THE LIABILITY VACUUM IN ARTIFICIAL INTELLIGENCE:
A COMPARATIVE ANALYSIS OF ACCOUNTABILITY FRAMEWORKS
WITH SPECIAL REFERENCE TO INDIA
ABSTRACT :
Artificial intelligence systems have shattered the foundational assumption on which liability law rests: that identifiable human agency lies at the proximate end of every harmful act. As autonomous systems make consequential decisions through processes that are neither transparent nor attributable to any singular actor, the existing architecture of Indian law — built on fault-based tort principles, contingent intermediary safe harbours under the Information Technology Act 2000, and a nascent data protection regime under the Digital Personal Data Protection Act 2023 — reveals itself as structurally inadequate rather than merely underapplied. This article defends the thesis that the juridical response to AI-caused harm must abandon the search for a proximate human tortfeasor and instead adopt a risk-allocation model that distributes accountability along the AI supply chain according to the capacity for riskcreation and the ability to benefit from deployment. Drawing on the constitutional principles of proportionality and informational autonomy articulated in Justice K S Puttaswamy v Union of India, the speech-protective doctrine of Shreya Singhal v Union of India, the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026, and the risk-stratification approach of the EU AI Act, the article proposes a tiered liability framework calibrated to autonomy level, foreseeability of harm, and the commercial beneficiary of AI deployment .
I. INTRODUCTION
When a self-learning recommendation algorithm amplifies misinformation that incites communal violence, when a credit-scoring model trained on historically biased data
systematically denies loans to marginalised communities, or when a synthetic deepfake generated by a generative AI platform destroys a private citizen’s reputation — the question
that law must answer is deceptively simple: who is responsible? The deceptiveness lies not in the question but in law’s confident, inherited assumption that the answer must be a person. That
assumption, always a legal fiction in the age of corporate entities, has become a structural failure in the age of autonomous machines. The rapid proliferation of AI-generated deepfakes and algorithmic decision-making systems demonstrates that these risks are no longer hypothetical but immediate and systemic. The governance challenge is not merely technical. It is constitutional. India’s digital legal architecture — the Information Technology Act 2000, the DPDP Act 2023, and the intermediary rules promulgated thereunder — was designed to regulate human actors who use
technology, not technology that acts with human-like autonomy. When that architecture is applied to AI systems, it produces not accountability but a vacuum: developers who disclaim
responsibility for emergent system behaviour, deployers who claim to be mere conduits, and regulators who possess broad notification powers but no statutory mandate to prescribe liability
for autonomous harm. This article proceeds as follows. Section II surveys the existing Indian legal framework and identifies the doctrinal points at which it fails to address AI accountability. Section III extracts and applies the constitutional principles established in Puttaswamy and Shreya Singhal to the AI liability problem. Section IV analyses the intermediary liability regime under the IT Act and
the 2026 Amendment Rules as applied to AI-generated content. Section V provides a comparative analysis against the EU AI Act and the US regulatory approach. Section VI
diagnoses the persistent legal gaps. Section VII proposes a tiered AI liability framework. The conclusion offers a normative argument for why Parliament, not the executive alone, must act.II. THE EXISTING INDIAN LEGAL FRAMEWORK: ARCHITECTURE
AND INADEQUACYA. Tort Law and the Phantom Tortfeasor
The common law of negligence, received into Indian jurisprudence and applied through the Law of Torts, predicates liability on the existence of a duty of care, breach of that duty by an
identifiable defendant, and causation linking the breach to the claimant’s damage. Each element assumes a human decision-maker whose conduct can be assessed against an objective
standard of reasonable care. Autonomous AI systems disrupt all three elements simultaneously. A deep learning model trained on data curated by one entity, deployed on infrastructure owned
by another, and used by a third does not ‘decide’ in any sense that doctrine has traditionally recognised. It processes. The process is opaque by design — its internal weights are not human reasons. There is, in the language of tort law, no cognisable act of the kind that can ground a duty relationship. India lacks a codified tort statute, and the common law position offers no doctrine of strict
liability for autonomous systems analogous to the rule in Rylands v Fletcher (which attaches to hazardous things accumulated on land). That doctrine requires a non-natural use and an
escape; it does not map onto the intangible harm caused by a recommendation algorithm. The result is a liability vacuum at the foundation of Indian private law.B. The IT Act 2000: Intermediary Safe Harbour and Its Structural Limits
Section 79 of the IT Act creates a conditional immunity for intermediaries from liability for third-party content hosted on their platforms. The immunity attaches provided the
intermediary does not initiate the transmission, select its recipient, or modify it; exercises due diligence; and, upon receiving ‘actual knowledge’ of unlawful content through a court order or
government notification, acts expeditiously to remove it. The safe harbour was originally designed for passive conduits — internet service providers and web hosts. Applied to AI, it
produces a perverse incentive: the more autonomous and opaque the AI-curated recommendation system, the more plausibly the platform operator can claim not to have
‘selected’ or ‘modified’ the content, and the stronger its immunity claim. The legislature compounded this inadequacy in 2023 by omitting Section 43A of the IT Act
through the DPDP Act, removing the only statutory provision that had previously imposed compensatory liability on entities that failed to implement reasonable security practices in
handling sensitive personal data. The omission, which transferred data-security accountability to the DPDP Act framework, created a transitional liability gap that a sophisticated AI actor could exploit during the period between the repeal of Section 43A and the full operationalisation of the DPDP Act .C. The DPDP Act 2023: A Consent Architecture Ill-Suited to Autonomous
ProcessingThe Digital Personal Data Protection Act 2023 constructs its accountability architecture on the concept of consent: a Data Fiduciary may process personal data only with the free, specific,
informed, and unambiguous consent of the Data Principal, or pursuant to a defined category of ‘certain legitimate uses’. The Act imposes meaningful obligations — security safeguards, data
minimisation, purpose limitation, breach notification, and mandatory erasure upon withdrawal of consent — and creates a sophisticated fiduciary-processor distinction that allocates
accountability between those who determine the purpose of processing and those who execute it. The DPDP Act’s framework is structurally sound for conventional data processing. It is structurally strained when applied to AI systems for two reasons. First, AI systems frequently derive inferences — creditworthiness scores, health predictions, recidivism risk assessments — from datasets to which individuals have consented for a different, specified purpose. The Act’s purpose-limitation principle prohibits this in theory; in practice, secondary inference is architecturally embedded in machine learning and nearly impossible to regulate through ex ante consent mechanisms alone. Second, while the Act imposes significant obligations on ‘Significant Data Fiduciaries’, including Data Protection Impact Assessments and independent audits, it leaves the criteria for classifying a fiduciary as ‘significant’ entirely to Central Government notification. An AI company causing widespread systematic harm may escape heightened obligations entirely if it does not meet an unpublished notification threshold .
III. CONSTITUTIONAL FOUNDATIONS: PUTTASWAMY, SHREYA
SINGHAL, AND THE AI LIABILITY PROBLEMA. Privacy as a Structural Constraint on AI Deployment
The nine-judge bench in Justice K S Puttaswamy (Retd) v Union of India reconstituted privacy not as a derivative liberty but as an independent fundamental right rooted in Article 21. Justice
Chandrachud’s concurring opinion is particularly instructive for AI governance: it identifies ‘informational privacy’ as a distinct strand of the right to privacy, encompassing an individual’s
ability to control data about herself, resist surveillance, and maintain a digital identity consistent with her autonomy.The constitutional significance of this formulation lies in its structural
implication: State or private action that subjects individuals to opaque, automated profiling without meaningful notice, without genuine consent, and without any mechanism for human
review constitutes an invasion of the fundamental right to privacy under Article 21, irrespective of whether it is performed by the State or a private actor operating in a regulatory space created
by the State. In Puttaswamy II (the Aadhaar judgment), the Court applied a proportionality test to data processing: any State-mandated collection and use of personal data must pursue a legitimate
aim, must be necessary for that aim, and must represent the least restrictive means of achieving it. Applied to AI liability, this constitutional proportionality standard demands that any
regulatory regime governing autonomous systems must not merely prohibit the worst abuses; it must require that the design and deployment of AI systems be calibrated to minimise privacy invasion. An AI system that achieves a commercial objective through disproportionate data collection violates Article 21 not only when it causes identifiable harm but structurally, by its
architecture. The DPDP Act, which permits the State to exempt its own instrumentalities from data-minimisation and erasure obligations on national security grounds, falls short of this
constitutional standard when applied to AI systems operated by or on behalf of the State.B. Shreya Singhal and the Doctrinal Toolkit for AI Speech Harm
In Shreya Singhal v Union of India, the Supreme Court struck down Section 66A of the IT Act on the ground that its open-textured prohibition on ‘grossly offensive’ online speech was
unconstitutional for want of definiteness — it chilled protected expression without providing the citizenry any fair notice of the conduct prohibited. The Court also read down Section
79(3)(b) to require that an intermediary’s safe harbour be lifted only upon a court order or competent government notification, not upon a private complaint. The substantive
contribution of Shreya Singhal to the AI accountability debate is its articulation of necessity and proportionality as constitutional constraints on any regime that imposes liability on
information intermediaries. This doctrinal inheritance constrains the design of AI liability law in two ways. First, any statutory or regulatory provision that imposes liability on AI developers or deployers for the speech output of their systems must be sufficiently precise to survive constitutional challenge: it cannot impose liability for ‘offensive’ or ‘dangerous’ content without defining those terms against a discernible standard. Second, any requirement that platforms proactively surveil and suppress AI-generated content inverts the Shreya Singhal logic — it transforms passive conduits into censors without judicial oversight. The 2026 IT Amendment Rules, which require Significant Social Media Intermediaries to deploy ‘reasonable and appropriate technical measures’ to verify whether user-uploaded content is synthetically generated, walk this constitutional tightrope. The Rules’ structural value lies in their specificity: they prohibit defined categories of unlawful synthetic content while preserving a safe harbour for platforms that comply — a design consistent with the Shreya Singhal framework. What remains measures, which reproduces the structural deficiency the Court condemned in Section 66A: a standard the regulated party cannot ex ante satisfy with confidence.C. The Press Freedom Dimension and AI-Generated Journalism
In Express Newspapers Pvt Ltd v Union of India, the Supreme Court affirmed that the freedom of the press under Article 19(1)(a) encompasses editorial autonomy, and that any restriction
must be reasonable, prescribed by law, and referable to a legitimate State interest under Article 19(2). As AI-generated journalism becomes commercially prevalent — automated reports,
synthetic anchors, algorithmic editorial curation — the question of whether the constitutional protection afforded to the press extends to AI-curated news content, and whether liability for
false AI-generated reporting can be imposed on the platform without violating Article 19(1)(a), acquires urgent practical significance. The 2026 Amendment Rules address synthetic
audiovisual content but are silent on AI-generated text. This silence is not innocuous: it creates an asymmetric accountability regime in which video deepfakes are regulated while
algorithmically fabricated written disinformation escapes the synthetic content framework entirely.IV. INTERMEDIARY LIABILITY AND THE SYNTHETIC CONTENT
FRAMEWORK: THE 2026 RULES ANALYSEDA. The Safe Harbour Applied to Generative AI
The Section 79 safe harbour was designed for passive hosts. Generative AI platforms are architecturally the opposite: they do not host pre-existing user content but actively generate
novel output in response to user prompts. The threshold doctrinal question — whether a generative AI platform ‘initiates’ the transmission of harmful content or merely provides the
‘tool’ that a user deploys — has not been judicially resolved in India. The answer has significant consequences: if the platform is the initiator, it loses the Section 79 immunity entirely; if the
user is the initiator, the platform retains it subject to expeditious takedown. The 2026 Amendment Rules partially resolve this ambiguity by creating a dedicated due diligence framework for intermediaries that enable or facilitate the creation of synthetically generated information. Under Rule 3(3), such intermediaries must deploy technical measures to prevent unlawful synthetic content, embed provenance metadata in permissible synthetic output, and prohibit users from suppressing or altering those metadata markers.The Rules reduce the takedown timeline upon actual knowledge from 36 hours to 3 hours and impose a 2-hour takedown obligation for complaints relating to non-consensual intimate imagery and impersonation. These are operationally significant reforms. They are, however, accountability rules for the aftermath of harm rather than liability rules that allocate compensatory responsibility for it. A victim whose reputation is destroyed by a widely circulated deepfake in the minutes before the 2-hour takedown clock begins to run has no statutory cause of action against the platform under the Rules .B. The Accountability Gap Between Regulation and Liability
The structural distinction between regulatory compliance obligations and civil liability is not a technicality. Compliance rules establish what platforms must do to avoid regulatory penalty;
they do not automatically create a private right of action for individuals harmed by platform failure. India’s AI governance architecture imposes obligations on Data Fiduciaries through the
DPDP Act and on intermediaries through the IT Rules, but neither instrument expressly creates a tortious cause of action for individuals harmed by autonomous AI systems. The Data
Protection Board of India, established under Section 18 of the DPDP Act as a fully digital regulatory body, has jurisdiction over data protection complaints but is not a civil court and
cannot award damages equivalent to the harm sustained. The gap between regulatory censure and compensatory justice is the liability vacuum at the heart of India’s AI governance architecture.V. COMPARATIVE ANALYSIS: EU AND US FRAMEWORKS AGAINST
THE INDIAN POSITIONA. The EU AI Act: Risk as the Organising Principle of Liability
The EU AI Act, enacted in 2024, represents the most comprehensive legislative attempt globally to create a risk-stratified governance framework for artificial intelligence. Its central
innovation is the substitution of human fault as the organising principle of liability with risk as that principle. Systems are classified across four tiers — unacceptable risk (prohibited), high
risk (stringent pre-market conformity obligations), limited risk (transparency obligations), and minimal risk (voluntary codes) — based on the nature of their deployment context rather than
the intent of their operators. This classification produces a form of strict liability for high-risk AI: a provider who deploys a biometric identification, credit-scoring, or criminal justice risk
assessment system that causes harm cannot escape liability by demonstrating that it exercised reasonable care; the very act of deploying a high-risk system without satisfying the conformity
requirements creates liability. The European Parliament’s 2020 resolution on civil liability for AI had called explicitly for strict liability for ‘high-risk AI systems’ and an insurance mandate for their operators. The enacted AI Act stops short of creating a direct civil liability right, but its Annex III (high-risk use cases) combined with the proposed AI Liability Directive establishes a rebuttable presumption of causation when a high-risk AI system causes harm that the defendant cannot rebut. The structural contribution of this approach is its recognition that the problem of AI
accountability is not primarily a problem of proving fault; it is a problem of attributing risk to the entity best positioned to manage it. This risk-creation logic — not negligence law’s proximate-cause logic — is the appropriate organising principle for AI liability .B. The United States: Sectoral Fragmentation and Executive Instability
The United States has approached AI governance through sectoral regulation and voluntary frameworks. The National Institute of Standards and Technology’s AI Risk Management
Framework (NIST AI RMF 1.0) offers a sophisticated playbook for AI risk assessment and mitigation, but it is voluntary and creates no legal obligation. Executive Order 14110 of 2023,
which imposed red-teaming and safety evaluation requirements on frontier AI models, was revoked in February 2025, illustrating the fundamental instability of executive-only
governance of a technology whose liability implications are multi-generational. The absence of a federal AI liability statute leaves victims of AI-caused harm dependent on state tort law,
consumer protection statutes, and existing federal anti-discrimination regimes — each designed for a pre-AI legal landscape. The US experience demonstrates the costs of regulatory
fragmentation: it produces inconsistent standards across states, incentivises forum shopping, and creates no coordinated mechanism for addressing cross-border AI harm.C. India’s Comparative Position: Regulatory Activity Without Liability
ArchitectureMeasured against these comparators, India’s position is one of regulatory activity without liability architecture. The 2026 IT Amendment Rules are sophisticated with respect to synthetic
content obligations — their deepfake-specific prohibitions, provenance-metadata requirements, and compressed takedown timelines address operationally significant harms. The DPDP Act’s consent framework, fiduciary obligations, and Data Protection Board are genuinely innovative institutional contributions. What India lacks, and what the EU AI Act
provides, is a statutory mechanism that translates regulatory non-compliance into compensatory civil liability. The EU’s conformity assessment system means that deploying a prohibited or non-compliant high-risk AI system is itself the wrong that founds liability. In India, a platform may violate every obligation imposed by the IT Amendment Rules — fail to
embed provenance metadata, fail to take down harmful synthetic content within the prescribed timelines, permit users to strip synthetic-content identifiers — and the regulatory consequence
is a monetary penalty payable to the Consolidated Fund of India, not compensation payable to the victim.VI. CHALLENGES AND PERSISTENT LEGAL GAPS
A. The Attribution Problem: Supply Chain Diffusion of Agency
The modern AI supply chain is deliberately fragmented: foundation model developers (who train the base system), fine-tuning operators (who adapt it for specific applications), API
deployers (who commercialise it), and end-users (who prompt it) each exercise partial influence over the system’s outputs. No single party exercises the degree of control that faultbased
liability law requires. This supply-chain diffusion of agency is not an accident; it is a structural feature of the commercial AI ecosystem that effectively distributes moral responsibility across
a network of actors while concentrating financial benefit in the model developer. India’s current framework — which regulates ‘Data Fiduciaries’ (those who determine the purpose of
processing) and ‘intermediaries’ (those who host third-party content) — was not designed for this supply-chain structure and maps imperfectly onto it.B. The Opacity Problem: Explainability Deficits and the Standard of Care
A negligence standard requires the court to assess whether the defendant’s conduct fell below the standard of a reasonable person in the defendant’s position. Where the defendant is an AI
system whose decision-making process is a sequence of mathematical transformations across hundreds of millions of parameters, no human expert can reliably reconstruct the causal chain
from input to output. This opacity problem is not merely an evidentiary inconvenience; it structurally undermines the intelligibility of the negligence standard as applied to AI harm. The
DPDP Act’s requirement of periodic Data Protection Impact Assessments for Significant Data Fiduciaries is a necessary but insufficient response: impact assessments record foreseeable risks at a point in time, but machine learning systems evolve their behaviour through continued training and cannot be assessed against a fixed standard of care.C. The Exemption Problem: Executive Discretion and Accountability Erosion
Both the DPDP Act and the IT Act vest broad discretionary powers in the Central Government to exempt entities from liability-generating obligations by notification — including the power
to exempt entire classes of Data Fiduciaries from core provisions of the DPDP Act34 and the power to exempt State instrumentalities from most data protection obligations on national
security grounds.35 Applied to AI systems operated by or on behalf of the State — predictive policing algorithms, algorithmic welfare eligibility systems, AI-assisted border management — these exemptions create a zone of State AI deployment that is insulated from any accountability mechanism. This outcome is constitutionally suspect in light of Puttaswamy’s proportionality requirement: a State AI system that invades the privacy of millions of citizens cannot constitutionally justify its exemption from accountability obligations merely by invoking the national security notification power.VII. PROPOSED FRAMEWORK: A TIERED AI LIABILITY MODEL
FOR INDIAA. Foundational Principles
The framework proposed here proceeds from three foundational principles derived from the constitutional and comparative analysis above. First, liability must be allocated to the entity
best positioned to manage the risk of harm, not the entity most proximate to the harmful act. Second, the standard of accountability must be calibrated to the degree of autonomy of the AI
system and the severity of the harm its deployment foreseeably occasions. Third, the framework must create private rights of action for injured individuals, not merely regulatory
penalties payable to the State — accountability without compensation is not justice.B. Tier Structure
Tier I: Prohibited Deployment (Absolute Liability)
AI systems whose deployment is categorically prohibited — including real-time mass biometric surveillance in public spaces, social scoring systems that determine access to public
goods, and AI systems used for predictive detention — should attract absolute liability for any harm caused, with no fault requirement and no exemption available. The prohibition should be
statutory, with a private right of action vested in any individual subjected to the prohibited system. The category should be defined by statute, not executive notification, to prevent
executive erosion of the prohibition over time.Tier II: High-Risk Deployment (Strict Liability with Insurance Mandate)
AI systems deployed in high-stakes decision-making contexts — credit scoring, healthcare diagnosis, criminal recidivism assessment, hiring, and welfare eligibility — should attract strict liability for providers and deployers. Liability should attach without proof of negligence upon demonstration that the AI system caused the harm in question. Providers and deployers of Tier
II systems should be required to maintain compulsory liability insurance, to conduct and publish mandatory algorithmic impact assessments before deployment, and to provide affected
individuals with a right to human review of adverse AI-assisted decisions. These obligations echo the constitutional proportionality standard of Puttaswamy II: the deployment of AI in
high-stakes contexts is a significant intrusion on individual autonomy, and the constitutional standard requires that it be accompanied by safeguards commensurate with that intrusion.Tier III: General AI Systems (Fault-Based Liability with Reversed Burden)
For AI systems outside the prohibited and high-risk categories, a fault-based standard remains appropriate, but the burden of proof should be reversed: once a claimant establishes that an AI
system caused identifiable harm and identifies the provider or deployer, the onus should shift to the defendant to establish that the system was designed, tested, and deployed in accordance with published technical standards and that the specific harm was not foreseeable through reasonable algorithmic impact assessment. This reversal addresses the evidentiary asymmetry
created by AI opacity: the claimant cannot access the training data, model architecture, or deployment parameters that would establish negligence; the defendant can. The reversal is
constitutionally grounded in the right to effective judicial remedy as a component of Article 21.Tier IV: AI-Generated Content (Platform Liability and Provenance Architecture)
For harms arising from AI-generated content — deepfakes, synthetic disinformation, AIassisted fraud — the 2026 IT Amendment Rules provide the regulatory foundation, but liability must
be extended beyond regulatory penalty. Platforms that fail to embed provenance metadata in synthetic content, that permit users to strip synthetic-content identifiers, or that fail to remove prohibited content within prescribed timelines should be liable in damages to injured individuals, not merely subject to monetary penalty under the Board’s jurisdiction. This extension is consistent with the Shreya Singhal framework: the safe harbour should be conditional not only on takedown compliance but on provenance compliance, and its loss should expose the platform to civil liability.C. Institutional Architecture
The tiered liability model requires institutional support that India’s current framework does not provide. Specifically, it requires:
(i) a dedicated AI Safety and Standards Authority empowered
to classify AI systems into tiers and to update those classifications as technology evolves;(ii)a mandatory algorithmic audit regime for Tier I and Tier II systems, conducted by accredited
independent auditors with access to training data and model architecture;(iii) an AI Liability
Fund financed through a levy on commercial AI revenues, to compensate victims of harm
attributable to AI systems where individual defendants lack the resources to satisfy judgments;
and(iv) a constitutional safeguard against executive exemption of State AI systems from Tier
I and Tier II liability, implemented through a parliamentary sunset clause requiring positive
legislative reauthorisation of any exemption every five years.These institutional recommendations are not aspirational; they are necessitated by the constitutional commitments
India has already made through Puttaswamy and Shreya Singhal.VIII. CONCLUSION
The liability vacuum in artificial intelligence is not a gap waiting to be filled by incremental legislative reform. It is a constitutional challenge. India’s Supreme Court has, through
Puttaswamy and Shreya Singhal, articulated a vision of human dignity that requires the State to ensure that technology deployment — whether by State actors or private entities operating
in State-created regulatory spaces — is proportionate, accountable, and subject to meaningful legal remedy. A legal framework that imposes obligations on AI platforms but denies victims a
civil cause of action, that classifies AI systems by executive notification rather than legislative criteria, and that insulates State AI deployment from accountability through broad security exemptions does not satisfy that vision. It preserves the form of accountability while evacuating its substance. The shift from fault-based to risk-allocation logic that this article defends is not a radical
departure from Indian legal tradition. It is the extension of an existing constitutional principle — that those who create serious risks bear the responsibility for managing them — to a domain
in which the traditional markers of agency, intent, and proximate causation have been rendered functionally incoherent by technological design. The question Parliament must answer is not
whether AI should be regulated but whether it should be governed — whether the human interests that India’s Constitution places at the centre of legal order will be extended to the age
of autonomous machines, or whether the liability vacuum will be institutionalised as the permanent condition of AI deployment in India. The answer, if Indian constitutionalism means what Puttaswamy says it means, is not in doubt. The urgency lies in the lag between constitutional commitment and legislative action — and it is a lag that compounds with every additional month of autonomous AI deployment in the absence of a framework that makes accountability real. While current regulatory efforts represent meaningful progress, their reliance on executivedriven mechanisms underscores the need for a comprehensive legislative framework to ensure sustained accountability.BIBLIOGRAPHY
Primary Sources — Legislation
Constitution of India (1950)
Information Technology Act 2000 (No 21 of 2000)
Digital Personal Data Protection Act 2023 (No 22 of 2023)
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as
amended by the Information Technology (Intermediary Guidelines and Digital Media Ethics
Code) Amendment Rules 2026 (Gazette Notification GSR 120(E), 10 February 2026)
EU Artificial Intelligence Act (Regulation (EU) 2024/1689) [2024] OJ L 1689Primary Sources — Case Law
Donoghue v Stevenson [1932] AC 562 (HL) Express Newspapers Pvt Ltd v Union of India AIR 1986 SC 872
Shreya Singhal v Union of India (2015) 5 SCC 1
Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1 (Puttaswamy I)
Justice K S Puttaswamy (Retd) v Union of India (2019) 1 SCC 1 (Puttaswamy II — Aadhaar)Secondary Sources — Journal Articles
Balkin J, ‘The Three Laws of Robotics in the Age of Big Data’ (2017) 78 Ohio St LJ 1217
Calo R, ‘Robotics and the Lessons of Cyberlaw’ (2015) 103 Cal L Rev 513
Hildebrandt M, ‘A Vision of Ambient Law’ in R Brownsword and K Yeung (eds), Regulating
Technologies (Hart 2008)
Pagallo U, ‘Vital, Sophia, and Co — The Quest for the Legal Personhood of Robots’ (2018) 9
Information 230
Solove D and Hartzog W, ‘The FTC and the New Common Law of Privacy’ (2014) 114 Colum L Rev
583Secondary Sources — Books
Zuboff S, The Age of Surveillance Capitalism (PublicAffairs 2019)
Pasquale F, The Black Box Society: The Secret Algorithms That Control Money and Information
(Harvard University Press 2015)Secondary Sources — Official Documents
National Institute of Standards and Technology, AI Risk Management Framework (NIST AI RMF
1.0, January 2023)
Ministry of Electronics and Information Technology (MeitY), Frequently Asked Questions on the IT
(Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 (10
February 2026)
European Parliament, Resolution of 20 October 2020 on a Civil Liability Regime for Artificial
Intelligence (2020/2014(INL))
Executive Order 14110 on the Safe, Secure, and Trustworthy Development and Use of Artificial
Intelligence (US, 30 October 2023)