Which Indian AI rules bind a GIFT City entity
India has no AI statute. This separates what binds you from the report, the voluntary guidelines and the draft that are cited as though they did.
What binds you
IFSCA displaces the mainland regulator rather than adding to it, so a GIFT City entity does not take the SEBI or RBI position on AI. It takes a document that appears to be the first Indian financial-sector instrument to name frontier AI as a defined scenario a board has to be shown.
Any entity licensed, recognised, registered or authorised by IFSCA — which displaces the mainland regulator rather than adding to it.
The most specific AI-facing obligations in India reach you, through an instrument that calls itself an advisory and is very largely drafted as “shall”.
Nothing on this list is an AI rule that binds you. That is the finding, not a gap in it. What does bind you today is technology-neutral: the incident reporting duty, your sector regulator’s cyber instrument, and — from 13 May 2027 — the DPDP obligations wherever a model touches personal data.
| Instrument | Force | From |
|---|---|---|
| CERT-In Directions, 2022 No. 20(3)/2022-CERT-In | Binding | 27 June 2022 |
| Digital Personal Data Protection Rules, 2025 G.S.R. 846(E) | Binding | 13 May 2027 |
| IFSCA Advisory on Heightened Cyber Security Risks from Frontier AI Models IFSCA-CSD/MSC/3/2026-DCS | Advisory, largely drafted as “shall” | 4 June 2026 |
| MeitY India AI Governance Guidelines | Voluntary | 5 November 2025 |
What each one asks for, and what it can do to you
- CERT-In Directions, 2022 — binding. A cyber incident reported to CERT-In within six hours of noticing it. The Directions are technology-neutral, so an incident caused by or involving an AI system is reportable on exactly the same terms as any other.
Enforceable against you today. A breach is actionable by the regulator under its own powers. Not an AI instrument, and included because it is the one obligation on this page that is certain to apply to an AI incident today. An organisation waiting for AI-specific reporting rules already has reporting rules. - Digital Personal Data Protection Rules, 2025 — binding. Where an AI system processes digital personal data, the Data Fiduciary obligations — notice, security safeguards, breach intimation, retention limits and Data Principal rights — reach that processing like any other. They commence on 13 May 2027.
Enforceable against you today. A breach is actionable by the regulator under its own powers. The date matters more here than elsewhere, because model training on personal data is the use most often described as already regulated in India. It is not yet: rules 3 and 5 to 16 commence eighteen months after publication. - IFSCA Advisory on Heightened Cyber Security Risks from Frontier AI Models — advisory, largely drafted as “shall”. Frontier AI carried as a named scenario in the cyber risk assessment, reviewed periodically and put before the Board — before the Standing Committee on Technology at an MII. A Software Bill of Materials covering open-source components. A comprehensive inventory of APIs and the applications consuming them, with rate-limiting and a whitelist. Critical service providers required to assess frontier-AI risk and furnish evidence of preparedness. Monitoring tuned for attack sequences that exceed plausible human-operated timelines. Human oversight and security testing of AI-generated code before production.
Issued as a circular, in force, and expressly diluting no other obligation — but titled an advisory, and encouraging compliance on its covering page. Read the annexure rather than the label: what is drafted with “shall” is what a supervisor will ask about. Titled an advisory, and its covering circular says entities are encouraged to comply. But it is a circular, in force with immediate effect, issued under the same sections as the Guidelines it sits alongside, and it states that it dilutes no existing obligation. Six of the eleven items in Annexure A are drafted with “shall”. An entity reading only the covering paragraph would take the whole annexure as optional and be wrong about two-thirds of it. As far as this register is aware it is the first Indian financial-sector instrument to name frontier AI as a defined scenario a board has to be shown. - MeitY India AI Governance Guidelines — voluntary. A set of governance recommendations for AI development and deployment in India, addressed to industry and to government.
Not enforceable. The document says so of itself, and adopting it is a choice rather than compliance. The Guidelines say of themselves that voluntary frameworks lack legal enforceability or punitive action, and they recommend amending the Information Technology Act rather than passing an AI law. They are the document most often cited as evidence that India “has AI governance rules”.
Indicative, and not legal advice. Every binding instrument here was read from the issuing regulator’s own notification; the non-binding documents are linked to their publishers. Whether an instrument reaches your organisation is a determination for your legal team.
Take this away as a print-ready AI obligations brief
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Five documents, five different forces
India has no AI statute and no AI regulator, so the question is never only whether a document reaches you. A committee report, a voluntary framework and a consultation paper all read like rules and none of them is one.
| Force | What it means |
|---|---|
| Binding | Enforceable against you today. A breach is actionable by the regulator under its own powers. |
| Advisory, largely drafted as “shall” | Issued as a circular, in force, and expressly diluting no other obligation — but titled an advisory, and encouraging compliance on its covering page. Read the annexure rather than the label: what is drafted with “shall” is what a supervisor will ask about. |
| Voluntary | Not enforceable. The document says so of itself, and adopting it is a choice rather than compliance. |
| A report to a regulator | A committee reporting to a regulator, not the regulator instructing you. It may become policy and has not. |
| Draft | A consultation paper. Nothing in it binds anyone, and the proposals in it may change or be dropped. |
Every binding instrument here was read from the issuing regulator’s own notification. Indicative, and not legal advice.
Every instrument cited here was verified against the issuing regulator's own notification on .Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- Is there a law regulating artificial intelligence in India?
- No. India has no AI statute and no AI regulator. The binding obligations come from sector regulators using existing powers: SEBI amended three sets of regulations on 6 February 2025, and IFSCA issued a frontier AI circular for GIFT City entities on 4 June 2026. MeitY’s India AI Governance Guidelines of 5 November 2025 are expressly voluntary and recommend amending the Information Technology Act rather than passing an AI law.
- Does the RBI have an AI framework banks must follow?
- No. The FREE-AI document of 13 August 2025 is a committee’s report to the Reserve Bank, not the Reserve Bank instructing a regulated entity, and nothing in it is enforceable against a bank today. It is routinely written up as “the RBI’s AI framework”, which reverses the direction of the document. What does bind an RBI regulated entity is the cybersecurity Directions of 31 July 2026, which apply to the systems it runs whether or not a model is inside them.
- When did SEBI’s AI rule for depositories commence?
- 10 February 2025, on publication in the Official Gazette. The Depositories and Participants amendment is widely reported as commencing on 1 April 2025, but its own regulation 2 carries a proviso putting the amendment in regulation 3(IV) into force on gazette publication instead — and regulation 3(IV) is the AI clause. The 1 April date is true of the fee clauses the same amendment carries and false of the clause it is cited for.
- Has SEBI required a kill switch for AI systems?
- No. The kill switch appears in SEBI’s consultation paper on guidelines for the responsible usage of AI and machine learning, issued for comment on 20 June 2025. It is a draft proposal. SEBI’s final guidelines were confirmed still unissued on 3 September 2026, checked against SEBI’s own circular and regulation listings rather than against commentary.
- What does the IFSCA frontier AI advisory require?
- Despite its title, most of its annexure is drafted with “shall”: frontier AI carried as a named scenario in the cyber risk assessment and put before the Board, a Software Bill of Materials covering open-source components, an inventory of APIs and the applications consuming them with rate-limiting and a whitelist, critical service providers required to furnish evidence of frontier-AI preparedness, monitoring tuned for attack sequences faster than a human could run, and human oversight plus security testing of AI-generated code before production.