India's AI Rules: Government Pre-Approval and What It Means for Launch Timing
India's MeitY advisory can require government authorisation before releasing certain GenAI systems publicly, with a Digital India Bill and sector sandboxes following. Plan your launch timeline accordingly.
India's approach contains one feature that few other jurisdictions have adopted, and it directly affects product timelines: government authorisation before public release of certain AI systems.
The framework is still forming — a MeitY advisory, a planned Digital India Bill, and a National AI Mission — but the pre-approval element is the part that changes how you plan.
The obligations as they stand
- Developers may need government authorisation before publicly releasing high-risk or generative AI systems.
- Deployers carry platform responsibility, particularly around misinformation control.
- Sector sandboxes in areas such as health and fintech are expected from mid-2026.
Why the timing point matters most
For most regulations, the question is what you must document. Here, the question is when you are allowed to ship.
If your launch plan assumes you can release a generative AI feature to Indian users on your own schedule, that assumption needs testing. An approval step that arrives late in a project can be far more disruptive than a documentation requirement, because it sits on the critical path.
A compliance obligation costs you effort. An approval gate costs you time. For a small company, time is usually the scarcer resource.
What SMEs should do
- Establish early whether Indian users can access your AI features. If the answer is yes and the feature is generative, treat authorisation as a project dependency rather than a formality.
- Build the approval step into your roadmap, not the launch checklist. Discovering it a fortnight before release is the expensive path.
- Watch the sandboxes. From mid-2026 these are likely to be the most SME-friendly route into regulated sectors, offering supervised testing without a full compliance apparatus.
- Take the misinformation duty seriously if you operate anything platform-like. That is where deployer responsibility concentrates.
Designing around an approval gate
If authorisation may sit on your critical path, architecture choices made early can save months later:
- Separate the AI feature from the core release. If the generative element ships behind a flag, the rest of the product is not held hostage to an approval timeline.
- Consider a staged rollout — internal, then limited, then public. Pre-approval concerns attach to public release, so the earlier stages can often proceed while you work through the process.
- Keep a non-AI fallback path for critical journeys. If a feature cannot launch on schedule, the product should still function.
None of this is India-specific good practice, which is rather the point. The same structure protects you anywhere an approval, audit or assessment could slip.
Reading the direction of travel
India is a draft-status jurisdiction on our map — the framework is not fully settled, and details will move. But the direction is clear enough to plan around: more scrutiny of public generative AI, sector-specific supervision, and a large domestic market that will make compliance worth the effort for most exporters.
If India is a growth market for you, the practical advice is to keep a watching brief and avoid architecting yourself into a position where an approval delay blocks your entire release.
Frequently asked questions
Does pre-approval apply to every AI product?
No. The advisory is aimed at high-risk and generative AI being released publicly. Internal tools and ordinary business software are not the target, but the boundary is not always crisp — take local advice before a public launch.
What are the sector sandboxes?
Supervised environments in sectors such as health and fintech, expected from mid-2026, designed to let organisations test AI systems under regulatory oversight. They are particularly useful for SMEs without in-house compliance teams.