Live 20 practitioner certifications live · First lesson free on every course Back to main site →

The regulator map. MeitY, DPDP Board, SEBI, RBI, IRDAI, TRAI and the Enforcement Directorate

Seven regulators touch Indian AI governance, each with a different mandate, a different enforcement style and a different timeline for its next move. This lesson maps the seven, with the specific question each one owns, and tells you which regulator to call first when an incident lands on your desk.

Free preview 12 min read Verified

A CTO at a Pune healthtech called me on a Saturday afternoon last August. One of his GenAI assistants had produced a wrong clinical recommendation for a user, and the user had posted screenshots on social media. The CTO wanted to know who he had to notify, and in what order, and within what timeline. "Just tell me the single number to call," he said. There is no single number. There are seven.

The Indian AI governance regime is distributed across seven regulators and one law-enforcement agency. If you cannot identify which regulator owns which question before an incident lands, you will spend the first 48 hours of an incident reading PDFs rather than running a response. This lesson maps the seven and gives you the "call first" sequence that works for the three most common incident classes.

MeitY sets the frame

The Ministry of Electronics and Information Technology is the national AI governance frame-setter. It published the Guidelines of 5 November 2025 [L4-C1]. It operates through PRID press releases, advisories and the IT Rules framework. MeitY owns three questions. One, what is the national AI governance posture? (Answer: voluntary, function-based, 7 Sutras.) Two, what are the obligations on intermediaries that touch AI-generated content? (Answer: IT Rules 2026 amendment of 10 February 2026 [L4-C2].) Three, when will any of this become mandatory? (Answer: no date yet; drafting of standalone AI law announced July 2026, no draft in Parliament.)

MeitY does not own the question of "has your specific AI system complied with the Guidelines". That question is reserved for sectoral regulators, future AIGG and the DPDP Board. MeitY sets the vocabulary. The sectoral regulators enforce.

The Data Protection Board of India owns DPDP enforcement

The Data Protection Board of India, constituted under Section 18 of the DPDP Act 2023, owns the specific question of whether an AI system processing personal data has complied with DPDP Section 10 obligations [L4-C3], including the Section 10(2)(c) proviso on algorithmic due diligence. The DPB can impose penalties up to Rs 250 crore under the Schedule for various breaches, with the Section 10 slice capped at Rs 150 crore. The DPB is operational for Rules 1, 2 and 17-21 since 13 November 2025; full Rule set operational from 13 May 2027.

If an AI incident involves personal data of Indian Data Principals, the DPB is one of your first calls. If it does not, the DPB is not relevant.

SEBI owns capital-markets AI

SEBI owns AI governance questions for its registered intermediaries. The AI Advisory of 5 May 2026 [L4-C4] sits on top of the CSCRF Framework. SEBI\'s enforcement style on AI matters is CSCRF-adjacent: audit, inquiry, direction, and ultimately the Section 11 and Section 12 SEBI Act powers. SEBI\'s next move will be the finalisation of its AML/CFT Master Circular refresh (October 2025 draft) and sector-specific implementation on the AI Advisory.

For a broker, DP, AMC, PMS, investment adviser, custodian, KRA or any other Section 12 SEBI Act intermediary, SEBI is the primary regulator for AI governance. The DPB is secondary (through DPDP coverage of personal data).

RBI owns banking and NBFC model risk

The Reserve Bank of India owns model risk management for banks and NBFCs through the Draft Model Risk Circular (5 August 2024, expanded 2026 cycle) [L4-C5] and the FREE-AI Report (13 August 2025). RBI\'s enforcement style is directional: Master Directions, inspections and Section 35A Banking Regulation Act powers. The AI incident reporting workflow in FREE-AI is advisory for now; the final Master Direction expected after the 24 July 2026 comments window will make it binding.

Eleven RE categories are in scope. A payments bank, small finance bank, NBFC-Middle Layer, NBFC-Upper Layer, Payments System Operator, Credit Information Company, Primary Dealer or Co-operative Bank running any AI/ML model in credit must plan for RBI model-risk expectations.

IRDAI owns insurance AI

The Insurance Regulatory and Development Authority of India owns AI governance for insurers, brokers, corporate agents, web aggregators, TPAs, repositories and IIBI. The current frame is the IRDAI Information and Cyber Security Guidelines of 6 April 2026, which treats AI primarily as a threat vector. The AI governance frame proper is being developed by the AI Working Group constituted on 19 June 2026. Report due September 2026; draft framework circular likely Q1-Q2 2027.

IRDAI\'s enforcement style is directional and licence-conditional. Non-compliance with cybersecurity or future AI guidelines can trigger supervisory action under the IRDAI Act 1999.

TRAI watches telecom AI, DoT holds the stick

The Telecom Regulatory Authority of India published recommendations in July 2023 proposing a national AIDAI (AI and Data Authority of India). MeitY did not adopt the proposal. The Department of Telecommunications under the Telecommunications Act 2023 and the Telecom Cyber Security Rules 2024 [L4-C6] is the operational regulator. The Rules are AI-silent in direct terms; AI responsibilities sit inside the generic defend obligation.

For a telecom service provider deploying AI (fraud detection, network optimisation, customer service), DoT is the first regulator; TRAI is advisory.

The Enforcement Directorate handles AI-enabled financial crime

The Enforcement Directorate does not regulate AI as such. But when AI is used in financial fraud, deepfake-enabled impersonation or sanctions evasion, the ED enters through PMLA and FEMA. ED cases around AI-enabled crime are still emerging; the regime is new and the practical precedent is thin. Teach ED as a backstop, not a front-line regulator.

The "call first" sequence for three common incident classes

Class 1, AI system harms a user. Example: wrong clinical recommendation, discriminatory credit decision. First call: your DPO + Legal, scope the Section 10 DPDP question. Then sectoral regulator if applicable (SEBI if a broker, RBI if a bank, IRDAI if an insurer). Then user communication under Sutra 6 and the IT Rules 2026 obligations if the output qualifies as Synthetically Generated Information.

Class 2, AI model compromised by attack. Example: prompt injection extracting training data, model inversion. First call: CISO + CERT-In under the 28 April 2022 Directions (6-hour clock). Then DPB if personal data affected. Then sectoral regulator. Then your developer vendor.

Class 3, AI-generated synthetic media incident. Example: deepfake of an employee goes viral. First call: Legal + MeitY under the IT Rules 2026 amendment (3-hour takedown clock, 2-hour non-consensual sexual imagery clock). Then police if an FIR is warranted (IPC 465/469, IT Act 66C/66E) [L4-C7]. Then user communication.

Five failure modes practitioners repeat

Treating MeitY as the enforcer. MeitY sets the frame, sectoral regulators and the DPB enforce.

Missing the DPB clock. DPDP Rule 7 commencement on 14 May 2027 will tighten the breach-reporting window. Prepare now.

Reading the Telecom Rules as AI-silent. They are AI-silent in direct terms, but your AI responsibilities sit inside the generic defend obligation.

Ignoring the IRDAI AI Working Group output. The forthcoming framework will reshape insurer AI programmes; a wait-and-see posture risks a scramble.

Treating ED as remote. AI-enabled financial crime cases will reach the ED. If your AI system is in the money-laundering adjacent space, build the discipline early.

Your artifact from Lesson 4

Build the Regulator Map for your organisation. For each AI system you operate, list the primary regulator, the secondary regulator, the "call first" person in each regulator relationship, and the current state of their next move. Save as Artifact 4 in your capstone workbook. Review quarterly.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (55 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
MeitY AI Governance Guidelines 2025, PIB PRID 2186639 (5 November 2025) (MeitY Guidelines announcement) L4-C1
PIB Press Release 5 November 2025 announcing the India AI Governance Guidelines under the IndiaAI Mission.
IT Rules 2026, IT Rules 2026 Amendment (10 Feb 2026) (IT Rules 2026 Amendment) L4-C2
IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026, in force 20 February 2026.
DPDP x AI, DPDP Act 2023 Section 10 (DPDP Section 10) L4-C3
Significant Data Fiduciary notification criteria on six factors including risk to Data Principal rights.
SEBI AI, SEBI AI Advisory HO/13/19/12 (5 May 2026) (SEBI AI Advisory 2026) L4-C4
SEBI Advisory on Emerging Advanced AI Tools for Vulnerability Detection dated 5 May 2026. Applies to over 10,000 regulated entities.
RBI AI, RBI Draft Model Risk Circular (5 August 2024) (RBI Model Risk 2024 draft) L4-C5
RBI draft on Regulatory Principles for Management of Model Risks in Credit, press release 5 August 2024, comments closed 4 September 2024.
Telecom AI, Telecom Cyber Security Rules 2024 (21 Nov 2024) (Telecom Cyber Rules 2024) L4-C6
Rules notified 21 November 2024 under the Telecommunications Act 2023. Six-hour incident reporting, CTSO must be an Indian citizen. No AI-specific provisions.
Related Statutes, IT Act 2000 Section 66C (IT Act S.66C) L4-C7
Punishment for identity theft under the Information Technology Act 2000.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The India AI Governance Perimeter and Why You Are Reading This
Module 2: The MeitY Guidelines, Section by Section
  • The 7 Sutras, one by one, with the Indian context behind each
  • The 6 Pillars across Enablement, Regulation and Oversight, and the two Pillars where you actually spend time
  • Developer, deployer, data provider. Three functions, three parallel sets of duties documented, signed and defended
  • Transparency reporting under Sutra 6, aligned to DPDP, and what a disclosure a regulator can understand actually looks like
  • AIGG, TPEC and AISI. The three institutions, the current state on 9 October 2026 and how to track
Module 3: RBI FREE-AI and Financial-Sector AI
  • The FREE-AI Committee, the Report of 13 August 2025 and the 26 Recommendations that preceded MeitY
  • The Model Risk Management Framework. RBI Draft of 5 August 2024 and the expanded 2026 cycle
  • AI in credit underwriting. Borrower scoring, bias testing and challenger models at an NBFC gold-loan and personal-loan book
  • The AI kill-switch and incident reporting. FREE-AI expectations, the Chapter 5 form and the CERT-In six-hour interface
  • The Bank and NBFC Board policy on AI. The twelve-clause specimen outline
Module 4: SEBI AI Vulnerability Advisory and Market Infrastructure
  • The SEBI AI Vulnerability Advisory of 5 May 2026. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026
  • Annexure A, ten items. The deep walk through items 2, 6c, 9 and 10
  • Market SOC onboarding. What M-SOC is, what it ingests and how an entity integrates
  • How the AI Advisory expands CSCRF audit scope. project-cyber-suraksha.ai and advisor obligations
  • Running the SEBI AI programme end-to-end on Aarti Capital Markets
Module 5: DPDP x AI
  • Section 10 Significant Data Fiduciary. The six-factor test and why nobody has been notified yet
  • Section 10(2)(c) proviso. Algorithmic due diligence, verbatim text and operational meaning
  • Rule 13. Twelve-month DPIA, independent audit and the Board reporting cadence
  • Rule 7 breach notification. AI incidents, the DPB clock, the MeitY expectation and the CERT-In six-hour window
  • Why DPDP has no Article 22. India chose a de facto automated decision regime through Section 10(2)(c)
Module 6: The AI Governance Officer's Playbook
  • The appointment Board resolution in detail. Five authorities, eleven paragraphs, one specimen
  • The AI inventory and model register. Columns, worked rows, and the "one-page in thirty minutes" test
  • The twelve-clause AI governance policy. Scope to third-party management, one clause at a time
  • The Board reporting cadence and the five KPIs that matter
  • Personal liability and the due-diligence defence. DPDP Schedule, sectoral penalties, Section 79 safe harbour
Module 7: Risk Assessment, DPIA and the Model Lifecycle
  • High-impact decision classification. The method MeitY left to you
  • The AI-specific DPIA. Ten sections that satisfy DPDP Section 10(2)(c) and Rule 13
  • Pre-deployment testing. Bias, robustness and security batteries that satisfy a regulator
  • Post-deployment monitoring. Drift, feedback loops, shadow mode and the thresholds that trigger review
  • Change control, retraining and incident response. Closing the lifecycle loop
Module 8: Transparency, Explainability and Human Oversight
  • User-facing transparency notices. Operationalising Sutra 6 for Aarti Capital's three AI use cases
  • Model cards and datasheets for datasets. The two documents a regulator will ask for first
  • Explainability for high-impact decisions. What SHAP, LIME and counterfactuals buy you, and where they fail
  • Human-in-the-loop oversight. Three stages, one SOP, and how to document that a human actually reviewed
  • Audit trail and immutable logging. Reconstructing a specific AI decision three years later
Module 9: Synthetic Media and the IT Rules 2026 Amendment
  • The new Synthetically Generated Information category under the IT Rules 2026 amendment
  • Labelling and provenance metadata. Watermarks, C2PA and metadata that survives re-encoding
  • The three-hour takedown and the two-hour non-consensual sexual imagery window
  • Deepfake case law. Rashmika Mandanna, Lok Sabha 2024 and Images Bazaar PIL
  • The MeitY advisories of 1 March and 15 March 2024. How India iterates fast
Module 10: Sectoral Deep-Dives: IRDAI, Telecom, Health and Public Services
  • IRDAI AI Working Group and the framework insurers should pre-build
  • The IRDAI 2026 Cyber Security Guidelines and AI as a threat vector
  • The Telecom Cyber Security Rules 2024 and where AI sits in a silent framework
  • TRAI's AIDAI proposal and why MeitY picked AIGG, TPEC and AISI instead
  • Healthcare, education and public-services AI: the gaps and the practitioner playbook
Module 11: The International Reference Layer
  • EU AI Act. The four risk tiers and the phased timeline that quietly binds Indian GCCs
  • NIST AI RMF 1.0 and the GenAI Profile. Four functions and twelve generative risks
  • OECD AI Principles. The common vocabulary that lets a Mumbai team talk to a Munich team
  • ISO/IEC 42001. The voluntary conformity path and the clause-by-clause map to the MeitY 7 Sutras
  • The GCC compliance architecture. One baseline plus two overlays, when EU plus India plus US arrives at once
Module 12: Capstone and Final Exam
  • Build your ten-week AI governance programme. The scope document and the stakeholder map
  • Weeks 1-10 Gantt and the twelve artifacts of the capstone workbook
  • The Board briefing deck and the year-1 operating calendar
  • The 25-anchor exam reference card
  • The final exam. 45 questions from a 70-item pool, 90 minutes, 75 percent pass