#AD
Corporate governance and compliance for AI businesses has moved from a desk-level worry to a corporate governance priority in India. The rules that decide how AI companies collect data, train models and make automated decisions are now real, dated and enforceable. Founders who assumed artificial intelligence existed in a regulatory grey zone are learning that it does not.
Prem Dharmani, founder of Astro247, has watched this shift up close while building an AI product that handles the personal data of Indian users. His view is direct.
“Governance is not something you switch on once the product works,” says Dharmani. “You either design for it on day one, or you clean up the mess later at many times the cost.”
AI Compliance is a Board Matter, Not an IT Ticket
Directors of any Indian company already carry duties under the Companies Act, 2013. They are answerable for risk oversight, internal financial controls and honest disclosure. Those duties do not pause because the product happens to run on a model.
When an AI system sits at the centre of the business, the risks it creates become the board’s risks. A biased output, a data leak or an automated decision that harms a user is no longer a problem for the engineering team to quietly fix. It is a governance failure the board may have to explain.
Dharmani points out that this is where most AI companies get the structure wrong. They treat AI as a technical detail pushed down to the CTO, while the board signs off on financials it understands and waves through the model it does not. That gap is exactly where compliance problems grow.
The stakes reach past regulators. Investors and acquirers now run data and AI practices through due diligence, and weak governance shows up as a lower valuation or a deal that stalls. For a founder raising capital or planning an exit, clean compliance is part of what the company is worth.
“When an investor asks how you handle user data, the honest answer is either a one-line yes or a long, uncomfortable pause,” says Dharmani. “You want to be the founder who can answer in one line.”
The Compliance Stack Every Indian AI Business Now Sits On
The clearest change is data. The Digital Personal Data Protection Act received Presidential assent in August 2023, and the DPDP Rules 2025 were notified in November 2025 with a phased, 18-month implementation window. Full compliance is due by May 2027, and penalties for serious breaches run up to ₹250 crore.
For AI companies, the sharpest edge is training data. If personal data is used to train or fine-tune a model, that processing needs a lawful basis, and for most businesses that means consent. The consent has to be specific to the purpose, and a user must be able to withdraw it. A model trained on data collected without a proper basis is a liability that does not disappear once the model ships.
The Rules ask for more than consent. They set up a Data Protection Board to hear complaints, require companies to report significant data breaches, and place stricter conditions on the personal data of children, including verifiable parental consent. An AI business also needs a working way for users to raise a grievance and have it resolved. These are the baseline a regulator will expect to see, not optional extras.
Above the data law sits a second layer. MeitY released the India AI Governance Guidelines on 5 November 2025, built on seven guiding principles the framework calls sutras. India has chosen not to pass a single AI Act. Instead, it applies existing laws through a principles-based, sector-led approach and leaves sector regulators to write their own binding rules.
A newer rule speaks to AI-generated content directly. On 10 February 2026, MeitY notified amendments to the IT Rules that require synthetically generated content to be clearly labelled, and these came into force on 20 February 2026. Any AI business whose product creates or alters images, audio or video has to factor labelling and record-keeping into how the product works, rather than treat it as a moderation problem for later.
That patchwork is already forming. The Reserve Bank of India published its FREE-AI framework for the financial sector in August 2025, and other regulators are expected to follow with rules of their own.
Dharmani says that “people keep waiting for one big AI law to tell them what to do. That law is not coming in the shape they expect. In practice you are governed by the data law, the IT rules and whichever regulator covers your sector, all at once. If you wait for a single rulebook, you will already be late.”
Governance By Design, Not By Paperwork
Prem Dharmani’s central point is that compliance built after the fact is weaker and more expensive than compliance built in. A consent flow retrofitted onto a live product tends to be clumsy. A data trail reconstructed months later is likely to have gaps. Documentation written to survive an inquiry, rather than as a record of real decisions, is prone to read that way.
His preferred approach is to treat governance as part of the build. Decide the lawful basis before collecting data. Log how a model was trained and on what. Keep a record of who signed off on high-impact decisions. None of this slows a serious company down for long, and it removes the panic that hits when a regulator, an investor or an acquirer starts asking questions.
He offers a plain example. A company trains a recommendation model on user data gathered under a vague, catch-all consent. The product works, growth is strong, and nobody revisits it. Then a user withdraws consent, or the Board asks on what basis that data was used. Now the team is unpicking a live model instead of pointing to a clean record. The cost of doing it right at the start was a few hours. The cost of fixing it later runs into weeks and legal fees.
Astro247 founder Prem Dharmani presents his views saying “The companies that will grow cleanly are the ones treating governance as product work, not legal cleanup. Regulators are moving towards asking for evidence you built as you went. You cannot fake that in a weekend.”
What Founders and Their Advisors Should Do Now
Prem Dharmani suggests a short set of moves that most AI businesses can start on this quarter:
- Map every AI system and the personal data it touches, including data used for training and for live inference.
- Fix the lawful basis for each dataset, and make consent specific, informed and easy to withdraw.
- Put a name against accountability. Decide who owns data protection and how user grievances get handled.
- Document as you build. Keep records of training data, model changes and sign-offs on high-impact decisions.
- If your product creates or edits images, audio or video, build content labelling and metadata into the workflow.
- Give AI a standing place on the board agenda, so oversight is real rather than assumed.
None of these steps needs a large legal budget to begin. They need a decision to take governance seriously before it becomes urgent. For AI businesses in India, that decision is the difference between growth that compounds and growth that stalls the moment a regulator, a partner or an investor looks closely.





