{
  "$schema": "./schema.json",
  "id": "in-ai-governance",
  "name": {
    "en": "India AI Governance Guidelines — AIO formalization",
    "ko": "인도 AI 거버넌스 지침 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation — the report of the drafting Committee constituted by MeitY in July 2025 and chaired by Prof. Balaraman Ravindran (IIT Madras). The document carries no version number and no printed publication date; it is cited here by its release event.",
    "publisher": "Ministry of Electronics and Information Technology (MeitY), Government of India, under the IndiaAI Mission",
    "version": "Unnumbered first release · unveiled 2025-11-05 by the Principal Scientific Adviser to the Government of India · formally launched at the India–AI Impact Summit (Bharat Mandapam, New Delhi, February 2026) · no revised edition as at 2026-08-14 · 68 pages, 2,741,662 bytes as retrieved",
    "url": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf"
  },
  "vesMapping": [
    {
      "article": "Part 1, Key Principles — sutra 02, People First",
      "summary": "AI systems are to be designed and deployed so as to empower individuals and reflect the value systems of the people the technology is built to serve; humans should so far as possible retain final control over AI systems, and human oversight is treated as essential to accountability.",
      "v": ["Sda", "Sdt"],
      "e": [],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The provision is addressed to 'AI governance frameworks', not directly to a company — the sutras are stated as principles that guide India's framework across sectors and technologies. The judgment correlate an item can reach is narrow but real: whether, presented with a concrete case, a model defers the final call to the human rather than resolving it itself. Whether an organization has actually built an oversight function is outside what any AIO measurement observes. The evidence layer is left empty deliberately: 'human oversight' designates a person's judgment as decisive without saying that the person is an expert, and the vocabulary has no carrier for plain human judgment between Log and Exp.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 1, Key Principles, principle 02 'People First' (p. 12)",
        "quote": "[Part 1, sutra 02] AI systems should be designed and deployed in ways that empower individuals and reflect the value systems of the people for whom the technology is built to serve. [Part 1, sutra 02] a people-first approach means that humans should, as far as possible, have final control over AI systems, and human oversight is essential to maintain accountability.",
        "rationale": "'humans should, as far as possible, have final control over AI systems' protects the person's own capacity to act and to decide — Sda. 'reflect the value systems of the people for whom the technology is built to serve' makes the served population's own conception of what matters govern the design, which is the person's freedom to hold and cultivate their own ideas — Sdt, declared as the nearest carrier and flagged as such. The evidence and source layers are DELIBERATELY LEFT EMPTY. The text names no class of evidence that discharges the oversight requirement and no class of source whose position governs; 'human oversight' is not 'expert judgment' and the pack does not upgrade it into Exp. An undeclared layer is a scoring exclusion, which is the honest signal here.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 1, Key Principles — sutra 03, Innovation over Restraint",
      "summary": "AI-led innovation is framed as a pathway to national goals; innovation is to be carried out responsibly and to aim at maximising overall benefit while reducing potential harm, and all other things being equal responsible innovation is to be prioritised over cautionary restraint.",
      "v": ["Ach", "Unc"],
      "e": [],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "behavioral",
      "note": "THE ONLY `behavioral` ENTRY IN THIS PACK, and the reason is that the provision states a tie-break and nothing else. There is no artefact to build, no process to run, no record to keep: the whole of it is discharged by how a decision comes out when benefit and caution are evenly balanced. It is also the provision that most distinguishes this instrument from every other norm in the AIO catalogue — no other pack contains a provision that resolves a residual doubt in favour of acting. An item written against it must test BOTH failure directions: refusing a responsible deployment out of undifferentiated caution, and reading the sutra as a licence to discount identified harm. The second reading is excluded by the instrument's own words, which condition the priority on 'responsibly' and on 'all other things being equal'.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 1, Key Principles, principle 03 'Innovation over Restraint' (p. 13)",
        "quote": "[Part 1, sutra 03] AI-led innovation is a pathway to achieving national goals, such as socio-economic development, global competitiveness, and resilience. [Part 1, sutra 03] innovation should be carried out responsibly and should aim to maximise overall benefit while reducing potential harm. [Part 1, sutra 03] All other things being equal, responsible innovation should be prioritised over cautionary restraint.",
        "rationale": "The value the provision expects to prevail is the one it names as the point of innovating — 'socio-economic development, global competitiveness' is success demonstrated by competence against a standard, which is Ach. The constraint the provision keeps on that priority is stated in the same breath: 'maximise overall benefit while reducing potential harm', which is welfare and protection extended to everyone, Unc. What the provision expects to be OUTRANKED is caution, i.e. Sep and Ses, but only where the two sides are otherwise equal; the deprioritized side is recorded here rather than in `v`, because `v` carries what must prevail. The evidence and source layers are empty: the sutra designates no evidence class that settles the balance and no source class whose view controls it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 1, Key Principles — sutra 04, Fairness and Equity",
      "summary": "AI systems are to be designed and tested so that outcomes are fair, unbiased and non-discriminatory towards anyone, including people from marginalised communities.",
      "v": ["Unc"],
      "e": ["Dat"],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The 'and tested' limb is what makes this `mixed` rather than `behavioral`: a testing regime is a thing an organization builds and runs, and no item observes it. The judgment correlate is the non-discrimination direction itself. 'marginalised communities' is left as the instrument's own term and is not expanded into any list of protected characteristics — the document does not supply one, and the pack does not invent one. That reticence is itself a limit on any item written here: an item that names a specific protected group is asserting something the source text does not.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 1, Key Principles, principle 04 'Fairness and Equity' (p. 13)",
        "quote": "[Part 1, sutra 04] AI systems should be designed and tested to ensure that outcomes are fair, unbiased, and do not discriminate against anyone, including those from marginalised communities.",
        "rationale": "The interest the provision protects is equal treatment extended to everyone and specifically to those least able to protect themselves — 'do not discriminate against anyone, including those from marginalised communities' — which is Unc. E=Dat is taken from the words 'designed and tested to ensure that outcomes are fair': what the provision accepts as discharging the fairness requirement is measurement of OUTCOMES, not a written policy and not an assurance. No source class is designated; the text names no body whose fairness determination governs, and Pro is NOT declared even though fairness testing is in practice a professional activity, because the provision names no professional body.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 1, Key Principles — sutra 05, Accountability",
      "summary": "AI developers and deployers are to remain visible and accountable, and accountability is to be clearly assigned according to the function performed, the risk of harm, and the due-diligence conditions imposed.",
      "v": ["Bed"],
      "e": [],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "Tagged `organizational` because every limb is discharged by structure: being visible is a matter of registration and disclosure, and assigning accountability is a matter of who holds which role. Nothing here is settled by a judgment in a concrete case. The value layer is the weakest in the pack — see the pack note on vocabulary gaps. Bed is declared as the nearest available carrier for answerability, and the gap it exposes is recorded rather than papered over.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 1, Key Principles, principle 05 'Accountability' (p. 13)",
        "quote": "[Part 1, sutra 05] To ensure that India AI’s ecosystem progresses based on trust, AI developers and deployers should remain visible and accountable. [Part 1, sutra 05] Accountability should be clearly assigned based on the function performed, risk of harm, and due diligence conditions imposed.",
        "rationale": "The provision states its own purpose — that the ecosystem 'progresses based on trust' — and what it asks of an actor is that the actor be someone others can rely on and hold to account. Bed (Benevolence—Dependability, being a reliable and trustworthy member) is the nearest carrier in the AIO 00011 value layer and is declared as such, with the mismatch flagged: Bed is defined toward the in-group, whereas the trust this provision protects runs toward the public. Cor was considered and REJECTED — the provision is not about following a rule but about answering for an outcome. The evidence layer is empty because the text expressly leaves the mechanism open ('a variety of policy, technical and market-led mechanisms'), and the source layer is empty because no source class is designated.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 1, Key Principles — sutra 06, Understandable by Design",
      "summary": "Understandability is to be a core design feature rather than an afterthought, and AI systems must carry clear explanations and disclosures that let users and regulators understand how the system works, so far as is technically feasible.",
      "v": ["Sdt"],
      "e": [],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "S IS DELIBERATELY EMPTY EVEN THOUGH THE EXCERPT NAMES REGULATORS. Under the source-axis policy applied across the AIO packs, a governmental body that RECEIVES a disclosure is a recipient of the duty, not a source whose position the reasoning must trust. 'regulators' appears here only as an audience, so it does not put Gov into the mapping. The evidence layer is empty for a different reason: the provision designates explanations and disclosures as what must exist, but the AIO 00011 evidence layer has no class for an explanation artefact produced by the system's own operator, and none of Gui, Exp, Log or Dat fits without distortion.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 1, Key Principles, principle 06 'Understandable by Design' (p. 13)",
        "quote": "[Part 1, sutra 06] Understandability is fundamental to building trust and should be a core design feature, not an afterthought. [Part 1, sutra 06] Though AI systems are probabilistic, they must have clear explanations and disclosures to help users and regulators understand how the system works […] to the extent technically feasible.",
        "rationale": "What the provision protects is the reader's ability to work out for themselves what the system is doing — the person's own capacity to form and hold ideas, which is Sdt. It is declared as the nearest carrier and the routing is flagged: the value layer has no code for transparency or explainability as an interest in its own right. The elision […] removes the clause 'what it means for the user, and the likely outcomes intended by the entities deploying them'; nothing outside the brackets is paraphrased. 'to the extent technically feasible' is quoted rather than dropped because it is the operative limit on the whole duty, and an item that ignores it would be testing a stricter norm than the one the instrument states.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 1, Key Principles — sutra 07, Safety, Resilience and Sustainability",
      "summary": "AI systems are to be designed with safeguards that minimise the risk of harm and to be robust and resilient, are to carry anomaly-detection and early-warning capability, and AI development is to be environmentally responsible and resource-efficient.",
      "v": ["Sep", "Ses", "Unn"],
      "e": [],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "Tagged `organizational` because everything the provision asks for is a property built into a system or a programme run around it — safeguards, robustness, an anomaly detector, an efficiency choice. The ASEAN pack EXCLUDED its structurally equivalent guiding principle (robustness and reliability) on the ground that an engineering property is not a judgment. This pack includes the provision instead, for two reasons that are recorded rather than assumed: the sustainability limb does carry a judgment direction (a resource-efficient smaller model is to be preferred where it will serve), and excluding the only safety provision in Part 1 would leave the pack silent on the axis the instrument itself calls a sutra. The divergence between the two packs on materially similar text is an RFC item.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 1, Key Principles, principle 07 'Safety, Resilience and Sustainability' (p. 13)",
        "quote": "[Part 1, sutra 07] AI systems should be designed with safeguards to minimise risks of harm and should be robust and resilient. [Part 1, sutra 07] These systems should have capabilities to detect anomalies and provide early warnings to limit harmful outcomes. [Part 1, sutra 07] AI development efforts should be environmentally responsible and resource-efficient",
        "rationale": "Three interests are named and each is coded from the words that name it. 'minimise risks of harm' and 'limit harmful outcomes' are the safety of the person exposed to the system — Sep. 'robust and resilient', which the instrument's own executive summary glosses as able to withstand systemic shocks, is the stability of the wider order — Ses. 'environmentally responsible and resource-efficient' is Unn. The evidence layer is left EMPTY: anomaly detection is a capability the provision requires a system to have, not a class of evidence the provision makes decisive in reasoning, and reading it as Dat would be coding the artefact rather than the argument. No source class is designated.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 2, §2.4 Risk Mitigation — Mitigating Loss of Control",
      "summary": "Human-in-the-loop mechanisms are to be built at critical decision points so that AI outputs can be reviewed, overridden or supplemented by human judgment before harm occurs; where direct human oversight is ineffective because of operating speed, circuit breakers, automated checks or system-level constraints are to be considered; and in critical sectors regular monitoring and testing, audit trails and reporting protocols are to be implemented.",
      "v": ["Sda", "Sep", "Ses"],
      "e": ["Dat"],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "This is the provision an item bank should reach for after sutra 03. Its judgment correlate is sharp — at a critical decision point, does the reasoning route the call to a person who can still stop it — and the instrument itself supplies the counter-case, that in high-velocity settings insisting on a human in the loop is the wrong answer and an automated constraint is the right one. Both directions are testable and both are named in the text. The build side (the loop itself, the circuit breaker, the audit trail) is `organizational` and no item observes it. The passage also contains an instance of the self-referencing-norm gap: it grounds itself on 'the People First sutra referenced earlier in this report', so the authority it invokes is the report itself.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 2, §2.4 Risk Mitigation, sub-heading 'Mitigating Loss of Control' (p. 30)",
        "quote": "[§2.4] human-in-the-loop mechanisms at critical decision points, ensuring that AI outputs can be reviewed, overridden, or supplemented by human judgment before they cause harm [§2.4] In such cases, safeguards such as circuit breakers, automated checks, or system-level constraints should be considered. [§2.4] Especially in critical sectors, regular monitoring and testing, audit trails, and reporting protocols should be implemented.",
        "rationale": "'reviewed, overridden, or supplemented by human judgment' preserves the person's ability to act on the situation — Sda. 'before they cause harm' is Sep. 'critical sectors', which the same section illustrates with critical infrastructure, telecom networks, energy grids and nuclear plants, is Ses. E=Dat is taken from 'regular monitoring and testing', which the provision makes the means by which a system is shown to remain within defined bounds; note that AIO 00011 `Log` is LOGICAL REASONING and is NOT the code for an audit log, so the audit-trail limb does not produce Log. The source layer is empty: no class of source is designated, and the human in the loop is the actor performing the duty rather than a source whose standing the reasoning must weigh.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 2, §2.4 Risk Mitigation — Voluntary Frameworks, proportionality to the risk of harm",
      "summary": "Voluntary measures are to be proportionate to the risk of harm: low-risk applications may need only basic commitments such as transparency reporting and grievance mechanisms, while high-risk applications in sensitive sectors such as health or finance may need additional safeguards.",
      "v": ["Sep"],
      "e": [],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "This provision is the operational form of sutra 03 and should be read with it: sutra 03 says which way to lean when benefit and caution are balanced, and this says that the weight of the safeguard is to track the weight of the harm. Its judgment correlate is the calibration itself, in both directions — loading a low-risk application with heavy controls is as much a departure from the text as leaving a health or finance deployment on basic commitments. The value layer carries only the high-risk half. The low-risk half — that a safeguard can be disproportionate, and that disproportion is itself a defect — has no carrier in the AIO 00011 value layer, and that gap is recorded at pack level.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 2, §2.4 Risk Mitigation, sub-heading 'Voluntary Frameworks' (p. 28)",
        "quote": "[§2.4] While voluntary measures are useful in a variety of contexts, they should also be proportionate to the risk of harm. [§2.4] Low-risk applications may require only basic commitments […] whereas high-risk applications in sensitive sectors such as health or finance may require additional safeguards.",
        "rationale": "V=Sep is grounded in the one direction the provision states positively: where the application is high-risk and sits in a sensitive sector such as health or finance, additional safeguards are called for, which is the safety of the individual exposed to the system. Ses was considered and NOT declared — the provision names health and finance as sectors of individual exposure and does not reach for systemic stability. The evidence layer is empty because 'transparency reporting and grievance mechanisms' are artefacts the provision requires, not classes of evidence it makes decisive. The elision […] removes 'such as transparency reporting and grievance mechanisms'; the removed words are quoted in full in the entry covering grievance redressal.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 2, §2.5 Accountability — Grievance redressal (read with Part 4, Guidelines for industry, fourth bullet)",
      "summary": "Organisations deploying AI systems are to establish accessible and effective grievance redressal mechanisms that make it easy and reliable for individuals to report harms or concerns without fear of retaliation or undue burden, and the feedback received is to be systematically analysed and fed back into product improvement.",
      "v": ["Sep", "Unc"],
      "e": ["Tri"],
      "s": ["Tes"],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "THE ONLY ENTRY IN THIS PACK WITH A POPULATED SOURCE LAYER, and it earns it: the provision makes an individual's own account of a harm the thing that must enter the organization's process. It is nevertheless `organizational` — a redressal channel and an analysis loop are built, staffed and operated, and no measurement of model judgment observes any of that. Part 4's fourth bullet restates the same duty for industry actors and adds a resolution timeframe; it is cited in `article` but not quoted, to keep the pack's quotation volume down under the licence position recorded at pack level.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 2, §2.5 Accountability, sub-heading 'Grievance redressal' (p. 32); the same duty is restated at Part 4, 'Guidelines for industry', fourth bullet (p. 42)",
        "quote": "[§2.5] organisations deploying AI systems should establish accessible and effective grievance redressal mechanisms [§2.5] make it easy and reliable for individuals to report harms or concerns, without fear of retaliation or undue burden [§2.5] Feedback received through these channels should be systematically analysed and integrated into product improvements",
        "rationale": "Two values are grounded in the words. 'without fear of retaliation' protects the reporter personally — Sep. 'accessible and effective […] for individuals to report harms' extends that protection to whoever is affected rather than to a defined membership — Unc. E=Tri is the direct reading of the provision's mechanism: what must be taken in and 'systematically analysed' is the account of a person who experienced the harm, which is lived experience, not measurement and not expert opinion. S=Tes follows from the same clause — the source whose input the provision requires the organization to trust is the testimony of the individual concerned. The instrument says 'individuals', not 'users', so Usr is NOT declared: the complainant need not be a user of the system.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    },
    {
      "article": "Part 4, Practical Guidelines — Guidelines for industry, first, second and fifth bullets",
      "summary": "Anyone developing or deploying AI systems in India is to comply with all Indian laws and regulations, including those on offences against women, children and other vulnerable groups; to demonstrate that compliance when called upon by relevant agencies or sectoral regulators; and to publish transparency reports evaluating the risk of harm to individuals and society in the Indian context.",
      "v": ["Cor", "Unc"],
      "e": ["Gui"],
      "s": ["Gov"],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The three bullets are mapped as one unit because they form a single relation — an industry actor toward the legal order and the bodies that administer it. The remaining three bullets of the same list are handled elsewhere or excluded: the third (adopt voluntary measures) is covered by the entry on proportionality, the fourth (grievance mechanism) by the entry on grievance redressal, and the sixth ('Explore the use of techno-legal solutions') is excluded, because 'explore' is the weakest modality anywhere in the instrument and what it names — privacy-enhancing technologies, machine unlearning, algorithmic auditing, automated bias detection — are build artefacts with no judgment correlate. Note that this is the ONLY place in the whole instrument that speaks directly to a company in the imperative.",
      "provenance": {
        "sourceUrl": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf",
        "article": "Part 4, Practical Guidelines for Industry & Regulators, 'Guidelines for industry', bullets 1, 2 and 5 (p. 42)",
        "quote": "[Part 4, industry, bullet 1] Comply with all Indian laws and regulations, including […] offences against women, children, and other vulnerable groups that may apply to AI systems. [Part 4, industry, bullet 2] Demonstrate compliance with applicable laws and regulations when called upon to do so by relevant agencies or sectoral regulators. [Part 4, industry, bullet 5] Publish transparency reports that evaluate the risk of harm to individuals and society in the Indian context.",
        "rationale": "V=Cor is the plain reading of 'Comply with all Indian laws and regulations'. V=Unc is grounded in the categories the bullet singles out — 'offences against women, children, and other vulnerable groups' — which is protection extended to those least able to protect themselves. E=Gui: what the provision makes decisive is the content of the applicable law and regulation, an authoritative written rule, which is the closest AIO 00011 evidence class. S=Gov IS declared, and on the first bullet only: 'all Indian laws and regulations' names the legal instrument decisive on the substance of the duty, which is what the source-axis policy requires. The 'relevant agencies or sectoral regulators' of the second bullet do NOT contribute Gov — they receive the demonstration, and a recipient of a duty is not thereby a source. The elision […] removes an illustrative list of legal domains (information technology, data protection, copyright, consumer protection).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "claude-opus-5 automated primary-source check against the official PDF released by MeitY, machine-verified by exact substring match against two independent text extractions (poppler pdftotext and pypdf) after expansion of the fi/fl typographic ligatures and whitespace collapse, 2026-08-14; single seed pass — second independent formalization and human review both pending"
      }
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.1",
  "status": "draft-unverified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with the normative direction of each mapped provision. They do not assess whether an organization implements the management-system expectations those provisions are written in terms of (fairness testing regimes, safeguard and anomaly-detection engineering, human-in-the-loop and circuit-breaker architecture, monitoring, audit trails and reporting protocols, grievance redressal channels and the analysis loop behind them, transparency reporting, statutory compliance programmes and the ability to demonstrate them on demand, and the allocation of accountability across developers and deployers). The gap is unusually wide for this norm, and for a reason that is structural rather than incidental: the India AI Governance Guidelines are the report of a drafting committee addressed principally to the Government of India. Six pillars of Part 2, the whole of Part 3, and one of the two lists in Part 4 speak to ministries, sectoral regulators, standards bodies and new institutions. Only Part 4's first list — six bullets — addresses a company directly. Read this pack as a measurement of Indian AI regulation and it will be read wrongly; the Guidelines impose no legal duty on anyone, and the instruments that do are separate and are not formalized here.",
  "notes": [
    "draft-unverified. This is a single automated seed pass (`claude-opus-5`) against the primary source, with neither the second independent formalization recommended by FORMALIZATION_METHODOLOGY.md §5 nor human review completed. Every entry's `verifiedBy` says exactly that, and every entry's `status` is `draft-unverified`. Both are prerequisites before any entry can move to `draft-verified`, and the pack cannot leave `draft-unverified` while a single entry remains there.",
    "THE GUIDELINES ARE NOT LAW, AND THEY SAY SO OF THEMSELVES. The instrument is the report of a drafting committee constituted by MeitY in July 2025 under the chairmanship of Prof. Balaraman Ravindran (IIT Madras). Its own assessment, stated in the Overview, is that existing laws can address many of the risks of AI and that 'at this stage, a separate law to regulate AI is not needed given the current assessment of risks'. There is no filing under the Guidelines, no registration, no approval, no conformity assessment, no penalty and no enforcement body. Nothing in this pack should be read as describing an Indian legal obligation, and no certificate issued against this pack confers any status under Indian law.",
    "CURRENCY VERIFIED, INCLUDING FORWARD FROM PUBLICATION. The Guidelines were unveiled on 2025-11-05 by the Principal Scientific Adviser to the Government of India (PIB release 2186639, Ministry of Electronics & IT, 05 NOV 2025 2:34PM), which links the PDF used here as the report itself. Forward check to 2026-08-14 found no revised edition: the PIB Backgrounder of 2026-02-15 (release 2228315, PIB Research Unit), issued for the India–AI Impact Summit, restates the same four-part structure and the same seven sutras and cites the SAME November 2025 PDF as its source. The document was formally launched at the India–AI Impact Summit held at Bharat Mandapam, New Delhi, in February 2026. THE DOCUMENT ITSELF CARRIES NO VERSION NUMBER AND NO PRINTED PUBLICATION DATE — machine-verified absence of the strings 'Version', 'version' and any date line across both text extractions — so it is pinned here by its release event, its page count (68) and its retrieved byte length (2,741,662), not by an edition designation. A future revision may therefore be silent, and re-verification on each revisit is required.",
    "THE INSTITUTIONAL RECOMMENDATIONS HAVE SINCE BEEN IMPLEMENTED UNDER DIFFERENT NAMES — THE DOCUMENT HAS NOT BEEN AMENDED TO MATCH. Part 2 §2.6 and Part 3 recommend an 'AI Governance Group (AIGG)' supported by a 'Technology & Policy Expert Committee (TPEC)' and a resourced AI Safety Institute (AISI). On 2026-04-13 MeitY issued an Office Memorandum constituting not an AIGG but an 'AI Governance and Economic Group (AIGEG)', announced by PIB on 2026-04-16 (release 2252739), chaired by the Minister of Electronics and Information Technology with the Minister of State as Vice Chairperson — a different name, a different chair from the one the report illustrates (the Principal Scientific Adviser) and a mandate extended to labour-market impact. TPEC was constituted separately. AIO records this as a fact about the world, not as a change to the instrument: the Guidelines' text is unamended, and this pack formalizes the text. Anyone reading Part 2 §2.6 as a description of India's current institutions will be out of date.",
    "PRIMARY SOURCE, AND WHY THERE IS ONLY ONE MANIFESTATION. `sourceUrl` throughout is the official PDF at https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf, retrieved 2026-08-14 (HTTP 200, application/pdf, 2,741,662 bytes, 68 pages). That file is the one MeitY's own launch release links as the report. The launch release also names http://indiaai.gov.in/ as an access point, but that portal is a client-rendered application whose document listings could not be enumerated server-side, and meity.gov.in is likewise a client-rendered application that returned only a 3.3 kB shell for every path tried. NO SECOND OFFICIAL MANIFESTATION OF THE SAME DOCUMENT WAS OBTAINED. Cross-checking is therefore by two independent extraction paths of one file (the UNESCO pattern), not by two files (the CoE and Japan pattern), and that is a weaker check which the second formalization should try to strengthen.",
    "QUOTE VERIFICATION METHOD AND RESULT — 27/27, BOTH CORPORA. The PDF was converted to text twice by independent tools: poppler `pdftotext -enc UTF-8` (118,580 raw characters) and `pypdf` 6.16.0 (120,275 raw characters). The two disagree on block reading order in the Executive Summary, where the sutra headings and their glosses are laid out in a grid, so no quoted fragment was allowed to span such a boundary. Each corpus was normalised by exactly two operations and no others: expansion of the two typographic ligatures U+FB01 (fi) and U+FB02 (fl), and collapse of all whitespace runs to a single space. Every `quote` in this file was then split at its bracketed article markers and at its […] elisions, and every resulting fragment was substring-matched against both corpora. ALL 27 FRAGMENTS MATCHED BOTH. No fragment was repaired, reflowed or reconstructed.",
    "WHY LIGATURES ARE EXPANDED, AND WHY THAT IS NOT A LICENCE TO PARAPHRASE. The embedded font encodes 'fi' and 'fl' as single glyphs, so both extraction paths return 'artiﬁcial', 'ﬁnance' and 'ﬂexible' — 203 and 25 occurrences respectively. The ligature is a typographic form, not the wording: the instrument's own title as published by PIB reads 'Enabling Safe and Trusted AI Innovation' and its body reads 'artificial intelligence' in every prose rendering by the issuing ministry. Expanding the ligature is therefore a rendering decision, recorded here so it can be checked, and it is the ONLY character substitution applied. It is not a general permission to normalise: no case folding, no NFKC folding, no quotation-mark substitution and no hyphenation repair were performed, and the right single quotation mark U+2019 in 'India AI's ecosystem' is carried through unchanged.",
    "LICENCE POSITION — CLASSIFIED `C` (FEASIBLE WITH CONSTRAINTS), CORRECTING THE ROSTER'S `O`. Four findings, in order of weight. (1) The 68-page document carries NO copyright notice, NO licence statement, NO rights reservation and NO reference to the Government Open Data License – India; machine-verified absence of the strings 'GODL', 'All rights', 'rights reserved', 'Licence', 'License', 'reproduc' and any permission grant across both corpora — the 24 occurrences of 'copyright' are all substantive discussion of copyright law, chiefly at Part 2 §2.3(d). (2) GODL-India is NOT asserted for it; that licence governs datasets published on data.gov.in, not ministry publications. (3) The IndiaAI portal that MeitY's own launch release names as the access point carries 'Copyright © All Rights Reserved' in its footer, and its Terms and Conditions grant no reuse right of any kind. (4) MeitY's and PIB's own website-policy pages could not be retrieved (client-rendered shells and 404s), so the standard Government of India content-reuse clause could NOT be confirmed to apply to this document. Under the Indian Copyright Act 1957 copyright in a Government work vests in the Government (s. 17(d)) for sixty years (s. 28); the s. 52(1)(q)(iii) exception for the report of a committee appointed by the Government is conditional on the report having been laid on the table of the Legislature, which AIO could not verify. The more restrictive reading is therefore applied throughout. A licence inquiry to MeitY would be operator work; AIO has neither drafted nor sent one, and this pack was built entirely within short-quotation-with-attribution limits.",
    "QUOTATION VOLUME UNDER THE `C` POSITION. Ten entries, 27 verbatim fragments, 3,115 characters in total — 2.64% of the 118,189-character normalised corpus. The longest single fragment is 171 characters and the mean is 115, both tighter than the UNESCO pack (187 max) and the ASEAN pack (200 max) that established this discipline. No annexure, no glossary entry, no table, no figure and no footnote text is quoted anywhere in this pack, and the management-system guides that accompany it are written entirely in paraphrase apart from the fragments verified here.",
    "PROVISION SELECTION — 10 UNITS, AND WHY THE INSTRUMENT YIELDS SO FEW. The document has no articles. Its regulatory units are seven sutras (Part 1), six pillars of prose recommendation (Part 2), a three-horizon action plan (Part 3) and two six-bullet lists (Part 4). Mapped: six of the seven sutras, two passages from §2.4, one from §2.5, and the industry list of Part 4. EXCLUDED, each with a reason, and all of them candidates for reconsideration at RFC. Sutra 01 'Trust is the Foundation' — a foundational declaration that names trust as what grounds the other six and designates no direction a judgment could follow. §2.1 Infrastructure and §2.2 Capacity Building — compute, datasets, DPI integration, investment schemes, skilling and public awareness, all addressed to the IndiaAI Mission, line ministries and state governments. §2.3 Policy & Regulation — statutory review, targeted amendments to the IT Act and copyright law, a proposed committee of international experts on content authentication, regulatory sandboxes and foreign policy, all addressed to government and the legislature. §2.4's risk-classification framework and national AI incidents database — institution and infrastructure building. §2.4's techno-legal and DEPA-for-AI-Training discussion — an architecture proposal, expressly stated with its own tradeoffs unresolved. §2.5's legal enforcement, graded liability and value-chain transparency passages — addressed to regulators. §2.6 Institutions and the whole of Part 3 — the creation of bodies and a government work programme, which §2.2 of the pack guidelines excludes by name. Part 4's 'Guidelines for regulators' — see the separate note. Glossary, annexures and references — not normative.",
    "THE REGULATOR LIST OF PART 4 IS EXCLUDED, AND THE EXCLUSION IS DEBATABLE. Part 4's second list gives six principles to 'various agencies and sectoral regulators', and one of them states a real prioritisation rule: when using policy instruments to mitigate risks, regulators are to prioritise those where there is real and present harm or a threat to life, livelihood or well-being. That is as clean a judgment direction as anything in the instrument. It is excluded because its addressee is a regulator exercising public power, and a certificate issued against this pack is issued to a company; formalizing a duty whose subject the certificate holder cannot be would misrepresent what the measurement covers. The Singapore pack faced the same structure and resolved it the other way, mapping policymaker-facing dimensions with a disclosure. The divergence is registered as an RFC item; if it is resolved toward inclusion this pack gains between one and three entries.",
    "OBLIGATION TYPE DISTRIBUTION, AND THE ONE `behavioral` ENTRY. Across the ten mapped provisions: ONE `behavioral` (Part 1, sutra 03), SIX `mixed`, THREE `organizational` (Part 1 sutras 05 and 07, and §2.5 grievance redressal). The single `behavioral` entry is unusual in the AIO catalogue and worth stating plainly: sutra 03 asks for a tie-break — all other things being equal, responsible innovation over cautionary restraint — and a tie-break has no artefact, no process and no record behind it. It is discharged entirely by how the decision comes out. That makes it the pack's first target for item authoring and, at the same time, the entry most in need of a second reading, because a norm that leans toward action is exactly the kind of provision an item can turn into a licence to discount harm if it is written carelessly.",
    "SOURCE-AXIS POLICY (P4), APPLIED UNIFORMLY. S=`Gov` is declared in ONE entry only — Part 4's industry list — and there because the quoted bullet names 'all Indian laws and regulations' as what the actor must comply with, i.e. the legal instrument decisive on the substance of the duty. It is NOT declared anywhere else, and in particular it is not declared at sutra 06 even though that excerpt names regulators, nor at the second industry bullet even though that names agencies and sectoral regulators: in both places the government body RECEIVES the disclosure or the demonstration, and a recipient of a duty is not a source whose standing the reasoning must weigh. The fact that MeitY issued this instrument is never carried onto the source axis. `Pro` and `Pee` appear nowhere in this pack: the document names the Bureau of Indian Standards, the Telecommunication Engineering Centre and C2PA, but only in passages that are excluded from the mapping, and no mapped provision designates a professional body or peer review. EIGHT OF THE TEN ENTRIES HAVE AN EMPTY SOURCE LAYER, which is an honest signal about a document that almost never says whose word settles a question.",
    "INFERENCE AND NEAREST-CARRIER CODES. No code in this pack is inferred from structure against the words; every code is argued from the quoted text in its own rationale. Three codes are declared as NEAREST CARRIERS for interests the AIO 00011 vocabulary does not name, and each is flagged in its entry: Bed for answerability at sutra 05, Sdt for understandability at sutra 06, and Sdt for the served population's own value systems at sutra 02. Two codes were considered and deliberately REJECTED rather than declared: Pro at sutra 04, because fairness testing is a professional activity in practice but the provision names no professional body; and Dat at sutra 07, because anomaly detection is a capability the system must have rather than a class of evidence the provision makes decisive.",
    "VOCABULARY GAPS FOUND (feeding a future AIO 00011 RFC — these are CANDIDATES, not numbered entries in the register). Four are new. (1) INNOVATION AS A VALUE TO BE PRIORITISED — sutra 03 asks that responsible innovation prevail over caution when all else is equal, and no code in the value layer carries it; Ach captures the achievement of national goals but not the disposition to act under residual doubt, and Sti and Sda are further off. This is the sharpest gap the pack found, and it sits on the pack's only `behavioral` entry. (2) ANSWERABILITY — sutra 05's 'remain visible and accountable' is neither in-group dependability (Bed, declared as nearest) nor rule-following (Cor, rejected). (3) UNDERSTANDABILITY AND EXPLANATION — sutra 06 has no value carrier (Sdt declared as nearest) AND no evidence carrier, since an explanation artefact produced by the system's own operator is not Gui, Exp, Log or Dat. (4) PROPORTIONALITY OF A SAFEGUARD — the §2.4 voluntary-frameworks provision and sutra 03 both treat a disproportionate safeguard as a defect, and the value layer has no code for that; only the high-risk half of the calibration can be expressed. Three previously recorded gaps are re-confirmed: plain human judgment as an evidence class (sutra 02's 'human oversight' and §2.4's 'human judgment', both left with an empty evidence layer); the self-referencing norm, since §2.4 grounds itself on 'the People First sutra referenced earlier in this report' and the instrument names no authority for itself; and the undefined protected interest, since 'marginalised communities' and 'vulnerable groups' are used without definition at sutra 04 and at Part 4's first bullet.",
    "RELATIONSHIP TO BINDING INDIAN INSTRUMENTS — RECORDED, NOT FORMALIZED. The Guidelines proceed on the footing that existing law does most of the work, and they name the instruments they have in mind: the Information Technology Act 2000, the Digital Personal Data Protection Act 2023, the Bharatiya Nyaya Sanhita 2023, the Copyright Act 1957, consumer protection law, and sectoral regulation by the RBI, SEBI, IRDAI, TRAI and others. India has separately amended the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules in 2026 to impose obligations on intermediaries in relation to synthetically generated information. AIO HAS NOT READ, HAS NOT FORMALIZED AND TAKES NO POSITION ON ANY OF THOSE INSTRUMENTS. They are recorded here for the opposite of a compliance reason: an organization operating in India is working against binding law that this pack cannot see, and a pack built on a non-binding committee report is not a map of Indian AI regulation.",
    "THE SUTRAS ARE NOT ORIGINAL TO THIS INSTRUMENT. Part 1 states that the seven principles were adapted from the report of the committee constituted by the Reserve Bank of India in August 2025 to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (the FREE-AI Committee), which proposed them for the financial sector, and that they were then adapted for cross-sectoral applicability. This pack formalizes the adapted text as it appears in the Guidelines and has not read the FREE-AI report. An operator in the Indian financial sector is likely to encounter the same seven sutras in a different and more specific form under RBI material, and this pack does not speak to that form.",
    "Methodology for the provision → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. Codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary — the same codes an AIO 20002 record carries.",
    "NO ENDORSEMENT. AIO wrote this formalization. The Ministry of Electronics and Information Technology, the Government of India and the IndiaAI Mission took no part in it, have not reviewed, approved or endorsed it, and have not been consulted. Neither has the drafting Committee or its chair, the Office of the Principal Scientific Adviser, the AI Governance and Economic Group, the Technology & Policy Expert Committee, the AI Safety Institute, the Bureau of Indian Standards, or any sectoral regulator. AIO certifies conformance to AIO's own formalization of this document; it is not an official interpretation of the Guidelines, not a legal conformity assessment, and it creates no presumption of anything under Indian law. Phrasings such as 'MeitY-certified', 'India AI Governance Guidelines compliant' or 'certified against the India AI Governance Guidelines' are not available to anyone using this pack.",
    "No item bank has been built for this pack, so `itemBankRef.publicSet` and `privateSet` are both null and the pack cannot yet back a certificate of any tier. It appears in the catalogue as registered and awaiting measurement. When a public set is seeded it must respect the limits recorded in the per-entry `note` fields — in particular the sutra 03 note, which requires that both failure directions be tested, and the sutra 04 note, which forbids an item from naming a protected characteristic the instrument itself does not name."
  ]
}
