Lakshmikumaran and Sridharan logo
Acts and Laws to Keep in Mind Before Implementing AI

Acts and Laws to Keep in Mind Before Implementing AI

Subhomoy Bakshi, Head of Digital Transformation

24 Sept 20256 min read

There is no single statute a company can read to become compliant with AI. There is instead a patchwork of two kinds of law: older rules that reach AI because they reach everything, and a first generation of AI-specific statutes still settling into force. The task for an enterprise is unglamorous but decisive, that is, to work out which of these apply to a use case before the use case goes live, not after a regulator asks the question.

Data protection is the law AI touches first. Almost any AI project that uses personal data steps straight into the data-protection regime of every jurisdiction it operates in. In the European Union, the GDPR sets the benchmark: lawful and transparent processing, enforceable individual rights, and, of direct relevance to AI, a right not to be subject to purely automated decisions with significant effects unless specific conditions are met. California's CCPA, as amended by the CPRA, sets comparable expectations in the United States. In India, the Digital Personal Data Protection Act, 2023, is now operational through the DPDP Rules, 2025, notified on 13 November 2025, with core obligations such as notice, security safeguards, and breach reporting phasing in through to roughly mid-2027. The Act turns on consent, data minimisation, and accountability, and it carries penalties of up to Rs 250 crore for a failure to take reasonable security safeguards. Other regimes, Brazil's LGPD and Singapore's PDPA among them, add their own requirements, so a multinational needs a privacy strategy that covers each market rather than the most convenient one. Before an AI system processes personal data, the Data Protection Officer or external counsel should test it against these laws, because a misstep here is measured in fines and in lost trust.

Sectoral regulators now treat AI as their business. If an AI system performs a regulated activity, assume the regulated rules apply as though a human were performing it. An AI making lending decisions does not escape fair-lending and credit-reporting law; an AI used in diagnostics does not escape medical-device regulation or patient-confidentiality rules such as HIPAA. In India, the Reserve Bank of India, SEBI, and IRDAI have each begun to examine AI within their domains, and the RBI's FREE-AI Committee report, "Framework for Responsible and Ethical Enablement of AI" (August 2025), is explicit that entities deploying AI remain accountable for the decisions those systems make, and recommends a board-approved AI governance policy. Elsewhere, regulators have issued AI-specific guidance, from proposed frameworks for AI in medical devices to expectations of explainability in AI-driven credit decisions. Check whether your regulator has spoken, because sectoral guidance can require algorithm audits, documentation, or, in some cases, clearance before deployment.

AI-specific regulation is arriving, and its reach is long. The most developed example is the European Union's AI Act, which entered into force in August 2024 and takes a risk-based approach. It bans a small set of unacceptable uses, such as social scoring; it subjects high-risk uses, including AI in hiring and critical infrastructure, to strict obligations on transparency, risk assessment, logging, and human oversight; and it imposes lighter transparency duties on lower-risk systems that interact with people. Its obligations phase in on a staggered timeline: the prohibitions applied from February 2025, obligations for general-purpose AI models from August 2025, and most high-risk obligations through 2026 and 2027 following the deferrals agreed in the 2026 Digital Omnibus. The Act reaches beyond the EU's borders in many cases, so a company that offers products there or processes EU residents' data may fall within it. The pattern is not confined to Europe. New York City's Local Law 144 has required bias audits of automated employment decision tools since 2023; Colorado enacted a broader AI statute whose substantive duties were later narrowed and whose effective date was pushed to January 2027; and China regulates recommendation algorithms and deep-synthesis or generative content. The practical response is to assign someone to track these developments, because a system you can foresee being classified as high-risk is far cheaper to build to standard now than to retrofit under deadline later.

Intellectual property law has not caught up, but it still governs. Existing IP frameworks apply to AI even where they fit awkwardly. Training a model on copyrighted material without permission is legally risky, and while fair use is argued in the United States, the question is unsettled and actively litigated, with cases against AI developers over their training data worth watching for the precedents they will set. Patent law, in most jurisdictions, does not permit an AI to be named as an inventor, so an AI-assisted invention needs a human inventor to be patentable. Trade-secret law can protect your data and algorithms if you keep them confidential, and it cuts the other way too, because a vendor's model may be a trade secret you cannot fully inspect, which affects how far you can explain its decisions. Licensing deserves the same care: open-source models and libraries carry terms that can restrict commercial use or compel you to share improvements, and compliance with those terms is not optional.

Liability defaults to the company deploying the system. When AI causes harm, the law today generally routes responsibility to the enterprise that put it to use, under ordinary product-liability or negligence principles. If an AI-driven service produces a flawed result that costs a client money, the client can sue as though a person had produced it; the AI is not a shield. The European Commission had proposed an AI Liability Directive to adapt liability rules to AI, but it withdrew that proposal in 2025, leaving AI liability in Europe to national law and the revised Product Liability Directive. Consumer-protection and advertising law still apply to AI-generated claims, and pricing algorithms that drift into coordinated behaviour can raise antitrust concerns that regulators have already flagged. The absence of a single "AI liability law" does not place AI outside the law; it means your company will answer for what the system does, so its outputs deserve the same diligence as human work product.

In India, the IT Act and its rules sit underneath all of this. Alongside the DPDP Act, the Information Technology Act, 2000, and its rules form the backbone of Indian cyber law, addressing unauthorised access and data theft that become live risks the moment an AI system is attacked or misused. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules matter for AI because the Ministry of Electronics and Information Technology has extended their logic to it: an advisory issued on 1 March 2024 initially required government permission to deploy under-tested AI, and was then revised on 15 March 2024 to drop that permission requirement while retaining duties around unlawful content, non-discrimination, electoral integrity, and the labelling of synthetic media. The direction of travel is clear, that is, existing content law is being read onto AI outputs, so an enterprise deploying generative AI must ensure the system does not produce content that Indian law already prohibits.

The workable method is to map every jurisdiction the business operates in or markets to, list the laws that apply as above, and then have them interpreted against each specific use case. Where regimes overlap, the strictest usually sets the effective standard, so many companies simply apply GDPR-grade controls everywhere. Soft-law frameworks from the OECD and UNESCO, though not binding, point where the hard law is heading, and the companies that adopt those principles early tend to find compliance easier when the rules tighten. Knowing the law is one thing; building the internal machinery to meet it is another, and it is where experienced legal counsel earns its place.