News Analysis • 5 min
ANI v. Open AI: How the Commercial Research Exception Impacts Fintech AI Governance Under the DPDP Act
The ANI v. Open AI ruling provides critical guidance on treating commercial AI model training as research, offering a potential exemption roadmap for fintechs processing digital personal data under the DPDP Act, 2023.
Last updated:
What Happened
According to a legal analysis published in August 2026 by Cyril Amarchand Mangaldas, the Indian judicial ruling in ANI v. Open AI established that commercial AI model training can be classified as research. This interpretation provides critical guidance on how computational data analysis interacts with both copyright laws and the Digital Personal Data Protection Act, 2023. The regulatory framework draws heavily on Singapore's approach, which amended its copyright legislation to permit computational data analysis for AI development. Singapore also issued guidance allowing legitimate-purpose exceptions under its data protection framework, even when monetization paywalls are present. The ANI v. Open AI ruling translates a similar dual approach to the Indian context, clearing a significant conceptual hurdle for developers.
Does The DPDP Act Apply Here
Applicability hinges heavily on data origins and territorial scope. Under Section 3 of the DPDP Act, 2023, the law applies to the processing of digital personal data within India, and processing outside India connected to offering goods or services to Data Principals in India. AI training pipelines routinely ingest massive datasets to build algorithmic models.
However, Section 3 expressly states that the Act does not apply to personal data made publicly available by the Data Principal or by someone under a legal obligation to do so. For fintechs scraping public domains for alternative credit scoring data, this carve-out is highly relevant. Conversely, proprietary transaction data remains fully within the regulatory scope and requires a valid lawful purpose.
Legal Implications Under DPDP
The primary friction point for AI development under the DPDP Act is establishing a valid ground for processing. Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. If commercial AI training qualifies as research, developers may be exempt from standard consent, itemised notice, and purpose limitation obligations when building or fine-tuning models.
Establishing this exemption requires strict internal governance to prove the activity is genuinely research and not production-level processing. The DPDP Rules, 2025 require verifiable data handling practices, meaning compliance teams must document their exemption rationale clearly. Furthermore, any cross-border transfer of AI training data is generally permitted unless the Central Government restricts transfer to notified countries or territories via a negative list.
Could This Happen To You
Fintech compliance heads face immense pressure as product teams rapidly deploy AI features to stay competitive. If your data science unit dumps production payment records into an unstructured data lake to train a customer service chatbot, your organization is exposed. If a regulator investigates or a breach occurs during this training phase, the Data Protection Board of India (DPBI) will demand immediate evidence of your lawful purpose.
An auditor will ask to see your Record of Processing Activities (RoPA) and proof that access controls were maintained across AI sandboxes. Furthermore, if that AI training environment suffers an exposure, the DPDP Rules, 2025 mandate breach intimation to affected Data Principals without delay, alongside a detailed report to the DPBI within 72 hours. You must ensure your incident response plans explicitly cover data science environments.
What Companies Should Do In The Next 30 Days
1. Map all AI training data pipelines. The compliance team must work with the data science lead to document exactly what personal data is flowing into internal or third-party AI models.
2. Classify data origins accurately. Separate proprietary customer financial data from publicly available data, as the latter falls outside the scope of the DPDP Act under Section 3.
3. Update the Record of Processing Activities (RoPA). The Head of Compliance must formally document whether a dataset is processed based on consent or a research exemption.
4. Review vendor data sharing agreements. Ensure third-party AI platform contracts clearly define liability, data retention limits, and cross-border transfer boundaries.
What To Watch
The boundary between commercial research and standard processing remains a high-risk area for financial institutions. We anticipate the DPBI will eventually issue specific guidance clarifying how research exemptions apply at scale for enterprise AI applications. Exactly 283 days remain until the DPDP hard compliance deadline of 13 May 2027.
Use this window to align your AI governance models with the Act and the operational specifics of the Rules, 2025. Ensure your data science teams are not creating blind spots in your compliance posture. To evaluate how your current AI data pipelines map against DPDP audit requirements, run a baseline assessment at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to data used for training AI models?
Yes, under Section 3, the Act applies to processing digital personal data within India. However, it explicitly excludes personal data made publicly available by the Data Principal, meaning some scraped datasets may fall outside its scope.
Can we process customer data for AI research without explicit consent?
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. The ANI v. Open AI ruling suggests commercial AI training might qualify as a research exception, though this requires careful legal documentation and alignment with the Act.
What happens if an internal AI research dataset is breached?
Under the DPDP Rules, 2025, any personal data breach requires intimation to affected Data Principals without delay. You must also submit a detailed breach report to the Data Protection Board within 72 hours, regardless of whether the data was in a research or production environment.
Are there restrictions on sending AI training data outside India?
Cross-border transfers are generally permitted under the DPDP Act. They are only restricted if the Central Government explicitly notifies a negative list of countries or territories where data cannot be transferred.
How should a Head of Compliance prepare AI pipelines for the 2027 deadline?
You must integrate AI data flows into your Record of Processing Activities (RoPA), clearly identifying the lawful purpose under Section 4. Additionally, you should review vendor contracts and establish clear breach response workflows for your data science environments.
ComplyDP