Japan’s Sakana AI Raises $135 Mn in Series B Funding Round

Sakana AI has announced on November 17 that it has raised $135 million (20 billion Yen) for its Series B round to accelerate its mission to develop AI sustainably and implement AI that benefits Japan.

The funding was received from new and existing investors, including Mitsubishi UFJ Financial Group (MUFG), Khosla Ventures, Factorial, Macquarie Capital, Fundomo, Mouro Capital, New Enterprise Associates, Geodesic Capital, Lux Capital, Ora Global, MPower Partners, Shikoku Electric Power, and In-Q-Tel (IQT).
The Series B funding will be allocated to accelerate R&D, with a focus on advancements in artificial intelligence through collective intelligence and self-evolution, particularly for the optimisation of Sovereign AI.

The company will strengthen its Applied Team to deepen finance partnerships and explore opportunities in defence and manufacturing. Additionally, it aims to build a scalable ecosystem by pursuing strategic investments, partnerships, and mergers and acquisitions for long-term global growth.

“Sakana AI’s unique determination to develop frontier AI technology sustainably, through innovation, aligns with our core values as Japan’s first ESG-integrated global VC fund investing in technologies that transform industries and society,” Kathy Matsui, general partner at MPower Partners, said.

Furthermore, this funding round has inflated Sakana AI’s valuation to around $2.635 billion (400 billion yen), setting a new record for unlisted startups in Japan.

The amount raised is approximately double that of the Series A funding acquired in September of the previous year. The new resources will be allocated toward the development of Sakana AI’s proprietary large language model (LLM).

Sakana AI’s LLM is designed to reflect the nuances of the Japanese language and culture, making it suitable for local industries. Until now, the startup has collaborated with entities such as MUFG and Daiwa Securities Group.

“For Japan, with a declining workforce and an ageing population, the benefits of AI technology are clear. Sakana AI is now entering its most exciting phase: deploying R&D into the business and public sectors,” the company said in a statement.

The post Japan’s Sakana AI Raises $135 Mn in Series B Funding Round appeared first on Analytics India Magazine.

7 Times AI Went to Court in 2025

The generative AI boom has unleashed a new wave of legal battles, and 2025 may go down as a watershed year. From entertainment giants to regulators and even rival tech founders, several lawsuits are crystallising how copyright, safety, and competition rules apply in the age of artificial intelligence (AI).

To understand how these issues are unfolding, here are seven examples of legal actions shaping the development and oversight of AI.

1. Disney & Universal vs Midjourney

On June 11, Disney and Universal filed a landmark suit in a US district court for Central California against Midjourney, Inc., accusing the AI company of infringing their copyrighted characters. According to the studios, Midjourney trained its image-generation model on their IP, including characters like Darth Vader, Minions, Elsa, Shrek and Buzz Lightyear without permission, and is now producing unauthorised copies for paying users. The complaint characterises Midjourney as a “bottomless pit of plagiarism” and seeks a preliminary injunction, damages, and a ban on further infringing content.

The case marks a critical moment: two of Hollywood’s biggest content owners argue that without limits, generative models could undercut the very business models they built.

2. Getty Images vs Stability AI

Getty Images sued Stability AI, maker of Stable Diffusion, in the UK, alleging that millions of its copyrighted photographs were scraped and used without authorisation to train the model. Stability, for its part, argued that its models do not store or reproduce the original images. The court agreed, ruling that there are “no copies in the model.” Getty also raised trademark claims, saying some AI-generated images still bore Getty’s watermark; the court found limited trademark infringement. Crucially, Getty dropped its key copyright-infringement claims tied to where training happened, which underscores how territorial issues—where training or scraping occurs—may shape future AI copyright litigation.

3. Raine vs OpenAI

The family of 16-year-old Adam Raine filed a wrongful-death lawsuit against OpenAI in August, alleging that the company weakened self-harm guardrails in ChatGPT before launching GPT-4o. The amended complaint argues OpenAI prioritised user engagement over safety, claiming that ChatGPT responded improperly to Raine’s suicidal ideation, and that the company ignored clear risks linked to its AI behaviour.

If the court finds OpenAI liable, it could force a reevaluation of how AI platforms incorporate psychological safety by design and whether they owe a duty of care to vulnerable users, especially minors.

4. State of Utah vs Snap Inc

On June 30, Utah’s attorney general and commerce department sued Snap Inc., accusing Snapchat of designing addictive features, like streaks and ephemeral messages, and misrepresenting the safety of its AI chatbot, My AI. According to Utah, Snap withheld critical data collection disclosures, including geolocation and biometric data, and profited by exploiting teenage users’ vulnerabilities.

The complaint asserts that the company’s design and engagement algorithms effectively “caught” minors in addictive loops, raising novel arguments about duty of care, algorithmic supervision, and child-safety regulation in digital products.

5. xAI / X Corp vs Apple & OpenAI

On August 25, Elon Musk’s xAI and X Corp filed a 61-page lawsuit in Texas against Apple and OpenAI, accusing both companies of anti-competitive behaviour. The complaint alleges Apple gave ChatGPT preferential treatment in the App Store and deeply integrated it into iOS, via Siri or Apple Intelligence, making it harder for rivals like xAI’s Grok to compete. xAI claims this creates a “moat” protecting OpenAI’s dominance and seeks injunctive relief, as well as billions in damages. A US district judge denied Apple and OpenAI’s request to have the lawsuit dismissed, meaning the case will continue, and xAI’s antitrust claims will now undergo more thorough legal scrutiny.

6) Anthropic’s $1.5 Billion Copyright Settlement

In a separate but equally consequential case, this year, Andrea Bartz, Charles Graeber, Kirk Wallace Johnson, et al. vs Anthropic PBC,Anthropic—maker of the Claude chatbot—agreed to pay $1.5 billion to settle a class-action lawsuit by authors and publishers. The plaintiffs had alleged that Anthropic downloaded millions of copyrighted books, including from pirate “shadow libraries”, without permission. Earlier, in June, a US judge ruled that Anthropic’s use of these books to train Claude was “exceedingly transformative” and thus constituted fair use, but the court also found that the way it stored pirated books in a central library was infringing.

7) Robby Starbuck vs Google

On October 22, activist and filmmaker Robby Starbuck filed a defamation lawsuit against Google, alleging that its AI models Bard, Gemini and Gemma generated fabricated statements falsely linking him to murder and child abuse. Starbucks claims that Google failed to prevent the spread of these statements and did not take timely corrective action even after receiving notice. His legal team argues that the incident caused severe personal and professional harm. The case is being closely watched because it could establish new rules on defamation, platform responsibility and AI hallucination liability.

The post 7 Times AI Went to Court in 2025 appeared first on Analytics India Magazine.

Indian IT Firms Rush to Adopt ISO 42001 as AI Enters Accountability Era

Even before regulators could decide how to govern AI, India’s IT services companies have started rewriting their own rulebooks.

At Mphasis, that rewrite concretised with the recent ISO/IEC 42001:2023 certification it was presented with, a first-of-its-kind international standard for AI management systems (AIMS) designed to ensure that organisations build, deploy, and monitor AI responsibly.

The standard provides an auditable framework for governing risks such as bias, data integrity, model drift, and ethical compliance, making it increasingly essential for enterprises in regulated or large-scale AI environments.

Mphasis told AIM the framework is being “embedded directly into our AI development and deployment processes within Mphasis.ai,” creating uniform governance across the full lifecycle.

Every AI project now incorporates “mandatory steps for risk assessment, bias mitigation, transparency documentation, and compliance with ethical guidelines,” making responsible AI a non-negotiable part of delivery. The company has restructured governance accordingly, establishing an AI Risk Management Committee and formal accountability for AI system owners.

Documentation requirements have been tightened; fairness checks, data validation, and systematic monitoring are now required at each stage. This aligns with the ISO’s continuous improvement loop, which Mphasis describes as embedding “the ISO’s ‘Plan-Do-Check-Act’ approach into our existing engineering culture.”

It expects measurable gains, saying the certification “strengthens our competitive positioning and helps reduce project risk”, while enabling faster time-to-value and smoother entry into regulated markets.

With 68% of new deals now AI-led, Mphasis says scalability is ensured by NeoIP, where Ontosphere applies governance automatically so responsible AI becomes “a scalable, self-sustaining capability.”

The Big Picture

The broader industry is moving in the same direction. Infosys, Cognizant, and other Indian IT providers have begun adopting ISO/IEC 42001 to meet rising expectations from global clients navigating tightening AI regulations.

NABCB, India’s national accreditation body, has played a pivotal role in operationalising ISO/IEC 42001 by becoming one of the earliest global bodies to approve accreditation schemes for the new AI management standard.

Its framework, launched in 2024, enables Indian certification bodies to conduct ISO 42001 audits under internationally recognised conformity norms.

This has effectively allowed Indian IT and enterprise organisations to be among the first globally to obtain certifiable, regulator-ready AI governance credentials.

Infosys’ executive vice-president Balakrishna DR said the certification not only distinguishes the company but “serves as a guiding beacon” for clients managing AI-related risks.

Cognizant CEO Ravi Kumar S said the standard reflects how businesses now expect partners who drive innovation while aligning with their values, adding that the certification “solidifies our role as a trusted leader in enabling ethical and sustainable digital transformation worldwide.”

As enterprises demand auditable controls around bias, transparency, and accountability, ISO 42001 is rapidly emerging as the AI-era equivalent of ISO 27001 for information security.

Mphasis reflects this sentiment, noting that the standard “is poised to become the global benchmark for AI governance,” evolving into a baseline qualification for IT service providers worldwide.

Reto P Grubenmann, director, head of certification & attestation, KPMG Switzerland, noted that ISO/IEC 42001:2023 verifies that a company’s AIMS meets international standards, offering long-term strategic and operational value.

EY similarly wrote that the standard “was crafted to tackle the concerns and obstacles associated with the conscientious deployment of AI technologies,” emphasising controls around security, fairness, transparency, safety, and data quality throughout the AI lifecycle.

EY also draws parallels with ISO/IEC 27001, urging organisations already compliant with it to integrate ISO 42001 to streamline governance and risk oversight.

What once served as a differentiator is now becoming a minimum qualification for companies handling mission-critical AI workloads, marking a decisive shift in how India’s IT sector builds, deploys, and assures AI systems.
As companies deepen their AI capabilities, many are expanding their broader compliance stack to reinforce trust. Certifications such as ISO 27001 for security, ISO 27701 for privacy, ISO 9001 for quality and SOC 2 for service reliability continue to anchor enterprise expectations, while sector-specific frameworks like PCI DSS and HIPAA apply where financial or health data is involved.

The post Indian IT Firms Rush to Adopt ISO 42001 as AI Enters Accountability Era appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.

Why Everyone’s Suddenly Talking About India’s New Data Protection Rules

The central government, on November 14, notified the long-awaited Digital Personal Data Protection (DPDP) Rules, 2025, formally setting in motion India’s multi-stage rollout of a modern privacy regime.

Notably, some of the provisions take effect immediately, most notably the establishment of the Data Protection Board of India (DPBI), headquartered in the National Capital Region (NCR).

Yet, the more profound transformation will unfold gradually over the next 12 to 18 months, as obligations around consent, processing notices, fiduciary responsibilities, and individual rights slowly come into force.

The announcement came after the Business Software Alliance (BSA), an industry body representing global tech giants like Microsoft, AWS, Adobe, IBM, Salesforce and SAP, among others, urged the Indian government to introduce a text and data mining (TDM) exception in copyright law, stressing that it is key to enabling responsible and competitive use of AI across industries.

The announcement also revives a larger question. During public consultation earlier this year, the draft rules received around 9,000 submissions. For a country of 1.4 billion people navigating an increasingly AI-driven digital landscape, does that number signal robust civic engagement or highlight the extent to which citizen awareness is still missing?

“In a country of over 1.4 billion people, expecting every citizen to become an expert on data privacy laws like the DPDP Act is unrealistic. The average person shouldn’t have to dive deep into legal jargon. Citizens should instead be aware of their basic rights and duties in simple terms, three or four key takeaways they can remember and act on. The conversation shouldn’t be about mastering the fine print, but about empowering individuals with the essentials,” said Pawan Prabhat, co-founder of Shorthills AI.

His point underscores that even as India builds one of the world’s most ambitious digital public infrastructures, individuals are still catching up to the fundamentals of data rights. In the age of generative AI, where personal information can be embedded in training sets, inferred by algorithms or profiled at scale, the stakes have never been higher.

But the uncertainty extends beyond citizens. Companies building AI systems face a regulatory landscape that leaves critical gaps unaddressed.

The DPDP Act mandates transparent processing, revocable consent, strong security controls and clearly defined processor contracts. “But the act leaves key AI issues unclear, such as on automated decisions, profiling, model-training uses, sensitive data distinctions, and core processes like consent, deletion, retention and cross-border transfers, creating major accountability gaps,” Srinivas Padmanabhuni, CTO at AIEnsured, told AIM.

While the draft rules attempt to operationalise the act, India is still negotiating the tension between enabling AI innovation and enforcing meaningful privacy protections.

“The establishment of a definite enforcement timeline signals a critical juncture,” said Mayuran Palanisamy, partner at Deloitte India. The rules emphasise breach reporting, verifiable parental consent, consent manager operations, significant data fiduciary criteria and prescriptive safeguards. Successful implementation will require regulators, businesses and consumers to collaborate continuously, and organisations must invest in updated processes, technologies and training to build transparency and integrate privacy into their systems and culture.

Legal experts echo the sentiment by welcoming the clarity, while warning that interpretational guidance will be essential as the rules move from paper to practice.

“The rules offer clear timelines and added flexibility for children’s data, but the real challenge will be delivering scalable, frictionless parental-consent tokens across India’s digital public infrastructure,” said Aparajita Bharti, founding partner at The Quantum Hub.

Children’s data emerges as another critical front in India’s new privacy regime, one where the government has struck a balance between safety, usability and operational flexibility. According to Bharti, the rules now provide the industry a phased compliance roadmap while addressing long-standing concerns around behavioural monitoring, age-appropriate content, parental controls and verifiable consent.

“We welcome these developments. MeitY has provided much-needed clarity and has been judicious in allowing an adequate transition period with major provisions coming into effect 18 months from now,” Shahana Chatterji, partner at Shardul Amarchand Mangaldas & Co, said.

“The industry must now focus on aligning data practices with the Act, and MeitY will need to provide the regulatory and interpretational clarity that will inevitably be needed,” he added.

India is accelerating into an AI-first decade with digital health records, algorithmic credit scoring, predictive governance systems and generative AI woven into daily life. The DPDP Act and its 2025 Rules will become the framework that determines how innovation, rights and accountability coexist.

The next 18 months will define how India interprets privacy in an AI-shaped world at a time when global peers are tightening their own data laws and determining how more than a billion citizens will experience digital agency in the years ahead.

The post Why Everyone’s Suddenly Talking About India’s New Data Protection Rules appeared first on Analytics India Magazine.