Subham Sourav is a third year student at National University of Study and Research in Law, Ranchi
Introduction
Artificial intelligence is quickly becoming a part of nearly every aspect of our lives. From self-driving cars to medical diagnostic tools, these smart systems are changing how we live and work. But what happens when an AI makes a mistake, or worse, causes harm? Pinpointing who is responsible in such situations is a monumental challenge for our current legal system. Since accountability in law often depends on who exercises control, analysing this concept becomes crucial to determining responsibility in AI-driven decisions. This piece will delve into how our laws typically define control, that crucial idea of who has the power to guide something and then look at real court cases to see how these ideas might apply to AI. Ultimately, we aim to suggest a clearer path for figuring out who is accountable when AI goes wrong.
Conceptualising Control in Indian Legal Frameworks
The attribution of legal liability often depends on identifying who holds the capacity to influence or direct a particular action or decision. In the context of AI systems, which are developed and operated by a chain of actors, ranging from coders and data scientists to platform integrators and end-users, the notion of “control” becomes central to any meaningful discussion of responsibility. Indian statutory frameworks across sectors offer a useful starting point to understand how the law conceives control as a determinant of accountability.
The Companies Act, 2013, under Section 2(27), describes control as the authority to choose a majority of directors or to influence management or policy choices, either directly or indirectly, through ownership, management rights, shareholder agreements, or voting agreements. The emphasis on both direct and indirect influence, as well as the inclusion of concerted actions by multiple actors, reflects a recognition that legal control may not always reside with the formal owner or top-level executive. This same conception of control is found in Section 2(1)(e) of SEBI (Substantial Acquisition of Shares and Takeovers) Regulations, 2011, where the proviso clarifies that merely holding the position of a director does not, in itself, amount to control. The regulatory language aims to move beyond titles and interrogate actual influence over strategic and operational decision-making.
The Competition Act, 2002, through the Explanation to Section 5, similarly includes in its definition of control the ability to manage the affairs of an enterprise, whether singly or jointly. This becomes relevant in AI governance contexts where decision-making is often distributed across joint ventures, collaborations, or outsourcing arrangements. In such cases, liability cannot be attributed solely on the basis of technical authorship or contractual authorship but must take into account how multiple actors exercise shared control.
The FDI Policy and the Foreign Exchange Management (Overseas Investment) Rules, 2022 further confirm this doctrinal consensus. Rule 2(c) of the 2022 Rules introduces a quantitative threshold, whereby control is presumed when a party has rights entitling it to ten percent or more of the voting rights in an entity. This move towards numerically grounded proxies for control underscores a broader trend of legal systems trying to define influence in practical, enforceable terms.
Across these statutes, the common thread is clear: control is a functional concept that is not reducible to mere ownership or titular authority. It is defined by the ability to shape decisions, exert influence over operations, or prevent certain outcomes. This conception provides a strong doctrinal foundation for assessing AI liability, where harm often emerges from behind-the-scenes roles such as algorithmic fine-tuning, data input selection, or interface design.
Learning from Court Cases: Where Does Control Lead to Liability?
While courts have not yet encountered a significant number of cases directly about AI causing harm, they have dealt with similar situations where it was difficult to pinpoint responsibility. By looking at how judges have thought about “control” in those cases, we can draw some valuable lessons for AI.
The Supreme Court’s ruling in Sunil Bharti Mittal v. CBI made it clear that you can not just blame an individual for a company’s wrongdoing simply because they hold a high position. The judges stated:
“An individual who has perpetrated the commission of an offence on behalf of a company can be made an accused, along with the company, if there is sufficient evidence of his active role coupled with criminal intent. Second situation in which he can be implicated is in those cases where the statutory regime itself attracts the doctrine of vicarious liability, by specifically incorporating such a provision.”(Paragraph 43)
This means we need to see evidence of someone’s “active role” and intention, or a specific law that says one party is responsible for another’s actions. For AI, this is important because a company cannot be held responsible merely because it created or utilized an AI System. Hence, identifying the individuals or entities exercising real functional control over the AI’s operation is key to assigning responsibility
Another important case is Arcelor Mittal India v. Satish Kumar Gupta. . Though centred on corporate debt, the Court’s reasoning provided a broader interpretation of “management” and “control,” recognizing that genuine influence may extend beyond formal positions to those who truly direct company decisions (para 45).
Applied to AI, this principle means liability should follow those exercising operational control such as data providers, model trainers, or platform managers rather than merely those holding formal titles
Perhaps the most expansive view of “control” came from the Supreme Court in State of Mysore v. Allum Karibasappa & Ors, where the judges simply said:
“The word ‘control’ suggests check, restraint or influence.”(Para 16 )
This kind of reasoning has huge implications for AI. It suggests that responsibility for AI harms might fall on the party closest to the end user, such as platform providers or companies that integrate AI into their services. If these parties handle maintenance, updates, or promise how well the AI will perform, they might be held liable, even if they did not build the core AI system. This approach cleverly connects formal agreements with the real-world power and responsibility these parties hold. It is a blueprint for how courts might deal with AI, especially when control is shared among many different actors, making it hard to pinpoint a single cause of harm.
Reconstructing the Legal Meaning of Control for AI Governance
Across the examined statutes and judgments, one consistent principle emerges: control is not limited to ownership or formal authority but includes any material ability to influence outcomes. This principle is particularly well-suited to the complexities of AI liability, where decision-making is often diffused, opaque, and recursive.
In light of this, attributing liability must be guided by a nuanced understanding of control as a function of operational proximity, decision-making power, and risk foreseeability. Courts and regulators should focus not just on who designed the AI system, but on who had the ability, and failed, to mitigate foreseeable harms arising from it. Control should be assessed across the AI lifecycle: during design (developers), deployment (integrators), and operation (platform providers or users with override capabilities).
Moreover, legal standards should incorporate both de jure and de facto elements of control (that is, control derived from lawful or formal authority, as well as control exercised in practice through actual influence or decision-making power). This would allow the law to pierce through corporate veils or platform-based intermediaries and hold accountable those who, while not in the spotlight, determine the architecture, guardrails, and operational norms of AI systems. A flexible, functionally grounded understanding of control, one that recognises indirect influence and contractual responsibility, is thus essential for building a just and enforceable AI liability framework.
Conclusion
The accelerating integration of artificial intelligence into core societal functions, ranging from public service delivery to private decision-making, demands the construction of a robust, forward-looking liability framework. While India does not currently have a dedicated statute addressing AI-specific harms, this gap need not be filled by reinventing the wheel. Instead, existing legal doctrines, especially those grounded in the idea of control, provide a workable starting point for regulating responsibility. In Indian jurisprudence, control has consistently served as a determinant of liability, particularly in corporate, tort, and administrative contexts. The same principle can be extended to AI, recognising that entities that design, supervise, or operationalise such systems possess both the ability and obligation to act responsibly. Thus, accountability should depend on the link between control and consequence; those who influence AI systems must answer for their outcomes.
However, any domestic framework must also be attentive to comparative developments. The European Union’s AI Act, for instance, classifies risks and imposes graduated duties based on the severity of potential harm; Japan similarly adopts a tiered, sector-specific model; and Singapore’s model framework prioritises transparency and explainability. These models show that control includes not only direct supervision but also early-stage governance, building safety, fairness, and accountability into the design and deployment of AI Systems. For India, this means constructing a regime that is not overly punitive or innovation-stifling, but one that places legal responsibility on those in positions of influence and foresight. A refined, principle-based liability structure grounded in control, complemented by mandatory risk assessments, rebuttable presumptions, and narrowly tailored safe harbour protections, can strike the right balance between fostering innovation and ensuring justice in the age of intelligent machines.
