**Executive Summary:**
The Ministry of Electronics and Information Technology addresses concerns regarding data privacy and national security related to AI applications. India's AI strategy focuses on democratizing technology use, creating economic opportunities, and establishing a robust AI ecosystem. The government is taking steps to host open-source AI models, enforce legal provisions against cybercrimes, and issue advisories to ensure data protection and responsible AI usage. An Advisory Group on AI has been formed to develop an India-specific regulatory framework.
**Key Points / Main Content:**
* **India's AI Strategy:**
* Aims to position India as a global AI leader.
* Launched the IndiaAI mission in March 2024 with seven key pillars.
* Focuses on addressing India-centric challenges and creating economic and employment opportunities.
* MeitY is hosting open-source AI models on the AIRAWAT compute infrastructure.
* **Legal Provisions (IT Act, 2000 & BharatiyaNyay Sanhita, 2023):**
* Sections 66C, 66D, 66E, 67A and 67B of the IT Act, 2000 address identity theft, cheating by personation, and publishing obscene material.
* Section 111 of the BNS, 2023 punishes cybercrimes and economic offenses by organized crime syndicates.
* Sections 318, 319, 353, and 356 of the BNS deal with cheating, public mischief, and defamation.
* **Data Protection Measures:**
* The Digital Personal Data Protection Act, 2023, mandates data fiduciaries to safeguard digital personal data and ensures the rights and duties of data principals.
* IT Rules, 2021, impose legal obligations on intermediaries to ensure accountability for safe internet usage, including the removal of misinformation and deepfakes.
* A grievance redressal mechanism under the IT Rules, 2021, provides timelines for addressing grievances related to morphed or artificially generated images.
* Ministry of Home Affairs has launched cybercrime reporting portal cybercrime.gov.in and tollfree number 1930.
* **CERT-In Advisories/Guidelines:**
* Published advisory on AI safety measures in May 2023.
* Launched Certified Security Professional in Artificial Intelligence (CSPAI) program in September 2024.
* Issued best practices for generative AI solutions in March 2025.
* Released technical guidelines for Bill of Materials (BOM) for software, hardware, AI, and quantum cryptography in July 2025.
* **AI Regulatory Framework:**
* Government has constituted an Advisory Group on AI for India-specific regulatory framework.
**Impact Analysis:**
* **Data Fiduciaries:**
* *Impact:* Obligated to safeguard digital personal data and be accountable for its protection.
* *Action Required:* Implement measures to comply with the Digital Personal Data Protection Act, 2023.
* **Intermediaries (Social Media Platforms):**
* *Impact:* Legally obligated to ensure accountability for safe internet usage, including the removal of misinformation and deepfakes.
* *Action Required:* Establish and maintain a grievance redressal mechanism as per IT Rules, 2021, and take swift action against prohibited content.
* **Indian Citizens (Data Principals):**
* *Impact:* Rights and duties defined under the Digital Personal Data Protection Act, 2023, ensuring their personal data is protected.
* *Action Required:* Understand their rights regarding data protection and utilize grievance redressal mechanisms if necessary.
* **Cybersecurity Professionals:**
* *Impact:* Enhanced skills and knowledge to secure AI systems through the CSPAI program.
* *Action Required:* Participate in the CSPAI program to address AI-related threats and ensure trustworthy AI deployment.
* **AI Developers and Researchers:**
* *Impact:* Access to open-source AI models via API on a chargeable basis.
* *Action Required:* Utilize available resources responsibly and adhere to ethical guidelines.
Key Entities Referenced
DeepSeek AI: An AI application raising data privacy and national security concerns.
IndiaAI mission: A strategic initiative launched in March 2024 to establish a robust and inclusive AI ecosystem in India.
AIRAWAT: Compute infrastructure managed by CDAC Pune, hosting open-source AI models.
CDAC Pune: Centre for Development of Advanced Computing, Pune, managing the AIRAWAT infrastructure.
IT Act, 2000: Information Technology Act, 2000, containing legal provisions related to cybercrimes and data protection.
BharatiyaNyay Sanhita, 2023: A legal code that includes provisions for punishing cybercrimes.
Digital Personal Data Protection Act, 2023: Legislation focused on safeguarding digital personal data and establishing accountability for data fiduciaries.
Information Technology Intermediary Guidelines and Digital Media Ethics Code Rules, 2021: Rules imposing legal obligations on intermediaries, including social media platforms, to ensure a safe and trusted internet.
GOVERNMENT OF INDIA
MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY
LOK SABHA
UNSTARRED QUESTION NO. 574
TO BE ANSWERED ON: 23.07.2025
CONCERNS OF DATA PRIVACY AND NATIONAL SECURITY WITH DEEPSEEK AI
574. SHRI MANISH TEWARI:
Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state:
(a) whether the Union Government is aware of the data privacy and national security concerns
associated with the DeepSeek AI application, as highlighted by several international organisations;
(b) the details of steps, if any, taken by the Government to assess the data storage, processing and
security practices of DeepSeek AI, particularly with regard to Indian users' personal data;
(c) the reasons for not banning the DeepSeek AI application in the country, despite bans imposed
by other countries to safeguard national security and user data privacy; and
(d) whether the Government proposes to issue any advisories or take regulatory measures to ensure
that Indian citizens' data is not exposed to potential misuse through such applications and if so, the
details thereof?
ANSWER
MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY
(SHRI JITIN PRASADA)
(a) to (d): India’s AI strategy is based on the Hon’ble Prime Minister's vision to democratize the
use of technology. It aims to address India centric challenges, create economic and employment
opportunities for all Indians.
AI ecosystem in India at present:
India has a strong information technology ecosystem. It generates annual revenues of more than
250 billion dollars and provides employment to more than 6 million people.
Global rankings such as Stanford AI rankings place India among the top countries in AI skills,
capabilities, and policies to use AI. India is also the second-largest contributor to GitHub AI
projects, showcasing its vibrant developer community.
India’s AI strategy:
India’s AI strategy aims to position India as a global leader in artificial intelligence. Government
launched IndiaAI mission in March 2024. It is a strategic initiative to establish a robust and
inclusive AI ecosystem aligned with India's development goals through its seven key pillars.
Hosting open-source AI models:
MeitY is in the process of hosting open-source AI models on the AIRAWAT compute
infrastructure managed by CDAC-Pune. At present, three open-source models from the LLAMAfamily have been deployed and are accessible to the developer community via API on a chargeable
basis.
Legal provisions under IT Act, 2000:
• Sections 66C (Punishment for identity theft) deals with misinformation, deepfakes, cheating
by personation or identity theft.
• Section 66D of the IT Act criminalizes the use of computer resources for cheating by
personation.
• Section 66E prescribes the punishment for capturing and publishing or transmitting the image
of a private area of any person without his or her consent.
• Section 67A and 67B make publishing or transmitting obscene material for instance, which
could be generated by using deepfake technology a punishable offence.
Legal provisions under BharatiyaNyay Sanhita, 2023:
• Section 111 of the BNS punishes the commission of any continuing unlawful activity including
economic offence, cyber-crimes, by any person or a group of persons, either as a member of
an organised crime syndicate or on behalf of such syndicate.
• Several other sections under the BNS also deal with cyber-crimes like cheating or cheating by
personation such as sections 318 (Cheating), 319 (cheating by personation), 353 (public
mischief), 356 (defamation).
Digital Personal Data Protection Act, 2023
• It casts obligations on Data Fiduciaries to safeguard digital personal data, holding them
accountable, while also ensuring the rights and duties of Data Principals.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules,
2021 (“IT Rules, 2021”)
• Central Government after extensive public consultations with relevant stakeholders has
notified the IT Rules, 2021.
• The IT Rules cast specific legal obligations on intermediaries, including social media
intermediaries and platforms, to ensure their accountability towards safe and trusted internet
including their expeditious action towards removal of the prohibited misinformation, patently
false information and deepfakes.
• In case of failure of the intermediaries to observe the legal obligations, they are liable for
consequential action or prosecution as provided under the extant laws.
• Under the IT Rules 2021, there is a provisions grievance redressal mechanism by the
intermediaries which inter-alia provides 24 hours of timelines for any grievances relating to
morphed or artificially generated images affecting the victim. If not satisfied with the
grievance redressal, aggrieved persons can approach Grievance Appellate Committee.
• Ministry of Home Affairs has launched a dedicated portal to report cybercrimes
[cybercrime.gov.in] and has also started a toll-free number 1930.
Indian Computer Emergency Response Team (CERT-In) Advisories/Guidelines:
• An advisory on safety measures to be taken to minimize the adversarial threats arising from
Artificial Intelligence (AI) based applications was published in May 2023.• The Certified Security Professional in Artificial Intelligence (CSPAI) program launched by
CERT-In and SISA in September 2024.
• An advisory depicting best practices for effective and responsible use of Generative AI
solutions was published in March 2025.
• Technical guidelines for Bill of Materials (BOM) for Software, Hardware, Artificial
Intelligence and Quantum & Cryptography requirements have been issued for enhancing the
security and transparency of software and emerging technologies supply chains in July 2025.
• The CSPAI program equips cybersecurity professionals with the skills to secure AI systems,
proactively address AI-related threats, and ensure trustworthy AI deployment in business
environments.
Government has constituted an Advisory Group on AI for India-specific regulatory AI
framework under the chairmanship of Principal Scientific Advisor (PSA) to Prime Minister. It
has members from diverse stakeholders from academia, industry and government.
*****