← Latest papers
💻 computer science

AI and Consumer Rights in India Working Paper

This working paper evaluates India's Consumer Protection Act, 2019, as a potentially applicable but insufficient framework for AI-related consumer harms, highlighting critical gaps in proving causation and allocating liability across the complex, overlapping AI value chain.

Original authors: Omir Kumar, Sriya Sridhar, Vibhav Mithal, Balaraman Ravindran

Published 2026-08-14
📖 4 min read☕ Coffee break read

Original authors: Omir Kumar, Sriya Sridhar, Vibhav Mithal, Balaraman Ravindran

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you're walking through a bustling digital marketplace where the shopkeepers aren't just people, but clever robots, chatbots, and invisible algorithms. These digital helpers are everywhere, from the apps on your phone to the systems that decide if you get a loan. But what happens when one of these digital helpers trips up? What if a chatbot gives you terrible medical advice, or an AI coding tool accidentally deletes your family's entire photo album? This is the world of Artificial Intelligence (AI) and Consumer Rights.

To understand the problem, we need to know two things. First, AI is like a super-smart student that learns from a massive library of data to make decisions or create things. Sometimes, this student makes mistakes, gets confused, or even learns bad habits from the books it read. Second, Consumer Rights are the rules that protect you when you buy something. If you buy a toaster that catches fire, the law says the company that made it or sold it must fix the mess. But AI isn't a simple toaster; it's a complex team effort involving data collectors, code writers, and app builders. The big question is: when a digital mistake hurts you, who do you blame? Is it the robot, the person who built the robot, or the person who just pressed the button?

This working paper by Omir Kumar, Sriya Sridhar, Vibhav Mithal, and Balaraman Ravindran from the Centre for Responsible AI at IIT Madras dives into this exact puzzle. They look at India's Consumer Protection Act, 2019, which is the rulebook for protecting shoppers. The authors ask: Does this old rulebook fit the new, weird world of AI?

The paper suggests that the Act is actually quite flexible. It defines "harm" broadly, covering not just broken bones or lost money, but also mental stress and emotional distress. It also defines "deficiency" as any fault or negligence in a service. Because these definitions are so wide, the authors argue that the Act could technically cover AI disasters. For example, if a chatbot encourages someone to do something harmful, or if an autonomous car ignores your instructions, these could be seen as "defective products" or "deficient services" under the law. However, the paper notes a specific limitation: the Act explicitly excludes services rendered free of charge. This means incidents occurring while using free AI-based applications may fall outside the scope of these protections, creating a potential gap for many users.

However, the paper points out that while the law can cover these cases, it's not a perfect fit yet. The biggest hurdle is proving causation. In a normal shop, if a shoe breaks your toe, it's easy to see the shoe caused the pain. But with AI, the "defect" might be hidden deep inside the code, or it might be a result of how the AI was trained on bad data. Proving exactly which part of the AI chain caused the harm is like trying to find a single specific grain of sand that caused a beach to collapse.

The authors also highlight a major confusion about who is responsible. The law currently divides people into three groups: Manufacturers (who make the product), Sellers (who sell it), and Service Providers (who use it to help you). But the AI world is messy. A single AI system might involve a data company, a model developer, a fine-tuner, and a deployer. These roles overlap and blur together. The paper suggests that while the law might stretch to cover all these players, it doesn't have a clear way to decide how much blame each one should take. Should the data provider be blamed for bad training data, or the company that used the AI? The current framework doesn't give a clear answer.

The paper concludes that while India's Consumer Protection Act is a good starting point and likely covers AI harms, it needs some tuning. The authors suggest that enforcement agencies need more technical training to understand how AI works, and they need to clarify how liability is shared among the many players in the AI value chain. Until then, if an AI messes up, figuring out who pays the bill might still be a bit of a guessing game. The paper doesn't claim the law is broken, but it does suggest that without clearer rules on how to split the blame, consumers might struggle to get the justice they deserve.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →