The Hidden Legal Crisis Behind India's Autonomous Vehicle Boom
Heart of India's AV Sector
Here is what makes India's situation genuinely unusual among major economies: testing autonomous vehicles on Indian roads is technically legal, but the minister responsible for road transport has repeatedly and publicly stated that driverless cars will not be permitted.
The Motor Vehicles (Amendment) Act, 2019 explicitly permitted AV testing, which was the first statutory acknowledgment that autonomous navigation technology exists in India. Startups moved fast. Minus Zero unveiled what it claimed was India's first autonomous vehicle ride in June 2023. Swaayatt Robots, founded by IIT Roorkee researcher Sanjeev Sharma, has conducted over 80 demonstrations navigating unmarked streets, toll plazas and chaotic urban traffic. The company raised USD 4 million in 2024 at a valuation of USD 151 million. Flux Auto is operating autonomous trucks in industrial zones. Flo Mobility is running driverless campus shuttles.
Meanwhile, Union Minister Nitin Gadkari has stated on multiple occasions from 2017 to 2025 that driverless cars will not be permitted in India. His reason: the technology would displace an estimated 70 to 80 lakh drivers employed in the transport sector. At the Zero Mile Samvad hosted by IIM Nagpur in December 2023, he linked his opposition directly to India's youth unemployment challenge, where the 15 to 29 age group faced roughly 10% unemployment in 2022 to 2023.
The legal status of these statements? Unclear. A minister's public declaration does not carry the force of law. No statutory prohibition on commercial AV deployment has been enacted. So the sector exists in a strange limbo: develop all you want, test if you like, but the government will not build you a road to market.
What Law Actually Governs Autonomous Vehicles Today
Four statutes form the patchwork framework currently applied to AVs in India. None of them was designed for this purpose.
The Motor Vehicles Act, 1988 is the primary legislation. It defines a "driver" as the person actually steering the vehicle. Every provision on liability, negligence and penalty flows from this assumption of human agency. Section 184 criminalises dangerous driving. Section 185 addresses driving under the influence. Section 112 regulates speed limits. Each of these provisions presupposes a human making real-time decisions. They cannot, without amendment, be applied to an algorithm behind the wheel.
The Consumer Protection Act, 2019 offers a residual remedy when an AV defect causes injury, since a faulty autonomous system could be characterised as a "defective product." But the CPA was designed for straightforward consumer-seller relationships. It cannot apportion liability across the chain that an AV incident actually involves: vehicle manufacturer, software developer, sensor hardware supplier, cloud services provider, telecom network operator. The conceptual mismatch is significant.
The Digital Personal Data Protection Act, 2023 (DPDPA) is the most consequential recent development for AV operators. A single autonomous vehicle generates approximately four terabytes of data per day through cameras, LIDAR, radar, ultrasonic sensors and GPS. Under the DPDPA, any entity collecting a passenger's location history, voice commands or biometric presence is a "data fiduciary" required to obtain free, specific and informed consent before processing that data. Penalties for security failures can reach Rs 250 crore. The DPDPA Rules 2025, notified in November 2025, set a compliance timeline running through May 2027, meaning AV operators need to be building consent architecture into their platforms now.
The Information Technology Act, 2000 covers cybersecurity at a general level but was drafted before vehicular cybersecurity was a recognised category of risk. A cyberattack on an AV's communication system that causes a physical accident sits in a legal grey zone this legislation was never designed to address.
The Liability Vacuum: The Most Dangerous Gap
The most structurally consequential failure in India's AV framework is the complete absence of a tortious liability regime for accidents involving autonomous vehicles. And this is not a theoretical problem. It is a practical disaster waiting to happen.
Under the Motor Vehicles Act, when an accident occurs, the tortfeasor is typically the driver. Fault is determined through the Motor Accidents Claims Tribunal (MACT) system. Compensation is calculated under Sections 163A and 166 of the MVA.
Now consider an AV accident caused by a sensor malfunction. Or an algorithmic error. Or a cyberattack. Or inadequate road signage the AV's training data did not anticipate. In each case, a different legal person bears moral and causal responsibility, and existing doctrine does not clearly allocate legal responsibility among them.
As the law currently stands, liability would likely default to the registered owner of the vehicle. Even if that person was a passenger with zero ability to intervene in an algorithmic failure.
This outcome is not just legally unsatisfying. It is manifestly unjust.
Other jurisdictions have moved to fix this. The UK's Automated Vehicles Act, 2024 places primary liability for accidents during self-driving mode on the manufacturer or "authorised self-driving entity" rather than the user. Germany amended its Road Traffic Act in 2017 to permit Level 3 AVs under specific conditions, requiring a remote "technical supervisor" capable of overriding the vehicle. India has adopted neither model. It has adopted nothing.
The Constitutional Stakes
Two constitutional provisions make India's regulatory vacuum more than a policy inconvenience. They make it a potential rights violation.
Article 21, which guarantees the right to life and personal liberty, has been interpreted by the Supreme Court to include the right to a safe environment and the right to health. Deploying AVs without adequate safety certification standards would be directly challengeable under Article 21. The State's positive obligation to protect life extends to technologies that operate in public spaces and carry the capacity to cause physical harm.
The right to privacy, recognised as a fundamental right under Article 21 by the Supreme Court's landmark nine-judge bench decision in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), is directly engaged by AV operation. A vehicle that continuously monitors your location, movements, voice and biometric data is not a passive machine. Any regulatory framework that fails to incorporate rigorous consent mechanisms and data minimisation standards would face serious constitutional challenge.
India's federal structure adds another layer of complexity. The Seventh Schedule places motor vehicles on the concurrent list, meaning both Parliament and state legislatures can legislate on the subject. State-level divergence is not hypothetical. West Bengal refused to implement the 2019 Amendment's enhanced penalty provisions, citing encroachment on state powers. A patchwork of state-level AV rules, should they emerge in the absence of central legislation, would create regulatory fragmentation that makes compliance for manufacturers effectively impossible.
What a Functional Framework Actually Needs
Drawing on comparative frameworks from the UK, Germany and the UNECE's Working Party on Automated and Connected Vehicles (WP.29), a minimally adequate Indian AV framework needs to address five distinct areas.
Tiered liability allocation. At SAE Level 3 and above, where the system and not the driver is making real-time decisions, primary liability must rest with the manufacturer or the entity that certified the software. Not with the registered owner. Not with the passenger. This is not a radical position. It is what both the UK and Germany have concluded.
Mandatory certification standards. ARAI (Automotive Research Association of India), already co-developing India's first indigenous AV prototype with Cognizant Technologies, is the natural certification authority. But its mandate needs formal expansion to cover AV-specific criteria: obstacle detection performance, traffic sign recognition, adverse weather operation, emergency vehicle response.
AV-specific insurance architecture. The current third-party liability insurance requirement is designed for human drivers. An AV liability regime should place a product liability insurance obligation on manufacturers and software developers, not just vehicle owners, reflecting where the actual decision-making and risk originate.
Data governance specific to AVs. The DPDPA provides a general framework for personal data but does not address operational telemetry, non-personal data or the specific cybersecurity standards AV systems must meet. India's broader posture on data localisation, reflected in the DPDPA's cross-border transfer restrictions and the RBI's payment data framework, strongly suggests that AV regulation will eventually need to specify where operational data is stored and who can access geospatial data collected across Indian cities.
A resolution of jurisdictional fragmentation. Central legislation with clear preemption of state-level variation in testing and deployment rules, or a formal division of authority that prevents regulatory patchwork, is essential before commercial deployment can be responsibly contemplated.
The Opportunity Cost of Inaction
India is a signatory to the 1968 Vienna Convention on Road Traffic, amended to explicitly permit automated driving technologies. The UNECE's WP.29 has developed international safety standards that form the technical baseline for AV regulation in jurisdictions that are moving ahead. Alignment with these standards would allow Indian-manufactured AVs to access export markets that require WP.29 compliance. It would also provide a technically grounded certification baseline for India's domestic framework.
The absence of that framework means foreign AV manufacturers face not just a missing deployment pathway. They face the absence of the type of technical harmonisation that would allow certifications from other jurisdictions to carry any weight in India.
Meanwhile, Swaayatt is demonstrating. Minus Zero is testing. Flux Auto is trucking. Flo Mobility is shuttling. The technology is not waiting.
The Bottom Line
India's autonomous vehicle sector exists in a condition of productive but legally precarious activity. The 2019 Amendment created a testing right. Companies have built on it. But the liability framework, the deployment pathway, the certification architecture and the data governance regime remain either absent or underdeveloped.
A minister's policy position, however sincerely held and politically understandable, is not a substitute for statute. And a statute designed in 1988 around a human driver is not a framework for a vehicle that drives itself.
The question is no longer whether autonomous vehicles will eventually operate on Indian roads. The commercial pressures, the demographic logic and the technological momentum are all pointing in one direction. The question is whether India will arrive at that point with a legal framework capable of governing it, or whether accident victims, developers and investors will continue operating in the space between a permissive testing provision and a minister's repeated objections.
The law needs to catch up. Before the technology catches someone off guard.
References: Motor Vehicles Act, 1988; Motor Vehicles (Amendment) Act, 2019; Consumer Protection Act, 2019; Digital Personal Data Protection Act, 2023; DPDPA Rules, 2025; IT Act, 2000; Justice K.S. Puttaswamy (Retd.) v. Union of India (2017); UK Automated Vehicles Act, 2024; UK Automated and Electric Vehicles Act, 2018; Germany Road Traffic Act (Amendment, 2017); Vienna Convention on Road Traffic, 1968 (amended); UNECE WP.29 standards; SAE International Automation Levels taxonomy.