Regulating Generative Artificial Intelligence in India: Evaluating the Adequacy of Existing Legal Frameworks Governing Liability, Transparency and Accountability

Sub topic :

Bridging India’s Regulatory Gap: A Critical Evaluation of Liability and Transparency Frameworks for Generative Artificial Intelligence

Abstract

Generative Artificial Intelligence (Generative AI) has transformed the digital world, enabling machines to generate text, images, audio, software code, and other content through sophisticated machine learning algorithms. While these technologies offer tremendous potential for innovation, they also pose complex legal challenges concerning liability, transparency, privacy, intellectual property rights, and accountability. In India, Artificial Intelligence is largely governed by existing legal structures, rather than specific regulations targeting AI.

This article discusses the sufficiency of the existing legal framework in India for the accountability issues stemming from Generative Artificial Intelligence systems. The discussion is focused on Information Technology Act, 2000, Digital Personal Data Protection Act, 2023, Copyright Act, 1957, Consumer Protection Act, 2019 and constitutional principles shaped by judicial precedents. The article argues that the existing legal framework does provide some mechanisms to address damages caused by AI but there are notable gaps in regulation resulting from the autonomous and complex character of Generative artificial intelligence systems. A responsible deployment of AI in India requires a risk-based approach to governance, along with enhanced transparency obligations.

Introduction 

Artificial Intelligence (AI) is one of the greatest technological innovations of the twenty-first century. Generative Artificial Intelligence is a remarkable progress within its varied types, as it empowers systems to generate human-like content on their own through the use of extensive data sets and learning of algorithms. The spread of applications such as AI-generated text, synthetic media, automated decision-making tools and creative content generation is increasing rapidly in sectors including education, healthcare, enterprise and government.

But as Generative AI grows, serious legal questions are emerging concerning responsibility and liability. Unlike traditional software systems, Generative AI models work by complex learning processes, making it difficult to establish accountability when AI-generated outputs cause harm.

This is a need for effective legal regulation to address issues such as false information, privacy violations, biased results, copyright infringement and consumer fraud.

India currently doesn’t have any comprehensive laws concerning artificial intelligence. Instead, the challenges raised by AI are dealt with through existing legal structures governing areas such as information technology, data protection, intellectual property, consumer rights and constitutional safeguards. The research assesses the adequacy of these existing frameworks in handling the accountability and transparency requirements of generative artificial intelligence systems.

Why Generative AI Matters and the Need for Regulation and Accountability


Generative AI is the term used for artificial intelligence systems that can generate new content by identifying patterns in huge data sets. Large Language Models ( LLMs ) and image generation systems are examples of technologies that use machine learning methods to produce human-like content .

The biggest problem with generative AI is the “accountability gap.” Artificial intelligence systems have a complex ecosystem of stakeholders including developers, data providers, platform operators and end users, but accountability in traditional legal systems is generally ascribed to identifiable human actors. If an AI output harms, who is liable?

For example, if an AI system generates misleading information, biased recommendations or defamatory content, it is not clear who is accountable: the person who created the model, the company that deployed the system or the person who used the output. Thus, accountability for adverse outcomes and transparency about how artificial intelligence systems work are core elements of AI governance.

Indian Law on AI Transparency and Liability Today

1. Information Technology Act, 2000

The main legislation governing digital activity in India is the Information Technology Act, 2000 (IT Act). They can still be applied to harms related to AI, even if some clauses are adopted before the broad development of AI. The Act provides for the procedure for dealing with data-related offences, cybercrimes, unauthorised access and intermediary obligations. Section 79 intermediary liability regime shields online platforms from liability for third-party content, provided that certain conditions are met.

The Supreme Court’s decision in Shreya Singhal v Union of India had a profound effect on intermediary regulation, acknowledging the need to safeguard online expression, while also providing for reasonable restrictions in line with constitutional principles. But generative AI platforms, which actually create content rather than just host content created by users, raise special issues. Therefore, the current middleware architecture might not be suitable for dealing with hazardous information generated by AI.

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were not aimed at foundation AI models or generative systems but placed new compliance obligations on intermediaries.

2. The Digital Personal Data Protection Act, 2023

The Digital Personal Data Protection Act, 2023 (DPDP Act) is the first comprehensive data protection law in India. The Act is very relevant as generative artificial intelligence systems are largely based on large scale data processing.

The Act sets standards around consent, protection of personal information and legitimate processing of personal data. If AI developers train models on personal data and the processing impacts identifiable individuals, they may have compliance requirements to meet.

The Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India identified privacy as a fundamental right under Article 21 of the Constitution and focused on informational autonomy and individual control over personal data.  This constitutional foundation reinforces the argument that artificial intelligence systems should be transparent in how they gather and use data.

The DPDP Act, however, does not address broader AI-related issues such as algorithmic bias, explainability or accountability for autonomous judgements and focuses largely on the protection of personal data.

3. Issues of content produced by AI and the Copyright Act, 1957

Generative AI raises major intellectual property issues, including questions of ownership and infringement.

The very basis of copyright protection is authorship and originality as recognised in the Copyright Act of 1957. The advent of AI-generated works raises the question of whether information produced without direct human authorship can be protected by copyright.

Another major issue is the use of copyrighted content to train AI models. Challenges arise in infringement, fair dealing and compensation processes when artificial intelligence systems are trained using protected works without authorisation.

Indian copyright law does not, as yet, envisage ownership of AI-generated works or AI training datasets. This leaves users, IT businesses and creators feeling uncomfortable.

4. The Consumer Protection Act, 2019

The Consumer Protection Act, 2019 protects against defective services and unfair trade practices. It could also cover consumer-facing generative AI apps that produce misleading results, deliver false information or offer inferior AI services.

For example, an AI-enabled financial advice tool may give bad recommendations that lead to financial loss, raising questions about the liability of the service provider.

Consumer law, however, generally presumes human control of goods and services. The output of generative AI is unpredictable, making it hard to prove negligence and causation.

The Judicial View of Technology, Accountability and Liability.

The Indian judiciary has always recognized the need for a balancing act between technological advancement and constitutional rights.

1. Justice K.S. Puttaswamy v. Union of India

    The Supreme Court’s declaration of privacy as a fundamental right resulted in the creation of principles of informational autonomy, consent and protection against unnecessary data intervention.

    Such ideas have direct implications for artificial intelligence (AI) systems that handle vast amounts of personal data. The decision affirms the importance of people having meaningful information and control over the way automated systems use their data.

    • 2. Shreya Singhal v. Union of India

    Shreya Singhal on the Supreme Court on Internet Regulation and Intermediate Liability.  It upheld intermediary requirements under section 79 but struck down section 66A of the IT Act for unduly curbing free speech.

    The decision is an example of the judiciary trying to maintain accountability in the digital spheres without unnecessarily throttling innovation. Similar balance concepts may guide future AI regulation.

    • 3. Anuradha Bhasin v. Union of India

    In the case of Anuradha Bhasin, the Supreme Court recognised the importance of internet connectivity for exercising constitutional rights. The decision shows that courts have acknowledged the close relationship between digital technologies and fundamental rights. The principles laid down in this case may offer guidance for future AI governance approaches, especially regarding transparency and limitations on digital interaction.

    Transparency Issues in Generative Artificial Intelligence

    1. Explainability

    Even the creators might have trouble trying to explain how generative AI models, which often work as “black boxes,” produce particular outputs. If something goes wrong it is hard to know who to blame if the process is not explainable.

    There should be a requirement to disclose model operations, sources of training data and limitations of AI-generated outputs within a clear AI framework.

    2. Discriminatory and Bias Results

    AI systems learn from past datasets that may contain societal biases. Because of this, they might repeat or worsen discrimination based on gender, caste, ethnicity, or other traits.

    Currently, algorithmic discrimination is not specifically addressed by Indian law. Article 14’s provisions on equality could provide a foundation, but there are still limited enforcement strategies.

    3. Gaps in Accountability

    Developers, deployers, and users are some of the many people involved in generative AI. Their individual responsibilities are not clearly defined under the current legal frameworks.

    A detailed AI regulatory framework should establish specific responsibilities based on each participant’s role and the risks involved.

    Adequacy  of the Current Indian Structure

    Data protection laws, information technology regulations, intellectual property laws, and consumer protection procedures are some of the protections the current Indian legal system provides. These laws demonstrate that India can tackle some AI-related harms.

    However, there are still many regulatory gaps. The existing laws were not designed for autonomous AI systems that can generate their own outcomes. Algorithmic bias, explainability, transparency, and AI-specific liability remain unresolved issues.

    A risk-based approach to AI governance might well provide the right answer, wherein various classes of AI-based applications could be identified depending on the harm they pose and regulated accordingly, with those of higher risk attracting stronger constraints. Going forward, AI regulation guidelines should have provisions for human supervision, accountability standards, audit procedures, and norms for information clarity.

    Developments like European Union AI regulation Act, OECD AI Principles and UNESCO Recommendation on the Ethics of Artificial Intelligence signifies  the increasing global inclination towards risk-based regulation. India can similarly build similar guidelines keeping its constitutional and technological specifics in consideration.

    Conclusion

    Generative AI offers both innovative possibilities and a raft of challenging legal questions. In the current Indian legal framework, limited answers exist for issues posed by AI through Information technology laws, Data protection laws, Copyright law and principles of Consumer protection. Still, such laws fail to adequately address specific liability issues that emerge in generative AI.

    The absence of specific obligations regarding explainability, transparency and algorithmic responsibility leaves an ambiguity as to liability.

    India needs a comprehensive approach to regulating the generative AI sphere based on risk classification, disclosure obligations, human oversight, and stakeholder accountability to enable an ethical and robust approach to AI. Regulations should foster the development of an ecosystem in which the AI operates in line with fundamental rights, accountability, and public confidence instead of stifling technical progress.

    THIS ARTICLE IS WRITTEN BY SURENDRA REDDY NALLATHIMMAREDDIGARI FROM  DR. B.R. AMBEDKAR COLLEGE OF LAW, ANDHRA UNIVERSITY

    REFERENCES :

     Information Technology Act, 2000 (Act No. 21 of 2000).

     Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).

     Copyright Act, 1957 (Act No. 14 of 1957).

     Consumer Protection Act, 2019 (Act No. 35 of 2019).

     Justice K.S. Puttaswamy (Retd.) v Union of India, (2017) 10 SCC 1.

     Shreya Singhal v Union of India, (2015) 5 SCC 1.

     Anuradha Bhasin v Union of India, (2020) 3 SCC 637.

     European Union, Artificial Intelligence Act, Regulation (EU) 2024/1689.

      OECD, OECD AI Principles (updated 2024).

     UNESCO, Recommendation on the Ethics of Artificial Intelligence (2021).

     UNESCO & MeitY, Catalysing AI Readiness in India (2024).

     UNESCO & MeitY, India AI Readiness Assessment Report (2026).