Information Technology Act, 2000
IT Act and Artificial Intelligence: AI Liability and Regulation in India
The IT Act was written before smartphones, social media or generative AI. It does not mention artificial intelligence. Yet AI systems now write, speak, create images and act on behalf of people, and each of these raises questions the Act must answer: is an AI agent's action binding, is an AI platform an intermediary, who is liable for harmful output, and may personal data be used to train a model? This note explains how existing provisions apply, where they strain, how the government has responded through advisories, guidelines and the 2026 rules, and how India's approach compares with the European Union's.
1. An Old Map for a New Territory
Explorers entering new land often carry an old map. Many roads are still in the right place, some are missing, and a few lead into rivers that did not exist when the map was drawn. The IT Act is that map for AI. Its broad, technology-neutral provisions on computers, automated systems and electronic records still guide the way; its intermediary provisions, drawn for platforms that merely carry other people's content, fit poorly on systems that create content themselves; and some ground, such as AI safety and bias, is simply not on the map.
2. How Existing Provisions Apply
Figure 1: AI questions and the provisions that answer them
- No definition of AI. The Act does not define artificial intelligence, but its definitions of computer, computer system, computer resource and data are wide enough to cover AI systems.
- Automated systems (s.11(c)). An electronic record is attributed to the originator if it was sent by an information system programmed by or on behalf of the originator to operate automatically. An AI agent that places orders or sends messages therefore binds the person who deployed it.
- Contracts (s.10A). Contracts formed through electronic means, including by automated systems on both sides, are not unenforceable because of that form. The Contract Act still governs consent and mistake.
- Offences. Harmful uses of AI fall within existing offences: identity theft and cheating by personation (ss.66C, 66D), capturing or publishing private images (s.66E), obscene and sexually explicit material (ss.67, 67A), and child sexual abuse material, which Section 67B expressly covers when a person 'creates text or digital images'.
3. Is an AI Platform an Intermediary?
- The safe harbour's premise. Section 79 protects an intermediary from liability for 'third-party information' it hosts or transmits, provided it does not initiate the transmission, select the receiver or select or modify the information.
- The difficulty. When a generative AI model produces text or images in response to a prompt, the output is created by the platform's own system. It is arguable that this is not third-party information and that the platform has 'selected or modified' it, so the safe harbour may not apply to the output itself.
- The government's approach. MeitY's advisories of March 2024 treated platforms offering AI models as intermediaries bound by due diligence under the IT Rules. The first advisory of 1 March 2024 required government permission before deploying under-tested models; the revised advisory of 15 March 2024 dropped the permission requirement and instead required labelling of unreliable outputs and of synthetic content.
- The 2026 amendment. The IT Rules, as amended in February 2026, impose specific duties on intermediaries whose computer resources enable the creation of synthetically generated information: technical measures to prevent unlawful synthetic content, prominent labels, permanent metadata and unique identifiers that cannot be removed (see Topic 21)
4. Liability across the AI Value Chain
Figure 2: Who may be responsible when AI causes harm
- User. A person who uses AI to impersonate, defraud, defame or create sexual images is liable under the IT Act and the BNS exactly as if other tools had been used.
- Deployer or platform. Bound by due diligence under the IT Rules; may lose safe harbour for content it generates or fails to remove on notice; bound by consumer law against misleading claims.
- Developer. No specific statutory regime yet. Liability may arise in negligence, under consumer protection law, or under the DPDP Act for how training data was collected.
- Guidelines. The India AI Governance Guidelines of November 2025 recommend clarifying liability across the value chain, in proportion to each actor's role and control.
5. Data, Copyright and Personality
- Training on personal data. Once the DPDP Act's substantive provisions commence, processing digital personal data to train AI requires consent or a legitimate use. The Act does not apply to personal data that the individual has made publicly available, which may cover some scraped data, but its limits are untested.
- Copyright. In ANI Media v. OpenAI, filed in the Delhi High Court in November 2024, a news agency alleged that using its content to train a large language model infringes copyright. The case raises whether training is infringement and whether Indian courts have jurisdiction.
- Voice and likeness. In Arijit Singh v. Codible Ventures LLP (Bombay High Court, 2024), the Court restrained AI platforms from cloning the singer's voice, holding that personality rights extend to voice and that AI tools enabling imitation infringe them.
- Bias and discrimination. AI decisions in lending, hiring or policing can reproduce bias. Article 14 constrains State use of AI, but there is no specific statute on algorithmic discrimination by private actors.
6. India's Policy Response
Figure 3: From strategy to rules
- NITI Aayog. The National Strategy for Artificial Intelligence (2018) and the Principles for Responsible AI (2021)
- IndiaAI Mission (2024). A national programme to build compute capacity, datasets, foundation models and skills.
- India AI Governance Guidelines (November 2025). Released by MeitY, they recommend against a standalone AI law for now, preferring to apply and amend existing laws such as the IT Act, the DPDP Act and consumer law, with sectoral regulators writing domain rules. They propose an AI Governance Group, a Technology and Policy Expert Committee and an AI Safety Institute.
- Synthetic content rules (February 2026). The first binding AI-specific obligations, focused on labelling and removal of synthetic content.
Figure 4: The seven principles of the India AI Governance Guidelines
7. Comparison with the EU AI Act
Figure 5: Two approaches to AI regulation
⚠ Exam trap Do not write that India has an AI Act. India regulates AI through existing laws, especially the IT Act, the IT Rules, the DPDP Act and consumer law, supplemented by MeitY's advisories, the 2025 Governance Guidelines and the 2026 synthetic content rules. The comprehensive, risk-based AI Act is the European Union's, in force from August 2024. |
8. Quick Revision and Memory Aids
- 'Old map, new territory'. The IT Act applied to AI.
- '11(c): the bot binds its master'. Attribution of automated systems.
- 'Third party or first party?'. The intermediary question for generative AI.
- 'Developer, deployer, user'. The liability chain.
- '1 March permission, 15 March labels'. The 2024 MeitY advisories.
- 'Seven sutras, no AI Act'. The 2025 Guidelines.
9. Frequently Asked Questions
Does the IT Act regulate artificial intelligence?
Not expressly, but its technology-neutral provisions apply: automated systems (s.11(c)), electronic contracts (s.10A), offences for misuse (ss.66C, 66D, 66E, 67 to 67B) and intermediary due diligence under the IT Rules, which were amended in 2026 to address synthetically generated content.
10. Related Topics
- Topic 13: Technology-Neutral Approach. Why the Act can reach AI at all.
- Topic 21: IT Act and Deepfakes. The sharpest AI harm and its regulation.