Published: October 6, 2026
StartupFeed Quick Take
- Anthropic gave about 80 of its 261-page IPO filing to risk, warning its own AI could cause harm.
- India has no single AI law, yet SEBI (February 2025), the RBI (August 2025) and MeitY (November 2025) all put the liability on the deploying firm.
- MeitY sets graded liability: blame tracks the AI’s job, the risk level, and the firm’s own checks.
Anthropic used almost a third of its IPO filing to warn its own AI could cause harm, a risk Indian founders now carry too.
The prospectus, reviewed by Reuters in late September, runs to 261 pages. About 80 cover risk, nearly twice the space given to the business.
Revenue hit $4.6 billion in 2025, up about twelve times from roughly $400 million in 2024. Anthropic has also pledged $518 billion to computing over the decade. A Nasdaq listing is expected later this year.
Anthropic did not soften the danger. It wrote the risk into the filing.
“… could further increase the risk that our models cause harm.”
Anthropic, from its IPO prospectus (Form S-1). Reported by Reuters, September 2026.
That lands a question Indian startups keep dodging. Call it AI liability. When an AI agent cancels an order or denies a valid loan, who answers, the model’s maker or the firm that deployed it?
India has no single AI law. But three regulators have already chosen a side. It is the deployer.
AI Liability in India: What the Rules Say
SEBI moved first and made it binding. In February 2025, it changed three sets of regulations. Any regulated firm using AI or machine-learning tools is now solely responsible for their output, for investor data, and for obeying the law.
The three rules cover stock exchanges, clearing corporations and intermediaries. SEBI has tracked AI in the markets since 2019. The 2025 change added the liability. The tool’s vendor is not named; the user carries the risk.
The RBI points the same way. A committee it set up in December 2024 produced a report, called FREE-AI, on August 13, 2025. It lists seven principles and 26 recommendations. One principle is accountability: the firm deploying AI stays answerable.
MeitY Sets Graded Liability for AI
MeitY took this national on November 5, 2025. Its India AI Governance Guidelines, launched under the IndiaAI Mission, rule out a standalone AI law for now. In its place comes graded liability, built on six pillars.
Graded liability ties blame to three things: the job the AI did, the risk it carried, and whether the firm ran its checks. A simple chatbot and a credit-scoring agent are not judged alike.
India’s current laws already cover AI, MeitY says, from data to consumer protection to crime. Sector regulators keep their powers. A new AI Governance Group and a national incident log will sit on top. The guidelines also flag gaps to fix, from intermediary liability to high-risk uses.
India’s Data Rules Are Already Ticking
India’s data law is no longer only on paper. The Act dates to 2023; the government published the rules in November 2025. The duties fall on the data fiduciary, the firm that decides how your data is used.
The hard duties, on breach reporting, consent and data transfers, start on May 14, 2027. Consent-manager rules come earlier, from November 2026. Breaches can draw penalties of up to Rs 250 crore.
A Data Protection Board with four members will enforce the law. Full enforcement is still 18 months away from the November 2025 start. The lesson for AI is blunt. An agent that leaks data gives its operator no cover.
How India Compares With the EU and US
Other big markets sit elsewhere. The European Union has the most detailed law; the United States has no single federal AI statute. Singapore first published a voluntary code in 2019, updated it in 2020, and added a generative-AI version in 2024.
The EU AI Act took force on August 1, 2024. Its rules for general-purpose models went live on August 2, 2025. The law sorts systems into four risk tiers.
Article 14 says high-risk systems must keep a human who can step in and override the machine. Breaking those rules can cost up to 15 million euros, or 3% of global turnover. For an Indian startup selling into Europe, that bites directly.
| Jurisdiction | Approach to AI liability | Key instrument | Status |
|---|---|---|---|
| India | Sector by sector; deployer is accountable | SEBI rules, RBI FREE-AI, MeitY guidelines (2025) | Part binding, part voluntary |
| European Union | One risk-based law | EU AI Act, Article 14 oversight | General-model rules live since Aug 2025 |
| United States | No single federal AI law | State laws and sector rules | Fragmented |
| Singapore | Voluntary code | Model AI Governance Framework | In use since 2019 |
What this means for you: If your Indian startup uses AI to make real decisions, in lending, hiring or trading, the law points the liability at you, not the vendor. Keep a human who can override the agent, log those reviews, and tighten data controls before the DPDP rules bite in May 2027.
StartupFeed Insight
The direction is clear, even without a single AI law. India is building liability from the bottom up, one regulator at a time, and each lands on the same party: the firm that chose to deploy the AI. For founders, that cuts both ways. The rules stay flexible and pro-innovation, so you can ship fast. But you cannot point at the model’s maker when an agent fails. The first real test will come in finance, where SEBI’s rule already binds. By mid-2027, once the DPDP duties are live, a data leak traced to an AI agent will sit squarely with the startup that ran it.
By Saraswati Chaubey, Writer
Have a tip? Write to us at editorial@startupfeed.in.



