Home / Resources / Compliance

Compliance · 6 min read · Updated 2026-07-06

India's DPDP Act and Enterprise AI: What MeitY, CERT-⁠In and RBI Expect You to Prove

India's compliance stack for enterprise AI — the DPDP Act 2023 and its 2025 Rules, CERT-In's six-hour incident clock and RBI's FREE-AI framework — rewards platforms that can prove data residency, evidence and oversight by architecture.

India is building its AI economy and its accountability regime at the same time. The Union Cabinet approved the IndiaAI Mission in March 2024 with an outlay of ₹10,371.92 crore, while NASSCOM's responsible-AI guidance pushes the industry toward governance by design. On the obligations side, MeitY notified the DPDP Rules 2025 on 14 November 2025, operationalising the DPDP Act 2023 with a phased compliance window of up to 18 months. CERT-In has enforced a six-hour cyber-incident reporting clock since 2022. And RBI's FREE-AI committee report of 13 August 2025 sets out seven guiding principles and 26 recommendations for AI in the financial sector. The message to enterprises is consistent: adopt AI — but be ready to prove how it behaves.

What does the DPDP Act demand of enterprise AI?

The DPDP Act treats every organisation processing digital personal data as a Data Fiduciary — and AI pipelines are processing. Three duties bite hardest:

  • Consent and purpose limitation — personal data entering prompts, RAG indexes or fine-tuning sets must map to a notified purpose; repurposing customer records as model context is processing that needs a lawful basis.
  • Breach notification — under the DPDP Rules 2025, affected individuals must be informed without delay and the Data Protection Board must receive a detailed report within 72 hours.
  • Significant Data Fiduciary duties — annual data protection impact assessments, audits and algorithmic due diligence for entities so designated.

Penalties under the Act reach ₹250 crore per breach category. An AI platform that cannot show which personal data entered which model, when and why, cannot answer any of this.

Can your AI stack survive CERT-In's six-hour clock?

CERT-In's directions of 28 April 2022 require covered entities to report cyber incidents within six hours of noticing them, and to retain logs for 180 days within India. Six hours is not enough time to reconstruct events from a vendor's opaque cloud. It demands AI audit trails that already exist: per-call records of who invoked which model, with what data, through which connector, and what came back. If assembling that evidence requires a support ticket to someone else's platform, the clock will beat you.

MeitY accelerates, RBI counsels care

MeitY's IndiaAI Mission funds compute, foundation models and Safe & Trusted AI, and its advisories signal closer scrutiny of deployed models. For financial entities, RBI's FREE-AI framework is more pointed: board-level accountability, explainability, resilience and proportionate oversight of high-risk use cases. For a bank or NBFC, the practical reading is that AI governance must live in the execution path — with human-in-the-loop approvals before consequential actions, not policy documents after them.

What should an Indian enterprise demand of an AI platform?

  • Data residency by architecture — inference, retrieval and logs inside your perimeter, air-gap capable; not contractual promises about foreign regions.
  • Evidence on demand — an append-only record of every AI action, ready for the Data Protection Board, CERT-In or RBI supervisors.
  • Human oversight — approval gates on agentic actions, with truthful status reporting.
  • Cost control — token-heavy RAG and agent workloads need budgets and routing, or adoption stalls.
  • Native fit for Indian operations — GST e-invoicing through the IRP, IRN generation, and governed connectors for Tally and Zoho Books.

India's direction is consistent across MeitY, CERT-In and RBI: the enterprises that win with AI will be those that can prove, inside their own perimeter, exactly what their AI did.

Related guides

Compliance

AI guardrails in Australia: what the Voluntary AI Safety Standard, Essential Eight and Privacy Act reform mean for enterprise AI

Australia is converging on AI governance from three directions at once — safety guardrails, cyber baselines and privacy reform — and enterprise AI platforms must now prove all three.

6 min read

Read the guide

Compliance

Japan AI Governance: What the AI Promotion Act, METI Guidelines and APPI Expect of Enterprises

Japan's AI Promotion Act, the METI/MIC AI Guidelines for Business and a tightening APPI form a soft-law stack that still expects enterprises to prove governance, human oversight and domestic data control.

6 min read

Read the guide

Compliance

Singapore AI Governance: What IMDA, PDPC and MAS Expect Enterprises to Prove

Singapore's AI governance stack — IMDA's Model AI Governance Framework, AI Verify testing, PDPC's PDPA guidance and MAS FEAT — rewards enterprises whose AI claims are provable, not merely stated.

6 min read

Read the guide
COMING SOONAANCER launches shortly.Register for prelaunch events & demos →