Hello, this is Ryuta Hamamoto from TIMEWELL.
India decided not to make an AI Act. In a 2026 world where the EU AI Act, Korea’s AI Basic Act, and Vietnam’s AI law are going live one after another, that stance is the one I keep coming back to.
“Not making a law” is not “no regulation.” The DPDP Act 2023 carries penalties up to 250 crore rupees. The IT Rules amendment from February 2026 imposes a 10% labeling duty. In November 2025 MeitY published AI Governance Guidelines framed as seven Sutras. Existing law does the binding. Guidelines do the philosophy.
Japanese AI media almost never treat this India-specific “Sutras” design head-on. For Japanese firms in Bengaluru, employers of Indian talent, and anyone setting global AI strategy, here is how I read the frame.
TL;DR
- India will not pass a comprehensive AI Act; it relies on DPDP Act + IT Rules + AI Governance Guidelines
- AI Governance Guidelines (November 2025) rest on seven Sutras and six Policy Pillars
- IT Rules amendment (February 2026) forces at least 10% labeling for synthetic media
- DPDP Act penalties max out at 250 crore rupees (~¥4.2 billion); full entity application from May 2027
- Three institutions: AI Governance Group, Technology and Policy Expert Committee, AI Safety Institute
- AI Impact Summit 2026 (February, New Delhi) projected Global South leadership
Why India chose “no AI Act”
On November 4, 2025, MeitY’s India AI Governance Guidelines put “light-touch” in the opening language1. That is a deliberate fourth stance—not China’s heavy state-led model, not the EU’s comprehensive hard law, not the US sectoral patchwork.
From conversations with Indian counsel and policy researchers, three reasons keep showing up.
First, protect India’s AI industry competitiveness. India is the world’s largest IT services exporter. TCS, Infosys, Wipro, HCL, Tech Mahindra and peers have huge scale on both AI development and adoption. An EU AI Act–weight regime would blunt that edge.
Second, existing law is already thick. IT Act 2000, DPDP Act 2023, the IT Intermediary Guidelines and Digital Media Ethics Code Rules 2021, plus sector regulators (RBI, SEBI, IRDAI) already supply tools. No new statute—stretch interpretation instead.
Third, leadership at AI Impact Summit 2026. Held February 19–20, 2026 in New Delhi, it was framed as the first Global South multilateral AI summit2. India sold itself as “the Global South voice that will not choke growth with heavy rules.”
I call this strategic non-regulation: not regulating is the strategy, so Indian AI industry can take global share in the gap. Japan is both competitor and student of that design.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Seven Sutras — philosophy without codifying it into hard law
The core of the Guidelines is the seven Sutras3. Borrowing Sanskrit “Sutra” (principle / aphorism) is cultural framing on purpose.
| Sutra | Meaning | Practical impact |
|---|---|---|
| 1. Trust | Establish trust | Base principle for all governance |
| 2. People First | People first | Prevent AI-driven human rights harm |
| 3. Innovation over Restraint | Innovation over restraint | Self-check against over-regulation |
| 4. Fairness & Equity | Fairness and equity | Bar algorithmic discrimination |
| 5. Accountability | Accountability | Provider responsibility systems |
| 6. Understandable by Design | Understandable by design | Embed explainable AI (XAI) |
| 7. Safety, Resilience & Sustainability | Safety, resilience, sustainability | Incident response; long-term social impact |
Order matters. Sutra 3, “Innovation over Restraint,” sits third—innovation-over-regulation is centered, unlike the EU AI Act’s “Trustworthy AI” at the top.
And the seven Sutras sit in a guideline, not a statute. No fines attach. But they will likely become interpretive hooks for IT Rules and DPDP. Litigation or administrative process may argue that an AI design “violates the Sutras.”
That is the clever part: keep philosophy out of the statute book, use it as a flexible interpretation lever. Japanese firms using AI in India can face “Sutras non-compliance” as litigation risk. Honestly, I would rather deal with a clear fine table than a philosophy that can be waved at you in court—but that is the design India chose.
Six Policy Pillars and three institutions
Six Policy Pillars carry the institutional skeleton4.
| Pillar | Content |
|---|---|
| 1. Infrastructure | IndiaAI Mission, compute, GPU sharing platforms |
| 2. Capacity Building | AI education, talent, research networks |
| 3. Policy & Regulation | Legal framework development |
| 4. Risk Mitigation | Risk management, incident response |
| 5. Accountability | Responsibility systems, grievance mechanisms |
| 6. Institutions | New bodies |
Under Institutions:
AI Governance Group (AIGG) — cross-ministry decision body, MeitY secretariat, finance/labor/health/transport among members. India’s AI policy command tower, still standing up.
Technology and Policy Expert Committee — advisory body of researchers, industry, civil society, international experts feeding AIGG; designed for public minutes and transparency.
AI Safety Institute (AISI) — technical core: safety testing, standards, international cooperation. Built to network with UK AISI (2023), US AISI (2024), and Japan AISI (2024)—a Global South AI Safety hub ambition.
AIGG and AISI target 2026 stand-up; the Expert Committee 2026–2027. What I watch closely is direct India AISI–Japan AISI linkage. Asia AI Safety cooperation with Japan and India on the front line is not a side story for us.
10% synthetic media labeling — IT Rules amendment impact
Of the three pillars, the sharpest operational bite is the IT Rules amendment (effective February 20, 2026)5. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 fold synthetically generated information (SGI) into intermediary duties.
Three main requirements:
(1) ≥10% labeling
AI-generated visual content (image/video) needs labeling for at least 10% of display time or area; audio needs an equivalent share. Explicit text such as “AI-generated” / “Synthetically Generated” is required.
(2) Permanent watermark or metadata
Labels must be in a form users cannot strip—steganographic metadata (C2PA, IPTC Photo Metadata) or persistent visual watermarks.
(3) Extra duties for Significant Social Media Intermediaries (SSMIs)
Platforms above 5 million users must:
- Collect user declarations that content is SGI
- Run reasonable automated AI-generation detection
- Display prominent labels on confirmed SGI
The 10% figure is a world-first numerical threshold—more explicit than the EU AI Act’s “clear and distinguishable” label or Korea’s “visible label.” Japanese firms shipping AI-generated content to India must build labeling that meets the 10% bar into the generation pipeline. If I had to pick one India checklist item for creative and marketing teams, it would be this.
DPDP Act’s 250 crore penalties and indirect AI reach
Without a comprehensive AI law, DPDP Act 2023 heavy fines do the de facto AI reach6.
| Violation type | Penalty cap |
|---|---|
| Serious data breach | 250 crore rupees (~¥4.2B / ~USD 30M) |
| Children’s data protection breach | 200 crore (~¥3.4B) |
| Notification duty breach | 150 crore (~¥2.5B) |
| Improper handling of personal data | 50 crore (~¥0.8B) |
Full entity application is set for May 13, 2027. Japanese India operations need DPDP compliance now. The “18 months from notification” clock is already running; 2025–2026 is transition.
I read DPDP as functioning as an AI regulation substitute. AI-generated content with personal data (face, voice, name) triggers consent, notice, and erasure. Training data with personal data pulls data-subject rights into model operations.
High-risk Japanese cases:
- HR tech and employee data: US HQ AI trained on Indian staff CVs/performance → DPDP cross-border and erasure apply
- Call-center AI and customer voice: Indian customer audio used for training → explicit consent and purpose limitation
- Generative AI and face data: ads with non-real model faces for India → evidence that no specific Indian person was used as base
The same penalty math applies across all of these. That is the content of “regulate AI without an AI Act.”
Organizing Japan→India expansion — how WARP SECURITY helps
TIMEWELL’s WARP SECURITY supports Japanese firms in India with an integrated compliance map across DPDP + IT Rules + AI Governance Guidelines.
Three design calls we hear most:
(1) Relationship with India AISI — how to disclose your AI Safety work to an institute likely to link with Japan AISI; voluntary submission packages are starting.
(2) Synthetic media pipeline retrofit — for HQ tools (Stable Diffusion, Midjourney API, internal LLMs), an edge layer that auto-applies 10% labeling on India delivery.
(3) DPDP cross-border transfers — notice/consent, encryption, and erasure for Indian personal data to HQ; GDPR-like, but also India’s Significant Data Fiduciary concept.
Enterprise design assumes India + EU + Korea + US at once. I recommend Singapore frameworks as a “regulatory hub” in the middle, with India’s DPDP + seven Sutras as Asia-local overlays.
Some firms post translated Sutras on the wall. It can look cosmetic—but asking in AI ethics committee minutes “Does this decision align with Sutra 3 (Innovation over Restraint)?” activates discussion more than people expect.
Latest as of August 2026
While India keeps light-touch, the opposite pole—the EU—is hardening. The Digital Omnibus amending the EU AI Act (Regulation (EU) 2024/1689) was adopted on July 8, 2026 as Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026, and entered into force on July 27, 2026.
Even after that amendment, the AI Act’s general date of application remains August 2, 2026 (European Commission). What actually starts on that date is Chapter IV transparency obligations (Art. 50), the Commission’s power to fine general-purpose AI (GPAI) model providers (Art. 101), and Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration)—not the substantive high-risk AI obligations. The GPAI model obligations themselves (Chapter V) and the penalty provisions (Chapter XII, Arts. 99–100) have applied since August 2, 2025; August 2, 2026 adds the Commission’s enforcement powers on top.
The substantive high-risk obligations (Chapter III, Sections 1–3) moved to a staggered schedule: Annex III systems (Art. 6(2)) from December 2, 2027, and product-embedded Annex I systems (Art. 6(1)) from August 2, 2028. The authorised representative (Art. 22), value chain (Art. 25), deployer (Art. 26), and fundamental rights impact assessment (Art. 27) duties kick in on the same dates. So “the AI Act applies in full on August 2, 2026” is not accurate. Penalties run up to €15M or 3% of worldwide turnover for GPAI-related breaches, and up to €35M or 7% for prohibited practices under Art. 5 (whichever is higher).
Japan published AI Business Guidelines v1.2 (MIC/METI) on March 31, 2026, advancing soft-law operation. India’s three pillars, EU hard law, and Japan’s guidelines coexist; multi-jurisdiction firms need alignment, not a single-template copy. See also Governed enterprise AI agents.
Key takeaways
- India runs a light-touch strategy with no comprehensive AI Act—existing law + guidelines as three pillars
- Guidelines = seven Sutras + six Pillars + three institutions (AIGG, Expert Committee, AISI)
- IT Rules force ≥10% labeling on synthetic media
- DPDP max 250 crore rupees (~¥4.2B); full entity application from May 2027
- AI Impact Summit 2026 sold Global South leadership
“Not making a regulation” is itself a sophisticated regulatory choice. EU and China fence with comprehensive statutes; India flexes with existing law plus philosophy. Which is “right” may take a decade—but both can work now, and that is what makes global AI regulation interesting.
When Japanese firms expand in India, “no AI law, so we are safe” is the most dangerous misread. DPDP’s 250 crore, IT Rules’ 10% labeling, Guidelines’ seven Sutras—where the three pillars cross is where compliance actually bites. Start there on Monday, not with a search for a statute that does not exist.
Further reading: Korea AI Basic Act January 2026, Vietnam AI Law—ASEAN’s first comprehensive AI statute, Singapore Agentic AI Governance Framework.
References
- India AI Governance Guidelines 2025: Key Principles - Bettering Results
- Regulating The Machine Mind: AI, Privacy, And Intellectual Property - IndiaLaw
- Notes from the Asia-Pacific region: India releases DPDPA rules - IAPP
- India Synthetic Content Regulations - IndiaTechDesk






