ThinkPatternGet the app
Perspective
POLITICS · JUL 30, 2026

India's AI Guardrails Stop at the State

The 7-Sutra guidelines, the data protection law, and the Supreme Court's own draft AI rules each regulate private-sector or citizen-facing AI use — and each leaves the executive's facial recognition deployment against protesters untouched.

India has built its AI guardrails framework by framework, each one addressing a different threat. The 7-Sutra guidelines, released in February, govern generative AI, deepfakes, and liability: the harms that flow from what private actors build and publish [1]. The Digital Personal Data Protection Act regulates how companies collect, process, and store personal data. The Supreme Court's own draft AI regulations, circulated in June, ban surveillance of litigants and judicial officers, prohibit AI risk-scoring for bail and recidivism, and mandate human primacy in judicial decision-making [2]. Three frameworks, three domains of protection. At Jantar Mantar, the student protest site in central Delhi, none of them applies. Since June 20, Delhi Police have deployed facial recognition tools — Ikshana surveillance vans with 360-degree cameras, smart glasses, and the Abhigyan face-matching app — against peaceful protesters, matching live feeds against a national criminal database [3]. The deployment operates without statutory authority, without a privacy impact assessment, and without data-retention limits. Biometric data is stored, in the words of the petition filed by MP AA Rahim, indefinitely in criminal databases. Private vendors — Aditya Infotech and Dimension NXG, which makes the AjnaLens smart glasses — handle the sensitive biometric data with no disclosed processing agreements [3].

These objects are wholly unconnected with the policing of a peaceful protest. The data so collected is retained, shared and processed without any disclosed safeguard, purpose limitation or retention schedule, and is, on the Respondents' own admission, liable to be stored indefinitely and enrolled into national criminal databases without end or accountability. — A. A. Rahim

The 7-Sutra guidelines address generative AI, deepfakes, and liability. They say nothing about the state's use of facial recognition against its own citizens. The framework's animating principle is "innovation over restraint" — a posture designed to encourage private-sector AI development, not to constrain police deployment of biometric identification [1]. The guidelines govern what private actors may build; they are silent on what the state may deploy. The DPDP Act governs private-sector data processing: consent, purpose limitation, the rights of data principals. It has not been invoked in any reported account of the Jantar Mantar deployment or the legal challenge to it [3][4]. The law exists on paper; it is not being applied to the state's biometric surveillance of protesters. A protester whose face is matched against a criminal database and stored indefinitely has no visible path through the data protection framework to challenge that collection. The Supreme Court's draft AI rules ban surveillance of litigants and judicial officers, prohibit AI risk-scoring for bail and recidivism, and mandate human primacy [2]. They are the most explicit guardrails in the country, and the most narrowly bounded. The rules govern the judiciary's own use of AI; they bind the court, not the police. A student protester at Jantar Mantar is not a litigant, and the Delhi Police are not a judicial body. The draft rules draw a line around the courtroom. The street remains unregulated. In a single operation at Jantar Mantar, Delhi Police ran both tracks simultaneously: they ordered platforms to block 450 social media accounts and requested user login records, while deploying facial recognition cameras to identify over 2,000 individuals with criminal records [5]. Content control and people identification, converging in one policing action. The same officer who orders a takedown now runs a face match. Solicitor General Tushar Mehta, the state's voice in court, has denied the deployment constitutes surveillance at all.

There is no snooping. — Tushar Mehta

The denial is itself the evidence of the gap. If facial recognition deployed against crowds, matching live feeds against criminal databases without consent or retention limits, does not qualify as surveillance, then nothing the state does with a camera will. The framework that would constrain it has been defined out of existence by the official who would be constrained. Mehta is the same voice who has defended the Telegram ban, the social media court-clip ban, and the Fact-Check Unit rules — arguing simultaneously that the state must control speech and that it is not monitoring people [4]. The inclusion track is real and substantial. Delhi has built an AI-powered Intelligent Grievance Monitoring System with IIT Kanpur, using semantic search to route citizen complaints — what officials call "responsive, accountable, and citizen-centric governance" [6]. The IndiaAI Mission is building a national compute stack of indigenous data centers and GPU clusters, explicitly modeled on the UPI public-private architecture that revolutionized digital payments [7]. Intel India is developing confidential computing architectures aligned with the DPDP framework, building privacy-by-design into commercial data infrastructure [8]. These are not rhetorical gestures. But they address citizen services and commercial data protection. The same national AI infrastructure being built for grievance redressal and model training could, by the architecture of the shared-stack model, also carry the surveillance tools deployed at Jantar Mantar. The inclusion track and the control track run on the same rails. The judiciary is the only institution drawing lines. The Bombay High Court struck down the government's Fact-Check Unit rules as unconstitutional — rules that would have let the executive flag content about its own business and strip platforms of safe-harbor protections. The Supreme Court, while considering a social media regulator, warned it would not approve rules that "gag somebody." When Youth Congress workers were arrested for protesting at the India AI Impact Summit, a magistrate called their action "symbolic political critique" and the High Court questioned the lack of reasoning for continued detention [9]. And the court's own draft AI rules are the only governance document in the country that explicitly bans a form of AI surveillance [2]. But the judiciary moves reactively, ruling on what has already been deployed. The Ikshana vans were at Jantar Mantar when the PIL arrived. The facial recognition system is operational while the challenge proceeds. The court can strike down a rule, question a detention, draft a guideline — and the cameras keep running. The guardrails exist. They face every direction except back at the state.


Sources
  1. 1. India Launches 7-Sutra AI Governance Guidelines for Safe Innovation
  2. 2. Supreme Court of India Drafts AI Use Regulations
  3. 3. MP AA Rahim Challenges Delhi Police Biometric Surveillance in Supreme Court
  4. 4. Delhi Police Use AI Facial Recognition on Student Protesters
  5. 5. Delhi Police Crack Down on AI-Generated Anti-Modi Content
  6. 6. Delhi Launches AI-Powered Intelligent Grievance Monitoring System
  7. 7. India Adopts Public-Private Model to Scale National AI Infrastructure
  8. 8. Intel India Develops Secure AI Architectures to Support Data Privacy
  9. 9. Delhi Courts Grant Bail to AI Summit Protesters

Keep reading in the app

The full perspective, free in the app.

Download on the App StoreComing soonGoogle Play