Introduction
Artificial Intelligence (AI) is rapidly transforming the healthcare sector in India. Hospitals, diagnostic centres, telemedicine platforms, and health technology companies increasingly use AI-based systems to assist in disease detection, medical imaging, treatment recommendations, patient monitoring, and healthcare administration. These technologies promise improved efficiency, reduced costs, and enhanced diagnostic accuracy. However, their growing role in clinical decision-making raises significant legal concerns regarding accountability when AI-generated recommendations result in patient harm.
Unlike some jurisdictions that have begun adopting AI-specific regulatory frameworks, India currently lacks a dedicated statute governing the use of AI in healthcare. Consequently, liability issues arising from AI-assisted medical decisions must be examined through existing legal principles relating to medical negligence, consumer protection, data protection, professional ethics, and information technology laws.
A central legal question emerges: when an AI-assisted medical decision causes injury to a patient, who bears responsibility—the doctor, the hospital, the software developer, the technology provider, or a combination of these stakeholders? The answer remains uncertain because traditional legal frameworks were developed in an era when medical decisions were made exclusively by human professionals. The increasing integration of AI into healthcare therefore presents significant interpretive challenges for Indian law.
This article critically examines the legal framework governing AI in healthcare in India, analyses liability allocation among various stakeholders, and evaluates the adequacy of existing laws in addressing emerging technological risks.
AI-Assisted Healthcare and Emerging Liability Challenges
Artificial Intelligence is no longer limited to administrative healthcare functions. Modern AI systems are capable of analysing radiological images, predicting disease progression, assisting in treatment planning, and providing preliminary diagnoses. While these technologies can improve healthcare delivery, they also create complex questions regarding responsibility when errors occur.
Consider a situation where an AI-powered radiology tool fails to identify an early-stage tumour visible on a patient’s scan. The treating doctor relies on the AI-generated report without independently reviewing the scan. As a result, treatment is delayed and the patient’s condition worsens. In such a scenario, several legal questions arise:
- Is the doctor negligent for relying on the AI output?
- Can the hospital be held liable for deploying the system?
- Does liability extend to the software developer that designed the algorithm?
- What happens if the error resulted from inadequate training data rather than software malfunction?
Indian law currently does not provide clear answers to these questions. Instead, courts would likely rely upon established principles of negligence, professional accountability, consumer protection, and data governance to determine liability.
The complexity of these issues demonstrates that AI should not be viewed merely as a technological innovation. It represents a fundamental shift in healthcare decision-making, requiring a reassessment of traditional legal doctrines.
Medical Negligence and AI-Assisted Decision Making
Traditional Standard of Care in India
Medical negligence in India is primarily governed by judicial precedents rather than comprehensive legislation. Courts generally assess whether a medical professional exercised the degree of care and skill expected from a reasonably competent practitioner in similar circumstances.
The Supreme Court’s decision in Jacob Mathew v. State of Punjab, (2005) 6 SCC 1, remains one of the leading authorities on medical negligence. The Court held that negligence arises when a medical professional fails to exercise reasonable competence expected from an ordinarily skilled practitioner.
The principle established in Jacob Mathew becomes particularly significant in the context of AI-assisted healthcare. The use of AI does not eliminate the doctor’s professional responsibility. Rather, AI functions as a decision-support tool that assists, but does not replace, clinical judgment.
If a doctor blindly follows an AI-generated recommendation without independently evaluating the patient’s symptoms, medical history, and clinical findings, a court may conclude that the doctor failed to exercise reasonable professional judgment. In such circumstances, liability may arise not because the AI made an error, but because the doctor failed to verify its output.
The Emerging Standard of Care
AI also raises a more complex question: could the failure to use highly reliable AI systems eventually amount to negligence?
As AI diagnostic systems become increasingly accurate and widely accepted within the medical profession, courts may begin to consider whether a reasonably competent practitioner should have utilised available AI-assisted diagnostic tools. This issue remains unresolved under Indian law, but it demonstrates how AI may gradually influence the standard of care expected from healthcare professionals.
Application of Kusum Sharma Principles
In Kusum Sharma v. Batra Hospital & Medical Research Centre, (2010) 3 SCC 480, the Supreme Court emphasised that doctors are expected to exercise reasonable care rather than achieve perfect results.
Applying this principle to AI-assisted healthcare suggests that doctors should not automatically be held liable merely because an AI system produced an incorrect result. Liability should arise only where the healthcare professional failed to exercise reasonable oversight, verification, or clinical judgment while using the technology.
Accordingly, Indian courts are likely to continue focusing on human conduct rather than technological failure when determining medical negligence claims.
Liability Allocation Framework Under Indian Law
One of the most difficult challenges presented by AI in healthcare is the allocation of liability among multiple stakeholders.
Liability of Doctors
Doctors remain the primary decision-makers in patient treatment. Consequently, they may be held liable where:
- They rely exclusively on AI-generated recommendations.
- They fail to verify AI outputs against clinical evidence.
- They ignore contradictory symptoms or test results.
- They fail to exercise independent professional judgment.
The presence of AI does not diminish the professional obligations imposed upon licensed medical practitioners.
Liability of Hospitals
Hospitals may incur liability under principles of institutional negligence and vicarious liability.
Potential grounds for hospital liability include:
- Deployment of unreliable AI systems.
- Failure to adequately train medical staff.
- Lack of oversight mechanisms.
- Inadequate quality assurance procedures.
- Failure to protect patient data.
Where a hospital knowingly adopts an AI system with recognised limitations or insufficient validation, courts may hold the institution responsible for resulting harm.
Liability of AI Developers and Technology Providers
Technology companies that design and market AI healthcare systems may also face liability under Indian law.
Potential grounds include:
- Defective software design.
- Algorithmic errors.
- Inadequate testing.
- Failure to disclose limitations.
- Misleading representations regarding accuracy.
The Consumer Protection Act, 2019 introduces product liability principles that may become relevant where defective AI systems cause injury to patients. If a developer falsely represents the reliability of an AI diagnostic tool or fails to identify foreseeable risks, liability may arise independently of any negligence by healthcare professionals.
Telemedicine Practice Guidelines, 2020 and AI-Assisted Healthcare
The Telemedicine Practice Guidelines, 2020 provide an important regulatory framework for technology-enabled healthcare services in India. Although the Guidelines were drafted before widespread adoption of advanced AI systems, they contain principles relevant to AI-assisted healthcare.
The Guidelines emphasise that Registered Medical Practitioners remain responsible for clinical decisions even when technology is used as an intermediary. The doctor must exercise professional judgment and ensure that medical advice is appropriate for the patient.
This principle has significant implications for AI liability. Even where an AI platform generates diagnostic recommendations, the treating practitioner remains accountable for reviewing and validating those recommendations before acting upon them.
However, the Guidelines do not specifically address autonomous or semi-autonomous AI systems capable of independently analysing medical information. Consequently, regulatory uncertainty exists regarding the extent of practitioner responsibility where AI systems perform substantial diagnostic functions.
This gap highlights the need for updated regulatory guidance addressing modern AI technologies in healthcare delivery.
Section 43A of the Information Technology Act, 2000 and Sensitive Health Data
Although India does not currently have a dedicated law regulating Artificial Intelligence in healthcare, Section 43A of the Information Technology Act, 2000 plays an important role in protecting patient information processed by AI systems.
Section 43A provides that where a body corporate possesses, deals with, or handles sensitive personal data and fails to implement reasonable security practices and procedures, resulting in wrongful loss or wrongful gain, it may be liable to pay compensation to the affected person. The provision imposes a legal duty upon organizations to maintain adequate data security standards.
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 further clarify that medical records and health-related information constitute Sensitive Personal Data or Information (SPDI). Since AI systems in healthcare depend upon large datasets containing patient histories, diagnostic reports, imaging records, and treatment information, hospitals and technology providers processing such information fall within the scope of these obligations.
The significance of Section 43A becomes particularly evident when AI systems rely on cloud-based storage or centralized databases. If inadequate cybersecurity measures expose patient records to unauthorized access, the healthcare institution may face liability regardless of whether the breach was caused by human negligence or technological vulnerability.
For example, if a hospital deploys an AI diagnostic platform that stores patient scans on an unsecured server and a data breach exposes thousands of medical records, affected patients may claim compensation under Section 43A. Thus, liability in AI-assisted healthcare extends beyond medical errors and includes failures in data governance and cybersecurity compliance.
Digital Personal Data Protection Act, 2023 and Algorithmic Processing
The Digital Personal Data Protection Act, 2023 (DPDP Act) represents India’s most significant legislative development in the field of data protection. Although the Act does not specifically regulate Artificial Intelligence, its provisions directly affect AI systems operating within the healthcare sector.
Healthcare AI systems process extensive amounts of personal data, including patient demographics, medical histories, laboratory results, prescriptions, and diagnostic images. Such processing must comply with the principles established under the DPDP Act.
The Act requires that personal data be processed for lawful purposes and, where applicable, based on valid consent. Healthcare providers and AI developers must ensure that patients are informed about the collection and use of their information. Data processing must remain limited to the purpose for which the information was originally collected.
However, the application of the DPDP Act to AI presents several unresolved legal challenges. AI systems frequently rely upon automated data analysis, predictive modelling, and machine learning processes that are not always transparent to users. Questions therefore arise regarding whether patients can meaningfully understand the extent of algorithmic processing occurring behind automated healthcare recommendations.
A further concern relates to algorithmic bias. AI systems trained on incomplete or unrepresentative datasets may produce inaccurate results for particular demographic groups. While the DPDP Act establishes obligations regarding lawful processing and data protection, it does not specifically address issues such as algorithmic fairness, explainability, automated decision-making, or AI accountability.
Consequently, the Act provides important safeguards for personal data but leaves significant regulatory uncertainty regarding the governance of AI-driven healthcare decisions. Future legislation may need to address these gaps through AI-specific compliance requirements.
National Medical Commission Ethical Framework and Professional Responsibility
The National Medical Commission (NMC) serves as the principal regulatory authority governing medical professionals in India. Although the NMC has not yet issued comprehensive AI-specific regulations, existing ethical principles continue to apply to healthcare practitioners using AI technologies.
Medical ethics in India are based upon principles of competence, patient welfare, confidentiality, professional accountability, and informed consent. These obligations remain attached to the licensed medical practitioner irrespective of the technologies employed during treatment.
The use of AI therefore does not transfer ethical responsibility from the doctor to the algorithm. A practitioner cannot defend a negligent decision solely by arguing that an AI system generated the recommendation. Ethical accountability continues to rest with the individual exercising clinical authority.
Informed consent assumes particular importance in AI-assisted healthcare. Patients should be informed where AI systems play a significant role in diagnosis or treatment planning. Transparency promotes trust and allows patients to make informed decisions regarding their healthcare.
Similarly, confidentiality obligations require healthcare professionals to ensure that AI systems do not compromise patient privacy. The ethical duty to protect sensitive medical information remains applicable even when data processing occurs through automated technological platforms.
Accordingly, AI should be viewed as a clinical support mechanism rather than a substitute for professional responsibility.
Important Judicial Decisions and Their Application to AI-Based Healthcare
Indian Medical Association v. V.P. Shantha
(1995) 6 SCC 651
In this landmark decision, the Supreme Court held that medical services generally fall within the scope of consumer protection law. Patients who suffer harm due to deficient medical services may seek remedies before consumer forums.
In the context of AI-assisted healthcare, this principle suggests that patients harmed by negligent use of AI-based diagnostic systems may pursue claims against healthcare providers under consumer protection mechanisms.
Jacob Mathew v. State of Punjab
(2005) 6 SCC 1
The Court clarified that medical negligence arises when a healthcare professional fails to exercise the degree of skill and care expected from a reasonably competent practitioner.
Applied to AI, the case indicates that doctors cannot blindly rely upon algorithmic outputs. If a practitioner accepts an AI-generated diagnosis without conducting appropriate clinical evaluation, liability may arise because the doctor failed to exercise independent professional judgment.
Kusum Sharma v. Batra Hospital & Medical Research Centre
(2010) 3 SCC 480
The Supreme Court emphasized that doctors are expected to exercise reasonable care rather than achieve perfect outcomes.
This principle is particularly relevant where AI systems generate incorrect recommendations despite reasonable precautions being taken by healthcare professionals. Liability should not arise merely because technology produced an imperfect result. Instead, courts should focus upon whether reasonable verification and oversight were exercised.
Justice K.S. Puttaswamy (Retd.) v. Union of India
(2017) 10 SCC 1
The Supreme Court recognized privacy as a fundamental right under Article 21 of the Constitution.
The judgment has significant implications for AI-based healthcare because these systems depend upon extensive processing of sensitive health information. Hospitals and technology providers must therefore ensure that AI deployment respects constitutional privacy principles and data protection requirements.
Practical Liability Scenarios
Scenario 1: AI Misdiagnosis
An AI radiology system fails to identify an early-stage tumour. The treating doctor relies entirely upon the AI-generated report and does not independently review the scan. The patient’s condition deteriorates due to delayed treatment.
Possible liability may arise against:
- The doctor for failing to exercise independent judgment.
- The hospital for inadequate supervision.
- The developer if the error resulted from a defective algorithm.
Scenario 2: Data Breach of Patient Records
A hospital adopts an AI platform that stores patient information in a poorly secured database. Hackers gain access to thousands of medical records.
Potential liability may arise under:
- Section 43A of the Information Technology Act, 2000.
- Digital Personal Data Protection Act, 2023.
- Constitutional privacy principles established in Puttaswamy.
Scenario 3: Algorithmic Bias
An AI diagnostic system is trained primarily on data from limited patient populations and produces inaccurate assessments for certain demographic groups.
Potential claims may involve:
- Product liability against developers.
- Institutional negligence against hospitals.
- Consumer protection claims by affected patients.
These examples demonstrate that AI-related liability frequently involves multiple stakeholders rather than a single responsible party.
Comparative Analysis: European Union and United States Approaches
European Union
The European Union has adopted the AI Act, which establishes a risk-based framework for regulating AI systems. Healthcare AI is generally classified as a high-risk category because errors may directly affect patient safety.
High-risk AI systems must satisfy requirements relating to:
- Risk management.
- Data quality.
- Transparency.
- Human oversight.
- Accountability mechanisms.
The EU approach recognizes that healthcare AI requires stricter regulatory supervision due to its potential impact on human life and health.
United States
The United States primarily regulates healthcare AI through the Food and Drug Administration (FDA). AI-enabled medical devices are subject to regulatory oversight before being introduced into the healthcare market.
The FDA focuses upon:
- Safety.
- Effectiveness.
- Performance monitoring.
- Post-market surveillance.
Unlike the European Union, the United States relies more heavily on sector-specific regulation rather than a comprehensive AI statute.
Position of India
India currently lacks an AI-specific healthcare regulatory framework. Existing laws relating to negligence, data protection, consumer rights, and professional ethics govern AI-related disputes. While these laws provide some protection, they do not fully address issues such as algorithmic accountability, explainability, and shared liability among multiple stakeholders.
Regulatory Gaps and Future Challenges
Several important regulatory gaps remain within the Indian legal framework.
First, there is no dedicated legislation governing AI in healthcare. Existing laws were developed before the emergence of advanced machine learning systems and therefore do not directly address algorithmic decision-making.
Second, Indian law does not clearly define liability where harm results from interactions among doctors, hospitals, software developers, and AI vendors. Determining responsibility becomes increasingly difficult when multiple actors contribute to a single outcome.
Third, there are no specific legal requirements regarding algorithmic transparency, explainability, or bias testing in healthcare AI systems.
Fourth, the current legal framework provides limited guidance regarding autonomous AI systems capable of performing diagnostic functions with minimal human involvement.
Addressing these challenges will require a comprehensive regulatory framework that balances innovation with patient safety and accountability.
Conclusion
Artificial Intelligence is reshaping healthcare delivery in India by improving diagnostic capabilities, enhancing efficiency, and supporting clinical decision-making. However, the increasing reliance on AI also creates significant legal challenges relating to medical negligence, data protection, privacy, professional accountability, and liability allocation.
Existing legal mechanisms, including the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, consumer protection laws, and principles of medical negligence, provide a partial framework for addressing AI-related disputes. Judicial decisions such as Jacob Mathew, Kusum Sharma, V.P. Shantha, and Puttaswamy continue to offer valuable guidance regarding professional responsibility, patient rights, and privacy protection.
Nevertheless, substantial regulatory gaps remain. Indian law does not yet provide clear answers regarding algorithmic accountability, allocation of liability among multiple stakeholders, or standards governing AI-assisted medical decision-making. As healthcare technologies become increasingly sophisticated, India may need a dedicated AI regulatory framework capable of ensuring patient safety while promoting responsible innovation.
References
Statutes and Regulations
- Constitution of India.
- Information Technology Act, 2000.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Consumer Protection Act, 2019.
- Digital Personal Data Protection Act, 2023.
- National Medical Commission Act, 2019.
- Telemedicine Practice Guidelines, 2020.
- European Union Artificial Intelligence Act, 2024.
Cases
- Indian Medical Association v. V.P. Shantha, (1995) 6 SCC 651.
- Jacob Mathew v. State of Punjab, (2005) 6 SCC 1.
- Kusum Sharma v. Batra Hospital & Medical Research Centre, (2010) 3 SCC 480.
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
Reports and Policy Documents
- NITI Aayog, Responsible AI for All: Approach Document for India.
- National Health Authority, National Digital Health Mission Framework.
- World Health Organization, Ethics and Governance of Artificial Intelligence for Health (2021).
- U.S. Food and Drug Administration, Artificial Intelligence and Machine Learning-Enabled Medical Devices Guidance.
- Organisation for Economic Co-operation and Development (OECD), Artificial Intelligence Principles.