Artificial intelligence is rapidly becoming a core component of the Web3 ecosystem. AI can be used to analyse blockchain transactions, detect fraud, automate smart contracts, power decentralised applications and support digital-asset platforms. At the same time, the combination of AI, blockchain and autonomous systems creates difficult questions about accountability, transparency and liability when an AI system causes harm.
India has taken a relatively flexible approach to AI regulation. Rather than introducing a single, comprehensive AI statute, the Government has developed a principle-based governance framework that works alongside existing laws.
India’s AI Governance Framework
The India AI Governance Guidelines, released by the Ministry of Electronics and Information Technology (MeitY) in November 2025, provide a framework for safe, inclusive and responsible AI adoption. The framework is built around seven principles, or “Sutras”, including trust, people-first development, innovation, fairness, accountability, explainability and safety, resilience and sustainability.
The Guidelines recognise that accountability is central to AI governance. They propose that responsibility should be assigned according to factors such as the role performed, the risk of harm and the due diligence undertaken by the relevant developer or deployer.
Who Is Liable When AI Causes Harm?
One of the most important legal questions surrounding AI is determining who should be responsible when an AI system makes a harmful decision.
Consider an AI-powered Web3 platform that automatically evaluates transactions and flags or blocks wallets. If the system incorrectly identifies a legitimate transaction as fraudulent, questions may arise concerning the developer, platform operator, data provider or other participants in the AI supply chain.
The emerging Indian approach focuses on role-based and risk-based accountability, rather than automatically attributing liability to the AI system itself. The AI Governance Guidelines recommend developing clearer liability regimes and using existing legal mechanisms wherever possible.
This means businesses cannot simply argue that “the AI made the decision” to avoid responsibility. Organisations deploying AI remain responsible for establishing appropriate safeguards, oversight and risk-management mechanisms.
AI, Blockchain and Data Protection
AI systems frequently depend on large datasets for training, testing and operation. When these datasets contain personal information, data-protection requirements become relevant.
The Digital Personal Data Protection Act, 2023 (DPDP Act) provides a framework governing the processing of digital personal data. The AI Governance framework identifies the DPDP Act as one of the existing legal foundations for responsible AI deployment.
Web3 businesses using AI should therefore consider whether personal data is being collected, processed, shared or retained through their applications, smart contracts or AI systems.
Explainability and Human Oversight
AI systems can be difficult to understand, particularly when complex models are involved. The India AI Governance Guidelines identify “Understandable by Design” as one of their core principles.
For businesses, this means users should receive meaningful information about how AI systems operate and how their outputs may affect them, to the extent technically feasible. Human oversight is particularly important where AI systems make decisions involving significant financial, legal or personal consequences.
Managing AI Liability Risks
Web3 and AI businesses should establish clear governance mechanisms before deploying high-impact systems. These can include:
- documenting the purpose and capabilities of AI systems;
- conducting risk assessments before deployment;
- maintaining appropriate human oversight;
- monitoring AI outputs for errors and harmful outcomes;
- maintaining audit trails and decision records;
- implementing cybersecurity and data-protection controls;
- establishing grievance and incident-response mechanisms; and
- clearly allocating responsibilities through contracts with developers and technology providers.
These measures can help demonstrate that reasonable precautions and due diligence were undertaken if an AI-related dispute arises.
Conclusion
The integration of AI with Web3 creates enormous opportunities but also introduces new accountability challenges. India’s emerging governance approach focuses on responsible innovation, human oversight, transparency and risk-based accountability rather than imposing a single rigid regulatory model.
For businesses, the key lesson is simple: AI should not be treated as an autonomous legal shield. Developers and deployers must understand the risks associated with their systems and establish appropriate safeguards.
As AI becomes increasingly autonomous and integrated with blockchain-based financial and digital ecosystems, clear governance frameworks will be essential to determine who is responsible, how harm should be addressed and how innovation can develop without compromising public trust.
