A CTO at a Pune healthtech called me on a Saturday afternoon last August. One of his GenAI assistants had produced a wrong clinical recommendation for a user, and the user had posted screenshots on social media. The CTO wanted to know who he had to notify, and in what order, and within what timeline. "Just tell me the single number to call," he said. There is no single number. There are seven.
The Indian AI governance regime is distributed across seven regulators and one law-enforcement agency. If you cannot identify which regulator owns which question before an incident lands, you will spend the first 48 hours of an incident reading PDFs rather than running a response. This lesson maps the seven and gives you the "call first" sequence that works for the three most common incident classes.
MeitY sets the frame
The Ministry of Electronics and Information Technology is the national AI governance frame-setter. It published the Guidelines of 5 November 2025 [L4-C1]. It operates through PRID press releases, advisories and the IT Rules framework. MeitY owns three questions. One, what is the national AI governance posture? (Answer: voluntary, function-based, 7 Sutras.) Two, what are the obligations on intermediaries that touch AI-generated content? (Answer: IT Rules 2026 amendment of 10 February 2026 [L4-C2].) Three, when will any of this become mandatory? (Answer: no date yet; drafting of standalone AI law announced July 2026, no draft in Parliament.)
MeitY does not own the question of "has your specific AI system complied with the Guidelines". That question is reserved for sectoral regulators, future AIGG and the DPDP Board. MeitY sets the vocabulary. The sectoral regulators enforce.
The Data Protection Board of India owns DPDP enforcement
The Data Protection Board of India, constituted under Section 18 of the DPDP Act 2023, owns the specific question of whether an AI system processing personal data has complied with DPDP Section 10 obligations [L4-C3], including the Section 10(2)(c) proviso on algorithmic due diligence. The DPB can impose penalties up to Rs 250 crore under the Schedule for various breaches, with the Section 10 slice capped at Rs 150 crore. The DPB is operational for Rules 1, 2 and 17-21 since 13 November 2025; full Rule set operational from 13 May 2027.
If an AI incident involves personal data of Indian Data Principals, the DPB is one of your first calls. If it does not, the DPB is not relevant.
SEBI owns capital-markets AI
SEBI owns AI governance questions for its registered intermediaries. The AI Advisory of 5 May 2026 [L4-C4] sits on top of the CSCRF Framework. SEBI\'s enforcement style on AI matters is CSCRF-adjacent: audit, inquiry, direction, and ultimately the Section 11 and Section 12 SEBI Act powers. SEBI\'s next move will be the finalisation of its AML/CFT Master Circular refresh (October 2025 draft) and sector-specific implementation on the AI Advisory.
For a broker, DP, AMC, PMS, investment adviser, custodian, KRA or any other Section 12 SEBI Act intermediary, SEBI is the primary regulator for AI governance. The DPB is secondary (through DPDP coverage of personal data).
RBI owns banking and NBFC model risk
The Reserve Bank of India owns model risk management for banks and NBFCs through the Draft Model Risk Circular (5 August 2024, expanded 2026 cycle) [L4-C5] and the FREE-AI Report (13 August 2025). RBI\'s enforcement style is directional: Master Directions, inspections and Section 35A Banking Regulation Act powers. The AI incident reporting workflow in FREE-AI is advisory for now; the final Master Direction expected after the 24 July 2026 comments window will make it binding.
Eleven RE categories are in scope. A payments bank, small finance bank, NBFC-Middle Layer, NBFC-Upper Layer, Payments System Operator, Credit Information Company, Primary Dealer or Co-operative Bank running any AI/ML model in credit must plan for RBI model-risk expectations.
IRDAI owns insurance AI
The Insurance Regulatory and Development Authority of India owns AI governance for insurers, brokers, corporate agents, web aggregators, TPAs, repositories and IIBI. The current frame is the IRDAI Information and Cyber Security Guidelines of 6 April 2026, which treats AI primarily as a threat vector. The AI governance frame proper is being developed by the AI Working Group constituted on 19 June 2026. Report due September 2026; draft framework circular likely Q1-Q2 2027.
IRDAI\'s enforcement style is directional and licence-conditional. Non-compliance with cybersecurity or future AI guidelines can trigger supervisory action under the IRDAI Act 1999.
TRAI watches telecom AI, DoT holds the stick
The Telecom Regulatory Authority of India published recommendations in July 2023 proposing a national AIDAI (AI and Data Authority of India). MeitY did not adopt the proposal. The Department of Telecommunications under the Telecommunications Act 2023 and the Telecom Cyber Security Rules 2024 [L4-C6] is the operational regulator. The Rules are AI-silent in direct terms; AI responsibilities sit inside the generic defend obligation.
For a telecom service provider deploying AI (fraud detection, network optimisation, customer service), DoT is the first regulator; TRAI is advisory.
The Enforcement Directorate handles AI-enabled financial crime
The Enforcement Directorate does not regulate AI as such. But when AI is used in financial fraud, deepfake-enabled impersonation or sanctions evasion, the ED enters through PMLA and FEMA. ED cases around AI-enabled crime are still emerging; the regime is new and the practical precedent is thin. Teach ED as a backstop, not a front-line regulator.
The "call first" sequence for three common incident classes
Class 1, AI system harms a user. Example: wrong clinical recommendation, discriminatory credit decision. First call: your DPO + Legal, scope the Section 10 DPDP question. Then sectoral regulator if applicable (SEBI if a broker, RBI if a bank, IRDAI if an insurer). Then user communication under Sutra 6 and the IT Rules 2026 obligations if the output qualifies as Synthetically Generated Information.
Class 2, AI model compromised by attack. Example: prompt injection extracting training data, model inversion. First call: CISO + CERT-In under the 28 April 2022 Directions (6-hour clock). Then DPB if personal data affected. Then sectoral regulator. Then your developer vendor.
Class 3, AI-generated synthetic media incident. Example: deepfake of an employee goes viral. First call: Legal + MeitY under the IT Rules 2026 amendment (3-hour takedown clock, 2-hour non-consensual sexual imagery clock). Then police if an FIR is warranted (IPC 465/469, IT Act 66C/66E) [L4-C7]. Then user communication.
Five failure modes practitioners repeat
Treating MeitY as the enforcer. MeitY sets the frame, sectoral regulators and the DPB enforce.
Missing the DPB clock. DPDP Rule 7 commencement on 14 May 2027 will tighten the breach-reporting window. Prepare now.
Reading the Telecom Rules as AI-silent. They are AI-silent in direct terms, but your AI responsibilities sit inside the generic defend obligation.
Ignoring the IRDAI AI Working Group output. The forthcoming framework will reshape insurer AI programmes; a wait-and-see posture risks a scramble.
Treating ED as remote. AI-enabled financial crime cases will reach the ED. If your AI system is in the money-laundering adjacent space, build the discipline early.
Your artifact from Lesson 4
Build the Regulator Map for your organisation. For each AI system you operate, list the primary regulator, the secondary regulator, the "call first" person in each regulator relationship, and the current state of their next move. Save as Artifact 4 in your capstone workbook. Review quarterly.