AI Regulations For The State: Flexible Or Invasive?
Mudita Gupta, B.A. LL.B., Jindal Global Law School
ABSTRACT
As India rapidly adopts AI for State functions such as facial recognition, surveillance and predictive policing, the legal framework governing these technologies remains inadequate in terms of personal data protection. The new Digital Personal Data Protection Act of 2023 remains silent on the use of AI by the State in processing personal data. This paper’s core concern lies in the broad exemptions provided by the Act to the State in the disguise of “certain legitimate uses.” As per this, the Act allows government agencies to bypass fundamental notice and consent requirements in the name of sovereignty and public order. This leaves room for serious misuse and a large difference from the provisions the Act seeks to enforce on the private sectors, then from the public. Furthermore, the Act fails to provide citizens with any kind of redressal mechanisms against ambiguous algorithmic decisions, as a result of using FRT, predictive policing, etc. Finally, the paper presents recommendations to prevent these issues and to ensure that India’s digital transformation does not come at the cost of fundamental rights.
