Our Expert in India
No results available
Who this guide is for: general counsel, in‑house legal teams, procurement leaders, and vendors or suppliers of generative AI operating in India.
What you will get: practical IP allocation options, sample clauses (ownership versus licence), indemnity language, liability caps, a compliance checklist mapped to India’s information technology rules, and a negotiation playbook for both buyers and vendors.
Estimated read time: 12–15 minutes.
AI contracts India teams are now negotiating in a materially different regulatory environment. India’s information technology framework is evolving to address synthetic media and generative AI, and proposed and amended rules under the Information Technology Act, 2000 point toward operational obligations such as labelling of synthetic content, traceability, designated grievance/compliance contacts and cooperation with takedown notices. As these obligations harden, what used to be soft governance commitments increasingly become contractual requirements. For buyers and vendors, that means IP ownership, warranties, liability caps and indemnities can no longer be treated as boilerplate; they must be drafted to allocate concrete regulatory risk.
Search engines increasingly surface AI-generated summaries for queries like this one, but summaries cannot draft the clause you need to sign next week. This guide fills the gap with clause-level drafting guidance, negotiation levers and a compliance mapping tuned to Indian law.
Methodology note: portions of the sample clauses in this guide were prepared with drafting-assistance tools and then reviewed against the primary regulatory sources cited throughout. Because the regulatory position on synthetic media and AI in India is developing, every clause should be verified against the rules in force at the time of contracting. This article is for general information and does not constitute legal advice.
The single most contested question in AI contracts India negotiations is ownership. When a user submits a prompt and a model returns text, code, images or audio, who holds the rights in that output, the buyer who prompted it, the vendor whose model produced it, or neither? Indian statutory law does not resolve this cleanly for machine-generated material, which is precisely why the contract, not the statute, will usually decide the outcome.
Indian copyright law, governed by the Copyright Act, 1957, is built around human authorship, and there is no bespoke statutory regime that vests ownership of purely machine-generated outputs. This creates uncertainty at the margins: outputs with substantial human direction may attract protection in the hands of the human contributor, while wholly autonomous outputs sit in a grey zone. Because the statute does not squarely address this point, parties should not assume any default allocation, they must contract expressly.
Two other bodies of law shape the picture. First, the Digital Personal Data Protection Act, 2023 governs how personal data used in prompts, fine-tuning or outputs may lawfully be processed, which constrains what a vendor may do with customer-derived material. (Note that the Act’s operative provisions come into force as notified by the Central Government, and the detailed rules under it should be checked for current status.) Second, the Supreme Court’s privacy jurisprudence, recognising informational privacy as a fundamental right in the Justice K.S. Puttaswamy v. Union of India line of cases, informs the standard of care around personal data embedded in training sets and outputs. Ownership drafting therefore cannot be divorced from data governance.
In practice, AI contract clauses allocate output rights through one of several models. The right choice depends on how the buyer intends to commercialise the outputs and how much residual value the vendor wants to retain.
When negotiating ownership of AI outputs India counsel should work through a consistent checklist rather than accepting the vendor’s first draft:
| Model | Buyer rights (what they get) | Vendor risk / commercial trade-off |
|---|---|---|
| Assignment of outputs | Full ownership; unrestricted commercialisation, modification and sublicensing; strongest position in disputes | Loss of residual value; higher price; vendor cannot re-use; may seek indemnity carve-outs and higher fees |
| Exclusive licence (territory/time) | Exclusive use within defined scope; competitors excluded; vendor retains title so buyer avoids maintenance of the IP asset | Revenue concentrated with one buyer within scope; vendor negotiates royalties, reporting and scope limits |
| Non‑exclusive licence | Lawful use of outputs at lower cost; fast to agree | Low vendor risk; buyer accepts that identical outputs may be licensed to others, unsuitable where exclusivity matters |
| Sublicense rights | Ability to extend use to affiliates, customers or partners | Vendor requires flow-down of compliance and indemnity terms; may charge per-sublicensee fees or seek escrow protection |
Ownership of the output is only half the risk. The far larger exposure often sits upstream, in the data on which the model was trained and fine-tuned. If a model was trained on infringing content or on personal data processed without a lawful basis, the buyer can inherit downstream liability. Well-drafted AI contracts India should therefore extend beyond outputs to interrogate provenance.
Buyers should require the vendor to warrant that training data was lawfully acquired, that the vendor holds or has cleared the necessary third-party rights, and that any personal data used was processed consistently with the Digital Personal Data Protection Act, 2023. A robust warranty addresses three risk vectors: third-party contractual rights, copyright in scraped or licensed corpora, and personal data captured in training sets. Where the vendor cannot warrant provenance absolutely, negotiate a qualified warranty backed by an indemnity for third-party infringement claims.
Provenance representations should cover the model itself: its origin, whether it is a foundation model licensed from a third party, how it was fine-tuned, and whether model weights incorporate any restricted or open-source components with reciprocal licensing obligations. This matters because a permissive-looking output can carry hidden licence conditions inherited from the base model. Vendors supplying fine-tuned or wrapped third-party models should disclose the provenance chain so the buyer can assess flow-through obligations.
Because warranties are only as good as the ability to test them, buyers should secure audit and certification rights. These can range from a right to receive third-party audit reports and safety-testing summaries, to a contractual right to inspect data-governance documentation, to periodic vendor certifications of continued compliance. For higher-risk deployments, negotiate the right to commission an independent audit at the vendor’s cost where a material breach is reasonably suspected.
Generative systems produce errors, hallucinations, defamatory statements, biased or infringing content, and liability for AI outputs must be allocated before, not after, an incident. The drafting challenge is to size caps and carve-outs so that risk falls on the party best able to control it, without making the deal commercially unviable for either side.
Start by categorising the harm the deployment could cause. A structured risk matrix lets counsel map each harm type to a liability treatment:
Liability caps are the central negotiation. Vendors typically seek a cap set at fees paid over a defined period; buyers seek higher caps for high-risk categories. The critical work is in the carve-outs, the categories that sit outside the cap or attract a super-cap. Common carve-outs in AI contracts India include gross negligence, wilful misconduct, breach of confidentiality, IP infringement indemnities and, increasingly, regulatory penalties arising from the vendor’s non-compliance with applicable IT rules. Buyers should resist a vendor attempt to exclude all consequential loss where regulatory penalties are foreseeable and directly attributable to the vendor’s default.
Liability drafting should be paired with operational obligations that reduce loss. Require the vendor to notify the buyer of material incidents within a defined window, to cooperate on containment, and, where feasible, to disable, roll back or recall problematic outputs or model versions. For synthetic-media incidents in particular, coordinate the contractual incident-response clause with any applicable takedown and grievance/point-of-contact duties under India’s IT framework so obligations do not conflict during a live event.
This is where most AI contracts India negotiations are won or lost. Warranties allocate the promise, indemnities allocate the money, and remediation allocates the fix. Each should be drafted deliberately, with buyer-side and vendor-side positions understood in advance.
At minimum, a buyer should seek warranties that the service complies with applicable law including the Information Technology Act, 2000 and rules made under it and the Digital Personal Data Protection Act, 2023; that outputs will not knowingly infringe third-party IP; that training data was lawfully sourced; and that deliverables are free of malware or malicious code. Vendors will seek to qualify these with knowledge and materiality thresholds. A balanced outcome usually qualifies the IP warranty by knowledge while keeping the legal-compliance and malware warranties absolute.
A generative AI indemnity clause turns on four variables: scope, trigger, defence control and limitation. Scope defines the losses covered, typically third-party claims for IP infringement, privacy breach and regulatory penalties. Trigger defines what activates the indemnity, a claim, a demand, or actual liability. Defence control determines who conducts the defence and who may settle. Limitation ties the indemnity to, or excludes it from, the general liability cap. The negotiation ranges from buyer-favour to vendor-favour:
Negotiation note: the most contested item is whether regulatory penalties under India’s IT rules sit inside or outside the indemnity. Buyers should push for coverage where the penalty stems from the vendor’s failure to meet its own statutory duties, such as any applicable labelling or traceability obligations.
Money is not always the buyer’s priority; continuity often is. A strong remediation regime should combine service credits for missed performance, rollback rights to a prior stable model version, an obligation to retrain or re-tune where systemic errors are identified, mitigation obligations, and coordinated public communications where an incident becomes public. For synthetic-media harms, remediation and any applicable takedown duties should be sequenced so the vendor acts within the required window.
The distinguishing feature of AI contracts India in the current environment is that regulatory duties are increasingly directly contractible. Rather than a generic “comply with law” clause, counsel should translate each specific duty into an operative obligation that can be monitored and enforced.
India’s evolving rules for intermediaries and synthetic/generative content point toward obligations that map naturally onto contract clauses. Because the precise requirements depend on the rules in force, verify the current text before relying on any specific duty:
Translate each duty into a clause and a control: a labelling clause tied to acceptance testing; a logging and audit clause with defined retention; a notice clause with response SLAs; a regulator-cooperation clause requiring the vendor to assist in responding to lawful requests; and a point-of-contact clause naming a role, not just an individual, so continuity survives staff changes. Each clause on synthetic-media compliance should reference the underlying obligation so the mapping is auditable.
Where personal data is processed, the contract must satisfy the Digital Personal Data Protection Act, 2023 (once its provisions and rules are in force). Include data-processing clauses that specify lawful bases, purpose limitation, restrictions on using personal data for further model training without an independent lawful basis, and a mechanism for handling data-principal requests. Data protection AI contracts should also allocate responsibility for breach notification and cooperation on data-principal rights, ensuring the vendor’s model-training practices do not create a compliance gap for the buyer.
Good AI procurement India practice front-loads risk assessment into vendor selection, so the contract negotiation begins from an informed position rather than a marketing deck.
Treat as red flags any vendor unwilling to disclose model provenance, any refusal to warrant training-data lawfulness, and any blanket exclusion of liability for regulatory non-compliance. Must-haves for the RFP include a commitment to applicable labelling and traceability obligations, a documented incident-response capability, and willingness to accept audit rights. Building these into procurement criteria strengthens the buyer’s negotiating leverage before drafting begins.
Due diligence should request model provenance documentation, red-team and safety-testing results, and any third-party audit reports. For deployments touching personal data, request the vendor’s data-governance documentation and evidence of DPDP-aligned processing. The depth of diligence should scale with the risk category identified in the liability matrix.
Define measurable performance obligations: accuracy or error-rate thresholds appropriate to the use case, explainability expectations where decisions affect individuals, and uptime commitments for the service. Tie these to service credits and to the remediation regime, so a persistent failure to meet accuracy or availability targets triggers concrete remedies rather than abstract dispute.
The clauses below are drafting starting points for AI contracts India negotiations. Each is a template to be adapted to the transaction and verified against current law. Every clause is labelled Draft, for negotiation; verify against law.
Adapt each clause to your transaction and to the rules in force at the date of contracting.
Drafting AI contracts India in a fast-evolving regulatory environment means treating regulatory duties as contract terms, not aspirations. The essentials are clear: fix output ownership expressly because the statute will not resolve it; warrant training-data and model provenance and back the warranty with an indemnity; size liability caps with carve-outs that keep regulatory penalties and IP claims where they belong; map each applicable IT-framework and DPDP duty to an operative clause with a monitorable control; and pair liability with a practical remediation and incident-response regime. Counsel who work through this checklist, and who negotiate from a risk matrix rather than a template, will produce AI contracts India that survive both commercial pressure and regulatory scrutiny.
Adapt the model clauses above to your transaction, verify each against current law, and treat them as the start of a negotiation, not the end of one.
This article is for general information and does not constitute legal advice. Sample clauses are drafts to be adapted and verified with qualified counsel.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Mitakshara Goyal at Svarniti Law Offices, a member of the Global Law Experts network.
posted 6 minutes ago
posted 21 minutes ago
posted 36 minutes ago
posted 51 minutes ago
posted 2 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 7 hours ago
posted 12 hours ago
posted 17 hours ago
posted 18 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message