Article · Cross-Border, Fintech & Emerging Technology

For Directors · Collective Governance, Regulatory Warfare & Exit Readiness

The AI & SGI Liability Shield

What Indian boards must govern before the next hallucination, deepfake or training-data dispute - liability routes, the 2026 synthetic-content rules, training-data audits and a 90-day readiness plan.

18 min read

Executive summary

A generative-AI failure is not merely a technology incident. A hallucinated statement that harms reputation, a synthetic video that impersonates a person, an unlawfully used dataset, or a missed takedown deadline can create a combined exposure under the Information Technology Act and Rules, defamation law, the Copyright Act, consumer-protection law, contract, sectoral regulation and - where personal data is involved - the Digital Personal Data Protection framework.

For directors, the immediate question is therefore not whether an AI system can be sued. Legal proceedings will ordinarily be directed at the natural persons and legal entities that design, deploy, control, publish, operate or benefit from the system. The board's role is to ensure that the company has a documented governance architecture which assigns accountability, identifies high-risk uses, preserves evidence, and enables fast, lawful remediation.

This article reflects the legal position publicly available as at 8 September 2026. It should be read as a board-level governance guide, not as a substitute for advice on a particular incident, product or regulated sector.

I. When AI causes harm, who faces liability?

An AI model is not a separate juristic person. In a dispute involving allegedly defamatory, infringing, misleading, discriminatory or privacy-invasive AI output, the likely respondents are the company operating or deploying the tool, relevant users or publishers, vendors, and - where the statutory tests are met - responsible officers and directors.

Liability will turn on facts that boards should demand are documented from the outset:

  • Who selected, procured, trained, fine-tuned or configured the model?
  • Who supplied prompts, data, rules, retrieval sources and publishing approvals?
  • Was the output automatically published, human-reviewed, or merely used internally?
  • Did the organisation know, or reasonably ought it to have known, of recurring defects or foreseeable misuse?
  • What contractual allocation of risk exists between the company, its AI vendor, customers, users and data suppliers?
  • What preventive controls, monitoring, complaint-handling and remediation steps were actually in force?
An "AI did it" explanation is not a liability shield. It is more likely to trigger inquiries into governance, human control, foreseeable risk and the adequacy of safeguards.

The applicable legal mosaic

India does not yet operate under one comprehensive, generally applicable AI statute. Instead, an enterprise AI deployment may engage multiple overlapping legal regimes:

  • Defamatory or false output - civil and criminal defamation principles, IT Act and Rules issues, contractual claims. Board concern: publication controls, escalation and correction protocols.
  • Deepfake or manipulated synthetic media - IT Rules 2021 as amended in 2026, criminal law, privacy and personality-rights claims, platform terms. Board concern: SGI identification, labelling, takedown readiness, evidence preservation.
  • Copyright or database-content dispute - Copyright Act, 1957, contract and confidence obligations. Board concern: dataset provenance, licence analysis, output-risk controls.
  • Personal-data use in training or deployment - DPDP Act and Rules as they come into force, IT Act security duties, contracts. Board concern: notice and consent or other lawful processing analysis, retention and processor controls.
  • AI-led marketing or customer communication - Consumer Protection Act, CCPA guidance, ASCI code, contract. Board concern: human substantiation, claim approvals and complaint handling.
  • Regulated-sector AI use - RBI, SEBI, IRDAI, health, telecom or other sectoral requirements. Board concern: sector-specific governance, auditability and accountability.

A policy that merely says "use AI responsibly" is insufficient. The policy must be connected to operational controls, accountable officers, contracts, records, technical testing and board reporting.

II. The 2026 SGI Rules: what actually changed

On 10 February 2026, MeitY notified amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 through G.S.R. 120(E). The amendments came into force on 20 February 2026 and expressly address "synthetically generated information" (SGI), including deepfakes and other AI-generated or AI-modified material.

The notified definition covers audio, visual and audio-visual information that is artificially or algorithmically created, generated, modified or altered through a computer resource, made to appear real, authentic or true, and depicting a person or event in a manner that is, or is likely to be perceived as, indistinguishable from a natural person or real-world event.

A company cannot safely treat a synthetic voice, avatar, altered video, simulated executive message or generated product demonstration as a purely creative asset. If it fits the definition, its creation, upload, distribution and response process must be considered against the amended intermediary framework and other applicable law.

Do not repeat the "24-hour rule" myth

The 2026 framework should not be described as imposing a blanket 24-hour takedown requirement for AI content. The reported amendment framework replaces the former 36-hour timetable with a three-hour response window for an intermediary receiving a relevant court or government order; reporting also identifies a two-hour timeline for specified urgent categories.

For a board, the operational implication is more demanding than the headline: the company must be able to receive a valid order, verify authority and scope, locate affected content, preserve evidence, execute the required restriction or removal, notify necessary internal stakeholders and document the response within a compressed period.

Labelling, provenance and three distinct roles

The amendments introduce due-diligence obligations directed at synthetic material, including disclosure and labelling and provenance-related requirements, alongside enhanced responsibilities for intermediaries and significant social-media intermediaries. A board should distinguish three roles:

  • Intermediary or SSMI role - the organisation hosts, transmits or enables user-generated content and may need processes for notices, orders, due diligence, detection, labelling, user disclosures and rapid removal.
  • Enterprise publisher role - the organisation creates or distributes its own synthetic media, such as marketing videos, executive communications, training material or customer-support avatars. It may not be an intermediary for that content, but still faces risks under defamation, consumer protection, contract, privacy, IP and general law.
  • Enterprise user role - employees use third-party AI tools internally or externally. The company needs acceptable-use, approved-tool, data-handling, human-review and incident-reporting controls.

The same corporate group can occupy all three roles. A single generic "AI policy" rarely addresses each adequately.

III. The hallucination problem

A hallucination is an AI output that is false, fabricated, unsupported or materially misleading, often delivered with unwarranted confidence. If a chatbot tells a customer that a competitor is insolvent, falsely attributes misconduct to an employee, fabricates clinical or financial advice, or invents a contractual term, the risk does not arise only from model error. It arises from the organisation's decision to present the output as reliable, authoritative or fit for the relevant purpose.

The legal analysis will be fact-specific. Courts may examine the nature of the statement, whether it was communicated to a third party, the foreseeable audience, the degree of human review, representations made by the company, notice of prior errors, the speed and adequacy of correction, and the harm caused.

Risk-tiering public-facing AI

Boards should require a risk-tiering approach rather than identical controls for every use case:

  • Internal drafting assistant - confidentiality, inaccurate advice, IP leakage. Minimum controls: approved tools, a no-sensitive-data rule, human validation.
  • Customer-service chatbot - consumer misinformation, contractual misstatement, defamation. Minimum controls: retrieval-grounded answers, escalation to humans, transcript retention, complaints workflow.
  • Marketing content generator - greenwashing, misleading claims, IP infringement. Minimum controls: legal and brand approval before publication, source substantiation, content labels where relevant.
  • HR or recruitment tool - bias, privacy, employment disputes. Minimum controls: documented purpose, testing, a human decision-maker, adverse-impact review.
  • Financial, health or legal support tool - regulated advice, serious consumer harm. Minimum controls: sector-specific review, conservative guardrails, mandatory human supervision, audit logs.
  • Synthetic executive voice or video - fraud, impersonation, reputational damage. Minimum controls: written approval, provenance and label controls, dissemination restrictions, incident response.
The higher the impact on rights, reputation, money, health, employment or public trust, the less defensible it is to rely on unchecked automated output.

Incident response: the first 24 hours still matter

Although the SGI Rules do not create a universal 24-hour AI takedown deadline, every enterprise should have a 24-hour internal AI-incident protocol as a risk-management target. Within the first day, the designated response team should:

  • Stop further dissemination, disable affected prompts, workflows or integrations where justified, and preserve logs and content.
  • Determine whether the material is SGI, whether it is hosted by the company or a third party, and whether an applicable intermediary process has been triggered.
  • Assess defamation, privacy, IP, consumer, securities, sectoral and contractual exposure.
  • Correct or clarify material public misinformation through the appropriate channel, without making admissions before legal review.
  • Notify insurers, affected vendors, regulators, customers or individuals where a legal duty or contractual commitment applies.
  • Record the timeline, decision-maker, evidence, remediation and preventive changes.

The board should receive a post-incident report identifying not just what the model did, but which control failed: dataset, prompt, retrieval source, deployment setting, approval process, monitoring, vendor assurance or escalation.

IV. Training data: the legal audit that cannot be deferred

The phrase "unlicensed data" obscures several distinct legal issues. A defensible training-data audit separates at least five questions:

  • Copyright - is the material protected? Was it copied, stored, mined, reproduced or used in a way requiring permission, or does a statutory exception or fair-dealing position plausibly apply?
  • Contract - was the source accessed subject to terms prohibiting scraping, training, commercial reuse, redistribution or derivative use?
  • Confidentiality and trade secrets - did the dataset include confidential client material, source code, unreleased documents, proprietary databases or information subject to a non-disclosure obligation?
  • Personal data - does the corpus contain digital personal data, and are collection, notice, consent or other lawful processing conditions, retention and security arrangements supportable under the applicable DPDP framework?
  • Provenance and output risk - can the enterprise identify the source, licence, transformations, permissions, restrictions, deletion rights and downstream use of the content?

A "publicly available online" label is not a substitute for this analysis.

ANI v OpenAI: important, but not a blanket licence

The Delhi High Court's 2026 interim decision in the ANI v OpenAI dispute is a significant Indian development on AI training and copyright. Public reporting states that the single judge declined interim relief and considered the process of LLM training capable of falling within research and fair-dealing reasoning, while ANI has appealed the ruling and the matter remains contested.

Boards should avoid two incorrect conclusions. The first is that all AI training on copyrighted works is lawful in India: the reported decision arose from particular pleadings, evidence and an interim stage, an appeal is pending, and different facts, contracts, outputs or data categories can alter the analysis. The second is that no AI training is defensible without a licence: Indian copyright analysis remains fact-specific and must account for the work, use, copying, purpose, commercial setting, contractual restrictions, output similarity and available statutory defences.

The prudent approach is not a binary claim. It is to build an evidence-backed data-governance file before training, fine-tuning, retrieval augmentation or large-scale ingestion.

The training-data audit pack

Every material AI system should have a maintained Training and Retrieval Data Register with, at minimum:

  • Dataset or source name, owner or controller, and acquisition date.
  • Data category: copyrighted work, personal data, confidential information, public-domain material, open-source content or synthetic data.
  • Licence, permission, terms-of-use and territorial restrictions.
  • Intended purpose: model training, fine-tuning, retrieval-augmented generation, evaluation, testing or output grounding.
  • Personal-data assessment and the legal or contractual basis relied upon.
  • Data minimisation, retention, deletion and refresh schedule.
  • Security and access controls, and third-party vendor or processor information.
  • Output-similarity or memorisation testing, where relevant.
  • Legal owner, technical owner and approval date.

The register should be supported by copies of licences, archived terms, data-processing agreements, vendor attestations, risk assessments and technical records. If challenged, the absence of provenance often becomes more damaging than the underlying legal position.

V. DPDP exposure: AI is also a data-governance issue

Where an AI system processes digital personal data - through customer chats, employee records, call transcripts, biometric inputs, support tickets, training corpora, inference logs or evaluation datasets - the organisation must assess its obligations under the Digital Personal Data Protection Act, 2023 and its phased implementation framework. Key board questions include:

  • Is personal data necessary for the identified AI purpose, or can it be excluded, masked, aggregated or synthetically generated?
  • Do privacy notices, consent flows and internal records clearly cover the actual AI use, including training, fine-tuning, model evaluation and vendor access?
  • Have contracts with AI providers restricted secondary use, retention, cross-border access, subcontracting and model-training rights?
  • Can the company honour rights requests and locate data across prompts, logs, embeddings, vector databases and vendor environments?
  • Has the organisation assessed whether its scale, risk profile or data practices call for enhanced governance, including a data-protection impact assessment?

AI governance should be integrated into the privacy programme - not operated as a parallel innovation initiative with separate data assumptions.

VI. The board-approved AI & SGI liability policy

A useful policy is not a marketing statement or a list of aspirational ethics principles. It should create enforceable internal rules, approvals and escalation pathways covering, at a minimum:

  • Scope and taxonomy - define AI, generative AI, SGI, automated decision-making, high-risk use case, approved tool, prohibited data and external publication.
  • Governance structure - identify the board committee, executive owner, AI governance committee, legal lead, privacy lead, information-security lead, business owner and incident commander.
  • Use-case inventory and risk-tiering - require registration and approval before deploying material AI systems, with heightened review for external, high-impact or regulated use.
  • Data governance - require provenance, licence, privacy, confidentiality and retention assessments for training, fine-tuning, retrieval and evaluation data.
  • Human oversight - specify where human validation is mandatory, who may approve AI-generated external content, and when automated decisions are prohibited.
  • SGI controls - require creation, disclosure and labelling procedures where relevant, protection against impersonation, and processes to respond to platform, court or government directions.
  • Output safeguards - establish testing for hallucinations, bias, toxicity, defamation, IP similarity, prompt injection, security vulnerabilities and unsafe instructions.
  • Vendor governance - require due diligence, minimum contractual protections, audit rights, security commitments, incident notification, data-use restrictions and exit or deletion arrangements.
  • Incident management - set internal response targets, escalation criteria, evidence preservation requirements, legal privilege protocols and board reporting.
  • Training and enforcement - mandate role-based training and consequences for staff who upload confidential data, bypass approvals or publish un-reviewed high-risk output.

The policy must be operationalised

Board approval matters, but it is not enough. The policy must become operational through workflows embedded in procurement, product development, legal review, information security, privacy, HR, marketing and vendor management. A practical test is whether the company can answer these questions in 48 hours:

  • Which AI systems are in production, who owns them, what data do they use and where are they hosted?
  • Which public-facing materials were generated or materially altered by AI?
  • Which systems ingest customer, employee, client or confidential information?
  • Which vendors may use company data to train their models?
  • Which systems can generate content about identifiable people, regulated products or financial outcomes?
  • Can the company suspend a system, preserve logs, correct output and coordinate a lawful response immediately?

If the answer is "we need to ask several teams," the governance programme is incomplete.

VII. Vendor contracts: do not outsource accountability

Most organisations will acquire AI capabilities from cloud, software-as-a-service, model or data vendors. That does not eliminate the deploying company's exposure to customers, employees, regulators or counterparties. For material AI vendors, contracts should address at least the following:

  • Permitted purposes and express limits on vendor use of company, customer and employee data.
  • Whether prompts, files, logs, embeddings and outputs may be retained or used for training.
  • Data-location, security, encryption, access-control and sub-processor requirements.
  • Ownership or use rights in inputs, outputs, fine-tuned models and improvements.
  • Warranties concerning lawful sourcing, IP risk, security practices and compliance commitments.
  • Indemnities for IP infringement, confidentiality breaches, data incidents and regulatory claims, subject to negotiated caps and exclusions.
  • Audit, transparency and documentation rights sufficient for the company's own assurance obligations.
  • Incident-notification periods shorter than the company's external response commitments.
  • Assistance with takedown, correction, evidence preservation, deletion, export and exit.
  • Limits on unilateral product changes that can materially alter risk or data use.

Boards should insist on an exception register for non-negotiable vendor terms, identifying accepted risk, business justification, compensating controls, executive owner and review date.

VIII. A 90-day board readiness plan

Days 1–30: establish visibility. Appoint a senior executive AI owner and constitute a cross-functional AI governance committee. Create an enterprise inventory of AI systems, pilots, third-party tools, data flows, public-facing uses and synthetic-media assets. Immediately prohibit entry of confidential, client, privileged, trade-secret or personal data into unapproved public AI tools. Identify systems that function as intermediaries, host user-generated content or distribute SGI. Review existing crisis, IT-security, grievance and media-response plans against the 2026 SGI framework.

Days 31–60: control high-risk uses. Adopt the AI & SGI liability policy and a risk-tiered use-case approval process. Establish the Training and Retrieval Data Register and prioritise high-value or externally sourced datasets. Implement human-review gates for public, marketing, employment, financial, health and legal uses. Test public-facing systems for hallucination, impersonation, defamation, unsafe claims, bias, prompt injection and data leakage. Amend priority vendor contracts or implement interim data-use restrictions.

Days 61–90: prove readiness. Run a tabletop exercise involving a deepfake executive video, a defamatory chatbot output and a three-hour takedown order. Measure detection, legal assessment, executive escalation, platform response, correction and evidence-preservation times. Present a board dashboard covering use-case inventory, risk ratings, incidents, vendor exceptions, data-provenance gaps and remediation dates. Train directors, senior management, product, support, marketing, HR and procurement by role. Schedule quarterly oversight and an annual independent audit of the highest-risk systems.

IX. Questions directors should ask

  • How many AI systems are in use, and how many are public-facing or high-risk?
  • Which systems use personal, confidential or third-party copyrighted data?
  • Which material datasets lack a documented licence, permission, lawful-use analysis or provenance record?
  • What public AI outputs are subject to human approval before release?
  • How many hallucination, bias, IP, privacy, impersonation or misinformation incidents occurred this quarter, and how quickly were they resolved?
  • Can the organisation comply with a three-hour court or government takedown direction where the amended IT Rules apply?
  • What contracts permit vendors to retain or train on company data, and who approved those exceptions?
  • Which synthetic-media assets are in circulation, and what labels, provenance records and approvals exist?
  • What is the organisation's D&O, cyber and technology-errors-and-omissions insurance position for AI-related claims?
  • Which unresolved risks exceed the board-approved risk appetite, and what decision is sought from the board?

Closing perspective

The legal question following an AI failure will rarely be whether a machine "intended" harm. The inquiry will focus on the organisation's choices: what it deployed, what it knew, what it represented, how it used data, what safeguards it maintained, and how it responded when the risk materialised.

India's 2026 SGI amendments make the compliance environment more immediate for platforms and digital businesses handling synthetic content. At the same time, evolving copyright litigation, data-protection implementation and sectoral expectations mean that every board should treat AI governance as a standing enterprise-risk function - not an innovation side project.

A board-approved policy, a living system inventory, documented data provenance, role-based human oversight, tested response playbooks and disciplined vendor controls will not eliminate AI risk. They do, however, place the company in a materially stronger position to prevent harm, respond quickly and demonstrate responsible governance when scrutiny arrives.

Source notes

  • MeitY notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 on 10 February 2026; they entered into force on 20 February 2026. Public materials identify the notification as G.S.R. 120(E).
  • The amended framework addresses synthetically generated information, including AI-generated or altered audio, visual and audio-visual content that appears real, authentic or true.
  • Public reporting describes a three-hour response period for relevant court or government orders and a two-hour period for certain urgent cases; it does not support describing the regime as a universal 24-hour AI takedown mandate.
  • ANI v OpenAI remains legally dynamic: reporting indicates that ANI appealed a single-judge decision concerning its interim-injunction request, with the appeal listed for hearing on 14 September 2026.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Boards should consult qualified legal counsel for company-specific guidance.