Qazi Ahmad Masood is a fourth year law student at Rajiv Gandhi National University of Law, Punjab.

Introduction

Artificial Intelligence (AI) is rapidly transforming industries the world over, and India stands to be an active participant in this transformation given its demographically diverse population, developing technological landscape, and government initiatives like the Digital India and the National AI Strategy. However, the nation’s regulatory system is dispersed and underdeveloped  and is governed by sectoral guidelines, which are unclear and insufficiently provide strategies for addressing risks related to AI. Global momentum has grown behind the application of a risk-based approach to regulations, where the use of AI technologies has been divided into different risk levels and applies appropriate controls. An example of this would be the EU’s AI Act, where stricter laws are applied to higher-risk systems, like those related to biometric authentication or healthcare, while looser regulations are applicable to low-risk uses and so promote innovation. India stands to benefit significantly by adopting the same multi-tiered system of regulations where the balance of innovation and ethical, transparent, and secure practices are effectively maintained. Adoption of the same would ensure the country has an evenly balanced and future-proofed AI regime, and, additionally, tackle sector-specific issues, promote responsible AI development and deployment , and build greater confidence among the public. India may transplant the EU’s all-inclusive model and make it applicable to its own socioeconomic situation. 

Present day Regulation of AI in India

Currently, there exist no integrated or comprehensive regulations for the development and use of artificial intelligence in India, and so regulations are piecemeal. Counterpoised to this, the country relies upon a fragmented combination of voluntary codes of best practices, principles, and sectoral regulations. For example, the Digital Personal Data Protection Act does not specifically regulate the systems of AI or impose safety and ethical norms; it deals only with the topic of data protection and security, its provisions may indirectly affect AI by governing how personal data is collected, processed, and stored; however, these measures are insufficient to address the broader ethical, safety, and accountability challenges unique to AI, underscoring the need for a dedicated regulatory framework tailored to AI technologies. Similarly, although the Digital India program promotes innovation and digital infrastructure, it does not have strong legislative support including the risks of the use of AI. Little impact comes from the government’s Principles of Responsible AI, which promote the importance of accountability, transparency, and fairness, since they are advisory and voluntary. This dispersed methodology gives rise to numerous difficulties. India experiences difficulty setting clear standards or proper monitoring because the country lacks both a core legislative template and the EU-like formal system of risk classification where the EU classifies the application of AI into the categories of unacceptable, high, limited, and low risks.

Developers, new businesses, and incumbent institutions struggle to build compliant AI products and better predict future legal requirements because of the resultant regulatory uncertainty. Moreover, handling sectoral risks becomes even more burdensome, and this occurs most significantly where risks of significant societal harm through exploitation or bias are the highest, for example, healthcare, financial services, law enforcement, and autonomous vehicles. Policymakers are presented with the dilemma of too much strictness potentially crushing investment and innovation, versus too little holding the prospect of increased harms, discrimination, and violations of privacy. Lack of an integrated, risk-based regulatory system inhibits the growth of responsible AI, erodes public confidence, and does not do justice to ethical and societal concerns.

What Is a Risk-Based Regulatory Framework?

Regulatory regime based on risk is a policy where rules and regulations are modified accordingly, according to the risks or possible harms related to certain systems of AI. Rather than imposing the same rules on every use, it weighs the risks and severity of harmful effects for various applications of AI and takes corresponding appropriate regulatory action.

Due to the inherent risk of severe damage or breaches of core human rights presented by the systems of highest risk, they are governed by strict oversight. These systems are tested rigorously, are transparent, and are bound by safety measures. High-risk examples of these systems include those deployed for the purpose of biometric identification, clinical diagnostics, and self-driving cars. Lower-risk applications, like chatbots or simple suggestion algorithms, are governed by less stringent regulatory requirements , promoting an atmosphere of innovation and experimentation. This forward-looking methodology aims to reconcile the necessity of advancing technologies with the key factors of defence, fairness, and responsibility.

This idea is illustrated by the European Union’s proposed AI Act, which classifies different systems according to their likely impact while rohibiting certain high-risk AI practices , like indiscriminate use of facial recognition and deceptive artificial intelligence. Suppliers of the highest risk of AI have to align their products and services with strict safety regulations, be transparent through full documentation, ensure human supervision, and have proper risk management strategies instituted throughout the system operating lifetime.

Need for the Risk-Based Approach for India.

Embracing a risk-based approach is particularly crucial for India as it navigates the complex and rapidly dynamic landscape of artificial intelligence development and application. Focusing regulatory energies on those deployments of AI where the risk of harm is higher, India can most effectively use its resources to maintain safety, security, and ethical requirements without unnecessarily hampering innovation. In healthcare, banking, and law enforcement, where the AI systems interact with sensitive information, make consequential decisions, and have direct effects on the lives of people, this selective regulation becomes indispensable. Focusing inspections on high-risk sectors could potentially prevent harm and promote people’s rights proactively.

Biometric authentication and machine learning-based diagnostics in the spaces of healthcare and security impose significant risks upon failure or bias inherent to these technologies. In addition, the risk-based approach to regulations promotes innovation by imposing minimal regulatory requirements for low-risk technologies, such as recommendation algorithms and chatbots, and therefore allows researchers and businesses to fast-track and scale their innovations without the imposing compliance costs. Such flexibility has the ability to enhance India’s position in the competition of artificial intelligence and accelerate the digitalization of the country. Implementation of the kind of the regulatory system also allays data privacy, bias, and surveillance fears by ensuring people are assured the systems of artificial intelligence that impact their security, rights, or privacy are subject to transparent and enforceable rules.

Through this, it promotes confidence among the people. Through focusing the regulatory resources where they are most needed, it also enables India to focus on the resolution of the social challenges, including privacy issues, safety risks, and bias within the data stores.

India’s Challenges in Implementing a Risk-Based Framework

India has an array of challenging tasks in applying a risk-based approach to the regulation of AI. India’s sectoral and institutional diversity along sector lines, e.g., manufacturing, public administration, healthcare, financial, and agricultural, each having distinct AI application and risk profile, constitutes the major challenge. Given the diversity, sectoral risk studies and customized standards are required but are difficult to develop and entail significant resources, particularly given varied degrees of technical expertise by companies. Apart from this, the capacity of India for regulations is already constrained by the availability of inadequate institutional structure, expertise, and technological bases to enable the effective observation, appraisal, and enforcement of the required AI standards. In the absence of adequate regulatory capacity, the regulators are likely to be unable to keep pace with fast-changing technologies, which would result in spaces of regulatory gaps and irregular regulations.

It is made even more complicated by data privacy and bias issues, where the identification of applications posing a higher risk often demands the handling of sensitive data, including healthcare records and bio-metrics. These data pose significant challenges in handling, all the more so because of the extensive and diversity of data repertoire existing in the nation.

Applications of AI also have biases in training data, which can lead to biased or discriminatory results. In India, sophisticated technologies and intelligence are currently being developed to decide strategies to detect and prevent these biases.  Last but not least, India lacks clear, concise definitions and standards of various degrees of AI risk that trigger legal and ethical problems.  It may be challenging to craft uniform and extensive legislation because the current legal systems are not sufficient to tackle challenges like accountability, transparency, or autonomous decision-making.

How India Can Adopt the Same Method and Learn Lesson from the EU. 

Through a systematic, risk-based approach, which has successfully balanced innovation and safety, ethics, and societal well-being, India could learn how the European Union has tackled the question of regulating AI.  First, build precise and transparent definitions of risk categories of AI use cases based on their ability to erode security, privacy, social justice, safety, health, and fundamental rights.  Policymakers have the prerogative of applying risk-based requirements because of this classification: systems involving unacceptable risks, like social scoring or mass surveillance, must be even banned entirely; systems of high risk, like biometric identification, medical diagnosis, or key infrastructure, must be tightly governed, audited, and transparent; limited-risk applications, like chatbots or recommender software, must be governed moderately that focuses on transparency and responsible data use; and low-risk tools, like plain data analysis or entertainments software, must be governed lightly to promote innovation.

To construct requirements appropriate to India’s unique socioeconomic profile while maintaining the spirit of justice, equity, and the public interest, it is essential that India set sectoral guidelines through consultative processes involving the government, industry, academia, and civil society. Complementing investment of funds in technological tools of reliability verification, bias perception, and safety, it remains essential to construct upon the foundations of current institutions such as the Artificial Intelligence Development and Adoption Initiative (AIDAI) to manage certification, compliance, and enforcement. In addition, holding training programs for industry and regulators will assist towards uniform comprehension and application of requirements by different sectors.

The EU’s AI Act classifies AI systems into unacceptable, high, limited, and minimal risk categories, with regulatory obligations calibrated to potential harm. Unacceptable-risk practices are prohibited, while high-risk systems are subject to audits, transparency requirements, and mandatory human oversight. Although this model offers regulatory clarity and proportionality, its direct transplantation into India would be unsuitable given differences in institutional capacity and enforcement architecture, necessitating contextual adaptation rather than replication.

By offering government financial support, recognition frameworks, and regulatory regimes allowing for the safe experimentation of new emerging technologies of artificial intelligence, responsible innovation is encouraged by inspiring developers and institutions to focus on ethical design principles, make internal risk assessments, and follow agreed best practices. Ultimately, international cooperation is necessary; aligning national law with global standards will inspire investment worldwide, foster cross-border commerce, and enable India to play the leading role in global discussion of the regulation of AI, ensuring therefore that the latter remains ethical, competitive, and accountable.

How Indian Issues Are Addressed by This Framework

In concrete terms, the critical challenges that India faces within the realm of artificial intelligence include prejudice, discrimination, privacy concerns, and data security, all of which are thoroughly addressed by this legal framework. The framework underscores the necessity of implementing stringent monitoring and fairness criteria for applications that notably influence individuals’ rights and opportunities by categorizing AI systems utilized in sensitive domains such as law enforcement, recruitment, and credit assessment as high-risk. By mitigating the chances of biased or discriminatory results, this focus advances social justice and equality.

The structure encourages greater control over systems that manage sensitive data through mandatory disclosures, robust data protection policies, and regular audits, considering the large volumes of personal data managed in sectors such as healthcare, finance, and government.  By keeping data breaches at bay, safeguarding privacy of the individual, and ensuring India’s broader data privacy goals, the measures aim to drive greater public trust in AI. The guidelines also call for the implementation of clear safety requirements, especially for critical uses in public safety, healthcare, and transport, to ensure the safety and reliability of AI systems that have direct impacts on public welfare.  This will help increase public trust. A conducive climate for entrepreneurs, researchers, and innovators to operate with regulatory flexibility without unnecessary expenses is brought about by the plan of the framework to introduce less regulation for low-risk usage, which recognizes the necessity to allow innovation. By focusing regulatory attention on industries holding substantial power, this balanced approach enables India to maintain competitiveness on the international stage.While India can draw valuable lessons from the EU’s risk-based AI classification, its vast cultural, socio-economic, and linguistic diversity necessitates adapting these categories to reflect local realities, for instance, high-risk AI systems in India should account for varied literacy levels, digital access disparities, and regional socio-economic vulnerabilities, which may amplify risks in sectors like healthcare, agriculture, and governance. Further Surveillance-oriented AI used in policing and governance also warrants heightened scrutiny due to risks of opacity and disproportionate impact on marginalised communities. Tailoring risk classifications to these domestic realities enables effective protection of rights while preserving regulatory flexibility for low-risk innovation. Thereby requiring more granular, context-sensitive risk assessments and tailored regulatory safeguards beyond the EU’s uniform categories.

India may transplant the EU’s all-inclusive model and make it applicable to its own socioeconomic situation. Context-sensitive, flexible, and responsible innovation-encouraging regulatory regime promoting pluralism and civic well-being is enabled by making these standards applicable.

Conclusion

Adopting the risk-based model of regulating artificial intelligence brings significant benefits, including the application of focused oversight for increased safety, innovation, and assurance of the ethical use of systems of AI. In targeting applications considered to be of high risk, India should be able to contain possible risks effectively while fostering an innovation-friendly setting. India, moreover, has the peculiar chance of learning and reinterpreting the examples of regulations like the EU’s proposed AI Act and applying them to the peculiarities of the nation’s socio-economic setting. This approach fosters broad-based growth, tackles the question of region-specific concern like bias, privacy, and data safety, and, through balancing innovation and societal values, ensures responsible growth.

Policymakers, corporate leaders, scholars, and civil society have to unite and make this aspiration become a reality.  Together, they are able to build, iterate, and deploy an end-to-end, ethical AI system benefiting all Indians and position India as a global leader  to define AI ethically and creatively. A context-sensitive, risk-based approach to AI regulation enables India to reconcile technological innovation with constitutional values of fairness, accountability, and proportionality.

Share this post