Every enterprise in India is now an AI user. Most are signing AI contracts that were written by technology vendors, for technology vendors, allocating all meaningful risk to the customer. The business that deploys AI without understanding what it has agreed to is not adopting technology — it is accepting unlimited liability for outcomes it does not control.
India's approach to AI regulation is taking shape across multiple fronts simultaneously. The Ministry of Electronics and Information Technology has issued advisories on AI deployment. The Digital Personal Data Protection Act 2023 creates obligations for AI systems that process personal data — including automated decision-making systems that make decisions with legal or significant effects on individuals. The SEBI has issued guidance on the use of AI in financial services. The RBI is developing an AI framework for regulated financial entities. The IRDAI is examining AI in insurance. Each of these regulatory streams has its own timeline and its own compliance obligations — and they interact with each other in ways that most AI legal advisers have not yet mapped.
Goldschmidt Pallonji's AI and Technology Law practice is built on a single premise: the legal issues raised by AI are not fundamentally new legal issues. They are existing legal frameworks — contract law, tort law, IP law, data protection law, consumer protection law, sector-specific regulation — applied to a new and challenging technology context. Understanding which existing legal framework applies to which AI problem, and how to structure AI deployments, contracts, and governance systems to manage the resulting legal risk, is the core of effective AI legal advice.
GP advises across the full AI legal spectrum: AI developers building products and needing to understand their legal exposure; enterprises deploying AI tools and needing contracts that protect them; financial services companies building AI-powered credit, fraud, and customer service systems under RBI and SEBI oversight; healthcare technology companies using AI in diagnostics and treatment recommendation under MCI and CDSCO frameworks; and platforms managing AI-generated content and the liability that attaches to it. For cross-border AI — products built in Australia, Singapore, or the UK deploying into India, or Indian AI products deploying overseas — GP provides the bilateral regulatory analysis that the jurisdiction overlap requires.
AI contracts, governance frameworks, DPDP compliance, training data licensing, sector-specific AI regulation, and cross-border AI deployment — the complete legal capability that AI-driven businesses require.
Review and negotiation of AI vendor contracts for enterprise customers — identifying the risk allocations that shift liability to the customer, negotiating output warranties, accuracy and reliability representations, indemnity provisions for third-party IP claims arising from AI-generated content, data security obligations, and audit rights. Drafting AI services agreements for AI product companies — the terms of service, acceptable use policy, and API terms that govern customer use of the AI system and allocate liability for misuse and harmful outputs. Model-as-a-service agreements, fine-tuning agreements, and custom model development contracts with appropriate IP ownership provisions.
Learn More →DPDP Act compliance for AI systems that process personal data — consent architecture for AI data collection and processing, automated decision-making frameworks where AI makes decisions with significant effects on individuals, data minimisation requirements for AI training datasets, purpose limitation analysis for AI systems trained on data collected for other purposes, and the rights of Data Principals (correction, erasure, and objection to automated processing) as they apply to AI-driven decisions. Significant Data Fiduciary obligations for large AI platforms — the Data Protection Impact Assessment requirements and the DPDP Board complaint management framework.
Learn More →The copyright status of data used to train AI models — the extent to which scraping publicly available content for AI training is permissible under Indian copyright law, the fair dealing provisions that may apply, and the licences that are required for training data that is not clearly in the public domain. Data licensing agreements for AI training datasets — acquisition of licensed training data, the terms that limit downstream use of models trained on the data, and the indemnity framework for third-party IP claims. For generative AI companies — the liability framework for AI-generated output that reproduces or closely resembles copyrighted material, and the contractual and technical risk management measures available.
Learn More →Legal framework for AI deployment in financial services — the RBI's guidance on algorithmic lending, explainability requirements for AI-based credit decisions, the SEBI framework for algorithm-based trading and AI in investment advisory, IRDAI requirements for AI in insurance underwriting and claims, and the account aggregator framework as it intersects with AI-driven financial advice. Fair lending obligations — ensuring AI credit models do not produce outcomes that constitute unlawful discrimination against protected categories. Model risk management frameworks for regulated financial entities deploying AI in customer-facing or risk management applications.
Learn More →Enterprise AI governance frameworks — the policies, procedures, and oversight structures that a responsible AI-deploying organisation should have in place. AI use policy for employees — governing acceptable use of generative AI tools, confidential information handling, and output verification requirements. AI procurement policy — the due diligence framework for evaluating AI vendors before deployment. Board-level AI oversight — the governance questions that boards of directors should be asking about their organisation's AI deployment, drawn from the OECD AI Principles, the NITI Aayog Responsible AI framework, and the emerging sectoral guidance from Indian regulators. AI risk register and incident response protocol for AI failures, hallucinations, and harmful outputs.
Learn More →The EU AI Act's extraterritorial reach — Indian AI companies whose products are deployed in the EU, or whose AI systems are used by EU-based customers, may be subject to the EU AI Act's obligations regardless of where the developer is located. High-risk AI system obligations, conformity assessment requirements, and prohibited AI practices under the EU AI Act, as applied to Indian AI developers. Comparison with the Singapore Model AI Governance Framework and the UK's pro-innovation approach — advising Indian AI companies on how to build compliance frameworks that address multiple overlapping regulatory regimes simultaneously rather than sequentially. The ASEAN AI Governance Framework and its implications for Indian AI products in Southeast Asia.
Learn More →India's AI regulatory framework is still being assembled. The AI-specific legislation that will govern liability, transparency, and safety requirements for AI systems in India has not yet been enacted. But the direction of travel is clear — from MeitY's AI advisories, the DPDP Act's automated decision-making implications, and the sector-specific guidance from RBI and SEBI. AI developers who build their legal infrastructure now — sound terms of service, DPDP-compliant data pipelines, appropriate IP ownership structures, and training data licensing arrangements — will have a competitive advantage over competitors who wait for the rules to be finalised. The company that builds its AI governance framework before the regulator requires it is the company that shapes what the regulator considers acceptable.
AI in medical diagnosis, treatment recommendation, and drug discovery operates in a regulatory environment that combines CDSCO's medical device regulations (AI-based diagnostic tools are classified as software as a medical device), the Medical Council of India's professional standards for medical practice, the Consumer Protection Act's product liability provisions, and the DPDP Act's requirements for health data processing. A wrong AI diagnostic recommendation is not merely a contract breach — it is potentially a criminal negligence matter, a product liability claim, and a CDSCO regulatory enforcement action simultaneously. GP advises HealthTech companies deploying AI in clinical settings on the complete liability landscape and the risk management framework that operating in it requires.
A 2023 survey found that a significant proportion of employees in Indian organisations use AI tools — including generative AI chatbots — for work tasks without employer knowledge or policy guidance. The data they are sharing with these tools includes confidential client information, unpublished financial results, proprietary business processes, and personal data of customers and employees. Most AI tools' terms of service permit the AI provider to use submitted data to improve their models — meaning that confidential information shared with an AI tool may become training data for that tool's future outputs. An AI use policy — governing which tools employees may use, what categories of information may be shared, and what output verification is required — is the first step in managing enterprise AI risk. GP drafts AI use policies and governance frameworks for enterprises that need to get ahead of this risk before an incident makes it urgent.
The most useful AI legal advice does not begin with "AI law" as a separate subject. It begins with the existing legal frameworks — contract law, IP law, data protection law, sector regulation, consumer protection — and asks how they apply to the specific AI deployment in question. GP's AI and Technology Law practice is built on deep foundations in all of these underlying areas — the DPDP Act implementation comes from our dedicated data protection practice, the training data copyright analysis comes from our IP practice, the AI procurement contracts are reviewed by lawyers who negotiate technology contracts as their primary work, and the sector-specific AI regulation draws on our sector regulatory practices. The AI law advice is integrated, not isolated.
Indian AI companies operate in a global regulatory environment. Their products may be used in the EU (triggering EU AI Act obligations), in Australia (triggering Australian Privacy Act and AI Ethics Framework obligations), in Singapore (triggering the Model AI Governance Framework), and in India (triggering the DPDP Act and sectoral regulators). A compliance framework designed only for India will not address the overseas obligations. GP's corridor expertise — Australia, Singapore, the UAE, the UK — means that cross-border AI compliance is assessed from practitioners who understand each jurisdiction's domestic framework, not from a research note about foreign regulations.
GP participates in MeitY consultations, SEBI AI working groups, and RBI FinTech advisory frameworks — not because regulatory engagement is a marketing activity, but because the clients who benefit most from AI law advice are those whose interests are reflected in the regulatory framework being built. GP advises AI companies and enterprise AI users on how to engage constructively with the regulatory process — providing technically informed responses to consultation papers, building relationships with the regulatory bodies that will enforce the framework, and structuring their operations in ways that anticipate where the regulation is heading.
Complete confidentiality maintained.
Advised a large NBFC on the legal review of a flagship AI-powered credit decisioning system before customer-facing deployment. GP's contract review identified that the AI vendor's terms: (1) disclaimed all liability for incorrect credit decisions made by the system; (2) required the NBFC to indemnify the vendor for any third-party claims arising from use of the system; and (3) permitted the vendor to modify the model's behaviour with 30 days' notice, potentially changing credit outcomes mid-deployment. GP renegotiated all three provisions — obtaining a capped vendor liability for model accuracy failures, removing the reverse indemnity, and securing a change-freeze period of 90 days with prior notice requirements. The NBFC deployed the system with a commercially defensible liability position and RBI-consistent model governance documentation.
Advised an Indian generative AI company planning to expand its enterprise product to EU customers on its obligations under the EU AI Act as a provider of a general-purpose AI model. GP's assessment identified the company's obligations under Article 53 (technical documentation, copyright compliance policy, training data summary), the transparency notice requirements for downstream deployers, and the additional obligations that would arise if the model were classified as a GPAI model with systemic risk above the 10^25 FLOPs training threshold. GP established a compliant documentation framework and copyright policy, advised on the training data inventory and copyright compliance assessment, and produced the technical documentation required for the EU AI Act register. The company onboarded its first EU enterprise customer within the compliance window.
Advised a HealthTech company on the complete legal and regulatory framework for its AI-powered medical imaging diagnostic tool, which analyses radiology scans and provides diagnostic suggestions to clinicians. GP assessed the tool's classification as a Software as a Medical Device (SaMD) under CDSCO's medical device regulations, the clinical evidence requirements for regulatory approval, the liability framework for diagnostic errors (distinguishing tool liability from clinician liability), the DPDP Act obligations for processing sensitive health data, the consent architecture required for patient data used in model training and improvement, and the terms of service for hospital and clinic customers that appropriately allocate liability for clinical decisions made with AI assistance. The governance framework positioned the company for CDSCO approval and enabled it to contract with hospital chains that had previously declined to engage with AI diagnostic tools without a compliant legal framework.
The practice is led by a technology lawyer with specific expertise in AI contracts, data protection, and digital platform regulation — working alongside GP's DPDP Act specialists, IP team for training data and copyright questions, and sector-specific regulatory lawyers for AI in financial services, healthcare, and other regulated sectors. For cross-border AI compliance, the practice draws on GP's corridor expertise for the EU, Australian, Singaporean, and UK AI regulatory frameworks.
The practice maintains active engagement with MeitY's AI consultation processes, NASSCOM's AI ethics working groups, and SEBI's FinTech advisory committee — ensuring that GP's AI law advice reflects the current direction of Indian AI regulation, not only its current state.
The twelve AI vendor contract provisions that most enterprises sign without reading — and what each one means for the business's liability exposure when the AI makes a mistake. A practical guide for legal, procurement, and technology teams reviewing AI vendor agreements.
Read Guide →The EU AI Act's obligations for general-purpose AI model providers and high-risk AI system developers — effective dates, compliance requirements, and the specific steps Indian AI companies need to take before the enforcement window opens for their product category.
Read Alert →Whether you need an AI vendor contract reviewed, a DPDP compliance framework for your AI system, an EU AI Act assessment, a sector-specific AI governance framework, or an AI use policy for your employees — our team responds within 24 hours.
By submitting you agree to our Privacy Policy. All communications are strictly confidential.