This article is written by Pratyush Pandey, a law student at ICFAI University, Dehradun, with a keen interest in Constitutional law.
The rapid deployment of artificial intelligence across sectors such as healthcare, transportation, finance, and law enforcement has begun to expose the limitations of India’s existing criminal law architecture. The Bharatiya Nyaya Sanhita, like the Indian Penal Code before it, was drafted around a human actor capable of forming intention or negligence, and the entire scaffolding of criminal responsibility rests on this assumption. When an autonomous or semi-autonomous system causes harm without any identifiable human decision at the moment of the act, the traditional requirements of mens rea and actus reus become difficult to apply in a coherent manner. This article examines the doctrinal strain that artificial intelligence places on Indian criminal law, surveys how other jurisdictions have begun to respond, and argues that India requires a purpose-built statutory framework rather than an attempt to stretch existing provisions to cover machine-caused harm.
Introduction
Artificial intelligence is no longer a subject confined to computer science departments or speculative fiction. It now drives cars, screens loan applications, assists in medical diagnosis, moderates online content, and increasingly informs decisions made by police and courts. As these systems take on tasks that were once performed exclusively by human beings, a difficult question has begun to surface: who should answer, in criminal law, when an AI system causes serious harm?
This question is not merely academic. A self-driving vehicle that misclassifies a pedestrian and causes a fatal collision, a diagnostic algorithm that recommends a harmful course of treatment, or a trading bot that manipulates a market through emergent behaviour nobody explicitly programmed, all raise the same underlying puzzle. Indian criminal law, built on nineteenth-century assumptions about human agency, has no settled answer.
This article proceeds in four parts. It first outlines the foundational principles of criminal liability under Indian law and explains why they sit uneasily with autonomous systems. It then considers specific fact patterns where the mismatch becomes visible. It surveys comparative developments, particularly in the European Union and the United States, before setting out concrete proposals for statutory reform in India.
The Foundations of Criminal Liability and Why AI Disrupts Them
Mens Rea and Actus Reus
Criminal liability in India, as in most common law systems, rests on two pillars: a guilty act (actus reus) and a guilty mind (mens rea). Sections dealing with offences under the Bharatiya Nyaya Sanhita, 2023, continue to define offences in terms of intention, knowledge, or negligence attributable to a person. An AI system, however sophisticated, does not possess intention in the legal sense. It does not knowingly choose an outcome; it produces an output based on statistical patterns learned from training data. The absence of a mental state that the law can meaningfully interrogate creates what several scholars have termed a ‘responsibility gap’.
The Problem of Multiple Human Actors
A second complication arises because AI systems are rarely built or deployed by a single person. A typical machine learning system involves data scientists who curate training data, engineers who design the model architecture, a corporation that markets the product, and an end user who deploys it in a particular context. When harm occurs, responsibility is diffused across this chain, and no individual actor may satisfy the threshold of culpability that criminal law demands. This is distinct from, though related to, the well-established problem of corporate criminal liability, because at least one link in the AI chain is not a human decision at all but an emergent output of the model itself.
Foreseeability and the Limits of Negligence
Indian courts have traditionally relied on the standard of the ‘reasonable person’ to assess negligence. Machine learning systems, particularly deep neural networks, often behave in ways that are not fully explainable even to their own designers. If a harmful output could not reasonably have been foreseen by any human in the chain, prosecuting anyone for criminal negligence becomes legally and morally questionable, even though a real victim has suffered real harm.
Illustrative Fact Patterns
The doctrinal difficulty is best understood through concrete scenarios that are already technically feasible or, in some jurisdictions, have already occurred.
- Autonomous vehicles: a self-driving car’s perception system fails to identify a pedestrian in low light and causes death. No human was driving; the software vendor did not intend the outcome; the owner merely activated an autopilot feature as instructed.
- Algorithmic trading: a trading algorithm engages in behaviour resembling market manipulation that was never explicitly coded but emerged from reinforcement learning against other automated traders.
- Medical diagnostic tools: a clinical decision-support system recommends a dosage that a treating doctor follows without independent verification, resulting in patient harm.
- Predictive policing and facial recognition: an AI system used by police misidentifies a suspect, leading to wrongful arrest and detention, raising questions of liability for both the developer and the deploying authority.
- Deepfakes and AI-generated fraud: generative AI tools are used to create synthetic audio or video impersonating real individuals for extortion, defamation, or financial fraud, complicating attribution of the underlying criminal act.
In each scenario, existing provisions of the Bharatiya Nyaya Sanhita and allied statutes such as the Information Technology Act, 2000, can be invoked only through analogy or strained interpretation. None of these statutes contemplates a non-human contributing cause with this degree of autonomy.
Comparative Perspectives
The European Union
The European Union has taken the most structured regulatory approach through the Artificial Intelligence Act, which classifies AI systems by risk category and imposes graduated obligations on providers and deployers of high-risk systems. While the Act is primarily a regulatory rather than a criminal instrument, it establishes documentation, transparency, and human-oversight obligations that could plausibly anchor future criminal negligence standards by defining what a ‘reasonable developer’ was obliged to do.
The United States
The United States has so far relied on a patchwork of tort law, sector-specific regulation, and existing criminal statutes applied by analogy, particularly in the context of autonomous vehicle collisions investigated by the National Highway Traffic Safety Administration. Liability in most publicised incidents has been resolved through civil settlement rather than criminal prosecution, which illustrates the reluctance of prosecutors to extend criminal liability into genuinely novel territory without clear statutory backing.
The United Kingdom and the Law Commission Approach
The Law Commission of England and Wales has, in the context of automated vehicles, recommended a distinction between the ‘user-in-charge’, who retains limited responsibility for matters unrelated to the driving task, and the automated driving system entity, an authorised corporate body treated as responsible for the vehicle’s driving behaviour. This model offers a useful template because it does not attempt to assign traditional mens rea to software; instead, it creates a statutory responsible entity.
Gaps in the Indian Legal Framework
India’s response to AI-related harm remains fragmented. The Information Technology Act, 2000, addresses computer-related offences but was drafted for an era of hacking and data theft, not autonomous decision-making systems. The Bharatiya Nyaya Sanhita, 2023, despite being a comprehensive re-codification of criminal law, does not contain a single provision addressing AI or autonomous systems. The Digital Personal Data Protection Act, 2023, governs data processing but is silent on criminal consequences flowing from algorithmic decisions. NITI Aayog’s strategy papers on responsible AI articulate ethical principles but carry no binding force and create no liability regime.
This absence of a dedicated framework leaves victims of AI-caused harm dependent on general provisions relating to rash or negligent acts, cheating, or causing death by negligence, none of which were designed with a non-human causal agent in mind. Prosecutors and courts are consequently forced to choose between under-inclusive interpretation, which lets genuine wrongdoing go unpunished, and over-inclusive interpretation, which risks punishing individuals for outcomes they could not reasonably have controlled.
Toward a New Legal Framework: Proposals for India
A coherent Indian response should combine targeted legislative amendment with a new regulatory-cum-liability statute rather than relying on judicial improvisation. The following elements are proposed.
A Statutory Definition and Risk Tiering
Any future law must begin with a workable statutory definition of an ‘autonomous system’ and a risk-based classification broadly similar to the EU model, distinguishing systems used in safety-critical contexts, such as transportation, healthcare, and law enforcement, from lower-risk consumer applications.
A Chain-of-Custody Liability Model
Rather than searching for a single culpable mind, the law should statutorily allocate responsibility along the development-to-deployment chain, attaching specific, pre-defined duties to developers, corporate deployers, and end users. Failure to discharge a defined duty, such as adequate testing, transparency documentation, or human-oversight protocols, would itself constitute the culpable conduct, replacing the search for subjective intention with an objective compliance standard.
Corporate Criminal Liability as the Primary Anchor
Since Indian law already recognises corporate criminal liability, high-risk AI systems should generally be deployed only through a registered corporate entity that assumes primary criminal responsibility for harm arising from the system’s operation, analogous to the ‘automated driving system entity’ proposed in the United Kingdom. This avoids the injustice of criminalising individual engineers for emergent behaviour they could not have reasonably foreseen, while still ensuring accountability.
A Rebuttable Presumption of Negligence
For high-risk systems, the law could introduce a rebuttable presumption that harm caused by the system resulted from inadequate testing, oversight, or design, shifting the evidentiary burden onto the deploying entity to demonstrate compliance with prescribed safety standards. This mirrors existing product liability logic while retaining a criminal law dimension for cases of gross non-compliance.
Mandatory Explainability and Audit Trails
A meaningful liability regime requires that high-risk AI systems maintain auditable logs of decision-making inputs, sufficient to reconstruct, after the fact, why a particular output occurred. Without this, both prosecution and defence are left arguing in the dark, and courts cannot meaningfully assess foreseeability or negligence.
A Specialised Regulatory and Adjudicatory Body
Given the technical complexity involved, ordinary criminal courts may be poorly placed to assess algorithmic conduct. India could consider a specialised tribunal or an expert regulatory authority empowered to conduct technical investigations and provide binding findings that criminal courts could rely upon, similar in spirit to how the National Green Tribunal handles technically complex environmental disputes.
Conclusion
Artificial intelligence does not fit comfortably within a criminal law built for human agents capable of intention and foresight. India’s current statutes, including the newly enacted Bharatiya Nyaya Sanhita, were not designed with autonomous decision-making systems in mind, and stretching existing provisions to cover machine-caused harm risks both under-protecting victims and unfairly criminalising individuals for outcomes beyond their control. A dedicated legislative framework, combining risk-based classification, chain-of-custody liability, corporate accountability, mandatory explainability, and specialised adjudication, would allow India to address AI-related harm without abandoning the foundational principles of criminal justice. The question is no longer whether such a framework is needed, but how quickly it can be designed and enacted before the technology outpaces the law even further.



