NextFin News - India is moving closer to a dedicated artificial-intelligence law after years of relying on existing internet and information-technology rules to manage synthetic content, deepfakes and other AI-related harms. IT Secretary S. Krishnan said the government has already used the IT rules and other provisions of law to address AI concerns, but that “probably the time has come to look at a separate legislation.”
The significance is less about a draft bill than about a policy shift. India’s current framework was built for intermediaries, takedowns and platform obligations. AI systems do not fit neatly into that model because they generate content, automate decisions and can be embedded across products and services in ways that blur the line between developer, deployer and user. Krishnan’s remarks suggest the ministry now sees those differences as large enough to justify a separate regulatory architecture.
That matters for companies because the move would take AI governance beyond content removal and into questions of transparency, testing, accountability and risk classification. It also matters for regulators because the technology is moving from experimental use into customer service, code generation, fraud detection, advertising and public-service delivery faster than the rulebook can evolve. Once AI becomes operational infrastructure rather than a novelty, general-purpose digital rules start to look incomplete.
Krishnan’s wording was careful. He did not announce a bill, a timetable or a final policy design. He said the government will “start looking at it” and that “the time is getting right.” That suggests consultation rather than immediate legislation, but it still marks a more explicit acknowledgment that AI may need rules distinct from the broader IT framework.
India has already shown its willingness to extend existing digital rules to synthetic media. The government has used the IT Rules, 2021 to tighten obligations on online platforms, including a requirement to remove AI-generated or synthetic content flagged by a competent authority or court within three hours. It has also proposed stricter disclosure requirements for synthetically generated information, including labels that remain visible during visual displays. Those steps address the outputs of AI. A separate framework would move upstream and ask how the systems themselves should be governed.
That distinction is central to the policy debate. A takedown rule can limit the spread of harmful content, but it does not resolve who is responsible when a chatbot fabricates information, a voice clone is used for fraud or an automated decision system produces an unfair result. A technology-specific law would have to decide whether obligations fall on the model developer, the app builder, the enterprise customer or all three.
Why Existing Rules Are Starting To Look Insufficient
India’s present approach works best when a harmful piece of content can be identified, flagged and removed. AI makes that model weaker. Generative systems can produce text, audio, image and video at scale, and they can do it inside products that do not look like traditional social platforms. That creates a regulation problem that is broader than content moderation and narrower than a full technology ban. It is a governance problem.
That is why accountability becomes so difficult. If a synthetic voice is used in a fraud attempt, the harm may involve a model developer, a distribution platform, a product integrator and the criminal actor who used the tool. If an AI assistant gives bad advice in finance, health or employment, the line between “tool” and “decision-maker” is often blurry. Legacy platform rules are not built for that ambiguity.
India can still lean on cybercrime provisions, intermediary obligations and consumer-protection tools for some cases. But those tools are reactive, and AI harms often spread faster than complaints can be processed. Once that mismatch becomes routine, the result is patchwork enforcement: some harms covered, some ignored, and similar systems treated differently depending on how they are deployed.
There is also a development-policy angle. India wants AI adoption to accelerate in banking, healthcare, education, logistics, retail and government services. Those are the same sectors where a bad model decision can create material damage. That is why the debate is not about whether to regulate AI, but how to do it without freezing deployment or leaving critical uses unaccountable.
The most likely answer is gradualism. Existing IT rules can deal with immediate synthetic-media issues, while a separate law can set out the rules for higher-risk AI use. That sequencing would reflect a simple reality: ad hoc fixes have been useful, but they are no longer enough on their own.
What A Separate Framework Would Need To Cover
The hard part now is design. A meaningful AI framework would need to distinguish between developers, deployers and users; between high-risk and low-risk applications; and between systems that assist human judgment and systems that make or materially shape decisions on their own. Without those distinctions, any law risks being either too broad to enforce well or too narrow to matter.
At minimum, policymakers would need to decide whether AI used in sensitive sectors should face documentation, audit or testing requirements before deployment. Financial services, insurance, employment, education, healthcare and public-sector services all raise different risks. A one-size-fits-all regime could impose heavy compliance costs on low-risk applications while failing to target the highest-stakes ones.
Enforcement is another issue. India’s digital rules have often relied on complaint-driven removal and intermediary compliance. AI governance is likely to require more proactive tools such as logging, incident reporting, model testing, red-teaming or pre-deployment assessments. Without some version of that, regulators would mostly be arriving after harm has already occurred.
India is unlikely to copy the strictest global model in full. Its policy style has generally favored flexibility, with broad principles in law and more detailed guidance later from the executive or a designated regulator. That approach would preserve room to adjust as models evolve, but it would still leave companies with a clearer compliance map than the current patchwork.
For businesses, the signal is already clear even without a bill. The era when AI could be treated as a temporary policy gap is ending. Firms operating in India should expect more scrutiny around disclosure, provenance, automated decision-making and synthetic media. The challenge will be less about accepting regulation in principle and more about building systems that can live with it.
“We have used the IT rules, and other provisions of existing law to address various concerns that AI raises, but now, probably the time has come to look at a separate legislation.”
Krishnan’s remarks do not define the eventual rulebook, but they do show that India’s AI debate has moved from principle to architecture. That usually means the policy conversation is no longer theoretical. It is becoming a design exercise.
The immediate market takeaway is not that India wants to suppress AI adoption. It is that the government now appears willing to treat AI as a separate policy category with separate risks and, eventually, separate obligations. The next question is how far it will go once the consultation begins.
Explore more exclusive insights at nextfin.ai.
