Is India Ready for What AI Is Becoming?

AI and its surrounding world saw two different things this week at vastly different levels, one is an internet trend where people are making 1980s-style images of themselves using AI and the other is the resignation and an alarming tweet by Jacob Coxon, a 27-year-old researcher who worked at OpenAI and Anthropic, resigned from Anthropic on Tuesday.

Coxon warned that AI companies are moving towards increasingly capable and potentially self-improving systems without fully understanding the risks. 

The two developments have little to do with each other, but together they show how quickly AI has moved from a specialised technology to an everyday product, while also becoming capable of much more autonomous tasks.

What is the problem here?

Coxon is concerned about what happens as AI systems become more capable and autonomous. While his resignation is not proof that self-improving AI will inevitably become dangerous, it reflects a concern increasingly being discussed within the industry.

A recent OpenAI cybersecurity incident involving Hugging Face, an AI platform, provides another example. During internal testing, OpenAI said its models circumvented controls intended to isolate them from the internet and accessed research infrastructure on Hugging Face systems. OpenAI called it a “warning shot.”

Now this brings a whole world of regulatory problems because if an AI system can make decisions and take actions without a human approving every step, accountability and responsibility become harder.

In India’s case, the country’s own AI Governance Guidelines recognise increasingly autonomous AI systems as a challenge for existing regulatory frameworks.

India’s AI Governance Guidelines

India released an overarching framework, the India AI Governance Guidelines, in November 2025 and the framework attempts to establish a principle and risk based approach for safety, accountability, fairness, transparency, and human oversight. 

India has deliberately chosen not to begin with a standalone AI Act. Its main overarching framework is the India AI Governance Guidelines, released in November 2025. They establish a principle-based and risk-based approach covering safety, accountability, transparency, fairness, human oversight and responsible innovation. However, the government also stated in a 2025 PIB release that a dedicated ‘horizontal AI law’ is not required at this stage.

But, the guidelines also acknowledge that the existing framework has gaps. They call for a review of laws covering liability across the AI value chain, data protection during AI development, generative AI misuse, AI-content provenance, copyrighted material used for training and risks in sensitive sectors.

The better approach for India may not be to put unnecessary restrictions on every AI system, but to create stricter rules for high risk AI. Systems used in healthcare, banking, policing, elections and other sensitive areas should have mandatory safety testing, human oversight and clear accountability when something goes wrong.

At the same time, the government needs stronger coordination between different regulators and agencies. AI companies should be required to clearly explain how they handle personal data, test powerful models for safety and label AI generated content where necessary. This could help India encourage AI innovation while also protecting people from its biggest risks.

Does India have laws covering AI?

While a specific law to govern AI doesn’t exist in India, the framework for the guidelines spreads across the IT Act 2000, Digital Personal Data Protection (DPDP) Act, 2023, IT Rules 2021, including the amendments made to the IT rules in 2026 (which introduced rules and requirements for AI-generated information, including mandatory labelling and traceability).

Copyright law, criminal law, consumer protection legislation and sector-specific regulations can also apply depending on how AI is being used. This means India does have laws governing many AI-related risks. The difficulty is that the applicable law changes depending on the technology, the sector and the harm involved.

The data question

The current 1980s-photo trend is a simple example. Uploading a photograph to an AI service does not by itself indicate a failure of India’s data-protection framework. But it raises questions about what happens to that photograph after it is uploaded: how long it is retained, whether it is used to improve the service, what derived information is created and how deletion works.

The DPDP framework already provides rules around the processing of personal data. The bigger challenge is applying those principles to AI systems where data can pass through multiple stages of processing and potentially contribute to model development. The government itself has identified data protection during AI development as an area requiring further review.

EU and US: Two different approaches

The European Union has taken a more prescriptive route through the EU AI Act, which classifies AI systems according to risk and creates specific obligations for prohibited uses, high-risk systems and general-purpose AI models with systemic risks. These obligations include areas such as evaluation, risk management, cybersecurity and incident reporting. The EU has also created an AI Office to oversee parts of the framework.

The US has taken a more fragmented approach, combining executive action, existing federal laws, voluntary frameworks, national-security measures and state legislation. A June 2026 executive order introduced a benchmarking process for certain frontier models and a voluntary pre-release access framework, while explicitly rejecting mandatory licensing for AI development and distribution.

Maharashtra may have a forward-thinking solution

Maharashtra government set up a panel to create a standard-operating procedure for regulating AI-powered smartglasses, after India saw several issues earlier with the glasses. This is expected to cover concerns around recording, live streaming, facial recognition and data collection. 

India already has privacy and data-protection laws, but a device combining a camera, microphone, AI processing and facial recognition creates situations that do not always fit neatly into existing categories. So if Maharashtra does come up with a solution, other states or even the centre can implement these in a forward-thinking manner.

Coordination and liability gaps

Fragmentation of the roles and responsibilities and coordination causes a lot of gaps in India. MeitY, RBI, CERT, MHA, DOT, and several other departments need to coordinate to fully cater to the regulatory needs but this is an administrative nightmare. 

India’s AI Governance Guidelines also advocate for a ‘whole of government’ approach towards regulating AI. 

The bigger question is what happens when an AI system crosses several regulatory categories. An AI-generated image can involve data protection and copyright. An AI system used by a bank can involve financial regulation and consumer protection. An autonomous AI system involved in a cyber incident can raise questions of criminal law, corporate responsibility and liability.

The technology is moving into these areas quickly. The test for India will be whether those gaps are addressed before they become much harder to regulate and AI becomes uncontrollable. 

X