How India's Existing Legal Framework Fails To Protect Children Interacting With Artificial Intelligence Systems

Somewhere in India this evening, a child too young to legally sign a contract is confiding in a chatbot. Not asking it homework questions, but talking to it about loneliness, about a fight at school, about feelings an eleven-year-old rarely voices to an adult. The chatbot listens patiently, responds warmly, and remembers nothing of the legal architecture built to protect that child, because that architecture was not designed with this relationship in mind. This is the quiet frontier of India's next digital rights debate, and it is arriving faster than our institutions are prepared to answer it.

For a decade, India's child-safety conversation online was framed almost entirely around content: pornography, cyberbullying, predatory contact, and data harvesting for targeted advertisements. These remain real and serious harms, and the legal system has built, however imperfectly, a response to them through the Protection of Children from Sexual Offences (POCSO) Act's provisions on child sexual abuse material, the Information Technology (IT) Act's takedown obligations, and now the Digital Personal Data Protection Act (DPDPA), 2023, which requires verifiable parental consent before processing a child's personal data and bars behavioural tracking and targeted advertising directed at minors.

However, the rise of generative artificial intelligence has introduced a category of harm that content-based regulation was never built to catch: relationship-based harm. In this paradigm, the risk lies not in what a child is shown, but in what a system persuades a child to believe, feel, or depend upon. Companion chatbots, often engineered for engagement rather than welfare, can cultivate emotional attachment in precisely the demographic least equipped to recognize such engagement as a commercial design choice.

The Inadequacy of Static Consent Models

To be fair to policymakers, India is not starting from zero. The DPDPA’s parental-consent and no-targeted-advertising provisions for children are among the most protective in comparative data law. Furthermore, the IT Rules amendments moving through 2026 add labeling requirements for AI-generated content and set faster takedown timelines. At the state level, the Government of Karnataka has drafted a 'Responsible Social Media and Digital Safety Bill', which proposes mandatory labeling of AI-generated content and mandates platform action within 24-48 hours on harmful material. At the central level, India's AI Governance Guidelines articulate child welfare as a core design principle.

Yet, the trouble is that nearly all of this scaffolding is content-and-consent architecture, adapted from an internet-safety paradigm built for static websites and social media feeds. Verifiable parental consent assumes a threshold moment—a sign-up—after which the relationship is presumed safe unless specific harmful content appears. But a companion AI's risk profile does not announce itself at sign-up. It accumulates over months of conversation, through a system optimized to maximize engagement by mirroring the child's emotional needs back at them. As UNICEF 's guidance on AI and children has noted, there are "genuinely novel risks distinct from, and in some ways harder to regulate than, the older harms of explicit content or online predators, because there is no obscene image to take down and no predator to name." The harm is diffuse, cumulative, and built into the product's design incentives.

The Limits of International Benchmarking

When looking at global solutions, India cannot simply import the models of other jurisdictions. France’s recent legislative approach, for instance, has leaned toward hard age gates, barring those under 15 from social platforms and redesigning algorithmic defaults. While conceptually robust, such a blunt instrument faces severe hurdles within India's digital-inclusion realities. A hard age-verification regime assumes reliable identity infrastructure that reaches every child uniformly. In reality, large sections of India's young population access AI-enabled devices through shared family phones, cybercafes, or school-provided tablets. In these environments, the very idea of a single verifiable “user” breaks down. Any regulatory response modeled uncritically on European age-gating risks becoming either unenforceable at scale or, worse, an exclusionary burden that only urban, digitally fluent families can navigate, while rural and lower-income children are pushed toward unregulated, unlabelled alternatives.

A New Path for Indian Digital Rights

If India is to successfully navigate this challenge, the legal community and policymakers must shift from a focus on static data protection to a comprehensive duty of care.

First, the DPDPA's child-consent framework needs an explicit AI-interaction layer. This should distinguish static data collection from ongoing, adaptive, relationship-simulating systems. Regulators must impose design obligations—not just consent obligations—on products marketed to or predictably used by minors. A consent checkbox cannot substitute for a duty to design conversational AI that recognizes signs of distress and routes a child toward a human, rather than deeper into the product’s feedback loop.

Second, the accountability gap between the platform and the model developer needs closing. Current intermediary-liability thinking, inherited from the social-media era, assigns responsibility to the platform hosting content. However, a companion chatbot's harmful output is generated, not merely hosted. The developer of the underlying model bears a design responsibility that existing IT Rules categories do not clearly capture. India's evolving AI governance framework should explicitly define this responsibility rather than leaving it to be litigated after harm occurs.

Third, and most urgently, this cannot remain a Centre-versus-States patchwork. If the Karnataka Bill and central guidelines continue to move on separate tracks, without interoperable definitions of “AI-generated content” or “child user,” the result will be a fragmented regulatory environment. A child's protection should not depend on which State's server logs the interaction. A harmonized national standard is essential to ensure that developers cannot simply relocate their operations to evade stricter scrutiny.

Conclusion: The Narrowing Window

India has an unusual advantage: it is legislating on the intersection of children and AI before, rather than after, a defining national scandal forces its hand. That window, however, will not stay open indefinitely. The DPDPA’s child provisions, the IT Rules amendments, and the AI Governance Guidelines were each meaningful steps, but they were largely settled before companion AI became a staple of a child's daily emotional life.

Closing the gap between what these frameworks assume about a “child user” and what a child actually does with AI is not a technical footnote; it is the next real test of whether India's digital rights architecture truly protects the people least able to protect themselves within it. The transition from reactive content moderation to proactive design-based regulation is the mandatory next step for legal professionals and lawmakers alike, ensuring that the technology of the future does not compromise the well-being of the next generation.