DEV Community

Manu Shukla
Manu Shukla

Posted on • Originally published at ecorpit.com

AIGEG and TPEC in 2026: India built AI governance without an AI law

AIGEG and TPEC in 2026: India built AI governance without an AI law

Summary. The Ministry of Electronics and Information Technology constituted the AI Governance and Economic Group on 16 April 2026 and the Technology and Policy Expert Committee on 18 April 2026. AIGEG is chaired by Ashwini Vaishnaw, Minister of Electronics and Information Technology, Railways and Information and Broadcasting, with Jitin Prasada as vice chairperson. TPEC is chaired by the Secretary, MeitY. Both give effect to the India AI Governance Guidelines that MeitY released on 5 November 2025 under the IndiaAI Mission, built around 7 guiding principles and recommendations across 6 pillars. Neither body is a regulator, and neither creates a single new obligation for an Indian company deploying AI.

That is the finding worth acting on, and MeitY has said so plainly. S. Krishnan, Secretary at MeitY, framed the guidelines this way at the November 2025 launch: "Our focus remains on using existing legislation wherever possible. At the heart of it all is human centricity, ensuring AI serves humanity and benefits people's lives while addressing potential harms."

The contrast with Europe is the whole story. The EU AI Act carries administrative fines of up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15,000,000 or 3% for other breaches. India has created a coordination layer and an advisory committee. If you are building a compliance programme for Indian operations in 2026, AIGEG changes your reading list, not your control set.

What was actually constituted, and when

Much of the commentary treats the April announcements as new regulation arriving. The sequence shows something narrower: an institutional layer being assembled on top of a guidelines document, with statutory duties still coming from elsewhere.

Date What happened Instrument type
2023 Digital Personal Data Protection Act passed Statute, binding
5 November 2025 MeitY releases India AI Governance Guidelines Policy framework, non-binding
19 to 20 February 2026 India hosts the India AI Impact Summit in New Delhi Convening
16 April 2026 AIGEG constituted as apex inter-ministerial body Executive order, coordination
18 April 2026 TPEC constituted as standing expert advisory body Executive order, advisory

The guidelines themselves were drafted by a committee chaired by Prof. Balaraman Ravindran of IIT Madras, with members including Rahul Matthan, partner at Trilegal, Debjani Ghosh, distinguished fellow at NITI Aayog, Dr. Kalika Bali, senior principal researcher at Microsoft Research India, and Sharad Sharma, co-founder of the iSPIRT Foundation. MeitY's release describes four components: seven guiding principles it calls Sutras, recommendations across six pillars, an action plan mapped to short, medium and long-term timelines, and practical guidance for industry, developers and regulators.

Prof. Ajay Kumar Sood, Principal Scientific Adviser to the Government of India, put the design philosophy at the launch as: "The guiding principle that defines the spirit of the framework is simple, 'Do No Harm'. We focus on creating sandboxes for innovation and on ensuring risk mitigation within a flexible, adaptive system."

Sandboxes and adaptive risk mitigation are not the language of a prohibition regime. That was deliberate.

What the two bodies do, and what they do not

MeitY's own description divides the labour cleanly. AIGEG sets strategic direction and coordinates policy across government. TPEC translates technical and policy questions into advice for AIGEG, covering global developments, emerging technologies, risks and regulation.

AIGEG's stated purpose is to align the actions of ministries, departments, regulators and advisory bodies around one national strategy. MeitY says the constitution of AIGEG gives formal effect to recommendations in both the AI Governance Guidelines and the Economic Survey, the latter having identified the need for a coordinating authority capable of aligning AI deployment with labour realities and social stability priorities.

Read that carefully. The problem AIGEG was created to solve is fragmentation inside government, not non-compliance inside companies. Its membership is drawn from government across policy development, science and technology, security and economic affairs. There is no enforcement wing, no penalty schedule, no registration regime and no filing obligation.

TPEC has even less contact with your organisation. It is chaired by the Secretary, MeitY, and staffed with experts from academic research, the technology industry and digital policy, and it advises one body: AIGEG.

Neither has been given the power to issue a binding direction to a private company. Compare that with the Data Protection Board of India under the DPDP Act, which can. Our engineering playbook for the DPDP Act covers what that regime actually requires in code and architecture.

Where your obligations actually come from

If AIGEG imposes nothing, the practical question is what does. For an Indian enterprise running AI systems in 2026, binding duties come from instruments that existed before April.

Source Binding on private companies? What it reaches
Digital Personal Data Protection Act 2023 Yes Personal data used to train, fine-tune or prompt any model
Information Technology Act and rules made under it Yes Intermediary duties, content, takedown, due diligence
Sectoral regulators, for example RBI and CDSCO Yes, within sector Financial services and medical device or clinical AI
Consumer protection and advertising law Yes Claims made about what an AI product does
India AI Governance Guidelines No Principles, recommended practice, sandbox design
AIGEG and TPEC No Government coordination and expert advice

The pattern is that AI-specific risk in India is being handled by pointing existing regulators at it rather than by creating a new one. Krishnan said as much. For a bank deploying a credit model, the binding constraint is RBI supervision and DPDP, not the guidelines. We wrote up the banking side separately in our checklist for the RBI's data governance draft.

This has a practical consequence that gets missed: nothing about the April announcements resets a DPDP timeline, and nothing in them grants an extension. Teams treating AIGEG as a signal that Indian AI rules are "still being written", and therefore as a reason to wait, are reading the wrong instrument. The data protection clock was already running.

India's approach against the EU AI Act

The two jurisdictions have made opposite bets, and if you operate in both you are running two compliance models at once, not one.

Dimension India, as of July 2026 EU AI Act
Instrument Guidelines plus executive-order bodies Directly applicable regulation
Binding on private firms No, obligations flow from existing law Yes, on its own terms
Risk classification Not codified in a statute Codified, with prohibited and high-risk tiers
Penalties Under the underlying law, not the guidelines Up to EUR 35,000,000 or 7% of worldwide turnover
Central body AIGEG, coordinating, no enforcement power National authorities plus the AI Office, enforcing
Design intent Sandboxes and adaptive risk mitigation Ex ante conformity and documentation

An Indian company selling software into the European Union does not get to apply the lighter domestic posture to that product. The EU AI Act reaches providers placing systems on the EU market regardless of where they are established, which is why we treat it as an export-readiness question rather than a European one. We covered the current milestone in the EU AI Act changes landing in August 2026.

The reverse is also worth stating plainly, because vendors are already using it as a scare tactic: there is no Indian equivalent of the EUR 35 million fine, because there is no Indian AI Act to be fined under.

What this changes operationally

Very little in the next two quarters, and that is the honest answer. Three things are worth doing anyway.

Keep your AI inventory current, because you will eventually need it. Every serious governance regime, EU or otherwise, starts by asking which systems you run, what they decide, and on whose data. Building that register now is cheap. Reconstructing it under a deadline is not. The register is also what makes a DPDP data-principal request answerable when the model, not the database, is holding the personal data.

Map each system to the regulator that actually covers it. A hiring model, a credit model and a diagnostic model face three different Indian regulators and one common data protection statute. AIGEG's existence does not change that mapping. It may eventually make the mapping more consistent, which is the point of a coordination body.

Treat the guidelines as a design reference rather than a checklist. They were written by a committee with real technical membership, and the sandbox framing suggests where enforcement attention will go if it arrives. Building to them costs little and puts you ahead of a possible codification. Our note on governance layers for enterprise AI agents covers how this looks in an actual architecture.

The engineering judgement here is uncomfortable but useful: a coordination body with no enforcement power is a signal about direction, not a deadline. Budget accordingly.

The inventory that survives any regime

The one artefact worth building before the rules settle is a register of AI systems. Every governance framework published so far, Indian guidelines and EU regulation alike, begins by asking the same questions. Here are the fields that carry weight, and why each exists.

Field Why it matters Answers a question from
System name and owning team Nothing gets fixed without a named owner Every regime
Decision or output it produces Determines whether a human is affected by it EU risk tiering, sector regulators
Personal data consumed, and lawful basis Whether DPDP applies and under what consent DPDP Act 2023
Model and version, hosted or third-party Vendor exposure and change control Contractual flow-down
Human review point, if any Whether an automated decision is contestable DPDP, sector regulators
Markets it is deployed into Whether the EU AI Act reaches this product EU AI Act
Evaluation record and date What you can show when asked Every regime

Two fields do most of the work. "Personal data consumed, and lawful basis" is what makes a DPDP data-principal request answerable when the personal data sits inside a fine-tuned model rather than a table you can query. "Markets it is deployed into" is what tells you which of your systems are subject to European obligations that no Indian statute imposes.

Keep this in version control next to the code rather than in a spreadsheet a compliance team maintains separately. A register that drifts from reality is worse than none, because it produces confident wrong answers under audit. Fill it in as systems ship, not in an annual sweep.

What to watch next

Three developments would change this analysis, and none has happened yet.

A codification of the guidelines into statute or into rules under an existing statute would move the six pillars from recommended practice to binding duty. Nothing published so far commits the government to that step.

A sectoral regulator issuing AI-specific directions under its own powers would bind firms in that sector immediately, without any AIGEG involvement. This is the most likely near-term route, given MeitY's stated preference for existing legislation.

Movement on DPDP enforcement matters more to most Indian companies than anything AIGEG does, because DPDP is the statute that already binds them and already covers the data their models consume. We tracked the broader picture in our piece on India's sovereign AI push and the IndiaAI Mission.

India-specific considerations

For Indian firms serving domestic customers only, the compliance posture in July 2026 is unchanged from March 2026: DPDP plus your sector regulator, with the AI Governance Guidelines as voluntary good practice. Anyone telling you that AIGEG created a new filing requirement is selling something.

For Indian services firms and global capability centres delivering to European or American clients, the client's regime governs the deliverable. That has been true since before AIGEG and remains the larger commercial exposure. Contractual flow-down of EU AI Act obligations into Indian delivery contracts is now common, and it is enforceable against you as a matter of contract even though no Indian statute imposes it.

For firms building on Indian-language or India-specific datasets, the sandbox emphasis in the guidelines is a genuine opening. The framework was designed to allow experimentation, and the Principal Scientific Adviser said so on the record.

FAQ

What is the AIGEG?

The AI Governance and Economic Group is a high-level inter-ministerial body constituted by MeitY on 16 April 2026. It is India's central mechanism for AI governance policy development and coordination across government. Ashwini Vaishnaw chairs it, with Jitin Prasada as vice chairperson, and its membership is drawn from ministries across policy, science, security and economic affairs.

What does TPEC do?

The Technology and Policy Expert Committee, constituted on 18 April 2026, is a standing advisory body chaired by the Secretary, MeitY. It provides AIGEG with technical, legal and policy expertise on global developments, emerging technologies, risks and regulation. It advises AIGEG only, and has no direct relationship with private companies.

Does AIGEG create new compliance obligations for companies?

No. Neither AIGEG nor TPEC has enforcement powers, a penalty schedule, or a registration or filing regime. Both were constituted by executive action to coordinate government policy and supply expert advice. Binding duties on Indian companies continue to come from the DPDP Act 2023, the IT Act and sectoral regulators.

Does India have an AI Act?

No. India has the India AI Governance Guidelines, released by MeitY on 5 November 2025, which are a policy framework rather than legislation. MeitY Secretary S. Krishnan stated at the launch that the focus remains on using existing legislation wherever possible, which is the opposite of the European approach.

How does this compare with the EU AI Act?

The EU AI Act applies directly to companies and carries fines of up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, and up to EUR 15,000,000 or 3% for other breaches. India's framework binds no private company on its own terms and relies on existing statutes and sector regulators instead.

What are the India AI Governance Guidelines?

A framework MeitY released on 5 November 2025 under the IndiaAI Mission, comprising seven guiding principles called Sutras, recommendations across six pillars, an action plan on short, medium and long-term timelines, and practical guidance for industry, developers and regulators. A committee chaired by Prof. Balaraman Ravindran of IIT Madras drafted them.

Should Indian companies wait for AI regulation before investing in governance?

No, for a specific reason. The DPDP Act 2023 already binds you and already covers the personal data your models consume, so waiting does not pause anything. An accurate AI system inventory mapped to the regulator covering each system is useful under any future regime and cheap to build now.

Does the EU AI Act apply to Indian companies?

It reaches providers placing AI systems on the European Union market regardless of where they are established, so Indian firms selling into the EU are covered for those products. Indian services firms are also seeing EU AI Act obligations flowed down contractually by European clients, which is enforceable as contract.

How eCorpIT can help

We build AI system inventories and governance controls that hold up under whichever regime turns out to apply, mapping each model to the Indian regulator that actually covers it and to any EU AI Act obligations flowed down through client contracts. That work is engineering rather than paperwork: data lineage, consent handling aligned with DPDP requirements, evaluation records and audit trails built into the system. eCorpIT is a CMMI Level 5 certified technology consultancy in Gurugram working with Indian enterprises and global capability centres. If you are unsure which obligations genuinely bind your AI systems today, talk to our team.

References

  1. Press Information Bureau, Government constitutes AI Governance and Economic Group (AIGEG) to lead India's national AI governance strategy, Ministry of Electronics and IT, 16 April 2026.
  2. Press Information Bureau, Government constitutes Technology and Policy Expert Committee (TPEC), Ministry of Electronics and IT, 18 April 2026.
  3. Press Information Bureau, MeitY unveils India AI Governance Guidelines under IndiaAI Mission, 5 November 2025.
  4. MeitY, India AI Governance Guidelines, full report, November 2025.
  5. MeitY, Constitution of AIGEG, composition and terms of reference, 2026.
  6. MeitY, Constitution of TPEC, composition and terms of reference, 2026.
  7. Article 99: Penalties, EU Artificial Intelligence Act.
  8. Chapter XII: Penalties, EU Artificial Intelligence Act.
  9. Implementation timeline, EU Artificial Intelligence Act.
  10. High-level summary of the AI Act, EU Artificial Intelligence Act.
  11. MeitY, Report on AI Governance Guidelines development, public consultation, Ministry of Electronics and IT.
  12. IndiaAI Mission, IndiaAI, Ministry of Electronics and IT.

Last updated: 21 July 2026.

Top comments (0)