India, Australia, and the regional pattern

Lesson 5 of 5 in Asia-Pacific: Japan, South Korea, Singapore, India, and Australia.

India governs the world’s largest online population with no standalone AI law — by choice, loudly reaffirmed in its pro-innovation with guardrails positioning and its 2025 AI Governance Guidelines. The machinery is promotional: the IndiaAI Mission (2024, seven pillars spanning compute, datasets, skills, and safe-and-trusted AI), an IndiaAI Safety Institute (announced January 2025, hub-and-spoke across research institutions), the DPDP Act 2023 as the data substrate, and the prestige of hosting the AI Impact Summit in New Delhi (February 2026) — the first Global South summit host.

But when a harm crystallised, Delhi legislated with precision. After a wave of political deepfakes, the IT (Intermediary Guidelines) Rules amendment — G.S.R. 120(E), notified 10 February 2026, effective 20 February 2026 — obliges platforms to ensure synthetically generated content is labeled, with metadata permanently embedded in the content itself. One binding rule, aimed at one harm, riding on existing intermediary law: India joined the China–Korea–EU labeling convergence without writing an AI act.

Australia ran the region’s most transparent deliberation — and reached the quietest conclusion. Its long-standing position is existing-law-first: the Privacy Act 1988, Australian Consumer Law, the Online Safety Act 2021, and the Corporations Act already reach most AI harms. In 2024 the government published a Voluntary AI Safety Standard (ten guardrails: accountability, risk management, testing, human oversight, transparency, contestability, and more) alongside a Proposals Paper for mandatory guardrails on high-risk AI — three legislative options on the table, EU-style act included.

Then, in late 2025, the government chose: no dedicated AI act. Existing regulators would handle AI within their remits, supported by a National AI Capability Plan; an Australian AI Safety Institute was announced on 25 November 2025. The counterweight is real, though: privacy reform added automated-decision transparency duties (in force from December 2026), and the consumer regulator has AI squarely in scope. Australia’s answer to Korea’s statute is a bet that general law plus targeted patches beats a new regime.

Interactive sorting exercise: Classify each Asia-Pacific instrument: binding law, voluntary instrument, or shelved/abandoned?

Step back and the regional pattern teaches the module’s final lesson. The split — statute (Korea), promotion law (Japan), toolkit (Singapore), targeted patch (India), existing-law bet (Australia) — is not random. It tracks each country’s regulatory tradition (Korea’s framework-act habit, Japan’s administrative guidance, Singapore’s standards-led development state), its industrial position (model-makers hesitate to bind themselves; model-takers regulate imports more readily), and its experienced harms (India regulated exactly the deepfake problem that hit its elections).

For practitioners, the consequence is concrete: a single product launched across the region faces labeling duties in three regimes (Korea, India — plus China next door), high-impact obligations in one (Korea), and evidence expectations everywhere — which is why the highest-common-denominator strategy usually starts with Korea’s requirements plus a portable assurance file built with Singapore’s tools.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.