AI in Indian compliance: what works, and what to be sceptical of
Where language models genuinely help a compliance function operating across Central and state law, where they are actively dangerous, and the four questions that separate a grounded system from a demo.
Every vendor in this market now says AI. The claims are largely indistinguishable and the underlying capability is not. This is an honest map, written by people who build these systems and therefore know where they break.
Where it genuinely works
Classification and extraction. Determining that a gazette notification amends a rule rather than introduces one, extracting the effective date, identifying the states affected. Reliable, measurable against ground truth, and it removes a large volume of tedious reading.
Retrieval across a fragmented corpus. This is the strongest application in the Indian context specifically. The current text of a rule frequently exists nowhere as a single document — it is an Act, plus rules, plus a state amendment, plus three notifications. Retrieval that assembles the applicable position across those fragments is genuinely valuable, because the alternative is a person who has to know where to look.
First-draft generation with citations. Drafting an SOP, a BRD section or a board note, with every claim linked to a source and a human approving before it counts.
Consistency checking. Finding places where your Gujarat SOP and your Maharashtra SOP have diverged in ways nobody intended. Models are good at this and humans are bad at it, because it requires holding a lot of text in mind at once.
Where it does not work
Ungrounded question answering on Indian law. A model without a retrieved corpus will answer confidently and, with meaningful frequency, wrongly. The specific failure mode in India is worse than elsewhere: models trained largely on Western legal text will answer an Indian question with reasoning imported from a regime that does not apply, and it will read plausibly.
Ask a general-purpose model whether a personal data breach requires notification and there is a real chance you get a GDPR-shaped answer about materiality thresholds. Under DPDP there is no materiality threshold. That answer is not slightly wrong; it is the opposite of the obligation.
State-level specificity from a general model. Whether Karnataka requires a half-yearly return under its rules is a fact about a gazette notification. A model without that notification retrieved will produce something confident and unreliable.
Interpretation where the answer depends on the officer. A great deal of Indian compliance turns on how a specific regional office applies a rule. This is institutional knowledge, not textual reasoning, and it belongs to a person who can be accountable for the position.
How to evaluate a claim
Four questions separate substance from marketing.
1. What is it grounded in, and can I see the sources?
If answers do not carry citations to specific provisions, the system is generating rather than retrieving. "Trained on Indian regulatory data" describes a training set and tells you nothing about whether a given answer is supported.
2. What does it do when it does not know?
Ask about a state's rules under a Code that has not notified them. A well-built system says the rules are not yet notified and shows what it searched. A poorly built one invents plausible rules. Ninety seconds, and the most informative thing you can do in a demo.
3. How is accuracy measured, and by whom?
Ask for the evaluation methodology and the results, including where it performs worst. A vendor who cannot produce this either has not measured it or does not like the numbers.
4. Is state coverage real or inferred?
Ask specifically: for Chhattisgarh, is the state rule ingested as a document, or is the system reasoning from the Central rule? The answer distinguishes a coverage claim from a coverage capability, and the difference is invisible in a demo unless you ask.
What we do
For transparency, since the above is a standard we should be held to:
- Retrieval is restricted to a curated corpus — the Acts, rules, notifications, state amendments and your own documents. No open-web generation path.
- Generation is constrained to cited passages, and a separate verification pass checks each claim against its citation before display.
- Where grounding is insufficient the system declines and shows what it searched. We measure refusal calibration and report it.
- Every prompt, retrieval set and response is logged.
- Your content is never used to train shared or third-party models, and inference runs under zero-retention terms.
That does not make it infallible. It makes it auditable, which in this domain is the property that matters.
The strategic point
The useful question is not "does this use AI". It is "what would I have to believe for this output to be safe to rely on, and can I check it?"
Applied that way, AI in Indian compliance is a substantial productivity gain on retrieval, extraction and drafting, with a hard boundary at interpretation — and the vendors worth taking seriously draw that boundary where you would.
Written by Rohit Menon, Principal Regulatory Analyst
Part of the team that builds and maintains the Regulens obligation library and platform. If you disagree with something here, we would genuinely like to hear it — get in touch.