation on the ethics of Artificial Intelligence.
Wachter, S., Mittelstadt, B., & Floridi, L. (2017). Why a right to explanation of automated decision-making does not exist in the General Data Protection Regulation. International Data Privacy Law, 7(2), 76–99. here
Yeung, K. (2018). Algorithmic regulation: A critical interrogation. Regulation & Governance, 12(4), 505–523. here