Somewhere in India this evening, a child too young to legally sign a contract is confiding in a chatbot. Not asking it homework questions, but talking to it about loneliness, about a fight at school, about feelings an eleven-year-old rarely voices to an adult. The chatbot listens patiently, responds warmly, and remembers nothing of the legal architecture built to protect that child, because that architecture was not designed with this relationship in mind. This is the quiet frontier of India's next digital rights debate, and it is arriving faster than our institutions are prepared to answer it.
For a decade, India's child-safety conversation online was framed almost entirely around content: pornography, cyberbullying, predatory contact, data harvesting for targeted advertisement. These remain real and serious harms, and the legal system has built, however imperfectly, a response to them the POCSO Act's provisions on child sexual abuse material, the IT Act's takedown obligations, and now the Digital Personal Data Protection Act, 2023, which requires verifiable parental consent before processing a child's personal data and bars behavioural tracking and targeted advertising directed at minors. But generative AI has introduced a category of harm that content-based regulation was never built to catch: relationship-based harm, where the risk lies not in what a child is shown, but in what a system persuades a child to believe, feel, or depend upon.
Companion chatbots designed for engagement, not welfare, can cultivate emotional attachment in exactly the demographic least equipped to recognise it as engineered. UNICEF's own guidance on AI and children has flagged emotional dependency on companion chatbots and AI-generated disinformation as genuinely novel risks distinct from, and in some ways harder to regulate than, the older harms of explicit content or online predators, because there is no obscene image to take down and no predator to name. The harm is diffuse, cumulative, and built into the product's design incentives.
The regulatory scaffolding exists but wasn't built for this
To be fair to policymakers, India is not starting from zero. The DPDPA's parental-consent and no-targeted-advertising provisions for children are among the more protective in comparative data law. The IT Rules amendments moving through 2026 add labelling requirements for AI-generated content and faster takedown timelines. States have begun legislating too Karnataka's draft Responsible social media and Digital Safety Bill, currently before the legislature's law department, proposes mandatory labelling of AI-generated content and platform action within 24-48 hours on harmful material. At the Centre, India's AI Governance Guidelines articulate child welfare as a design principle, and a private member's Bill in the Lok Sabha has floated mandatory ethical review for high-risk AI systems.
The trouble is that nearly all of this scaffolding is content-and-consent architecture, adapted from an internet-safety paradigm built for static websites and social media feeds. Verifiable parental consent assumes a threshold moment sign-up after which the relationship is presumed safe unless specific harmful content appears. But a companion AI's risk profile does not announce itself at sign-up. It accumulates over months of conversation, through a system optimised to maximise engagement by mirroring the child's emotional needs back at them. No consent form, however well-drafted, anticipates that.
What other jurisdictions are attempting, and why India cannot simply import them
France's approach debated recently at a New Delhi forum bringing together Indian and French policymakers has leaned toward hard age gates: barring under-15s from social platforms outright and redesigning algorithmic defaults around parental consent rather than a one-time click-through. It is a blunt instrument, and one India's own digital-inclusion realities complicate considerably. A hard age-verification regime assumes reliable identity infrastructure reaching every child uniformly, when in fact large sections of India's young population access AI-enabled devices through shared family phones, cybercafes, or school-provided tablets, where the very idea of a single verifiable “user” breaks down. Any Indian regulatory response modelled uncritically on European age-gating risks either being unenforceable at scale or, worse, becoming another documentation burden that formal, urban, digitally fluent families can navigate while rural and lower-income children are pushed toward unregulated, unlabelled alternatives precisely the exclusionary pattern India's digital governance has struggled with before.
Three things India's legal response actually needs
First, the DPDPA's child-consent framework needs an explicit AI-interaction layer, distinguishing static data collection from ongoing, adaptive, relationship-simulating systems, and imposing design obligations not just consent obligations on products marketed to or predictably used by minors. A consent checkbox cannot substitute for a duty to design conversational AI that recognises signs of distress and routes a child toward a human, rather than deeper into the product.
Second, the accountability gap between platform and model developer needs closing. Current intermediary-liability thinking, inherited from the social-media era, assigns responsibility to the platform hosting content. But a companion chatbot's harmful output is generated, not hosted the developer of the underlying model bears a design responsibility that existing IT Rules categories do not clearly capture, and India's evolving AI governance framework should say so explicitly rather than leaving it to be litigated after harm occurs.
Third, and most urgently, this cannot remain a Centre-versus-States patchwork. Karnataka's Bill and the Centre's guidelines are moving on separate tracks, with no guarantee of interoperable definitions of “AI-generated content” or “child user.” A child's protection should not depend on which State's server logs the interaction.
A narrow window
India has an unusual advantage here: it is legislating on children and AI before, not after, a defining scandal forces its hand, as social media regulation so often was. That window will not stay open. The DPDPA's child provisions, the IT Rules amendments, and the AI Governance Guidelines were each meaningful steps when drafted but each was substantially settled before companion AI became a mainstream part of a child's daily emotional life. Closing the gap between what these frameworks assume about a “child user” and what a child actually now does with AI is not a technical footnote. It is the next real test of whether India's digital rights architecture protects the people least able to protect themselves within it.
Author is an Assistant Professor at School of Law CHRIST (Deemed to be University), Delhi NCR Campus. Views are personal.