Issue Brief No: 08
Governing the Next AI Frontier: India’s Need for Enforceable Guardrails
Author: Gopikrishna Sumathi Simhanjana
Introduction
Artificial intelligence (“AI”) now confronts India as an economic, strategic, regulatory and security question at once. With the IndiaAI Mission approved in March 2024 at an outlay of ₹10,371.92 crore,[1] the Government has signalled that India will not remain a passive consumer of AI systems built elsewhere. The Mission funds compute capacity, indigenous models, datasets, start-up support and the promotion of safe and trusted AI. Sustaining that ambition, however, depends on whether India can govern the risks that accompany AI at the scale envisaged.
The timing matters. Frontier AI systems — general-purpose models at or beyond the current state of the art[2], are acquiring capabilities in reasoning, code generation and autonomous tool use. Agentic systems built on them can plan and execute multi-step tasks with limited human intervention. The same capabilities that promise gains in healthcare[3], finance[4] and public administration[5] also lower the cost of cyber exploitation[6], of fraud at scale[7], and of synthetic media capable of distorting public discourse[8], elections[9] and democratic institutions[10]. Capability, in this technology, is dual-use by construction.
Recent assessments of AI-assisted cyber operations sharpen the point[11]. Whether any extreme scenario materialises soon matters less than a structural shift already underway: AI is compressing the interval between vulnerability discovery, exploitation and response[12]. For a country operating population-scale digital public infrastructure, expanding fintech rails and designated critical information infrastructure, that compression is a present operational risk rather than a forecast.
The question before India is therefore how to build an AI ecosystem in which scale, innovation and public-interest safeguards coexist. This brief argues that India’s governance gap lies in enforcement rather than articulation, and it proposes five instruments through which principles the Indian state has already adopted can acquire legal force: a mandatory AI-incident reporting duty paired with a liability safe harbour; safety conditions attached to publicly funded compute and data; binding rules for public-sector AI imposed through procurement; statutory footing for the governance institutions India has already designed; and a Union–State coordination mechanism for AI deployment in state domains.
The Implementation Deficit
India’s policy lineage on this subject is nearly a decade deep. In February 2018, the Ministry of Electronics and Information Technology (“MeitY”) constituted four expert committees on artificial intelligence,[13] and in July 2019 the Committee on Platforms and Data on Artificial Intelligence published its draft report recommending a National Artificial Intelligence Resource Platform, the migration of government data onto common platforms in well-defined formats, anonymisation infrastructure to open large datasets to the public, and government investment in bias-free datasets.[14] The significance of that starting point is worth registering: India’s earliest institutional thinking treated data and platforms, rather than models, as the foundation of AI capability.
Between these two events, the NITI Aayog released a National Strategy for Artificial Intelligence (“NSAI”) in June 2018, branding India’s approach as “AIforAll” and recommending, among its four plans, the development of sector-specific regulatory guidelines for responsible AI.[15] Notably, the NSAI was and remained a discussion paper. Therefore, India’s founding AI policy document is itself an instrument that recommends future frameworks rather than enacting present obligations, a pattern each successive document in this lineage has repeated.
In 2021, NITI Aayog carried the lineage from infrastructure to principle, framing responsible AI around constitutional values, public trust, safety, inclusivity, privacy and accountability, and accepting that principles would have to be operationalised across the public sector, private sector and academia.[16] The Subcommittee on AI Governance and Guidelines Development, constituted by MeitY under the multi-stakeholder Advisory Group chaired by the Principal Scientific Adviser, was then tasked with identifying gaps in existing frameworks[17] and recommended a whole-of-government approach with a lifecycle-based governance.[18] The India AI Governance Guidelines carry this work forward by recognising AI as a dual-use technology, identifying risks from deepfakes and algorithmic bias to national security threats, and organising governance around seven guiding sutras, from “Trust is the Foundation” to “Safety, Resilience and Sustainability”.[19]
India’s governance gap is therefore one of translation. Principles articulated across seven years of committee work have yet to become enforceable, auditable obligations, and the distance between the two has consequences that widen with every high-impact deployment.
The existing legal position is best understood as legally plural rather than legally absent. Binding obligations already arise under the Digital Personal Data Protection (“DPDP”) Act, 2023 and the DPDP Rules, 2025; the Information Technology Act, 2000; the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021, including the 2026 amendments addressing synthetically generated information; CERT-In’s incident-reporting directions; and sectoral guidelines and regulatory frameworks by the Reserve Bank of India (“RBI”), Securities and Exchange Board of India (“SEBI”), Insurance Regulatory and Development Authority of India (“IRDAI”) and Telecom Regulatory Authority of India (“TRAI”).
Sectoral regulators are also beginning to respond to frontier capability directly rather than generically. For example, SEBI’s May 2026 Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection is India’s first sectoral regulatory response to AI systems able to identify and exploit vulnerabilities at machine speed and scale. The Advisory requires all regulated entities to treat AI-model capability as a distinct risk scenario under the Cyber Security and Cyber Resilience Framework, to patch systems immediately, and to subject every AI-flagged vulnerability to human validation before remediation.[20] The Advisory also demonstrates both the strength and the limit of sectoral regulation, i.e., a regulator can move within weeks when frontier capability threatens its domain, but its writ ends at the securities-market perimeter. The same capability directed at a hospital network or a port authority answers to no equivalent instrument.
Alongside these instruments, the AI Governance Guidelines, NITI Aayog papers and MeitY advisories supply policy direction and a shared risk vocabulary. The coexistence of these instruments is unremarkable. However, the difficulty is that a single high-impact AI system can cut across all of them, producing at once a cyber incident, a data breach and a discriminatory outcome, depending on how it is trained, integrated and deployed, without any single point of accountability, any consistent audit standard, or any clear remedy for the person affected.
Two weaknesses in this plural framework deserve particular attention, because both sit exactly where the stakes are highest.
The first concerns the DPDP Act itself. The statute most often cited as India’s binding digital safeguard is weakest precisely where AI deployment is most rights-sensitive. For state deployments in welfare, policing, or automated governance, Sections 7(b) and 7(c) allow public authorities to bypass consent entirely for providing subsidies or performing state functions, while Section 17(4) exempts them from core data-erasure obligations and certain data-correction duties. Where national security or public order is invoked, Section 17(2)(a) permits the Central Government to exempt designated State instrumentalities from the Act altogether. Systemic public auditing of these automated pipelines is simultaneously blocked as Section 44(3) of the DPDP Act replaces Section 8(1)(j) of the Right to Information Act, 2005 (“RTI Act”) with an absolute bar on disclosing any public information, shielding public algorithms from civil society scrutiny. Crucially, for private sector AI deployment, Section 3(c)(ii)(A) creates a painful logical paradox: it completely excludes personal data from the Act’s scope if the Data Principal made it public themselves. By legally equating routine digital expression with a total surrender of privacy, the Act enables private tech giants to aggressively scrape, harvest, and exploit vast public digital footprints. This allows commercial developers to train proprietary frontier AI models and deploy invasive automated profiling systems with absolute statutory immunity and zero accountability to the people who’s lives they analyse.
The second concerns institutional design. The Guidelines deliberately reject a standalone AI regulator in favour of a coordination architecture: an AI Governance Group (“AIGG”) supported by a Technology and Policy Expert Committee (“TPEC”), working with existing sectoral regulators. TRAI, by contrast, had recommended the opposite in July 2023, an independent statutory authority for AI, and that recommendation was not taken up. The coordination model is defensible for a technology whose risks are sector-specific, but it can deliver enforceability only if the AIGG’s outputs attach to duties that some existing body can enforce. Coordination without an enforcement mechanism reproduces the softness it was designed to cure.
Where the State itself deploys AI, such as in welfare eligibility, policing, taxation, health or education, governance must also answer to constitutional standards, since such systems implicate privacy, equality, dignity and procedural fairness. The proportionality framework laid down in K.S. Puttaswamy v. Union of India[21] supplies the benchmark, and the Article 14 doctrine against arbitrariness constrains automated administrative action no less than human action.[22] Albeit no Indian court having yet ruled squarely on algorithmic decision-making by the State, comparative jurisprudence indicates the direction of travel. The Hague District Court struck down the Netherlands’ SyRI welfare-fraud scoring system as a disproportionate interference with private life,[23] and the England and Wales Court of Appeal held police use of live facial recognition unlawful for want of an adequate legal framework[24]. Indian deployments should therefore be subjected to a structured pre-deployment and post-deployment governance process, rather than leaving constitutional compliance to ex post facto litigation.
Capability as Trigger, Deployment as Site
Much of India’s AI-relevant regulatory architecture responds after harm becomes visible. Frontier risk begins earlier, when models are trained, tested, red-teamed, released, fine-tuned, connected to external tools or integrated into enterprise and critical systems. Only a narrow class of systems warrants frontier-level scrutiny, and the trigger for that scrutiny should combine capability with context: model autonomy, the ability to use external tools, capabilities relevant to cyber operations or biosecurity, access to sensitive datasets, deployment at population scale, integration with critical infrastructure, or use in decisions affecting rights and entitlements.
Global models offer material for this framework, but no template. The EU AI Act presumes systemic risk in general-purpose models above a training-compute threshold of 10²⁵ floating-point operations, and California’s Transparency in Frontier Artificial Intelligence Act (or SB-53) attaches its transparency and incident-reporting duties to large frontier developers defined by compute and revenue thresholds. Both are training-side triggers, suited to jurisdictions where frontier models are built. India is, for the foreseeable future, predominantly a deployer of frontier capability. The EU’s threshold does, admittedly, reach imported models, since its obligations attach at market placement; but that design presumes an enforcement apparatus able to compel and verify training-run disclosures from developers with no domestic establishment — leverage India does not currently hold. More decisively, a training-side threshold measures the wrong variable for Indian risk: what matters here is not the compute behind a model but what the model is connected to once deployed. Deployment-side triggers keyed to capability and context are therefore the correct adaptation for India.
The Guidelines gesture at this deployment-side architecture: its action plan lists India-specific risk frameworks, regulatory gap analysis, liability regimes, an AI incidents database, grievance redressal, regulatory sandboxes and common standards. However, these remain programmatic proposals, and commentary has fairly observed that the document is light on accountability and liability[25]. The harder task, which the Guidelines defer, is converting these proposals into rights-sensitive,[26] legally grounded[27] and independently enforceable safeguards.
Further, the pace objection cuts against documents, not designs. Any framework specified at the level of named technologies will be obsolete on arrival, which is why the triggers proposed here are keyed to capability and context rather than to particular models or techniques, and why even the EU made its compute threshold adjustable by delegated act rather than fixing it in the Regulation's text. The incident-reporting duty completes the answer, since a mandatory reporting stream is the mechanism by which a framework learns what the technology has become.
Compute and Data as Governance Levers
Since access to the infrastructure on which Indian AI systems will be trained, tested and deployed runs through the Government, namely the subsidised GPU capacity allocated through IndiaAI Compute Portal and the curated datasets of AIKosha, it can govern through the terms of access, not only through regulation. Access to subsidised compute and public datasets can be made conditional on proportionate safety obligations, calibrated to the capability triggers set out above: documentation and red-teaming for large training runs, incident reporting for high-capability deployments, and baseline security and provenance practices for all recipients. These are contractual conditions, written into the Mission’s existing empanelment contracts, allocation terms and data set licenses. They require no legislation, which makes them the fastest available route from principle to enforceable obligation, and a proving ground for standards that may later mature into law.
The scope of this conditionality should be stated honestly. It reaches only what is built on public infrastructure: indigenous models, fine-tuned derivatives, and start-ups on subsidised compute. Frontier systems trained abroad sit outside it, which is why this instrument works alongside the deployment-side triggers rather than in place of them.
The public-private boundary is in any case porous: where private AI systems plug into public rails, the UPI model applies, in which private banks and payment applications operate on shared infrastructure but are governed through NPCI’s conditions of participation. Access-based governance of that kind is ownership neutral, which is why the instruments proposed here attach to capability, context, and infrastructure rather than to whether the deployer is public or private.
Compute alone, however, will not secure the sovereignty the Mission seeks.[28] Models trained on Indian infrastructure will be locally relevant, safe and useful only to the extent that the underlying datasets are high-quality, rights-compliant and interoperable. India’s data advantages are real — scale, digital public infrastructure, linguistic diversity and sectoral digitization. However, much of this data remains fragmented across institutional silos with inconsistent metadata and access frameworks.[29] This is the oldest insight in India’s AI policy lineage. The 2019 Committee-A report made common data platforms, anonymisation infrastructure, investment in bias-free datasets its central recommendations. Seven years on, they remain substantially unimplemented. That delay is why a trusted data stack, with common standards on consent, provenance and interoperability, may prove as consequential for Indian AI as GPU capacity itself.
The legal basis of training data remains the unresolved question beneath this stack, and the answer is currently being written from three directions: statute, court and contract. Section 3(c)(ii) of the DPDP Act places publicly available personal data outside the statute; the copyright position has now received its first, but expressly provisional judicial treatment:[30] in July 2026, the Delhi High Court refused ANI Media (P) Ltd.’s (“ANI”) interim injunction against Open AI OPCO LLC (“OpenAI”), holding prima facie that storing copyrighted news content to train LLMs falls within the fair-dealing exception for “private or personal use, including research” under Section 52(1)(a)(i) of the Copyright Act, 1957, and that ANI had not demonstrated memorization or regurgitation of its work in the model’s outputs. The holding is confined to the injunction application, and the court stated its findings would not prejudice final adjudication, and the main suit continues. Therefore, India’s operative rule on training-data lawfulness presently rests on a prima facie reading of a closed statutory exception drafted long before machine learning existed. The third source is contractual: the licensing terms attached to AI Kosha datasets will set de facto national norms for lawful access to training data, and will do so faster than either the courts or the Parliament.
None of this need burden low-risk innovation. As argued above, the regulatory trigger is capability and context. Small developers, academic projects, public-interest tools and ordinary enterprise applications should face minimal obligations; the structured requirements attach where systems are high-capability, deployed at scale, or integrated into sensitive sectors.
Critical Infrastructure and Incidents Beyond Cyber
AI governance is also a critical infrastructure question.[31] India already accepts that some digital systems are vital enough to warrant a distinct protective regime. The National Critical Information Infrastructure Protection Centre (“NCIIPC”) exists under Section 70A of the IT Act because the disruption of such systems can affect national security, the economy, public health or safety.[32]
As the adoption of AI expands across banking, logistics, healthcare, manufacturing, power systems, transport, agriculture, urban governance and public administration, governance failures may not remain confined to software performance but may have financial, public health, trade, security or democratic implications.
For example, an AI-enabled cyber vulnerability in a port system[33] can affect trade. A flawed health AI tool can affect diagnosis and public trust.[34] An autonomous financial tool can create market or consumer harm.[35] Deepfakes can distort elections[36] and social stability.[37] AI-enabled fraud can scale faster[38] than traditional enforcement systems can respond.
India’s cybersecurity apparatus has moved early on this front. CERT-In’s 2026 Advisory on frontier AI-driven cyber risks, its Blueprint for defending digital infrastructure against AI-assisted vulnerability exploitation[39], and the June 2026 CERT-In Guidelines for Original Equipment Manufacturers (OEMs),[40] together recognise that frontier systems accelerate vulnerability discovery, exploit development, reconnaissance, phishing and multi-stage operations, and the OEM Guidelines carry that recognition into compliance practice through requirements on AI-assisted security testing, accelerated patching, disclosure and supply-chain assurance. These instruments show CERT-In acting in anticipation of AI-enabled cyber risk rather than in reaction to it.
CERT-In’s remit, however, is cyber. Existing hooks under the IT Act and the Intermediary Rules reach impersonation, unlawful synthetic media, privacy violations and platform takedown duties. They do not reach the wider class of AI incidents that India’s own governance process contemplates: discriminatory automated decisions, wrongful denial of public services, unsafe autonomous behaviour, and critical-sector malfunctions that involve no cyber breach at all.
The Guidelines answer this gap with a voluntary, no-penalty AI incidents database That design will, however, under-collect precisely the incidents that matter most, because those are the incidents that carry legal and reputational exposure for the reporting organisation. The sounder design separates the duty from the consequence. Reporting of material AI incidents should therefore be a mandatory, time-bound duty for deployers of systems that meet the capability-and-context triggers, just as CERT-In already requires cyber incidents to be reported within six hours. California’s SB-53 supplied the second element of the design: incident reports flow through a confidential channel shielded from public disclosure, and the duty is enforced through penalties for failing to report, not through the contents of the report itself. India should add a third element: an entity that reports in good faith and on time should not have its own disclosure treated as primary evidence for penalizing it. The duty makes the system enforceable and the database representative; the safe harbour preserves the incentive to report. The protection should be use-based rather than an immunity: the report cannot be tendered as primary evidence against its maker, but regulators remain free to act on independently obtained material, and protection attaches only to timely, good-faith disclosure and never to the underlying conduct. Because only statute can restrict what an independent regulator does with a document, the safe harbour is a further reason the duty ultimately requires statutory form. Reports should flow to a coordination point shared by CERT-In, sectoral regulators and the AIGG, so that recurring failure patterns are visible across sectors before they scale.
One note of realism belongs here. CERT-In’s existing six-hour mandate is itself unevenly complied with, and an AI-incident duty enacted without supervisory capacity would repeat that experience.[41] Materiality thresholds, graduated reporting timelines and budgeted analytical staffing are part of the design, not refinements to it.
Federalism: Where National Guardrails Meet State Deployment
The deployments this brief is most concerned with are welfare eligibility, policing, health administration, land records which are executed largely by state governments, because health, agriculture, police and land are State List subjects under the Seventh Schedule of the Constitution. National guidelines do not automatically reach a state department’s procurement of a risk-scoring or facial-recognition system. India’s AI governance question is therefore vertical as well as horizontal, and the southern states illustrate both the stakes and the vacuum.
Several of them have legislated or issued policy into the gap: Tamil Nadu adopted a Safe and Ethical AI policy as early as 2020,[42] and Telangana and Karnataka operate their own AI frameworks and missions.[43] Their economies show why governance quality is a competitiveness variable rather than a compliance cost. Karnataka’s expanding technology ecosystem[44] and Bengaluru’s start-up base[45] make export-facing IT services dependent on cross-border trust in data handling and product safety. Tamil Nadu’s ports and logistics chains - three of India’s twelve major ports sit on its coast – are digitizing under the Sagarmala programme’s modernization pillar which includes AI-driven logistics management, making their reliability and cybersecurity trade issues rather than IT issues; the stakes are not hypothetical, as the V.O. Chidambaram Port at Tuticorin was among the NCIIPC-designated critical infrastructure entities targeted by the China-linked RedEcho Group in 2020-21.[46] Telangana’s pharmaceutical and health-technology base raises consent, data protection and liability questions in clinical AI.[47] Kerala’s public-service delivery model makes administrative opacity a direct public-trust risk.[48] Andhra Pradesh’s ports and industrial corridors, together with the maritime Union Territories of Puducherry, Lakshadweep and the Andaman and Nicobar Islands, sit within strategically significant coastal geographies where AI-enabled logistics and surveillance intersect with maritime security.[49]
What is missing is a mechanism through which national standards in impact assessment, audit, and incident reporting, bind state procurement and deployment. Three instruments could close this gap without constitutional strain: model procurement clauses issued for adoption by states; conditionality attached to centrally sponsored digital schemes, as is already routine in other sectors; and a standing AIGG–state coordination channel through which state deployments feed the national incidents database and draw on national risk frameworks. Without a vertical mechanism of this kind, the guardrails debate will remain a Union-level conversation about deployments that mostly happen elsewhere.
From Voluntary Principles to Auditable Assurance
The AIdea of India: Outlook 2026 report records a consequential shift: Indian enterprises are moving from AI pilots to production, and they identify integration, data readiness, security, compliance and scaling as their principal obstacles.[50] As AI industrialises, institutions must be able to demonstrate, through evidence rather than attestation, that responsible-AI principles operate in practice. For high-impact systems, that means living compliance artefacts: documentation duties (model documentation, dataset versioning, decision logs) and verification duties (impact assessments, periodic safety review, audit, and third-party validation where the stakes warrant it).
The Guidelines’ answer is that voluntary frameworks will generate the evidence base for later binding rules, and that many AI risks are addressable under existing law.[51] Both claims are half right. Evidence generation and enforceability are complements rather than alternatives. A mandatory reporting duty is the evidence engine, since voluntary schemes systematically omit the incidents with legal exposure. And existing-law coverage fails at exactly the cross-cutting incidents identified above. Sequencing voluntarism first defers the hard cases; it does not resolve them.
Public-sector AI warrants treatment as a distinct governance category. Where systems decide eligibility, score risk, detect fraud, recognise faces or allocate public-health resources, voluntary compliance is insufficient, because such decisions engage the constitutional standards discussed earlier. The duties follow from the doctrine: pre-deployment impact assessment, human review of adverse decisions, audit trails, explainability proportionate to the decision’s consequences, accessible grievance redressal, and named responsibility within the deploying department. The instruments are available now. Conditions of this kind can be written into government procurement contracts and imposed through departmental office memoranda, routes that the executive already uses to set procurement policy across ministries[52] without waiting for statute. And building the Puttaswamy proportionality into deployment is considerably cheaper than litigating it out afterwards.
Nonetheless, the limit of this route should be stated as plainly as its speed: instruments the executive issues, the executive can withdraw, and they create no statutory rights in the person wrongly denied a benefit. They are scaffolding for a dedicated legislation addressing the gap and not a substitute for it — though once departments publish standards for automated decisions, Article 14’s bar on arbitrary departure from self-imposed norms lends even these instruments a measure of enforceability.
India and the Global South
India cannot simply import a governance model. The EU’s risk-tiered regime is under active revision amid competitiveness pressure. The United States pairs an innovation-first federal posture with state-level frontier statutes such as SB-53. China’s approach is state-directed. India’s circumstances differ from all three: population-scale public deployment, digital public infrastructure, linguistic diversity, and a development mandate that regulation must serve rather than obstruct.
Those circumstances are shared across much of the Global South, which is why India’s choices will travel. The ambition itself is not new, i.e., the 2018 NSAI already cast India as an “AI Garage” for emerging economies, building solutions for Indian conditions and replicating them in similarly placed countries. What has been missing since 2018 is the implemented governance record that would make the Garage’s exports credible. The vehicles are concrete rather than aspirational: the India AI Impact Summit in New Delhi in February 2026, the first frontier-AI summit hosted in the Global South;[53] India’s standards and GPAI engagement; and the export of digital public infrastructure, through which India’s governance defaults propagate to adopting countries. But leadership of this kind is a function of implementation. India can export only a governance model it has actually operated, and its credibility abroad will track its enforceability at home.
Conclusion and Recommendations
India’s AI challenge is not a lack of ambition but the task of making ambition governable. The framework India has already designed can acquire legal force through five instruments, none of which requires abandoning an innovation-first posture:
Each instrument is calibrated. Voluntary frameworks continue to govern low-risk innovation; sectoral regulators retain their domains; enforceable obligations attach only where capability, context and constitutional stakes demand them. India has built the policy vocabulary and much of the institutional design for this transition. Whether principles become guardrails, and guardrails become practice, before high-impact deployment outpaces both is the test the next two years will set.
REFERENCES:
[1] Cabinet Approves Ambitious IndiaAI Mission to Strengthen the AI Innovation Ecosystem, Press Information Bureau of India, New Delhi, 07 March 2024, available at https://www.pib.gov.in/PressReleasePage.aspx?PRID=2012355 (last accessed on 10 June 2026).
[2] AI Safety Summit 2023: The Bletchley Declaration, 13 February 2025, available at https://www.gov.uk/government/publications/ai-safety-summit-2023-the-bletchley-declaration/the-bletchley-declaration-by-countries-attending-the-ai-safety-summit-1-2-november-2023 (last accessed on 01 July 2026).
[3] Collaco, B.G., Haider, S.A., Prabha, S. et al., The role of agentic artificial intelligence in healthcare: a scoping review, npj Digit. Med. 9, 345 (March 2026), available at https://doi.org/10.1038/s41746-026-02517-5 (last accessed on 10 June 2026).
[4] Roshan Shetty, This is what the new frontier of AI-powered financial inclusion looks like, World Economic Forum, 09 December 2025, available at https://www.weforum.org/stories/financial-and-monetary-systems/this-is-what-the-new-frontier-of-ai-powered-financial-inclusion-looks-like/ (last accessed on 10 June 2026).
[5] Berlin Global Government Technology Centre & Capegemini, Making Agentic AI Work for Government: A Readiness Framework, Insight Report, World Economic Forum, April 2026, available at https://reports.weforum.org/docs/WEF_Making_Agentic_AI_Work_for_Government_A_Readiness_Framework_2026.pdf (last accessed on 09 June 2026).
[6] Anthropic, Project Glasswing: An initial update, Announcements, 22 May 2026, available at https://www.anthropic.com/research/glasswing-initial-update; See also, Anthropic, Assessing Claude Mythos Preview’s cybersecurity capabilities, Frontier Red Team, 07 April 2026, available at https://www.anthropic.com/research/mythos-preview.
[7] Julapa Jagtiani, Raghavendra Rau, et al., AI-Enabled Fraud is on the rise – Here’s how to beat it, Federal Reserve Bank Philadelphia, 26 March 2026, available at https://www.philadelphiafed.org/-/media/FRBP/Assets/Economy/Articles/ai-enabled-fraud-is-on-the-rise-article.pdf (last accessed on 10 May 2026).
[8] Dia Rekhi, Your vote for their prompts: Risk of ‘AI swarms’ automating political movements rises, The Economic Times, 09 June 2026, available at https://economictimes.indiatimes.com/tech/artificial-intelligence/your-vote-for-their-prompts-risk-of-ai-swarms-automating-political-movements-rises/articleshow/131599532.cms?from=mdr (last accessed on 09 June 2026).
[9] Daniel I. Weiner & Lawrence Norden, Regulating AI Deepfakes and Synthetic Media in the Political Arena, Expert Brief, Brennan Center for Justice, 05 December 2023, available at https://www.brennancenter.org/our-work/research-reports/regulating-ai-deepfakes-and-synthetic-media-political-arena (last accessed on 09 June 2026).
[10] Shashi Tharoor, The new digital slavery needs constitutional guardrails, The Hindu, p.08, 29 June 2026; See also, Marc Ballon, USC Study Finds AI Agents Can Autonomously Coordinate Propaganda Campaigns Without Human Direction, 11 March 2026, available at https://viterbischool.usc.edu/news/2026/03/usc-study-finds-ai-agents-can-autonomously-coordinate-propaganda-campaigns-without-human-direction/; and Raluca Csernatoni, Can Democracy Survive the Disruptive Power of AI?, Carnegie Europe, available at https://carnegieendowment.org/research/2024/12/can-democracy-survive-the-disruptive-power-of-ai (last accessed on 20 June 2026).
[11] Frontier AI Trends Report, AI Security Institute, December 2025, available at https://aisi.s3.eu-west-2.amazonaws.com/Frontier+AI+Trends+Report+-+AI+Security+Institute.pdf (last accessed on 20 June 2026).
[12] Defending Against Frontier AI Driven Cyber Risks, CERT-In Advisory 2026 (20), 26 April 2026, available at https://www.cert-in.org.in/s2cMainServlet?VLCODE=CIAD-2026-0020&pageid=PUBVLNOTES02 (last accessed on 20 June 2026).
[13] Office Memorandum, Ministry of Electronics and Information Technology, Government of India, New Delhi, No.4(8)/2017-ITEA, 07 February 2018, available at https://www.meity.gov.in/static/uploads/2024/02/constitution_of_four_committees_on_artificial_intelligence_0.pdf (last accessed on 07 July 2026).
[14] Ministry of Electronics and Information Technology, Government of India, Draft Report of Committee-A on Platforms and Data on Artificial Intelligence, July 2019, available at https://www.meity.gov.in/static/uploads/2024/02/11ab.pdf (last accessed on 07 July 2026).
[15] National Strategy for Artificial Intelligence, NITI Aayog, June 2018 available at https://www.niti.gov.in/sites/default/files/2023-03/National-Strategy-for-Artificial-Intelligence.pdf (last accessed on 10 June 2026).
[16] Responsible AI: Approach Document for India, Part 1- Principles for Responsible AI, NITI Aayog, February 2021, available at https://www.niti.gov.in/sites/default/files/2021-02/Responsible-AI-22022021.pdf (last accessed on 12 June 2026).
[17] See Report on AI Governance Guidelines, IndiaAI, available at https://indiaai.gov.in/article/report-on-ai-governance-guidelines-development (last accessed on 20 June 2026).
[18] Subcommittee on AI Governance and Guidelines Development, Ministry of Electronics and Information Technology, Government of India, Report on AI Governance Guidelines Development (2025) available at https://indiaai.s3.ap-south-1.amazonaws.com/docs/subcommittee-report-dec26.pdf (last accessed on 20 June 2026).
[19] Ministry of Electronics and Information Technology, Government of India, India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation, available at https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf (last accessed on 25 June 2026).
[20] Securities and Exchange Board of India, Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection, Circular No.: HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, 5 May 2026, available at https://www.sebi.gov.in/legal/circulars/may-2026/advisory-on-emerging-advanced-artificial-intelligence-ai-tools-for-vulnerability-detection_101270.html (last accessed on 01 August 2026).
[21] K.S. Puttaswamy v. Union of India , (2017) 10 SCC 1.
[22] See Dr. Raghvendra Kumar Chaudhary, Constitution never approved algorithmic governance: Why India Needs Right to Human Decision-Making, 06 August 2026, LiveLaw, available at https://www.livelaw.in/articles/constitution-never-approved-algorithmic-governance-india-right-human-decision-making-544523 (last accessed on 08 August 2026). The author persuasively argues that Article 14’s guarantee against arbitrariness and Article 21’s promise of fair procedure both presuppose a decision-maker capable of reasoning, explanation, and being persuaded. Chaudhary traces this lineage through A.K. Kraipak v. Union of India (extending natural justice to administrative functions) and Maneka Gandhi v. Union of India (requiring state action to be fair, just, and reasonable). Because automated systems classify rather than reason, their deployment by the State without human review evades the traditional ‘application of mind’ required under Indian administrative law. This administrative evasion is illustrated by the tragic 2017 case of eleven-year-old Santoshi Kumari, whose family ration card was automatically cancelled by a database update without any human officer executing a formal ‘decision’.
[23] NJCM v. Staat der Nederlanden, Rb. Den Haag, 5 Feb. 2020.
[24] R (Bridges) v. Chief Constable of South Wales Police, [2020] EWCA Civ 1058.
[25] Amber Sinha, India’s New AI Governance Plan is Much Ado About Nothing, TechPolicy.Press, 21 November 2025, available at https://www.techpolicy.press/indias-new-ai-governance-plan-is-much-ado-about-nothing/ (last accessed on 2 June 2026).
[26] Apar Gupta & Naman Kumar, Green Light for AI, Orange for Rights, 26 November 2025, available at https://internetfreedom.in/green-light-for-ai-orange-for-rights/ (last accessed on 10 June 2026).
[27] Apar Gupta, Gayatri Malhotra & Naman Kumar, Submission on behalf of the Internet Freedom Foundation to the thematic report Freedom of Expression and Elections in the Digital Age by the Special Rapporteur on Freedom of Opinion and Expression, 15 January 2025, available at https://drive.google.com/file/d/1g9Rskybv_WDweWCniaZH6B9M05RmiseV/view?ref=static.internetfreedom.in (last accessed on 10 June 2026).
[28] Experiments in AI, IndiaAI Mission: Dataset over GPUs, 17 August 2025,
https://gpt3experiments.substack.com/p/indiaai-mission-dataset-over-gpus (last accessed on 6 June 2026).
[29] Alexy Thomas, Unified data stack: the missing link in India’s AI ambitions, 02 January 2026, available at https://www.forbesindia.com/article/upfront/column/unified-data-stack-the-missing-link-in-indias-ai-ambitions/2989946/1 (last accessed on 05 June 2026).
[30] ANI Media Pvt. Ltd. v. Open AI OPCO LLC, I.A. 45300/2024 in CS (Comm) 1028/2024, I.A. 45301/2024 & I.A.26192/2025, 24 July 2026, available at https://delhihighcourt.nic.in/app/showFileJudgment/ABL24072026SC10282024_171649.pdf (last accessed on 29 July 2026).
[31] Matteo Wong, Claude Mythos is everyone’s problem, The Atlantic, 09 April 2026, available at https://www.theatlantic.com/technology/2026/04/claude-mythos-hacking/686746/ (last accessed on 15 May 2026).
[32] Leah Sadoian, NCIIPC Explained: Safeguarding India’s Critical Infrastructure, 01 December 2025, available at https://www.upguard.com/blog/nciipc-explained (last accessed on 10 June 2026).
[33] Anusha Guru, Securing Indian Ports: Cyber Security Vulnerabilities and the Road Ahead, Observer Research Foundation, 17 July 2025, available at https://www.orfonline.org/expert-speak/securing-indian-ports-cybersecurity-vulnerabilities-and-the-road-ahead (last accessed on 10 June 2026).
[34] Choi, J., Kim, Y.J., Lyu, P. et al. Public reactions to hospitals after adverse events involving AI, npj Digital Public Health 1, 17 (2026). https://doi.org/10.1038/s44482-026-00021-x (last accessed on 10 June 2026).
[35] Potential market crisis from autonomous AI trading systems, OECD.AI Policy Observatory, available at https://oecd.ai/en/incidents/2025-04-09-a174 (last accessed on 06 June 2026).
[36] See Supra n.8, Your vote for their prompts & n.9 Regulating AI Deepfakes and Synthetic Media in the Political Arena.
[37] Eurasian Research Institute, Deepfakes’ social risks, Akhmet Yassawi University, available at https://www.eurasian-research.org/publication/deepfakes-social-risks/; See also, Andrey G. Ignatyev, Tatiana A. Kurbatova, Deepfakes and Security in the Information Environment Challenges for Governments, Society, and Business, available at https://www.global-solutions-initiative.org/publication/deepfakes-and-security-in-the-information-environment-challenges-for-governmentssociety-and-business/ (last accessed on 06 June 2026).
[38] Supra n. 7, AI Enabled Fraud is on the Rise.
[39] CERT-IN, Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities and Exploitation in Digital Infrastructure, 25 May 2026, available at https://cert-in.org.in/PDF/Blueprint_for_Defending_against_AI_Assisted_Exploitataion.pdf (last accessed on 10 June 2026).
[40] CERT-IN, Guidelines regarding AI-Accelerated Vulnerability Protection and Response Requirements for Original Equipment Manufacturers (OEMs), and Technology Providers, 10 June 2026, available at https://www.cert-in.org.in/PDF/OEM_and_Technology_Providers_Guidelines.pdf (last accessed on 10 June 2026).
[41] Sarvesh M, RTI: No details on how many entities have complied with CERT-In’s cybersecurity directions, 21 March 2023, MEDIANAMA, available at https://www.medianama.com/2023/03/223-rti-cert-in-cybersecurity-directions-compliance-status/; See also, Sarvesh M, Cybersecurity rules: Only 15 entities reported incidents within the stipulated 6 hours, RTI reveals, 21 March 2023, MEDIANAMA, available at https://www.medianama.com/2023/03/223-cybersecurity-incident-reporting-six-hour-window-rti/ (last accessed on 20 June 2026).
[42] Government of Tamil Nadu, Tamil Nadu Safe and Ethical Artificial Intelligence Policy, 2020, available at https://it.tn.gov.in/sites/default/files/2021-06/TN_Safe_Ethical_AI_policy_2020.pdf (last accessed on 10 June 2026).
[43] See generally Dr. Nivash Jeevanandam, Six Notable Indian state governments AI initiatives in 2024, IndiaAI Mission, 10 November 2024, available at https://indiaai.gov.in/article/six-notable-indian-state-governments-ai-initiatives-in-2024 (last accessed on 10 June 2026).
[44] State planning commission pitches tech ecosystem push beyond Bengaluru to tier-II, III cities, The Economic Times, 11 May 2026, available at https://economictimes.indiatimes.com/tech/technology/state-planning-commission-pitches-tech-ecosystem-push-beyond-bengaluru-to-tier-ii-iii-cities/articleshow/131017782.cms?from=mdr (last accessed on 10 June 2026).
[45] Shilpa Elizabeth, Bengaluru ranked second-best AI-native cluster in Asia, top 15th startup ecosystem globally, The Hindu, 17 June 2026, available at https://www.thehindu.com/news/cities/bangalore/bengaluru-ranked-second-best-ai-native-cluster-in-asia-top-15th-startup-ecosystem-globally/article71112163.ece (last accessed on 10 June 2026).
[46] Sushovan Sircar, Chinese ‘Red Echo’ Targeted 10 Power Stations, 2 Ports in India, The Quint, 05 March 2021, available at https://www.thequint.com/cyber/security/chinese-state-sponsored-red-echo-to-continue-targeting-india-2021-power-grid-port#read-more (last accessed on 10 June 2026); See also Vaitheeswaran B, Tamil Nadu worries AI and trade risks impacting economic growth, https://timesofindia.indiatimes.com/city/chennai/tamil-nadu-worries-ai-trade-risks-impacting-economic-growth/articleshow/118983278.cms (last accessed on 17 June 2026).
[47] See Shantanu Jindel & Shweta Gupta, AI in healthcare: trends and challenges in India, 02 November 2023, available at https://www.ibanet.org/ai-healthcare-india (last accessed on 10 June 2026).
[48] Abhijay S, From Opaque to Open: The Quest for Algorithmic Accountability in Indian Public Services, Impact and Policy Research Institute, 18 March 2026 available at https://www.impriindia.com/insights/algorithmic-accountability-services/#google_vignette (last accessed on 10 June 2026).
[49] See Supra n. 33, Securing Indian Ports: Cyber Security Vulnerabilities and the Road Ahead.
[50] Earnst & Young, Is India ready for Agentic AI - The AIdea of India: Outlook 2026, Confederation of Indian Industry, 2026, available at https://www.ey.com/content/dam/ey-unified-site/ey-com/en-in/insights/ai/documents/is-india-ready-for-agentic-ai-the-aidea-of-india-outlook-2026.pdf (last accessed on 10 June 2026).
[51] Supra n. 17, AI Governance Guidelines.
[52] See General Financial Rules, 2017, Ministry of Finance (Department of Expenditure); for precedent of government-wide procurement conditions imposed by executive order, see Rule 144(xi), inserted by OM No. F.6/18/2019-PPD (23 July 2020).
[53] Jibu Elias, The Global South can shape AI in practical terms: Why the India AI Impact Summit Matters, OECD.AI Policy Observatory, 15 February 2026, available at https://oecd.ai/en/wonk/the-global-south-can-shape-ai-in-practical-terms-why-the-india-ai-impact-summit-matters (last accessed on 10 June 2026).
Simhanjana Gopikrishna Sumathi is a Research Officer at the Deccan Centre for International Relations. She holds an LLM in National Security Laws with a Certificate in International Human Rights Laws from Georgetown University Law Centre, and her research focuses on national security law and policy, geopolitics, AI governance and emerging technologies, with particular emphasis on their implications for India and the Indo-Pacific. She is an attorney and published researcher with experience across legal practice, policy research and international affairs.
Disclaimer: The views and opinions expressed in the article are those of the author and do not necessarily reflect the official position of the Deccan Centre for International Relations.