AI Governance · India

India's AI Governance Opportunity: Build Operational Governance Before Regulation Forces It

MeitY's AI Governance Guidelines are voluntary today — built on seven "sutras," self-certification, and regulatory sandboxes rather than mandates. But the Guidelines are explicit that existing law already applies to AI, and three new institutions are being stood up to enforce exactly that. Indian enterprises and GCCs that build inventory, risk assessment, evidence, and monitoring into their AI programs now will absorb tomorrow's mandates smoothly. Those that wait will be reconstructing the evidence trail under pressure, the same way many were caught out by the DPDP Act.

Crest.Digital Editorial August 22, 2026 11 min read AI Governance

On August 7, 2026, Ampcus Cyber convened policymakers, regulators, CXOs, and cybersecurity leaders at the GRC India AI Conclave in New Delhi, under the theme "Empowering a Secure and AI-Driven Digital India." The conversations covered India's evolving AI governance framework, the Digital Personal Data Protection Act, and financial-sector cyber resilience — but the subtext running through the day was simpler than any single session title: India's AI governance framework already exists, it is currently voluntary, and the enterprises that treat that voluntariness as a reason to wait are making the same mistake many made with the DPDP Act.

The Ministry of Electronics and Information Technology's AI Governance Guidelines take what the government calls a "techno-legal" approach — seven guiding principles, three new institutions, and a deliberate preference for self-certification and regulatory sandboxes over prescriptive mandates. A standalone AI law has been assessed as unnecessary for now. But the Guidelines are explicit on one point that changes how any enterprise should read them: existing law — the DPDP Act 2023, the IT Act 2000, consumer protection statutes, and sector rules from the RBI, SEBI, and IRDAI — already applies to AI systems. The Guidelines do not create new obligations. They clarify how the obligations enterprises already carry apply to AI, and they signal where enforcement is heading next.

That is precisely the pattern DPDP Act compliance followed. "Nothing to do until Significant Data Fiduciary designations are announced" turned out to be an expensive read of a law that was, in fact, already in force. The AI Governance Guidelines are set up to repeat that lesson on a shorter timeline — three institutions (an inter-ministerial policy group, an expert advisory committee, and a safety-testing institute) are already being stood up, and each will eventually ask enterprises to produce evidence of governance that does not yet exist in most organizations. Building that evidence now, inside the governance workflows enterprises already run for vendor and third-party risk, costs far less than reconstructing it later under a compressed deadline.

Could your organization already produce an AI system inventory and evidence trail on request?

See how a vendor and AI risk intelligence platform extends the same inventory, risk assessment, and evidence discipline built for third-party governance to an enterprise's own AI systems.

Explore Crest Intelligence

The Regulatory Window Is Open — And It Won't Stay That Way

It is worth being precise about what "voluntary" means in this context, because it is easy to misread as "optional." MeitY's Guidelines rely on self-certification and sandbox arrangements rather than binding rules, and the government has explicitly opted against a new horizontal AI statute for now, favoring enforcement through the regulatory channels that already exist. That is a meaningfully different posture from the EU's AI Act, which sets binding obligations with defined penalties. It is not, however, an invitation to deprioritize AI governance — it is a signal that enforcement will arrive sideways, through the RBI, SEBI, IRDAI, and DPDP Act mechanisms an enterprise already answers to, rather than through a dedicated AI regulator with its own inspection calendar.

🏛️
Three Institutions, Not Yet Operational — But Coming The Guidelines establish an AI Governance Group (an inter-ministerial policy body), a Technology & Policy Expert Committee (scientists and legal experts who will define what "reasonable" AI governance looks like), and an AI Safety Institute (testing and standards, particularly for high-risk sectors like healthcare, finance, and critical infrastructure). None exist yet in full operational form. When they do, the first thing each will ask for is evidence of existing governance — an AI inventory, documented risk assessments, and bias-testing results.

The practical read for an Indian enterprise or GCC is straightforward: the absence of a binding AI law today is not the same as the absence of AI-related regulatory risk today. A credit-decisioning model already sits under RBI's model risk expectations whether or not MeitY's sutras are cited by name. An AI-driven underwriting engine already sits under IRDAI's oversight. An AI system processing personal data already carries full DPDP Act obligations. The Guidelines' real contribution is naming the gap between what enterprises are already required to do and what most are currently able to demonstrate they are doing — and that gap is what the coming institutions will test first.

Inside the Seven Sutras — What They Actually Ask Enterprises to Do

Each of the seven principles MeitY calls "sutras" reads, at the policy level, like a value statement. At the operational level, each one translates into a specific thing a compliance, risk, or technology team has to be able to show. Trust is the foundation means documenting what an AI system does, how it decides, and what data it touches, in a form that satisfies both internal audit and an external examiner. People first means every AI system that affects an individual's outcome needs a defined point where autonomous action stops and a named human reviews it — particularly relevant as agentic AI systems take on tasks that used to require a human to initiate them.

Innovation over restraint is permission to experiment inside guardrails, including through regulatory sandboxes arranged with sector regulators, rather than a license to skip governance because the technology is new. Fairness and equity means pre-deployment bias testing for any AI system touching hiring, credit, insurance, or service delivery, with particular attention to how automated decisions affect vulnerable groups. Accountability is the sutra with the sharpest teeth for enterprise buyers of AI: responsibility follows function, meaning the organization that decides how an AI system is used — the deployer, not necessarily the AI vendor that built it — carries primary responsibility for what that system does. A vendor's disclaimer does not transfer that responsibility away.

Understandable by design means an AI-driven decision needs to be explainable in language a customer, an ombudsman, or a regulator can follow — "the model said no" stops being an acceptable answer to a declined loan application or a rejected insurance claim. Safety, resilience, and sustainability covers robustness against adversarial manipulation — prompt injection, data poisoning — alongside the resource footprint of AI workloads, a dimension that will matter more as India's data centre capacity scales and BRSR Core sustainability disclosures extend their reach. None of these seven ideas is unfamiliar to a mature AI governance program built into vendor due diligence — what is new is having a named government framework that enterprises will eventually be measured against.

Ready to build the sutra-to-evidence mapping before an institution asks for it?

Crest.Digital pairs configurable AI and vendor risk assessments with a structured evidence repository and agentic AI workflows — so the inventory, the mapping, and the audit trail already exist when a regulator or reviewer comes asking.

Why This Moment Matters Even More for India's GCCs

Nowhere is the "build now, not later" case stronger than inside India's Global Capability Centres. The Nasscom-Zinnov GCC Value Orbit report puts India's GCC count at 2,117 centres across 3,728 units, employing roughly 2.36 million professionals as of FY26 — a base that has grown 32% since FY2021, with 506 Forbes Global 2000 companies now running operations from the country. AI is not a side project inside this ecosystem: nearly half of all GCCs established since FY2021 were built with AI as a core focus from inception, more than 1,200 GCCs have already embedded AI and machine learning capabilities, and the talent base supporting that work has reached roughly 250,000 AI professionals across 250-plus dedicated Centres of Excellence.

📊
"From What AI Can Do to How to Govern It" Per the Nasscom-Zinnov report, GCC conversations have shifted from experimentation toward deployment across products, internal operations, and customer offerings — and 64% of GCC site leaders now hold dual mandates combining global functional ownership with site-level responsibility for mission-critical functions including cybersecurity and AI governance specifically.

That dual-mandate structure is exactly why GCCs are better positioned than most organizations to move quickly here, not worse. A GCC already answers to its global parent's governance expectations — often shaped by the EU AI Act, sector regulation in the parent's home market, or internal enterprise risk policy — while operating inside India's own emerging framework. Rather than building a separate "India AI governance" track, the more efficient move is extending the TPRM and vendor governance discipline GCCs have already built to cover AI systems specifically: the inventory-to-evidence muscle already exists, it just needs to be pointed at a new object.

An 8-Point Framework for Building Operational AI Governance Now

None of the eight points below requires standing up a parallel compliance function. Each one extends a workflow most GRC and TPRM programs already run — inventory, risk assessment, evidence, approval, monitoring, audit trail — to AI systems specifically, ahead of the sutras becoming an enforcement checklist rather than a policy aspiration.

1

AI System Inventory Mapped to Business Function

Catalogue every AI system — purchased, embedded inside a vendor product, or internally built — with a named owner and business purpose, not just a product name.

2

Regulatory Obligation Mapping

Cross-reference each system against DPDP Act obligations and the sector regulator already governing the business unit — RBI, SEBI, or IRDAI.

3

Risk & Impact Classification

Tier systems by the consequence of their decisions — credit, hiring, underwriting, safety — so governance effort concentrates where the stakes are highest.

4

Human Oversight & Escalation Thresholds

Define exactly where autonomous action stops and a named human reviewer takes over, particularly for agentic AI systems acting on an employee's behalf.

5

Bias, Fairness & Explainability Evidence

Run pre-deployment bias testing and maintain a retrievable, human-readable rationale for any AI-driven decision that affects an individual.

6

Third-Party & Vendor AI Accountability

Extend the same inventory and evidence discipline to vendor-supplied AI — accountability follows the deploying enterprise, not the vendor's disclaimer.

7

Continuous Monitoring & Reassessment Triggers

Watch for model retraining, use-case expansion, and vendor or subprocessor changes as events that route a system back for reassessment.

8

Audit-Ready Governance Evidence Trail

Keep the inventory, assessments, and monitoring record retrievable in a form that can be produced the day a regulator or institution asks for it.

Points two and six are where most Indian enterprises currently have the widest gap. Regulatory obligation mapping tends to happen informally, if at all, and vendor-supplied AI is routinely governed less rigorously than internally built systems — exactly backwards from what the Guidelines' accountability sutra requires, since the deploying enterprise carries the responsibility either way.

Building the Program: A Six-Step Playbook

Turning the framework into an operating capability starts with the AI systems already running in the business today, not with a perfect governance architecture designed before anything is inventoried.

AI Governance Build Checklist for Indian Enterprises

  • Start the inventory this quarter: Don't wait for the AI Safety Institute to define "high-risk" before cataloguing what AI is already in production.
  • Assign one owner per system: Reuse the accountability structure already built for vendor and third-party risk rather than creating a new one.
  • Map each system to the regulator you already report to: DPDP Act, RBI, SEBI, or IRDAI obligations, depending on the business function involved.
  • Layer bias, fairness, and explainability testing onto existing risk templates: Extend what already exists rather than building a separate AI-specific process from scratch.
  • Extend the same discipline to vendor-supplied AI: Don't let third-party AI escape governance just because it arrived through procurement rather than internal development.
  • Rehearse producing the evidence trail: Treat it as an audit dry run, so the first real request isn't also the first real test.

The step most organizations skip is the first one — starting the inventory before the framework feels finished. Waiting for AISI testing protocols or TPEC benchmarks to be finalized before cataloguing existing AI systems means losing the months in between, which is exactly the time that should be spent building the evidence base the Guidelines will eventually expect enterprises to already have.

Where Agentic AI Fits — Scaling Governance Across a Large AI Portfolio

A GCC or large Indian enterprise running dozens to hundreds of AI systems across global and domestic mandates cannot maintain a current inventory, a sutra-by-sutra compliance map, and an evidence trail through periodic manual review alone — the pace of AI adoption inside India's GCC ecosystem, in particular, outruns a quarterly audit cycle by a wide margin. This is precisely the kind of continuous, cross-referencing work agentic AI is well suited to, applied to the governance-building problem itself.

Continuous Inventory & Regulatory Mapping at Portfolio Scale

An agentic workflow can continuously discover new AI systems entering the portfolio — a new vendor feature, a newly embedded model, an internally built pilot — and cross-reference each one against the applicable sutra and regulatory obligation as it appears, rather than waiting for the next scheduled review to catch it. This extends the same operational discipline behind continuous AI monitoring as a governance requirement to the specific problem of staying current against a still-evolving Indian framework.

AI-Assisted Evidence Assembly Ahead of Institutional Review

Once the inventory and mapping exist, an agentic layer can assemble the supporting evidence — bias-testing results, human-oversight logs, monitoring records — into a form ready for a TPEC-style review or a sector regulator's request, well before that request actually arrives. This is the same forward-looking discipline behind Crest.Digital's approach to connecting AI compliance policy to retrievable evidence, applied specifically to a regulatory environment that is still forming its own testing protocols.

Human-in-the-Loop on Every Accountability Determination

What the agentic layer does not do is decide whether a system is compliant, whether an observed gap is acceptable, or who is accountable for a given outcome. The Guidelines' own accountability sutra keeps that judgment with a named human — an agent that both generates the evidence and decides what it means would collapse the very separation of duties the framework is built on. That division of labor mirrors how Crest.Digital frames accountability for AI-related decisions more broadly: automation handles the continuous, volume-heavy work of watching and assembling, while judgment on what it means stays with a person who can be named if a regulator asks who decided.

Enterprises and GCCs that already run mature vendor and third-party governance hold a genuine head start here — the underlying discipline transfers directly. What changes is the object being governed, and how much runway remains before "voluntary" becomes "expected as a baseline" the way it did with the DPDP Act.

Frequently Asked Questions

Not directly. The Guidelines take a voluntary, techno-legal approach built on self-certification and regulatory sandboxes rather than prescriptive mandates, and the government has assessed that a standalone AI law is not needed at this stage. But the Guidelines explicitly state that India's existing laws — the DPDP Act 2023, the IT Act 2000, consumer protection statutes, and sector-specific rules from the RBI, SEBI, and IRDAI — already apply to AI systems. Enforcement is arriving through the regulators enterprises already report to, not through a new horizontal AI statute, which means treating the Guidelines as optional reading is a mistake even though compliance with the Guidelines themselves is not yet mandatory.

The Guidelines are anchored in seven principles MeitY calls sutras: Trust Is the Foundation, People First, Innovation over Restraint, Fairness and Equity, Accountability (responsibility follows function, so the deploying enterprise bears primary responsibility for AI outcomes, not just the vendor), Understandable by Design, and Safety, Resilience, and Sustainability. Each sutra reads as a policy principle but translates into a specific operational obligation once an enterprise tries to demonstrate it is actually meeting it.

Start with an inventory. India's 2,100-plus GCCs cannot govern AI systems they have not catalogued, and nearly half of GCCs established since FY2021 were built with AI as a core focus from inception — meaning the AI footprint inside many centres is larger than a first informal count would suggest. Once the inventory exists, map each system against the sutras and the specific regulator the GCC already reports to, then layer risk classification, human oversight thresholds, and an evidence trail on top. GCCs that already run vendor governance or TPRM workflows have a structural advantage — the same inventory-to-evidence discipline extends naturally to AI systems.

Directly, and by design. The Guidelines do not create a parallel compliance track — they clarify that AI systems processing personal data remain fully subject to the DPDP Act 2023, that AI-driven credit decisioning and fraud detection fall under the RBI's existing IT governance and model risk expectations, that AI-driven trading and advisory tools remain within SEBI's existing algorithmic-trading regime, and that AI-driven underwriting sits within IRDAI's existing oversight. An enterprise that has already mapped its AI systems against these existing obligations is, in practice, already meeting a large share of what the sutras ask for — the gap is usually documentation and evidence, not a missing control.

Building and maintaining an AI system inventory, mapping each system against the right regulator, and assembling evidence across a large and constantly changing AI portfolio is not something a compliance team can sustain through periodic manual review, especially inside GCCs running dozens or hundreds of AI systems across global and local mandates. An agentic AI layer can continuously discover new AI systems entering the portfolio, cross-reference each one against the applicable obligation, and assemble supporting evidence ahead of a review. What it does not do is decide whether a system is compliant or who is accountable for an outcome — that judgment stays with a named human, informed by what the agent surfaced rather than replaced by it.

AI Governance India TPRM Platform India GCC Third Party Risk Management AI TPRM Platform Agentic AI