Amrita Sinha


Who Is Responsible When AI Gives Wrong Information

23 August 2026

A tax tribunal in Bengaluru recalled an order worth roughly ₹669 crore after it emerged that four of the authorities it rested on did not exist. The Bombay High Court quashed an assessment of nearly ₹28 crore that had been built on three invented precedents. Neither the tribunal nor the High Court had been deceived by a forger. They had been handed citations produced by a language model, and nobody had checked them.1

In July this year, in Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd., 2026 INSC 668, the Supreme Court said what was going to happen next. Citing a fake or hallucinated precedent without verifying it is misconduct on the part of an advocate. An order resting on such material is a nullity. A judge who relies on one commits a serious lapse. The Court asked the Bar Council of India to constitute a committee.2

So the question that gets asked at every seminar (who is responsible when artificial intelligence gives wrong information) is not open in India. It has been answered. What has not been noticed is that the answer runs in one direction only, and stops well short of the machine.

What the answer covers

Read the Supreme Court's direction carefully and you will see that every person it touches is a human being at the end of the chain. The advocate who filed the citation. The judge who accepted it. The disciplinary machinery under the Advocates Act, 1961 that will now deal with the first.

This is not a criticism of the ruling. On its own terms it is plainly right. An advocate owes a duty of candour to the court, and that duty has never depended on where the false statement came from. If you would be answerable for citing a case a junior invented, you are answerable for citing one a machine invented. The tool is new; the obligation is not.

But notice what the ruling does not do, because it was never asked to. It says nothing about the company whose product composed the citation. It could not. That company was not before the Court, and no Indian statute clearly tells us what its position is.

The definition everything turns on

The instinct is to reach for the safe harbour in section 79 of the Information Technology Act, 2000. That is the provision which protects platforms from liability for what their users post. To reach it, you must first be an intermediary. Section 2(1)(w) defines that word as any person who, on behalf of another person, receives, stores or transmits a record, or provides any service with respect to that record.3

Those five words are doing an enormous amount of work, and they were written in 2000 for a machine that carried other people's messages. An internet service provider transmits a record somebody else composed. A marketplace stores a listing somebody else uploaded. A social platform displays a post somebody else wrote. In each case there is an author, and the intermediary is not it.

The machinery of section 79 assumes exactly that. In Shreya Singhal v. Union of India, 2015 INSC 257, the Supreme Court read down section 79(3)(b) so that an intermediary loses the protection only on receiving actual knowledge through a court order, or on being notified by the appropriate government agency, and is then required to take the material down. The entire mechanism presupposes something that can be taken down, put there by somebody else. There is nothing to take down when the sentence was composed on request and has never existed anywhere before.

When a model produces the sentence Sharma v. State of Maharashtra, and no such case exists, on whose behalf is it acting? Not the user's; the user asked a question and got an answer he did not write and could not have predicted. Not any third party's; there is no third party. The sentence has no author in the sense the Act contemplates. It is not being carried. It is being made.

That should mean the safe harbour does not apply. Read plainly, that leaves the provider more exposed than a platform, not less. The protection of section 79 is the price the law pays for treating someone as a conduit. A system that composes is not a conduit, and should not get the conduit's immunity.

Asked about this in Parliament in July, the Government's answer was that whether a given AI service is an intermediary, and whether section 79 protects it, depends on the nature of the service and the functions it performs.4 That is not wrong. It is simply not an answer. It means the question will be settled case by case, some years from now, by whichever litigant can afford to take it far enough. In the meantime the uncertainty itself operates as a kind of immunity, because no one wants to be the test case.

The rules that arrived, and what they left out

India did legislate on artificial intelligence this year. In February the Ministry of Electronics and Information Technology amended the Intermediary Guidelines to bring synthetically generated information within the due diligence framework: mandatory labelling and provenance metadata for synthetic content, and a takedown window for flagged unlawful material cut from thirty-six hours to three.5

Read what that regulates. The definition is built around content generated or altered algorithmically so as to appear real: the fabricated face, the cloned voice, the video of an event that never happened. It is a deepfake regime, and as a deepfake regime it is a serious piece of work.

It is not a regime about false statements. A hallucinated citation is not a synthetic likeness of anything. It does not imitate a real person or a real event; it asserts a proposition that happens to be untrue, in the same typeface as every true proposition around it. Labelling would not have saved the Bengaluru tribunal, because everyone already knew the text came from a machine. What nobody knew was that it was wrong.

We have regulated the fake face and left the fake sentence alone. That is an understandable order of priorities: the deepfake harms are vivid and the political pressure was real. But it means the specific failure now costing Indian litigants crores sits outside the only AI-specific rules we have.

What the ordinary law would say, if asked

None of this means there is no law. It means there is no special law, and the general law has not yet been pointed at the problem.

A Canadian tribunal has already done the pointing. In Moffatt v. Air Canada, a passenger relied on an airline chatbot's assurance that he could apply for a bereavement fare after travelling. The airline's defence was that the chatbot was a separate entity responsible for its own statements. The tribunal rejected this in a sentence that ought to be quoted more often in India: the chatbot was part of the airline's website, and the airline was responsible for the information on its website however that information was produced.6

The reasoning transfers. A deployer who puts a model in front of the public and invites reliance on what it says is making a representation. If the representation is false and reliance was foreseeable, the ordinary law of negligent misstatement is available. Where the user is a consumer, the Consumer Protection Act, 2019 supplies deficiency in service without needing any of this to be resolved first.

Which leaves the disclaimer. Every such service is supplied on terms saying outputs may be inaccurate and must be independently verified. Those clauses will decide most disputes before any court sees them, and they are not obviously unassailable. Indian law has never accepted that a term in a standard-form contract is enforceable merely because it was accepted; where bargaining power is absent, an unreasonable exclusion can be struck down.7 Nobody negotiates the terms of service of a language model. Whether a clause disclaiming all responsibility for accuracy survives that scrutiny, in a product sold precisely for the accuracy of its answers, is a question no Indian court has been asked.

The asymmetry

Put the two ends of the chain beside each other.

At one end is an advocate. She is now on notice that repeating an unverified output is professional misconduct, with the disciplinary consequences that attach to that word. Her liability is personal, immediate and non-delegable.

At the other is the company that produced the sentence. It has a contractual disclaimer, an unresolved question about whether it is an intermediary at all, a set of AI rules aimed at a different harm, and no Indian judgment against it.

What is uncomfortable about this distribution is not that the advocate is liable. She should be. It is that responsibility has landed almost entirely on the party least able to prevent the error. She can only check the output after it exists, one citation at a time. The people who chose the training data, set the guardrails, decided how confidently the system would assert things it had no basis for, and whether it would say I do not know: they made the decisions that determine how often there is anything to catch. They are, at present, the only participants with no legal exposure at all.

This is what happens when responsibility is not allocated but allowed to settle. It does not settle where it will do the most good. It settles on whoever is standing closest to the harm when it lands.

What would actually help

Not, I think, a new statute about artificial intelligence. Three narrower things.

The first is to answer the intermediary question instead of deferring it. If a system generates rather than transmits, say so, and say that section 79 does not reach it. The Government's function-based test is defensible in principle but it converts a question of law into years of litigation, and uncertainty is never neutral; it favours whoever can afford to wait.

The second is to stop treating accuracy as an ordinary contractual term where a product is sold for professional use. A model marketed to advocates for legal research is being sold for the reliability of its answers. A clause disclaiming that entirely is disclaiming the thing purchased.

The third is the least glamorous and would do the most. Verification is currently manual, invisible and unenforced. If a system used in professional practice were required to distinguish what it has retrieved from a real source from what it has composed (not a label saying this is AI-generated, which everyone already knows, but a link to the judgment or an admission that there is none), most of these cases would not arise. The Bengaluru tribunal did not need to be told the text came from a machine. It needed to be told that four of the four citations led nowhere.

Until something of that kind exists, the position is the one the Supreme Court has correctly stated and nobody should mistake for the whole of it: if you repeat what the machine told you, you own it. The machine's owner does not. Somewhere in that gap sits a sentence that decided a ₹669 crore matter, and no person in Indian law wrote it.

Filed under Cyber Law

  1. Both incidents are among those collected in MediaNama's survey of AI hallucination cases in Indian courts, July 2026. Figures are as reported. ↩
  2. Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd., 2026 INSC 668. The judgment itself is linked above. No summary of it, including this one, is a substitute for reading it. The Court had signalled the same position earlier in the year. Readers relying on this should take the judgment from the reported text rather than from any summary, including this one. ↩
  3. Information Technology Act, 2000, s. 2(1)(w): an intermediary, with respect to any particular electronic record, is “any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record”. The section then lists examples: telecom providers, network service providers, search engines, online marketplaces. Every one of them handles material composed by someone else. ↩
  4. The Ministry of Electronics and Information Technology's position, given in July 2026, is that whether an AI system falls within s. 2(1)(w) and is eligible for the s. 79 exemption depends on the nature of the service, the functions performed, and the applicable provisions. Reported by MediaNama. ↩
  5. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, notified 10 February 2026 and effective 20 February 2026. See the summaries by Freshfields and RNA. Commentaries differ on how far the labelling obligation extends to text as distinct from audio-visual material; the definition of synthetically generated information is framed around content made to appear real. The point made here does not depend on resolving that: labelling identifies origin, not falsity. ↩
  6. Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal, February 2024). Discussed by the American Bar Association. A small-claims decision of a Canadian tribunal binds nothing in India; it is cited for the reasoning, which is transferable, and not as authority. ↩
  7. The principle is long established in Indian contract law. See Central Inland Water Transport Corporation v. Brojo Nath Ganguly, 1986 INSC 66, and LIC of India v. Consumer Education & Research Centre, 1995 INSC 367, on unfair terms in contracts between parties of unequal bargaining power. The Consumer Protection Act, 2019 also now addresses unfair contract terms directly. ↩