AI Governance and Ethics: A Practical Framework for Indian Organisations

Category: AI Trends

By Garage Labs Team

A practical, India-specific framework for AI governance: DPDP Act compliance, bias testing, human-in-the-loop rules, and vendor due diligence any organisation can adapt.

AI governance in an Indian organisation means three concrete things. Know what data your AI tools touch and whether that use is lawful under the DPDP Act, 2023. Keep a human accountable for any AI-assisted decision that affects a person's rights or opportunities. And check vendor claims before you trust them with your data. None of this requires a 40-page policy document on day one, just an owner, a short checklist, and a review cadence you actually follow.

What does "AI governance" mean in practice, not in theory?

Most AI governance content is written for regulators and philosophers. Practically, for an Indian organisation adopting AI tools in 2026, governance boils down to four questions you should be able to answer for every AI tool or workflow in use:

If you can't answer these for your current AI usage, that's your starting point. Governance isn't a separate project bolted onto your AI adoption. It's the operating discipline that lets you scale AI use without scaling risk. If you haven't yet mapped out how AI adoption is even sequenced across your organisation, our AI Adoption Roadmap: A Practical Plan for Indian Organisations is a useful companion piece. Governance sits alongside that rollout, not after it.

What does the DPDP Act, 2023 actually require of AI users?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's core data protection law, and it applies to any organisation processing personal data of individuals in India, regardless of whether you've built a formal "AI policy." Feeding customer data, employee data, or citizen data into an AI tool is a form of processing, and the Act's obligations attach to that processing itself.

In plain terms, here's what matters for AI use:

We're deliberately not citing specific section numbers here. The DPDP Act's rules are still being operationalised through subordinate rules and Data Protection Board guidance, and precision on section references is less useful to you than getting the practical obligations right. Treat this as a starting map, not a legal opinion, and get counsel involved before you finalise policy language.

What is human-in-the-loop and when is it mandatory?

Human-in-the-loop (HITL, i.e. keeping a human reviewer in the decision path) is the single most important governance control for AI-assisted decisions. An AI system can recommend, draft, flag, or score, but a human with real authority to override the output makes the final call, especially where the decision affects someone's access to a job, loan, service, or benefit.

You need HITL, at minimum, for decisions that are:

Where HITL is less critical: internal drafting, first-pass research, formatting, and other low-stakes assistive use where a human reviews the output anyway before it goes anywhere. The mistake most organisations make isn't skipping human review everywhere. It's assuming that a human "in the loop" who rubber-stamps AI output without real scrutiny counts as governance. It doesn't. If your reviewers approve 98% of AI recommendations without pushback, that's a sign the review is theatre, not oversight. For a worked example of what HITL and governance look like when applied to one sector specifically, see AI for Public Administration, where the stakes of automated decision-making are especially visible.

How do you check for bias and fairness in AI-assisted decisions?

Bias in AI outputs isn't a hypothetical risk you address by writing a values statement. It shows up concretely: a resume-screening tool that downgrades candidates from certain colleges or with career gaps, a credit-scoring assistant that correlates with pin codes that proxy for caste or religion, a customer service AI that responds differently based on the language or dialect used.

Practical steps that actually catch this:

None of this requires a data science team. It requires someone with the authority to pause a rollout if the numbers look wrong, and the discipline to actually look.

When do you need to disclose that AI was involved?

Transparency doesn't mean stamping "AI-generated" on everything. It means disclosing AI involvement where it changes how a reasonable person would interpret or trust the output: customer-facing chatbots that could be mistaken for a human agent, AI-assisted decisions that affect someone's application or eligibility, AI-generated content presented as original human analysis or testimony, and AI-driven pricing or recommendation systems where disclosure builds trust rather than eroding it.

You generally don't need to disclose AI use for internal drafting, research assistance, or formatting where a human reviews and owns the final output. That's just a tool, the same way spellcheck is a tool. The test is simple: would the person on the other end feel misled if they found out later? If yes, disclose upfront.

What should you check before adopting a third-party AI tool?

Most organisations don't build their own models. They adopt SaaS AI tools, and the governance risk mostly lives in that vendor relationship. Before signing up, check:

This is exactly the kind of judgment call that a "learn 50 AI tools in a weekend" webinar doesn't prepare you for. Knowing which tool has the flashiest demo tells you nothing about whether it's safe to plug into your HR or finance data. We've written more on why 50-AI-tools courses don't work. Governance is a judgment skill, not a tool inventory.

A simple governance framework you can adapt

You don't need a 40-page policy to start. You need clear ownership and a short set of rules everyone can actually remember.

Governance areaPractical requirementWho owns it in most organisations
Data handling (DPDP compliance)Map what personal data flows into which AI tools; confirm lawful basis and purpose limitationData protection officer / compliance lead, with IT
Bias and fairness testingTest consequential AI decisions against diverse samples before and after rolloutFunction head using the tool (HR, credit, admissions), with a technical reviewer
Transparency and disclosureDisclose AI involvement wherever it would change how someone interprets the interactionProduct/communications lead
Human-in-the-loopNamed human reviewer with real override authority for consequential decisionsDepartment manager accountable for the outcome
Vendor due diligenceChecklist review (data residency, training use, certifications, breach terms) before any new AI tool is adoptedProcurement/IT, with legal sign-off for consequential tools
Incident responseDefined process for what happens when an AI output causes harm or a breach occursCompliance lead, with executive escalation path

Assign each row to a real person, set a review cadence (quarterly is reasonable for most mid-sized organisations), and revisit the table whenever you adopt a new AI tool or expand an existing one into a new use case.

Honest limits

Where to build these skills

Understanding governance isn't something you pick up from a tool-list webinar. It's a judgment skill built through structured, applied learning. Garage Labs Tech has trained 150,000+ professionals across 17+ countries, with a 49,000+ member community, and runs programmes in collaboration with IIT Delhi, IIM Lucknow, Masters' Union, and the Harvard Business School Alumni Association.

If you're starting from the basics of applied AI use in an organisational context, AI Fluency is a 6-week live, no-code programme (₹32,000+GST, roughly ₹37,760) that covers responsible, practical AI adoption. If you're further along and want your team to actually build and govern AI workflows, including agents that touch real data, the Applied AI Accelerator Bootcamp is a 10-week live programme (no prior tech background needed) (₹75,000+GST, roughly ₹88,500) where participants ship 7 to 10 AI agents, including RAG (Retrieval-Augmented Generation) pipelines, culminating in a Demo Day. Not sure where you stand? Take the free AI readiness quiz first.

Frequently asked questions

Does a small organisation need a formal AI governance policy?

You need clear ownership and a short checklist more than you need a formal document. A one-page table assigning who owns data handling, bias checks, and vendor vetting is more useful early on than a lengthy policy nobody reads. Formalise it as your AI use scales.

Does the DPDP Act apply if we only use AI tools internally, not customer-facing?

Yes, if the data involved is personal data, including employee data. The DPDP Act applies to the processing of personal data of individuals in India regardless of whether the AI use is internal or customer-facing.

Who should own AI governance inside an organisation?

There's no single universal answer, but it should be a named individual, not a committee with diffuse responsibility. Typically that's a compliance or data protection lead, working with IT and the business function heads who actually use the AI tools day to day.

How often should we re-test an AI tool for bias?

For consequential decisions (hiring, credit, admissions), quarterly review of outcomes is a reasonable baseline, with an additional check any time the underlying model or vendor changes. Low-stakes internal use needs far less frequent review.

What's the single biggest governance mistake organisations make?

Treating human-in-the-loop as a checkbox rather than real oversight: having a person technically "review" AI output without giving them the time, authority, or incentive to actually push back on it.

For a broader view of how governance fits into your overall AI rollout, browse our programmes or take the free AI readiness quiz to see where to start.

Read the full article on Garage Labs Tech — India's applied AI education platform. Explore our AI courses and programmes.