
Why Criminal Law Struggles With Machines
Indian criminal law rests on two pillars. The first is actus reus, meaning the physical act or omission that constitutes an offence. The second is mens rea, meaning the guilty mental state, such as intention, knowledge, or negligence, behind that act. An AI system can certainly produce actus reus, for instance by generating harmful content or causing physical harm through a robotic system. What it cannot straightforwardly have is mens rea, because current AI systems do not possess consciousness, intention, or moral judgment in the legal sense, even when their output looks deliberate.
Key Legal Provisions
- Bharatiya Nyaya Sanhita, 2023 (BNS): This replaced the Indian Penal Code, 1860 as India’s primary criminal code from July 2024. It defines terms like act, omission, and intention in human-centric language, and Section 2 clarifies that corporations can qualify as “persons” for criminal purposes, though this has not been extended to AI systems themselves.
- Information Technology Act, 2000 (IT Act): Governs offences involving computer systems. Section 43 deals with civil penalties for unauthorised access or damage to computer systems, while Section 66 criminalises such acts when done dishonestly or fraudulently. These sections are commonly invoked when AI tools are misused for hacking or data theft.
- Section 66E and Section 67, IT Act: Address violation of privacy and publishing obscene material electronically, relevant to AI-generated deepfakes and morphed content.
- Section 85, IT Act: Extends liability to companies for offences committed with the consent or connivance of persons in charge, a route often used to reach the humans behind an AI system.
- Consumer Protection Act, 2019: Introduces product liability, allowing a manufacturer or service provider to be held responsible for harm caused by a defective product or deficient service, a useful civil law tool when an AI-powered product malfunctions.
- Digital Personal Data Protection Act, 2023 (DPDP Act): Regulates how personal data is processed, which becomes relevant when AI systems are trained on or misuse personal data without consent.
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules: These rules, amended most recently in 2026, place obligations on platforms to label and take down synthetically generated or AI-manipulated content, addressing the deepfake problem specifically.
Rights and Obligations
Victims of AI-caused harm retain the right to file a complaint and seek redress, whether through criminal prosecution of a responsible human, a civil suit for damages, or a consumer complaint for a defective product. Developers, deployers, and operators of AI systems carry corresponding obligations: exercising due diligence in design and testing, ensuring adequate human oversight, and complying with data protection and platform rules. Where negligence in deployment can be shown, liability tends to fall on these human or corporate actors rather than the machine itself.
Who Is Actually Liable: Comparison Table
| Scenario | Likely Liable Party | Governing Law |
|---|---|---|
| AI-generated deepfake used to defame someone | Person who created or uploaded content | BNS, Section 66E/67 IT Act |
| Autonomous vehicle causes an accident | Manufacturer, software developer, or negligent operator | Consumer Protection Act, BNS negligence provisions |
| AI system used to hack or steal data | Person operating or directing the AI tool | Sections 43 and 66, IT Act |
| Faulty AI medical diagnostic tool causes harm | Manufacturer or healthcare provider | Consumer Protection Act, 2019 |
| AI trained on personal data without consent | Data fiduciary or company deploying the AI | DPDP Act, 2023 |
Frequently Asked Questions
No. Since AI has no legal personhood, prosecution is directed at the humans or companies behind it.
Typically the manufacturer, software developer, or operator, depending on where the negligence or defect occurred.
No specific AI provisions exist yet. Existing sections on unauthorised access, data misuse, and obscene content are applied to AI-related conduct instead.
Yes, under Section 85 of the IT Act and general corporate liability principles, if consent, connivance, or negligence by responsible persons is shown.
Sections addressing privacy violation and obscene content under the IT Act, alongside newer intermediary rules requiring labelling and takedown of synthetic content.
Want the deeper dive? Grab the reference book.