For decades, the digital world operated under a silent consensus: Silicon Valley provided the code, and the rest of the world provided the data. But as artificial intelligence (AI) evolves from a convenient novelty into the very nervous system of national governance, that era of technological dependence is reaching a volatile end.
In New Delhi, the conversation has shifted from “digital adoption” to “digital swaraj“—a demand for absolute technological self-reliance. The national discourse is shifting from data sovereignty to a more expansive technological sovereignty. The urgency of this shift was laid bare earlier this month with the release of Mythos AI in the U.S. in April this year.
Developed by Anthropic, Mythos is not just another chatbot; it is an autonomous cybersecurity sentinel capable of identifying “zero-day” vulnerabilities across entire operating systems without human intervention. While its creators champion it as a defensive breakthrough, for India, it represents a systemic digital threat.
When an external entity holds a “master key” to global software vulnerabilities, a nation’s financial and critical infrastructure is only as secure as a foreign corporation’s goodwill.
India’s response is rooted in its unique Digital Public Infrastructure (DPI). Unlike the closed ecosystems of the West or the state-monitored walls of China, India’s “India Stack”—comprising Aadhaar, UPI, Direct Benefit Transfers, and the newer ONDC—treats technology as a public good. This foundation is now being leveraged to build a “Sovereign AI” stack. According to a recent KPMG report (2026),[1] India is developing a national 38,000-GPU compute pool and indigenous 2nm chip designs to ensure that the “brains” of its AI do not reside on foreign servers.
India’s farsighted goal is a hybrid model where global innovation meets local control, where interoperable technologies meet local needs, and where globally standardised digital products and services meet domestic laws and customs. If proved robust and reliable, it can be a model for many countries of the Global South that fall between the U.S. private structures and the Chinese state-led ones.
This infrastructure is being fortified by a sophisticated new legal architecture. The Digital Personal Data Protection Act, 2024, safeguards the privacy and data of Indians. The IT Rules (Amendment) of February 2026 represents a decisive break from “intermediary neutrality”. a legal and technical principle that treats online service providers (such as search engines and social media platforms) as passive conduits, not responsible for the content uploaded by their users, provided they do not initiate transmission, select the recipient, or modify the information. This is also called the ‘safe harbour’ protection under the IT Act, 2000, which ensures that platforms are not treated as publishers or speakers of third-party content.[2]
The law now mandates a three-hour takedown window for AI-generated misinformation and requires “traceability metadata” for all synthetically generated content. This is a vast improvement over the previous 36-hour window for social media platforms to remove unlawful content (on grounds such as national security, public order, or decency) after ‘actual knowledge’ of it was received.[3]
Slashing the response time for deepfakes by 92% – which are still actively proliferating in India due to a massive surge in the technical sophistication of AI-generated content reaching millions of social media users within minutes after being uploaded – will give respite to victims of malicious digital content.[4] Even with a mandated 3-hour takedown window, the damage from online viral velocity is often swift and severe.
India is asserting that its digital borders are as real – and as defensible – as its physical ones. India’s DPI is designed to counter private AI architectures by shifting the balance of power from proprietary, closed-loop systems to open, interoperable, and citizen-centric frameworks. While private AI architectures often rely on data monopolies and vendor lock-in, the DPI model aims to democratise technology by providing shared building blocks that anyone can use to innovate.
India’s ambitions of being the provider of alternative solutions from Big Tech (whose solutions may not be in congruence with the priorities of developing countries) extend beyond its own borders. At the India AI Impact Summit 2026, the message to the Global South was clear: you no longer have to choose between “digital colonisation” and digital isolation. By offering its DPI and low-cost AI models to over 45 countries, India is positioning itself as the “provider of choice” for nations that want to modernise without surrendering their data sovereignty to trillion-dollar tech giants.
The path forward is not about isolationism but about algorithmic accountability. For India, Sovereign AI is not merely a technical milestone; it is the ultimate safeguard of national interest in an age where the greatest weapon is not a missile but a line of code.
Ashish Bharadwaj is the Distinguished Fellow for Law and Education, Gateway House.
This article was exclusively written for Gateway House: Indian Council on Global Relations. You can read more exclusive content here.
Support our work here.
For permission to republish, please contact outreach@gatewayhouse.in
© Copyright 2026 Gateway House: Indian Council on Global Relations. All rights reserved. Any unauthorised copying or reproduction is strictly prohibited.
[1] KPMG International (2026): “Sovereign AI and National Security: Strengthening autonomy in critical systems.”
[2] Several countries are in various stages of legislation that makes platforms pay for the content they take from publishers. In May 2026, Australia’s News Bargaining Incentive becomes law, forcing platforms to pay Australian news publishers. Brazil is at the forefront of the movement to balance the rights of content creators and AI developers; it has compensation mechanisms in its legislative bill. The EU AI Act will be implemented in August, focusing on transparency and identifying AI systems that are high risk. India is seriously considering the payment model. It is mindful to balance the need for locally relevant data to train Indian AI models against pressure from the creative and news industries to be paid for providing data used to train LLMs.
[3] Categories of highly sensitive content, such as non-consensual intimate imagery and victim-centric complaints, had a faster mandated removal time of 24 hours.
[4] The speed of regulation is currently being outpaced by the volume of creation. Women are increasingly becoming victims of deepfakes and other forms of technology-facilitated digital violence.


