MSME & Policy

No New Law, Three New Committees: How India's AI Governance Guidelines Will Actually Bind You

When MeitY released the India AI Governance Guidelines on 5 November 2025, the question that went around every compliance team I know was whether AI was now regulated in India. The answer given almost everywhere was no — the guidelines are voluntary, they create no new statute, they establish committees rather than a regulator. Relief followed. Budget lines for compliance were deferred to the next cycle.

That reading is accurate about the document and wrong about the consequence. I spent a long time inside the machinery that turns policy intent into obligation, and the lesson that stays with me is that in India a rule rarely arrives as a rule. It arrives as a procurement condition, a sectoral circular, a clause in a licence renewal. By the time it looks like regulation it has already been operating for two years.

What the document actually says

The guidelines rest on seven principles the drafters call sutras: trust is the foundation, people first, innovation over restraint, fairness and equity, accountability, understandable by design, and safety, resilience and sustainability. Read as a list they are unremarkable. Every national AI framework published since 2019 contains a version of them.

The institutional design is the part worth attention. Three bodies are created. The AI Governance Group is an inter-ministerial body giving policy direction and harmonising positions across departments. The Technology and Policy Expert Committee supplies the technical and strategic expertise that group will lean on. The AI Safety Institute is the operating arm — safety testing, standard-setting, international engagement.

And then the crucial move, which is easy to miss because it is phrased as restraint rather than assertion: the guidelines decline to propose a new AI statute. They hold instead that existing law already covers most of the ground. Four instruments are named — the Information Technology Act 2000, the Digital Personal Data Protection Act 2023, the Consumer Protection Act 2019, and the Copyright Act 1957.

Why "voluntary" is the wrong word to plan around

A framework that creates no new offence is not the same as a framework that creates no new exposure. What these guidelines do is tell every existing regulator in the country how to read the statute it already administers when the facts involve an AI system.

Consider what that means in practice. If your lending decisions are model-driven, the relevant question was never going to be whether an AI law exists. It is whether the Consumer Protection Act treats an automated denial you cannot explain as a deficiency in service. If you train on scraped material, the Copyright Act 1957 was already there, and the guidelines' own recognition that copyright sits inside the AI question tells you the argument has moved from theoretical to live. If you process personal data through a model, the DPDP Act applies to you today, with no AI-specific amendment required — a point that matters especially for smaller firms that assumed the exemptions would carry them, and which I have written about separately in the context of the DPDP startup exemption and what it does not cover.

The guidelines also flag an amendment they consider necessary rather than optional: updating the IT Act to define the roles of AI developers, deployers and users, and to clarify the scope of safe harbour and due diligence for generative and adaptive systems. That is not a philosophical note. Safe harbour is the provision that determines whether a platform answers for what passes through it. Any narrowing of it reallocates liability, and reallocated liability is felt long before the amendment is drafted, because commercial contracts start pricing it immediately.

The three routes by which this becomes binding

Guidance without a regulator still binds, and in India it does so along three well-worn paths.

The first is public procurement. Government and public sector undertakings are among the largest buyers of software in the country. Once an inter-ministerial body has published a position on what trustworthy AI looks like, that position propagates into tender conditions and technical qualification criteria with no legislative step at all. A vendor who cannot answer a question about model explainability does not get penalised; the vendor simply stops qualifying. I watched this happen with security certification and again with accessibility standards, and in both cases the market moved years ahead of the law.

The second is sectoral regulation. The guidelines explicitly leave enforcement with existing regulators, and the ones that matter for most organisations move quickly. The RBI has been directive about model risk in credit and about outsourcing. SEBI has views on algorithmic execution. The insurance and telecom regulators have their own instruments. None of them needs to wait for an AI Act to issue a circular that lands on your operations next quarter.

The third is contractual allocation. This is the one that arrives soonest and gets discussed least. Large customers respond to regulatory ambiguity by pushing warranties and indemnities down their supply chain. If you sell an AI-assisted service to a bank, you will find the bank's obligations reproduced in your master services agreement long before any regulator writes to you. The guidelines make that reallocation easier to justify, because they give a well-advised counterparty a document to cite.

What the committees will and will not do

It is worth being honest about the limits here, because there is a habit in Indian commentary of treating the creation of a body as the solution of a problem. Three bodies with advisory and coordinating mandates will not produce enforcement. They will produce standards, testing protocols, an incidents database, and eventually the technical vocabulary that regulators and courts borrow when they need one.

That last function is the important one, and it is slow. The value of the AI Safety Institute is not that it will police anybody. It is that in three years, when a dispute turns on whether a deployment was reasonable, there will be a published Indian standard to measure it against instead of an imported one. The guidelines set a phased path toward that — institutions and risk frameworks first, then standards and legislative amendment in the nine to twelve month band, then longer-term monitoring and any new statute.

Nine to twelve months for standards and amendments is not a long horizon for an organisation that has to change how it documents decisions.

What I would actually do

The instinct in most organisations will be to wait for clarity. That instinct is usually right and is wrong here, because the cost of the first step is low and the cost of taking it late is not.

Begin with an inventory rather than a policy. Most Indian organisations of any size cannot currently produce a list of where machine learning touches a decision that affects a person — credit, hiring, pricing, claims, content moderation. Until that list exists, no framework you adopt means anything, because you cannot apply it to systems you have not enumerated. This is unglamorous work and it is the whole foundation.

Then attach a named human to each item on that list. Accountability is one of the seven sutras and it is the one Indian institutions handle worst, because our default is to assign responsibility to a committee. A committee cannot be asked why a particular applicant was refused. Somebody has to be able to answer for each system, and that person should know they are the answer before anyone asks.

Third, write down what your models were trained on and what they were tested against, in whatever form you can manage now. Documentation created before a dispute is evidence. Documentation created after one is advocacy, and it reads that way. The same discipline applies whether the eventual questioner is a regulator, a customer's legal team, or an internal auditor — and it is closely related to the record-keeping gap I described in the context of agentic AI and the missing system of record.

None of that requires knowing what the eventual statute will say. All of it will be required whatever the statute says.

The pattern worth recognising

India has chosen, deliberately, to govern AI through its existing legal estate rather than through a new one. That is a defensible choice and probably the right one for a market at this stage of adoption. It is also a choice that shifts the burden of interpretation onto the governed. Where a dedicated statute tells you what is prohibited, a principles-based approach layered over four older laws tells you to work it out and be ready to defend your reasoning.

Organisations that treat the guidelines as a reprieve will spend the next year comfortable. Those that treat them as a description of how they are already being judged will spend it building the records that make the comfortable ones nervous in 2027.

Dr. Dibyendu Choudhury

Dr. Dibyendu Choudhury

Author of 9 published books. Retd. Govt. Employee (MoMSME) · MSME Policy Expert · Visiting Faculty at NI-MSME · Vedic Philosophy Scholar. Writing at the intersection of ancient Indian wisdom, modern entrepreneurship, and national policy.

Never Miss an Insight

Join 47,000+ readers — free fortnightly newsletter on MSME policy, Vedic wisdom & leadership.