AI & emerging technology law in India, argued by lawyers who read the model card before the contract.
SIRI Law LLP advises Indian and cross-border companies on EU AI Act compliance, DPDP Act 2023 obligations for AI systems, LLM vendor risk, algorithmic liability, and NIST AI RMF governance — under attorney-client privilege, backed by an in-house cybersecurity practice that can test the system the law firm is reviewing.
Why this page exists
India isn't writing an AI Act. It's aiming existing law at AI — and the aim is getting sharper.
If you build, deploy, or procure AI systems that touch Indian users, the Ministry of Electronics and Information Technology (MeitY) has been explicit: there is no plan for a horizontal AI statute in the near term. Instead, your obligations already sit inside the DPDP Act 2023, the IT Act 2000, the IT Intermediary Rules, and whichever sector regulator — RBI, SEBI, IRDAI — already supervises your business.
That is not a lighter compliance burden. It is a more fragmented one. A single AI feature — say, a credit-scoring model or a customer-support chatbot — can simultaneously trigger DPDP consent and purpose-limitation duties, IT Rules synthetic-content labelling if it generates media, sectoral RBI or SEBI conduct rules if it touches financial decisions, and EU AI Act exposure the moment your product is offered to a single user in Frankfurt or Paris. Most legal teams read these as separate problems handled by separate advisors. We read them as one system, because that is how a regulator, a plaintiff's lawyer, or a Data Protection Board investigator will eventually read them too.
The DPDP Act's application to AI is the sharpest edge in the room. Companies training or fine-tuning models on personal data of individuals in India do not get a carve-out because the processing happens inside a neural network rather than a spreadsheet — the Act's consent, purpose-limitation, and data-minimisation obligations apply in full, and the DPDP Rules 2025 (notified 14 November 2025) converted what used to be principle into procedure: defined breach-notification timelines, Significant Data Fiduciary duties, and a Data Protection Board of India that is already operational and accepting complaints in the National Capital Region.
For companies with any EU-facing footprint, the picture shifted again in May 2026. The European Parliament, Council, and Commission reached a political agreement on the AI Act "Digital Omnibus" that pushes back the compliance clock for high-risk systems — Annex III use-based systems to December 2027, Annex I product-embedded systems to August 2028 — while accelerating the deadline for AI-generated content transparency (watermarking) to December 2026. The relief is real, but it is not yet final law, and it does not touch the prohibited-practices regime that has applied since February 2025. Treating a proposed delay as settled compliance strategy is precisely the kind of assumption that turns into a governance gap.
Named counsel, not a call centre
Every AI matter carries a named lead who answers for the outcome.
What we cover
Our AI & emerging technology law practice
Six practice lines, built to match how AI risk actually shows up in a company — not how a law firm's org chart is drawn. Each one below states exactly what work product you receive.
EU AI Act Compliance
Risk classification against Annex I and Annex III, conformity assessment preparation, and technical documentation for Indian companies exporting AI products or services into EU markets — built around the revised Omnibus timeline, not the original one.
- Prohibited-practice screening (in force since Feb 2025)
- High-risk classification memo with Annex citations
- Conformity assessment roadmap and CE-marking pathway
- Watermarking / transparency compliance for Dec 2026
NIST AI RMF Implementation
Legal translation of the NIST AI Risk Management Framework's Govern, Map, Measure, and Manage functions into board-level policy, a documented risk register, and named accountability — the artefacts a regulator or acquirer's diligence team actually asks to see.
- AI governance charter and RACI mapping
- Risk register aligned to RMF categories
- Board-level AI oversight policy
- Model inventory and lifecycle documentation
Algorithmic Liability & Bias
Legal risk assessment for automated decision-making — discriminatory outcome exposure, explainability obligations, and the human-oversight standard regulators and courts are converging on, benchmarked against Indian consumer-protection law and emerging global precedent.
- Pre-deployment discrimination risk review
- Explainability and human-oversight design memo
- Litigation readiness for automated-decision disputes
- Sector-specific liability mapping (RBI/SEBI/IRDAI)
LLM Vendor Contracts
Data processing agreements, model-licensing terms, IP ownership clauses, hallucination liability waivers, and indemnification frameworks — reviewed and redlined for enterprises deploying third-party LLMs from OpenAI, Anthropic, Google, Microsoft Azure, and others.
- DPA redlines against DPDP Act requirements
- Output-ownership and IP indemnity clauses
- Hallucination and accuracy liability allocation
- Sub-processor and cross-border transfer terms
Generative AI Governance
Enterprise AI governance policy, acceptable-use frameworks, employee AI guidelines, copyright treatment of AI-generated output, and trade-secret protection for confidential data entered into AI tools — drafted to survive an actual employee reading them, not just a board sign-off.
- Acceptable-use policy and employee AI guidelines
- Copyright ownership position for AI-generated work
- Trade-secret and confidentiality controls for AI tool use
- Vendor and shadow-AI risk assessment
AI Security & Privacy Integration
Combined legal-technical review of AI system security — model inversion and extraction risk, training-data privacy under the DPDP Act, prompt-injection liability, and adversarial-attack legal exposure — run jointly with SIRI's cybersecurity red team under one privilege.
- Joint legal + red-team AI security review
- Training-data provenance and DPDP compliance audit
- Prompt-injection and jailbreak liability assessment
- Incident response protocol for AI-specific breaches
Evidence, not guesswork
How the three frameworks that actually bind you compare
Most "AI law" content online explains the EU AI Act in isolation. Your exposure rarely is. Here is how the frameworks most relevant to an Indian company actually stack up, side by side.
| Dimension | DPDP Act 2023 + Rules 2025 (India) | EU AI Act (post-Omnibus, May 2026) | India AI Governance Guidelines (Feb 2026) |
|---|---|---|---|
| Legal status | Binding statute + notified rules | Binding regulation, directly applicable in EU member states | Voluntary, principles-based |
| Who it binds | Any entity processing personal data of individuals in India | Providers/deployers placing AI systems on the EU market, regardless of where they're based | Encouraged for all AI developers and deployers in India |
| Key compliance date | 13 May 2027 (full compliance) | 2 Dec 2027 (Annex III) / 2 Aug 2028 (Annex I) | No fixed date — reference framework for sector regulators |
| Maximum penalty exposure | Up to ₹250 crore per instance under Section 33 | Up to €35 million or 7% of global annual turnover | No direct penalty — but shapes how regulators interpret existing law |
| AI-specific trigger | Any AI system trained on or processing personal data | Risk classification under Annex I / Annex III use cases | All AI systems, scaled by the seven sutras' risk lens |
| Practical relevance to India-based companies | Directly binding — the primary compliance obligation today | Binding only if offering into the EU market; still shapes global best practice | Indirectly binding — sector regulators increasingly reference it |
Sources: DPDP Rules 2025 (Gazette G.S.R. 846(E), 14 Nov 2025); EU Digital Omnibus on AI political agreement (7 May 2026); India AI Governance Guidelines (MeitY, Feb 2026). Figures current as of publication — verify against the latest gazette notifications and EU trilogue outcomes before relying on specific dates.
What non-compliance actually costs
Four ways AI exposure becomes AI liability
Boards tend to treat "AI risk" as a single abstract category. In practice, it resolves into four distinct, quantifiable exposures — each with a different owner, a different regulator, and a different defence.
Maximum per-instance penalty under DPDP Act Section 33 for significant data fiduciary failures, including AI systems processing personal data without valid consent architecture.
Maximum fine or share of global annual turnover for prohibited AI practices — the one part of the EU AI Act regime that has applied without delay since February 2025.
Findings from a non-privileged technical or consulting AI audit are typically discoverable in litigation — an unfavourable finding can become evidence used against you.
Response window under the IT Amendment Rules 2026 for flagged synthetically generated information — a compressed timeline most content and product teams aren't built for.
Why SIRI
Why you need a lawyer who understands AI architectures
No other firm in India combines attorney-client privilege with technical execution across cybersecurity and emerging technology law. That is not a slogan — it is a structural difference in how the work gets done.
Legal + technical integration
Our attorneys understand transformer architectures, RAG pipelines, embedding stores, and LLM API contracts — not just the statute. That means DPAs that actually match how your vendor's system processes data, and governance frameworks your engineering team can implement without a translation layer.
Attorney-client privilege
Every AI risk assessment we run is conducted under privilege. Unlike a management-consulting or technical-audit report, our findings generally cannot be subpoenaed in a regulatory investigation or civil litigation — a distinction that matters enormously the day an assessment finds something unflattering.
Multi-jurisdictional tracking
India's DPDP Act, the EU AI Act (including the 2026 Omnibus amendments), the US executive-order landscape, and emerging APAC frameworks are tracked continuously and translated into what they actually mean for an India-incorporated entity — not a generic global summary.
Integrated cyber + AI security
SIRI's penetration-testing team can assess your AI system's technical vulnerabilities — model inversion, prompt injection, training-data leakage — while our attorneys address the resulting legal liability, in the same engagement, under the same privilege. No standalone law firm offers this.
How an engagement runs
From first call to a governance framework you can defend
Exposure assessment
We map every AI system touching personal, financial, or regulated data, and classify each against DPDP, EU AI Act, and sector-specific obligations.
Week 1Gap analysis
A privileged memo naming the specific statutory or contractual gaps — not a generic checklist — ranked by penalty exposure and remediation cost.
Weeks 1–2Framework build
Governance policy, vendor contract redlines, and board-level oversight documentation drafted jointly with your legal, product, and engineering leads.
Weeks 2–5Standing counsel
Ongoing advisory as regulations shift — including EU Omnibus developments and India's evolving AIGEG guidance — so the framework doesn't go stale.
OngoingWho we work with
Industries where AI risk and regulatory risk are the same conversation
AI governance looks different in a hospital than in a hedge fund. We tailor the framework to the sector's existing regulator, not a one-size template.
Frequently asked
AI law in India — the questions we actually get asked
Does India have a standalone AI law like the EU AI Act?
Not yet, and not imminently. MeitY's AI governance drafting committee — constituted in July 2025 — assessed that a horizontal AI statute is not needed at this stage, concluding that the DPDP Act 2023, the IT Act 2000, the IT Intermediary Rules, and sector-specific regulation from RBI, SEBI, and IRDAI already provide adequate coverage when applied through a risk-based lens. The voluntary India AI Governance Guidelines, released in February 2026, supplement this with seven principles rather than new binding law. The practical implication: your AI compliance obligations are already in force, distributed across statutes you may already be tracking for other reasons.
Do the EU AI Act's high-risk obligations still apply from August 2026?
The original 2 August 2026 deadline for high-risk AI system obligations has been postponed following a political agreement reached by EU negotiators on 7 May 2026 as part of the "Digital Omnibus on AI." Under the revised timeline, Annex III (use-based) high-risk systems now face obligations from 2 December 2027, and Annex I (product-embedded) high-risk systems from 2 August 2028. Two things to note: this agreement still requires formal adoption, expected around June–July 2026, and the prohibited-practices regime — the strictest tier — has applied without delay since February 2025 regardless of the Omnibus. Companies that paused EU AI Act preparation entirely on the strength of a headline are taking on unnecessary risk.
Does the DPDP Act apply to AI models trained on personal data?
Yes, without exception for the fact that the processing happens inside a model rather than a conventional database. Any AI system that ingests, processes, stores, or outputs personal data belonging to individuals in India is subject to the full DPDP Act 2023 framework, as operationalised by the DPDP Rules 2025 (notified 14 November 2025 via Gazette G.S.R. 846(E)). This includes consent-collection architecture, purpose limitation, data minimisation, defined breach-notification timelines, and data principal rights such as erasure and access — all building toward the 13 May 2027 full-compliance deadline.
What happens if my LLM vendor's contract doesn't address DPDP obligations?
You remain the Data Fiduciary — and the liable party — regardless of what your vendor's standard terms say. Most off-the-shelf LLM API agreements are drafted for a US or EU regulatory baseline and do not address DPDP-specific requirements such as breach-notification timelines to the Data Protection Board of India or data principal rights fulfilment. A vendor contract review before signature, not after an incident, is the difference between a negotiated data processing addendum and an indemnification fight.
Is a privileged AI risk assessment different from a technical or consulting audit?
Yes, and the difference is not academic. Findings from a legal assessment conducted by a law firm under attorney-client privilege are, in general, protected from compelled disclosure in litigation or a regulatory investigation. Findings from a standalone technical audit or management-consulting review typically carry no such protection — meaning an unfavourable finding can itself become discoverable evidence used against the organisation that commissioned it. This is the structural reason companies increasingly route AI risk assessments through counsel rather than directly through a consulting engagement.
We're a seed-stage startup — do we need this yet?
Usually sooner than founders expect, for one specific reason: the cost of building governance in from day one is a fraction of retrofitting it after a funding round's due diligence, an enterprise customer's vendor security questionnaire, or a DPDP complaint surfaces a gap. Investors and enterprise buyers increasingly ask AI governance questions directly, and a founder who can produce a coherent answer — rather than an improvised one — closes faster.
Ready when you are
Ready to govern AI with legal authority?
Book a consultation with SIRI's AI Law team. We'll assess your exposure across DPDP, EU AI Act, and sector-specific obligations, map what actually applies to your systems, and build a governance framework that holds up under privilege — not just under a slide deck.
Related services
Other ways SIRI Law LLP supports AI-deploying organisations
AI & LLM security
Adversarial testing of LLMs, RAG pipelines, and AI APIs for prompt injection and model inversion.
Data privacy & cybersecurity law
DPDP Act compliance, consent architecture, and breach notification protocols.
Corporate & commercial law
M&A due diligence, contracts, and governance — with cyber risk assessed inside every deal.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

