India needs regulations that are strict where risks are high but lighter where risks are limited, NITI Aayog Member Rajiv Gauba has said, arguing that policymakers must keep pace with rapid changes in artificial intelligence, cybersecurity and digital technologies without choking innovation and investment.
Speaking at the fifth Kautilya Economic Conclave in New Delhi on October 3, Gauba said policymakers should not frame the debate as a choice between regulation and economic growth.
The objective, he said, should instead be to manage risks while allowing innovation, competition and investment to develop.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
‘Firm Where Risks Are High, Light-Touch Where Risks Are Low’
Gauba called for a shift toward what he described as light-touch and risk-proportionate regulation.
Under such an approach, regulatory requirements would depend on the potential harm associated with a particular activity rather than applying equally strict rules to every business or technology.
He said the State should be “firm where risks are high, and light-touch where risks are low”, while remaining predictable in both situations.
The idea is particularly relevant for emerging technologies where regulators may face pressure to intervene before the risks are fully understood.
Gauba said authorities should first assess whether new rules are actually necessary before imposing them on rapidly evolving sectors.
AI and Cybersecurity Moving Faster Than Regulatory Systems
Gauba highlighted artificial intelligence, cybersecurity and digital technologies as areas where technological change is advancing faster than many existing institutions and regulatory frameworks can adapt.
This creates a difficult policy problem.
If governments move too slowly, serious privacy, security, consumer-protection or financial risks may emerge before safeguards are in place.
But overly restrictive rules introduced too early can make it harder for companies to experiment, compete or introduce new services.
NITI Aayog’s position, as outlined by Gauba, is that regulation should therefore be proportionate to the actual level and consequences of risk.
Regulators Need Better Coordination
Gauba also warned about overlapping responsibilities between regulatory agencies.
As technology companies increasingly operate across finance, communications, data, competition and consumer markets, a single business model may fall under several regulators at the same time.
That can lead to duplicated requirements in some areas while leaving gaps in others.
Gauba called for stronger coordination among regulators to avoid such overlap and close areas where no authority has clear responsibility.
This issue has become increasingly important as AI products move beyond standalone software.
An AI service, for example, could simultaneously involve data-protection obligations, cybersecurity risks, consumer rights, financial regulation or competition concerns depending on how it is deployed.
Regulatory Independence Must Come With Accountability
Gauba also stressed that independent regulators should remain accountable for how they exercise their powers.
He said regulators need sufficient autonomy to make difficult decisions without improper influence.
At the same time, public confidence requires transparent decision-making, clear procedures, effective review mechanisms and accountability for regulatory performance.
That means independence should not translate into unchecked discretion.
Businesses and citizens should be able to understand how decisions are reached, what rules apply and what options exist when a regulatory decision is challenged.
Regulators Need More Technical Expertise
Another concern raised by Gauba was whether regulators themselves possess enough specialised knowledge to oversee increasingly complex markets.
He called for stronger analytical capacity and greater access to expertise as technologies and business models become more sophisticated.
That includes closer engagement with industry, universities and technology institutions.
For areas such as AI and cybersecurity, this could become particularly important.
Regulators increasingly need to understand not only legal or economic questions but also how technologies function, how vulnerabilities arise and how technical safeguards can fail.
Without that capability, authorities risk either underestimating genuine threats or imposing rules that do not address the underlying problem.
Global Trade and Technology Risks Are Reshaping Regulation
Gauba placed the regulatory debate in a wider economic and geopolitical context.
He pointed to disruptions in trade routes and supply chains, as well as growing use of tariffs, export controls and investment restrictions as strategic tools.
These developments are changing the environment in which Indian businesses operate.
Technology regulation can no longer be viewed only as a domestic compliance issue.
Restrictions on semiconductor exports, data flows, AI models or critical technologies can affect supply chains, investment decisions and access to technology across countries.
Gauba argued that regulatory frameworks therefore need to adapt to both technological change and geopolitical uncertainty.
Regulation Linked to India’s 2047 Growth Ambitions
The remarks were also tied to India’s broader Viksit Bharat 2047 economic ambitions.
Gauba said sustaining high growth would require a regulatory environment that supports investment and competition while still dealing with genuine risks.
He also referred to the government’s trust-based governance and Jan Vishwas approach, which seeks to reduce unnecessary compliance burdens while retaining enforcement in areas where violations can cause significant harm.
The three-day Kautilya Economic Conclave, being held from October 3 to October 5, has brought together policymakers, economists and financial experts from around 30 countries under the theme “Resilience in an Age of Flux”.
Why This Matters for AI Regulation
Gauba did not announce a new AI law or specific regulatory framework.
His remarks instead outline a broader philosophy that could influence how India approaches emerging technologies.
For AI, a risk-proportionate model could mean stronger controls for systems used in areas such as critical infrastructure, finance or high-impact decision-making, while lower-risk applications face fewer restrictions.
The exact form of any such framework would depend on future government policy.
For companies developing or deploying AI in India, the larger message is that regulatory oversight is likely to become more sophisticated rather than simply heavier.
What this means for you
India’s regulatory direction is increasingly moving toward rules that depend on the seriousness of the risk involved rather than treating every technology or business model the same. For AI and cybersecurity companies, this could mean stricter scrutiny in high-risk uses but fewer compliance burdens where potential harm is limited.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics