India moves to regulate AI: what to fix now
A consultation paper on AI regulation is due within a month. One part of the law is already in force, and a few habits will keep you on the right side of it.
· 3 min read · For owners and officers using AI in customer-facing work

You may already be using AI somewhere — a chatbot that answers on WhatsApp, a tool that writes product descriptions, a voice that reads out a notice in Tamil. Until now the rules around this were loose. That is changing, and the direction is clear enough to plan around.
What changed on 8 October
The Union Minister for Electronics and Information Technology said on 8 October 2026 that the Centre will release a consultation paper on AI regulation within a month. He named what it will cover: AI safety, deepfakes, harms caused by AI use, a human-first approach, and skilling. He also said industry must carry the main responsibility for these risks. A consultation paper is not law. It is the stage where government puts up its thinking and asks for views before drafting. If AI touches your customers, that is your window to read it and say something.
This is a shift. In November 2025 the ministry published the India AI Governance Guidelines — seven guiding principles and recommendations across six pillars, with the stated focus on using existing laws wherever possible. The consultation paper is the step after that, towards a law of its own.
What is already in force
One part is not waiting for the consultation. On 10 February 2026 the IT Rules of 2021 were amended to cover "synthetically generated information" — audio, images or video made or changed by a computer so that it looks real. Three points matter:
- Such content must carry a label that is easy to notice, and, where technically possible, hidden provenance data saying which tool made it. The label must not be removable.
- Routine work is excluded — colour correction, noise removal, formatting, and good-faith making of documents, presentations, PDFs or training material with illustrative images.
- The time to take down unlawful content, after a court order or a proper written intimation from government, is now three hours. It used to be thirty-six.
These duties sit on platforms and on the tools that generate the content, not on every business. But they decide what those tools will let you do, and they tell you where the law is heading.
What to fix this week
- Write down where AI is used in your work today — replies, summaries, images, voice, marking, inspection. Most firms find more places than they expected.
- Label AI-made images, voices and videos in your own ads and customer messages, even where no rule forces you to yet. It costs nothing and it protects you later.
- Never use a real person's face or voice without written consent. That is exactly where the deepfake worry is aimed.
- Keep a log — what went in, what came out, who approved it. If a complaint arrives a year later, the log is your answer.
- Name one person as accountable, and keep a human sign-off before anything reaches a customer or a citizen.
- Read your AI vendor's contract on data: where it is stored, who can see it, and whether your data is used to train their model.
How we can help
We build AI into working software with the label, the log and the human check already inside it, using our own focused models — Vizhi for vision, Sol for Tamil, English and Hindi, Kural for speech, Thedal for search, Thudippu for machine health. You can see how we think about this on our AI page. If you want a plain reading of what these rules mean for the AI you already use, talk to us.


