By Jeet Pattanaik
India’s government now says the country may need a dedicated law on artificial intelligence. Like much of the Global South, India is anxious to get ahead in AI, and that anxiety is no longer only about acquiring the technology. It is about building the legal and regulatory infrastructure to govern it. In this op-ed, Jeet Pattanaik argues that what goes into that law matters more than whether it passes. India should build on its own strengths of public digital infrastructure, borrow from the EU AI Act’s risk-based design, learn from Europe’s stumbles, and write a law that holds the state to the same standard as business.
A widow in Hyderabad lost her family’s subsidised rice, as Al Jazeera reported in 2024, because a computer system confused her late husband, a rickshaw puller, with another man of a similar name who owned a car. Officials took the system’s word for it. She was one of thousands of families dropped by Telangana’s Samagra Vedika platform, and it was left to them to prove they were poor enough to deserve food.

Nobody explained why. No official had to look again. No law required one to.
Although the system was built under a previous state government, the problem transcends one party. It is the absence of rules that apply to any government. I keep coming back to this case because it shows, better than any policy paper, why India needs an AI Act.
The government seems to have reached the same conclusion, at least in principle. In November 2025, the Ministry of Electronics and Information Technology (MeitY) said a standalone AI law wasn’t needed. However, by July this year, India’s IT Secretary was telling reporters that “probably the time has come to look at a separate legislation.” That is a welcome shift. The real question now is what kind of law India writes.
India is not deciding this alone.
Across the Global South, governments are discovering that acquiring AI capability is the easier half of the problem, and that building the legal machinery to govern it is slower, more contested and less well funded.
The Global Index on Responsible AI found this year that most Global South countries have only soft-law frameworks, which can set direction and build consensus but cannot create binding rights or hold anyone to account.
It calls the result a growing governance asymmetry, and India currently sits on the wrong side of it.
A decent start, pointed the wrong way
It would be unfair to say India has done nothing. The data protection act is up and running. The February 2026 changes to the IT Rules made deepfake labelling mandatory, India’s first binding AI-specific rules. The Reserve Bank’s FREE-AI framework is thoughtful, and the new IndiaAI Safety Institute gives the government technical muscle it lacked two years ago.
But almost all of it points in one direction: at platforms and private companies. And almost all of it rests on executive rulemaking under the IT Act of 2000, a law the IT minister himself says was written for a different era.
The problem isn’t only that the IT Act is old. It’s that the rules built on it come from a single ministry, without Parliament ever voting on them. That makes them easy to issue and just as easy to reverse.
In March 2024, MeitY told AI companies they needed government permission before releasing “unreliable” models. About two weeks and one industry backlash later, the requirement was gone. Nothing changed in law, because nothing had ever been in law. For a startup planning a product, or a citizen trying to understand their rights, a rule that can vanish in a fortnight is no rule at all. A statute passed by Parliament can’t be withdrawn by a press release.
The state and its algorithms
The deeper gap is the state itself. The data protection act lets the government exempt its own agencies under Section 17 and says nothing specific about automated decisions.
Yet governments are among the most consequential users of these systems, in welfare eligibility, policing, and monitoring.
Here India is behind countries with far smaller economies. Ethiopia’s 2024 data protection proclamation already gives people the right to request human intervention in, and to contest, decisions made solely by automated systems. India’s does not.
The Supreme Court settled the principle back in 2017. Its judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, requires any state intrusion into privacy to be lawful, necessary and proportionate. It’s hard to see how quietly deleting a family from the ration rolls passes that test. Yet nothing in current law forces the question.
There is also a definitional trap. Samagra Vedika is largely a data-matching system, not a chatbot or a frontier model. If India’s law defines “AI” narrowly, its most harmful examples could fall outside it. The Act should cover automated decision systems of every kind, judged by what they decide, not by how they are built.
There’s a federal twist, too. Welfare and policing are largely state subjects, and states are moving quickly: Madhya Pradesh and Chhattisgarh have both announced substantial budgets for AI in public services.
A law that covers only central ministries and private companies would miss much of the automation ordinary Indians actually encounter, which is administered through states. It has to set a national floor that applies to state governments as well, as the data protection act already does.
Fair objections, and a better answer
Some thoughtful people oppose a single, economy-wide AI law, and they have a point. The government’s own high-level committee, which produced the India AI Governance Guidelines in November 2025, concluded that a standalone law was not presently necessary. IT Minister Ashwini Vaishnaw put the case more sharply at Davos in January 2026, arguing that AI regulation must follow a techno-legal approach rather than standalone laws: build bias-mitigation and deepfake-detection tools robust enough to survive judicial scrutiny, rather than write statutes that the technology will outrun.
There are practical objections too. The Reserve Bank of India and the Securities and Exchange Board of India know banking and markets far better than any new AI regulator would. The United States has no federal AI law, and the United Kingdom has chosen a sector-led approach. South Africa has now taken the same route, though its path has been bumpy: its draft national AI policy was withdrawn in June 2026 after officials found it cited sources that did not exist, apparently because AI had been used in drafting it without adequate checking. India’s regulators are stretched, and its courts are already heavily backlogged, so new legal rights might exist only on paper.
To me, each of these objections is an argument about how to design the law, not a reason to skip it.
Let the Act set the rights and the red lines, and let sector regulators fill in the technical detail, which officials reportedly already have in mind. Give people a quick administrative appeal instead of years in court. Phase obligations in as the capacity to enforce them grows.
Take Europe’s design, skip its sequencing
The EU AI Act gets the structure right. Obligations grow with the stakes of a decision, not with how clever the technology is. There’s a short list of outright bans, including social scoring by governments or companies and emotion recognition at work or in school.
India should add one ban of its own: no system should infer a person’s caste from proxies such as surname or locality or use caste to disadvantage anyone.
The only exception should be where the law itself requires caste data, as it does for reservations in public employment and economic benefits. Public bodies should also assess the rights impact of high-risk systems before switching them on, and list those systems in a public register.
Where Europe went wrong was timing. In July 2026 it pushed back its high-risk rules by sixteen months, mainly because the technical standards companies needed weren’t ready.
That didn’t surprise me. In large multi-country SAP programs, the hardest problems I faced were rarely the rules themselves. They were interfaces that retried and posted the same transaction twice, data that slowly drifted apart between headquarters and local sites, and documentation that looked complete until the system went live.
Law that runs ahead of shared definitions and testing tools creates confusion, not safety. India should build the benchmarks first.
Something India can add
India also has an advantage Europe lacks: a proven record of building digital public infrastructure at scale. Through the Account Aggregator framework, it built consent managers so people could control how their financial data is shared, and the system passed 100 million successful consents in 2024.
It could build the same kind of plumbing for challenging decisions.
Picture an “algorithmic receipt.” Whenever a high-risk automated system denies you a benefit, a loan or a job application, you’d get a simple record, perhaps delivered through DigiLocker. It would say that a system was involved, name the main factors behind the outcome, and explain how to ask for a human review within a fixed number of days. A family wrongly flagged as car owners would see that error in writing and could correct it in minutes rather than months.
Limits on emergency powers
There’s one more thing to get right. Officials have reportedly discussed giving the government power to shut down AI systems or demand technical disclosures in an emergency. That may sometimes be justified. But such powers should expire automatically, be reported to Parliament, and be open to challenge in court. These are limits that any future government, of any party, would also have to respect.
The law itself should go through Parliament after real public consultation. Its regulator needs statutory independence, separate from the ministry that also has the job of growing the industry.
That will not be easy: India’s Data Protection Board is appointed by the central government. An AI regulator would need fixed tenure and a broader selection process to earn public trust.
The judiciary has already set an example. The Supreme Court’s draft rules for AI in courts are clear that the technology can help judges but never decide cases. The executive should hold itself to at least the same standard.
Why this is a democratic question
There is an argument underneath all of this that is easy to miss. A citizen who is denied a benefit by an official can ask why, complain, go to a representative, or vote the government out. Each of those depends on knowing that a decision was made, who made it, and on what grounds. Automated decisions erode all three, quietly and without anyone intending it. The widow in Hyderabad had no one to argue with.
That is not a technology problem. It is a participation problem.
A country that automates the administration of welfare, policing and identity without a corresponding right to an explanation has not only deployed a new tool. It has removed a point at which citizens could push back, and it has removed it from precisely the people with the least capacity to push back anywhere else.
India has spent a decade arguing, rightly, that digital public infrastructure can expand citizenship rather than shrink it. Aadhaar, UPI and DigiLocker were sold on that promise. An AI Act is where that promise gets tested. Not because the technology is dangerous, but because the alternative is a state that can say no to you without ever having to say why.
India wants to show the world a different model for governing AI, and for much of the Global South it would be the most consequential example available. That is a worthy ambition. But the model will only be convincing if it works for people like that widow in Hyderabad, who deserved an answer from the machine that said no, and from the officials who relied on it.
Jeet Pattanaik is a Berlin-based enterprise AI architect and founder of Glokal AI. He has led large-scale SAP transformation programmes across Europe, writes on AI governance for CIO.com, The New Stack and TechTarget, and is the author of Ethics in AI and Sovereign AI.
This article is published under the sole responsibility of the author, with editorial oversight. The views expressed do not necessarily reflect those of the editorial team or the CEU Democracy Institute.