Policy
India Weighs Risk-Based AI Law For High-Stakes Systems
India is considering a graded AI law that would place lighter rules on low-risk tools and stricter oversight on systems used in finance, healthcare, infrastructure, and other high-impact sectors.
By Michael C ·

India is moving closer to an AI law built around graded, risk-based rules, a framework that would treat ordinary productivity tools very differently from systems used in banking, healthcare, critical infrastructure, and other high-impact settings.
The Economic Times reported that officials are considering a structure in which low-risk systems such as chatbots, recommendation tools, and office software face minimal obligations, while high-risk systems face stricter requirements around safety, accountability, audits, and oversight.
That approach mirrors the direction of AI regulation globally. Governments are learning that a single rulebook for every algorithm is too blunt. The real policy question is where an AI system is used, what decisions it influences, and whether errors could harm people, markets, or public services.
For India, the stakes are especially large. The country wants to support AI startups, digital public infrastructure, enterprise adoption and domestic model development, while also protecting citizens from opaque systems that could affect credit, health access, employment, education, or public benefits.

A graded law would give regulators more flexibility, but it also creates hard classification fights. Companies will want their products treated as low-risk. Civil-society groups will argue that seemingly ordinary tools can become high-impact when deployed at scale. Regulators will need criteria that are clear enough to enforce and flexible enough to handle new model capabilities.
The financial sector will likely be one of the earliest tests. AI systems used for credit, fraud detection, compliance, trading, collections, and customer service can affect consumers even when a human remains somewhere in the loop. A risk-based law would have to decide when oversight attaches to the model, the institution, or the final decision process.
Healthcare raises a different set of issues. AI can help triage patients, read scans, summarize records and support doctors, but failures can produce direct harm. A country with India's scale needs rules that improve access without allowing untested systems to become invisible clinical gatekeepers.

The most important design choice may be enforcement capacity. Passing a law is easier than building the technical teams, audit processes, complaint channels and sector regulators needed to make it work. India has the talent base to build that capacity, but it will need coordination across ministries and regulators.
A risk-based law would not settle India's AI future by itself. But it would mark a shift from broad principles to operational governance. The next question is whether the rules can be precise enough for companies to follow, strong enough for citizens to trust and flexible enough for a market that is changing every quarter.
Topics: India, AI law, risk-based regulation, AI governance