India’s MeitY Finalizes AI Governance Framework: Mandatory Audits for Models Above 1 Billion Parameters
Every major AI lab operating in India just received a compliance deadline. India’s Ministry of Electronics and Information Technology (MeitY) has circulated a near-final draft of its AI governance rules, and the central requirement is unambiguous: any artificial intelligence model exceeding 1 billion parameters deployed within Indian borders must undergo mandatory third-party audits. For OpenAI, Google DeepMind, and Meta — whose Llama models have seen widespread adoption across Indian enterprises and developer communities — the clock is now running.

The framework represents one of the most consequential developments in global AI policy this year, positioning India not as a regulatory follower but as a standard-setter for large-model governance across the Global South and beyond.
—
What the Draft Framework Actually Requires
At the core of MeitY’s AI governance proposal is a tiered risk classification system that categorizes AI deployments according to their potential societal impact. Models are sorted into low, medium, and high-risk tiers, with the 1-billion-parameter threshold serving as the primary trigger for the most stringent compliance obligations.
For models crossing that threshold, the draft mandates:
– **Third-party technical audits** conducted by accredited assessment bodies prior to deployment or upon significant model updates – **Transparency disclosures** covering training data provenance, intended use cases, and known limitations – **Incident reporting mechanisms** requiring developers to notify MeitY within a defined window if a deployed model causes or contributes to measurable harm – **Ongoing monitoring obligations** that extend beyond the initial audit cycle
The 6-month compliance window gives affected organizations a defined but demanding runway to align their India operations with the new rules. For companies already navigating the EU AI Act’s phased implementation, the parallel timeline adds another layer of operational complexity — though India’s framework is notably more targeted in its parameter-based trigger than the EU’s broader risk-category approach.
—
Who Is Directly Affected

The practical scope of this framework is broad. OpenAI’s GPT-series models, Google DeepMind’s Gemini family, and Meta’s openly available Llama models all comfortably exceed the 1-billion-parameter threshold. So do a growing number of models developed by Indian AI startups and research institutions that have scaled their architectures to compete with global counterparts.
Enterprise deployments fall equally within scope. Indian banks, healthcare providers, and government-adjacent technology platforms that have integrated large language model capabilities — whether through APIs or on-premise deployments — will need to verify that their upstream model providers are audit-compliant under the new rules.
The draft envisions a new category of accredited auditors to handle large language model assessments, raising immediate questions about capacity. Building a credible auditor ecosystem capable of technically evaluating frontier models is a substantial undertaking, and the 6-month compliance window will pressure MeitY to move quickly on accreditation standards.
—
India’s Strategic Positioning in Global AI Policy
The timing of this framework is deliberate. By moving toward enforceable large-model rules before the EU AI Act’s most demanding provisions take full effect, India is signaling that it intends to shape — not simply adopt — international norms for AI governance.
This matters for several reasons. India is one of the world’s largest AI deployment markets by user volume, and its regulatory posture carries significant weight with developers who cannot afford to treat the country as a secondary compliance jurisdiction. A mandatory audit regime backed by credible enforcement gives MeitY genuine leverage in negotiations with global AI developers over data practices, safety standards, and market access conditions.
The framework also reflects a broader shift in Indian technology policy. AI compliance has moved from a discussion topic in policy circles to a structured regulatory obligation, and the parameter-based threshold lends the rules a technical precision that earlier, more principles-based guidance lacked.
—
Key Tensions and Open Questions
Despite its ambition, the draft framework leaves several critical issues unresolved.
**Audit methodology standardization** remains undefined. Without agreed technical benchmarks for what a compliant large language model audit actually tests — bias evaluation, safety red-teaming, capability assessments — auditors and developers will operate with considerable interpretive latitude, potentially producing inconsistent outcomes across the industry.
**Open-source model treatment** presents another pressure point. Meta’s Llama models are publicly available, meaning compliance obligations would fall on Indian deployers rather than Meta itself in many use cases. How MeitY intends to enforce audit requirements across a fragmented landscape of open-weight model deployments has not yet been clarified.
**Cross-border data flows** connected to audit processes raise sovereignty questions the draft does not fully address. Auditing a frontier model’s training data provenance may require access to information that developers consider proprietary or that is stored in jurisdictions operating under conflicting legal frameworks.
Industry stakeholders are expected to submit formal comments before the framework is finalized, and these tensions are likely to dominate that process.
—
What Comes Next
MeitY is expected to open a formal public consultation period before the rules are gazetted, giving industry, civil society, and technical experts a structured opportunity to shape the final text. The accreditation process for third-party auditors will likely run in parallel, as the framework cannot function without a qualified auditor pool in place before the compliance deadline arrives.
For AI developers and enterprise teams operating in India, the immediate priority is a clear-eyed assessment of which deployments cross the 1-billion-parameter threshold and what documentation — training data records, model cards, internal safety evaluations — already exists to support an audit process.
India’s move toward mandatory, technically grounded AI oversight is not a regulatory experiment. It is a structural shift in how one of the world’s most significant AI markets governs frontier technology. Organizations that treat MeitY’s framework as a compliance checkbox rather than a strategic operating condition will find themselves poorly positioned as the rules take effect — and as other major economies watch India’s implementation closely for a model worth replicating.
Send free SMS worldwide
Reach any mobile number in 200+ countries from your browser. No signup, no app.
Send a free SMS →

