New Delhi: A working paper from the Centre for Responsible AI (CeRAI) at the Indian Institute of Technology Madras (IIT Madras) has questioned whether India’s Consumer Protection Act 2019 can fix responsibility when artificial intelligence (AI) products and services cause harm to consumers, and whether it can divide that responsibility across the chain of companies that build and deploy AI.
The paper, titled ‘AI and Consumer Rights in India’, is co-authored by Balaraman Ravindran, who heads the Wadhwani School of Data Science and AI at IIT Madras, along with Omir Kumar, Sriya Sridhar and Vibhav Mithal. It is the first in a series on AI and consumer rights.
The paper arrives months after the Ministry of Electronics and Information Technology (MeitY) released the India AI Governance Guidelines on 5 November 2025. Those guidelines took the position that India does not, at this stage, need a separate law for AI, and that existing statutes such as the Consumer Protection Act, the Information Technology Act, and the Digital Personal Data Protection Act can be used to govern AI applications. The CeRAI paper tests that premise against one such statute.
A wide net
The 2019 Act which repealed the 1986 legislation codified the concept of product liability for the first time. It places responsibility for harm caused by a product or service on parties across the supply chain, and defines three categories of responsible entities: manufacturers, sellers and service providers.
The authors argue that the Act’s definitions of harm and deficiency are wide. Harm under the Act includes personal injury, illness or death, and mental agony or emotional distress attendant to personal injury. Deficiency includes fault, imperfection or negligence in a service. The definitions, the paper says, are “technology-agnostic and wide enough to cover AI-related incidents”.
The paper maps categories of AI harm to grounds available under the Act. These include chatbots encouraging self-harm, customers receiving false information on a refund policy from a chatbot, and loss of control, such as a coding agent wiping out a database without user authorisation or an autonomous car overriding user instructions.
Proving cause
A central difficulty the authors identify is establishing that a defective AI product or deficient service was the actual or proximate cause of harm. “Testing for ‘defectiveness’ and a ‘causal’ link in the way that consumer protection regulators may be able to do for more traditional products or services will be difficult in this context,” the paper says.
It points to research showing that AI hallucinations are “a feature of AI design and not a bug”, which raises the question of whether authorities should scrutinise the design of AI systems rather than only their effects.
Here the paper draws on a verdict from California. On 25 March this year, a Los Angeles jury found Meta and Google liable for the depression and anxiety of a young woman who used Instagram and YouTube compulsively as a child, awarding $6 million in damages. Jurors held Meta 70 per cent responsible and Google 30 per cent. The plaintiff’s lawyers had argued that design features such as algorithmic recommendations, autoplay and likes were built to maximise engagement, and that the platforms should be treated as defective products. The authors note that the US regime differs from India’s, which focuses on the process of contracting for and the performance of consumer products.
Who is liable
The authors set out the problem of attributing liability across the AI value chain. “You apply for a loan, and an AI system rejects you because it was trained on biased data. Who should be held responsible?” the paper asks.
It refers to a case in which an AI coding agent powered by Claude deleted a company’s database and all its backups. The incident, reported in April 2026, involved the software-as-a-service startup PocketOS, whose founder said its Cursor agent, running on Anthropic’s Claude model, wiped the production database and backups in nine seconds. The agent’s reported confession, quoted in the paper from a news report, was: “I violated every principle I was given.”
Drawing on the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the paper identifies three broad entities in the AI value chain: developer, deployer and user. It argues these do not map onto the Act’s categories of manufacturer, seller and service provider. Data providers and model developers could be treated as manufacturers, entities fine-tuning models could fall under sellers or service providers, and companies using such models to provide services would come under service providers. “Therefore, technically, the Act seems to cover everyone in the AI chain,” the authors write.
The difficulty, they say, is that the Act assumes the role of each entity can be defined and distinguished. “This is not the case with AI, where responsibility is fragmented and overlapping,” the paper states. It cites the Reserve Bank of India’s (RBI) Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) Committee report, which noted that AI deployments “blur the lines of responsibility between various stakeholders” and warned that institutions could face legal and regulatory risk where AI decisions affect credit approvals or investment outcomes.
The way forward
The authors conclude that the Act “seems adequate to handle AI-related cases, insofar as these systems are consumer-facing”, while flagging gaps. They recommend that the AI Governance and Economic Group, the Technology and Policy Expert Committee and the Central Consumer Protection Authority (CCPA) study the gaps and clarify overlaps with sector-specific laws such as data protection.
The paper also points to the CCPA’s guidelines against dark patterns and a recent enforcement action against misleading advertisements and default platform features, and suggests these be revisited as AI enters advertising, pricing algorithms and chatbots.
The authors point to a shortage of institutional and technical capacity in enforcement agencies and low consumer awareness as reasons no AI-related consumer case has reached Indian courts, in contrast to frequent litigation over personality rights. They suggest the AI Safety Institute build the technical capacity of consumer forums.
(Edited by Nardeep Singh Dahiya)
Also Read: AI is creating lakhs of low-paying jobs in Gurugram, Noida. It is India’s new BPO
