0tokens

Apply for AI Grants India

Financial support for innovators building the future of AI in India.

Apply now

Chat · ai compliance calendar india

AI Compliance Calendar India: 2026 Deadlines and Controls

  1. aigi

    India’s AI compliance landscape is not governed by a single “AI Act” or a standard quarterly filing to MeitY. Compliance depends on what your system does, whose data it handles, the sector in which it operates, and whether it affects people’s rights, money, safety or access to services. A useful AI compliance calendar India should therefore combine recurring governance work with trigger-based legal reviews.

    For builders, the goal is straightforward: know which obligations apply, assign an owner, preserve evidence, and review the system whenever its data, model, users or risk profile changes. This approach is more reliable than treating compliance as an annual paperwork exercise.

    What changed by 2026

    The Digital Personal Data Protection Act, 2023 (DPDP Act) is central to India’s AI governance conversation. Organisations using personal data in training, evaluation, personalisation, inference or monitoring should track the Act’s commencement and detailed rules, then update their controls accordingly. Requirements may differ based on whether an organisation is a Data Fiduciary, Data Processor or a notified Significant Data Fiduciary.

    Other obligations can arise from existing laws and regulators, including:

    • Information technology and cybersecurity rules, including incident response, logging, access control and intermediary obligations where relevant.
    • Sector regulation, such as RBI expectations for banks and regulated financial entities, IRDAI requirements for insurance, SEBI obligations for market participants, and health, telecom or transportation rules.
    • Consumer protection and advertising law, particularly where AI-generated claims, recommendations or pricing could mislead users.
    • Employment, accessibility, copyright and contract requirements, depending on the system’s use and data sources.
    • Export and customer requirements, including the EU AI Act or enterprise security questionnaires for Indian companies selling overseas.

    Do not assume that a government consultation, policy paper or voluntary framework creates a filing deadline. Verify each obligation against an official notification, regulator circular, contract or licence condition. For practical implementation, teams can also compare this workflow with Enterprise-Grade AI for Compliance Management in India.

    A practical 2026 compliance calendar

    Every week: monitor and triage

    Assign a compliance owner to review relevant updates from MeitY, CERT-In, sector regulators, the Data Protection Board when operationally relevant, and customer or procurement portals. Record the source, publication date, applicability, action required and owner in a change log.

    Engineering and product teams should also flag changes to prompts, models, vendors, datasets, user groups and deployment geography. A small change can create a new privacy, security or sector-risk assessment.

    Every month: review the AI inventory

    Maintain a live register of every material AI use case. At minimum, capture:

    • Business owner, technical owner and vendor.
    • Model, version, hosting location and connected systems.
    • Data categories, source, retention period and lawful purpose.
    • User population and affected third parties.
    • Human review points, known limitations and escalation path.
    • Applicable contracts, policies, regulator expectations and risk rating.

    Run a monthly access and logging review. Check that production data is not being sent to an unauthorised model provider, that secrets and personal data are protected, and that discontinued models or datasets are removed. Teams managing infrastructure can pair this with How to Automate Cloud Compliance Monitoring in 2026.

    Every quarter: test controls and vendors

    A quarterly review should test, rather than merely confirm, whether controls work. Sample outputs for accuracy, bias, unsafe content, privacy leakage and unacceptable recommendations. Recheck role-based access, retention, backups, incident contacts and vendor commitments.

    Review third-party providers for subprocessors, data location, training-on-customer-data terms, breach notification, deletion support, audit rights and service changes. Update the risk register when a model is fine-tuned, a new data source is introduced, or the system moves from internal assistance to customer-facing decisions.

    High-risk workflows should have a documented human override and an appeal or correction route. If multiple agents perform regulated actions, define permissions and approval boundaries; AI Agent Orchestration for Enterprise Compliance offers a useful way to think about those controls.

    Twice a year: run a formal impact assessment

    For systems used in credit, hiring, insurance, healthcare, education, public-facing identity, safety or large-scale profiling, conduct a deeper assessment at least every six months and before major releases. Document the intended purpose, necessity, foreseeable harms, affected groups, mitigations, residual risk and go/no-go decision.

    Validate whether notices and consent flows match actual processing. Check data-subject request handling, correction and deletion workflows, retention schedules, grievance escalation and evidence of vendor instructions. If the system serves European users or customers, maintain a separate EU AI Act workstream rather than assuming Indian compliance transfers automatically; see EU AI Act Compliance for Indian Startups: 2026 Guide.

    Annually: approve governance and evidence

    At least once a year, the board, founders or designated risk committee should review the AI register, material incidents, unresolved risks, regulatory changes, supplier concentration and budget for remediation. Refresh policies covering acceptable use, data handling, model development, security, human oversight and incident response.

    Commission independent testing for material systems where proportionate. Preserve an evidence pack containing approvals, assessments, dataset records, test results, model cards, contracts, access reviews, training records, incidents and corrective actions. A CA or compliance professional can help align this pack with wider business obligations; Indian CA Compliance: A Practical Guide for Businesses is a useful companion for that process.

    Event-based deadlines matter most

    Some of the most important compliance actions begin when an event occurs, not on a fixed date. Create a 24-hour internal escalation rule for suspected breaches, followed by the legally applicable notification analysis. Trigger a new review when:

    • A model or vendor changes materially.
    • Personal or sensitive data is added to training or prompts.
    • The system begins making recommendations or decisions about individuals.
    • A security incident, harmful output or user complaint occurs.
    • The company enters a new sector, state, country or customer segment.
    • A regulator, enterprise customer or auditor requests evidence.

    Do not invent routine filings that do not apply. Instead, map each real obligation to its source and deadline. For example, CERT-In directions may impose specific reporting and log-retention expectations for covered entities, while sector regulators and contracts may impose additional timelines.

    Build a compliance tracker that teams will use

    A spreadsheet is sufficient for an early-stage startup if it has clear fields and ownership. Use columns for requirement, source link, applicability, action, due date, recurrence, owner, status, evidence location and escalation. Larger teams can connect tickets, asset inventories, vendor registers and monitoring tools.

    Keep a decision log for assumptions. Record why a use case is classified as low, medium or high risk, who approved it, and what would cause reassessment. Automating reminders is helpful, but automation does not replace legal interpretation or accountable sign-off. For broader platform design ideas, see How to Automate Legal Compliance with AI in India.

    Common mistakes to avoid

    • Treating voluntary principles as statutory deadlines.
    • Copying a foreign AI compliance checklist without mapping Indian law.
    • Recording policies but not preserving test results and approvals.
    • Allowing vendors to use prompts or customer data for training by default.
    • Failing to identify a human decision-maker for high-impact outputs.
    • Reviewing models annually while ignoring production changes between reviews.

    A defensible calendar is evidence-driven, risk-based and connected to product release processes. Start with an inventory, identify the laws and contracts that actually apply, set recurring reviews, and create event-based escalation rules. Revisit the map as Indian rules and sector guidance develop through 2026.

    Apply for AI Grants India

    If you are building an AI compliance, governance or security product in India, apply to AI Grants India for potential funding, visibility and ecosystem support.

    Last updated 23 September 2026

AIGI may be inaccurate. Replies seeded from the guide above.