Skip to Content

ARTIFICIAL INTELLIGENCE AND THE LAW

BALANCING INNOVATION, ACCOUNTABILITY AND FUNDAMENTAL RIGHTS IN INDIA
9 October 2026 by
MADHU SURYA M , BA.LLB(HONS) - IV YEAR, THE TAMILNADU DR AMBEDKAR LAW UNIVERSITY, SCHOOL OF EXCELLENCE IN LAW, CHENNAI
​

ABSTRACT

Artificial Intelligence (AI) is rapidly becoming part of decision-making in finance, healthcare, education, policing, employment, courts, and public administration. Its ability to process large volumes of information can improve efficiency, but opaque models, biased datasets, extensive data collection, and automated decisions may also affect equality, privacy, liberty, and procedural fairness. India does not yet have a single comprehensive AI statute. Instead, the regulatory framework is developing through constitutional principles, sectoral legislation, the Information Technology framework, and the Digital Personal Data Protection Act, 2023 and Rules, 2025. This article examines whether the existing framework is sufficient to address rights-based risks created by AI. It adopts a doctrinal and analytical methodology, examining constitutional provisions, legislation, judicial decisions, and the emerging European Union model. Particular attention is given to Articles 14, 19, and 21 of the Constitution, informational privacy, algorithmic discrimination, transparency, and accountability. The article argues that India should adopt a risk-based, human-centred governance framework without unnecessarily restricting beneficial innovation. It recommends mandatory impact assessments for high-risk systems, meaningful human oversight, explainability, auditability, data governance, grievance redressal, and stronger institutional coordination. The European Union AI Act offers useful comparative lessons, but Indian regulation should remain responsive to domestic constitutional values, institutional capacity, and developmental priorities.

Keywords: Artificial Intelligence; Fundamental Rights; Article 14; Article 21; Privacy; Algorithmic Bias; Data Protection; AI Regulation; Accountability; India.

1. INTRODUCTION

Artificial Intelligence has moved from being a specialised technological field to a general-purpose infrastructure capable of influencing everyday legal and social relationships. AI systems can classify information, generate content, recommend decisions, identify patterns, and predict outcomes. These capabilities can support public administration, medical diagnosis, legal research, education, and economic activity. At the same time, the delegation of consequential decisions to systems that may be difficult to understand or challenge creates a distinctly legal problem: when an automated output causes harm, who is responsible and what remedy is available?[1]

The Indian legal system currently approaches AI through a combination of constitutional rights, existing technology legislation, data protection rules, and sector-specific regulation rather than through one dedicated AI statute. The Digital Personal Data Protection Act, 2023 recognises the protection of personal data while permitting lawful processing, and the Digital Personal Data Protection Rules, 2025 provide an implementation framework. However, data protection alone cannot address every AI-related risk. A system may produce discriminatory results, interfere with freedom of expression, affect access to public services, or influence judicial and administrative decisions even where the underlying processing is otherwise lawful.[2]

This article therefore examines whether India's existing legal framework can adequately protect fundamental rights while preserving technological innovation. It argues that regulation should focus not simply on AI as a technology, but on the level of risk created by a particular use. The central objective should be accountable and human-centred AI rather than either unrestricted deployment or excessive prohibition.

2. RESEARCH QUESTIONS, OBJECTIVES AND METHODOLOGY

The article addresses three principal research questions:

  1. To what extent can Articles 14, 19, and 21 of the Constitution address rights-based harms arising from AI systems?

  2. Are the existing Indian data protection and technology laws sufficient to ensure transparency, accountability, and meaningful remedies in high-risk AI use?

  3. What regulatory lessons can India draw from the European Union's risk-based AI framework?

The objectives are to examine the constitutional basis for regulating AI, analyse the relevant statutory framework, identify accountability gaps, and develop practical recommendations for rights-respecting AI governance.

The research adopts a doctrinal and analytical methodology. Primary sources include constitutional provisions, legislation, rules, and judicial decisions; secondary and tertiary sources include academic commentary, policy documents, and comparative regulatory materials.

3. CONSTITUTIONAL FOUNDATIONS FOR AI REGULATION

3.1 Article 14 — Equality and Non-Discrimination

Article 14 guarantees equality before the law and equal protection of the laws. In the context of AI, this provision becomes particularly significant because automated systems can produce discriminatory outcomes even without explicit discriminatory intent. Algorithmic decision-making may rely on historical data that reflects past patterns of exclusion, or may use proxy variables that correlate with protected characteristics such as caste, religion, or gender.

The traditional equality inquiry focuses on whether the State's classification is reasonable and whether it has a rational nexus to a legitimate purpose. AI complicates this analysis because the discrimination may emerge from complex interactions within the system that are not readily apparent to either the decision-maker or the affected individual. The legal challenge is therefore not only to identify improper intention but also to examine the design, data, validation, and real-world effects of the system.

3.2 Article 19 — Freedom of Speech and Expression

Article 19(1)(a) protects freedom of speech and expression, subject to reasonable restrictions under Article 19(2). AI systems can affect this right in several ways. Content moderation algorithms may remove or restrict lawful speech. Recommendation systems may amplify certain viewpoints while suppressing others. Generative AI may produce content that is difficult to distinguish from human-created expression.

The constitutional challenge is to ensure that AI-mediated restrictions on speech satisfy the requirements of Article 19(2) and are not arbitrary or disproportionate. The Supreme Court's jurisprudence on free expression, including the principles established in Shreya Singhal v. Union of India, provides a framework for evaluating whether AI-related restrictions meet constitutional standards.

3.3 Article 21 — Life, Liberty, and Privacy

Article 21 provides that no person shall be deprived of life or personal liberty except according to procedure established by law. The Supreme Court's decision in K.S. Puttaswamy v. Union of India established privacy as a fundamental right and required that any restriction on privacy satisfy the tests of legality, legitimate State purpose, and proportionality.[3]

AI systems frequently collect, infer, or combine personal information to create profiles that an individual may never have knowingly supplied. The Puttaswamy principles are therefore directly relevant to AI governance. They require that data collection and processing have a legal basis, serve a legitimate purpose, and be proportionate to the aim pursued. The decision also connects privacy with individual autonomy and informational control, values that are essential in evaluating AI systems that make consequential decisions about individuals.[4]

4. STATUTORY AND REGULATORY FRAMEWORK

4.1 Digital Personal Data Protection Act, 2023 and Rules, 2025

The Digital Personal Data Protection Act, 2023 is central to AI governance because many AI systems depend upon personal data. The Act regulates the processing of digital personal data and establishes obligations for Data Fiduciaries, together with rights of Data Principals and an institutional mechanism through the Data Protection Board of India. Its provisions concerning notice, consent, legitimate uses, general obligations, children's data, access, correction, erasure, and grievance redressal can operate as safeguards where AI development or deployment involves personal data.[5]

The Act nevertheless has a narrower focus than a comprehensive AI law. It is principally concerned with processing of digital personal data rather than the full lifecycle risks of AI. Consequently, a harmful AI outcome may fall outside a purely data-protection analysis where the central issue is discrimination, explainability, product safety, or allocation of public power. The 2025 Rules add operational detail to the statutory framework, but they do not transform the DPDP regime into a general AI accountability law.[6]

4.2 Information Technology Framework and Sectoral Regulation

The Information Technology Act, 2000 and the rules framed under it remain relevant to online intermediaries, cybersecurity, and electronic activity. However, these instruments were not designed specifically for modern generative AI, foundation models, or automated high-stakes decision-making. Sectoral regulators may address particular applications, but fragmented regulation can create uncertainty where an AI system operates across several sectors simultaneously.

The result is a regulatory gap between data protection and broader algorithmic accountability. India therefore needs mechanisms that identify high-risk uses, impose proportionate duties, and provide affected persons with meaningful avenues for explanation and redressal.

5. JUDICIAL PERSPECTIVE AND ACCOUNTABILITY

Indian constitutional jurisprudence provides principles capable of guiding AI regulation even without an AI-specific statute. Puttaswamy establishes privacy as a fundamental right and requires legality, legitimate State purpose, and proportionality when privacy is restricted. The decision also connects privacy with individual autonomy and informational control. These principles are relevant where AI systems collect, infer, or combine personal information to create profiles that an individual may never have knowingly supplied.[7]

Algorithmic discrimination raises an additional Article 14 concern. Traditional equality review focuses on the State's classification and the rationality of its action. AI complicates this inquiry because discrimination may emerge from historical datasets, proxy variables, or correlations that are not openly selected by the decision-maker. The legal challenge is therefore not only to identify an improper intention but also to examine the design, data, validation, and real-world effects of the system.

The emerging importance of human oversight is also visible in contemporary judicial policy discussions. In 2026, the Supreme Court released draft regulations addressing AI use in courts, including safeguards against judicial outcomes being reached solely through algorithmic decision-making and requirements for human authority in adjudicative decisions. Although these are draft regulatory measures rather than a general AI statute, they demonstrate a significant principle: AI may assist legal institutions, but consequential judicial authority should remain subject to accountable human decision-makers.[8]

This principle should extend beyond courts. In welfare allocation, recruitment, credit, education, policing, and healthcare, human oversight should be meaningful rather than merely formal. A person should not be told that a decision cannot be reviewed because "the algorithm decided it." Accountability must ultimately attach to an identifiable institution or decision-maker.

6. COMPARATIVE PERSPECTIVE: THE EUROPEAN UNION AI ACT

The European Union has adopted a comprehensive risk-based approach through Regulation (EU) 2024/1689, commonly known as the AI Act. The framework categorises AI according to risk and combines prohibited practices, requirements for high-risk systems, transparency obligations, and governance mechanisms.[9] The EU model is particularly relevant because it places fundamental rights, safety, and trustworthy AI alongside innovation rather than treating them as competing objectives. [10]

The AI Act prohibits specified harmful practices, including certain manipulative systems, social scoring, and individual predictive policing based solely on profiling. High-risk systems are subject to stronger requirements, while certain general-purpose AI models have additional obligations. The framework also recognises fundamental-rights impact assessment for specified high-risk deployments. This is important because it shifts regulation from reacting to individual harm towards identifying and mitigating risks before deployment.[11]

For India, the EU model should be treated as a comparative reference rather than copied wholesale. India's constitutional structure, administrative capacity, digital public infrastructure, and socio-economic conditions differ from those of the EU. Nevertheless, the principles of risk classification, impact assessment, transparency, human oversight, and institutional enforcement are adaptable to the Indian context.

The European approach also demonstrates the value of regulatory coordination. Fundamental-rights authorities can request information and documentation concerning high-risk AI systems, and the framework provides mechanisms for cooperation between market-surveillance and rights-protection authorities. India could similarly create coordinated oversight between data protection, sectoral regulators, and a specialised AI governance institution.[12]

7. FINDINGS AND DISCUSSION

The research indicates that India's existing legal framework provides important building blocks but remains incomplete for comprehensive AI governance. First, constitutional rights can constrain public use of AI, particularly through equality, privacy, liberty, and proportionality principles. Second, the DPDP Act and Rules establish an important data-governance foundation. Third, existing technology and sectoral laws can address specific forms of misuse. However, these mechanisms do not consistently address explainability, algorithmic bias, model accountability, high-risk classification, pre-deployment impact assessment, or responsibility across the AI supply chain.

A central concern is the accountability gap created by complex AI systems. Developers may control model architecture, deployers control the context of use, data providers influence training material, and public authorities may make the final decision. Without clear allocation of responsibility, each actor may attribute the harm to another. Regulation should therefore impose duties proportionate to the role and risk of each actor.

Another concern is the difference between transparency and meaningful explanation. Merely disclosing that AI was used does not allow an affected person to challenge a decision. For high-risk decisions, meaningful safeguards should include the purpose of the system, relevant factors, the possibility of human review, available evidence, and a route to correction or appeal. At the same time, disclosure requirements must protect legitimate trade secrets and cybersecurity interests. The goal should be contestability, not unrestricted disclosure of source code.

The regulatory approach should also recognise that innovation and rights protection are not inherently contradictory. Predictable rules can encourage responsible investment by reducing uncertainty. A proportionate framework would allow low-risk experimentation while imposing stronger safeguards on systems that can materially affect rights, safety, or access to essential services.

8. CONCLUSION

Artificial Intelligence presents India with both a governance challenge and an opportunity to strengthen the quality of decision-making. The central legal issue is not whether machines should be permitted to assist human activity, but whether the use of AI can remain consistent with constitutional values when it affects individuals in consequential ways. Articles 14, 19, and 21 provide a powerful rights-based foundation, while the DPDP Act, 2023 and Rules, 2025 provide an important data-protection layer. Yet these instruments do not, by themselves, constitute a comprehensive framework for algorithmic accountability.

India should therefore move towards a proportionate, risk-based, and human-centred AI governance model. The EU AI Act demonstrates how risk classification, impact assessments, transparency, human oversight, and institutional enforcement can be combined. India can adapt these principles to its own constitutional and developmental context. The objective should be neither technological exceptionalism nor blanket prohibition. It should be accountable innovation in which AI remains subject to law, human judgment, and effective remedies. Such an approach would ensure that technological progress strengthens, rather than weakens, the constitutional promise of equality, liberty, dignity, and privacy.

Reference

[1] European Commission, "AI Act," Shaping Europe's Digital Future (2026), digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.

[2] Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025 (14 November 2025), www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWA.

[3] K.S. Puttaswamy v. Union of India (2017) 10 SCC 1.

[4] K.S. Puttaswamy v. Union of India (2017) 10 SCC 1.

[5] Digital Personal Data Protection Act, 2023, Act No. 22 of 2023.

[6] Digital Personal Data Protection Rules, 2025.

[7] K.S. Puttaswamy v. Union of India (2017) 10 SCC 1.

[8] Supreme Court of India, Draft Regulations for Use of Artificial Intelligence in Courts, 2026; Supriya Shekher Azad and Kamaan Mehta, "Inside SC's Proposed Regulations for AI Use in Courts: What's Allowed, What's Absolutely Barred," Indian Express (13 July 2026), indianexpress.com/article/explained/explained-ai/sc-proposed-regulations-ai-use-in-courts-10783388/.

[9] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (AI Act).

[10] European Commission, "AI Act," Shaping Europe's Digital Future (2026), digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.

[11] European Commission, "Governance and Enforcement of the AI Act," Shaping Europe's Digital Future (7 August 2026), digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement.

[12] European Commission, "Governance and Enforcement of the AI Act," Shaping Europe's Digital Future (7 August 2026), digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement.

MADHU SURYA M , BA.LLB(HONS) - IV YEAR, THE TAMILNADU DR AMBEDKAR LAW UNIVERSITY, SCHOOL OF EXCELLENCE IN LAW, CHENNAI 9 October 2026
Share this post
Category
Sign in to leave a comment