India's Premier Full-Service Law Firm — Precision. Pedigree. Global Reach.
Goldschmidt Pallonji& Associates
Get in Touch
Home / Practices / AI & Technology Law
★★★ Differentiator Practice

AI & Technology Law

Every enterprise in India is now an AI user. Most are signing AI contracts that were written by technology vendors, for technology vendors, allocating all meaningful risk to the customer. The business that deploys AI without understanding what it has agreed to is not adopting technology — it is accepting unlimited liability for outcomes it does not control.

AI Contracts · GenAI Liability · Training Data · DPDP · Platform Regulation · AI Governance
AI Developers · Enterprise AI Deployments · FinTech · HealthTech · Platforms · Regulators
The Practice

Artificial intelligence has moved faster than the law. The contracts governing AI deployments were written in a legal vacuum — and most of them show it. India's AI regulatory framework is being built now, and the businesses that are not building their AI governance structures in anticipation of that framework will be rebuilding their entire AI stack when the rules arrive.

India's approach to AI regulation is taking shape across multiple fronts simultaneously. The Ministry of Electronics and Information Technology has issued advisories on AI deployment. The Digital Personal Data Protection Act 2023 creates obligations for AI systems that process personal data — including automated decision-making systems that make decisions with legal or significant effects on individuals. The SEBI has issued guidance on the use of AI in financial services. The RBI is developing an AI framework for regulated financial entities. The IRDAI is examining AI in insurance. Each of these regulatory streams has its own timeline and its own compliance obligations — and they interact with each other in ways that most AI legal advisers have not yet mapped.

Goldschmidt Pallonji's AI and Technology Law practice is built on a single premise: the legal issues raised by AI are not fundamentally new legal issues. They are existing legal frameworks — contract law, tort law, IP law, data protection law, consumer protection law, sector-specific regulation — applied to a new and challenging technology context. Understanding which existing legal framework applies to which AI problem, and how to structure AI deployments, contracts, and governance systems to manage the resulting legal risk, is the core of effective AI legal advice.

GP advises across the full AI legal spectrum: AI developers building products and needing to understand their legal exposure; enterprises deploying AI tools and needing contracts that protect them; financial services companies building AI-powered credit, fraud, and customer service systems under RBI and SEBI oversight; healthcare technology companies using AI in diagnostics and treatment recommendation under MCI and CDSCO frameworks; and platforms managing AI-generated content and the liability that attaches to it. For cross-border AI — products built in Australia, Singapore, or the UK deploying into India, or Indian AI products deploying overseas — GP provides the bilateral regulatory analysis that the jurisdiction overlap requires.

Key Frameworks & Legislation
DPDP Act 2023 IT Act 2000 / IT Rules MeitY AI Advisories SEBI AI Framework RBI AI Guidelines Consumer Protection Act Copyright Act — AI Output
Practice at a Glance
Tier
★★★ Differentiator Practice
Client Types
AI developers · Enterprise AI users · FinTech / RegTech · HealthTech · EdTech · Platforms · Overseas AI companies entering India
Core Services
AI contracts · GenAI liability · Training data licensing · AI governance frameworks · DPDP compliance for AI · Sector AI regulation · Platform liability · AI IP
Sector Focus
Financial services (RBI / SEBI) · Healthcare (MCI / CDSCO) · Insurance (IRDAI) · Education · E-commerce · Content platforms
Cross-Border
EU AI Act impact on Indian companies · AUS AI framework · SGP Model AI Governance · UK AI regulation
Speak to Our AI & Tech Law Team
What We Do

Our AI & Technology Law Services

AI contracts, governance frameworks, DPDP compliance, training data licensing, sector-specific AI regulation, and cross-border AI deployment — the complete legal capability that AI-driven businesses require.

🤖

AI Contracts & Vendor Agreements

Review and negotiation of AI vendor contracts for enterprise customers — identifying the risk allocations that shift liability to the customer, negotiating output warranties, accuracy and reliability representations, indemnity provisions for third-party IP claims arising from AI-generated content, data security obligations, and audit rights. Drafting AI services agreements for AI product companies — the terms of service, acceptable use policy, and API terms that govern customer use of the AI system and allocate liability for misuse and harmful outputs. Model-as-a-service agreements, fine-tuning agreements, and custom model development contracts with appropriate IP ownership provisions.

Learn More →
🔒

DPDP Act — AI System Compliance

DPDP Act compliance for AI systems that process personal data — consent architecture for AI data collection and processing, automated decision-making frameworks where AI makes decisions with significant effects on individuals, data minimisation requirements for AI training datasets, purpose limitation analysis for AI systems trained on data collected for other purposes, and the rights of Data Principals (correction, erasure, and objection to automated processing) as they apply to AI-driven decisions. Significant Data Fiduciary obligations for large AI platforms — the Data Protection Impact Assessment requirements and the DPDP Board complaint management framework.

Learn More →
🎬

Training Data Licensing & Copyright

The copyright status of data used to train AI models — the extent to which scraping publicly available content for AI training is permissible under Indian copyright law, the fair dealing provisions that may apply, and the licences that are required for training data that is not clearly in the public domain. Data licensing agreements for AI training datasets — acquisition of licensed training data, the terms that limit downstream use of models trained on the data, and the indemnity framework for third-party IP claims. For generative AI companies — the liability framework for AI-generated output that reproduces or closely resembles copyrighted material, and the contractual and technical risk management measures available.

Learn More →
🏥

AI in Financial Services — RBI & SEBI

Legal framework for AI deployment in financial services — the RBI's guidance on algorithmic lending, explainability requirements for AI-based credit decisions, the SEBI framework for algorithm-based trading and AI in investment advisory, IRDAI requirements for AI in insurance underwriting and claims, and the account aggregator framework as it intersects with AI-driven financial advice. Fair lending obligations — ensuring AI credit models do not produce outcomes that constitute unlawful discrimination against protected categories. Model risk management frameworks for regulated financial entities deploying AI in customer-facing or risk management applications.

Learn More →
🏢

AI Governance Frameworks & Board-Level AI Policy

Enterprise AI governance frameworks — the policies, procedures, and oversight structures that a responsible AI-deploying organisation should have in place. AI use policy for employees — governing acceptable use of generative AI tools, confidential information handling, and output verification requirements. AI procurement policy — the due diligence framework for evaluating AI vendors before deployment. Board-level AI oversight — the governance questions that boards of directors should be asking about their organisation's AI deployment, drawn from the OECD AI Principles, the NITI Aayog Responsible AI framework, and the emerging sectoral guidance from Indian regulators. AI risk register and incident response protocol for AI failures, hallucinations, and harmful outputs.

Learn More →
🌎

Cross-Border AI Regulation — EU AI Act & Global Compliance

The EU AI Act's extraterritorial reach — Indian AI companies whose products are deployed in the EU, or whose AI systems are used by EU-based customers, may be subject to the EU AI Act's obligations regardless of where the developer is located. High-risk AI system obligations, conformity assessment requirements, and prohibited AI practices under the EU AI Act, as applied to Indian AI developers. Comparison with the Singapore Model AI Governance Framework and the UK's pro-innovation approach — advising Indian AI companies on how to build compliance frameworks that address multiple overlapping regulatory regimes simultaneously rather than sequentially. The ASEAN AI Governance Framework and its implications for Indian AI products in Southeast Asia.

Learn More →
Key Highlights

Four AI legal risks that Indian enterprises are currently carrying — most without realising it.

The AI vendor contract that makes you liable for the AI's mistakes
Most enterprise AI contracts — the terms of service for ChatGPT, Gemini, Copilot, and their enterprise API equivalents — contain provisions that disclaim the vendor's liability for the accuracy or reliability of AI outputs, prohibit the customer from relying on AI outputs without independent verification, and require the customer to indemnify the vendor for claims arising from the customer's use of the AI system. A company that deploys AI in a customer-facing application under these terms, and whose customer suffers harm from an incorrect AI output, has contractually accepted the liability that the vendor disclaimed. GP reviews and renegotiates enterprise AI vendor contracts to shift these risk allocations to a commercially defensible position before the contract is signed.
AI and the DPDP Act — automated decisions about people require a legal basis
The Digital Personal Data Protection Act 2023 applies to AI systems that process personal data — which includes virtually every AI system that makes decisions about individual customers, users, or employees. The consent architecture for data collection and processing, the purpose limitation principle (data collected for one purpose cannot simply be reused to train an AI model without reassessment), and the rights of data principals to seek human review of automated decisions all require specific implementation steps for AI-deploying businesses. The companies that begin building DPDP-compliant AI infrastructure now will not be rebuilding their data pipelines when the enforcement rules are notified.
Who owns the output — and who is liable for it
Under the Indian Copyright Act, copyright vests in the author of a work — and AI systems are not legal persons capable of authorship. AI-generated output is therefore either owned by the human who directed the AI (the prompter) or by no one (public domain), depending on the degree of human creative contribution. For a business that produces AI-generated content commercially — marketing copy, legal documents, financial reports, medical summaries — the copyright ownership question and the liability for inaccurate or harmful content are both unresolved in Indian law. GP advises on structuring the human creative contribution in AI-assisted workflows to preserve copyright ownership, and on the liability framework for AI-generated outputs that cause harm.
The EU AI Act reaches Indian companies — even if they never set foot in Europe
The EU AI Act applies to any provider of an AI system that is placed on the EU market or used in the EU — regardless of where the provider is established. An Indian AI company whose product is used by a single EU customer may be subject to the EU AI Act's obligations: conformity assessment, technical documentation, transparency notices, and for high-risk AI systems, registration in the EU AI database. The penalties for non-compliance are severe — up to 3% of global annual turnover for violations of transparency requirements and up to 6% for prohibited AI practices. Indian AI companies that export to or have users in the EU need an EU AI Act compliance assessment before their next EU customer onboards.
For AI Developers — Building the Legal Foundation Before the Regulatory Hammer Falls

India's AI regulatory framework is still being assembled. The AI-specific legislation that will govern liability, transparency, and safety requirements for AI systems in India has not yet been enacted. But the direction of travel is clear — from MeitY's AI advisories, the DPDP Act's automated decision-making implications, and the sector-specific guidance from RBI and SEBI. AI developers who build their legal infrastructure now — sound terms of service, DPDP-compliant data pipelines, appropriate IP ownership structures, and training data licensing arrangements — will have a competitive advantage over competitors who wait for the rules to be finalised. The company that builds its AI governance framework before the regulator requires it is the company that shapes what the regulator considers acceptable.

AI in Healthcare — Where the Stakes of a Wrong Output Are Highest

AI in medical diagnosis, treatment recommendation, and drug discovery operates in a regulatory environment that combines CDSCO's medical device regulations (AI-based diagnostic tools are classified as software as a medical device), the Medical Council of India's professional standards for medical practice, the Consumer Protection Act's product liability provisions, and the DPDP Act's requirements for health data processing. A wrong AI diagnostic recommendation is not merely a contract breach — it is potentially a criminal negligence matter, a product liability claim, and a CDSCO regulatory enforcement action simultaneously. GP advises HealthTech companies deploying AI in clinical settings on the complete liability landscape and the risk management framework that operating in it requires.

Your Employees Are Already Using AI. Do You Know What They Are Sharing?

A 2023 survey found that a significant proportion of employees in Indian organisations use AI tools — including generative AI chatbots — for work tasks without employer knowledge or policy guidance. The data they are sharing with these tools includes confidential client information, unpublished financial results, proprietary business processes, and personal data of customers and employees. Most AI tools' terms of service permit the AI provider to use submitted data to improve their models — meaning that confidential information shared with an AI tool may become training data for that tool's future outputs. An AI use policy — governing which tools employees may use, what categories of information may be shared, and what output verification is required — is the first step in managing enterprise AI risk. GP drafts AI use policies and governance frameworks for enterprises that need to get ahead of this risk before an incident makes it urgent.

The GP Difference

Why GP for AI & Technology Law

1

AI law as existing law — not a separate silo

The most useful AI legal advice does not begin with "AI law" as a separate subject. It begins with the existing legal frameworks — contract law, IP law, data protection law, sector regulation, consumer protection — and asks how they apply to the specific AI deployment in question. GP's AI and Technology Law practice is built on deep foundations in all of these underlying areas — the DPDP Act implementation comes from our dedicated data protection practice, the training data copyright analysis comes from our IP practice, the AI procurement contracts are reviewed by lawyers who negotiate technology contracts as their primary work, and the sector-specific AI regulation draws on our sector regulatory practices. The AI law advice is integrated, not isolated.

2

India + global regulatory landscape — one complete picture

Indian AI companies operate in a global regulatory environment. Their products may be used in the EU (triggering EU AI Act obligations), in Australia (triggering Australian Privacy Act and AI Ethics Framework obligations), in Singapore (triggering the Model AI Governance Framework), and in India (triggering the DPDP Act and sectoral regulators). A compliance framework designed only for India will not address the overseas obligations. GP's corridor expertise — Australia, Singapore, the UAE, the UK — means that cross-border AI compliance is assessed from practitioners who understand each jurisdiction's domestic framework, not from a research note about foreign regulations.

3

Regulatory engagement — shaping the framework, not just reacting to it

GP participates in MeitY consultations, SEBI AI working groups, and RBI FinTech advisory frameworks — not because regulatory engagement is a marketing activity, but because the clients who benefit most from AI law advice are those whose interests are reflected in the regulatory framework being built. GP advises AI companies and enterprise AI users on how to engage constructively with the regulatory process — providing technically informed responses to consultation papers, building relationships with the regulatory bodies that will enforce the framework, and structuring their operations in ways that anticipate where the regulation is heading.

Representative Matters

The type of work we do.

Complete confidentiality maintained.

India Enterprise AI — Contract Renegotiation

Large NBFC — AI vendor contract renegotiated, unlimited liability position corrected before customer deployment

Advised a large NBFC on the legal review of a flagship AI-powered credit decisioning system before customer-facing deployment. GP's contract review identified that the AI vendor's terms: (1) disclaimed all liability for incorrect credit decisions made by the system; (2) required the NBFC to indemnify the vendor for any third-party claims arising from use of the system; and (3) permitted the vendor to modify the model's behaviour with 30 days' notice, potentially changing credit outcomes mid-deployment. GP renegotiated all three provisions — obtaining a capped vendor liability for model accuracy failures, removing the reverse indemnity, and securing a change-freeze period of 90 days with prior notice requirements. The NBFC deployed the system with a commercially defensible liability position and RBI-consistent model governance documentation.

India + EU GenAI Product — EU AI Act Compliance

Indian GenAI startup — EU AI Act general-purpose AI model obligations assessed, compliance framework established ahead of EU expansion

Advised an Indian generative AI company planning to expand its enterprise product to EU customers on its obligations under the EU AI Act as a provider of a general-purpose AI model. GP's assessment identified the company's obligations under Article 53 (technical documentation, copyright compliance policy, training data summary), the transparency notice requirements for downstream deployers, and the additional obligations that would arise if the model were classified as a GPAI model with systemic risk above the 10^25 FLOPs training threshold. GP established a compliant documentation framework and copyright policy, advised on the training data inventory and copyright compliance assessment, and produced the technical documentation required for the EU AI Act register. The company onboarded its first EU enterprise customer within the compliance window.

India HealthTech AI — Governance Framework

HealthTech company — AI diagnostic tool governance framework, CDSCO SaMD classification, DPDP health data compliance

Advised a HealthTech company on the complete legal and regulatory framework for its AI-powered medical imaging diagnostic tool, which analyses radiology scans and provides diagnostic suggestions to clinicians. GP assessed the tool's classification as a Software as a Medical Device (SaMD) under CDSCO's medical device regulations, the clinical evidence requirements for regulatory approval, the liability framework for diagnostic errors (distinguishing tool liability from clinician liability), the DPDP Act obligations for processing sensitive health data, the consent architecture required for patient data used in model training and improvement, and the terms of service for hospital and clinic customers that appropriately allocate liability for clinical decisions made with AI assistance. The governance framework positioned the company for CDSCO approval and enabled it to contract with hospital chains that had previously declined to engage with AI diagnostic tools without a compliant legal framework.

Practice Leadership

Our AI and Technology Law practice is built on the convergence of GP's strongest practices — data protection, IP, contract law, sector regulation — applied to the specific challenges that AI deployment creates.

The practice is led by a technology lawyer with specific expertise in AI contracts, data protection, and digital platform regulation — working alongside GP's DPDP Act specialists, IP team for training data and copyright questions, and sector-specific regulatory lawyers for AI in financial services, healthcare, and other regulated sectors. For cross-border AI compliance, the practice draws on GP's corridor expertise for the EU, Australian, Singaporean, and UK AI regulatory frameworks.

The practice maintains active engagement with MeitY's AI consultation processes, NASSCOM's AI ethics working groups, and SEBI's FinTech advisory committee — ensuring that GP's AI law advice reflects the current direction of Indian AI regulation, not only its current state.

GP
AI & Technology Law Team
Tech Lawyers + DPDP + IP + Sector Regulation
AI Contracts DPDP Act 2023 EU AI Act AI Governance FinTech / HealthTech AI
Regulatory engagement: MeitY AI consultations · SEBI FinTech advisory · NASSCOM AI Ethics · RBI FinTech framework
✉ Write to Our AI & Tech Law Team Meet All Our Partners
Latest Insights
AI Law Guide

The Enterprise AI Contract Review Checklist — 12 Provisions That Put the Risk on You

The twelve AI vendor contract provisions that most enterprises sign without reading — and what each one means for the business's liability exposure when the AI makes a mistake. A practical guide for legal, procurement, and technology teams reviewing AI vendor agreements.

Read Guide →
Regulatory Alert

EU AI Act — What Indian AI Companies With EU Users Must Do Before August 2026

The EU AI Act's obligations for general-purpose AI model providers and high-risk AI system developers — effective dates, compliance requirements, and the specific steps Indian AI companies need to take before the enforcement window opens for their product category.

Read Alert →
AI & Technology Law

Speak to Our AI & Technology Law Team

Whether you need an AI vendor contract reviewed, a DPDP compliance framework for your AI system, an EU AI Act assessment, a sector-specific AI governance framework, or an AI use policy for your employees — our team responds within 24 hours.

AI vendor contract review — identifying and renegotiating the risk allocations that expose you
DPDP Act + EU AI Act — India and global compliance from one team
Sector AI — financial services, healthcare, insurance, platforms
Response within 24 hours — guaranteed
Send Us a Message

By submitting you agree to our Privacy Policy. All communications are strictly confidential.