Last verified: August 30, 2026. This is a neutral descriptive comparison, not policy advocacy. Both frameworks are actively changing.

India and the US are diverging on artificial intelligence governance in 2026. For the Indian diaspora working across both — a US-based engineer at a company with an India team, an NRI founder building a product for both markets, an Indian data scientist reporting to a US manager — the practical implications matter. This is the comparison nobody in the diaspora press has written yet.

India's Framework — What Actually Applies Today

The Digital Personal Data Protection Act (DPDP) 2023

India's baseline data-protection law — comparable in scope to the GDPR but with meaningful differences. Key AI-relevant provisions:

Advertisement
  • Requires explicit consent for processing personal data — including inputs to AI systems that identify individuals.
  • Establishes Data Fiduciary obligations; some entities are classified as "Significant Data Fiduciaries" with additional obligations (impact assessments, DPO appointments).
  • Cross-border transfer of personal data is generally permitted, subject to notified restrictions.

MeitY AI Advisories

The Ministry of Electronics and IT has issued a series of advisories (March 2024, subsequent updates) covering:

  • Labelling of AI-generated content, including deepfakes.
  • Reliability testing before deployment of models to Indian users.
  • Bias evaluation for models used in employment, credit, and other consequential decisions.

The advisories are not always binding as law but are influential in practice, particularly for platforms.

Deepfake and Synthetic Content Rules

India has moved aggressively on synthetic-content labelling. Content-labeling requirements apply to platforms; individual creators face liability under existing IT Rules.

US Framework — The Patchwork

The US does not have a single federal AI law. What exists:

Federal Level

  • Executive branch guidance (subject to change with each administration).
  • Sector-specific rules — FDA on medical AI, EEOC on hiring-algorithm bias, SEC on AI use in financial services.
  • NIST AI Risk Management Framework — voluntary but widely adopted.

State Level (Where the Action Is)

  • Colorado passed the first comprehensive US state AI law, focused on "high-risk" AI systems (employment, credit, education) with impact-assessment requirements.
  • California has multiple relevant laws — AB 1008 (AI transparency), SB 942 (AI content watermarking), CCPA extensions covering automated decision-making.
  • Texas, Illinois, New York, Virginia — each with its own approach; Illinois BIPA remains a significant liability vector for biometric-adjacent AI.

Sectoral Overlays

  • HIPAA for anything touching health data.
  • FCRA if AI is used in credit or employment screening.
  • SOX / FINRA / SEC in financial services.

Practical Consequences for a US Company with an India Team

  • Cross-border data transfer from US to India for training or evaluation typically requires: (a) contractual data-processing agreements, (b) explicit consent flows in the Indian product, (c) documented lawful basis in the DPDP.
  • Bias-evaluation requirements for employment-adjacent models may need to satisfy BOTH Colorado's rules and India's MeitY advisories if you serve customers in both.
  • Data localization — India does not have a hard localization requirement for most AI use cases but has proposed one for sensitive personal data in some drafts. Watch this space.

For an NRI Founder Building for Both Markets

  • Product consent flows must satisfy the stricter of DPDP and applicable US state law — usually California CCPA/CPRA is the binding US benchmark.
  • Content labelling — both India and (increasingly) US states require some form of synthetic-content disclosure. Build it in from day one.
  • Employment-screening use of AI for your own hiring — if any hire could be in Illinois, BIPA restricts your use of biometric evaluation tools. If any hire could be in Colorado, the AI Act's impact assessment applies. India adds a light-touch overlay.

What NRI Employees Should Know

  • Consent to biometric processing — if your employer uses AI for productivity monitoring, resume screening, or interview evaluation, both DPDP and (in some US states) local law require meaningful consent.
  • Right to explanation — the DPDP includes limited rights for individuals affected by automated decisions. Some US state laws (Colorado) go further for high-risk systems.
  • Cross-border employment reviews — if you moved from India to the US inside the same employer, your India-era data may now sit in US systems. DPDP portability provisions may apply.

The Rate of Change

Both frameworks are moving. India's DPDP rules are in staged implementation. US state legislatures are proposing new AI bills every session. Federal-level US movement remains uncertain. What is a stable rule today may be nudged by regulation in 12 months. Design for the direction of travel, not the current-day snapshot.

Advertisement

Companion Reading

  • USCIS AI & The Algorithms Deciding Your Green Card
  • US NRI Money & Compliance Hub 2026
  • India AI regulation 2026 — DPDP Act NRI business

This piece is descriptive comparison, not legal advice. Cross-border AI compliance is complex; consult qualified data-protection counsel in both jurisdictions before making product decisions.