Embedding Compliance by Design: India’s Techno-Legal Framework for AI and Why It May Outpace the EU…
In January 2026, the Office of the Principal Scientific Adviser released a white paper that, if you read past the bureaucratic title…
Embedding Compliance by Design: India’s Techno-Legal Framework for AI and Why It May Outpace the EU AI Act
In January 2026, the Office of the Principal Scientific Adviser released a white paper that, if you read past the bureaucratic title, contains a genuinely interesting idea. It proposes a techno-legal framework for AI governance. The pitch: instead of waiting for AI systems to cause harm and then scrambling to regulate them, why not build legal compliance directly into the technology? Bake consent mechanisms, audit trails, bias detectors, and explainability features into the system from the start. Don’t bolt them on later.
It sounds obvious when you say it like that. But it’s a fundamentally different philosophy from what the rest of the world is doing. The European Union’s AI Act, which partially kicked in last year, takes the opposite route. It classifies AI systems into risk categories, writes detailed rules for each category, and enforces compliance through audits and fines. India is betting that you can skip the classification step entirely and instead make governance a feature of the technology itself.
I spent the last few weeks reading both frameworks, and I think India’s instinct is right but its execution is incomplete. Here’s why.
Two Models, Two Philosophies
The EU AI Act is built on classification. Every AI application gets sorted into one of four buckets: unacceptable risk (banned, like China-style social scoring), high risk (think hiring algorithms, credit scoring, law enforcement tools), limited risk (needs transparency labels), and minimal risk (do whatever you want). If your system falls in the high-risk bucket, you need third-party audits, detailed documentation, human oversight mechanisms, and conformity assessments before you can deploy. Get it wrong and you’re looking at fines up to 35 million euros or 7% of your global revenue. That’s real money.
India’s white paper looks at this and essentially says: the buckets are the problem. A large language model can diagnose diseases in the morning, draft contracts at lunch, and generate political deepfakes by evening. Calling the system “high-risk” or “low-risk” tells you nothing useful because the risk lives in how someone uses it, not in the model itself.
So instead of classification, the white paper proposes lifecycle governance. At every stage of building and running an AI system, you embed specific safeguards. Privacy tools during data collection. Fairness testing during training. Explainability during inference. Real-time monitoring once it’s live. The compliance isn’t a checkpoint you pass once; it’s a continuous process woven into the system’s architecture.
The institutions backing each model are different too. The EU has a centralized AI Office with enforcement teeth. India proposes something looser: an inter-ministerial coordination group, a technical advisory committee, and an AI Safety Institute for monitoring. Actual enforcement? That stays with existing regulators and courts, using existing laws. Which, as I’ll get to, is a problem.
Photo by Glenn Carstens-Peters on Unsplash
Why India’s Instinct Is Right
I’ll be honest: when I first read the white paper, I assumed it was the usual “pro-innovation” dodge that governments use when they don’t want to regulate. But the more I thought about it, the more the core logic held up.
Traditional regulation works by defining a problem, writing rules, and enforcing them after violations. That’s fine for industries where the product stays the same after it leaves the factory. AI doesn’t work like that. Models learn, adapt, and get repurposed. A bias detection module running continuously inside the system catches problems that a one-time pre-deployment audit would miss entirely. An ongoing audit log is more useful for accountability than a conformity certificate gathering dust in a compliance folder.
There’s also a cost argument that matters more than people admit. India has over 960 legal tech companies. Most of them are small. If you dropped the EU’s compliance requirements on them tomorrow, with all the third-party audits, documentation mandates, and conformity assessments, most would either shut down or ignore the rules. Neither outcome helps anyone. The techno-legal model, if done right, could set meaningful standards without choking the ecosystem that’s supposed to follow them.
Where It Falls Apart
Here’s the problem. If the obligation is to “embed compliance by design,” who decides what compliance actually means? The white paper recommends voluntary self-certification and industry codes like ISO/IEC 42001. I understand why. Standards are flexible, they’re developed by people who understand the technology, and they’re easier to update than legislation. But voluntary standards without enforcement are suggestions. And suggestions don’t change corporate behaviour when there’s money on the line.
Then there’s the legal infrastructure problem, which is harder to fix. India’s primary digital law is the IT Act of 2000. It was written before smartphones existed. It says nothing about algorithmic decision-making, AI-generated content, or what happens when an autonomous system causes harm. Courts are doing their best to stretch it, but you can only stretch a 25-year-old law so far before it tears. The Digital Personal Data Protection Act of 2023 covers data, but data is only one piece of the AI accountability puzzle. Fairness, transparency, explainability: none of these have a clear statutory home in Indian law right now.
And timing matters. The EU AI Act, for all its bureaucratic weight, gives companies clarity. They know the rules. They know the penalties. They can plan. India’s framework is still a collection of guidelines, principles, and white papers. The AI Ethics and Accountability Bill that was introduced in Lok Sabha in December 2025 signals that some parliamentarians want harder rules, but it’s a Private Member’s Bill. Those almost never pass. Until India converts its principles into enforceable law, the techno-legal framework is a thought experiment, not a regulatory system.
Photo by Kyle Glenn on Unsplash
What Would Actually Work
I don’t think India needs to copy the EU. The classification model has its own issues; it’s rigid, expensive, and arguably too slow for how fast AI moves. But India does need to build legal scaffolding around its techno-legal foundation. Keep the lifecycle-based, design-centric approach. It’s genuinely smart. But add three things.
First, binding minimum standards for high-impact applications. Not the EU’s elaborate risk tiers, but a clear rule: if your AI system makes decisions about people’s credit, employment, healthcare, or legal rights, certain safeguards are mandatory, not voluntary. Second, mandatory incident reporting. The white paper already floats the idea of a national AI incident database. Make it compulsory. Third, real penalties. Not necessarily EU-scale fines, but enough to make non-compliance more expensive than compliance.
India is hosting some of the world’s biggest AI events, producing legal tech startups at a rate that rivals most countries, and sitting on a digital infrastructure that’s genuinely world-class. The ambition and the ecosystem are there. What’s missing is a legal framework that takes its own ideas seriously enough to enforce them.
The techno-legal approach is a good start. It just can’t be where India stops.
메타데이터
- post_id
- 9afbdb8dbc84
- slug
- embedding-compliance-by-design-indias-techno-legal-framework-for-ai-and-why-it-may-outpace-the-eu-9afbdb8dbc84
- url
- https://medium.com/@mishramanya/embedding-compliance-by-design-indias-techno-legal-framework-for-ai-and-why-it-may-outpace-the-eu-9afbdb8dbc84
- canonical_url
- https://medium.com/@mishramanya/embedding-compliance-by-design-indias-techno-legal-framework-for-ai-and-why-it-may-outpace-the-eu-9afbdb8dbc84
- author_url
- https://medium.com/@mishramanya
- status
- ok
- fetched_at
- 2026-06-09 15:37:30