TL;DR: India’s AI Governance Guidelines (2025) position trust, accountability, and human-centric design as the operating model for AI adoption, according to Appknox, while the policy also pushes enterprises toward lifecycle traceability, explainability, and human-in-the-loop oversight. The practical issue is that governance now has to align with security controls that can prove how AI systems behave, not just what they were built to do.
NHIMG editorial — based on content published by Appknox: AI for India, built on trust: what the new AI governance guidelines mean for the future
By the numbers:
- The country already hosts over 1,500 AI-driven startups across sectors including healthcare, fintech, retail, logistics, and cybersecurity.
Questions worth separating out
Q: How should security teams use AI in access decisions without losing governance?
A: Use AI for recommendation, triage, and pattern detection first, then keep human approval for privileged, exception-heavy, or business-sensitive access.
Q: Why do AI SOC agents need machine identity governance?
A: Because they operate through API credentials, service accounts, and delegated permissions, not through a human analyst session.
Q: How do you know if trust-by-design is actually working in AI?
A: You know it is working when every critical model decision can be traced back to data sources, reviewers, policy checks, and retraining events.
Practitioner guidance
- Define AI ownership across the lifecycle Assign a named owner for each model, dataset, and AI-enabled workflow, then record who approves retraining, rollback, and production changes.
- Bind human review to high-risk AI decisions Identify outputs that can affect access, compliance, payments, or customer treatment, and require logged human review before those outputs are acted on.
- Treat AI service identities as governance assets Inventory the service accounts, API keys, and tokens used by AI systems, then apply least privilege, rotation, and access review to those identities.
What's in the full article
Appknox's full blog post covers the operational detail this post intentionally leaves for the source:
- The article’s full breakdown of the seven governance principles and six implementation pillars behind the guidelines.
- Detailed enterprise readiness tables for accountability, traceability, human review, and secure-by-design controls.
- The developer checklist covering model provenance, bias testing, and human validation workflows.
- Appknox’s discussion of AI-specific security testing for APIs, SDKs, and integrated model interfaces.
👉 Read Appknox’s analysis of India’s AI governance guidelines and trust-by-design controls →
India’s AI governance guidelines: what changes for security teams?
Explore further
India’s AI governance direction confirms that trust is now a control objective, not a policy slogan. The article shows a model built around accountability, explainability, and human oversight rather than compliance theatre. That matters because AI programmes now need controls that can prove behaviour across the full lifecycle, from data ingestion to retraining. For identity and security teams, this is a governance pattern that mirrors how access should be managed in high-risk environments.
A question worth separating out:
Q: Which control matters most for high-risk AI systems?
A: Human oversight matters, but only when it is backed by accurate inventory, data traceability, and enforceable documentation. If the system cannot be classified correctly or its data flows cannot be explained, oversight becomes ceremonial. Practitioners should treat traceability as the control that makes every other requirement testable.
👉 Read our full editorial: India’s AI governance guidelines frame trust as a security control