How India's Existing Legal Framework Fails To Protect Children Interacting With Artificial Intelligence Systems
Somewhere in India this evening, a child too young to legally sign a contract is confiding in a chatbot. Not asking it homework questions, but talking to it about loneliness, about a fight at school, about feelings an eleven-year-old rarely voices to an adult. The chatbot listens patiently, responds warmly, and remembers nothing of the legal architecture built to protect that child, because that architecture was not designed with this relationship in mind. This is the quiet frontier of India's next debate, and it is arriving faster than our institutions are prepared to answer it.
For a decade, India's child-safety conversation online was framed almost entirely around content: pornography, cyberbullying, predatory contact, and data harvesting for targeted advertisements. These remain real and serious harms, and the legal system has built, however imperfectly, a response to them through the 's provisions on child sexual abuse material, the 's takedown obligations, and now the , which requires before processing a child's personal data and bars and directed at minors.
However, the rise of generative artificial intelligence has introduced a category of harm that was never built to catch: . In this paradigm, the risk lies not in what a child is shown, but in what a system persuades a child to believe, feel, or depend upon. Companion chatbots, often engineered for engagement rather than welfare, can cultivate emotional attachment in precisely the demographic least equipped to recognize such engagement as a commercial design choice.
The Inadequacy of Static Consent Models
To be fair to policymakers, India is not starting from zero. The DPDPA’s parental-consent and no-targeted-advertising provisions for children are among the most protective in comparative data law. Furthermore, the IT Rules amendments moving through add labeling requirements for AI-generated content and set faster takedown timelines. At the state level, the has drafted a '', which proposes mandatory labeling of AI-generated content and mandates platform action within 24-48 hours on harmful material. At the central level, India's AI Governance Guidelines articulate child welfare as a core design principle.
Yet, the trouble is that nearly all of this scaffolding is content-and-consent architecture, adapted from an internet-safety paradigm built for static websites and social media feeds.
assumes a threshold moment—a sign-up—after which the relationship is presumed safe unless specific harmful content appears. But a companion AI's risk profile does not announce itself at sign-up. It accumulates over months of conversation, through a system optimized to maximize engagement by mirroring the child's emotional needs back at them. As
's guidance on AI and children has noted, there are
"genuinely novel risks distinct from, and in some ways harder to regulate than, the older harms of explicit content or online predators, because there is no obscene image to take down and no predator to name."
The harm is diffuse, cumulative, and built into the product's design incentives.
The Limits of International Benchmarking
When looking at global solutions, India cannot simply import the models of other jurisdictions. France’s recent legislative approach, for instance, has leaned toward hard age gates, barring those under 15 from social platforms and redesigning algorithmic defaults. While conceptually robust, such a blunt instrument faces severe hurdles within India's digital-inclusion realities. A hard age-verification regime assumes reliable identity infrastructure that reaches every child uniformly. In reality, large sections of India's young population access AI-enabled devices through shared family phones, cybercafes, or school-provided tablets. In these environments, the very idea of a single verifiable “user” breaks down. Any regulatory response modeled uncritically on European age-gating risks becoming either unenforceable at scale or, worse, an exclusionary burden that only urban, digitally fluent families can navigate, while rural and lower-income children are pushed toward unregulated, unlabelled alternatives.
A New Path for Indian
If India is to successfully navigate this challenge, the legal community and policymakers must shift from a focus on static to a comprehensive .
First, the DPDPA's child-consent framework needs an explicit AI-interaction layer. This should distinguish static data collection from ongoing, adaptive, relationship-simulating systems. Regulators must impose design obligations—not just consent obligations—on products marketed to or predictably used by minors. A consent checkbox cannot substitute for a duty to design conversational AI that recognizes signs of distress and routes a child toward a human, rather than deeper into the product’s feedback loop.
Second, the accountability gap between the platform and the model developer needs closing. Current thinking, inherited from the social-media era, assigns responsibility to the platform hosting content. However, a companion chatbot's harmful output is generated, not merely hosted. The developer of the underlying model bears a design responsibility that existing IT Rules categories do not clearly capture. India's evolving AI governance framework should explicitly define this responsibility rather than leaving it to be litigated after harm occurs.
Third, and most urgently, this cannot remain a Centre-versus-States patchwork. If the Karnataka Bill and central guidelines continue to move on separate tracks, without interoperable definitions of “AI-generated content” or “child user,” the result will be a fragmented . A child's protection should not depend on which State's server logs the interaction. A harmonized national standard is essential to ensure that developers cannot simply relocate their operations to evade stricter scrutiny.
Conclusion: The Narrowing Window
India has an unusual advantage: it is legislating on the intersection of children and AI before, rather than after, a defining national scandal forces its hand. That window, however, will not stay open indefinitely. The DPDPA’s child provisions, the IT Rules amendments, and the AI Governance Guidelines were each meaningful steps, but they were largely settled before companion AI became a staple of a child's daily emotional life.
Closing the gap between what these frameworks assume about a “child user” and what a child actually does with AI is not a technical footnote; it is the next real test of whether India's architecture truly protects the people least able to protect themselves within it. The transition from reactive content moderation to proactive design-based regulation is the mandatory next step for legal professionals and lawmakers alike, ensuring that the technology of the future does not compromise the well-being of the next generation.