This article is written by Sonam Kumari, a student of KLE Society’s Law College, Bengaluru.

Artificial Intelligence (AI) has emerged as a transformative technological force that is fundamentally reshaping governance, economic systems, and social interactions. Its capacity to process vast amounts of data and generate predictive insights has enabled unprecedented efficiencies across sectors such as healthcare, finance, law enforcement, and public administration. However, alongside these benefits, AI introduces complex legal and ethical challenges relating to accountability, transparency, algorithmic bias, and the protection of fundamental rights.
This article critically examines the need for AI regulation through a comparative analysis of the European Union’s AI Act and India’s evolving regulatory framework, primarily governed by the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023.
It argues that India’s current regulatory approach remains fragmented, reactive, and insufficient to address the systemic risks posed by AI technologies. By contrast, the EU’s risk-based regulatory model provides a structured and rights-oriented framework.
The article proposes that India adopt a rights-centred, risk-calibrated approach incorporating constitutional safeguards, institutional oversight, and proportionate regulation. It further evaluates judicial responses to algorithmic decision-making and addresses counter-arguments concerning overregulation. Ultimately, the article contends that effective AI governance must balance innovation with the preservation of human dignity, autonomy, and justice.
Introduction
Artificial Intelligence has evolved from a supplementary technological tool into a central determinant of decision-making processes across both public and private domains. AI systems are now widely used in areas such as predictive policing, algorithmic credit scoring, automated hiring, and welfare distribution. These systems not only enhance efficiency but also significantly influence outcomes that affect individual rights and societal structures.
The increasing reliance on AI exposes a fundamental tension between technological autonomy and legal accountability. Traditional legal frameworks, particularly in tort and administrative law, are premised on human intent, foreseeability, and control. AI systems, however, operate with varying degrees of autonomy and can produce outcomes that are neither fully predictable nor directly attributable to human actors. This phenomenon gives rise to what scholars describe as a “responsibility gap,” where harm occurs but liability cannot be clearly assigned.
Moreover, AI systems are deeply embedded in data ecosystems that involve the large-scale collection and processing of personal information. This raises significant concerns regarding privacy, data security, and informational asymmetry. Individuals often lack meaningful control over how their data is used, leading to an imbalance of power between data subjects and data controllers.
The constitutional implications of AI deployment are particularly significant in India. In Justice K.S. Puttaswamy v Union of India, the Supreme Court recognised the right to privacy as an intrinsic component of the right to life and personal liberty under Article 21. The large-scale deployment of AI systems, especially by state actors, therefore operates within a framework that demands heightened scrutiny.
This article advances two central arguments. First, AI must be regulated as a systemic risk to constitutional rights rather than merely as a technological innovation. Second, India must adopt a rights-centred, risk-based regulatory framework, drawing inspiration from the European Union while tailoring it to its own socio-economic context.
Theoretical Foundations: Why AI Requires Regulation
AI systems differ fundamentally from traditional technologies in their ability to learn, adapt, and make decisions autonomously. This shift challenges the foundational assumptions of legal systems that rely on human agency and accountability.
One of the primary concerns is the opacity of AI systems. Many advanced AI models, particularly those based on deep learning, operate as “black boxes,” where the internal decision-making processes are not easily interpretable. This lack of transparency undermines procedural fairness and makes it difficult for individuals to challenge decisions that adversely affect them.
Another critical issue is algorithmic bias. AI systems are trained on historical datasets that may contain embedded social biases. As a result, these systems can replicate and amplify discriminatory patterns, particularly in areas such as employment, lending, and criminal justice. This raises serious concerns under principles of equality and non-discrimination.
Additionally, the development and deployment of AI involve multiple actors, including developers, data providers, and end-users. This creates a diffusion of responsibility, making it difficult to assign liability when harm occurs.
These challenges highlight the need for a comprehensive regulatory framework that addresses not only technical issues but also broader legal and ethical concerns.
The European Union’s Risk-Based Regulatory Model
The European Union has taken a pioneering approach to AI regulation through the AI Act, which represents the most comprehensive legislative framework in this domain. The Act adopts a risk-based classification system that categorises AI systems by their potential to cause harm.
AI systems posing unacceptable risks, such as social scoring systems, are prohibited. High-risk systems, including those used in critical infrastructure and law enforcement, are subject to stringent compliance requirements, including conformity assessments, documentation, and human oversight. Lower-risk systems are regulated through transparency obligations or minimal intervention.
A key feature of the EU framework is its emphasis on ex ante regulation. By requiring compliance measures before deployment, the EU seeks to prevent harm rather than merely address it after it occurs. This reflects the principle of proportionality, ensuring that regulatory intervention is commensurate with the level of risk.
The EU model also integrates fundamental rights into its regulatory structure, recognizing that AI systems can significantly impact human dignity, autonomy, and equality. While the framework has been criticized for imposing compliance burdens, particularly on smaller enterprises, it provides a robust and structured approach to AI governance.
India’s Emerging but Fragmented Framework
India’s approach to AI regulation remains fragmented and underdeveloped. Unlike the EU, India has not yet enacted a dedicated AI law and instead relies on a combination of existing legislation and policy initiatives.
The Information Technology Act 2000 provides the foundation for digital governance in India. However, it was enacted before the advent of modern AI technologies and does not address issues such as algorithmic accountability or autonomous decision-making.
The Digital Personal Data Protection Act 2023 represents a significant step forward in data governance. It introduces a consent-based framework for data processing and establishes obligations for data fiduciaries. However, its scope is limited to data protection and does not extend to broader issues of AI regulation.
Policy initiatives, particularly those led by NITI Aayog, emphasize ethical AI principles such as fairness, transparency, and inclusivity. While these initiatives are important, they lack binding legal force and therefore have limited impact on actual regulatory practices.
Overall, India’s regulatory framework is characterized by fragmentation, lack of enforceability, and absence of a coherent strategy for addressing AI-related risks.
Recent policy developments, including the IndiaAI Mission and government discussions on responsible AI governance, indicate growing regulatory attention towards artificial intelligence. However, these initiatives largely operate at the policy level and do not yet constitute a comprehensive statutory framework comparable to the European Union’s AI Act.
Liability and Accountability in AI Systems
The issue of liability presents one of the most complex challenges in AI regulation. Traditional tort law is based on fault and foreseeability, which are difficult to apply to autonomous systems.
This creates what is often referred to as the autonomy paradox: as AI systems become more autonomous, traditional liability frameworks become less effective.
Three primary models of liability have been proposed. Fault-based liability requires proof of negligence but may be difficult to establish in cases involving complex AI systems. Strict liability imposes responsibility regardless of fault but may discourage innovation. Enterprise liability assigns responsibility to entities that benefit economically from AI deployment.
Among these, enterprise liability offers a balanced approach, as it aligns responsibility with risk creation and economic benefit. A hybrid model combining strict liability for high-risk systems with fault-based liability for lower-risk applications would provide a proportionate solution.
At present, Indian law does not provide a dedicated liability regime for harms caused by autonomous AI systems, leaving courts to rely upon existing principles of tort, contract, and statutory law.
AI Regulation as Constitutional Governance
AI regulation must be understood as an extension of constitutional governance, particularly when AI systems are used in public functions. Algorithmic decision-making has the potential to affect fundamental rights under Articles 14, 19, and 21 of the Indian Constitution.
Biased algorithms may violate the right to equality under Article 14, while surveillance technologies may infringe upon freedom of expression under Article 19. Large-scale data processing also raises concerns under Article 21, particularly in relation to privacy and dignity.
The opacity of AI systems further complicates due process, as individuals may be unable to challenge decisions affecting them. This necessitates the incorporation of mechanisms such as algorithmic audits, explainability, and judicial oversight.
Judicial Responses to Algorithmic Decision-Making
Indian courts have not yet developed extensive jurisprudence specifically addressing algorithmic decision-making, making comparative judicial developments particularly relevant.
Courts across jurisdictions have begun addressing the challenges posed by AI systems. In State v Loomis, the use of an algorithm in sentencing raised concerns regarding due process due to its lack of transparency.
In R (Bridges) v Chief Constable of South Wales Police, the UK Court of Appeal held that the use of facial recognition technology violated privacy rights due to insufficient safeguards.
Similarly, in the SyRI case, the Netherlands court struck down an algorithmic welfare system for violating privacy and disproportionately affecting vulnerable populations.
These cases demonstrate an emerging judicial consensus emphasizing transparency, proportionality, and accountability in AI governance.
Counter-Arguments: The Case Against Overregulation
Critics argue that strict AI regulation may hinder innovation and impose significant compliance costs, particularly on start-ups and smaller enterprises. There is also concern that regulatory frameworks may become outdated due to the rapid pace of technological change.
However, these concerns highlight the need for better regulation rather than less regulation. A risk-based approach ensures that regulatory burdens are proportionate, while mechanisms such as regulatory sandboxes allow for innovation within controlled environments.
Conclusion
The regulation of Artificial Intelligence represents one of the most significant legal challenges of the modern era. As AI systems increasingly shape social and economic outcomes, the risks associated with unregulated deployment become more pronounced.
The European Union’s AI Act demonstrates that a structured, rights-based regulatory framework is both feasible and effective. India, however, remains at an early stage, relying on fragmented and non-binding measures.
A balanced regulatory approach is essential, one that integrates innovation with constitutional safeguards. The legitimacy of AI governance will ultimately depend on its ability to preserve human dignity, autonomy, and justice in an increasingly automated world.
The absence of a dedicated AI statute in India creates uncertainty regarding accountability, transparency, and protection of fundamental rights in increasingly automated decision-making environments.
Frequently Asked Questions
1. What is the EU AI Act?
It is a comprehensive regulation that classifies and governs AI systems based on risk levels.
2. Does India have a dedicated AI law?
India currently relies on existing IT laws and sectoral guidelines rather than a single AI statute.
3. Why compare EU and Indian AI laws?
It helps assess regulatory maturity, policy gaps, and global compliance standards.
4. What are high-risk AI systems under the EU AI Act?
They include AI used in critical areas like healthcare, policing, and employment decisions.
5. What is India’s current approach to AI regulation?
India follows a developing framework focused on innovation, ethics, and digital governance.


