India hasn't passed a dedicated AI Act, and that gets misread constantly as "India isn't regulating AI yet." It is. AI security compliance India-wide already runs through a stack of enforceable law data protection rules, intermediary rules, sector regulators and two of the biggest pieces became operative in the last year. Businesses waiting for a single horizontal statute before they act are already behind.
The government's own posture is deliberately light-touch by design: use existing law, intervene sharply where the harm is concrete deepfakes, election misinformation, financial fraud and leave broader AI governance to voluntary guidelines for now. That approach makes AI security compliance India obligations easy to underestimate, because there's no single document to read. There's a patchwork, and each piece has its own effective date.
The Digital Personal Data Protection Act received presidential assent in 2023, but it only became operative once MeitY finalized the DPDP Rules on November 13, 2025. The rollout is phased through May 2027, but the core obligations already apply: explicit, informed consent for processing personal data, purpose limitation, data minimization, and breach notification. For any business training or fine-tuning models on data that includes Indian users, this is the first filter not a future compliance project, a current one. Significant Data Fiduciaries face additional requirements, including impact assessments and audits, and children's data carries its own parental-consent layer that most AI tutoring, gaming, and content-recommendation products haven't fully mapped yet.
On February 20, 2026, MeitY's amendments to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules became operative for "synthetically generated information" the government's term for deepfakes and AI-generated media. The obligations are specific and unforgiving on timing: a 3-hour takedown window for general unlawful content, compressed to 2 hours for high-risk categories like non-consensual intimate imagery, plus mandatory labeling and permanent provenance metadata for lawful synthetic content. Miss the window, and a platform loses Safe Harbor protection outright. Any intermediary operating in India social platforms, video-sharing sites, messaging apps is in scope, and "we didn't know it was AI-generated" is not a defense the rules leave room for.
While MeitY's November 2025 AI Governance Guidelines remain voluntary seven non-binding principles under the IndiaAI Mission the regulators that actually supervise money and markets aren't waiting for legislation to catch up.
SEBI's Regulation 16C puts regulated entities under a strict-responsibility standard for AI they deploy in securities markets the firm is accountable for the model's output, full stop, regardless of which vendor built it. The RBI's FREE-AI framework sets out expectations for AI in banking that mirror what global regulators are converging on elsewhere: model inventories, human oversight, and bias testing. Combined, these make AI security for BFSI sector India one of the most tightly supervised corners of AI deployment in the country, well ahead of any horizontal statute.
Treating India as a "wait and see" jurisdiction because there's no single AI Act is the mistake that shows up in an audit or a takedown notice, not a headline. A program built to actually hold up includes:
When evaluating vendors, the businesses getting this right aren't just checking which of the best AI security companies India 2026 has to offer show up on a shortlist they're asking each one for testing evidence against the DPDP, IT Rules, and sector-specific obligations that actually apply to their systems.
India's regulatory approach is pragmatic by design: light-touch until the harm is concrete, then fast and specific. For businesses, that means the absence of a single AI Act isn't a grace period. It's a patchwork that's already enforceable, phased in earlier than most compliance calendars accounted for, and getting denser every quarter.
Subscribe to our newsletter for the latest AI news