India_AI_Ethics_Accountability_bill_2025_Image-24-Aug-2026

Before It Becomes Law: A GRC Practitioner’s Guide to India’s AI Ethics and Accountability Bill, 2025

India’s AI Ethics & Accountability Bill 2025 – What It Means for You | CYBER COPS India
AI Governance · Indian Law · GRC Analysis

India’s First AI Law – Almost.
The AI Ethics & Accountability Bill, 2025 Decoded

India tabled its first dedicated Artificial Intelligence Bill in Parliament on 17 December 2025. It isn’t law yet – but if you work with AI, you need to understand what it proposes before it is.

📅 Published: 24 August 2026  |  Bill introduced: 17 December 2025 📝 Bill No. 59 of 2025 · Lok Sabha ✍ Neelabh Rai
⚠ Legislative Status Notice: The Artificial Intelligence (Ethics and Accountability) Bill, 2025 (Bill No. 59 of 2025) is a Private Member’s Bill. As of August 2026, it has not been enacted into law, has not been referred to a Standing Committee, and has not been debated on the floor. The Monsoon Session of Parliament (20 July – 13 August 2026) concluded without the Bill being taken up. This article is for informational and awareness purposes only and does not constitute legal advice.

1. Why Now? The Regulatory Void India Needed to Fill

For the better part of a decade, India’s approach to artificial intelligence was largely aspirational – strategy documents, advisory frameworks, and ministerial speeches. Nothing with teeth. Then, on 17 December 2025, BJP Member of Parliament Bharti Pardhi tabled the Artificial Intelligence (Ethics and Accountability) Bill, 2025 in the Lok Sabha – and for the first time in Indian parliamentary history, a dedicated AI Bill was placed before either House.

Let me put the significance of that in perspective before we get into the details: since 1952, India has passed exactly fourteen Private Member’s Bills into law – the last one in 1970. So no, this Bill is not going to become law tomorrow. But Parliament tabling it matters enormously, for the same reason that a draft RFP matters before a contract is signed: it signals intent, shapes conversations, and often gets folded into government-sponsored legislation.

📌 Analogy – The Traffic Signal Problem

Imagine a city that grew rapidly and built flyovers, underpasses, and busy intersections – but nobody had drawn the traffic rules yet. Everyone figured it out informally. That worked when there were a hundred cars. Now there are ten lakh. The AI landscape in India is exactly that. Generative AI went mainstream in late 2022. Indian adoption was explosive. But the legal architecture stayed at the level of honking and hand signals. This Bill is India’s first attempt to draw the traffic rules.

Three pressures converged to make this inevitable. First, algorithmic bias at scale – when AI systems make decisions on loans, jobs, or law enforcement, they don’t just inconvenience people, they can systematically disadvantage entire communities. Second, unaccountable surveillance – facial recognition systems and behavioural prediction tools were being deployed without any meaningful oversight framework. Third, and most critically, the growing realisation that voluntary guidelines simply cannot protect fundamental rights.

The MeitY India AI Governance Guidelines, released just weeks earlier in November 2025, had taken a “light-touch” approach – principles, not law. The Bill takes the opposite position: if we are serious about AI being fair and accountable, we need something you can be fined for.

2. What the Bill Actually Says – The Plain Language Version

The Bill covers the development, deployment, and use of AI technologies across India. Before we look at what it does, let’s look at what it defines – because definitions in law are never trivial.

Key Definitions to Know

🤖

Artificial Intelligence (AI)

Computer systems capable of performing tasks that ordinarily require human intelligence – including decision-making, language processing, and visual perception. Deliberately broad to capture both current and evolving AI systems.

⚖️

Algorithmic Bias

Systematic errors within AI systems that produce unfair or discriminatory outcomes. The Bill explicitly names this as a regulatory concern – a signal that equality protections are being extended to the algorithmic realm.

👥

Stakeholders

Developers, deployers, users, AND affected individuals or communities. Crucially, the people harmed by an AI system are recognised as stakeholders – not just the companies that built or ran it.

📌 Analogy – Who is a “Stakeholder” in a Bridge?

When a bridge is built, stakeholders include the civil contractor (developer), the toll operator (deployer), the commuters (users), and the residents living near it (affected community). The IT Act traditionally focused on the contractor and operator. This Bill says: the commuter who falls through a cracked railing also has rights and remedies. That’s a meaningful philosophical shift.

How the Bill’s regulatory architecture flows – from AI developer to citizen remedy:

AI Ethics and Accountability Bill – regulatory architecture flowchart Flowchart showing how an AI developer interacts with the Ethics Committee, how high-risk AI systems need prior approval, how bias leads to mandatory withdrawal, and how affected citizens can file complaints leading to penalties. AI developer / deployer Builds or operates an AI system Mandatory duties Transparency Disclose purpose, data & logic Bias audits Regular checks; diverse datasets Record-keeping Evidence of compliance High-risk AI? Surveillance / credit / employment YES Ethics Committee Prior approval required NO Standard deploy Self-compliance obligations Approved? YES Deploy With conditions NO Withdrawal Until corrected Complaint Citizen remedy File with Ethics Committee Penalty imposed Up to ₹5 crore + criminal Developer obligations Ethics Committee actions Approved / compliant path Enforcement / penalty path

3. The Ethics Committee for AI – India’s Would-Be AI Watchdog

The centrepiece of the Bill is the creation of a statutory Ethics Committee for Artificial Intelligence, constituted by the Central Government through a Gazette notification. This is not an advisory body in the tradition of NITI Aayog – it is envisioned as a regulator with real powers.

Who Would Sit on It?

  • 1 A Chairperson with expertise in ethics and technology
  • 2 Representatives from academia, industry, civil society, and government
  • 3 Specialists in law, data science, and human rights

The multi-stakeholder composition is intentional. AI governance cannot be left to technologists alone. A data scientist might optimise an algorithm for accuracy while a lawyer spots that it violates Article 14. A civil society representative might flag that “accuracy” was measured on a dataset that underrepresented Dalit women. The Committee is structured to ensure these tensions surface before harm occurs.

What Would the Committee Do?

  • 1 Develop and recommend ethical guidelines for AI technologies
  • 2 Monitor compliance with those ethical standards
  • 3 Review cases of misuse, bias, or violations of the Bill
  • 4 Promote awareness and capacity-building among stakeholders
  • 5 Investigate complaints of algorithmic bias and recommend penalties
  • 6 Grant prior approval for AI surveillance deployments
  • 7 Submit an annual report to the Central Government, laid before Parliament within six months
📌 Analogy – The Building Inspector for AI

Think of this Committee as the municipal building inspector – but for AI systems. You wouldn’t build a high-rise and ask people to move in without a structural certificate. Under this Bill, you couldn’t deploy a high-risk AI system in law enforcement or finance without the Committee’s ethical clearance. The difference from most regulators is the “before deployment” scrutiny for surveillance AI – it’s prior permission, not post-facto penalty.

The Committee would be funded through parliamentary grants – expenditures charged to the Consolidated Fund of India. This is significant because it signals the government’s intention for the Committee to be institutionally independent, not reliant on industry fees that could create perverse incentives.

4. What AI Developers Would Be Required to Do

If the Ethics Committee is the referee, developers are the players with the longest list of rules to follow. The Bill imposes detailed obligations designed to drag AI systems out of the “black box” and into the light.

Transparency Obligations

Developers would be required to disclose:

  • A The intended purpose and limitations of their AI systems – you can’t claim your credit-scoring AI is general-purpose when it was designed for a specific demographic
  • B The data sources and methodologies used for training – provenance matters because biased data produces biased AI
  • C The reasoning behind AI-driven decisions that affect individuals – this is essentially a statutory “right to explanation,” mirroring what the GDPR created in Europe
  • D Model architecture, training data sources, and bias-mitigation measures – documented before deployment (the Bill envisions “transparency by design”)
📌 Analogy – The Drug Insert Leaflet

Every medicine you buy comes with a package insert – active ingredient, mechanism of action, contraindications, side effects. Patients and doctors make informed decisions based on that information. The Bill essentially mandates the same for AI systems that make decisions about people’s lives: a “product insert” that explains how the system works, what it can’t do, and what errors it might produce. Right now, most AI deployers don’t even know what’s in the package.

Bias Audit Obligations

Developers must conduct regular bias audits to identify and mitigate systematic errors. They must ensure diversity and inclusivity in training datasets. And critically – if a system is found to exhibit significant bias, it must be withdrawn until corrective measures are implemented. This “recall” provision for biased AI is significant. It moves the cost of getting it wrong from the affected community back onto the developer where it belongs.

Record-Keeping

Developers must maintain records demonstrating compliance with ethical standards. For GRC professionals reading this – yes, that is an evidence management obligation. Documentation is not optional. Audit trails will matter.

5. High-Risk AI – Where the Bill Gets Its Sharpest Teeth

The Bill takes a risk-based approach, imposing the strictest controls on what it implicitly recognises as high-risk AI applications. Two domains receive the most detailed attention.

AI-Driven Surveillance

The Bill places explicit restrictions on AI in surveillance. Facial recognition systems, behavioural tracking tools, and other AI-enabled monitoring capabilities would be permitted only for lawful purposes and subject to prior approval from the Ethics Committee. This is not a post-facto check – it is a gate that must be passed before deployment.

In an Indian context, where civil society has repeatedly raised concerns about the unregulated expansion of facial recognition in public spaces – from airports to railway stations to public protests – this provision carries particular weight.

📌 Analogy – The Search Warrant Principle

India’s legal system has long required law enforcement to obtain a magistrate’s warrant before entering a private space. The Bill applies the same logic to AI surveillance: you need prior institutional approval before deploying a system that watches people. The Ethics Committee is, in this sense, the magistrate for algorithmic surveillance.

AI in Critical Decision-Making

AI systems used in law enforcement, financial credit assessment, and employment decisions are subjected to heightened ethical scrutiny. The Bill explicitly prohibits these systems from discriminating on the basis of race, religion, or gender. This is a direct extension of constitutional principles – Articles 14, 15, and 16 of the Indian Constitution – into the algorithmic domain.

⚠ REAL-WORLD SCENARIO – Why This Matters

Imagine a private bank deploys an AI-powered loan approval system. The model was trained on historical loan data. Historically, applicants from a particular region had lower approval rates – not because of creditworthiness, but because of systemic under-banking. The AI learns that pattern and continues it. Under this Bill, the bank would be required to audit for exactly this type of bias, ensure training data diversity, and withdraw the system if significant bias is found. A family denied a legitimate home loan because of where their surname signals they’re from would have recourse to the Ethics Committee.

6. Penalties – When Non-Compliance Has a Price Tag

Guidelines only change behaviour when someone believes they will be enforced. The Bill addresses this with a penalty framework that combines financial sanctions, licence actions, and criminal liability.

Type of Action What Triggers It Consequence
Financial Penalty Failure to comply with ethical guidelines or transparency obligations Up to ₹5 crore, scaled by severity of violation
Licence Action Serious or repeated violations of the Bill’s provisions Suspension or cancellation of licences
Criminal Liability Repeat or severe violations – particularly where fundamental rights are affected Criminal prosecution of responsible persons
Withdrawal Order AI system found to exhibit significant bias Mandatory withdrawal until remediation

The ₹5 crore ceiling will draw comparisons with the DPDP Act 2023, which goes up to ₹250 crore. The AI Bill’s penalty framework is less punishing financially, but the addition of criminal liability for individuals makes it more personally consequential for executives and decision-makers than pure corporate fines typically are.

“Any individual affected by AI misuse would have the right to approach the [Ethics] Committee, embedding accountability mechanisms directly into the AI lifecycle.”

7. An ISO 42001:2023 Practitioner’s Reading of the Bill

ISO 42001:2023 LI PERSPECTIVE

What a Lead Implementer Sees in This Bill

Having worked through ISO 42001:2023 – the international standard for AI Management Systems – the parallels between the Bill and the standard are immediately visible. But so are the gaps. Here is my honest assessment:

  • Ethics Committee ≈ Clause 5 (Leadership) + Clause 6 (Planning): ISO 42001 requires top management to establish AI policy and define roles. The Bill’s Ethics Committee is the external equivalent – a mandatory leadership body for AI governance when internal governance fails. If your organisation already has an AI policy under ISO 42001, the Committee becomes the external validator, not a replacement.
  • Bias audits ≈ Clause 9.1 (Performance Evaluation) + Annex A (Controls): Mandatory bias audits map directly to the performance monitoring and measurement requirements of Clause 9.1. Specifically, ISO 42001 Annex A.6 covers impact assessment – the Bill mandates this for high-risk systems by statute. If you’ve been treating this as optional, you now have legislative reinforcement.
  • Transparency by design ≈ Clause 8.4 (AI System Impact Assessment): The Bill’s pre-deployment documentation requirements align tightly with what ISO 42001 calls an AI System Impact Assessment. Document the intended use, the limitations, the training data provenance, and the bias mitigation before deployment. This is not new – ISO 42001 already requires it. The Bill would make it legally mandatory for high-risk systems.
  • Right to explanation ≈ Clause 4.2 (Interested Parties) + Annex A.8: ISO 42001 requires organisations to identify the needs and expectations of interested parties – including those affected by AI systems. The Bill’s statutory right to explanation is a codified version of this. Organisations already complying with ISO 42001 on explainability will have a head start.
  • The Gap – No Conformity Assessment Mechanism: ISO 42001 includes a clear conformity assessment path – internal audits, management reviews, and third-party certification. The Bill does not yet define an equivalent. It creates the Ethics Committee as regulator but does not specify whether ISO 42001 certification, or any other standard, would be recognised as evidence of compliance. This needs to be clarified before the Bill is enacted, or industry will be left guessing.
  • Recommendation for Organisations: Do not wait for this Bill to become law. Use ISO 42001:2023 as your readiness framework now. Every control you implement under the standard is a compliance asset the moment AI legislation arrives – and legislation will arrive, whether this Bill or the next.

How ISO 42001:2023 clauses map to the Bill’s provisions – where they align, and where the Bill goes further:

ISO 42001:2023 to AI Bill 2025 clause mapping Mind-map style diagram showing five ISO 42001 clauses on the left connecting to corresponding Bill provisions on the right, with alignment strength indicated by colour. A gap row at the bottom shows where the Bill has no ISO equivalent. ISO 42001:2023 AI Ethics & Accountability Bill 2025 Clause 5 – Leadership & AI policy Org must establish roles & governance aligns Ethics Committee (§3) Statutory external governance body Clause 6 – AI risk planning Identify & treat AI-related risks aligns Risk-based high-risk classification Surveillance, credit, employment Clause 8.4 – Impact assessment AI system impact evaluated pre-deploy aligns Transparency by design (§4–5) Document purpose, data, bias steps Clause 9.1 – Performance evaluation Monitor, measure, analyse, evaluate aligns Mandatory bias audits (§4) Regular checks; withdrawal on bias Clause 4.2 – Interested parties Identify needs of all stakeholders aligns Right to explanation (§5) Statutory remedy for affected persons No ISO 42001 equivalent Conformity assessment path absent gap ↗ Prior approval – surveillance AI Bill goes beyond standard (§6)

There is one area where I would argue the Bill goes further than ISO 42001 and appropriately so: the prior-approval requirement for AI surveillance. ISO 42001 handles this through risk assessment processes that are largely internal. The Bill externalises that checkpoint. For sensitive applications – facial recognition in public spaces, predictive policing, biometric profiling – an external approval gate is the right architecture. Organisations serious about responsible AI should be welcoming this, not dreading it.

8. What Should You Actually Expect – and When?

Private Member’s Bills in India have a notoriously difficult path. The track record is 14 passed in seven decades. That said, dismissing this Bill as inconsequential would be a mistake. Here is a realistic reading of what lies ahead:

Scenario 1 – The Bill Gets Absorbed

The most likely outcome is that the Bill’s provisions – particularly the Ethics Committee concept, the bias audit mandate, and the right to explanation – get absorbed into the Digital India Act (the anticipated successor to the IT Act 2000) or into a government-sponsored AI policy framework. This is how Private Member’s Bills typically influence law in India. The provisions live on; the original Bill does not.

Scenario 2 – Standing Committee Examination

The Bill could be referred to the Parliamentary Standing Committee on Information Technology, which would then consult industry, civil society, and technical experts. This process produces a detailed report that shapes subsequent government action. The Monsoon Session (July-August 2026) has concluded without the Bill being taken up, making the Winter Session 2026 the next significant checkpoint for any AI policy signal.

Scenario 3 – Direct Enactment

Unlikely but not impossible. If political will aligns – perhaps triggered by a high-profile AI harm event, a judicial direction, or India’s AI policy ambitions on the global stage – the government could take up the Bill’s framework and fast-track it. The India AI Impact Summit 2026 signals India wants to lead AI governance discourse for the Global South. That ambition and a domestic vacuum of enforceable AI law are not comfortable bedfellows.

Three realistic paths the Bill could take from here – and how each leads to the same compliance outcome:

Three legislative scenarios for the AI Ethics and Accountability Bill 2025 Flowchart showing Bill No. 59 of 2025 at the top branching into three scenarios: absorbed into Digital India Act, referred to Standing Committee, or direct enactment; all three converge on organisations needing AI compliance readiness. Bill No. 59 of 2025 Private Member’s Bill – Parliament Scenario 1 Provisions absorbed into Digital India Act Scenario 2 Standing Committee examination & report Scenario 3 Direct enactment (political will aligns) Most likely Possible Unlikely but not impossible AI compliance readiness required Regardless of which path the Bill takes Next checkpoint: Winter Session 2026 · India AI Impact Summit 2026
📋 WHAT ORGANISATIONS SHOULD DO TODAY

Regardless of which scenario plays out, the compliance direction is clear. Start now:


1. Inventory your AI systems. Know what you have, what decisions they make, and who is affected. You cannot manage what you have not mapped.

2. Conduct bias audits on high-risk applications. HR, credit, law enforcement, content moderation – if AI is making or influencing decisions in these areas, audit the datasets and the outputs for discriminatory patterns.

3. Build documentation hygiene. Model architecture, training data provenance, bias mitigation measures – document before deployment. This is an ISO 42001 requirement today and would be a legal obligation tomorrow.

4. Insert AI ethics clauses in vendor contracts. If you procure AI from a third party, the bias audit responsibility, the transparency obligation, and the right to explanation all flow through to you as the deployer. Your contract should reflect that.

5. Designate an AI compliance function. The DPDP Act created the Data Protection Officer role. AI legislation will likely create an equivalent. Build that function now – even informally – before it becomes mandatory and rushed.

9. Conclusion – The Signal, Not Just the Bill

The Artificial Intelligence (Ethics and Accountability) Bill, 2025 may or may not become law in its current form. But that’s almost beside the point. Its significance is what it signals: India’s Parliament has formally acknowledged that AI poses risks serious enough to require statutory intervention. That is not a small thing.

We are moving – slowly, but unmistakably – from a world where AI ethics was something companies put in their annual reports to a world where it has consequences attached to non-compliance. The EU moved first with the AI Act. China regulated algorithmic recommendations. India is finding its own path – one that balances the need for AI-driven economic growth with the constitutional guarantees of equality and non-discrimination that are not negotiable.

For anyone working in cybersecurity, GRC, data protection, or technology law in India – this Bill is required reading, not optional background. The frameworks it proposes – the Ethics Committee, bias audits, transparency by design, the right to explanation – will shape Indian AI governance for years, regardless of whether Bill No. 59 of 2025 is the vehicle that gets them there.

The question is not whether India will regulate AI. The question is whether your organisation will be ready when it does.

💡 Final Thought

When electricity was introduced in Indian homes, nobody handed out a rulebook for safe wiring. That came after enough fires. We have the opportunity with AI to write the wiring code before the fires start. That opportunity doesn’t stay open forever.

Neelabh Rai
Neelabh Rai
ASCL CCCI  |  BSI CLIP ISO 27701:2019 & GDPR  |  CQI/IRCA ISO 27001:2022 LA
ISO 42001:2023 LI  |  IRCA ISO 22301 LA  |  TISAX LA/LI (TÜV SÜD)
Diploma in Indian Cyber Law, Govt. Law College Mumbai  |  B.Tech IT (AKGEC UPTU)
Fellow IETE  |  EC Member IETE Noida  |  Founder, CYBER COPS India  |  14+ Years GRC
Senior Internal Auditor and Information Security Operations Specialist with 14+ years of experience in ISMS auditing, TISAX, business continuity management, and privacy compliance. Founder of CYBER COPS India (cybercops.in), a platform dedicated to cybersecurity awareness, Indian cyber law advisory, and digital forensics research since 2009.
© 2025–2026 CYBER COPS India  |  Researching Bits & Bytes for a safer cyberspace  |  cybercops.in

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.