India’s AI Law: A Third Way Emerges Between Washington and Brussels

India’s Ministry of Electronics and Information Technology (MeitY) Secretary, S. Krishnan, confirmed last week that the government is actively drafting a “well-calibrated” AI law, studying both the US market-driven approach and the EU’s risk-based AI Act. This announcement comes as the country’s AI market is projected to reach $17 billion by 2027, according to a NASSCOM report. For founders building in or for India, this signals the end of regulatory ambiguity and the beginning of a structured compliance era. The question is not whether regulation will come, but which model India will adopt and how that will reshape the competitive landscape.

The timing is deliberate. India currently hosts over 3,000 AI startups, many of which rely on open-source models or US-based infrastructure. The government’s dual study of the US and EU frameworks suggests it wants to avoid both the heavy-handed bureaucracy of Brussels and the laissez-faire chaos of Silicon Valley. The resulting law could become a template for the Global South, where countries like Brazil and Indonesia are watching closely. For founders, this means the window for unregulated experimentation is closing, but so is the risk of sudden, draconian bans.

The US vs. EU Divide: What India Is Weighing

The US approach to AI regulation is fragmented and industry-led. There is no single federal AI law. Instead, the White House’s Executive Order on AI from October 2023 relies on voluntary commitments from major players like OpenAI, Google, and Microsoft. The Federal Trade Commission uses existing consumer protection laws to police AI harms. This model favors innovation speed but leaves startups in a gray zone, especially around liability for AI-generated content or bias in hiring tools.

The EU’s AI Act, passed in March 2024, takes the opposite tack. It classifies AI systems into four risk categories: unacceptable, high, limited, and minimal. High-risk systems, such as those used in critical infrastructure or employment, face strict requirements for transparency, human oversight, and conformity assessments. Non-compliance can trigger fines of up to 7% of global annual turnover. This gives startups a clear rulebook but also imposes significant upfront costs for legal and technical audits.

India’s MeitY Secretary emphasized that the government is “studying both models” to find a middle path. Early indications suggest India will adopt a risk-based framework similar to the EU, but with lighter compliance burdens for small and medium enterprises. Sources close to the drafting committee say the law will likely exempt startups under a certain revenue threshold from full audits, while requiring all AI systems to undergo a basic “safety assessment” before deployment. This hybrid approach could give Indian founders the regulatory clarity they need without strangling early-stage innovation.

What the Law Will Actually Target

The coming Indian AI law is expected to focus on three core areas: data governance, algorithmic accountability, and sector-specific applications. Data governance is particularly sensitive given India’s ongoing debates over its Digital Personal Data Protection Act, which took effect in August 2023. AI systems that process personal data will need to comply with both laws, creating a dual compliance burden for startups in health tech, fintech, and edtech.

Algorithmic accountability will likely require companies to document training data sources, explain model decisions in lay terms, and establish grievance redressal mechanisms for users affected by AI outputs. This mirrors the EU’s requirement for “human oversight” but may be less prescriptive. For example, instead of mandating a specific technical standard, India could require companies to publish a “model card” summarizing the system’s strengths and weaknesses, similar to the approach used by Hugging Face.

Sector-specific applications will be targeted first. The government has already created advisory committees for AI in healthcare, agriculture, and financial services. These sectors are considered high-risk because of their direct impact on human welfare. A diagnostic AI tool in rural India, for instance, will face stricter scrutiny than a chatbot for customer support. Founders building in these verticals should expect sectoral guidelines to precede the general law, possibly by mid-2025.

The Geopolitical Angle: Sovereignty and Standards

India’s AI law is not just about domestic regulation. It is also a strategic move in the global AI race. The US and EU are both trying to export their regulatory models. The US promotes a “values-based” approach through initiatives like the AI Safety Institute, while the EU uses its market size to enforce the Brussels effect, where companies comply with EU rules globally to avoid fragmentation.

India, as the world’s most populous country and a major tech talent hub, cannot afford to be a rule-taker. By drafting its own law, India is asserting regulatory sovereignty. This could lead to a situation where startups must comply with three sets of rules: US, EU, and Indian. For founders targeting international markets, this means building compliance from day one, not as an afterthought. The good news is that India’s law is likely to be interoperable with the EU’s framework, given the government’s active study of the AI Act. But interoperability does not mean identical requirements. Founders should budget for multiple compliance workflows.

The law also has implications for data localization. India’s previous attempts to mandate data localization for payments and social media have been controversial. The AI law could introduce new localization requirements for training data, especially for systems that use Indian language datasets or demographic data. This would directly impact startups that rely on global cloud providers or foreign open-source models.

What This Means for Founders

For AI founders building in India or targeting Indian users, the message is clear: prepare for structured regulation, not a free-for-all. Here are the actionable takeaways:

  • Start compliance work now. Even before the law passes, adopt industry best practices like model documentation, bias testing, and user consent mechanisms. This will reduce the shock when formal rules arrive. The government has signaled it will look favorably on early adopters.
  • Build for interoperability. If your product serves users in the US, EU, and India, design your system to meet the highest common denominator of rules. For example, if you plan to comply with the EU AI Act, you will likely be most of the way toward Indian compliance.
  • Watch sectoral guidelines closely. If you are in healthcare, agriculture, or finance, expect targeted rules before the general law. Engage with government consultation processes now. The MeitY has a history of incorporating industry feedback, as seen in the data protection law.
  • Budget for legal and technical overhead. Compliance will not be free. Plan for costs related to audits, documentation, and potential localization of training data. Early-stage startups may qualify for exemptions, but do not assume that.
  • Consider the geopolitical angle. India’s law is part of a broader push for digital sovereignty. If your startup relies on foreign AI models or data, explore partnerships with Indian cloud providers or open-source alternatives to reduce regulatory risk.

India’s AI law is not a threat. It is a signal that the market is maturing. Founders who treat regulation as a design constraint rather than a nuisance will have a competitive advantage. The window for regulatory arbitrage is closing, but the opportunity to build trustworthy, scalable AI in one of the world’s fastest-growing digital economies has never been bigger.