India’s Ministry of Electronics and Information Technology (MeitY) has released AI governance guidelines that represent the country’s first comprehensive framework for responsible AI deployment. While advisory rather than legally binding, these guidelines carry significant weight for businesses operating AI systems in India.
Overview of the Framework
The guidelines establish a set of principles and expectations for AI development and deployment, drawing from global best practices while adapting them to the Indian context. The framework covers the entire AI lifecycle — from design and development through deployment and monitoring.
Core Principles
Transparency and Explainability
Organisations deploying AI systems must ensure that the decision-making processes of their AI models are transparent and explainable to the extent practicable. This is particularly critical for AI systems used in:
- Credit scoring and lending decisions
- Healthcare diagnostics
- Government service delivery
- Recruitment and employment decisions
Fairness and Non-Discrimination
AI systems must be designed and tested to minimise bias and ensure equitable outcomes across different demographic groups. The guidelines specifically reference the need to address bias in training data, algorithmic design, and output validation.
Accountability
The guidelines establish a clear expectation that organisations deploying AI systems maintain human oversight and accountability mechanisms. This includes:
- Designating a responsible person or team for AI governance
- Maintaining audit trails of AI-driven decisions
- Establishing grievance redressal mechanisms for individuals affected by AI decisions
- Regular impact assessments for high-risk AI applications
Intersection with the DPDPA
The AI governance guidelines must be read alongside India’s Digital Personal Data Protection Act (DPDPA). Where AI systems process personal data, the full suite of DPDPA obligations applies, including:
- Consent requirements for data used in AI training and inference
- Purpose limitation restricting the use of personal data to stated purposes
- Data minimisation ensuring only necessary data is processed
- Right to erasure which may conflict with model training requirements
Key insight: The intersection of AI governance and data protection creates a dual compliance requirement that many organisations in India are not yet prepared for. Companies deploying AI should conduct a combined AI governance and DPDPA compliance assessment rather than treating them as separate exercises.
Implications for Businesses
Immediate Actions
Businesses deploying AI in India should consider the following steps even though the guidelines are currently advisory:
- Conduct an inventory of all AI systems in use across the organisation
- Assess each system against the MeitY principles
- Document AI governance processes and decision-making frameworks
- Establish bias testing and monitoring protocols
- Integrate AI governance considerations into existing data protection compliance programmes
Looking Ahead
The advisory nature of these guidelines is likely temporary. India’s regulatory trajectory suggests that binding AI legislation will follow, potentially building on this framework. Early compliance positions organisations favourably for when mandatory requirements are introduced.
Comparison with Global Frameworks
| Aspect | India (MeitY) | EU AI Act | US (NIST AI RMF) |
|---|---|---|---|
| Legal status | Advisory | Binding regulation | Voluntary framework |
| Risk classification | Implicit | Explicit (4 tiers) | Risk-based approach |
| Penalties | None currently | Up to €35M / 7% turnover | None |
| Sectoral focus | Healthcare, finance, gov | All sectors | All sectors |
| Effective date | Published 2025 | Phased 2024–2027 | Published 2023 |
Conclusion
MeitY’s AI governance guidelines represent an important first step in India’s AI regulatory journey. While not yet legally binding, they establish the baseline expectations that will likely inform future legislation. Businesses deploying AI systems in India should treat compliance with these guidelines as both a risk management exercise and a competitive advantage.