India AI governance, sector by sector
India does not have a standalone horizontal AI law. Instead, AI governance operates through sector-specific regulation layered on the DPDP Act 2023 foundation. For organisations operating in India, the practical compliance challenge is mapping AI use against both the horizontal DPDP framework and sector-specific requirements.
Banking and financial services
RBI FREE-AI Framework. The Framework for Responsible and Ethical Enablement of AI addresses governance structures, risk management, transparency, fairness, and data governance for banks, NBFCs, and payment system operators. FREE-AI is the report of an expert committee constituted by the RBI, released on 13 August 2025, setting out seven guiding principles and 26 recommendations, several of them addressed to the RBI itself. It is not RBI guidance and does not by itself create supervisory expectations or examination risk. RBI has separately issued a draft Guidance on Regulatory Principles for Model Risk Management, put out for public comment in June 2026.
RBI (Digital Lending) Directions, 2025. Effective 8 May 2025, these consolidate and replace the 2022 guidelines. Directly relevant to AI-driven lending: all lending must be through a regulated entity; data collection must be need-based with customer consent; data must be stored on servers in India; Default Loss Guarantee (DLG) arrangements between regulated entities and lending service providers are permitted subject to a 5% cap on the loan portfolio under RBI's June 2023 DLG guidelines. AI credit scoring and automated lending decisions must comply.
Master Direction on IT Governance (2023). Applies AI as information technology: board-level IT governance; information security management; IT outsourcing and vendor management; business continuity. AI systems in banks must comply.
IRDAI. Insurance Regulatory and Development Authority guidance applies to AI in insurance underwriting, pricing, and claims. AI pricing models must be fair and non-discriminatory.
SEBI. Securities and Exchange Board of India regulates algorithmic trading, AI in securities advisory, and automated portfolio management. Registration and compliance requirements apply to AI-driven investment tools.
Healthcare
CDSCO. The Central Drugs Standard Control Organisation regulates AI medical devices under the Medical Devices Rules 2017 (amended). AI-based diagnostic, monitoring, and treatment devices require regulatory approval. Software as a Medical Device (SaMD) including AI is within scope.
ICMR. Indian Council of Medical Research ethical guidelines apply to AI in biomedical and health research. Informed consent, ethics committee approval, and data protection requirements apply.
ABDM. The Ayushman Bharat Digital Mission creates a digital health infrastructure. AI systems interfacing with ABDM must comply with health data standards and interoperability requirements.
Telemedicine. Telemedicine Practice Guidelines (2020) apply to AI used in telemedicine, AI clinical decision support deployed in telehealth must comply.
IT services and outsourcing
India is a global hub for IT services and business process outsourcing. Companies deploying AI for clients face dual compliance obligations: Indian law (DPDP Act, IT Act, sector regulation) for their India operations, plus client jurisdiction requirements for the AI services they provide (GDPR for EU clients, CCPA for California clients, APRA (Australian Prudential Regulation Authority) CPS 230 for Australian financial services clients).
Key considerations: data localisation requirements under DPDP and sector-specific regulation; cross-border data transfer mechanisms; contractual obligations with international clients; ISO/IEC 42001 and SOC 2 certification expectations from enterprise clients; AI-specific contract provisions (no-training commitments, model documentation, bias testing).
DPDP Act, the horizontal layer
The DPDP Act 2023 and Rules 2025 (notified 13 November 2025, implemented in three phases) apply across all sectors. Significant Data Fiduciaries (likely to include major banks, insurers, and IT companies) face enhanced obligations: DPO appointment; independent data auditor; DPIA for high-risk processing including AI. Maximum penalty: 250 crores (approximately US$26 million) per contravention.
Primary sources: Reserve Bank of India · MeitY, DPDP Framework · CDSCO
Related reading
- AI in India's Financial Services: RBI, SEBI, and IRDAI Frameworks for AI Governance
- Enterprise AI Compliance in India: DPDP Act, RBI, SEBI, IRDAI, and the Governance Framework
- Singapore MAS (Monetary Authority of Singapore) AI Compliance for Financial Services: What to Implement Now
- AI Governance in India: DPDP Act, SEBI, RBI, and the Emerging Regulatory Landscape