The Ministry of Electronics and Information Technology is shifting from existing laws to a dedicated, risk-based AI regulatory framework. This approach aims to protect users while balancing innovation, with stricter rules expected for high-risk sectors like banking and healthcare. Investors should monitor how upcoming guidelines from SEBI and the government impact compliance costs for tech-heavy companies.
The Indian government is moving to establish a formal, standalone legal framework for artificial intelligence, marking a significant departure from its previous reliance on existing information technology and data protection laws. Top officials at the Ministry of Electronics and Information Technology have confirmed that the government is actively developing a risk-based, graded regulatory approach. This shift acknowledges that while AI offers substantial economic benefits, the technology requires specific legal guardrails to address safety and accountability.
A Graded Regulatory Approach
The proposed framework intends to categorize AI applications based on potential harm. Under this model, low-risk tools—such as basic productivity applications or minor automation—would face light-touch oversight to avoid stifling innovation. In contrast, high-risk sectors including banking, healthcare, and critical infrastructure will likely face stringent requirements. These mandates could include mandatory audits, detailed transparency disclosures, and strict liability standards. By differentiating between applications, regulators hope to manage systemic risks without creating a rigid system that hampers technological growth.
Market Oversight and Operational Risks
Financial markets are set to see some of the most immediate impacts. The Securities and Exchange Board of India (SEBI) is drafting specific guidelines for the use of artificial intelligence and machine learning in capital markets. A key area of concern is the proposal for a mandatory human-in-the-loop requirement, where critical decisions cannot be left entirely to algorithms. Furthermore, the regulator is evaluating the necessity of a kill-switch mechanism, which would allow for the emergency, manual shutdown of an AI system if it behaves unpredictably or risks causing market instability. For fintech firms, banks, and technology service providers, these requirements could necessitate significant changes to existing software architecture and operational workflows.
Compliance Costs and Business Impact
For investors, the primary monitorable in this transition is the potential rise in compliance costs. Companies currently using AI to drive efficiency, manage credit risk, or power trading algorithms may face higher expenses related to governance, technical disclosures, and external audits. While larger, well-capitalized firms may absorb these costs more easily, smaller entities might find the regulatory burden more challenging. The uncertainty regarding specific compliance deadlines and the final language of the legislation also introduces a period of policy risk, as firms await the government's official consultation papers.
What Investors Should Track Next
The government is expected to release further details and initiate public consultations before the end of 2026. Investors should monitor company commentary regarding their readiness for these potential mandates, particularly firms with high reliance on automated decision-making. Future updates on the specific thresholds for what constitutes a high-risk AI application will be critical, as this will define the scope and intensity of the regulatory impact on individual companies and sectors.
