← All digests

Long-form essayJuly 12, 2026

The law India said it didn't need

Thematic essay — week of July 6 to 12, 2026

Seven months ago, MeitY's position was that India did not need a dedicated AI law. This week, that position reversed twice over — first when the IT minister told industry the IT Act era was over, then when the ministry's own secretary confirmed a drafting process was starting — and it reversed in the same seven days that gave India its clearest evidence yet of what an AI law's sharpest tool, the power to switch a model off, actually does when a state uses it. India spent the week watching two frontier labs get gated, priced, and re-priced by government-adjacent decisions on the other side of the world, while its own regulators quietly finished assembling the pieces — a Supreme Court ruling, an RBI draft framework, a standing government-procurement panel — that a horizontal AI statute would eventually sit on top of. This is an essay about why the reversal happened now, what the reported framework would actually do, and what the week's frontier-lab governance episodes tell India about the tool it is about to build for itself.

The reversal, dated precisely

Track the sequence and the reversal has an unusually clean paper trail, because each step is attributed and dated.

In November 2025, MeitY released its AI Governance Guidelines — explicitly non-binding, the soft-law instrument the ministry said was sufficient. As late as December 2025, MeitY Secretary S. Krishnan said the government was not planning a new dedicated AI law. Then, on June 10, 2026, IT Minister Ashwini Vaishnaw told PTI that India needs a new AI law distinct from the IT Act era — a break from the ministry's own December position, and one the July 8 digest situates precisely: Vaishnaw was "telling industry MeitY was in talks on a new framework because 'the world of AI is very different from the world when the IT Act was enacted in 2000.'" On July 3, Krishnan himself moved: Business Standard and the Free Press Journal carried his statement that the time has come to consider separate AI legislation. And on July 9, speaking at CII's GCC Business Summit, Krishnan made it operational — "We will have to start discussing in various groups as to what the stakeholders feel about it and we will start a process of drafting," as the July 8 digest records it.

Four data points, seven months, one direction. What makes this week's confirmation more than a restatement of the July 3 signal is the sequencing the July 8 digest flagged: "The July 9 statement is the bureaucratic confirmation of a political decision Vaishnaw had already signalled a month earlier — not a new development so much as the civil service catching up to the minister." Political leadership moved first; the technical secretariat is now formally aboard. That is a specific and checkable claim about how this reversal happened inside the Indian state, and it matters for what comes next — a ministry executing a decision made above it drafts differently than a ministry that arrived at the decision itself.

None of this is text yet. Every account of what the eventual law contains — described in subsequent Economic Times reporting the July 9 digest cites — rests on "a graded, risk-based framework that would regulate low-risk systems such as chatbots and recommendation engines lightly, place stricter duties on high-risk AI in banking, finance, and health, let sectoral regulators including RBI, SEBI, and IRDAI write their own AI rules, and grant the government emergency powers to disable a dangerous AI system and demand technical disclosure." Officials are explicit, per that reporting, that no draft bill, consultation paper, or timeline exists. The distance between "the time has come" and an actual bill is not small: the July 9 digest, quoting the government's own framing, notes that "no draft bill, consultation paper, or timeline exists yet," and the July 8 digest adds the historical yardstick — "previous UK/EU AI-law drafting cycles ran 18–24 months from announcement to text." Treat everything that follows as the shape of an intention, not the content of a statute.

What the reported framework would actually do

Strip the framework description down to its moving parts and three choices stand out, because each is a specific institutional bet rather than a generic commitment to "regulate AI."

The tiering is risk-based, not use-based. Chatbots and recommendation engines — the largest population of deployed Indian AI systems by volume — sit in the light-touch tier regardless of who runs them. Banking, finance, and health AI sit in the strict tier regardless of how mundane the specific application. This is the same design principle the EU AI Act (Regulation (EU) 2024/1689) uses — unacceptable-risk uses banned outright, high-risk systems (credit scoring, biometric identification, critical infrastructure) subject to conformity assessment and human oversight duties, limited-risk systems carrying transparency obligations, and everything else largely unregulated. India's reported framework borrows the shape without (yet) the EU's binding conformity-assessment machinery — a lighter version of the same architecture, consistent with the light-touch posture MeitY has held since DPDP.

Rule-writing is delegated to sectoral regulators, not centralized. This is not a new invention sitting on top of existing law; it is a formalization of something already in motion, and the week's own archive shows the pattern operating live. RBI's draft Guidance on Regulatory Principles for Model Risk Management — out June 24, 2026, comment window open through July 24 — already asks regulated financial entities to run board-approved model-risk frameworks with kill-switch mechanisms and explainability duties for credit and fraud decisions, as the July 8 and July 9 digests both note. A reported horizontal statute that lets RBI, SEBI, and IRDAI keep writing their own AI rules is choosing not to fight that momentum but to formalize it — the statute sits above the sectoral regulators rather than replacing them. The July 9 digest calls this "a specific bet about how Indian AI governance gets built: distributed to the regulators who already supervise the sectors, not centralized in a single AI authority." That is the opposite of the single-authority model some jurisdictions have chosen, and it is consistent with how DPDP itself has operated — a horizontal data-protection statute layered over sector-specific practice rather than displacing it.

Emergency powers are the sharp edge, and they are also the least specified part. A power to disable an AI system in production and compel technical disclosure is, on paper, a strong instrument. What makes it strong or weak in practice is entirely in the definitions nobody has written yet: what counts as dangerous, who decides, on what evidence, with what appeal. The July 9 digest is blunt about this: "its usefulness and its risk both live in the definitions... None of that is specified, and specifying it is where a light-touch framework and a heavy one diverge." This is the clause with no domestic precedent to measure against — which is exactly why the same week supplied, from outside India, the closest thing to a field test.

The evidence file the same week produced

Here is where the daily chronicle earns its keep, because India did not have to imagine what a state's power to gate or disable a frontier model looks like in practice. It watched two versions of it happen to two different labs, on two different mechanisms, inside the same seven days its own emergency-powers clause was being described in the press.

Version one: the export-control shutoff, now closing its arc. Anthropic's Claude Fable 5 had been suspended worldwide since June 12 under a US Commerce Department directive — the trigger, per Anthropic's own account carried in the July 7 digest, a safeguard bypass Amazon researchers found that let the model identify and, in one case, demonstrate exploitation of software vulnerabilities. On June 30, Anthropic announced Fable 5 would return globally on July 1, "eighteen days after the June 12 US export-control directive forced it offline." In the same announcement, per the July 7 digest, the company said it "has started developing a jailbreak severity-scoring framework with Amazon, Microsoft, Google, and other partner companies" — a four-criteria rubric (capability gain, breadth, ease of weaponization, discoverability) drafted, the digest notes, "in the immediate aftermath of an export-control suspension." That framework is a private, cross-lab analogue of exactly the kind of severity taxonomy a government emergency-disable power would need to operate — and it emerged from the labs, not from a regulator, while the regulator's directive was still the reason the model had been off.

The restoration did not end the story cleanly. By July 9, Anthropic moved Fable 5 off subscription plans entirely, onto metered usage-credit billing at $10 per million input tokens and $50 output — "the highest per-token price Anthropic has put on a public model," per the July 9 digest, double Opus 4.8's rate ($10/$50 versus Opus 4.8's $5/$25). Anthropic's own framing, carried via BleepingComputer, calls this "a capacity-management measure rather than a permanent repricing." Whether that holds is unresolved. But the sequence — suspend, restore, then reprice sharply upward under a "temporary" label — is itself a template: a single model can be made unavailable, then available on materially worse terms, entirely at the vendor's and the state's discretion, with no consultation of the customer base on the other end.

Version two: the government-coordinated preview, now in general availability. OpenAI's GPT-5.6 family — Sol, Terra, Luna — began a limited preview on June 26 restricted, per the July 7 digest, to "roughly 20 trusted partner organizations whose participation was shared with the government before broader access," at the US administration's request, over concern, as the July 10 digest's account of the same episode puts it, that the model could be misused "to discover software vulnerabilities, write malware, or automate cyberattacks." OpenAI said publicly it complied but that such restrictions "shouldn't be the norm." The gate held twelve days, with, per the July 10 digest, "no publicly disclosed change to the model in between" — and general availability landed July 9, alongside ChatGPT Work, OpenAI's new enterprise document-and-spreadsheet agent.

The July 10 digest's read of that sequence is the sharpest single sentence the week produced on what an emergency-powers clause looks like in operation: the twelve-day gate is "a real-world data point for how such a power actually gets exercised: quietly, for a short window, against named enterprise customers rather than the public, and apparently without a public accounting of what the review found." That is not a hypothetical description of India's reported emergency-disable clause. It is a description of the US government exercising a functionally equivalent power, twelve days before India's own IT Secretary confirmed a drafting process was starting, over a model whose flagship tier — Sol — is priced at $5 input / $30 output per million tokens and whose mid tier, Terra, at $2.50/$15, was released the same week TCS put a $2.6 billion AI revenue run rate on its books.

Two governments, two different levers — export control on one side, informal pre-release coordination on the other — arrived at structurally similar outcomes: a frontier model's public availability delayed or altered on a timetable a government participated in setting, disclosed after the fact rather than negotiated with affected users in advance. Neither episode is India-directed. Both are the nearest available evidence of what India's own reported disable-and-disclose power would need to specify to avoid replicating the same opacity — which decisions get explained, to whom, and on what timeline.

A third state instrument, and why it sharpens the same question

The same week carried a third data point that is not about gating access but about who owns the counterparty. On July 2, the Financial Times reported — corroborated by CNBC, TechCrunch, and Forbes, per the July 9 digest — that Sam Altman had proposed ceding roughly 5% of OpenAI's equity, "$42.6 billion at the company's $852 billion post-money valuation," to a US sovereign wealth fund, with Anthropic, Google, and Meta reportedly invited to cede similar stakes. The proposal is unconfirmed and would likely need congressional approval; treat it, as the July 9 digest does, as "a reported proposal, not a decided arrangement."

What makes it relevant here is not whether it happens but what it does to the sovereignty argument India is already having with itself. NASSCOM's new chairperson, Fractal Analytics co-founder Srikanth Velamakanni, gave that argument its sharpest domestic framing the same week, telling Bloomberg's Emerging series on July 10 that AI sovereignty should be read not as self-sufficiency but as a "smart way of interdependency" — a nation ensuring its AI systems can keep operating "without facing external control or shutdown at a moment's notice." Velamakanni's five-layer stack — energy, compute, data, models, applications — argues India should concentrate scarce capital on the layers where dependence is most exposed rather than try to own every layer at once. It is a coherent position, and, as the July 10 digest notes, also "the position of someone whose company profits from being the integration layer between global AI and Indian enterprise, not from building a foundation model" — worth holding alongside the argument, not as a rebuttal to it.

The OpenAI equity report sharpens Velamakanni's framework by testing it against a concrete case: if the counterparty behind a frontier API becomes partly state-owned, is dependence on that counterparty still "smart interdependency," or does it become something closer to what Velamakanni's own "external control" language was warning against? The report does not resolve that question — it hasn't happened, and may not. But it is the sharpest version yet of the scenario India's own build-vs-buy debate has been circling since long before this week, now with a specific dollar figure and a specific mechanism attached.

What this looks like elsewhere

Two comparables place India's reported architecture.

The EU chose codified tiers with binding conformity assessment. The AI Act's structure — unacceptable-risk practices banned outright, high-risk systems (credit, employment, law enforcement, critical infrastructure) subject to mandatory conformity assessment, registration, and human-oversight duties, with phased application running into 2026–2027 — is the fullest version of the risk-tiered model India's reported framework echoes. The EU's version is also the slowest to arrive at enforceable text: from the Commission's original 2021 proposal to a fully phased-in regime spans roughly six years. If the UK/EU 18–24-month drafting-to-text benchmark the July 9 digest cites holds for India, and the EU's own multi-year phase-in is any guide to what comes after text exists, "the time has come" this week is a long way from a compliance deadline.

China chose algorithm-level registration ahead of any omnibus law. Since 2023, China's Cyberspace Administration has required generative-AI service providers whose algorithms carry "public opinion attributes or social mobilization capabilities" — not all generative-AI providers — to file and obtain security assessments for their algorithms, with filing due within 10 business days after public launch rather than before it. That's narrower in scope than a blanket pre-launch regime but still a standing, per-algorithm filing obligation with no equivalent in either the EU's or India's reported approach. India's reported framework, with its emergency disable-and-disclose power reserved for exceptional cases rather than any standing filing requirement, sits closer to the EU's ex-post, risk-tiered model than to China's targeted, deployment-triggered registration model — a choice consistent with the light-touch, sectoral-delegation posture MeitY has held since DPDP, but one that leaves India, like the EU, dependent on catching problems after deployment rather than requiring providers to register in advance.

Set against both, the United States — the government whose two episodes this week supplied India's evidence file — has no comparable statute at all. What Washington exercised over Fable 5 and GPT-5.6 this week ran through export control and informal pre-release coordination, not codified AI law. That is the asymmetry worth sitting with: the state India is watching most closely for what an emergency-powers clause looks like in practice is a state that has chosen not to legislate one, and instead exercises the equivalent power through instruments that predate AI entirely. India's reported framework would put text and process around a power the US currently exercises without either.

The domestic pieces already in place

None of this is happening in a vacuum where only the statute is missing. The week showed at least three domestic institutions already writing rules for AI inside their own jurisdiction, ahead of and independent from any horizontal law — which is itself evidence for the sectoral-delegation bet at the center of the reported framework.

The Supreme Court, on July 2, set aside NCLT and NCLAT insolvency orders in Pooja Ramesh Singh v Jammu and Kashmir Bank Ltd after finding three of six judgments the tribunal relied on did not exist and the rest carried invented paragraphs, declaring — in the bench's own words, per the July 7 digest — that "it is necessary for Courts to adopt a zero-tolerance mode for producing, citing or using AI-generated precedents without verification," and directing the Bar Council of India to frame profession-wide AI-use guidelines. The July 7 digest calls this "the judiciary... set[ting] an AI standard for its own domain by judgment, without waiting for an omnibus AI law" — and names the pattern precisely: "India's AI-governance frame is being drawn institution by institution."

MeitY's own National e-Governance Division has been running a parallel, quieter build on the demand side. ANI reported July 9 — consolidating an empanelment that, per the July 12 digest, had actually been in place since an April 22 letter to Innefu Labs — that NeGD has empanelled six firms (CoRover, TCS, NEC Corporation India, Innefu Labs, Kyndryl Solutions, and Cactus Technology Solutions) as standing AI-implementation partners any ministry, state government, or PSU can engage without a fresh tender. The July 12 digest frames this as "the operational counterpart of a policy posture that has so far mostly expressed itself through capital and missions" — procurement infrastructure arriving ahead of, and independent from, the statute that would eventually govern what gets procured.

And underneath both, RBI's draft model-risk guidance — kill-switch mechanisms, board-approved frameworks, credit- and fraud-decision explainability, comment window closing July 24 — is the sectoral regulator the reported framework names explicitly as a rule-writer, already exercising exactly that role while the horizontal statute remains undrafted.

Put together: a judiciary writing precedent-verification rules by judgment, a ministry writing procurement infrastructure by empanelment, and a central bank writing model-risk rules by draft guidance — three institutions moving on their own tracks, at their own speed, inside the perimeter a horizontal AI law would eventually try to draw around all three. The statute, when it exists, will have less blank space to fill than "no law yet" suggests.

Where this lands

Several of the open threads here resolve on dates close enough to track directly.

July 24, 2026 — RBI's comment window on the draft Model Risk Management guidance closes. Whatever RBI publishes next is the first concrete text any Indian regulator has produced this year that resembles the "high-risk AI" tier the reported horizontal framework describes; it will show whether the sectoral-delegation model produces workable rules faster than a horizontal statute could.

MeitY's stakeholder consultation process, once it opens — the July 8 digest names the next concrete signal to watch: "who's invited, and whether NASSCOM and IAMAI issue public submissions." If Velamakanni's five-layer sovereignty framing surfaces in a NASSCOM submission, that is the clearest evidence the industry-sovereignty argument this week sharpened is shaping the statute rather than remaining a media framing exercise.

The Bar Council of India's AI-use guidelines — no deadline was set by the Supreme Court's July 2 direction. Their scope — disclosure duties, verification standards, sanctions — will show whether the judiciary's zero-tolerance ruling stays a citation-hygiene rule specific to courts or becomes a template other professional bodies borrow, the way the reported horizontal law borrows RBI's kill-switch language.

Whether India appears in the first wave of any future US pre-release review process — the GPT-5.6 gate and the Fable 5 shutoff both excluded India from any privileged early-access tier; both also resolved into general, undifferentiated global access once the gate lifted. Whether that pattern holds for the next frontier release, or whether India starts appearing on the kind of coordinated-access list GPT-5.6's preview ring represented, is the cleanest external signal of how much weight India's own sovereignty argument is carrying with the labs that matter to it.

The emergency-powers clause's actual text, whenever it arrives. Given the eighteen-day arc of the Fable 5 story and the twelve-day arc of the GPT-5.6 story, both now fully resolved within the archive, India's drafters have two worked examples — disclosed late, narrowly scoped, resolved within roughly two to three weeks each — to measure a domestic clause against. Whether the eventual text requires faster disclosure, broader consultation, or a shorter maximum gating window than either precedent is the single most legible test of whether India is building a stronger version of the power it watched exercised this week, or a weaker one.

The reversal, read straight

Return to the question the lede opened with: why did MeitY's position flip this week, and not some other week. The honest answer is not that India suddenly discovered a domestic AI harm large enough to require a statute — nothing in the archive this window names one. The more precise answer is that the case for a light-touch, advisory-only posture got harder to make with a straight face in a week when the two governments India's builders actually depend on for frontier capability demonstrated, twice, that model access is a lever a state pulls when it decides to, on its own schedule, with disclosure arriving after the fact rather than before. Krishnan's July 9 language — a process of drafting, stakeholder discussions, no text yet — is not evidence India has solved anything. It is evidence that the question "should India have the power to do this too, and on what terms" stopped being hypothetical the same week two other governments answered it for their own citizens without being asked.

What the framework will actually contain is still unwritten, and the honest position, seven months into a debate that just restarted, is that nobody outside the drafting room knows yet whether emergency powers land closer to the EU's slow, codified, six-year-and-counting model or something faster and less specified. What is settled, for now, is only the direction: India decided this week that not having the tool was no longer the safer choice than building one — and it made that decision with two live demonstrations, from outside its own borders, of exactly what the tool does when a government reaches for it.

Sources

  • 2025-12 / 2026-06-10 / 2026-07-03 / 2026-07-09. MeitY's AI-law reversal sequence — Krishnan's December 2025 no-new-law position, Vaishnaw's June 10 PTI statement, Krishnan's July 3 statement, and his July 9 CII GCC Business Summit remarks. India AI Digest 2026-07-08 and India AI Digest 2026-07-09 .
  • 2026-06-24. RBI draft Guidance on Regulatory Principles for Model Risk Management, comment window through July 24. India AI Digest 2026-07-08 and India AI Digest 2026-07-09 .
  • 2026-06-30 / 2026-07-01 / 2026-07-02. Anthropic redeploys Claude Fable 5 globally, announces cross-lab jailbreak severity-scoring framework. India AI Digest 2026-07-07 .
  • 2026-07-09. Anthropic moves Fable 5 to metered usage-credit billing at $10/$50 per million tokens. India AI Digest 2026-07-09 .
  • 2026-06-26 / 2026-07-09. OpenAI's GPT-5.6 government-coordinated preview and general-availability launch, including ChatGPT Work. India AI Digest 2026-07-07 , India AI Digest 2026-07-10 , and India AI Digest 2026-07-12 .
  • 2026-07-02. Reported OpenAI proposal to cede 5% equity to a US sovereign wealth fund. Financial Times reporting, corroborated by CNBC, TechCrunch, and Forbes. India AI Digest 2026-07-09 .
  • 2026-07-02. Supreme Court sets aside NCLT/NCLAT orders built on AI-hallucinated citations, Pooja Ramesh Singh v Jammu and Kashmir Bank Ltd, 2026 INSC 668; directs Bar Council of India to frame AI-use guidelines. India AI Digest 2026-07-07 .
  • 2026-07-09. NeGD empanels six firms as standing AI-implementation partners for government; empanelment dated to an April 22, 2026 letter. India AI Digest 2026-07-12 .
  • 2026-07-10. NASSCOM chair Srikanth Velamakanni's "smart interdependence" framing, Bloomberg Emerging interview. India AI Digest 2026-07-10 .
  • EU AI Act (Regulation (EU) 2024/1689) — risk-tiered structure. European Commission, regulatory framework overview.
  • China's generative-AI algorithm registration regime, 2023. Cyberspace Administration of China measures, English translation via Stanford DigiChina.