Preprint
Article

This version is not peer-reviewed.

India’s AI Policy Landscape: A Policy Critique of Strategy, Governance, Rights, and State Capacity

Submitted:

22 June 2026

Posted:

24 June 2026

You are already at the latest version

Abstract
India’s artificial intelligence (AI) policy landscape has rapidly matured from an aspirational innovation strategy into a deeply layered governance architecture. This framework now encompasses a nationwide development strategy. The macro-level policy trajectory remains consistent: catalyze domestic innovation, leverage systems for developmental objectives, and consciously avoid ex-ante regulations that might stifle the domestic ecosystem. India relies on a pragmatic matrix of existing statutory laws, targeted legislative amendments, voluntary industry standards, and progressive institutional risk management capacity-building. This architecture possesses substantial structural strengths, particularly in its attention to socio-economic inclusion, public-interest, state capacity enhancement, and the unique utilization of Digital Public Infrastructure (DPI). Yet, it domain contains unresolved internal structural tensions. While India’s foundational strategy and guidance documents consistently employ a rights-affirming vocabulary, the operative statutory mechanisms and enforcement pathways frequently create an architecture where innovation policy appears decoupled from enforceable civil rights, and state discretion is more robustly specified than safeguards. This paper presents a critical reading of this landscape, evaluating its primary strengths, internal systemic contradictions, legal-policy gaps, and the practical difficulties likely to arise during implementation on the ground.
Keywords: 
;  ;  ;  ;  ;  
Subject: 
Social Sciences  -   Government

India’s AI Policy Landscape: A Policy Critique of Strategy, Governance, Rights, and State Capacity

India’s artificial intelligence (AI) policy landscape has rapidly matured from an aspirational innovation strategy into deeply layered governance architecture (Ministry of Electronics and Information Technology [MeitY], 2025). This framework encompasses a nationwide development strategy, codified responsible AI principles, sector-specific regulatory interventions, horizontal privacy legislation, updated cyber law, and emerging governance guidelines (NITI Aayog, 2018; MeitY, 2023; MeitY, 2025). The macro-level policy trajectory remains consistent: catalyze domestic technological innovation, leverage algorithmic systems for public-interest and developmental objectives, and consciously avoid premature or compliance-heavy ex-ante regulations that might stifle the domestic ecosystem (NITI Aayog, 2018; MeitY, 2025). Instead, India relies on a pragmatic matrix of existing statutory laws, targeted legislative amendments, voluntary industry standards, and progressive institutional capacity-building to monitor and mitigate emerging risks (MeitY, 2025).
This architecture possesses substantial structural strengths, particularly in its attention to socio-economic inclusion, public-interest application deployment, state capacity enhancement, and the unique utilization of Digital Public Infrastructure (DPI) (NITI Aayog, 2018; MeitY, 2025). It reflects a grounded, practical understanding that AI governance cannot be imported wholesale from foreign models such as the European Union or the United States, as it must remain responsive to domestic socio-economic realities (NITI Aayog, 2018; MeitY, 2025).
Yet, this policy domain contains unresolved internal structural tensions. While India’s foundational strategy and guidance documents consistently employ a rights-affirming vocabulary – emphasizing individual privacy, informational autonomy, algorithmic fairness, accountability, and robust human oversight – the operative statutory mechanisms and enforcement pathways frequently create an architecture where innovation policy is decoupled from enforceable civil rights, and state discretion is more robustly specified than citizen safeguards (NITI Aayog, 2018; MeitY, 2023; MeitY, 2025). This paper presents a critical reading of this landscape, evaluating its primary strengths, internal systemic contradictions, legal-policy gaps, and the practical difficulties likely to arise during implementation on the ground.

Evolution of the Governance Architecture

India’s AI governance model rests upon at least six distinct, overlapping strategic and legislative layers (NITI Aayog, 2018; MeitY, 2023; MeitY, 2025). The baseline was established by NITI Aayog’s 2018 National Strategy for Artificial Intelligence, which framed the country’s macro vision around the ethos of “AIforAll” (NITI Aayog, 2018; MeitY, 2025). This foundational document directed public and private focus toward sectors capable of yielding the highest social externalities: healthcare, agriculture, education, smart cities, and smart mobility (NITI Aayog, 2018).
Subsequently, NITI Aayog’s Responsible AI for All series (2021a, 2021b, 2022) attempted to operationalize these abstract aspirations into concrete design and system considerations (NITI Aayog, 2021a). These documents explored risks such as algorithmic opacity, safety-critical failures, and data privacy vulnerabilities, utilizing Facial Recognition Technology (FRT) as a specific use-case stress test to evaluate the efficacy of ethical benchmarks (NITI Aayog, 2021a).
This evolution culminated in MeitY’s publication of the India AI Governance Guidelines (2025), shifting national policy from high-level principles to structural governance design (MeitY, 2025). The Guidelines structure national oversight around seven fundamental “sutras” or principles: Trust, People First, Innovation over Restraint, Fairness & Equity, Accountability, Understandable by Design, and Safety, Resilience & Sustainability (MeitY, 2025). These core principles were explicitly adapted from the framework developed by the Reserve Bank of India’s (RBI) FREE-AI Committee Report (2025), establishing a cross-sectoral, technology-agnostic baseline designed to apply across all digital spaces and regulatory purviews (MeitY, 2025).
Statutorily, these principles interact directly with horizontal frameworks: the Digital Personal Data Protection (DPDP) Act, 2023, which governs the processing of digital personal data (MeitY, 2023; MeitY, 2025); the Information Technology (IT) Act, 2000, which remains the structural backbone for platform classification, intermediary liability, and cybersecurity monitoring (MeitY, 2025); and the Department for Promotion of Industry and Internal Trade’s (DPIIT) Working Paper on Generative AI and Copyright (2025), which encapsulates the ongoing legal and economic contentions surrounding mass unlicensed data ingestion for machine learning models (DPIIT, 2025).

Prominent Strengths of the Current Framework

A defining strength of the Indian model is its refusal to reduce AI technology policy to industrial competitiveness or top-line fiscal growth alone (NITI Aayog, 2018). By indexing national capability directly to distributive purpose, public service delivery, and the mitigation of historical access barriers, the policy matrix ensures that public funding and strategic alignments target systemic welfare objectives (NITI Aayog, 2018; MeitY, 2025).
Furthermore, the framework demonstrates a highly developed ecosystem perspective (MeitY, 2025). The 2025 Guidelines explicitly recognize that safe, trustworthy, and inclusive AI deployment cannot occur in an infrastructural vacuum (MeitY, 2025). The emphasis on public enablers – such as expanding data availability through the AIKosh platform, the Open Government Data Platform, and the National Data and Analytics Platform – reflects an understanding of the material components required to support non-monopolistic innovation (MeitY, 2025). Critically, the framework notes that providing access to reliable, representative, and standardized “evaluation datasets” and computational infrastructure is a prerequisite for developers to perform safety evaluations and for public authorities to validate the effectiveness of guardrails at population scale (MeitY, 2025).
The framework has also evolved from broad ethical manifestos to actionable risk management instruments (MeitY, 2025). The 2025 Guidelines categorize risks based on empirical markers of harm, mapping out distinct mitigation paths for malicious uses (such as deepfakes), algorithmic discrimination, transparency failures, systemic risks, and national security threats (MeitY, 2025). By recommending specific techno-legal interventions – including content authentication, dataset provenance tracking, incident reporting, and mandatory human-in-the-loop mechanisms – the policy moves toward a structured regime of “compliance-by-design” (MeitY, 2025).
Finally, India’s approach correctly avoids the pitfall of an omnibus, technology-specific statue that regulates the underlying technology in the abstract (MeitY, 2025). Instead, it prefers a sector-led, distributed model that applies existing statutory laws to specific algorithmic applications (MeitY, 2025). The framework acknowledges that AI harms materialize with unique domain-specific characteristics, requiring the expert implementation of distinct oversight bodies – ranging from the RBI’s financial risk protocols and SEBI’s market integrity frameworks to the Telecommunication Engineering Centre’s (TEC) fairness assessment ratings and the Indian Council of Medical Research’s (ICMR) ethical guidelines for biomedical automation (MeitY, 2025).

Internal Policy Tensions and Contradictions

The most significant institutional contradiction within the landscape is the structural disconnect between rights-affirming principles and expansive state exceptions (NITI Aayog, 2021a; MeitY, 2023). NITI Aayog’s responsible AI papers consistently emphasize the principles of constitutional morality, informational autonomy, purpose limitation, and meaningful consent (NITI Aayog, 2021a).
However, the operative statutory reality under the DPDP Act, 2023 contains wide-ranging carve-outs for public authorities (MeitY, 2023). Section 17 of the Act explicitly permits the Central Government to exempt notified instrumentalities of the state from core data protection obligations – including notice requirements, collection limitations, and data erasure duties – in the interests of state security, sovereignty, public order, or the performance of sovereign functions (MeitY, 2023). Consequently, a deep policy friction emerges: while private entities face rigorous compliance mandates and severe financial penalties, state agencies operate with wide executive discretion, creating potential vulnerabilities where automated administrative systems intersect with the delivery of public benefits (MeitY, 2023; MeitY, 2025).
There is a parallel tension between horizontal data minimization rules and the fundamental data ingestion logic of frontier AI systems (MeitY, 2023; MeitY, 2025). The statutory architecture of the DPDP Act, 2023 is built around the premise of specific, bounded, and unconditional consent for defined use cases (MeitY, 2023). Yet, the 2025 Guidelines openly acknowledge that core privacy doctrines like collection and purpose limitation sit uneasily with contemporary general-purpose and multimodal AI models (MeitY, 2025). These models rely on the massive ingestion, continuous processing, and emergent downstream repurposing of large-scale datasets, leaving the practical boundaries of research and “legitimate use” exceptions highly contested (MeitY, 2023; MeitY, 2025).
Furthermore, an institutional contradiction exists between India’s pro-innovation regulatory forbearance and its demands for structural liability (MeitY, 2025). The 2025 Guidelines favor an agile, flexible model that relies heavily on industry-led voluntary codes, self-certifications, and regulatory sandboxes with localized legal immunities (MeitY, 2025). While this soft-governance approach reduces administrative friction during the nascent stage of ecosystem development, it conflicts with the parallel policy mandate to enforce predictable liability and protect citizens from systemic harms affecting livelihoods, personal liberty, or critical infrastructure (MeitY, 2025).
A structural mismatch also persists regarding platform classification and intermediary safe-harbors under the Information Technology Act, 2000 (MeitY, 2025; Government of India, 2000). Section 79 of the Act protects digital platforms from liability for unlawful third-party content, provided they remain passive conduits that do not initiate, select, or modify the hosted information (MeitY, 2025; Government of India, 2000). The 2025 Guidelines explicitly concede that generative AI systems do not fit cleanly into these legacy definitions, as they dynamically generate, modify, and synthesize novel outputs based on user prompts (MeitY, 2025). Until the underlying cyber law is updated with targeted amendments, the boundary of legal immunity for developers and deployers remains an unresolved point of litigation (MeitY, 2025).
The policy insistence on human oversight runs directly counter to the administrative incentives of the state (NITI Aayog, 2022; MeitY, 2025). NITI Aayog’s work on FRT and the 2025 Guidelines call for meaningful human-in-the-loop mechanisms, operator training, and system overrides to mitigate the risk of automation bias and loss of control (NITI Aayog, 2022; MeitY, 2025). However, public administration systems in India frequently automate processes precisely to minimize human intervention, accelerate throughput, and lower costs across vast population scales (NITI Aayog, 2022; MeitY, 2025). In practice, automated administrative systems often ossify into absolute gatekeepers, transforming recommendatory safeguards into rigid operational barriers.

Significant Policy Gaps

Despite the granular detail of recent guidelines, a critical gap remains the absence of a binding, statutory risk-tiering framework (MeitY, 2025). Looking across comparable global frameworks that enforce clear red lines and categorical prohibitions on high-risk applications, India’s risk classification system remains largely conceptual and recommendatory (MeitY, 2025). High-risk deployments by public authorities – such as predictive policing, automated welfare filtering, and live facial recognition surveillance – are analyzed extensively in policy prose but lack an enforceable, uniform compliance or licensing architecture (NITI Aayog, 2022; MeitY, 2025).
In relation to personal freedom, the sharpest deficiency is the lack of specific statutory protections against state surveillance and purpose creep (NITI Aayog, 2022; MeitY, 2023). NITI Aayog’s analysis of FRT explicitly notes that mass surveillance threatens the constitutional right to informational autonomy, that consent is compromised when public services depend on biometric enrollment, and that state actions must pass the rigorous tests of legality, necessity, and proportionality (NITI Aayog, 2022). Yet, neither the DPDP Act nor the IT Act codifies a specialized, restrictive statutory regime governing biometric data processing by law enforcement or administrative agencies, leaving civil liberties dependent on ex-post constitutional litigation before the High Courts (NITI Aayog, 2022; MeitY, 2023).
A parallel gap exists regarding the procedural right to explainability and contestability (NITI Aayog, 2022; MeitY, 2025). While the FREE-AI Committee Report and the 2025 Guidelines emphasize the necessity for systems to be “understandable by design,” India’s legal order does not grant citizens an explicit, enforceable right against solely automated decision-making (MeitY, 2025). An individual who suffers a loss of opportunity, credit denial, or administrative exclusion due to an algorithmic output faces an uneven remedial path, as current laws lack clear provisions mandating disclosure of the underlying algorithmic rationale or a statutory right to automated-output contestability (MeitY, 2025).
On national security, the framework remains structurally fragmented (MeitY, 2025). The Guidelines correctly identify the perils of AI-facilitated disinformation campaigns, model poisoning, data corruption, and adversarial inputs targeting critical infrastructure (MeitY, 2025). However, the institutional execution splits responsibilities across disconnected silos (MeitY, 2025). The coordination between CERT-In’s six-hour cyber incident reporting mandates, the National Critical Information Infrastructure Protection Centre’s (NCIIPC) secure system protocols, and the newly established AI Safety Institute (AISI) lacks an integrated statutory interface, leaving the security of sensitive data networks heavily reliant on reactive administrative advisories (MeitY, 2025).
Furthermore, the policy space lacks a comprehensive social compact regarding labor transitions and algorithmic management (NITI Aayog, 2018; MeitY, 2025). While the 2018 National Strategy discussed workforce skilling and the potential for domestic employment generation via low-skill data annotation markets, the broader landscape remains silent on the rights of workers subjected to automated surveillance, algorithmic performance metrics, or automated termination protocols within the rapidly expanding gig economy (NITI Aayog, 2018; MeitY, 2025).
Finally, the copyright and training data impasse represents a critical regulatory blind spot (DPIIT, 2025; MeitY, 2025). The 2025 Guidelines concede that India’s current Copyright Act, 1957 fails to shield commercial AI training from infringement claims (MeitY, 2025). The DPIIT’s 2025 Working Paper exposes a deep industry polarization: the tech industry demands a broad, non-remunerative Text and Data Mining (TDM) exception with a machine-readable opt-out, while content creators and media publishers warn that unlicensed ingestion poses an existential threat to creative livelihoods (DPIIT, 2025). By shifting the burden of compliance entirely onto content creators through unstandardized technological tools like robots.txt, the current unguided opt-out approach compromises data transparency, leaves small-scale creators unprotected, and generates severe legal uncertainty that hinders sustainable model development (DPIIT, 2025).

Practical Implementation Hardships

The primary obstacle to operationalizing India’s AI governance guidelines is acute institutional capacity constraints (MeitY, 2025). A principle-based, distributed regulatory model assumes that existing ministries, law enforcement agencies, public procurement officers, and sectoral regulators possess the deep technical expertise required to audit algorithmic systems, evaluate data protection impact assessments, and identify subtle algorithmic biases (MeitY, 2025). The 2025 Guidelines explicitly admit that public sector functionaries and regulators currently lack the necessary technical grounding (MeitY, 2025). This deficit threatens to reduce sophisticated regulatory guidelines into superficial, check-the-box compliance exercises.
This capacity gap is further exacerbated by profound federal and sectoral unevenness (MeitY, 2025). While advanced financial and telecommunications regulators maintain a mature compliance culture, local state and municipal authorities lack the resources and administrative infrastructure to concrete monitor automated systems (MeitY, 2025). A uniform national policy will inevitably fracture into highly disparate enforcement realities across different states, creating regulatory gaps and uneven protections for citizens (MeitY, 2025).
Furthermore, public procurement suffers from severe information asymmetry (NITI Aayog, 2018; MeitY, 2025). When state agencies procure high-risk algorithmic systems from private vendors, they remain dependent on proprietary self-certifications regarding model safety, explainability, and bias mitigation (NITI Aayog, 2018; MeitY, 2025). Because private developers guard their source code and training methodologies as protected trade secrets, public authorities face substantial technical barriers when attempting to conduct independent validation or algorithmic audits, rendering the mandate for meaningful human oversight structurally weak at the contractual interface (NITI Aayog, 2018; MeitY, 2025).

Strategic Recommendations for Structural Reform

To transform India’s AI governance architecture into a resilient, legally unassailable, and rights-respecting governance model, four clear structural reforms should be prioritized:
1. Codify a Tiered, Mandatory Risk Framework: India must transition from recommendatory guidelines to a binding statutory instrument that explicitly tiers AI applications by risk (MeitY, 2025). This framework must establish clear “red lines” for prohibited systems (such as dark patterns that cause consumer harm or unauthorized mass biometric profiling) while enforcing mandatory ex-ante audits, dataset provenance verifications, and strict security protocols for high-risk applications in public governance and critical infrastructure (MeitY, 2025).
2. Narrow the Scope of State Exemptions: To preserve the integrity of informational autonomy, the broad state exemptions under Section 17 of the DPDP Act, 2023 must be strictly hemmed in by legal and procedural guardrails (MeitY, 2023). State data processing must be subject to clear statutory necessity, suitability, and proportionality standards, accompanied by mandatory internal records of reasoning and independent oversight by the DPB (NITI Aayog, 2021a; MeitY, 2023). In highly sensitive public deployments like biometric surveillance, a bespoke statutory law must be enacted to establish explicit legal thresholds, judicial warrant requirements, strict retention limits, and robust civil remedies (NITI Aayog, 2021a; MeitY, 2023).
3. Enact a Statutory Right to Contestability: Legally operationalize the “People First” sutra by codifying an explicit right against solely automated decision-making where the outcome materially impacts an individual’s life, liberty, livelihood, or access to public services (MeitY, 2025). This reform must guarantee citizens the right to receive an intelligible, contextual explanation of the algorithmic rationale and a seamless, independent administrative pathway to seek binding human review and timely grievance redressal (MeitY, 2025).
4. Establish a Balanced, Statutory Licensing Framework for AI Ingestion: Resolve the intellectual property impasse by rejecting both an unguided, zero-price TDM exception and a fragmented system of direct voluntary licensing (DPIIT, 2025). India should adopt a hybrid statutory model that permits permission-free access to lawfully acquired data for model training to prevent innovation holdouts and mitigate data bias, while guaranteeing an unwaivable right to equitable remuneration for all content creators (DPIIT, 2025). This framework can be efficiently administered through a centralized, non-profit rights management collective, simplifying compliance for startups while systematically protecting the financial sustainability of the creative economy (DPIIT, 2025).
5. Enforce Incident Reporting: Incident reporting should move from recommendation to practice. A national AI incident mechanism, linked with CERT-In and sectoral databases, could generate exactly the empirical evidence that policymakers would need. But it must be designed carefully: confidential enough to encourage reporting, standardized enough to be useful, and public enough in aggregated form to support learning and trust.

Closing Remarks

India’s AI policy landscape is ambitious, increasingly detailed, and in several respects well self-aware. It understands ecosystem deficits, it sees the strategic role of digital public infrastructure, it recognizes bias, opacity, surveillance risk, deepfakes, and cyber threats, and it is trying to govern without choking innovation at birth.
Still, the framework needs refinement for enforceable guarantees, binding limits on state use, allocating liability. With stronger rights architecture, clearer institutional accountability, and more disciplined implementation, India would build an AI governance model that is administratively energetic and normative.

References

  1. DPIIT (Department for Promotion of Industry and Internal Trade). (2025). Working paper on generative AI and copyright – Part I. https://www.dpiit.gov.in/static/uploads/2025/12/ff266bbeed10c48e3479c941484f3525.pdf.
  2. Government of India. (2000). Information Technology Act, 2000 (updated). https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf.
  3. Ministry of Electronics and Information Technology (MeitY). (2023). Digital Personal Data Protection Act, 2023. https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf.
  4. Ministry of Electronics and Information Technology (MeitY). (2025). India AI Governance Guidelines. https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf.
  5. NITI Aayog. (2018). National strategy for artificial intelligence. https://www.niti.gov.in/sites/default/files/2023-03/National-Strategy-for-Artificial-Intelligence.pdf.
  6. NITI Aayog. (2021a). Responsible AI for All: Part 1 – Principles for Responsible AI. https://www.niti.gov.in/sites/default/files/2021-02/Responsible-AI-22022021.pdf.
  7. NITI Aayog. (2021b). Responsible AI for All: Part 2 – Operationalizing Principles for Responsible AI. https://www.niti.gov.in/sites/default/files/2021-08/Part2-Responsible-AI-12082021.pdf.
  8. NITI Aayog. (2022). Responsible AI for All: Part 3 – Adopting the Framework: A Use Case Approach on Facial Recognition Technology. https://www.niti.gov.in/sites/default/files/2022-11/Ai_for_All_2022_02112022_0.pdf.
  9. Reserve Bank of India [RBI]. (2025). FREE-AI Committee Report: Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector. https://rbidocs.rbi.org.in/rdocs/PublicationReport/Pdfs/FREEAIR130820250A24FF2D4578453F824C72ED9F5D5851.PDF.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

© 2026 MDPI (Basel, Switzerland) unless otherwise stated

Accessibility

Disclaimer

Terms of Use

Privacy Policy

Privacy Settings