Fixation of liability in the AI world – Rethinking India's Legal Framework

AI Liability India - Legal Framework and Governance

Artificial intelligence is rapidly transforming the fabric of India's economy. From healthcare diagnostics and financial services to transportation and public governance, AI systems are increasingly being integrated into decision-making processes that affect millions of people.

However, as AI systems become more autonomous and complex, an urgent question arises: Who is Legally Responsible When AI Causes Harm?

This article examines India's current legal framework governing Legal AI liability, identifies key gaps in the existing regulatory approach, and explores possible solutions for strengthening Legal AI governance in the country.

Understanding liability in context of Legal AI

If we go by legal terms then Liability can be referred to as the legal responsibility, obligation or debt a person or entity has for their actions or inactions often requiring them to compensate another party for damages.

Now, traditionally establishing legal liability requires four elements:

  1. A duty of care owed by the defendant
  2. Breach of that duty
  3. A causal connection between the breach and the harm
  4. Actual damage suffered by the claimant

In conventional cases such as road accidents or defective consumer goods, this framework works effectively as the cause of the harm can be usually traced to the specific action or actor.

However in case of Legal AI, this framework gets complicated in various ways:

  • The Black Box problem – How a Decision Is Arrived At In AI?

The 'black box problem' in artificial intelligence refers to the difficulty in determining how an AI system reached a particular decision due to the opacity of its internal processes. Many advanced AI models, particularly those based on machine learning, do not provide transparent or easily interpretable reasoning for their outputs.

When the decision-making process of a Legal AI system cannot be clearly understood, it becomes difficult for courts to determine whether the harm was caused by a defect in the system, biased data, improper deployment, user interaction or something else. As a result, the black box nature of AI complicates the attribution of legal responsibility in cases involving AI-related harm.

  • Multiple Actors in the AI Value Chain

Unlike traditional products, AI systems are rarely built by a single entity. Their lifecycle often involves multiple participants, including:

  • Dataset providers
  • Algorithm developers
  • Model trainers
  • Users

When harm occurs, identifying which participant bears legal responsibility becomes complex.

  • Self-Learning and Adaptive Systems

Self-learning and adaptive AI systems refer to artificial intelligence models that can modify their responses over time by learning from new data or interactions with users. Unlike traditional software that follows fixed instructions, these systems continuously evolve, making their future actions difficult to predict.

This characteristic complicates liability in law because harm may arise from changes in the system's behaviour after it has been developed or sold. As a result, it becomes difficult to determine whether responsibility lies with the developer, data provider, deployer, or user, since the AI system may produce outcomes that were not explicitly programmed or anticipated at the time of its creation.

Current Legal Framework for AI Liability in India

India currently does not have a dedicated legal framework specifically addressing liability arising from artificial intelligence (AI). Instead, AI-related harms are governed through a combination of existing technology laws, criminal statutes, sectoral regulations, and voluntary governance frameworks.

1. Baseline Legislation

  • Information Technology Act, 2000 – Governs cyber offences and intermediary liability. Provisions such as Section 66D (cheating by personation) and Sections 67, 67A, and 67B (obscene or sexually explicit electronic content) may apply to certain Legal AI-generated harms, including impersonation or deepfakes.
  • Bharatiya Nyaya Sanhita, 2023 – Section 356 (defamation) may be invoked where AI-generated content harms an individual's reputation.
  • Digital Personal Data Protection Act, 2023 – Regulates the processing of personal data, which may apply where AI systems misuse or unlawfully process personal information.

2. Sectoral Regulatory Guidance

Sector-specific regulators have issued limited guidance on the use of Legal AI within their domains, including:

  • RBI for financial services,
  • SEBI for algorithmic systems in securities markets, and
  • ICMR for ethical use of AI in healthcare.

3. Policy Initiatives and Voluntary Standards

India's AI governance ecosystem also includes policy-level and voluntary frameworks such as:

  • India AI Governance Guidelines (2025) and the IndiaAI Mission,
  • ISO/IEC 42001 AI Management Systems standard adopted by BIS
  • TEC 57050:2023 Fairness Assessment Standard for AI systems.

4. Key Limitations

  • Existing laws are technology-neutral and largely reactive, addressing harms only after they occur.
  • Provisions apply only to specific types of misconduct (such as fraud, defamation, or obscene content).
  • The framework does not adequately address Legal AI-specific risks, including algorithmic bias, multi-actor liability, autonomous decision-making, and large-scale misinformation.

Consequently, India's current framework provides baseline safeguards but remains fragmented and insufficient to comprehensively address Legal AI liability.

Proposed Solutions for Reforming the AI Legal Framework

Recent policy discussions in India recommend adopting a techno-legal approach to AI governance, where legal safeguards are complemented by technical and institutional mechanisms. Instead of relying solely on traditional legal remedies, governance measures should be embedded directly into the design, development, and deployment of AI systems, enabling proactive management of risks.

Some key approaches suggested for strengthening the AI liability framework include:

  • Lifecycle-based governance – Regulating Legal AI systems across their entire lifecycle, including development, training, deployment, and post-deployment monitoring.
  • Technical oversight mechanisms – Introducing tools such as algorithmic audits and fairness assessments to detect risks like bias, safety failures, or misuse.
  • Institutional oversight and reporting systems – Establishing mechanisms such as Legal AI incident reporting databases and coordinated regulatory oversight to improve accountability.

Together, these measures aim to create a more integrated and forward-looking governance framework that addresses emerging risks while maintaining space for innovation and responsible AI development.

Conclusion

As AI technologies continue to expand across sectors, India's existing legal framework remains fragmented and largely reactive in addressing AI-related harms. Strengthening the framework through clearer governance mechanisms and accountability measures will be essential to ensure responsible AI development while safeguarding public trust and rights.

Leave a Comment

Your email address will not be published. Fields marked with * are required.

This is a required field.
This is a required field.
This is a required field.

Please correct errors before submitting this form.

Need Help?