See how Trussed maps to your regulation in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    India AI Governance Guidelines: Enterprise Compliance Guide

    India's AI governance guidelines, developed by MeitY through the IndiaAI Mission, use a principle-based, risk-tiered approach built on existing law rather than a standalone AI statute. Enterprises must map AI systems and AI agents to IT Act and DPDP Act obligations, assign internal accountability for risk classification, and maintain audit-ready logging of AI decisions and data access.

    India's AI governance guidelines, developed by MeitY through the IndiaAI Mission, use a principle-based, risk-tiered approach built on existing law rather than a standalone AI statute. Enterprises must map AI systems and AI agents to IT Act and DPDP Act obligations, assign internal accountability for risk classification, and maintain audit-ready logging of AI decisions and data access, since sector regulators may add further requirements and no single prescriptive technical standard yet exists.

    Framework at a Glance

    Guiding Principles
    Seven Sutras including trust, accountability, fairness and equity, and safety and resilience
    Legal Basis
    Built on the IT Act and DPDP Act, 2023 rather than a new standalone AI law
    Regulatory Model
    Sector regulators apply AI oversight within existing mandates; no central AI regulator
    Framework Status
    Principle-based and iterative, expected to evolve through phased refinement

    What the India AI Governance Guidelines Cover

    India's national AI governance approach originates from a subcommittee convened by the Ministry of Electronics and Information Technology (MeitY) under the IndiaAI Mission. Rather than proposing a single standalone AI law, the guidelines adopt a principle-based, risk-tiered framework anchored in seven guiding principles referred to as Sutras, including trust, accountability, fairness and equity, safety and resilience, and being understandable by design.

    The framework does not create a centralized AI regulator. Instead, it recommends that existing sector regulators, such as those overseeing financial services, healthcare, and telecommunications, apply AI-specific oversight within their current mandates. To support coordination across sectors, the guidelines propose an AI governance group and a technical secretariat responsible for policy alignment and incident response coordination. The approach is explicitly framed as iterative, meaning enterprises should expect phased refinement over time rather than a fixed, one-time compliance standard.

    How the Guidelines Relate to Existing Law

    Instead of introducing new AI-specific statutes, the guidelines direct enterprises to existing legal instruments, primarily the Information Technology Act and the Digital Personal Data Protection Act, 2023, as the near-term basis for AI oversight. For AI systems that process personal data, DPDP obligations around purpose limitation, consent, and data fiduciary accountability apply directly, meaning consent-tracking and data-minimization controls are current compliance requirements, not future ones.

    Separately, MeitY advisories issued in March 2024 introduced due-diligence obligations for intermediaries deploying under-tested or unreliable AI models, including labeling and disclosure requirements so users are informed when interacting with such systems. A later revision removed an earlier requirement for prior government permission before deployment, shifting the obligation toward disclosure rather than pre-approval. Enterprises deploying generative or under-tested models to end users should treat these labeling obligations as active requirements rather than pending guidance.

    Enterprise Obligations: Risk Classification, Accountability, and Auditability

    The guidelines do not yet publish a prescriptive risk classification schema for AI systems. Enterprises are expected to interpret risk tiers based on the stated principles, particularly accountability and safety and resilience, and to document a defensible rationale for how a given AI system or AI agent has been classified. This places the burden of risk assessment on the enterprise rather than on a regulator-issued checklist.

    Accountability, as a named principle, implies that enterprises should designate clear internal ownership for AI risk classification and compliance sign-off, rather than leaving oversight diffused across teams with no single accountable party. Auditability follows from the same accountability principle: if a regulator or sector body requests evidence of how an AI system reached a decision or what data it accessed, enterprises need logging sufficient to reconstruct that history.

    This is particularly relevant for autonomous AI agents, which may access personal or sensitive data and take actions without direct human review at each step. Where an AI agent performs functions that qualify as a data fiduciary under the DPDP Act, consent and purpose-limitation controls apply to its data access, not only to the underlying model.

    Closing the Compliance Gap

    Enterprises can reduce uncertainty by treating the guidelines as an operating checklist tied to existing law, not as a future statute to wait on:

    • Inventory before assuming new rules apply. Map existing AI systems and agents against IT Act and DPDP Act obligations before assuming AI-specific requirements are separate or additional.
    • Check sector regulator guidance separately. Sector bodies overseeing financial services, healthcare, and similar industries may issue their own AI-specific rules beyond the national guidelines.
    • Treat compliance as a living record. Since the guidelines are iterative, build documentation and risk classifications to be updated, not finalized once.
    • Enforce access scope at runtime, not just in policy. Where AI agents hold standing access to systems or data, runtime enforcement of permissions and tool approval keeps access provable at audit time. Runtime governance platforms such as Trussed AI provide audit logging and permission enforcement that support the accountability and auditability expectations described in the guidelines.
    • Review incident response readiness. Confirm internal processes align with the guidelines' recommended incident reporting and coordination practices.

    Technical and organizational controls to prioritize

    • Documented risk classification with a clear internal owner for each AI system and agent
    • Consent-tracking and purpose-limitation controls for personal data processed under the DPDP Act
    • Audit-ready logging of AI decisions, data access, and agent actions
    • Labeling and disclosure for generative or under-tested models exposed to end users
    • Runtime permission enforcement where agents retain standing access to tools or data

    Frequently Asked Questions

    Are India's AI governance guidelines legally binding?

    Based on available guidance, the framework functions primarily as advisory and principle-based, relying on existing statutes such as the IT Act and DPDP Act for enforceable obligations. Binding force for AI-specific requirements depends on future legislative or sector-regulator action, so enterprises should track updates rather than treat current guidance as fixed law.

    Which sector regulators might add AI-specific requirements?

    The guidelines anticipate regulators overseeing financial services, healthcare, and telecommunications applying AI oversight within their existing mandates. Enterprises should check with applicable sector regulators directly, since specific AI rules from these bodies were not detailed in the national guidelines and may evolve separately.

    Do the guidelines apply to AI agents specifically, or only to AI models?

    The guidelines address AI systems broadly rather than naming AI agents as a distinct category. Where an AI agent processes personal data or makes decisions affecting individuals, DPDP Act obligations and the accountability and auditability principles apply to its actions the same way they apply to other AI systems.

    Assess Your AI Agent Compliance Readiness

    Review how your AI agents handle identity, permissions, and audit logging against India's evolving AI governance expectations.

    Talk to an Expert