Summary
MeitY is weighing a standalone law to regulate AI, separate from the IT Act, 2000, covering agentic AI autonomy, consent-based rules for deepfakes and regulatory sandboxes for high-risk sectors like finance. Two private legal experts have been asked to draft separate liability frameworks, as officials grapple with how the IT Act's "safe harbour" principle applies to AI systems that actively generate, not just host, content.
WHY IN NEWS FOR UPSC & STATE PCS
The move follows growing instances of high-quality deepfakes and mounting concern over agentic AI - autonomous systems that plan and execute multi-step tasks with minimal human oversight. The government previously held that existing laws were sufficient for AI; this marks a clear reversal, prompted partly by incidents like Grok AI being reprimanded for enabling deepfakes of women.
Standard News
The law was written for platforms that host. AI platforms create.
A rule built for a different problem Section 79 of the IT Act, 2000 gives internet platforms "safe harbour"
- legal protection from liability for what their users post. The logic is straightforward: a platform can't be expected to police every piece of content a user uploads in real time, so as long as it removes flagged material when notified, it isn't treated as the author of the harm. That logic depends entirely on one assumption: the platform is a passive host and a human user is the one who actually created the problematic content. AI breaks that assumption completely. When a generative AI model produces a deepfake or an AI chatbot generates a defamatory claim about a real person, there was no user "posting" anything in the traditional sense - the system itself generated the content, often by pattern-matching across scraped internet data and then editorializing in ways that are genuinely hard to trace back to any single source.
Who actually gets hurt when this gap exists Picture a woman whose public Instagram photos get scraped and turned into a non-consensual deepfake by an AI tool she's never heard of, on a platform she never used. Under India's current data law, this scenario sits in an uncomfortable legal blind spot: the Digital Personal Data Protection Act, 2023 exempts publicly available personal data from its protections, meaning the very fact that her photos were public makes them fair game for scraping under existing rules. The AI platform isn't quite a "publisher" the way a newspaper is and it isn't quite a neutral "host" the way a comment section is either - it's something the current legal categories weren't built to describe. This is precisely the gap MeitY is now trying to close with a standalone AI law - not a patch to the IT Act, but a separate framework built around consent for synthetic media and around defining exactly how much autonomy an "agentic" AI system should be allowed before its actions require a clearly identifiable, liable party standing behind them.
Why "agentic" is the harder half of the problem Deepfakes are the visible, easily explained version of this issue.
Agentic AI - systems that don't just generate a single output but autonomously plan and execute multi-step actions, retaining and reusing data along the way - is the version regulators are far more anxious about, precisely because accountability gets murkier with every additional autonomous step the system takes on its own.
That's why the government specifically flagged Singapore's newly announced agentic AI governance framework as a reference point and why even historically lighter-touch regulatory jurisdictions are re-examining their stance.
The exam-relevant insight here isn't "India is regulating AI"
- it's that the entire liability architecture built for the user-generated content era assumed a human always sits behind the harmful output. AI has quietly broken that assumption and the law is only now catching up to say so.
Quick Facts
MeitY is weighing a standalone AI law (separate from the IT Act, 2000) covering a consent-based framework for synthetic content, curbs on agentic AI autonomy, and regulatory sandboxes for high-risk applications. Two legal experts have been asked to submit separate draft liability frameworks. RBI and SEBI expected to be consulted for sandboxes in finance and public services.
Connect the dots for your UPSC preparation.
Standard news covers the event. Log in to read our comprehensive analysis and uncover the hidden constitutional, structural, and ethical dimensions of this topic:
The exact legal distinction MeitY's two private-sector legal experts are being asked to resolve between "generator" liability and "host" liability
Why the DPDP Act's public-data exemption creates a specific, exploitable loophole for AI training data scraping
How the proposed regulatory sandbox with RBI and SEBI would work in practice for high-risk financial AI applications
What Singapore's Model AI Governance Framework for agentic AI actually proposes and why India is studying it closely
Included in this analysis
Join thousands of aspirants analyzing the news deeply.
Log In to Read Full ArticleDon't have an account? Sign up for free