**Executive Summary**
This document outlines the legal safeguards implemented in India to protect children from potential harms arising from AI and related technologies. These safeguards are based on the Prime Minister's vision for democratizing technology. Key legal frameworks, regulations, and initiatives are detailed, with a focus on preventing the hosting or sharing of harmful content, protecting children's personal data, and promoting cyber safety.
**Key Points / Main Content**
* **Information Technology (IT) Act, 2000 and IT Rules:**
* Intermediaries must prevent hosting or sharing content harmful to children, including sexually explicit or violent material.
* Unlawful content must be removed within 3 hours (2 hours for non-consensual sexual/intimate content) of notification.
* Platforms must report related offenses under laws like the Bharatiya Nagarik Suraksha Sanhita, 2023, and the Protection of Children from Sexual Offences Act, 2012.
* **Protection of Children's Data (DPDP Act, 2023 and Rules, 2025):**
* Covers personal data collected through technologies, including AI-powered toys.
* Requires verifiable parental consent before processing a child's personal data.
* Prescribes mechanisms for obtaining parental consent, including identity and age verification.
* Prohibits tracking, behavioral monitoring, and targeted advertising at children.
* **CERT-In Initiatives:**
* Regularly disseminates safety, security tips, awareness posters, infographics, and videos on online safety for children.
* **Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules):**
* Organizations must collect personal data only for stated purposes and obtain consent before sharing.
* Privacy policies must be published, and sensitive personal data must not be published or further disclosed.
* **India AI Governance Guidelines:**
* Promote human-centric and responsible AI development, recognizing children's vulnerability to AI risks.
* Recommend risk assessment frameworks and monitoring of AI-related harms.
* **Regulatory Framework for Toy Safety and Harmful Content:**
* Toys must comply with Toy Quality Control Order and BIS standards.
* Harmful or explicit content involving children is regulated under the IT Act, IT Rules, and POCSO Act.
* **Information Security Education and Awareness (ISEA):**
* Programs aim to build human resources in information security and raise general awareness on cyber hygiene.
* Extensive workshops have been conducted for various demographics, including school children, teachers, and law enforcement.
* **Studies and Guidelines by NCPCR:**
* NCPCR conducted a study on the effects of mobile phone and internet device usage on children.
* NCPCR has published guidelines on cyber safety and protection for children, including "Being Safe Online" and guidelines for schools on preventing bullying and cyberbullying.
* NCERT has released a handbook on "Safe online learning."
* **Measures to Strengthen National Response to Cybercrimes:**
* **National Cyber Crime Reporting Portal:** Operated by MHA for citizens to report cybercrimes, with a focus on crimes against children.
* **Indian Cyber Crime Coordination Centre (I4C):** Ensures coordinated action against cybercrime, including child sexual exploitation.
* **Financial Assistance:** Provided to States/UTs for capacity building in cybercrime prevention.
* **Website Blocking:** Periodic blocking of websites containing Child Sexual Abuse Material (CSAM) based on Interpol inputs.
* **ISP Directives:** Internet Service Providers are directed to block CSAM websites and promote parental control filters.
* **Public Awareness:** Initiatives like @CyberDost, radio campaigns, and handbooks promote cyber safety.
* **MoU with NCMEC, USA:** Enables sharing of tipline reports on online child sexual exploitation for prompt action.
**Impact Analysis**
**Children**
* **Impact:** Increased protection from harmful online content, exploitation, and misuse of their personal data due to various legal safeguards and awareness programs.
* **Action Required:** No direct action required from children; they are the beneficiaries of these protections.
**Intermediaries (e.g., Social Media Platforms)**
* **Impact:** Obligated to remove unlawful content within strict timeframes and report related offenses.
* **Action Required:** Implement robust content moderation systems, ensure prompt removal of reported harmful content, and establish reporting mechanisms for offenses.
**Organizations collecting personal data**
* **Impact:** Must adhere to stated purposes for data collection, obtain consent before sharing, and publish privacy policies. Sensitive personal data requires special handling.
* **Action Required:** Review and update data collection, consent, and privacy policies to comply with DPDP Act and SPDI Rules. Implement measures to protect sensitive personal data.
**Parents and Lawful Guardians**
* **Impact:** Have the right and responsibility to provide verifiable consent for the processing of their child's personal data.
* **Action Required:** Exercise due diligence in providing consent and utilize available resources on cyber safety to protect their children online.
**Law Enforcement and Government Agencies**
* **Impact:** Enhanced tools and frameworks for investigating and prosecuting cybercrimes, with a focus on child protection.
* **Action Required:** Utilize the National Cyber Crime Reporting Portal, I4C, and financial assistance for capacity building to effectively combat cybercrimes against children.
**Internet Service Providers (ISPs)**
* **Impact:** Directed to dynamically block CSAM websites and promote parental control filters.
* **Action Required:** Implement technical measures to block identified CSAM websites and actively promote parental control solutions to users.
Key Entities Referenced
Information Technology (IT) Act, 2000: This act and its associated rules address intermediaries' responsibilities in preventing the hosting or sharing of content harmful to children.
Digital Personal Data Protection Act, 2023: This act and its rules provide special safeguards for processing children's personal data, requiring verifiable parental consent.
Indian Cyber Crime Coordination Centre (I4C): An established entity to ensure coordinated action against cybercrime, including child sexual exploitation.
Ministry of Home Affairs (MHA): Operates the National Cyber Crime Reporting Portal and supports the Cyber Crime Prevention against Women and Children Scheme.
National Commission for Protection of Child Rights (NCPCR): Has conducted studies and prepared guidelines on cyber safety and protection of children.
Ministry of Electronics & IT
Legal safeguards in place to prevent potential
harms that may arise from AI and related
technologies
Posted On: 11 MAR 2026 3:55PM by PIB Delhi
India's AI strategy is based on Hon'ble Prime Minister's vision of democratizing technology. It aims to
address India centric challenges, create opportunities and ultimately improve the lives of citizens.
At the same time, the Government is conscious of the potential harms that may arise from AI and related
technologies.
Legal safeguards are in place to prevent harm towards children:
1. Information Technology (IT) Act, 2000
IT Act, 2000 and IT Rules require intermediaries (social media platforms) to prevent hosting or sharing
content that is harmful to children including content that is sexually explicit or promotes violence.
Platforms must remove unlawful content within 3 hours (2 hours for non-consensual sexual/intimate
content) of being notified by the government or court order.
Platforms are also obligated to report to appropriate authorities about the related offences under laws such
as Bharatiya Nagarik Suraksha Sanhita, 2023, or the Protection of Children from Sexual Offences Act,
2012.
2. Protection of Children’s Data (DPDP Act, 2023)
Digital Personal Data Protection Act, 2023 and Rules, 2025 cover personal data collected through
technologies including AI-powered toys
Act provides special safeguards for processing of personal data of children by mandating the verifiable
consent of the parent or lawful guardian before processing any personal data of a child
The Rules prescribe operational mechanisms for obtaining verifiable parental consent, including through
identity and age verification measures and the use of virtual tokens.
The act and rules made there under prohibit tracking, behavioural monitoring or targeted advertising
directed at children.
3. CERT-In regularly shares safety, security tips, and awareness posters, infographics, and videos on its
official websites and social media handles to sensitise internet users about online safety measures for
children.
4. Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal
Data or Information) Rules, 2011, (SPDI Rules).These rules require organisations to collect personal data only for stated purposes, obtain consent before
sharing it, and publish privacy policies. Sensitive personal data must not be published and must not be
further disclosed by third parties.
5. India AI Governance Guidelines
These Guidelines promote human-centric and responsible AI development. It recognize that children
constitute a vulnerable group that may face risks from AI systems, and long term harm.
The Guidelines recommend risk assessment frameworks and monitoring of AI-related harms to help
policymakers better understand real-world risks from AI systems and design appropriate governance
responses.
6. Regulatory Framework for Toy Safety and Harmful Content
Toys in India must comply with Toy Quality Control Order and BIS standards, while harmful or explicit
content involving children is regulated under the IT Act, IT Rules and POCSO Act.
7. Information Security Education and Awareness (ISEA)
Programmes have been conducted for generating human resources in Information Security and creating
general awareness on various aspects of cyber hygiene and cyber security.
So far, 4,309 awareness workshops conducted across the country covering over 9.63 lakh participants,
including school/colleges students, teachers, law enforcement, government personnel, and general public.
1,186 awareness workshops were conducted for school children and students covering 3.38 lakh
participants.
1.13 lakhs school teachers, police personnel & volunteers have been trained as master trainers in 66
programs and around 15 crores estimated beneficiaries covered through indirect mode.
8.Studies conducted by the National Commission for Protection of Child Rights (NCPCR):
NCPCR has conducted a study on “Effects (Physical, Behavioural and Psycho- social) of using Mobile
Phones and other Devices with Internet Accessibility by Children” in 2021. The study report is available
at: https://ncpcr.gov.in/uploads/165650458362bc410794e02_effect1.PDF
Additionally, NCPCR has prepared following guidelines on Cyber Safety and Protection of children:
Guideline and standard content for raising awareness among children, parents,educators and general
public titled “Being Safe Online” is available at:https://ncpcr.gov.in/public/uploads/1661337049630
5fdd946c31_being-safe-online.pdf
Guidelines on Cyber Safety (for inclusion in) Manual on Safety and Security of Children in Schools
are available at:https://ncpcr.gov.in/uploads/16613369326305fd6444e1b_cyber-safety- guidline.pdf
Guidelines for Schools for prevention of bullying and cyber bullying” are available at:https://ncpcr.g
ov.in/uploads/1714382687662f675fe278a_preventing-bullyingandcyberbullying-guidelines-for-scho
ols-2024.pdf
National Council of Educational Research and Training has also released a handbook on “Safe online
learning in times of COVID-19”. The handbook is available athttps://ncert.nic.in/pdf/announcement/Safet
olearn_English.pdf
9.Additional measures to strengthen the national response to cybercrimes:
To further strengthen the mechanism to deal with such cybercrimes in a coordinated manner, the
Government has also taken several other measures, including the following:Ministry of Home Affairs (MHA) operates National Cyber Crime Reporting Portal
(www.cybercrime.gov.in) to enable citizens to report all cybercrimes, with special focus on crimes
against children
Indian Cyber Crime Coordination Centre (I4C) has been established to ensure coordinated and
comprehensive action against cybercrime, including child sexual exploitation
Financial assistance is provided to States/UTs under the Cyber Crime Prevention against Women
and Children Scheme for capacity building, including cyber forensic laboratories and training of
police, prosecutors and judicial officers
Government periodically blocks websites containing Child Sexual Abuse Material (CSAM) based
on inputs from Interpol, routed through the Central Bureau of Investigation (CBI)
Internet Service Providers have been directed to dynamically block CSAM websites using global
databases such as the Internet Watch Foundation (UK) and Project Arachnid (Canada)
ISPs have also been advised to promote parental control filters and block access to identified CSAM
websites, including through international gateways
Public awareness on cyber safety is promoted through initiatives such as @CyberDost, radio
campaigns, and publication of handbooks for students and adolescents
MoU has been done between NCRB (MHA) and the National Center for Missing and Exploited Children
(NCMEC), USA . This enables sharing of tipline reports on online child sexual exploitation, which are
further disseminated to States/UTs through the national portal for prompt action.
This information was provided by the Union Minister for Electronics & Information Technology Shri
Ashwini Vaishnaw in Lok Sabha today.
****
MSZ
(Release ID: 2238191) Visitor Counter : 169
Read this release in: Gujarati , Urdu , ही