Direct Answer to India’s AI Rules

India did not have a single, horizontally applicable artificial intelligence statute in force as of 28 September 2026 comparable to the EU AI Act. Regulation is instead divided among sector-specific laws, government advisories, procurement conditions, court procedures, data-protection requirements, and rules that may be proposed or introduced after the stated date. For legal research and eDiscovery, that fragmented system is more important than the absence of one omnibus AI law. Lawyers must still comply with the Digital Personal Data Protection Act, 2023 and its 2025 rules where applicable, professional duties governing confidentiality and supervision, client instructions, court orders, and applicable rules governing electronic evidence. They should also verify whether a new executive, legislative, or sectoral measure has changed the position before deploying a particular system.

Also worth reading: How Are Law Firms Using AI for eDiscovery and Legal Document Drafting in 2026? · Which AI eDiscovery pilot metrics should legal teams track in 2026? · What Should a Legal AI Procurement Checklist Cover for eDiscovery and Legal Work in 2026?

The practical answer is that Indian legal teams may use AI, including for legal research and document drafting, but they should not treat general-purpose models as authoritative substitutes for a lawyer. A defensible workflow identifies the permitted purpose, selects an appropriately governed tool, limits data exposure, requires human verification, preserves an audit trail, and assigns responsibility for every output. This is especially important for eDiscovery, where an AI system may decide which documents are responsive, privileged, duplicate, or worth reviewing. A technically sophisticated classification process does not eliminate legal responsibility; it makes that responsibility more visible and, in some circumstances, harder to explain if the underlying evidence is incomplete.

No universal Indian rule currently provides a safe harbour for lawyers using AI or establishes a single mandatory “human in the loop” percentage for every legal task. Nevertheless, courts and regulators can expect a person to understand the technology being used, protect client information, verify material facts, and correct errors. The relevant legal question is therefore not simply whether AI is allowed, but whether its use is consistent with applicable law, professional obligations, the lawyer’s instructions, and ordinary quality-control standards.

Why the Indian Framework Remains Fragmented

India’s approach is shaped by a combination of the Digital Personal Data Protection Act, sectoral regulation, existing technology and intermediary rules, judicial oversight, and government guidance. The Digital Personal Data Protection Act creates obligations around processing personal data in digital form, while the wider Indian legal system also contains rules on confidentiality, privilege, electronic records, and evidence. Some AI applications may additionally be affected by sector-specific requirements involving financial services, health, telecommunications, government datasets, or public procurement. This patchwork can create overlapping duties, particularly when the same legal team works on a dispute involving personal information from several regulated sectors.

The supplied research context includes references to a need for a concrete Indian AI policy framework, global AI regulatory tracking, Indian data protection and AI analysis, and governance of global capability centres in Bengaluru. Those references point to continuing policy debate, but they should not be read as proof that a comprehensive Indian AI statute applies to all legal AI. A policy discussion, summit, model guideline, consultation paper, or proposed legislative amendment is not the same as an enforceable law. Before purchasing a tool or changing a production workflow, a legal team should identify the exact instrument, issuing authority, legal status, commencement date, and affected entity.

This distinction matters because AI tools often operate across jurisdictions. A research platform may retrieve Indian cases, international materials, and commercial databases while storing prompts or retrieved documents outside India. International transfer restrictions can arise under India’s data-protection rules, and the vendor’s processing terms may impose further limitations. Likewise, a service trained or hosted abroad may not be covered by an Indian certification, procurement approval, or professional indemnity policy. The applicable rules should therefore be assessed at the level of the actual data flow and service architecture, not inferred from the model’s name or marketing description.

FeatureGeneral-purpose public AI toolEnterprise legal AI platformTraditional legal research or review service
Primary valueFast drafting, summarisation, and question answeringGoverned search, analysis, drafting, and document workflowsLawyer-led research, review, and advice with fewer workflow automations
Data controlsMay be limited or user-dependentUsually offers contractual, administrative, and technical controlsPerformed under professional confidentiality and engagement terms
Indian compliance workUsually requires separate assessmentOften includes configurable regions, retention, and audit featuresDepends on the provider and engagement
CostOften low-cost or free at entryFrequently subscription-based per user or organisationCharged by time, volume, matter, or subscription
Main riskUnverified output, data exposure, and unclear retentionCost, vendor dependence, configuration errors, and residual model errorHigher labour cost and slower repetitive processing
Suitable useLow-risk brainstorming and preliminary analysisControlled research, review prioritisation, and drafting with reviewHigh-stakes opinions, nuanced analysis, and final professional judgement
## AI eDiscovery Under India’s Evolving Rules

Electronic discovery in India is not governed by one AI-specific procedure. The starting point is the applicable procedural law, including the governing rules of the court or tribunal, electronic-record rules, disclosure obligations, and orders concerning preservation or production. Depending on the matter, a party may need to collect, process, review, and produce email, messages, databases, shared workspaces, and other digital records. AI can help identify names, dates, legal issues, responsive passages, possible privilege indicators, duplicates, and review priorities. It cannot, without supervision, decide that a document is legally privileged in every context or that a factual issue is immaterial.

The Digital Personal Data Protection Act and its operative rules add an important control layer when personal data is processed in connection with litigation or investigation. Data minimisation does not mean that a party may disregard preservation or disclosure duties; it means that collection, access, transfer, retention, and deletion should be proportionate and legally justified. A legal team should coordinate AI review with its data-protection obligations, litigation-hold duties, and any court-approved confidentiality measures. Reviewing a smaller, well-defined collection may be more defensible than uploading an entire custodial mailbox to a service without a documented basis.

Indian courts can assess whether parties acted responsibly when managing electronic evidence, and a weak process for explaining AI-assisted review may create credibility problems. The organisation should be able to state which records were collected, how the collection was validated, which tool or rules ranked documents, who investigated privilege, how false negatives were tested, and who made final decisions. It should also preserve model names and versions, prompts or configurations where appropriate, processing reports, exceptions, and human corrections. These records support reproducibility and allow counsel to answer questions about technology without claiming that the tool itself is conclusive.

Legal Research and Document Drafting Controls

Legal research presents two different risks: finding the wrong authority and overstating the authority that was found. An AI system may hallucinate a case, statute, quotation, court, date, or procedural rule. It may also retrieve a real decision but fail to account for later authority, statutory amendments, judicial treatment, or the distinction between a binding precedent and a persuasive source. Indian legal work requires checking the official text or a reputable legal database and reading the surrounding treatment before relying on a result. Citations should be independently verified, even when the platform claims to provide source links.

A controlled research workflow separates discovery from verification. The AI may suggest search concepts, candidate authorities, statutory provisions, and arguments, but a qualified lawyer should confirm each material proposition against the primary source. The record should identify the query, search date, jurisdictional filters, database version, and any limitation caused by the corpus. For document drafting, the lawyer should supply verified facts and approved authorities, require the system to mark uncertainty, and compare the draft against the instructions and source documents. The final work product remains the product of the lawyer, not an acceptable automated output merely because it is fluent.

Confidentiality and supervision are central concerns. The Digital Personal Data Protection Act, professional rules, client contracts, and common-law duties can restrict unauthorised disclosure of client information. A public chatbot should generally receive only minimised, non-identifying, or synthetic material. An enterprise service may support stronger controls, but those controls still require a contract and operational implementation. A contract promising that prompts are not used for training is not enough if the organisation uploads the wrong document, fails to enable a promised setting, or permits excessive user access.

Practical Steps for Indian Legal Teams

The first step is to classify the use case by risk. Low-risk activities might include internal brainstorming, issue spotting on public material, or summarising a document that contains no sensitive information. Higher-risk activities include ranking potentially privileged communications, deciding responsiveness, analysing opposing counsel’s strategy, preparing a filing without review, or answering a regulator using AI-generated text. The risk assessment should name the intended user, affected person, data category, consequence of error, and approval authority. It should also state whether the tool is a general model, a retrieval system, an eDiscovery classifier, or a conventional database with AI features.

The second step is to perform a documented vendor and data-flow review. The team should examine hosting location, subprocessors, retention, model training, encryption, access logs, deletion, incident response, service availability, and the legal basis for any international transfer. It should verify whether Indian data-residency or sectoral requirements apply and whether the contract allocates responsibility for errors, IP, confidentiality, and regulatory cooperation. The review should be refreshed at meaningful intervals, such as annually for a stable deployment and whenever a material model, vendor, data category, or legal requirement changes.

The third step is to establish human review and testing. A sensible pilot may compare AI results with a sample manually reviewed by experienced lawyers, measuring recall, precision, privilege false positives, citation accuracy, and time saved. Legal teams should not accept a vendor’s overall accuracy percentage without knowing the dataset, task definition, threshold, and population tested. A model that performs well on public commercial contracts may perform poorly on multilingual emails, scanned records, mixed-language Indian-language documents, or encrypted repositories. Pilot results should therefore inform deployment rather than serve as a permanent guarantee.

Common Mistakes and Cost Realities

One common mistake is assuming that a future-looking AI governance announcement is already a binding legal requirement. Another is treating a model’s citation output as proof of research. Teams also err by allowing unrestricted prompt uploads, failing to document model versions, measuring productivity before measuring quality, or using a single accuracy figure to represent every workflow. Overreliance on automated privilege review can produce both confidentiality incidents and missed evidence. A second common error is assuming that a global tool’s terms provide Indian-law compliance automatically; they may address privacy or security but not professional duties, procedural rules, or local transfer conditions.

Pricing varies by service and usage. Public chatbot access may be free or begin with a low monthly consumer subscription, while professional research and drafting platforms commonly use per-user, per-seat, annual, or organisation-wide subscriptions. Enterprise eDiscovery products may be priced by user, collected data volume, processing capacity, review volume, hosted data, or a negotiated platform fee. The total cost of ownership can include implementation, permissions, data preparation, human verification, training, security review, integrations, and the labour required to correct errors. A cheaper tool may be economically attractive for low-risk research, but an expensive platform can still be poor value if it is applied without validated workflows.

Cost layerTypical approachWhat to calculate
Entry AIFree or consumer subscriptionUser limits, acceptable data, export rights, and retention
Professional legal platformMonthly or annual per-user feeSeats, corpus access, citations, drafting limits, and support
eDiscovery deploymentPlatform fee plus processing and review costsCollection size, hosting, processing, review volume, and matter duration
GovernanceStaff time, contracts, security, and trainingApproval cycles, testing, monitoring, audits, and incident response
## When to Act, Escalate, or Pause

A team can usually begin a controlled pilot when the use case is low risk, the data is public or synthetic, the tool has passed a basic security and privacy review, and a lawyer will verify every material output. It should escalate to a matter partner, information-security lead, privacy counsel, or client representative when the dataset includes privileged material, personal data, regulatory communications, or information subject to a preservation obligation. Multi-party or cross-border discovery deserves particular care because the collection, production order, and applicable privacy rules may differ by participant and jurisdiction.

A deployment should pause when the system proposes an unsupported citation, produces inconsistent results across repeated queries, cannot explain an important ranking, or handles a material language poorly. Teams should also pause if a vendor cannot answer basic questions about retention, training, subprocessors, or deletion. Court deadlines do not remove the need for quality control, but they may require a staged process: narrow the collection, use human review, seek directions where appropriate, and document limitations. The organisation should not upload sensitive material merely because a deadline is approaching.

The date on the page matters. As of 28 September 2026, users should recheck official Indian government publications, Gazette notifications, court directions, and professional-body guidance before relying on this general explanation. A new consultation, executive measure, or enacted provision could alter the analysis. The safest operational standard remains conservative: use AI to organise and accelerate work, but require qualified humans to validate law and evidence, protect confidential information, and explain material decisions.

The Defensible Operating Standard

Indian legal AI is not defined by a blanket prohibition or a single approval system. It is defined by the interaction between data-protection law, procedural duties, professional responsibility, vendor contracts, and human judgement. That answer is less dramatic than announcing that AI has transformed Indian legal practice, but it is more useful for eDiscovery and legal document drafting. The technology may reduce repetitive search, improve consistency, and make large collections more navigable, yet it cannot guarantee truth, privilege, or legal compliance.

For a law firm, company, in-house department, or global capability centre, the best approach is a documented policy plus matter-specific controls. The policy should identify approved use cases, prohibited uploads, escalation conditions, review responsibilities, and records to retain. Each deployment should include validation, version tracking, access restrictions, and a clear escalation route. Teams should compare the total cost with a traditional research or review process and test whether the measured benefit survives human verification. If it does not, the automation has not delivered value.

The legal team should ultimately be able to answer five plain questions: what tool was used, what data did it process, how was its output checked, who made the final decision, and what records prove those facts. A system that cannot answer those questions is not ready for high-stakes Indian legal work. A system that can answer them remains subject to changing law, vendor changes, and professional oversight. That is the practical meaning of an Indian legal AI policy in 2026: not a promise of certainty, but a repeatable way to use uncertainty with discipline.