India's AI rules, explained: seven sutras and no new law yet
India chose guidelines over legislation: seven principles, three proposed institutions and an existing-laws-first approach. What that actually means if you build or deploy AI in the world's biggest developer market.
By Yash Malviya
Published

The law that isn't one
On 5 November 2025, India's Ministry of Electronics and Information Technology unveiled the India AI Governance Guidelines under the IndiaAI Mission, and the most important thing about them is what they are not. They are not an AI Act. There is no new statute, no dated compliance calendar, no penalty schedule. India looked at the same technology Brussels spent three years legislating over and chose a different instrument entirely: a principle-based framework that leans on laws the country already has.
That choice is explicit, not accidental. "Our focus remains on using existing legislation wherever possible," MeitY secretary S. Krishnan said at the launch. "At the heart of it all is human centricity, ensuring AI serves humanity and benefits people's lives while addressing potential harms." The guidelines were drafted by a committee constituted in July 2025 under Prof. Balaraman Ravindran of IIT Madras, put through public consultation, and refined by a second committee before release.
Seven sutras, four parts
The framework is organised as four parts: guiding principles, recommendations across six governance pillars, an action plan on short, medium and long timelines, and practical guidance for industry and regulators. The principles are the seven "sutras": trust, people-first governance, innovation over restraint, fairness and equity, accountability, understandability by design, and safety, resilience and sustainability.
One of those is doing more work than the others. The official backgrounder states it flatly: "All other things being equal, responsible innovation should be prioritised over cautionary restraint." Most governance documents bury their priorities. This one prints them.
“The guiding principle that defines the spirit of the framework is simple, 'Do No Harm'. We focus on creating sandboxes for innovation and on ensuring risk mitigation within a flexible, adaptive system.”

Three new institutions, all still proposals
The guidelines recommend creating an AI Governance Group to coordinate across ministries, a Technology and Policy Expert Committee, and an AI Safety Institute for risk assessment. All three are proposals, not operating bodies, and the distance between a recommended institution and a staffed one is where frameworks like this succeed or stall. Watch for the notifications that actually constitute them.
What binds you today
None of this means AI in India is unregulated. It means the binding rules live elsewhere: information technology law, the data-protection regime, consumer protection, intellectual property and criminal law. The framework's own position is that many AI-related risks can be addressed under India's existing legal framework, while flagging genuine gaps around generative AI, liability and the use of training data for future review.
The guidelines' spirit is best captured by the man who launched them. "The guiding principle that defines the spirit of the framework is simple, 'Do No Harm'," said Prof. Ajay Kumar Sood, Principal Scientific Adviser to the Government of India. "We focus on creating sandboxes for innovation and on ensuring risk mitigation within a flexible, adaptive system."
The context is a state that is building AI capacity faster than it is regulating it. Under the IndiaAI Mission, more than 38,000 GPUs have been onboarded to a subsidised national compute facility, and the AIKosh platform hosts over 9,500 datasets and 273 sectoral models. The government's own backgrounder claims nearly 90% of Indian startups integrate AI in some form. Deployment first, governance alongside: that is the bet.
“Our focus remains on using existing legislation wherever possible. At the heart of it all is human centricity, ensuring AI serves humanity and benefits people's lives while addressing potential harms.”
The contrast with Brussels
Set this beside the EU's AI Act and its moving deadlines and you get the cleanest natural experiment in AI governance anywhere. Europe wrote dated obligations with penalty schedules and is now paying the coordination cost of moving them. India wrote principles with no dates, kept its existing statutes as the enforcement layer, and pointed the machinery at adoption, hosting the India-AI Impact Summit in New Delhi in February 2026 partly to make that governance philosophy an export, especially to the Global South.
For anyone building for the Indian market, the practical reading is simple. Nothing new binds you today. But the sutras tell you exactly where scrutiny will land when it comes: human oversight, grievance channels, transparency about what your system does. Those are cheap to build now and expensive to retrofit under pressure.
Our take
India's framework is refreshingly honest about its priorities: innovation over restraint, in writing. The strength of that bet is speed in a market of 1.4 billion people. The vulnerability is that principle-based governance is only as good as the institutions behind it, and all three of those are still on paper. Builders should take the freedom and build the oversight the sutras describe anyway, because when the first large-scale AI harm arrives in India, the rules that follow will be written around whoever caused it.
Frequently asked questions
Did India pass a new AI law?
No. On 5 November 2025 India's Ministry of Electronics and Information Technology unveiled the India AI Governance Guidelines under the IndiaAI Mission, and they are not an AI Act. There is no new statute, no dated compliance calendar and no penalty schedule. India chose a principle-based framework that leans on laws the country already has.
What are the seven sutras?
The seven sutras are the framework's guiding principles: trust, people-first governance, innovation over restraint, fairness and equity, accountability, understandability by design, and safety, resilience and sustainability. The priority of innovation over restraint is explicit. The official backgrounder states that, all other things being equal, responsible innovation should be prioritised over cautionary restraint.
What institutions do the guidelines propose?
The guidelines recommend three national bodies: an AI Governance Group to coordinate across ministries, a Technology and Policy Expert Committee, and an AI Safety Institute for risk assessment. All three are proposals, not operating bodies. The article notes the distance between a recommended institution and a staffed one is where frameworks like this succeed or stall.
If there is no new AI law, what binds AI in India today?
The binding rules live in existing law: information technology law, the data-protection regime, consumer protection, intellectual property and criminal law. The framework's position is that many AI-related risks can be addressed under India's existing legal framework, while flagging genuine gaps around generative AI, liability and the use of training data for future review.
How much AI capacity is India building while it governs by guidelines?
Under the IndiaAI Mission, more than 38,000 GPUs have been onboarded to a subsidised national compute facility, and the AIKosh platform hosts over 9,500 datasets and 273 sectoral models. The government's own backgrounder claims nearly 90% of Indian startups integrate AI in some form. The article describes the approach as deployment first, governance alongside.
Sources
What each one is, and whose it is.
- 1
MeitY Unveils India AI Governance Guidelines under IndiaAI Mission, Press Information Bureau, Government of India (November 5, 2025)
Press report - 2
India AI Governance Guidelines: PIB Backgrounder, Press Information Bureau, Government of India (February 15, 2026)
Press report - 3
AI Impact Summit 2026: India's AI Governance Guidelines anchored by seven sutras, The Tribune (ANI) (February 15, 2026)
Press reportIndependent of the vendor - 4
India's AI Governance Guidelines: 7 Principles for Safe AI, NewKerala (ANI) (February 15, 2026)
Press reportIndependent of the vendor