Disclaimer

In accordance with the rules of the Bar Council of India, ProSquad Legal is prohibited from soliciting work or advertising in any manner. By clicking on "I AGREE", the user acknowledges the following:

  1. The user seeks information about ProSquad Legal, its practice areas, and its attorneys solely for personal use and understanding.
  2. The information provided on this website is made available only at the user's specific request. Any material downloaded or accessed is done at the user's discretion, and the transmission, receipt, or use of this site does not create a lawyer-client relationship.
  3. The content on this website does not constitute legal opinions or advice.

ProSquad Legal is not liable for any consequences arising from actions taken by the user based on the information provided on this website. For any legal issues, the user is strongly advised to seek independent legal counsel.

Technology adoption
and risk allocation.

AI governance and technology contracting: model risk assessment, output ownership, training data and vendor indemnities, alongside SaaS terms, escrow and intermediary obligations.

/ 02

AI Governance & Technology

AI risk usually arrives through procurement rather than through regulation.

Governance work covers a register of what is already in production, a sorting of use cases by consequence, evaluation before deployment, and monitoring that continues after it, with someone named against each of those steps.

The exposure that shows up first is rarely the model itself. Staff paste customer records into consumer tools, and that is likely to be processing under the Digital Personal Data Protection Act, 2023, depending on the data and the circumstances, whether or not anybody approved the tool. The same is true of the browser extension somebody installed to summarise meetings.

Pilots become production quietly. A tool built in a fortnight by one team ends up carrying decisions a department relies on, with no record of what it was tested against or who signs off when the output is wrong. Nobody decided to deploy it; it simply stopped being switched off, and by the time anyone asks the governance question there is a workflow depending on the answer.

Then there is the contracting, which decides more than the policy does. Data and exit terms in a SaaS agreement, the scope of an indemnity once a model has produced something nobody intended, and the due diligence conditions in the IT Rules, 2021 that a platform must meet to keep safe harbour under Section 79 of the Information Technology Act, 2000.

Contemporaneous records of governance decisions are commonly relied on later.


India does not have a dedicated statute governing artificial intelligence at the date of this page, and the framework is still being built. That is the accurate starting point, and it shapes how the advice has to be given. What governs an AI deployment today is the law that already applies to what the system does: the Information Technology Act, 2000 and the IT Rules, 2021 where a platform or intermediary is involved, the Digital Personal Data Protection Act, 2023 where personal data is processed, copyright for training material and generated output, contract for everything the parties allocate between themselves, and consumer law for the way a capability is described to the market. Sector regulators have begun issuing guidance of their own, and more of the operative detail is likely to arrive that way than through a single general statute. So a position is worth stating with the parts that rest on settled law separated from the parts that rest on a reasonable reading of an unsettled area.

Governance therefore carries weight that regulation currently does not. The durable protections are the ones you control: what you agreed with your vendor, what you documented before deployment, and what you can show about monitoring since.

A workable AI governance framework starts with a use-case inventory, because organisations rarely know how many models are already in production. Each use case is then sorted by consequence rather than by technical sophistication. A model that drafts marketing copy carries different risk from one that screens job applicants, prices credit, or moderates user content. Higher-consequence uses attract more control: a documented evaluation before deployment, human review that is real rather than nominal, defined escalation when output is contested, monitoring for drift, and a log good enough to reconstruct why a particular decision came out the way it did. Human review is frequently documented without being operationally effective. A reviewer handling high volumes, with a default of approval and no time to interrogate anything, produces a record of oversight rather than oversight itself, and that distinction is likely to be scrutinised.

Who owns model output is less settled than commercial teams assume. Copyright under the Copyright Act, 1957 is built around an author, and although the definition of author in Section 2(d) addresses computer-generated works, its application to the output of modern models is untested. Two things follow. Ownership as between you and your vendor can be allocated contractually, so that whatever rights exist end up where the commercial deal intends. And exclusivity in raw model output is an uncertain foundation for a business model, because a similar prompt may produce similar output for somebody else, and the vendor’s terms may say so in as many words. The same clause usually settles what the provider may do with your prompts and with the outputs it returns, which is a separate bargain from ownership and often the more valuable one. Read them together, because a broad ownership grant sitting above a broad usage right can leave the vendor with everything it wanted anyway.

So the record of human contribution is worth keeping wherever the output matters commercially. It costs almost nothing at the time and cannot be reconstructed afterwards.

Training and fine-tuning raise the question everyone would rather put off, which is what the licence to the underlying material actually permitted. Content licensed for a stated purpose does not automatically extend to training. Scraped material may be subject to the terms of the site it came from, and the enforceability of those terms varies. And India’s copyright exceptions under Section 52 are enumerated, including a fair dealing limb, rather than an open-ended fair use standard, which narrows the arguments available to anyone relying on them. Where training data contains personal data, the Digital Personal Data Protection Act, 2023 applies to that processing, including to the purpose for which the data was originally collected, and a purpose stated as service delivery may not extend to model training. We advise on what can be used, what needs a fresh licence, and what is better left out, and on keeping a provenance record for datasets while it is still possible to compile one.

The indemnity is where AI contracting genuinely differs. A conventional IP indemnity covers claims that the software infringes; it does not necessarily cover a claim arising from what the model produced after your team prompted it. We look for indemnity that extends expressly to output, for the carve-outs that would swallow it, being modification, combination with other material, use outside the documentation, or prompts characterised as misuse, and for whether the cap on liability leaves the indemnity worth having. Beyond infringement there is exposure to defamatory, discriminatory or otherwise harmful output, and the contract should say who carries it. Warranties deserve equal attention, because vendors will resist warranting accuracy and can often be expected to. You can reasonably ask for precision about what the service does, commitments on how customer data and prompts will be used, an undertaking that customer content will not be used to train models serving other customers unless expressly agreed, security commitments, and notice of material changes to the underlying model.

Swapping a model for a newer version can change output behaviour materially. That is a change control question, and it belongs in the contract rather than in a release note.

India has no general statutory right to an explanation of an automated decision at the date of this page, though that does not end the analysis. Sector regulators expect decisions in regulated activities to be explicable, consumer law reaches misleading descriptions of what a system does, due diligence in respect of algorithmic software can apply to entities notified as significant data fiduciaries, and employment or access decisions taken by a model create exposure where there is no record of how they were reached. Obligations around synthetic and manipulated content are an area of active rulemaking. Disclosure where a user would reasonably expect to know, and a record capable of supporting the decision if it is challenged later, are the usual working positions. Disclosure also has a commercial edge to it. A customer who finds out from somewhere else that a decision about them was made by a model reacts to the concealment rather than to the model, and that reaction is harder to answer than the original question was.

Most technology contracting is still ordinary contracting done carefully. In SaaS the clauses that decide disputes are the ones on data and exit: who owns customer data, what the provider may do with it, whether derived or aggregated data may be used to improve the service, and what is returned or deleted at termination and in what format. Service levels need a defined measure of availability, honest exclusions for maintenance, and a decision on whether service credits are the exclusive remedy for downtime, which they are frequently drafted to be. Suspension rights, renewal pricing and exit assistance follow close behind, and renewal pricing repays a hard look at signature, because bargaining power drains away once the data is inside the system. Disputes here frequently arise on exit and transition rather than on performance, and on how much of the customer’s operation has been built around a service it cannot easily leave.

Source code escrow works where software is licensed and deployed in your own environment. Release events and verification are the provisions that usually determine whether escrow is effective, and release events are commonly drawn to cover insolvency, cessation of support and material breach. For a hosted service it rarely restores continuity on its own, and transition assistance, data export in a usable format and step-in arrangements do more.

Where a business hosts or transmits third-party content, Section 79 of the Information Technology Act, 2000 offers protection from liability for that content. The protection is conditional. The conditions sit in the due diligence requirements of the IT Rules, 2021: publishing terms and a privacy policy, informing users of prohibited content, acting on legal orders and valid notices within the periods Rule 3 prescribes, appointing a grievance officer with published contact details, and running the grievance process the Rules require, which carries its own periods for acknowledgement and disposal. Further obligations apply to significant social media intermediaries, a classification that turns on a registered user threshold set by notification. Failing the due diligence conditions puts the Section 79 exemption at risk, which makes this compliance substantive rather than administrative housekeeping. It is also the compliance most often delegated to whoever built the website, with the result that the grievance officer named on a page left the company two years ago and the address collects nothing anybody reads. The obligations are continuing ones, so a policy published at launch and never revisited is worth less than it looks, particularly where the product has since added user messaging, reviews or file sharing without anyone treating those as content the business now hosts.

A product that hosts user content is likely to fall within the statutory definition of intermediary, which turns on receiving, storing or transmitting a record on behalf of another person.

When the counterparty is offshore, the enforcement analysis changes before the drafting does. A limitation of liability negotiated hard is worth little against an entity with no Indian presence and no assets here, so the real questions are which entity actually signs, whether a parent guarantee is available, where disputes are seated and under what law, and how an award or judgment would be enforced in practice. Standard vendor paper also assumes its home regime, which means the data terms often need rewriting for the Digital Personal Data Protection Act, 2023 rather than annotating. We negotiate those positions and advise on which of them are worth spending negotiating capital on.

How we help

  • AI use-case inventory & risk classification
  • AI governance policies & deployment review
  • Training data licensing review
  • AI vendor terms, warranties & indemnities
  • SaaS, licensing & subscription agreements
  • Service levels, support & exit terms
  • Source code escrow & continuity arrangements
  • Intermediary compliance under the IT Rules, 2021

The framework we work within

Information Technology Act, 2000
Intermediary liability and the conditional safe harbour under Section 79.
IT Rules, 2021
Due diligence, grievance officers, takedown timelines and obligations of significant intermediaries.
Copyright Act, 1957
Authorship and ownership, licensing of training material, and the enumerated exceptions in Section 52.
Digital Personal Data Protection Act, 2023
Processing of personal data in training, inference and product telemetry.
Consumer Protection Act, 2019
Misleading claims about what a product or automated system can do.
No dedicated AI statute
At the date of this page, AI is addressed through existing law and sector guidance rather than a dedicated statute.

Questions we are often asked

Between you and your vendor, whoever the contract says, which is why the clause is worth reading. The harder question is whether anyone owns it as copyright at all. The Copyright Act, 1957 is built around an author, and although the definition of author in Section 2(d) addresses computer-generated works, its application to the output of modern models is untested. So ownership or a broad licence from the vendor is worth securing, a record of the human contribution is worth keeping where the output is commercially important, and a business model that depends on exclusivity in raw output rests on an uncertain footing.

Start by checking whether it covers output at all. Many indemnities cover claims that the service infringes, which is a different thing from a claim arising out of what the model generated in response to your prompts. Then read the carve-outs, because modification, combination with other material, use outside the documentation and misuse of prompts can between them remove most of the protection. Then check the liability cap, since the cap determines the practical value of the indemnity. Harmful and defamatory output should be dealt with expressly.

The value of escrow depends on how the software is deployed. Escrow works well for software licensed and deployed in your own environment, where the deposited code and a verification exercise get you to a running system. A hosted service depends on infrastructure, configuration, third-party components and live data that escrow does not deliver, so code alone rarely restores continuity. Where the service is genuinely business-critical, transition assistance, regular data export in a usable format, and defined step-in or wind-down obligations are the provisions that do the work. Those deliver more than a deposit nobody has ever tested.

No. It is conditional, and the conditions are the due diligence obligations in the IT Rules, 2021. That means publishing terms and a privacy policy, telling users what content is prohibited, acting on court orders and valid government notices within the periods Rule 3 prescribes, appointing a grievance officer and publishing the contact details, and actually operating the grievance process rather than listing it on a page. Additional obligations apply to significant social media intermediaries, a classification that turns on a registered user threshold set by notification. Failing the conditions puts the protection at risk, so compliance here is substantive rather than administrative.

Facing something in
ip, tech & data?

Every enquiry is confidential. Tell us what you’re facing and our team will come back to you.

Get in Touch