Artificial Intelligence and Legal Liability in India : Challenges of Accountability, Privacy and Regulation

 

Author :  D. Jeevitha,

Vel Tech Rangarajan Dr. Sagunthala R&D Institute of Science and Technology ( Vel tech school of law)

 

To the Point

Artificial Intelligence (AI) has rapidly transformed modern society and is increasingly being used in healthcare, banking, education, employment, legal research, policing, content creation and public administration. While AI provides efficiency, innovation and convenience, its increasing use also creates significant legal concerns relating to privacy, accountability, discrimination, intellectual property, negligence and liability.

The central legal issue is determining who should be legally responsible when an AI system causes harm. Liability may potentially arise against the developer who creates the system, the organisation that deploys it, the user who operates it, or several parties depending on the circumstances. Traditional legal principles may not always be sufficient because AI systems can make predictions or generate decisions through complex processes that are difficult to understand or trace.

India does not presently have one comprehensive legislation exclusively regulating Artificial Intelligence. Instead, different aspects of AI are governed through existing legal frameworks such as the Information Technology Act, 2000, Digital Personal Data Protection Act, 2023, Consumer Protection Act, 2019, Copyright Act, 1957, and constitutional principles. These laws address issues including data protection, unlawful online activities, consumer rights, intellectual property and fundamental rights. Privacy is one of the most important concerns associated with AI. AI systems often depend upon large quantities of data, including personal information. The Supreme Court’s decision in Justice K.S. Puttaswamy (Retd.) v. Union of India recognised privacy as a fundamental right under Article 21 of the Constitution. Therefore, the collection and processing of personal data through AI must respect constitutional and statutory safeguards. AI can also generate inaccurate or fabricated information. This problem is particularly serious in legal practice because incorrect AI-generated case laws or legal authorities may affect judicial decision-making. In Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd., the Supreme Court addressed the dangers of relying upon AI-generated, non-existent legal authorities and emphasised the importance of human verification and accountability.

Therefore, India’s AI governance must strike a balance between technological innovation and legal responsibility. Effective regulation should promote transparency, human oversight, data protection and accessible remedies while ensuring that AI remains a tool assisting human decision-making rather than replacing human accountability.

Use of Legal Jargon

The rapid development of Artificial Intelligence (AI) has created new legal challenges that require the application of established legal principles to technologically complex situations. AI systems may be developed by one entity, trained using data collected by another, deployed by an organisation and ultimately used by an individual. Therefore, determining legal responsibility requires a clear understanding of relevant legal terminology. Legal liability refers to the legal responsibility of a person or organisation for an act, omission or consequence that results in legally recognised harm. In the context of AI, liability may arise when an AI system causes financial loss, privacy infringement, discrimination or other legally actionable harm.

Due diligence refers to the reasonable care and precautions that an individual or organisation is expected to take to prevent foreseeable harm. AI developers and deployers may need to conduct adequate testing, monitoring and risk assessment before introducing an AI system into practical use.

Data fiduciary is an important concept under India’s data-protection framework. It generally refers to an entity that determines the purpose and means of processing personal data. When AI systems process personal information, the responsibilities of the relevant data fiduciary become particularly important in protecting individuals’ privacy and ensuring lawful data processing.

Algorithmic accountability refers to the responsibility of persons or organisations involved in designing, developing, deploying or operating automated systems for the consequences of those systems. It seeks to ensure that AI does not become a mechanism through which human responsibility is avoided.Natural justice represents the principles of procedural fairness. Where AI-assisted systems influence decisions affecting an individual’s rights or interests, affected persons may require fairness, an opportunity to be heard and an impartial decision-making process.

Proportionality requires that restrictions imposed upon fundamental rights must have a legitimate objective and must not go beyond what is reasonably necessary to achieve that objective. This principle is particularly relevant where AI is used for surveillance, law enforcement or public administration.Negligence means a failure to exercise the standard of reasonable care required in the circumstances. In AI-related disputes, negligence may potentially arise from inadequate testing, careless deployment, failure to correct known errors or insufficient monitoring. Vicarious liability refers to circumstances in which one party may be held legally responsible for the acts or omissions of another, where recognised legal requirements are satisfied. Its application to AI requires careful examination because AI systems do not possess independent legal personality. Human oversight means maintaining meaningful human supervision over important AI-assisted decisions. Human involvement is particularly necessary where AI outputs may significantly affect an individual’s rights, employment, finances or access to essential services.

Explainability refers to the ability to understand how an AI system reached a particular output or recommendation. Transparency and explainability can assist affected persons, regulators and courts in identifying errors and determining responsibility. Thus, AI challenges traditional legal concepts because responsibility may be distributed among developers, model providers, data suppliers, deployers, intermediaries and end users. A suitable legal framework must therefore identify the role and responsibility of each participant while ensuring that technological complexity does not undermine accountability.

The Proof

The legal implications of Artificial Intelligence (AI) in India can be examined through existing constitutional provisions, statutes, judicial decisions and emerging regulatory developments. Although India does not presently have one comprehensive legislation exclusively governing AI, several existing laws provide legal safeguards against different forms of AI-related harm.

The Constitution of India provides the fundamental foundation for regulating AI. Article 14 guarantees equality before the law and equal protection of laws, making it relevant to concerns regarding algorithmic discrimination and biased automated decision-making. Article 19(1)(a) protects freedom of speech and expression, which becomes significant when AI-generated content, automated moderation or deepfakes affect online expression. Article 21 protects life and personal liberty and has been interpreted to include the right to privacy. In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Supreme Court recognised privacy as a fundamental right under Article 21. This decision is highly relevant to AI because many AI systems depend upon the collection, analysis and processing of personal information. Any use of personal data through AI must therefore comply with applicable privacy and data-protection principles.

The Digital Personal Data Protection Act, 2023 provides a statutory framework for processing digital personal data and imposes responsibilities upon data fiduciaries. This becomes particularly important when AI systems process personal information for automated analysis, profiling or personalised services.

The Information Technology Act, 2000 and its associated framework also remain relevant to unlawful online activities and intermediary responsibilities. AI-generated misinformation, impersonation and harmful digital content may raise questions under existing information-technology laws.

The Consumer Protection Act, 2019 may also become relevant where AI-powered products or services result in consumer harm, deficiency in service or product-related liability. Similarly, the Copyright Act, 1957 raises important questions concerning AI-generated works, training data and infringement of existing copyrighted material.

Judicial developments further demonstrate the importance of human responsibility. In Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd., the Supreme Court dealt with the use of AI-generated, non-existent legal authorities and emphasised the importance of verifying AI-generated legal information before relying upon it. These developments establish an important legal principle: AI may assist human decision-making, but it cannot eliminate human accountability. India therefore requires a balanced regulatory approach that promotes innovation while ensuring privacy, transparency, fairness, human oversight and effective legal remedies.

Abstract

Artificial Intelligence (AI) has emerged as one of the most influential technological developments of the modern era. Its increasing application in healthcare, banking, education, employment, legal services, governance and digital communication has created significant opportunities for economic and social development. At the same time, the rapid adoption of AI has generated complex legal questions concerning privacy, accountability, discrimination, negligence, intellectual property and legal liability.

This article examines the challenges associated with determining legal responsibility when an AI system produces harmful, inaccurate or discriminatory outcomes. Unlike traditional technologies, AI systems may involve multiple participants, including developers, data providers, technology companies, deployers and end users. Consequently, identifying the person or organisation responsible for AI-related harm can be legally complex. The article analyses India’s existing legal framework applicable to AI, including the Constitution of India, Information Technology Act, 2000, Digital Personal Data Protection Act, 2023, Consumer Protection Act, 2019 and Copyright Act, 1957. Particular attention is given to the constitutional right to privacy recognised by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India.

 

The article also considers the emerging judicial approach towards AI-generated information, particularly the Supreme Court’s decision in Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd., which highlights the necessity of human verification when AI-generated legal material is used in judicial proceedings. The article argues that India’s approach to AI regulation should maintain a balance between technological innovation and legal accountability. Effective governance should promote transparency, human oversight, responsible data processing, fairness and accessible remedies for individuals affected by AI. Ultimately, AI should remain a tool supporting human decision-making, while legal responsibility must continue to rest with identifiable and accountable human actors or institutions.

Case Laws 

1. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)

The landmark decision in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) is one of the most significant constitutional judgments concerning the right to privacy in India. The case was decided by a nine-judge Constitution Bench of the Supreme Court of India, which unanimously recognised privacy as a fundamental right protected under the Constitution.The Court held that privacy is intrinsically connected with human dignity, individual autonomy, liberty and personal freedom. The judgment clarified that the right to privacy is not merely a common-law or statutory right but forms an essential part of the fundamental rights guaranteed by the Constitution, particularly under Article 21.

The judgment has considerable significance in the context of Artificial Intelligence and data protection. Modern AI systems depend heavily upon data. They may collect, analyse and process personal information for purposes such as facial recognition, automated profiling, behavioural analysis, targeted recommendations, predictive analytics and personalised services. If such information is collected or processed without adequate safeguards, it may interfere with an individual’s reasonable expectation of privacy

For example, an AI-powered facial-recognition system may identify individuals in public places, while an automated profiling system may make predictions about a person’s behaviour or preferences. Such technologies raise questions regarding consent, informational autonomy, surveillance and misuse of personal data.

The Puttaswamy judgment established that restrictions upon privacy cannot be arbitrary. Any interference with fundamental rights must satisfy appropriate constitutional requirements, including legality, legitimate state purpose and proportionality. This principle is particularly important when AI technologies are deployed by government authorities for surveillance, law enforcement or public administration.

The judgment also emphasises the importance of individual control over personal information. AI developers and organisations processing personal data must therefore consider whether data collection is lawful, necessary and proportionate to the purpose for which it is undertaken.

The case demonstrates that technological advancement cannot operate independently of constitutional protections. AI innovation must remain consistent with privacy, dignity and individual autonomy. The principles established in Puttaswamytherefore provide an important constitutional foundation for India’s emerging approach to responsible AI governance.

2. Shreya Singhal v. Union of India (2015)

The Supreme Court’s decision in Shreya Singhal v. Union of India (2015) is another important case for understanding the relationship between technology regulation and fundamental rights. The case primarily concerned Section 66A of the Information Technology Act, 2000, which criminalised certain forms of online communication. The Supreme Court struck down Section 66A as unconstitutional because the provision imposed an unreasonable restriction on the freedom of speech and expression guaranteed under Article 19(1)(a). The Court observed that the restrictions created by the provision were vague and had the potential to suppress legitimate forms of expression.

The judgment is relevant to Artificial Intelligence because generative AI can create and distribute enormous quantities of text, images, audio and video content. AI-generated content may include legitimate artistic, educational, political and journalistic expression. Therefore, excessive or vague regulation of AI-generated content could potentially interfere with constitutionally protected freedom of expression.

At the same time, freedom of speech under Article 19(1)(a) is not absolute. Article 19(2) permits reasonable restrictions on specified grounds, including security of the State, public order, decency or morality, defamation and incitement to an offence.

This creates an important regulatory challenge for AI. Governments and regulators may need to address harmful AI-generated content such as impersonation, misinformation, deepfakes and other unlawful material. However, regulatory measures should be clear, reasonable, proportionate and legally justified, rather than imposing unnecessarily broad restrictions.

The principles developed in Shreya Singhal therefore provide valuable guidance for AI regulation. The State must protect individuals and society from genuine technological harms while simultaneously protecting legitimate digital expression.

The case ultimately demonstrates that technology itself cannot be treated as a justification for restricting fundamental rights. AI regulation must remain consistent with constitutional guarantees and the rule of law. Consequently, India’s future AI framework should seek a careful balance between innovation, freedom of expression, public interest and protection against technological misuse.

Sure. Below are the remaining sections in an academic legal-article style, keeping the total article within your 2,500-word limit. Since the requested word counts together are substantial, the case-law section is kept close to 700 words.

Conclusion

Artificial Intelligence has become an important component of India’s technological and economic development. Its applications provide significant benefits in areas such as healthcare, education, banking, governance, legal research and communication. However, the increasing dependence on AI also creates complex legal challenges involving privacy, discrimination, misinformation, intellectual property, negligence and accountability. India currently addresses these concerns through a combination of constitutional principles and existing legislation rather than one comprehensive AI-specific statute. The Constitution, Information Technology Act, Digital Personal Data Protection Act, Consumer Protection Act and Copyright Act collectively provide important legal safeguards. Judicial decisions such as Puttaswamy, Shreya Singhal and AnuradhaBhasin further establish principles of privacy, freedom of expression and proportionality that can guide AI governance.

Recent judicial developments concerning AI-generated legal information demonstrate another essential principle: human beings cannot escape legal responsibility merely because technology was involved in the decision-making process. AI should therefore function as an assisting technology rather than a substitute for human judgment.

India should adopt a balanced and risk-based approach towards AI regulation. High-risk AI applications should be subject to stronger requirements relating to transparency, testing, human oversight, data protection and accountability. Individuals affected by harmful automated decisions should also have meaningful mechanisms to seek explanation, correction and legal remedies. Ultimately, effective AI governance should follow the principle of “innovation with accountability.” Regulation should not unnecessarily restrict technological progress, but technological advancement must remain consistent with constitutional rights, rule of law and human dignity. A responsible legal framework can enable India to benefit from AI while ensuring that innovation does not come at the cost of individual rights and social justice.

 

FAQ

1. Does India have a separate AI law?

India does not currently have one comprehensive statute exclusively regulating Artificial Intelligence. AI-related matters are addressed through existing laws and regulatory frameworks.

2. Who is liable when AI causes harm?

Liability depends upon the circumstances. Developers, deployers, organisations or users may potentially be responsible depending upon their role and applicable law.

3. Does AI have legal personality?

Generally, AI systems are not recognised as independent legal persons under Indian law. Legal responsibility therefore remains with identifiable human beings or organisations.

4. Is privacy protected against AI misuse?

Yes. The constitutional right to privacy recognised in Justice K.S. Puttaswamy v. Union of India provides an important safeguard, alongside statutory data-protection requirements.

5. Can lawyers rely completely on AI-generated legal information?

No. AI-generated legal information must be independently verified because AI systems can produce inaccurate or fabricated information.