The Ministry of Electronics and Information Technology is examining a consent based framework for synthetically generated content, limits on the autonomy of agentic AI, and regulatory sandboxes for high risk applications, as it weighs whether India needs a dedicated artificial intelligence law.

The significant procedural choice is that any such law would stand on its own rather than sit under the Information Technology Act of 2000. The ministry's cyber laws division has been asked to audit the IT Act and the rules made under it to find the gaps. That is the right sequence: you cannot sensibly draft a new statute until you know what the existing one already reaches.

Synthetic content is the more tractable half. It means digital media made or altered by a machine rather than a person, and a consent requirement puts the question where it belongs, on whether the person depicted agreed.

Agentic AI is where this gets genuinely hard. These are systems that take a high level goal and independently plan multi step actions, call external tools, and adjust as they go with little human supervision. The government is expected to consider how much autonomy such agents should have, and whether they may retain and reuse data they encounter. Both questions cut across every sector at once, which is why the ministry is expected to consult the Reserve Bank of India and the Securities and Exchange Board of India on a sandbox.

Two outside legal experts have been asked to submit separate draft liability frameworks. Liability is the crux. When an agent acting on a goal causes loss, the law has to say whether responsibility sits with the deployer, the model developer, or the person who set the goal, and today it does not.