AIセキュリティ

Seven Sutras: India’s AI Governance Explained — DPDP Act ₹25 Billion Penalties × 10% Synthetic Media Labeling

Published2026-05-20Updated2026-08-01Ryuta Hamamoto

Seven Sutras: India’s AI Governance Explained — DPDP Act ₹25 Billion Penalties × 10% Synthetic Media Labeling.

Seven Sutras: India’s AI Governance Explained — DPDP Act ₹25 Billion Penalties × 10% Synthetic Media Labeling
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

India decided not to make an AI Act. In a 2026 world where the EU AI Act, Korea’s AI Basic Act, and Vietnam’s AI law are going live one after another, that stance is the one I keep coming back to.

“Not making a law” is not “no regulation.” The DPDP Act 2023 carries penalties up to 250 crore rupees. The IT Rules amendment from February 2026 imposes a 10% labeling duty. In November 2025 MeitY published AI Governance Guidelines framed as seven Sutras. Existing law does the binding. Guidelines do the philosophy.

Japanese AI media almost never treat this India-specific “Sutras” design head-on. For Japanese firms in Bengaluru, employers of Indian talent, and anyone setting global AI strategy, here is how I read the frame.

TL;DR

  • India will not pass a comprehensive AI Act; it relies on DPDP Act + IT Rules + AI Governance Guidelines
  • AI Governance Guidelines (November 2025) rest on seven Sutras and six Policy Pillars
  • IT Rules amendment (February 2026) forces at least 10% labeling for synthetic media
  • DPDP Act penalties max out at 250 crore rupees (~¥4.2 billion); full entity application from May 2027
  • Three institutions: AI Governance Group, Technology and Policy Expert Committee, AI Safety Institute
  • AI Impact Summit 2026 (February, New Delhi) projected Global South leadership

Why India chose “no AI Act”

On November 4, 2025, MeitY’s India AI Governance Guidelines put “light-touch” in the opening language1. That is a deliberate fourth stance—not China’s heavy state-led model, not the EU’s comprehensive hard law, not the US sectoral patchwork.

From conversations with Indian counsel and policy researchers, three reasons keep showing up.

First, protect India’s AI industry competitiveness. India is the world’s largest IT services exporter. TCS, Infosys, Wipro, HCL, Tech Mahindra and peers have huge scale on both AI development and adoption. An EU AI Act–weight regime would blunt that edge.

Second, existing law is already thick. IT Act 2000, DPDP Act 2023, the IT Intermediary Guidelines and Digital Media Ethics Code Rules 2021, plus sector regulators (RBI, SEBI, IRDAI) already supply tools. No new statute—stretch interpretation instead.

Third, leadership at AI Impact Summit 2026. Held February 19–20, 2026 in New Delhi, it was framed as the first Global South multilateral AI summit2. India sold itself as “the Global South voice that will not choke growth with heavy rules.”

I call this strategic non-regulation: not regulating is the strategy, so Indian AI industry can take global share in the gap. Japan is both competitor and student of that design.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

Seven Sutras — philosophy without codifying it into hard law

The core of the Guidelines is the seven Sutras3. Borrowing Sanskrit “Sutra” (principle / aphorism) is cultural framing on purpose.

Sutra Meaning Practical impact
1. Trust Establish trust Base principle for all governance
2. People First People first Prevent AI-driven human rights harm
3. Innovation over Restraint Innovation over restraint Self-check against over-regulation
4. Fairness & Equity Fairness and equity Bar algorithmic discrimination
5. Accountability Accountability Provider responsibility systems
6. Understandable by Design Understandable by design Embed explainable AI (XAI)
7. Safety, Resilience & Sustainability Safety, resilience, sustainability Incident response; long-term social impact

Order matters. Sutra 3, “Innovation over Restraint,” sits third—innovation-over-regulation is centered, unlike the EU AI Act’s “Trustworthy AI” at the top.

And the seven Sutras sit in a guideline, not a statute. No fines attach. But they will likely become interpretive hooks for IT Rules and DPDP. Litigation or administrative process may argue that an AI design “violates the Sutras.”

That is the clever part: keep philosophy out of the statute book, use it as a flexible interpretation lever. Japanese firms using AI in India can face “Sutras non-compliance” as litigation risk. Honestly, I would rather deal with a clear fine table than a philosophy that can be waved at you in court—but that is the design India chose.

Six Policy Pillars and three institutions

Six Policy Pillars carry the institutional skeleton4.

Pillar Content
1. Infrastructure IndiaAI Mission, compute, GPU sharing platforms
2. Capacity Building AI education, talent, research networks
3. Policy & Regulation Legal framework development
4. Risk Mitigation Risk management, incident response
5. Accountability Responsibility systems, grievance mechanisms
6. Institutions New bodies

Under Institutions:

AI Governance Group (AIGG) — cross-ministry decision body, MeitY secretariat, finance/labor/health/transport among members. India’s AI policy command tower, still standing up.

Technology and Policy Expert Committee — advisory body of researchers, industry, civil society, international experts feeding AIGG; designed for public minutes and transparency.

AI Safety Institute (AISI) — technical core: safety testing, standards, international cooperation. Built to network with UK AISI (2023), US AISI (2024), and Japan AISI (2024)—a Global South AI Safety hub ambition.

AIGG and AISI target 2026 stand-up; the Expert Committee 2026–2027. What I watch closely is direct India AISI–Japan AISI linkage. Asia AI Safety cooperation with Japan and India on the front line is not a side story for us.

10% synthetic media labeling — IT Rules amendment impact

Of the three pillars, the sharpest operational bite is the IT Rules amendment (effective February 20, 2026)5. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 fold synthetically generated information (SGI) into intermediary duties.

Three main requirements:

(1) ≥10% labeling

AI-generated visual content (image/video) needs labeling for at least 10% of display time or area; audio needs an equivalent share. Explicit text such as “AI-generated” / “Synthetically Generated” is required.

(2) Permanent watermark or metadata

Labels must be in a form users cannot strip—steganographic metadata (C2PA, IPTC Photo Metadata) or persistent visual watermarks.

(3) Extra duties for Significant Social Media Intermediaries (SSMIs)

Platforms above 5 million users must:

  • Collect user declarations that content is SGI
  • Run reasonable automated AI-generation detection
  • Display prominent labels on confirmed SGI

The 10% figure is a world-first numerical threshold—more explicit than the EU AI Act’s “clear and distinguishable” label or Korea’s “visible label.” Japanese firms shipping AI-generated content to India must build labeling that meets the 10% bar into the generation pipeline. If I had to pick one India checklist item for creative and marketing teams, it would be this.

DPDP Act’s 250 crore penalties and indirect AI reach

Without a comprehensive AI law, DPDP Act 2023 heavy fines do the de facto AI reach6.

Violation type Penalty cap
Serious data breach 250 crore rupees (~¥4.2B / ~USD 30M)
Children’s data protection breach 200 crore (~¥3.4B)
Notification duty breach 150 crore (~¥2.5B)
Improper handling of personal data 50 crore (~¥0.8B)

Full entity application is set for May 13, 2027. Japanese India operations need DPDP compliance now. The “18 months from notification” clock is already running; 2025–2026 is transition.

I read DPDP as functioning as an AI regulation substitute. AI-generated content with personal data (face, voice, name) triggers consent, notice, and erasure. Training data with personal data pulls data-subject rights into model operations.

High-risk Japanese cases:

  • HR tech and employee data: US HQ AI trained on Indian staff CVs/performance → DPDP cross-border and erasure apply
  • Call-center AI and customer voice: Indian customer audio used for training → explicit consent and purpose limitation
  • Generative AI and face data: ads with non-real model faces for India → evidence that no specific Indian person was used as base

The same penalty math applies across all of these. That is the content of “regulate AI without an AI Act.”

Organizing Japan→India expansion — how WARP SECURITY helps

TIMEWELL’s WARP SECURITY supports Japanese firms in India with an integrated compliance map across DPDP + IT Rules + AI Governance Guidelines.

Three design calls we hear most:

(1) Relationship with India AISI — how to disclose your AI Safety work to an institute likely to link with Japan AISI; voluntary submission packages are starting.

(2) Synthetic media pipeline retrofit — for HQ tools (Stable Diffusion, Midjourney API, internal LLMs), an edge layer that auto-applies 10% labeling on India delivery.

(3) DPDP cross-border transfers — notice/consent, encryption, and erasure for Indian personal data to HQ; GDPR-like, but also India’s Significant Data Fiduciary concept.

Enterprise design assumes India + EU + Korea + US at once. I recommend Singapore frameworks as a “regulatory hub” in the middle, with India’s DPDP + seven Sutras as Asia-local overlays.

Some firms post translated Sutras on the wall. It can look cosmetic—but asking in AI ethics committee minutes “Does this decision align with Sutra 3 (Innovation over Restraint)?” activates discussion more than people expect.

Latest as of August 2026

While India keeps light-touch, the opposite pole—the EU—is hardening. The Digital Omnibus amending the EU AI Act (Regulation (EU) 2024/1689) was adopted on July 8, 2026 as Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026, and entered into force on July 27, 2026.

Even after that amendment, the AI Act’s general date of application remains August 2, 2026 (European Commission). What actually starts on that date is Chapter IV transparency obligations (Art. 50), the Commission’s power to fine general-purpose AI (GPAI) model providers (Art. 101), and Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration)—not the substantive high-risk AI obligations. The GPAI model obligations themselves (Chapter V) and the penalty provisions (Chapter XII, Arts. 99–100) have applied since August 2, 2025; August 2, 2026 adds the Commission’s enforcement powers on top.

The substantive high-risk obligations (Chapter III, Sections 1–3) moved to a staggered schedule: Annex III systems (Art. 6(2)) from December 2, 2027, and product-embedded Annex I systems (Art. 6(1)) from August 2, 2028. The authorised representative (Art. 22), value chain (Art. 25), deployer (Art. 26), and fundamental rights impact assessment (Art. 27) duties kick in on the same dates. So “the AI Act applies in full on August 2, 2026” is not accurate. Penalties run up to €15M or 3% of worldwide turnover for GPAI-related breaches, and up to €35M or 7% for prohibited practices under Art. 5 (whichever is higher).

Japan published AI Business Guidelines v1.2 (MIC/METI) on March 31, 2026, advancing soft-law operation. India’s three pillars, EU hard law, and Japan’s guidelines coexist; multi-jurisdiction firms need alignment, not a single-template copy. See also Governed enterprise AI agents.

Key takeaways

  • India runs a light-touch strategy with no comprehensive AI Act—existing law + guidelines as three pillars
  • Guidelines = seven Sutras + six Pillars + three institutions (AIGG, Expert Committee, AISI)
  • IT Rules force ≥10% labeling on synthetic media
  • DPDP max 250 crore rupees (~¥4.2B); full entity application from May 2027
  • AI Impact Summit 2026 sold Global South leadership

“Not making a regulation” is itself a sophisticated regulatory choice. EU and China fence with comprehensive statutes; India flexes with existing law plus philosophy. Which is “right” may take a decade—but both can work now, and that is what makes global AI regulation interesting.

When Japanese firms expand in India, “no AI law, so we are safe” is the most dangerous misread. DPDP’s 250 crore, IT Rules’ 10% labeling, Guidelines’ seven Sutras—where the three pillars cross is where compliance actually bites. Start there on Monday, not with a search for a statute that does not exist.

Further reading: Korea AI Basic Act January 2026, Vietnam AI Law—ASEAN’s first comprehensive AI statute, Singapore Agentic AI Governance Framework.

References

Footnotes

  1. India AI Governance Guidelines - PIB India

  2. India AI Governance Guidelines: Empowering Ethical and Responsible AI - IndiaAI Official

  3. Decoding the India AI Governance Guidelines - Saikrishna & Associates

  4. India Issues 2025 AI Governance Guidelines - Privacy World

  5. India's Deepfake Crackdown: IT Rules 2026 Amendment - Rotavision

  6. DPDP Penalties: 250 Crore Fine Explained - Guardata

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles