Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Regulatory Framework on AI, Cyber Security and Cyberspace

Overview of AI Regulation and Cyberspace Governance in India

Updated 11 October 2026 · Fact-checked

India has no single AI statute. AI, cyberspace and cyber security are governed by the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, rules, agency directions and policy documents. You answer by naming the provision, applying it to the facts, and concluding who is liable or empowered.

Understand Overview of AI Regulation and Cyberspace Governance in India

Start with a simple point: India has no dedicated law on artificial intelligence in the material supplied here. An AI system is regulated through the laws that already govern computers, data, networks and the people who run them. Your job in the exam is to find the right existing provision for the facts.

The base law for cyberspace is the Information Technology Act, 2000. It extends to the whole of India and, save as otherwise provided, also applies to any offence or contravention under it committed outside India by any person (section 1(2)). It does not apply to documents or transactions specified in the First Schedule, which the Central Government can amend by notification (section 1(4)).

The Act covers three broad areas that matter for AI and cyber security. First, institutions: the Indian Computer Emergency Response Team (CERT-In) is the national agency for incident response under section 70B. Second, state powers: section 69B lets the Central Government authorise a government agency to monitor and collect traffic data to enhance cyber security. Third, offences: section 66F punishes cyber terrorism.

The second layer is data protection. The Digital Personal Data Protection Act, 2023 (DPDP Act) deals with personal data processed by Data Fiduciaries. It gives Data Principals rights, for example the right under section 11 to get a summary of the personal data being processed. It also sets up a Board. Section 44 of the DPDP Act omits section 43A of the IT Act, so the old compensation provision for failure to protect data is removed once that amendment operates. Check the commencement position in your study material before you assume it is in force.

The third layer is policy and soft law: advisories, guidelines and national strategies. They guide conduct but are not statutes. A good answer separates binding law (Acts, rules, directions with penalties) from policy (guidance without statutory force).

Key rules to remember

Territorial reach of the IT Act
Applies to whole of India + offences or contraventions committed outside India by any person (save as otherwise provided)
Section 1(2). Exceptions: documents or transactions in the First Schedule (section 1(4)).
CERT-In functions
Collect, analyse and disseminate cyber incident information; forecast and alerts; emergency measures; coordinate response; issue guidelines, advisories, vulnerability notes and white papers; other prescribed functions
Section 70B(4)(a) to (f).
CERT-In powers and penalty
May call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person. Default: imprisonment up to 1 year or fine up to ₹1 crore or both
Section 70B(6) and (7). Court takes cognizance only on a complaint by an officer authorised by CERT-In (70B(8)).
Section 69B traffic data monitoring
Central Government notifies an agency to monitor and collect traffic data; intermediary or person in charge must give technical assistance; intermediary's intentional or knowing default: up to 1 year imprisonment or fine up to ₹1 crore or both
Section 69B(1), (2), (4). Procedure and safeguards are as prescribed.
Cyber terrorism
Section 66F: intent to threaten unity, integrity, security or sovereignty of India or strike terror + prohibited act + specified consequence; punishment up to imprisonment for life
Also covers unauthorised access to information restricted for State security or foreign relations (66F(1)(B)). Conspiracy is punished equally.
Section 43A status
Section 43A (compensation for failure to protect data) omitted by section 44(2)(a) of the DPDP Act, 2023
Contrast old and new regimes when asked.

How to solve Overview of AI Regulation and Cyberspace Governance in India questions

Use this sequence for any question on AI regulation or cyberspace governance. It mirrors the provision, analysis, conclusion pattern of the written paper.

  1. 1Read the facts and list the actors: company, AI developer, intermediary, data centre, government agency, individual.
  2. 2Identify the issue type: incident response, state monitoring, offence, data protection, or policy.
  3. 3Name the governing law first: IT Act, 2000 or DPDP Act, 2023. Say plainly if no AI-specific statute applies.
  4. 4State the exact provision and section number only where you are sure, using its conditions in plain words.
  5. 5Apply each condition to the facts one by one, such as intent, authorisation, negligence or default.
  6. 6State the consequence: penalty, direction, right or compensation, with the correct limit.
  7. 7Add practical compliance points: reporting incidents, giving technical assistance, security practices, data principal requests.
  8. 8Conclude in one clear sentence that answers the question asked.

Quickest way: Actor, power, consequence

When to use it: Use it for short-note and 5-mark questions where time is tight.

  1. Write the actor (CERT-In, notified agency, intermediary, Data Fiduciary).
  2. Write the power or duty in one line with the section.
  3. Write the consequence of default or breach.
  4. Close with one line on whether the source is binding law or policy.

Common mistakes in Overview of AI Regulation and Cyberspace Governance in India

  • Saying India has a comprehensive AI Act.

    Students assume AI has a dedicated law like some foreign regimes.

    Fix: State that AI is governed through existing laws such as the IT Act and DPDP Act plus policy guidance.

  • Treating section 43A as still the main data protection remedy.

    Older notes still teach it.

    Fix: Mention that DPDP Act section 44(2)(a) omits it, and explain the shift to the DPDP framework.

  • Mixing up section 69B and section 70B.

    Both deal with cyber security and agencies and carry a similar penalty.

    Fix: 69B is traffic data monitoring by a notified agency. 70B is CERT-In as national incident response agency.

  • Giving the old penalty for section 69B or 70B.

    Pre-2023 books show different figures.

    Fix: Use up to one year and fine up to ₹1 crore, as substituted by Act 18 of 2023 w.e.f. 30-11-2023.

  • Claiming the IT Act applies only within India.

    Students forget section 1(2).

    Fix: State that it also applies to offences or contraventions committed outside India by any person, save as otherwise provided.

  • Treating policy documents as enforceable law.

    Advisories sound authoritative.

    Fix: Label them guidance unless an Act or rule gives them binding force. Note CERT-In directions under 70B(6) are enforceable.

Worked examples

Example 1

A cloud data centre in Pune refuses to give CERT-In information it called for after a ransomware incident. Advise on the legal position.

Show the solution
  1. Provision: section 70B(4) makes CERT-In the national agency for incident response, including collecting information on cyber incidents.
  2. Section 70B(6) lets CERT-In call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person.
  3. Analysis: a data centre is expressly named, so the call for information binds it.
  4. Section 70B(7): failure to provide information or comply is punishable with imprisonment up to one year or fine up to ₹1 crore or both.
  5. Procedure: under section 70B(8), a court takes cognizance only on a complaint by an officer authorised by CERT-In.
  6. Practical point: the data centre should comply promptly and record its response.

Answer: The refusal is an offence under section 70B(7), punishable with up to one year's imprisonment or fine up to ₹1 crore or both, and prosecution needs a complaint by a CERT-In authorised officer.

Example 2

An analytics startup in Bengaluru uses an AI tool on customer data. A customer asks what personal data is processed and with whom it is shared. Which law gives this right, and what must the startup provide?

Show the solution
  1. The startup is a Data Fiduciary and the customer is a Data Principal under the DPDP Act, 2023.
  2. Section 11(1) gives a Data Principal who previously gave consent the right to obtain information on request, in the prescribed manner.
  3. The startup must give a summary of personal data processed and the processing activities.
  4. It must give the identities of all other Data Fiduciaries and Data Processors with whom the data was shared, with a description of the data shared.
  5. It must give any other prescribed information.
  6. Exception: under section 11(2), clauses (b) and (c) do not apply to sharing with another Data Fiduciary authorised by law that made a written request for prevention, detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.
  7. Note that using AI does not change the duty. The Act applies to the personal data processing.

Answer: Section 11 of the DPDP Act, 2023 gives the right. The startup must provide a summary of data and processing, identities of those with whom data was shared, and other prescribed information, except for sharing covered by the section 11(2) law-enforcement exception.

Exam tips

  • Open every answer by stating that India regulates AI through existing laws, then name them.
  • Learn the section 69B and 70B penalty (up to one year, fine up to ₹1 crore) and the 2023 amendment date.
  • Keep a one-line contrast ready: section 43A omitted by DPDP Act section 44(2)(a).
  • Use the format provision, application to facts, conclusion, and add one practical compliance step.
  • For policy-based questions, say whether the instrument is binding or advisory.

Practice questions from Regulatory Framework on AI, Cyber Security and Cyberspace

Overview of AI Regulation and Cyberspace Governance in India: frequently asked questions

Does India have a specific law on artificial intelligence?

Based on the provisions covered here, there is no standalone AI statute. AI use is governed through the IT Act, 2000, the DPDP Act, 2023 and policy guidance. Check your study material for any later developments.

What is the role of CERT-In under the IT Act?

Under section 70B, CERT-In is the national agency for cyber incident response. It collects and analyses incident information, issues alerts and advisories, coordinates response, and can call for information and give directions.

What happens to section 43A after the DPDP Act?

Section 44(2)(a) of the DPDP Act, 2023 omits section 43A of the IT Act. Data protection duties now sit mainly in the DPDP Act once its provisions are in force.

Does the IT Act apply to offences committed outside India?

Yes, save as otherwise provided. Section 1(2) says it applies also to any offence or contravention under the Act committed outside India by any person.