Developer
What is Developer
A developer, in ordinary usage, is any person or organisation that creates a new product or system. In the technology domain, the term has acquired a specific juridical character. A developer refers to any natural person, legal entity, public authority, or other body that designs, creates, trains, modifies, or builds a software or artificial intelligence (AI) system and places it on the market or makes it available to users, whether for commercial gain or without charge. The developer's function is both technical and legal: it shapes the system's architecture, training data, algorithms, outputs, and operational parameters, and in doing so assumes primary responsibility for the safety, accuracy, fairness, and legality of the system it produces.
The concept of a developer in technology law is closely linked to the idea of a duty of care. Because the developer determines what a system does, how it processes data, and what outputs it generates, it occupies the position in the technology supply chain most capable of preventing foreseeable harm.[1] Every major AI governance framework from the EU AI Act[2] to the India AI Governance Guidelines places the heaviest compliance and accountability obligations on the developer.
The term is not limited to individual software engineers who write code. It encompasses organisations that commission AI systems built by third parties and release them under their own names or trademarks, research institutions that develop foundational AI models for public release, and entities that fine-tune or adapt existing AI models for specific commercial applications. In all such cases, the entity that controls the design, development, and market placement of the system bears developer responsibilities.
Official Definition of Developer
This section discusses the term as defined in authoritative legal and official sources. India does not, as of March 2026, have a standalone statute that defines the term "developer" in the technology or AI context. The definitions in force are drawn from related legislation, official government documents, international instruments, and case law.
"Developer" as Defined in Legislation(s)
No standalone Indian statute defines "developer" in the technology or AI context. The Information Technology Act 2000, which remains the backbone of digital governance in India, was enacted before AI technologies became widespread and does not use the term "developer" or directly address the obligations of entities that design or build AI systems.[3] The Digital Personal Data Protection Act 2023 and the Consumer Protection Act 2019 impose obligations on entities performing the developer function but describe them through different terminology.[4][5]
In comparative jurisdiction, The European Union AI Act provides the most comprehensive statutory definition applicable to developers operating in or accessing the European market.[6]
Legal Provisions Relating to "Developer"
The following statutory provisions, while not expressly defining "developer," are conceptually relevant for a holistic understanding of the developer's legal position.
The Information Technology Act 2000
Under Section 79 the Information Technology Act 2000, entities that receive, store, or transmit electronic records on behalf of others qualify as "intermediaries" and enjoy conditional safe harbour protection from liability for third-party content.[3] The India AI Governance Guidelines 2025 identify a critical gap: AI systems that generate or modify content autonomously may not qualify as traditional intermediaries, since they do not merely transmit information on behalf of others but initiate, create, or alter information based on algorithmic processes.[7] The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 address AI generated content specifically but do not define "developer" as a standalone legal term.[8]
The Digital Personal Data Protection Act 2023
Under Section 2(i) of the Digital Personal Data Protection Act 2023, , the term "data fiduciary" covers any person who alone or jointly with others determines the purpose and means of processing personal data.[4] An AI developer that decides what personal data will be collected to train its model, how that data will be processed, and what the model will do with data inputs from users, is a data fiduciary and is subject to data fiduciary obligations including purpose limitation, data minimisation, security safeguards, breach notification, grievance redressal, and erasure of data upon fulfilment of purpose.[4]
Under the Digital Personal Data Protection Act 2023, s 2(k), the term "data processor" covers any person who processes personal data on behalf of a data fiduciary.[4]
An AI developer engaged under contract to build a system on behalf of a client organisation, where the client retains control over the purposes of data use, qualifies as a data processor with more limited but still enforceable obligations.
The Consumer Protection Act 2019
Chapter VI (ss 82–87) of the Consumer Protection Act 2019 provides for product liability provisions that impose strict and fault-based liability on product manufacturers and service providers for defective products and deficient services.[5] While the Act does not expressly address software or AI systems, its product liability provisions apply where a consumer suffers harm from a defective AI-powered product or service.[5] An AI developer that places a defective AI system on the market, or makes false claims about its capabilities, faces direct liability exposure under the Act. Unfair limitation-of-liability clauses may constitute unfair contract terms under s 2(46) of the Consumer Protection Act, 2019 and may be declared null and void by the State Commission under s 49(2).[5]
"Developer" as Defined in International Instrument(s)
OECD Recommendation of the Council on Artificial Intelligence
The OECD Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449, adopted 22 May 2019, updated May 2024) is the first intergovernmental standard on AI, adopted by 42 countries and subsequently endorsed by the G7 and G20.[9] The Recommendation uses "AI actors" to cover all parties in the AI system lifecycle, including those who research, develop, and deploy AI systems. Developers are held responsible for design choices, algorithmic bias mitigation, data quality, monitoring of systems placed in the market, and providing clear documentation of system capabilities and limitations.
UNESCO Recommendation on the Ethics of Artificial Intelligence
The UNESCO Recommendation on the Ethics of Artificial Intelligence (adopted unanimously at the 41st session of UNESCO's General Conference, 23 November 2021) expressly includes developers and researchers among the parties responsible for implementing its ten ethical principles.[10] Member States are called upon to ensure that developers conduct ethics impact assessments prior to development, document the limitations and potential harms of their systems, apply privacy-by-design principles from the earliest stages of development, and apply non-discrimination and fairness principles at the data collection, model training, and testing stages.
United Nations Chief Executives Board Principles for the Ethical Use of Artificial Intelligence
The United Nations Chief Executives Board Principles for the Ethical Use of Artificial Intelligence in the United Nations System (CEB, 2022) hold UN entities that develop or procure AI systems accountable for ensuring that those systems comply with ten principles grounded in human rights and international law, drawn from the UNESCO Recommendation 2021.[11]
Regional instrument
The EU AI Act
The clearest and most consequential instance of definitional substitution is found in Regulation (EU) 2024/1689, the EU Artificial Intelligence Act. [12] The Act does not use the word "developer" anywhere in its operative provisions. In its place, Article 3(3) introduces the category of "provider," defined as any natural or legal person, public authority, agency, or other body that develops an AI system or a general-purpose AI model, or that has such a system or model developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or without charge. [12]This definition performs the same function as "developer" in ordinary usage but transforms the concept into a legally enforceable category carrying specific obligations that scale with the risk level of the system in question.[12]
The substitution is not merely terminological. By replacing "developer" with "provider," the EU AI Act accomplishes two things simultaneously. It captures both first-party developers who build systems in-house and organisations that commission third-party development but release the resulting system under their own brand. It also anchors accountability to the act of market placement rather than the act of technical creation alone, ensuring that entities which exercise commercial control over an AI system's entry into use cannot escape provider obligations by characterising themselves as non-technical actors. This shift from informal terminology to a legally enforceable category represents the most fully elaborated response to the definitional problem, and the EU model has influenced the drafting choices of subsequent frameworks in other jurisdictions.
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law
The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No 225, adopted 17 May 2024, opened for signature 5 September 2024, entered into force 1 November 2025) is the first binding international treaty specifically governing AI.[13] The Convention imposes obligations on state parties to adopt legal, administrative, or other measures to ensure that activities within the lifecycle of AI systems including design and development are consistent with human rights, democracy, and the rule of law. India is not a signatory, but the Convention is directly relevant to Indian developers operating in the European market or subject to EU AI Act obligations.[13]
Developer as Defined in Official Document(s)
Private Member Bills
The Artificial Intelligence (Ethics and Accountability) Bill, 2025
The Artificial Intelligence (Ethics and Accountability) Bill, 2025, introduced in the Lok Sabha on 5 December 2025 by Smt Bharti Pardhi, MP, is the first Indian legislative proposal to define "developer" as a statutory category in the AI context.
Clause 2(d) of the Bill defines a developer as a person who designs, develops, and implements AI models and systems, thereby identifying the developer not merely as a coder but as the entity that exercises control over the entire process from design through its implementation.
This definition matters because it fixes the point of legal accountability at the stage where the most consequential decisions about system architecture, training data, and algorithmic logic are made.
- Cl.6 operationalises this definition by imposing specific obligations on developers
- They must disclose the purpose, functionality, and limitations of their AI systems, reveal the data sources and methodologies used for training, explain the reasoning behind automated decisions that affect individuals, conduct regular bias audits to ensure training datasets represent diverse populations, and maintain detailed compliance records that make ethical governance auditable rather than aspirational.
- If a system exhibits significant bias or harmful effects, the developer is required to withdraw or modify it.
The Bill thus moves India from a position where developer accountability existed only in non-binding guidelines such as the India AI Governance Guidelines 2025 to a framework where enforceable statutory duties attach directly to the entity that designs and builds the AI system, with penalties extending up to five crore rupees for non-compliance.[14]
The India AI Governance Guidelines (Ministry of Electronics and Information Technology, November 2025)
The India AI Governance Guidelines (Ministry of Electronics and Information Technology, November 2025) define "developers" as entities that design, build, or modify AI systems, models, or components. The Guidelines distinguish developers from "deployers," defined as entities that place AI systems into operational use in a specific context, and from "end users," who interact with AI systems as the final recipients of outputs.[15] Developers bear primary responsibility for safety testing, technical documentation, and risk classification during the design and pre-deployment phase. Where a developer and a deployer are the same entity, all obligations attach to that single entity; where they are separate, liability is allocated based on the stage at which the relevant design choice was made.[15]
Sector Specific Guidelines
Reserve Bank India
The RBI Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) (Reserve Bank of India, 13 August 2025) uses "AI developer" to refer to entities engaged in building AI systems for the financial sector. The FREE-AI Framework recommends that regulated financial entities that build AI systems in-house or commission such systems from third parties maintain board-approved AI policies governing the development process, maintain AI inventories that include developer-specific information such as training data provenance, model version histories, and testing results, and include appropriate contractual provisions to ensure developer cooperation in ongoing risk management and incident reporting.[16]
In the financial sector, the RBI FREE-AI Framework recommends that financial sector AI developers provide regulated entities with full technical documentation of the systems supplied, disclose known model limitations and failure modes, and participate in model validation and audit processes.
The Indian Council of Medical Research Ethics Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare (ICMR, 2023)
The Indian Council of Medical Research Ethics Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare (ICMR, 2023) draw a clear distinction between AI developers and healthcare providers as two separate parties bearing different obligations in the healthcare AI supply chain.[17] Developers bear primary responsibility for ensuring that AI systems used in clinical settings are trained on representative, unbiased data, are validated across relevant demographic groups, and are transparent about their limitations.[17]
In the healthcare sector, the ICMR Ethics Guidelines impose obligations on AI developers supplying diagnostic or clinical AI systems. These include ensuring that training data is representative of the Indian population, validating systems across gender, age, and demographic groups, disclosing algorithmic limitations to clinical deployers, and cooperating with post-deployment monitoring. A clear legal demarcation of responsibility between the AI developer and the healthcare provider is recommended to prevent ambiguity in cases of diagnostic error.
TRAI recommendations on Leveraging Artificial Intelligence and Big Data
In the telecommunications sector, the TRAI Recommendations on Leveraging Artificial Intelligence and Big Data (TRAI, 20 July 2023) recommend a risk-based compliance framework for AI developers supplying systems to telecom operators, with stricter pre-deployment assessment and disclosure obligations for developers of high-risk applications.[18]
State-Specific Legislations and Policy Documents
Technology regulation in India falls exclusively within the Union's legislative competence under the Constitution of India, Seventh Schedule, List I (Union List), Entry 31. Software and AI development are therefore governed at the national level only. State governments have issued sector-specific AI guidelines in domains within their concurrent competence, but these do not define "developer" as a legal term and do not impose legally binding obligations on AI developers operating within their territories.
Tamil Nadu
Tamil Nadu's Safe and Ethical Artificial Intelligence Policy (Government of Tamil Nadu, 2020) is the first state-level AI policy in India. It places obligations on government departments using AI systems within the state and applies to AI deployers (government departments) rather than to developers.[19]
Telengana
Telangana's AI Procurement Guide (Government of Telangana, 2023) addresses how state government agencies should procure AI systems from technology providers, placing disclosure and accountability obligations on vendors (developers) as contractual conditions of government procurement. This indirect regulatory mechanism conditions access to state contracts on developer compliance with specified transparency and safety standards.[20]
also add https://nasscom.in/ai/pdf/the-developer's-playbook-for-responsible-ai-in-india.pdf
"Developer" as Defined in Official Government Report(s)
India AI Governance Guidelines (MeitY, November 2025)[21]
The India AI Governance Guidelines are the most comprehensive Indian government document to address the developer role. The Guidelines, produced by a MeitY committee constituted under the IndiaAI Mission in July 2025, identify the developer as the primary point of accountability in the AI supply chain, with responsibility extending through the entire system lifecycle. The Committee observed that current Indian laws are inadequately equipped to attribute liability across the AI value chain, noting that the Information Technology Act 2000 was drafted over two decades ago and does not account for entities that design and deploy AI systems autonomously. The Committee recommended a graded liability model in which the developer bears the highest standard of care at the design and training stage, while deployers and users bear proportionate obligations at the stages they control. The Guidelines also recommended that a risk-tiered classification framework for AI systems be established, analogous to the EU AI Act's risk-based architecture, with developer obligations scaling proportionately with risk.
NITI Aayog, Responsible AI for All (2021)[22]
NITI Aayog's two-part report on Responsible AI addressed the obligations of entities designing and building AI systems in India. Part 2 recommends that developers conduct bias audits at the design stage, build explainability into system architecture, disclose the known limitations of their systems to downstream deployers and end users, and maintain version control and audit trails of all model iterations and training data transformations to support post-deployment accountability.
Carnegie Endowment for International Peace, Regulating AI in India: Principles for a Path Forward (November 2024)[23]
This report documented the approach of India's key regulators on the question of developer liability and noted that a de facto approach in Indian regulatory deliberations was to impose different obligations on developers and deployers, following the model established in the EU AI Act. The report noted that India intends to regulate AI applications rather than AI technology itself: where the developer also deploys, it bears the full range of obligations; where the developer only creates and hands over to a deployer, its obligations focus on ensuring that the system is adequately documented, tested, and accompanied by accurate disclosures of capabilities and limitations.[23]
"Developer" as Defined in Case Law(s)
Indian courts have not, as of March 2026, decided any case that formally defines "developer" as a legal term in the technology or AI context. Developer liability in India is currently governed by general principles of tort law, contract law, and the Consumer Protection Act 2019.
Justice K S Puttaswamy (Retd) v Union of India [2017] (9) SCC 1
The Supreme Court's decision in Justice K S Puttaswamy (Retd) v Union of India [2017] (9) SCC 1 is foundational for all AI developer obligations involving personal data. The nine-judge bench unanimously held that privacy is a fundamental right under the Constitution of India, art 21, and established a three-pronged test for any interference with privacy: legality, a legitimate aim, and proportionality.[24] The India AI Governance Guidelines 2025 and the NITI Aayog Responsible AI documents apply this framework to AI developers: any AI system that processes personal data must have a lawful basis, pursue a legitimate purpose, and avoid disproportionate interference with the data subject's privacy.[7][22]
Donoghue v Stevenson [1932] AC 562.
The foundational duty of care principle applicable to technology developer liability derives from the House of Lords decision in Donoghue v Stevenson [1932] AC 562. [25]The neighbour principle articulated by Lord Atkin holds that any person who creates a product that can reasonably be expected to reach end users without intermediate examination must take reasonable care to avoid acts or omissions which could reasonably be foreseen to injure those users. This principle applies by analogy to AI developers: a developer who creates a system whose outputs are foreseeably relied upon by end users owes those users a duty of care. Breach of that duty through inadequate testing, failure to disclose known limitations, or deployment of a system incapable of performing its represented functions would found a tortious claim for negligence if harm results.[25]
Emaar MGF Land Ltd v Aftab Singh [2018] CPJ 417 (NC)
The National Consumer Disputes Redressal Commission, in Emaar MGF Land Ltd v Aftab Singh [2018] CPJ 417 (NC), held that a service provider who delivers a service causing financial loss to a consumer is liable under consumer protection legislation. [26]While arising in the real estate context, the principle that a service provider cannot contractually exclude liability for deficient services causing foreseeable harm is directly applicable to AI developers: limitation-of-liability clauses in software licence agreements, while enforceable between commercial parties, are subject to challenge under the Consumer Protection Act 2019, s 2(47) where they exclude liability for foreseeable harm caused to consumers.[5]
Singh v Illusory Systems Inc
In Singh v Illusory Systems Inc (United States District Court, District of Oregon, Case No 3:22-cv-00112-MO, decided 5 January 2023), the court dismissed negligence claims on the basis of the economic loss rule, holding that the existence of a software licence and terms of use between the parties negated any independent duty of care in tort.[27] While this decision does not bind Indian courts, it illustrates a pattern relevant to Indian AI developers: limitation of liability clauses in licence agreements are a primary line of defence against negligence claims, though they remain subject to challenge under the Consumer Protection Act 2019 where the developer's bargaining power leaves the consumer no room to negotiate.[5]
Use of Different Nomenclature Across Frameworks
The entity that performs the function of designing, building, and releasing a technology system appears under several different terms across legal frameworks, policy documents, and regulatory guidance. The table below summarises the principal terminological variations.
| Term | Framework | Scope / Note |
| Provider | EU AI Act, art 3(3) | Corresponds to "developer" in common usage; both first-party builders and organisations that commission development but release under own brand. |
| Developer | India AI Governance Guidelines 2025; NITI Aayog Responsible AI 2021; ICMR Ethics Guidelines 2023 | Standard term used in Indian regulatory discourse and the United States. |
| AI Actor | OECD Recommendation on AI (OECD/LEGAL/0449); UNESCO Recommendation 2021 | "Developer" is a sub-category of the broader "AI actor" covering developers, deployers, researchers, and other supply-chain parties. |
| Foundation Model Provider / Downstream Provider | EU AI Act, arts 51–56 | Distinguishes entities at different stages of the AI development chain; a downstream provider building on a foundation model may acquire provider status. |
| Data Fiduciary / Data Processor | Digital Personal Data Protection Act 2023, ss 2(i) and 2(k) | Describes the developer's role when the development activity involves processing personal data. |
| Vendor | Telangana AI Procurement Guide 2023, s 2 | Procurement context; technology company supplying an AI system to a government agency. |
| Operator | Older regulatory texts and commercial contracts | Inconsistent with the developer–deployer distinction adopted in modern frameworks; now deprecated in AI governance usage. |
International Experience
The term "developer" occupies an uncertain position in contemporary AI law. Across the major regulatory frameworks enacted or proposed between 2019 and 2025, no jurisdiction has adopted "developer" as a primary statutory category. Instead, legal systems have pursued one of four distinct strategies: substituting the term with a functionally equivalent legal category; treating the developer role as one node within a distributed lifecycle of responsibility; approximating the function through sector-specific nomenclature embedded in a strict regulatory structure; or remaining silent on the question entirely, leaving the concept to soft law and policy guidance. Understanding how these strategies differ illuminates the deeper question that AI governance frameworks are attempting to resolve, namely, which actor in the AI supply chain bears primary legal accountability for the behaviour of an autonomous system.
The EU AI Act[12]
The clearest and most consequential instance of definitional substitution is found in Regulation (EU) 2024/1689, the EU Artificial Intelligence Act. The Act does not use the word "developer" anywhere in its operative provisions. In its place, Article 3(3) introduces the category of "provider," defined as any natural or legal person, public authority, agency, or other body that develops an AI system or a general-purpose AI model, or that has such a system or model developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or without charge.[9] [12]This definition performs the same function as "developer" in ordinary usage but transforms the concept into a legally enforceable category carrying specific obligations that scale with the risk level of the system in question.[12]
The substitution is not merely terminological. By replacing "developer" with "provider," the EU AI Act accomplishes two things simultaneously. It captures both first-party developers who build systems in-house and organisations that commission third-party development but release the resulting system under their own brand. It also anchors accountability to the act of market placement rather than the act of technical creation alone, ensuring that entities which exercise commercial control over an AI system's entry into use cannot escape provider obligations by characterising themselves as non-technical actors. This shift from informal terminology to a legally enforceable category represents the most fully elaborated response to the definitional problem, and the EU model has influenced the drafting choices of subsequent frameworks in other jurisdictions.
The OECD Principals
Jurisdictions that have absorbed OECD principles most directly, including the United States, the United Kingdom, Canada, Australia, and Japan, have approached the question differently.[28][29] Rather than substituting a new term for "developer," these frameworks treat the developer function as one role among several within a distributed lifecycle of responsibility. The OECD Recommendation of the Council on Artificial Intelligence, first adopted in May 2019 and updated in May 2024, introduced the concept of "AI actors" to describe all parties engaged across the AI system lifecycle, encompassing design, data collection, model building, validation, deployment, and post-deployment monitoring.[9][28] Each actor bears obligations proportionate to the stage of the lifecycle it controls and the degree of influence it exercises over system behaviour at that stage.
Under this model, the question of who is the developer gives way to the question of what decisions were made at which stage and by whom. Responsibility is distributed rather than concentrated. A data curator who assembles training datasets, a model architect who designs the system's structure, and an organisation that deploys a third-party model in a new context may each bear distinct obligations without any one of them being designated the "developer" in a formal legal sense. The United Kingdom's AI regulation policy, the United States federal AI governance guidance issued under Executive Order 14110 and its successors, and Canada's Directive on Automated Decision-Making all reflect this lifecycle approach, emphasising accountability frameworks that attach to roles and functions rather than to a single legally defined actor.[29][30] The advantage of this model is its flexibility across diverse deployment contexts; its limitation is that it can produce attribution gaps when harm arises at the intersection of multiple lifecycle stages.
China
China's regulatory approach represents a third distinct strategy. Rather than adopting a single overarching term equivalent to "developer," Chinese AI regulation has introduced context-specific categories that approximate the developer function within a tightly controlled regulatory structure.[31][32] The Provisions on the Management of Algorithmic Recommendations (2022) and the Interim Measures for the Management of Generative Artificial Intelligence Services (2023) use terms such as "algorithm provider" and "service provider" to designate the entities that design, train, and operate AI systems for public-facing use.[32] These categories impose obligations of registration, algorithmic transparency, content governance, and security assessment that are functionally similar to the provider obligations under the EU AI Act but are embedded within a framework oriented toward state oversight and content control rather than risk classification alone. The Chinese approach demonstrates that a functional equivalent to "developer" can be constructed through sectoral regulation without adopting either the EU's risk-based terminology or the OECD's lifecycle vocabulary.[31][32]
The Global South
A substantial portion of the world's jurisdictions have not yet addressed the definitional question at all. In Mexico, Brazil, the Philippines, Kenya, and Nigeria, AI governance remains at the level of national strategy documents, ethics guidelines, and policy recommendations.[33][34] These instruments may use the word "developer" descriptively but do not constitute binding law and impose no enforceable obligations on entities that design or train AI systems. The absence of a statutory definition in these jurisdictions does not reflect indifference to the question but rather the regulatory infancy of their AI governance frameworks and, in many cases, a deliberate reliance on soft-law instruments as a transitional measure. Brazil's Bill 2338/2023 and the Philippines' National AI Strategy are moving toward more structured legislative frameworks, suggesting that the silence in these jurisdictions is provisional rather than permanent.[33][34]
Research that Engages with "Developer"
A considerable volume of academic and policy research examines developers as key nodes in AI governance ecosystems, focusing on accountability, explainability, and human oversight. Within the Indian justice context, this discourse emerges primarily from civil society, think tanks, and academic institutions.
Vidhi Centre for Legal Policy: "AI and the Indian Legal System: Pathways to Responsible Innovation" (2023)[35]
This study interrogates the capacity of Indian AI developers to integrate ethics by design in judicial and administrative decision tools. It highlights deficits in institutional accountability ,developers are rarely bound by sector-wide ethics charters and urges the creation of an "AI Developer Registry" for justice applications. The paper draws on comparative insights from the EU AI Act and the Singapore PDPC framework. A significant gap identified is the absence of mandatory pre-deployment bias audits for AI systems used in judicial or law enforcement contexts.
NITI Aayog and Centre for Internet and Society: "Responsible AI for Social Empowerment" (RAISE) White Paper (2022)[36]
This report discusses the developer's dual role as innovator and risk manager in public-sector AI deployments. It advocates open-data partnerships and the establishment of developer evaluation criteria emphasising bias testing and dataset documentation. A notable overlap with other research is its insistence on treating responsible AI as a design-stage obligation rather than a post-deployment corrective measure.[36]
Indian Institute of Public Administration: "Ethics and Accountability Frameworks for AI Governance in Judicial Data Systems" (2024)
This study expands on the notion that the identity of the developer ,public sector or private contractor ,significantly determines transparency outcomes. It urges statutory codification of developer obligations and the creation of independent verification zones similar to EU notified bodies. A key gap identified is the absence of a statutory mechanism for post-deployment auditing of AI systems supplied by private developers to judicial and administrative bodies.
Challenges
The following challenges relate to data, process, and implementation in the analysis and governance of the developer role in India's technology ecosystem.
Absence of a statutory definition
No Indian statute currently defines "developer" in the AI context. Developers are governed through general tort, contract, and consumer protection law, and through sectoral regulatory guidance that is not uniformly binding.
Fragmented regulatory landscape
Developer obligations arise under multiple overlapping frameworks ,the IT Act 2000, the DPDPA 2023, the Consumer Protection Act 2019, and sector-specific guidance from RBI, ICMR, and TRAI ,without a unified coordination mechanism.
Upstream-downstream liability gaps:
The allocation of liability between foundation model providers, fine-tuners, and downstream developers remains unresolved in Indian law, creating uncertainty about which entity bears responsibility for harms arising from complex, multi-layered AI supply chains.
Data transparency and accessibility
Developers are not yet required by law to maintain or disclose model cards, training data provenance logs, or algorithmic audit trails. This limits the ability of regulators, courts, and affected parties to assess system behaviour.
Standardisation and harmonisation
The divergence in terminology across frameworks ,"developer," "provider," "AI actor," "data fiduciary" ,creates interpretive challenges for compliance and enforcement, particularly for entities operating across multiple jurisdictions.
Implementation status
India does not yet have a risk-tiered classification framework for AI systems analogous to the EU AI Act, meaning developer obligations cannot yet be calibrated to the level of risk posed by a given system.
Way Ahead
The following suggestions have been put forward by senior judges, stakeholders, academics, and research organisations in the context of defining and operationalising the developer role in India.
Enactment of a statutory definition
A standalone AI Act or an amendment to the Information Technology Act 2000 should provide a clear statutory definition of "developer" in the technology and AI context, distinguishing the developer's role from those of the deployer and end user, consistent with the India AI Governance Guidelines 2025.
Graded liability model
Legislation should adopt a graded liability model in which the developer bears the highest standard of care at the design and training stage, with obligations scaling proportionately with the risk level of the system, analogous to the EU AI Act's risk-based architecture.
Mandatory documentation requirements
Developers of AI systems deployed in justice, healthcare, and financial sectors should be required by law to maintain and disclose technical documentation including training data provenance, model version histories, known limitations, and testing results.
AI Developer Registry
A publicly accessible registry of AI developers operating in regulated sectors, as recommended by the Vidhi Centre for Legal Policy, would improve traceability and accountability.
Independent audit and verification
The creation of independent audit bodies analogous to EU notified bodies, capable of assessing developer compliance with safety and transparency obligations, has been recommended by the Indian Institute of Public Administration.
Harmonisation of terminology
Regulatory guidance should harmonise the terminology used across Indian frameworks to ensure that the developer's obligations are consistently understood and enforced.
Open-source considerations
Any forthcoming AI regulatory framework should include proportionate provisions for open-source developers, avoiding disproportionate compliance burdens that may stifle innovation and inclusive AI development, consistent with the recommendation in the India AI Governance Guidelines 2025.
Related Terms
The following terms are comparable, synonymous, or umbrella terms as used in the Indian and international context.
• Deployer: An entity that places an AI system into operational use in a specific context. Distinct from the developer, who creates the system.
• Data Fiduciary: Under the Digital Personal Data Protection Act 2023, s 2(i), any person who determines the purpose and means of processing personal data. An AI developer that controls training data processing qualifies as a data fiduciary.
• Data Processor: Under the Digital Personal Data Protection Act 2023, s 2(k), any person who processes personal data on behalf of a data fiduciary. A contract developer building a system on behalf of a client may qualify as a data processor.
• Provider: The term used in the EU AI Act, art 3(3), to describe the entity that performs the development function. Equivalent to "developer" in common usage.
• AI Actor: A broader term used by the OECD and UNESCO to encompass developers, deployers, researchers, and other parties engaged in the AI value chain.
• Intermediary: Under the Information Technology Act 2000, s 2(1)(w), an entity that receives, stores, or transmits electronic records on behalf of others. AI developers may or may not qualify as intermediaries depending on the nature of their system.
• Vendor: Used in procurement contexts (Telangana AI Procurement Guide 2023) to refer to the technology company supplying an AI system to a government agency.
• Foundation Model Provider: Under the EU AI Act, arts 51 to 56, the entity that develops a base AI model on which downstream providers build applications.
11. References
- ↑ Donoghue v Stevenson [1932] AC 562 (HL).
- ↑ Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence [2024] OJ L 1689/1 < https://eur-lex.europa.eu/eli/reg/2024/1689/oj > accessed 28 March 2026.
- ↑ 3.0 3.1 Information Technology Act 2000 <https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf accessed 28 March 2026.
- ↑ 4.0 4.1 4.2 4.3 Digital Personal Data Protection Act 2023 < <https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf>
- ↑ 5.0 5.1 5.2 5.3 5.4 5.5 Consumer Protection Act 2019 <https://egazette.nic.in/WriteReadData/2019/210422.pdf> accessed 28 March 2026.
- ↑ Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence [2024] OJ L 2024/1689 (EU AI Act).
- ↑ 7.0 7.1 Ministry of Electronics and Information Technology, India AI Governance Guidelines (2025)
- ↑ Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026.
- ↑ 9.0 9.1 9.2 OECD, Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449, 2019, updated 2024) <https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449 accessed 28 March 2026.
- ↑ UNESCO, Recommendation on the Ethics of Artificial Intelligence (2021) <https://www.unesco.org/en/artificial-intelligence/recommendation-ethics> accessed 28 March 2026.
- ↑ UN Chief Executives Board, Principles for the Ethical Use of Artificial Intelligence in the United Nations System (2022) <https://unsceb.org/principles-ethical-use-artificial-intelligence-united-nations-system> accessed 28 March 2026.
- ↑ 12.0 12.1 12.2 12.3 12.4 12.5 Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 2024/1689, Art 3(3), Art 99.
- ↑ 13.0 13.1 Council of Europe, Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No 225, 2024) <https://www.coe.int/en/web/artificial-intelligence/convention> accessed 28 March 2026.
- ↑ The Artificial Intelligence (Ethics and Accountability) Bill 2025 (Lok Sabha Bill No 59 of 2025), introduced 5 December 2025. Available at < https://sansad.in/getFile/BillsTexts/LSBillTexts/Asintroduced/59%20of%202025%20AS125202594603PM.pdf?source=legislation>accessed 16 April 2026.
- ↑ 15.0 15.1 Ministry of Electronics and Information Technology, India AI Governance Guidelines (2025) <https://indiaai.gov.in> accessed 28 March 2026.
- ↑ Reserve Bank of India, Framework for Responsible and Ethical Enablement of Artificial Intelligence (13 August 2025) <https://www.rbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=56254> accessed 28 March 2026.
- ↑ 17.0 17.1 Indian Council of Medical Research, Ethics Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare (2023) < https://ethics.ncdirindia.org/ICMR_AI_Guidelines.pdf > accessed 28 March 2026.
- ↑ Government of Telangana, AI Procurement Guide (2023) <https://startup.telangana.gov.in/wp-content/uploads/2021/04/AI-framework.pdf> accessed 28 March 2026.
- ↑ Government of Tamil Nadu, Safe and Ethical Artificial Intelligence Policy (2020) < https://it.tn.gov.in/sites/default/files/2021-06/TN_Safe_Ethical_AI_policy_2020.pdf> accessed 28 March 2026.
- ↑ Government of Telangana, AI Procurement Guide (2023)< https://startup.telangana.gov.in/wp-content/uploads/2021/04/AI-framework.pdf>
- ↑ Ministry of Electronics and Information Technology, India AI Governance Guidelines (IndiaAI Mission, November 2025).
- ↑ 22.0 22.1 NITI Aayog, Operationalizing Principles for Responsible AI (August 2021) < https://www.niti.gov.in/sites/default/files/2021-08/Part2-Responsible-AI-12082021.pdf > accessed 28 March 2026.
- ↑ 23.0 23.1 Carnegie Endowment for International Peace, Regulating AI in India (November 2024)
- ↑ Justice KS Puttaswamy (Retd) v Union of India (2017) 9 SCC 1
- ↑ 25.0 25.1 Donoghue v Stevenson [1932] AC 562 (HL)
- ↑ Emaar MGF Land Ltd v Aftab Singh (2018) CPJ 417 (NC)
- ↑ Singh v Illusory Systems Inc (D Oregon, 5 January 2023)
- ↑ 28.0 28.1 US Executive Order 14110 Executive Order 14110 on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (30 October 2023) 88 FR 75191
- ↑ 29.0 29.1 UK AI White Paper Department for Science, Innovation and Technology, 'A pro-innovation approach to AI regulation' (UK Government White Paper, CP 815, March 2023)
- ↑ Canada — Directive on Automated Decision-Making Treasury Board of Canada Secretariat, Directive on Automated Decision-Making (effective 1 April 2019, last amended 1 April 2023)
- ↑ 31.0 31.1 China — Algorithmic Recommendations Provisions Cyberspace Administration of China, Provisions on the Management of Algorithmic Recommendations (promulgated 4 January 2022, effective 1 March 2022
- ↑ 32.0 32.1 32.2 China — Generative AI Interim Measures Cyberspace Administration of China and others, Interim Measures for the Management of Generative Artificial Intelligence Services (promulgated 13 July 2023, effective 15 August 2023)
- ↑ 33.0 33.1 Brazil — Bill 2338/2023 Brazil, Projeto de Lei nº 2338/2023 (Bill on Artificial Intelligence), introduced to the Federal Senate 3 May 2023
- ↑ 34.0 34.1 Philippines — National AI Strategy Department of Information and Communications Technology (Philippines), National Artificial Intelligence Strategy Roadmap (2021)
- ↑ Vidhi Centre for Legal Policy, AI and the Indian Legal System (2023) <https://vidhilegalpolicy.in/wp-content/uploads/2021/04/Responsible-AI-in-the-Indian-Justice-System-A-Strategy-Paper.pdf accessed 28 March 2026.
- ↑ 36.0 36.1 NITI Aayog, Responsible AI for Social Empowerment (2022) <https://www.niti.gov.in/sites/default/files/2022-11/Ai_for_All_2022_02112022_0.pdf accessed 28 March 2026.