UPSC CSE 2026 Essay Paper Discussion

AI Governance in India: Regulating Power Without Strangling Innovation

A UPSC Mains editorial on AI governance in India, balancing the IndiaAI Mission and IT Amendment Rules 2026 against the EU's risk-based AI Act.

The IndiaAI Mission rests on seven pillars

A voice that sounds exactly like a finance minister tells you to invest. A video of a cricketer endorses an app he’s never touched. A welfare database quietly drops a name, and a woman in a village learns she’s been delisted only when her ration stops. None of these is science fiction. All of them happened in India before any law was written to stop them. So the question isn’t whether artificial intelligence needs governing. It’s how you govern a technology that’s already rewriting power before the statute book has caught up.

That’s the real tension every aspirant has to hold. AI is now the engine of a national growth bet, with billions of rupees and a sovereign ambition riding on it. And AI is, at the same time, a new structure of power, one that can clone a voice, deny a benefit, or surveil a street with almost no one answerable for the harm. Regulate too hard and you smother the startups before they scale. Regulate too softly and you hand citizens to a system that owes them nothing. The mark-scoring problem is to do both at once.

The Issue, Framed

Start with the vocabulary, because most of the confusion around this topic comes from people using big words loosely. Let’s pin them down before the argument begins.

A foundation model is a very large AI system trained on huge amounts of data, the kind that can then be adapted to many tasks, write text, generate images, answer questions, without retraining from scratch. ChatGPT-style systems sit on foundation models. A deepfake is synthetic audio, image, or video that’s algorithmically generated or altered to look authentic, a fake that wears the face and voice of a real person. Algorithmic bias is what happens when an automated system produces systematically unfair outcomes, usually because it learned from skewed data or was deployed on people it wasn’t built for. And risk-based regulation is the design choice of regulating an application according to the harm it can cause rather than banning or freeing the underlying technology wholesale. Hold those four. The whole debate runs through them.

Now the Indian frame. The country is making two moves at once, and they pull in opposite directions. The first is a growth push. The IndiaAI Mission, approved by the Union Cabinet in March 2024 with an outlay of ₹10,371.92 crore over five years, is the government’s bet on building AI capacity, compute, datasets, skills, indigenous models, before regulation can choke it. That’s the accelerator.

The second is a brake. On 10 February 2026 the Ministry of Electronics and IT (MeitY) notified the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, effective 20 February 2026. These are India’s first binding rules on AI-generated content. They define “synthetically generated information,” force platforms to label it with visible marks and embedded provenance data, and tighten takedown clocks, court and government orders down to around 3 hours, intimate-image and impersonation deepfakes as fast as 2 hours. The “IT Rules” are subordinate rules made under the IT Act, 2000, not a fresh standalone law.

So here’s the framing that wins marks. India has chosen to accelerate and brake on the same road, without yet building the road, a dedicated AI law. The editorial peg that lit this up, The Hindu‘s 4 May 2026 OpED “AI and a gathering storm of unchecked power,” argues that AI has stopped being a mere tool and become a structure of power, concentrating authority in a handful of corporations and surveillance systems with little democratic oversight. That’s the deeper worry sitting under the policy detail.

What the Data Says

The numbers tell a split-screen story, ambition on one side, exposure on the other, and a Mains answer has to read both. Start with the ambition. India ranks 2nd in the world for AI talent, with roughly 50,460 AI authors and inventors, behind only the United States, per Stanford’s HAI AI Index 2025. So this isn’t a country short on brains. The IndiaAI Mission’s ₹10,371.92 crore is the financial scaffolding for that talent, including a plan to procure 10,000-plus GPUs, the specialised chips AI training runs on, through a public-private partnership.

But the same Stanford index flags the gap. India passed only one AI-related law across 2016 to 2025, even as it built world-class talent. That’s the legislative vacuum the brake-and-accelerator metaphor is pointing at. And the index records something sharper still: India showed the steepest rise of any major economy in public concern about AI use, up roughly 14 percentage points from 2024 to 2025. So the anxiety isn’t a fringe worry. It’s the fastest-growing public sentiment about this technology anywhere.

The harms aren’t projections either. In the two months before India’s 2024 Lok Sabha elections, an estimated 50 million-plus AI voice-clone calls went out, and the Election Commission directed parties to pull offending synthetic media within 3 hours of notice. Celebrity scam-deepfakes of business and sports figures multiplied through 2023 and 2024. Industry estimates of deepfake-driven fraud losses run into tens of thousands of crores, but treat those firmly as estimates, attributed to industry reporting, never as official figures.

Then the quiet harms, the ones with no headline. Documented work points to biometric authentication failures in Aadhaar-linked welfare hitting Dalit, women, and rural users hardest, and to back-end systems delisting people with no notice and no appeal. No statute today names who’s liable when an automated decision wrongly denies a benefit, the developer, the deployer, or the platform. That missing answer is the accountability gap in one line.

The IndiaAI Mission rests on seven pillars
The IndiaAI Mission rests on seven pillars.
India's light-touch path versus the EU's risk-based law
India’s light-touch path versus the EU’s risk-based law.

The Case For

The case for a light-touch, pro-innovation approach is genuinely strong, and an answer that pretends otherwise reads lazy. So let’s state it at full strength.

First, the catch-up imperative. India has the talent but almost no foundation-model base of its own. The IndiaAI Mission is a bet on building capacity first, GPUs, datasets, indigenous models, before heavy compliance arrives. Pile on EU-style obligations now and you risk crushing startups before they ever reach scale. You’d be regulating an industry India doesn’t yet have. So the sequencing argument is real: build, then govern.

Second, the technology outruns the statute. AI moves faster than any legislature can draft. Hard-code definitions into primary law and you risk freezing today’s categories into tomorrow’s obsolete rules. IT Minister Ashwini Vaishnaw has framed India’s logic as deliberately calibrated, leaving “space for innovation to flourish” while controlling the harms, mirroring the staged path India used for data privacy and telecom. A principles-first guideline you can update beats a rigid law you can’t.

Third, existing law already bites. The IT Act 2000, the Digital Personal Data Protection (DPDP) Act 2023, the new Bharatiya Nyaya Sanhita, and consumer and personality-rights law already cover most concrete AI harms, fraud, defamation, non-consensual imagery. India’s own IndiaAI Governance Guidelines, released in November 2025, lean on exactly this stack rather than proposing a new omnibus AI statute. So a fresh blanket law could be redundant overhead layered on rules that already apply.

Fourth, innovation is itself a public good here. India’s AI is already delivering for farmers, patients, and students through its digital public infrastructure, the shared digital rails like Aadhaar and UPI. Carnegie India’s work argues regulation should be rooted in “public benefit rather than fear.” Tax the upside with fear-driven rules and the people who lose most are the ones the tools were starting to help. And the design tradition India is leaning on isn’t a vacuum, NITI Aayog’s 2021 Responsible AI approach paper already set out seven principles, safety, inclusivity, equality, privacy, transparency, accountability, and the protection of positive human values, as a soft framework to grow into. So the official claim isn’t “no rules.” It’s “principles you can update faster than a statute.”

And fifth, the Brussels-effect trap. The EU AI Act’s compliance load is already criticised as a barrier to entry. A developing economy that imports that wholesale could end up entrenching dependence on the few foreign incumbents rich enough to afford the paperwork. So light-touch isn’t only about speed. It’s about not handing your own market away.

The Case Against

Here’s what the light-touch case walks past. “Light-touch” has a way of sliding into “no-touch,” and the harms it leaves unaddressed are already landing on real people. On that test, the gaps are serious.

Start with elections and information integrity. Fifty million-plus voice-clone calls in a single election cycle isn’t a hypothetical risk, it’s a documented assault on the democratic process, and it hits citizens’ wallets through scam-deepfakes at the same time. Voluntary corporate ethics didn’t stop it. The Election Commission’s 3-hour takedown orders were a scramble after the fact, not a system built in advance. So the argument that existing law “already bites” runs into the plain evidence that it didn’t bite hard enough or fast enough.

Then algorithmic bias, which produces exclusion now, not in some imagined future. When biometric authentication fails a daily-wage worker and her welfare entitlement vanishes, the harm is concrete and it falls on the people least able to fight back. Facial recognition has been deployed by police forces without clear statutory oversight. These systems affect rights, and they do it with no named authority to appeal to. A regime that’s relaxed about general-purpose chatbots can’t be equally relaxed about an algorithm deciding who eats.

Next, the accountability gap. No Indian statute today answers the basic question: who’s liable when an AI decision harms someone? Developer, deployer, platform, regulator? Voluntary ethics frameworks don’t create a remedy a citizen can actually use in a courtroom. A right with no remedy is decoration.

And the deepest worry, the one the editorial peg names directly. AI is increasingly a structure of power, concentrating authority in a few large corporations and in surveillance infrastructures that outrun democratic oversight. The Hindu‘s OpED frames this as a sovereignty and civil-liberties stake, not just consumer protection. (Its more dramatic illustrations, including casualty figures attributed to AI-enabled military targeting, are the author’s argument and should be cited to him, not stated as established fact.) When the stakes are power itself, “let the market self-regulate” stops being a neutral choice.

Finally, the legitimacy risk. With public concern about AI rising faster in India than almost anywhere, a state seen as absent loses trust precisely when it can least afford to. And it’s telling that the Centre itself has reportedly been weighing a stricter framework even while holding the light-touch line. The official position may be steadier in speeches than in fact.

Regulate by harm, not by the technology in the abstract
Regulate by harm, not by the technology in the abstract.

The Deeper Structural Read

Step back from the rules and the real fault line shows up. It isn’t “innovation versus regulation.” That framing is a trap, because it pretends the two are enemies. The sharper read is that India is choosing what kind of regulation, and the choice is between regulating the technology and regulating the harm.

The instinct of a nervous state is to regulate the technology, to define “AI” and write rules around the category. That’s what the EU’s standalone AI Act does, and it’s why it draws the Brussels-effect criticism. The smarter design, and the one India’s own guidelines gesture toward, is to regulate the outcome: who gets hurt, in what domain, with what severity. A recommendation engine and a policing algorithm are both “AI.” Treating them identically is the actual mistake, in either direction.

This is where the EU contrast earns its place in your answer, used as a mirror, not a model to copy. The EU AI Act (Regulation 2024/1689), the world’s first comprehensive AI law, sorts uses into four risk tiers: unacceptable uses are banned, high-risk uses carry heavy obligations, limited-risk uses, deepfakes among them, must be disclosed, and minimal-risk uses are left free. The logic is exactly right, calibrate the rule to the risk. The execution is what a developing economy can’t simply lift, because India’s compliance capacity and its industry’s maturity aren’t the EU’s. So borrow the logic, calibrate the intensity.

There’s a federalism layer underneath, too, the GS2 seam. Policing, public health, and welfare delivery sit substantially with the states, yet AI governance is being driven from the Union through MeitY and central rules. When a central instrument reaches into a state-run welfare roll or a state police camera network, the friction is structural, not partisan. Any durable architecture has to bring sectoral and state regulators in rather than centralise everything in one ministry.

And here’s the part that should sit with you as a future administrator. The state is one of the largest deployers of AI in the country, in welfare, in policing, in tax. So the question “who regulates AI” can’t have an answer that conveniently exempts the government’s own systems. A governance regime that disciplines private deepfakes but leaves a welfare algorithm unauditable hasn’t solved the accountability problem. It’s just chosen which citizens to protect.

One more layer makes this an India-specific story rather than a borrowed Western debate. Hosting the AI Impact Summit 2026 at Bharat Mandapam in February, with the New Delhi Declaration on AI Impact endorsed by roughly 89 countries and organisations, India positioned itself as a rule-shaper for the Global South, not a rule-taker copying Brussels or Washington. That ambition only holds up if the domestic regime is coherent. You can’t credibly write the world’s rules on inclusive, human-centred AI while leaving your own citizens without a remedy for an unaccountable algorithm at home. So the structural read isn’t only about harm and innovation. It’s about whether India’s external aspiration and its internal governance tell the same story.

What Should Be Done

So what does a sensible Indian architecture look like? Not a plea for “balance,” but a buildable design, regulate harm, not the technology in the abstract, and calibrate intensity to capacity. Seven moves, and none of them strangles innovation.

  1. Adopt harm-based, risk-tiered rules. Borrow the EU’s risk logic without its weight: binding obligations for high-risk uses in health, finance, policing, and elections, light-touch treatment for general-purpose AI. Reserve the hard rules for demonstrable harm, so most innovation stays free while the dangerous edge cases get watched.
  2. Give the synthetic-media rules statutory teeth. Build on the IT Amendment Rules 2026, labelling, provenance metadata, fast takedowns, and back them with primary legislation and proportionate penalties, while explicitly protecting satire, journalism, and education so the cure doesn’t gut free speech.
  3. Mandate algorithmic accountability for the state. Require bias audits and algorithmic impact assessments for government AI in welfare, policing, and credit, plus a right to explanation and appeal and a named authority answerable for automated decisions. This is the Digital Personal Data Protection Act ethic extended from data to decisions.
  4. Use sectoral regulators plus a coordinating body. Let the RBI, SEBI, IRDAI, health regulators, and the Election Commission own the risks in their domains, with MeitY and an inter-ministerial AI group coordinating to close gaps and prevent turf wars, the “whole-of-government” design Carnegie India argues for.
  5. Protect compute and talent sovereignty. Keep delivering the IndiaAI Mission, GPUs, datasets, skills, and Indian-language foundation models, so regulation doesn’t quietly hand the market to foreign incumbents. This ties directly to the broader digital public infrastructure story India is building.
  6. Stand up a national AI Safety Institute. A public-interest body for evaluation, red-teaming, standards, and incident reporting, institutionalising the Mission’s “Safe and Trusted AI” pillar and the commitments India made hosting the AI Impact Summit 2026 in New Delhi.
  7. Anchor everything in rights and due process. Tie the whole structure to DPDP Act enforcement and to Articles 14, 19, and 21, equality, free expression, privacy, so those guarantees are the floor, not an afterthought bolted on later.

Every one of these regulates a harm, not a tool. That’s the difference between a regime that protects citizens and one that just slows down builders. India’s “MANAV” framing from the 2026 Summit, the acronym Prime Minister Modi unveiled for moral, accountable, sovereign, accessible, and legitimate AI, points the same way: human at the centre, technology in service. (Note it’s the AI-vision acronym, not the older genomics project of a similar name.)

For Your Mains Answer

This topic is a GS3 anchor with a clean GS2 bridge. It lets you move from science and technology into governance, rights, and federalism in a single, tightly argued frame, which is exactly the kind of cross-paper synthesis that scores.

GS paper mapping: GS3, science and technology developments and applications, indigenisation, internal security through communication networks, the economy of AI. GS2, government policies and regulatory design, statutory and regulatory bodies, transparency and accountability in governance, and fundamental rights.

Likely question frames:

  • “India must regulate the harms of artificial intelligence without strangling its innovation.” Critically examine in light of the IndiaAI Mission and the IT Amendment Rules, 2026.
  • A light-touch approach to AI risks becoming a no-touch approach. Discuss with reference to algorithmic accountability and information integrity in India.
  • Compare India’s principles-first AI governance with the EU’s risk-based AI Act, and suggest a calibrated architecture suited to Indian conditions.

Quotable data points:

  • ₹10,371.92 crore, the IndiaAI Mission outlay over five years, approved March 2024, including 10,000-plus GPUs via PPP.
  • IT Amendment Rules, 2026, notified 10 February, effective 20 February 2026, India’s first binding regime for labelling synthetically generated content, with takedown windows as short as 2 to 3 hours.
  • 2nd in the world for AI talent (~50,460 authors and inventors), yet only one AI-related law passed 2016 to 2025.
  • India’s sharpest-in-class rise, roughly +14 percentage points, in public concern about AI, 2024 to 2025.
  • 50 million-plus AI voice-clone calls before the 2024 Lok Sabha elections; ECI 3-hour takedown directive.
  • EU AI Act (Regulation 2024/1689): four risk tiers, the first comprehensive AI law, in force from August 2024.

Keywords to use: foundation models, synthetically generated information, provenance and watermarking, algorithmic bias, algorithmic accountability, risk-based regulation, light-touch and co-regulation, compute sovereignty, AI-as-power, information integrity.

Syllabus linkages: awareness in IT and AI; internal security through communication networks; government policies and interventions; regulatory bodies; transparency and accountability; fundamental rights; India and global groupings.

Balanced conclusion line: The goal isn’t to choose between innovation and safety but to regulate AI’s harms precisely enough that the technology stays free to build and the citizen stays free from unaccountable power, regulating the harm, never the imagination.

How to Build the Answer

Open on the conflict, not a definition. The tension, that AI is both a growth engine and a structure of power, tells the examiner in one line that you’ve grasped the policy problem and the value clash at once. Drop a one-line definition of a deepfake or a foundation model in the second sentence, where it supports the argument rather than delaying it.

Bring data early but ration it. A strong first body paragraph can carry three figures, ₹10,371.92 crore, 2nd in AI talent, 50 million voice-clone calls, and then say what each proves. UPSC rewards the move from fact to inference, so the number is the anchor and the “this means” is the mark.

Steelman the side you don’t favour. If you back stronger guardrails, first concede why light-touch has a real rationale, the catch-up imperative, the pace of the technology. If you back light-touch, first admit the documented harms. That’s how an answer reads balanced without going vague.

Group the way forward, don’t scatter it. Cluster the reforms, risk-tiered rules, statutory backing for the synthetic-media rules, algorithmic accountability for the state, sectoral regulators with a coordinating body, compute sovereignty, an AI safety institute, rights as the floor. Use the topic’s own vocabulary so it reads as governance analysis, not a news recap.

Common Mistakes to Avoid

  • Don’t reduce it to “AI is good or bad.” The examiner wants design, what to regulate, how hard, and who enforces it, not a verdict on the technology.
  • Don’t confuse the IT Rules with a standalone AI law. India has subordinate rules under the IT Act, 2000, not a dedicated AI statute. Saying otherwise is a factual error that costs you.
  • Don’t copy the EU Act wholesale. Use it as a contrast and a source of logic, then explain why India calibrates intensity to its own capacity.
  • Don’t state estimates as facts. Deepfake-fraud loss figures and OpED casualty claims are estimates or arguments, attribute them, don’t assert them.
  • Don’t forget the citizen. Name the welfare beneficiary wrongly delisted, the voter targeted by a clone call. Governance answers that name who’s at risk score higher.

A Compact Answer Spine

  1. Introduction: Frame the accelerator-versus-brake tension in one sentence; define a deepfake or foundation model in the next.
  2. Evidence: Two or three attributed figures, each tied to an implication, ambition on one side, harm on the other.
  3. Arguments: The case for light-touch (catch-up, pace, existing law), then the case for guardrails (elections, bias, accountability, power). Keep both fair.
  4. Structural diagnosis: The real choice is regulating harm versus regulating the technology; calibrate intensity to capacity; mind the federal seam.
  5. Way forward: Five to seven grouped reforms, each with a clear actor, MeitY, sectoral regulators, an AI safety institute, the courts.
  6. Conclusion: Adapt the balanced line to the exact question wording.

Diagram or Flowchart Idea

For a 15-marker, draw one ascending harm ladder rather than a decorative mind map: minimal-risk tools (light-touch) → synthetic media (labelling and provenance) → election deepfakes and scams (fast takedown plus penalties) → welfare, credit, and policing algorithms (bias audit, impact assessment, appeal) → frontier models and mass surveillance (strongest oversight, safety-institute evaluation). The examiner reads the calibration logic in five seconds.

For a 10-marker, skip the diagram and use a two-column table, “India (light-touch)” against “EU (risk-based),” covering instrument, philosophy, structure, deepfake rule, and standalone law. It does more work and is faster to evaluate under time pressure.

Ethics and Governance Angle

Add one ethical line even in a GS3 answer. The deepest question here isn’t efficiency, it’s who answers when an impersonal system causes harm. Name the concrete person: the daily-wage worker dropped by a biometric failure, the voter deceived by a cloned voice. Naming that citizen sharpens the answer and signals you see governance as a service to people, not an exercise in administration.

Then convert empathy into design. Don’t just say “protect the vulnerable.” Say how: bias audits for state AI, a right to explanation and appeal, a named accountable authority, satire and journalism protected from over-broad takedowns. That’s the move from moral language to administrative maturity.

A sentence pattern that travels across topics: “The use is legitimate in aim, but its legitimacy depends on accountability, proportionality, and a remedy the citizen can actually reach.” It accepts the state’s objective without handing it a blank cheque, which is exactly what a balance question rewards.

How to Use Data Without Sounding Mechanical

Use fewer numbers than you know. Three explained figures beat ten scattered ones. Lead with one big number for scale (₹10,371.92 crore), use a second for contrast (2nd in talent, only one AI law), and use a third to prove the harm (50 million voice-clone calls). One ambition figure, one paradox, one harm is usually enough.

Never leave a statistic standing alone. Follow it with “this means” or “the policy implication is.” That small move turns a fact sheet into analysis. In Mains, facts are raw material; judgment is the finished answer.

Finish by asking whether a tired examiner can follow your answer in a single pass. Short introduction, data early, two sides marked cleanly, a grouped way forward. Clarity isn’t a lower standard than depth, it’s how depth becomes visible. Cut any line that sounds impressive but does no work, and replace it with a fact, a cause, a consequence, or a reform. Write for marks, not for noise. Always be specific.

FAQ

Does India have a dedicated AI law?

No. As of 2026, India governs AI through existing statutes, the IT Act 2000, the DPDP Act 2023, consumer and sectoral law, plus subordinate rules like the IT Amendment Rules 2026 and the non-binding IndiaAI Governance Guidelines. It has deliberately avoided a standalone, EU-style AI Act, calling its approach light-touch and pro-innovation.

What do the IT Amendment Rules, 2026 actually require?

Notified on 10 February and effective 20 February 2026, they define “synthetically generated information,” require platforms to prominently label such content and embed provenance metadata with a unique identifier, make significant social media intermediaries collect user declarations about synthetic content, and tighten takedown windows, court and government orders to around 3 hours and intimate-image or impersonation deepfakes as fast as 2 hours.

How is India’s approach different from the EU AI Act?

The EU AI Act (Regulation 2024/1689) is a binding, standalone law that sorts uses into four risk tiers, unacceptable, high, limited, and minimal. India has chosen a principles-first, light-touch path built on existing laws and sectoral regulators, with no single AI statute. The EU regulates the technology comprehensively; India aims to regulate specific harms.

What’s the strongest argument for regulating AI harder in India?

That the harms are already here, not hypothetical, 50 million-plus voice-clone calls before the 2024 elections, biometric welfare failures excluding the poor, and no statute naming who’s liable for a harmful automated decision. With public concern about AI rising faster in India than almost anywhere, a state seen as absent risks both real harm and lost legitimacy.

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Written by

Jwala Kumar Sir

Jwala Kumar teaches Science and Technology at Anantam IAS. He covers space, biotechnology, quantum computing, defence systems and cybersecurity, explaining the underlying science first so aspirants can read a new mission or policy announcement without waiting for a coaching handout.

Preparing for UPSC CSE 2026? Sit in a free demo class.

No sales call. No brochure. Watch a real Monday-morning GS session taught by ex-Rau's IAS faculty.