The SC Draft Regulation on AI: Intersection with Existing Laws


An analysis of the Supreme Court’s Draft Regulations for the Use of Artificial Intelligence in Courts, 2026, examining its intersection with the Digital Personal Data Protection Act, Information Technology Act, and the BNS, BSA and BNSS, particularly in relation to data protection, cybersecurity, AI accountability, hallucinations, electronic evidence and human oversight.

Introduction

Recently, the Supreme Court issued a Draft titled “regulation for the use of Artificial Intelligence in Courts, 2026”1 (the Draft), which aims to introduce and regulate the use of artificial intelligence (AI) in Indian Courts. AI is a branch of computer science that attempts to replicate the behaviour of human intelligence by studying the patterns of problem-solving skills of the human brain to develop intelligent software and systems.2 The use of AI is growing in every field; its regulation is a prevailing concern that many countries are trying to address, and India is no exception. The application of AI becomes more complicated in the legal field, where decisions are highly subjective and vary among individuals based on their morals, values, and pre-established beliefs. The proposed Draft has considered this difficulty by recognising the AI as strictly subservient to human judgment and restricted its scope solely to an assistive capacity.3

The Draft introduction has considerable advantages because of the time-saving characteristic of AI, assisting the Indian legal system, which is overburdened mainly due to the insufficient number of Judges, legal professionals, infrastructure, etc. However, there are certain ethical concerns related to data protection, constitutional morality, accuracy, employment, cyber-attack, algorithm accountability, and numerous further concerns can be discovered during the operation of the AI system. However, for this, the Draft imbues the human primacy, transparency, accountability, data protection, and judicial independence, signifying that the rules are balancing the growing technology of computer science with the Indian constitutional values.

The present Draft consists of 10 chapters in toto, which cover the general principles governing the use of the AI, provide information about its usages, institutional mechanisms, regular audits, capacity building, and training. Moreover, Regulation 5 of the Draft gives primacy to the Rule of Law, subjecting the use of AI in the Indian legal system to the principles of the Constitution, existing laws, principles of natural justice, and the Bangalore Principles of Judicial Conduct. The Draft provides limited remedies to the aggrieved, but Regulation 53 of the Draft has enlarged the ambit by referring to the other laws for that purpose. This blog examines and analyses the intersection of the proposed Draft with the Digital Personal Data Protection Act, 2023 (DPDP Act), Information Technology Act, 2000 (IT Act), and the major criminal laws.

Draft AI regulations complementary with the DPDP Act and the IT Act

The Draft, being non-exhaustive, operate alongside the DPDP Act, the IT Act, and the applicable rules and regulations framed thereunder. Regulation 47 of the Draft requires that the AI system comply with the DPDP Act and the IT Act, which govern the protection of personal data and judicial information.4 The DPDP Act applies to data processed by “automated means”, i.e., any digital process capable of operating automatically in response to instructions.5 Similarly, the IT Act is the primary legislation governing electronic communications, transactions, and digital commerce in India.

The Draft underscores the principles of human primacy, transparency, accountability, and data protection, which are aligned with the objectives of the DPDP Act and the IT Act, thereby protecting processed digital personal data. The Draft includes an incorporation by reference clause under Regulation 3(2), wherein undefined terms in the Draft have been made pari materia to the meaning assigned in the DPDP Act and the IT Act. Regulation 3(1)(s) of the Draft makes an explicit reference to the DPDP Act by defining the term “data”, which refers to any information, facts, ideas, opinions, or instructions understood or processed by humans or computers as per Section 2(h), DPDP Act. Moreover, Regulation 3(r) refers to the IT Act for the definition of “cybersecurity”, which is defined under Section 2(nb), IT Act as safeguarding information and digital resources from unauthorised use, access, etc. Cybersecurity is one of the core principles highlighted in the Draft under Regulation 15 and Chapter VII, mandating the protection of the court data processed/stored through the deployed AI system, and mandatory cybersecurity audits for enhancing transparency and accountability. The IT Act complements this principle through its Chapter XI, penalising the act of data breach and cyber contraventions.

The Draft coincides with the DPDP Act on the principle of data minimisation, ensuring limited and purposeful data usage. Regulation 3(1)(t) read with Regulation 10 of the Draft mandates that only “necessary” personal data should be collected, processed, and retained by the deployed AI system. The Draft does not clarify what is “necessary”, but Section 4, DPDP Act provides for consensual and legitimate use of personal data and only for the lawful purposes, i.e. any purpose not prohibited by law. Moreover, Regulation 11 of the Draft imposes additional constraints by limiting the purpose to one as approved by the appropriate authority. Hence, where an AI system is deployed to allocate hearing dates, it would require only case numbers, the processing stage, and the court’s calendar. The additional data, such as Aadhaar numbers or the parties’ medical records, would violate the principle of data minimisation.

Regulation 7 of the Draft requires the AI system to clearly explain its working and decision-making, and imposes stricter restrictions on a black box AI, i.e. one that is incapable of such Explanation. This transparency and explainability can be guided by the scheme of Sections 11 and 12, DPDP Act, wherein the person whose data has been used (data principal) has the right to access the prescribed information, along with the correction and erasure of such data. The IT Amendment Rules, 2026 advance these accountability and transparency principles by imposing mandatory labelling, due diligence, and traceability obligations on intermediaries dealing with AI-generated or synthetically generated content.6

Regulation 20 of the Draft illustrates the circumstances where the use of AI is strictly prohibited. Subsequently, Regulation 21 provides for reporting to the AI secretariat regarding the violations of any of the prohibitions for appropriate action, including suspension of the deployed AI system. Furthermore, Regulation 3(1)(e) read with Regulations 3(1)(za) and 39, defines “AI incident” as an event where AI fails, malfunctions, or generates erroneous outputs breaching the data security or confidentiality, or otherwise harms an individual’s rights. In these circumstances, the AI secretariat will take appropriate remedial measures. Additionally, Regulation 43 of the Draft requires the courts, parties, and their legal representatives to disclose any material use of AI in judicial proceedings, ensuring independent responsibility for any AI-generated content.7

However, the Draft provides a limited mechanism under Regulation 52 to redress the grievance of the individual who suffered direct/indirect harm due to the violation of the prohibition under Regulation 20. In this regard, the DPDP Act provides guidance when an AI incident involves personal data, as Section 13 of the Act places absolute responsibility on the person who uses such data, i.e., the data fiduciaries, for safe-harbouring of the personal data for ensuring accountability. Further, the Digital Personal Data Protection Rules, 2025 (DPDP Rules, 2025) provide for penalties upon the person who breaches the obligation and responsibility regarding the maintenance of data. Thus, although the DPDP Act does not address every form of “harm” due to an AI incident, it offers a partial framework for cases involving a personal data breach. The Draft under Chapter VII mandates that AI systems must abide by the data protection rules and safeguard sensitive judicial data. In consonance with this, Section 43-A, IT Act provides for a scheme of compensation to the affected person due to failure to protect personal data. Additionally, Section 67-C, IT Act requires intermediaries (service providers) to preserve specified information, and failure to do so shall be punishable.

The Draft, outline the ethical deployment of the AI system, and the DPDP Act and the IT Act provide for the statutory remedial measures to some extent; hence, the two Acts can be said to be complementary to the Draft.

Draft AI regulations and major criminal laws

Regulation 53 of the Draft provides for the saving clause, clarifying that the Draft does not take away any remedies available under any other laws. The three newly enacted major criminal laws — the Nyaya Sanhita, 2023 (BNS), Sakshya Adhiniyam, 2023 (BSA), and Nagarik Suraksha Sanhita, 2023 (BNSS) are drafted progressively to accommodate the increasing use of AI within the criminal justice system.

Regulation 19 of the Draft provides for the permissible use of the deputed AI system for judicial and administrative functions, including case management, legal research, transcription, translation, accessibility services, document verification, and litigant assistance, while mandating human oversight for accuracy and accountability. This helps in saving time and enhances outcomes. However, the AI is not devoid of inaccuracies pertaining to bias and fairness. The AI works based on data fed into it and from previous experiences, making it more prone to internal bias, leading to discriminatory results. Hence, the deployed AI must be transparent about its reasoning, for instance where an AI system is used for legal research or document verification, the output generated must be capable of being traced back to the underlying reasoning to check the accuracy of the result so generated.

The BNS incorporates provisions addressing the concerns related to accountability, privacy, data protection, and the misuse of the deployed AI systems.8 BNS contains provisions that can establish accountability over the “user” of an AI-deployed system. Section 2(8) BNS, while defining “document”, incorporates the inclusion of any electronic or digital records which can be used as evidence, and Section 2(39) BNS incorporates a technology-related definition from the IT Act, thereby providing a foundation for addressing AI-related issues. For instance, the person accountable for outputs of such a deployed AI system can be made liable under Sections 318, 316 (cheating and criminal breach of trust), 336 (forgery), 356 (defamation), 353 (public mischief) and 252 (public servant using malicious report), where they deliberately manipulate the AI system for unlawful purposes. This may include altering AI outputs to give preference or to delay case scheduling, or manipulating the translation as to deceive parties, present fabricated AI-generated precedents, generate fake summons to deceive people, etc. However, it is pertinent to note here that the liability under BNS will arise only when there is intentional misuse of the deployed AI system rather than an inherent malfunction.

The Supreme Court and a few High Courts, such as the Gujarat and Andhra Pradesh High Courts, have highlighted the risk of AI hallucinations while using AI in drafting and researching.9 The Draft deals with such “hallucination” in Regulation 3(z) read with Regulation 8 of the Draft, wherein, in case of hallucination, i.e., generation of factually incorrect or non-existent result, the sole accountability rests on the officer who makes a decision based on such hallucinations. Hence, an AI -generated evidence becomes admissible only when they are verified and unfabricated as to methodology and facts on which its reasoning is based. This is supported by Regulation 3(zb) read with Regulations 35 and 19 of the Draft, which makes it mandatory for any output of the deployed AI system to comply with human-in-loop requirements, i.e., AI-generated outputs are subject to mandatory human review and verification, with final decision-making authority and accountability remaining with a human at all times.10

BSA acknowledges the submission of AI-generated evidence under Sections 60 and 63. Regulation 20(h) explicitly specifies that AI-generated evidence can be presented only after full disclosure of its AI-generated character. Hence, any AI-generated material can be presented in the court as evidence with Section 63 BSA certificate mentioning the details of the AI system used and what inputs were provided. Additionally, the opinion of the Examiner of Electronic Evidence (appointed under the IT Act) will be required as per Section 39(2) BSA.

BNSS facilitates the use of electronic means at investigation, inquiry, as well as trial stages under Section 105 (search and seizure), Section 532 (trial and proceeding in electronic mode) and Section 63 (summons). Further, first information report (FIR) and police reports are also allowed in electronic form under Sections 173 and 210. The digitisation of such data makes case management efficient and reduces the risk of tampering. Such digitised data can facilitate AI assistance for transcription, i.e., audio-video recorded statements converted into text form, or for translation, summarisation, defect scrutiny, and even for analytical purposes to a restricted extent as allowed by the Draft under Regulation 19.

Therefore, while BSA and BNSS make the deployment and use of AI systems efficient and regulated, BNS ensures that any misuse of such systems is punished. Thus, collectively, the three laws ensure that the objective of the Draft regulations is fulfilled by promoting the responsible use of AI to improve the functioning of the judicial system while establishing accountability and responsibility in the event of misuse or abuse.

Conclusion

The Draft has been introduced by the Supreme Court following the India-AI Impact Summit 2026 in March, hosted under India AI Mission with a focus on “AI for development and Impact”.11 The introduction of AI will be confined to assisting in administrative and clerical functions while limiting the adjudicatory functions to the judicial intelligence, thus harnessing emerging technologies without compromising the foundational values of the justice delivery system.

The two legal maxims — actus curiae neminem gravabit and actus legis nemini facit injuriam, make it important that the deployed AI system under the authority of law shall cause no prejudice or harm to anyone. The Draft acknowledges this by recognising its operation as supplementary to existing laws, which can fill up the gaps by providing substantive safeguards relating to cybersecurity, intermediary obligations, and partial remedial mechanisms in cases involving personal data breaches.

However, like every other policy, the biggest challenge would lie in its implementation. The success of this Draft will largely depend on the effective adaptation by the court personnel and other stakeholders in the judicial proceedings. In a country like India, where a significant technological divide still exists, and where people have relied on traditional human-driven methods for centuries, especially among court personnel, making the adoption of AI practically challenging. Though the Draft has sought to address this concern by separately providing for the training programs, the real test will be the effectiveness of these programs among the stakeholders, with the necessary skill and adaptability of the AI in the judicial system.

*5th year student (BA LLB Hons.), Dharmashastra National Law University, Jabalpur. Author can be reached at: shivam096-22@mpdnlu.ac.in.

**5th year student (BA LLB Hons.), Dharmashastra National Law University, Jabalpur. Author can be reached at: chanchal027-22@mpdnlu.ac.in.

11. Ministry of Electronics & Information Technology, Government of India, India AI Impact Summit 2026, IndiaAI Mission, available at <



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *