India’s Emerging AI Law: Autonomy, Consent and Regulatory Sandboxes
Why in News?
The India AI law debate entered a new phase on 22 July 2026 after The Indian Express reported that the Ministry of Electronics and Information Technology, or MeitY, is examining a standalone statute rather than placing all new provisions under the Information Technology Act, 2000.
The reported design questions concern limits on agentic AI autonomy, consent for synthetic use of a person’s likeness or voice, allocation of model liability, and regulatory sandboxes for high-impact applications. No draft Bill was publicly released with the report, so these elements should be read as proposals under examination, not settled law.
- The cyber laws division of MeitY has reportedly been asked to analyse gaps in the Information Technology Act, 2000 and rules framed under it.
- The government is expected to examine how independently an AI agent may act and whether it may retain and reuse data after completing a task.
- A proposed consent-based framework would address synthetic media made from a person’s image, video or voice without permission.
- The report says two private-sector legal experts were asked to prepare separate liability frameworks for AI models.
- Consultation with the Reserve Bank of India and SEBI is reportedly contemplated for sandboxes in finance and public services.
The development matters in the context of:
- India already regulates synthetic media through the IT Rules, 2021 as amended in 2026; a new statute would have to fit this existing layer rather than start from zero.
- The central policy challenge is to assign responsibility across the AI value chain without treating every low-risk tool like a system that can affect credit, welfare, policing or critical infrastructure.
- The issue links innovation policy with privacy, dignity, free speech, consumer protection, cybersecurity and administrative accountability.

UPSC Relevance
Prelims Relevance
- MeitY administers the Information Technology Act, 2000 and the intermediary-rule framework relevant to online AI harms.
- Agentic AI can plan a sequence of actions, invoke external tools and adapt its steps toward a user-defined objective with limited supervision.
- Section 79 of the IT Act provides conditional exemption from liability to intermediaries for third-party information when statutory conditions and due diligence are met.
- The 2026 SGI amendments to the IT Rules took effect on 20 February 2026 and created specific duties concerning realistic synthetic audio, visual and audio-visual information.
- Under amended Rule 3(3), covered intermediaries must use reasonable technical measures against unlawful SGI and label permissible SGI with provenance mechanisms where technically feasible.
- A significant social media intermediary must seek a user declaration and use reasonable technical measures to verify whether uploaded content is SGI before publication.
- The DPDP Act, 2023 excludes personal data made publicly available by the Data Principal from its application; its provisions have a staggered commencement.
- A regulatory sandbox permits bounded live testing under specified users, duration, safeguards and regulatory supervision; it is not a general exemption from law.
- The India AI Governance Guidelines organise policy around seven sutras and favour a risk-based, evidence-led, proportional and sectorally enforced approach.
Mains Relevance
GS Paper 2
- Examine how a standalone AI law can protect privacy, dignity and free expression while preserving procedural safeguards and judicial review.
- Assess the institutional design needed for coordination among MeitY, sectoral regulators and standards bodies in a cross-sector technology.
- Analyse accountability when AI is deployed in welfare delivery and public administration, including notice, explanation, human review and remedy.
GS Paper 3
- Discuss the security and systemic risks created by autonomous AI agents with access to data, payment rails, software tools or critical systems.
- Evaluate regulatory sandboxes as a way to test high-impact AI while containing consumer, market and cybersecurity risks.
- Compare platform safe harbour with the more complex responsibility of a model developer or deployer whose system helps generate the disputed output.
Essay
- Innovation earns legitimacy when human agency remains stronger than machine autonomy.
- In the digital age, consent concerns not only data collection but also the recreation of identity.
- Good regulation builds trust by making power traceable, contestable and answerable.
Background and Context
From principle-based guidance to possible legislation
India’s current AI-governance architecture combines existing law, sectoral oversight, voluntary standards and technical safeguards.
- The India AI Governance Guidelines identify seven principles: trust, people first, innovation over restraint, fairness and equity, accountability, understandable-by-design systems, and safety, resilience and sustainability.
- The guidelines recommend an AI Governance Group, a Technology and Policy Expert Committee and an AI Safety Institute, while leaving sectoral regulators responsible within their mandates.
- Their action plan includes reviewing legal gaps, drafting laws as risks evolve and piloting regulatory sandboxes in high-risk domains.
- A standalone statute would mark a shift from relying mainly on existing technology, data, consumer, criminal and sectoral laws.

What makes agentic AI a distinct regulatory problem
A chatbot mainly returns an answer, while an AI agent may take a chain of consequential actions in digital or physical systems.
- An agent may break a goal into tasks, call an application programming interface, browse records, write code, send instructions or initiate a transaction.
- Risk rises with the agent’s permissions, persistence and reach, not merely with the size of its underlying model.
- Data retention creates a second risk: an agent that remembers credentials, health details or work files may reuse them beyond the original context.
- High-impact uses need human approval gates before irreversible acts such as transferring money, denying a benefit, modifying a public record or controlling critical equipment.
- Practical controls include least-privilege access, time-limited credentials, action logs, spend limits, secure execution environments, rollback mechanisms and an effective stop control.
- These controls complement the broader discussion in India’s AI accountability framework for critical infrastructure and cybersecurity.
Deepfake consent beyond a disclosure label
Labelling tells viewers that media is synthetic; consent asks whether the person’s identity could be used to create or circulate it at all.
- The amended IT Rules define synthetically generated information around realistic synthetic audio, visual or audio-visual depictions of a person or event; pure text alone is outside this special definition.
- Permitted SGI must carry a clear label and, where technically feasible, permanent metadata or another provenance mechanism identifying it and the generating resource.
- Covered platforms must prevent unlawful categories such as non-consensual intimate imagery, deceptive impersonation, false electronic records and certain synthetic material involving weapons or explosives.
- The existing rules focus heavily on platform due diligence, labelling and removal. A consent framework could separately specify permission for capturing, cloning, training on, generating and distributing a person’s likeness or voice.
- Consent should be specific, informed, purpose-bound and withdrawable; a single acceptance for one advertisement shouldn’t silently authorise reuse in another product or political message.
- The problem is illustrated by non-consensual AI sexual deepfakes, where dignity and bodily privacy harms can become irreversible before ordinary notice-and-takedown processes finish.
Liability across the AI value chain
AI output can involve several actors, so liability should follow control, knowledge, duty and causal contribution rather than attach automatically to one entity.
- The developer designs or trains the model, the deployer integrates it into a service, the operator sets the objective, and an intermediary may host or distribute the result.
- A model provider may control safety testing and capability restrictions; a deployer may control sector data and approval workflows; a user may intentionally prompt deception or bypass safeguards.
- The classic safe-harbour logic for passive hosting doesn’t map neatly onto systems that generate, rank, transform or act on information, but Section 79 questions still require a fact-specific legal test.
- A proportionate framework can distinguish ordinary negligence, breach of a statutory duty, reckless deployment and intentional misuse instead of imposing undifferentiated strict liability.
- Documentation should support attribution: model and system cards, evaluation results, incident logs, tool-call records, version histories and notices to affected persons.
- For government deployment, accountability can’t be outsourced to a vendor. The public authority must remain answerable for legality, non-discrimination, reasons and an accessible appeal.
How a risk-based regulatory sandbox should work
A sandbox is useful when the regulator needs evidence from controlled deployment before deciding how a rule should apply.
- The RBI regulatory sandbox allows live testing in a controlled environment, while SEBI’s framework uses limited users, defined test periods and regulator-set conditions.
- An AI sandbox should begin with a precise use case, risk hypothesis and exit criterion, not a broad permission to experiment on the public.
- Entry conditions should require impact assessment, lawful data access, cybersecurity testing, red-team results, human oversight and a named accountable officer.
- Test boundaries should cap users, geography, transaction value, duration, autonomy and the categories of data an agent may retain.
- Participants need informed notice, an easy opt-out, compensation and grievance routes, while vulnerable people shouldn’t bear disproportionate experimentation risk.
- A sandbox must not waive core duties under privacy, consumer protection, anti-discrimination, criminal or sectoral law; any relaxation should be specific, temporary and published.
Constitutional and governance safeguards
AI regulation is credible only when it protects people from both private technological power and arbitrary state action.
- Article 21 protects life and personal liberty, with privacy and dignity central to consent, surveillance, profiling and synthetic-identity harms.
- Article 19(1)(a) protects speech and expression; restrictions on deceptive or unlawful synthetic media must remain within Article 19(2) and avoid vague over-removal.
- Article 14 requires non-arbitrary state action, making bias testing and reasoned human review important when an automated system affects rights or benefits.
- Rules should provide notice, an intelligible explanation, a channel for correction and human reconsideration when a consequential automated decision is challenged.
- Independent audits must protect trade secrets without making secrecy a shield against regulatory inspection or an affected person’s right to an effective remedy.
- India’s diversity requires testing across languages, dialects, disability contexts and social groups; imported benchmarks may miss locally concentrated harms.
Way Forward
Define scope before obligations
- Separate general-purpose models, deployers, agents, high-impact systems and distribution platforms so that duties match actual control.
- Publish clear thresholds for high-impact use based on rights, safety, scale, reversibility and vulnerability, with periodic review as capabilities change.
Build consent and provenance together
- Require verifiable permission for cloning an identifiable person’s face or voice, alongside durable labelling and content-provenance signals.
- Create a rapid, victim-centred process for removal, evidence preservation, account action and remedy in impersonation and intimate-image cases.
Control autonomous action
- Mandate least privilege, bounded memory, tool allow-lists, transaction caps, monitoring and human confirmation for irreversible high-risk actions.
- Require pre-deployment evaluation and post-deployment incident reporting, with stronger duties when systems operate in finance, health, welfare or critical infrastructure.
Make sandboxes accountable
- Coordinate MeitY with RBI, SEBI and other sectoral regulators through common minimum safeguards and domain-specific conditions.
- Publish sandbox objectives, exemptions, aggregate results and exit decisions so experimentation produces reusable regulatory knowledge.
Conclusion
A standalone AI law can add value if it closes identifiable gaps around autonomous action, synthetic identity, value-chain liability and high-impact testing. Simply adding another broad statute could instead multiply overlap and uncertainty.
The durable approach is risk-based and rights-preserving: keep humans answerable for consequential systems, trace synthetic content, place liability where control lies, and allow experimentation only inside transparent boundaries. That is how India can pair innovation with public trust.
UPSC Practice Questions
Prelims MCQ 1
With reference to India’s framework for synthetically generated information (SGI), consider the following statements:
- The SGI-specific definition under the amended IT Rules is limited to audio, visual or audio-visual information meeting the prescribed realism threshold.
- Routine good-faith colour correction that doesn’t materially misrepresent the underlying content is excluded from SGI.
- Pure text generated by a chatbot is always classified as SGI under the special definition.
How many of the above statements are correct?
(a) Only one (b) Only two (c) All three (d) None
Answer: (b) Only two
Explanation:
Statements 1 and 2 are correct. The amended IT Rules’ SGI definition focuses on realistic synthetic audio, visual and audio-visual content. Text-only output isn’t SGI under that special definition, though unlawful text remains subject to other legal duties.
Prelims MCQ 2
Which one of the following best describes a regulatory sandbox?
(a) A permanent exemption from all laws for technology firms (b) A private laboratory operating without regulatory supervision (c) Controlled live testing under defined boundaries and regulatory oversight (d) A compulsory certification that guarantees a product is risk-free
Answer: (c) Controlled live testing under defined boundaries and regulatory oversight
Explanation:
A regulatory sandbox permits bounded testing with specified users, duration, safeguards and regulator-set conditions. It neither guarantees safety nor creates a blanket immunity from applicable law.
UPSC Mains Questions
- A future Indian AI law must govern autonomous action rather than merely regulate model output. Discuss the distinctive risks of agentic AI and suggest a proportionate framework of permissions, human oversight, auditability and liability for high-impact deployments. (15 marks, 250 words)
- Deepfake labelling improves transparency but doesn’t fully answer the question of consent. Examine how India can protect likeness, voice, privacy and dignity while preserving legitimate journalism, satire, art and public-interest expression. (15 marks, 250 words)
- Regulatory sandboxes can help the state learn from innovation, but they can also transfer experimentation risks to citizens. Evaluate the safeguards needed for sandboxes involving AI in finance and public services. (10 marks, 150 words)
Sources: MeitY: India AI Governance Guidelines and The Indian Express.
Frequently Asked Questions
Is India’s standalone AI law already enacted?
No. The 22 July 2026 report describes issues under government examination, and no draft Bill accompanied it. India already has AI-relevant rules under the IT Act, the amended IT Rules and other laws, but the proposed standalone statute’s final scope, wording and legislative timetable remain unsettled.
What is agentic AI?
Agentic AI is a system that can plan several steps, call external tools, adapt its approach and act toward a high-level goal with limited supervision. Its risk depends heavily on permissions, data access, memory and whether it can make irreversible decisions or transactions.
How are deepfakes regulated now?
The IT Rules, as amended in 2026, impose SGI-specific duties involving prevention of unlawful synthetic content, prominent labelling, provenance mechanisms and stronger verification by significant social media intermediaries. Faster removal duties also apply to specified impersonation, morphed and intimate content.
Why is consent different from labelling?
A label helps an audience recognise that media is synthetic. Consent concerns whether a person’s face, voice or identity could be captured, cloned, generated and distributed for that purpose. A labelled deepfake may still violate privacy, dignity, contract or another applicable law.
Who may be liable for AI harm?
Responsibility may lie with different actors: the developer, model provider, deployer, operator, user or distribution platform. A sound framework would examine each actor’s control, knowledge, duty, safeguards and causal contribution instead of assigning every failure to one participant.
Does a regulatory sandbox waive all laws?
No. A sandbox is a controlled testing arrangement with limited scope, duration, users and regulator-set conditions. Any relaxation should be specific and temporary. Core duties involving privacy, consumer protection, cybersecurity, criminal law and sectoral safeguards should continue to protect participants.