Skip to Content

Vibe Coding and Legal Challenges in India: A Comprehensive Guide (2026)

By December 2025, Collins English Dictionary had named vibe coding the Word of the Year. That is not a small thing. That is the dictionary telling you that a technical term coined by one AI researcher crossed over into the mainstream vocabulary of an entire civilization within a single calendar year.

But here is what nobody at the Collins ceremony talked about: the legal wreckage that follows when you ship code nobody wrote, nobody reviewed, nobody truly understands, and nobody knows who owns.

The Scale of What Is Happening

Before getting to law, it is worth understanding the sheer scale of what vibe coding has produced in a very short time. These are not projections or guesses. They come from documented industry data.

In 2024, AI-generated code accounted for 41 percent of all new code written globally. That translates to roughly 256 billion lines of code. At Amazon, approximately 30 percent of code going into production is now AI-generated. The same figure holds roughly at Google and Microsoft. Meta has announced ambitions to reach 50 percent within this decade.

In Y Combinator's Winter 2025 batch, 25 percent of startups had codebases that were 95 percent AI-generated. More striking: 44 percent of non-technical founders now build their first product prototype using AI coding tools rather than hiring a developer.

In India, the scale is just as dramatic. The country has over 5 million software developers, a startup ecosystem that ranks third globally, and a freelance developer market that feeds into projects across North America, Europe, Southeast Asia, and the Middle East. Platforms like GitHub Copilot, Cursor, Claude, Replit, and ChatGPT Code Interpreter are now part of the daily workflow of developers in Bengaluru, Hyderabad, Pune, Chennai, and every tier-two city with a decent internet connection.

The productivity argument is compelling. A solo developer using vibe coding tools can now do what previously required a team. A non-technical founder can ship a working MVP in days. An Indian freelancer can take on contracts that would previously have required subcontracting. The economic logic is irresistible.

The legal logic is a minefield.

 

The Security Problem Nobody Wants to Talk About

The law follows harm. And before understanding India's legal challenges with vibe coding, you need to understand what AI-generated code actually looks like in terms of quality and security, because it is the quality failures that create the legal liability.

The Veracode 2025 GenAI Code Security Report is one of the most comprehensive studies done on this question to date. Researchers analyzed over 100 large language models across 80 distinct coding tasks. Their finding: 45 percent of all AI-generated code introduces security vulnerabilities. These are not cosmetic issues. Many are critical flaws that appear on the OWASP Top 10, which is the authoritative list of the most dangerous web application security risks in existence.

In December 2025, a security startup called Tenzai ran a controlled test across five of the most widely used vibe coding tools, namely Claude Code, OpenAI Codex, Cursor, Replit, and Devin. They gave each tool identical prompts to build three standard applications. Across 15 applications produced, the tools collectively generated 69 vulnerabilities, with approximately six rated as critical severity. The researchers specifically called out that AI agents are "very prone to business logic vulnerabilities" because they lack the intuitive understanding that human developers use to reason about how a workflow should actually operate in the real world.

CodeRabbit published an analysis in December 2025 of 470 open-source GitHub pull requests where AI had co-authored the code. The AI-authored pull requests contained 1.7 times more major issues than human-written ones. Security vulnerabilities appeared at 2.74 times the rate. Logic errors were 75 percent more common.

Wiz, the cloud security company, found that 20 percent of vibe-coded applications deployed in production environments contained serious vulnerabilities or configuration errors.

Then there is the Enrichlead story, which became a cautionary tale across developer Twitter and LinkedIn. The founder of this startup publicly posted that 100 percent of the platform's code was written by Cursor with zero human-written lines. Within days of launch, security researchers discovered the platform had elementary flaws allowing anyone to access paid features without paying and exposing backend data to unauthorized parties. The founder had no way to fix it quickly because he did not understand the code the AI had generated. He could not debug what he had never written.

Apiiro, which monitors code security for Fortune 50 enterprises, tracked a 10-fold increase in security findings per month between December 2024 and June 2025, from roughly 1,000 findings monthly to over 10,000, directly attributable to the acceleration of AI-generated code deployment.

These numbers matter for law because Indian statutes on cybersecurity, consumer protection, data privacy, and contractual liability all trace back to a simple question: was the harm caused by negligence? When 45 percent of AI-generated code contains vulnerabilities and a developer deploys that code without review, the negligence argument writes itself.

 

The First Real Indian Court Battle: ANI vs OpenAI

The most consequential AI legal case currently active in India is not about vibe coding specifically, but it will determine the rules that vibe coders live under. ANI Media Private Limited, the wire news agency, filed CS(COMM) 1028/2024 before the Delhi High Court in November 2024. ANI is suing OpenAI for copyright infringement, alleging that ChatGPT was trained on ANI's news articles, including content behind paywalls, without permission and without compensation.

The Delhi High Court, in its order dated 19 November 2024, recognised that this case raised questions of profound legal novelty for India. The court framed four specific questions for deliberation. First, whether storing ANI's copyrighted content to train ChatGPT constitutes infringement under the Copyright Act of 1957. Second, whether generating responses from that trained model constitutes a separate act of infringement. Third, whether the defense of fair use under Section 52 of the Copyright Act is available to OpenAI for commercial-scale AI training. Fourth, whether Indian courts have territorial jurisdiction at all when the servers are in the United States.

OpenAI responded by raising the jurisdiction objection immediately and by noting that it had already blocklisted ANI's domain in October 2024 to prevent further training on that content. The court recorded this and continued proceedings.

By early 2025, the Federation of Indian Publishers applied to join as intervenors. The Digital News Publishers Association filed its own intervention application. As of mid-2025, hearings were still ongoing with no final verdict.

The reason vibe coders should follow this case is simple. If the court finds that using copyrighted content to train AI without permission is infringement, then the models powering the very tools developers use are legally tainted under Indian law. Every output those models produce in India could carry a copyright question mark. The code your Cursor session generates, if it draws on training data the court considers improperly obtained, sits on uncertain legal ground.

The DPIIT clarified in mid-2024 that it would not extend a blanket fair use defense under Section 52 of the Copyright Act to commercial AI training. The ministry also constituted an eight-member expert panel in May 2025 to evaluate whether the Copyright Act needs amendment to create a dedicated chapter on AI-generated works. That panel is ongoing. It may produce a new Chapter XII-A addressing authorship, licensing for training data, and ownership of AI outputs.

Until it does, the ownership question for AI-generated code in India is genuinely unresolved.

The Supreme Court's standard for copyright protection in India comes from Eastern Book Company v. D.B. Modak, reported at (2008) 1 SCC 1. The court held that a work must reflect the exercise of skill and judgment to qualify for copyright protection. Whether a vibe-coded program, generated from a natural language prompt with minimal human creative input, satisfies that standard is an open question. The parallel international precedent from Thaler v. Perlmutter in the United States, affirmed by the DC Circuit in March 2025, held clearly that human authorship is essential to a valid copyright claim. Indian courts reasoning from Eastern Book Company would likely reach the same conclusion.

The Arijit Singh Ruling and What It Signals for AI Applications

On 26 July 2024, the Bombay High Court delivered a ruling that the Indian AI industry cannot ignore. In COM IPR Suit (L) No. 23443 of 2024, Arijit Singh, the singer with 138.5 million Spotify listeners as of early 2025 making him one of the most-streamed artists globally, sued multiple defendants for using AI voice-cloning tools to replicate his voice without consent. The defendants were creating fake songs, merchandise, GIF platforms, and even operating domain names using his name to extract commercial value from his identity.

Justice R.I. Chagla, writing the judgment, said that what shocked the conscience of the court was the manner in which celebrities and performers were vulnerable to being targeted by unauthorized generative AI content.

The court issued an ex-parte ad-interim injunction with dynamic scope, meaning it automatically extends to mirror websites and future infringing parties without requiring the plaintiff to come back to court each time. The protection covers his name, voice, vocal style, vocal technique, vocal arrangements, mannerisms, photographs, likeness, signature, and persona. It extends across physical media, digital platforms, the metaverse, deepfake technology, AI voice conversion tools, and synthesized voice applications.

This ruling did not confine itself to celebrities. The principle it articulated is threefold: the person must be a celebrity, the unauthorized use must allow identification of that person, and the use must be for commercial gain. The commercial gain threshold is not especially high. An app with even modest monetization that uses a real person's replicated voice or likeness to deliver its service could meet it.

In November 2024, the Delhi High Court applied identical reasoning in Dr. Devi Prasad Shetty v. Medicine Me and Others, reported as CS(COMM) 1053/2024. Dr. Shetty, the cardiac surgeon who founded Narayana Health, obtained injunctive relief against Facebook pages that were using AI-generated deepfake videos of him to promote unauthorized medical products and drive traffic to fraudulent websites.

For a vibe coder building a health advisory app, an AI tutor that speaks in the voice of a known educator, a dubbing platform, an AI customer service avatar modeled on a celebrity, or any application that incorporates identifiable real human attributes generated by AI without consent, these two cases define the legal exposure. The Bombay High Court moved fast, issued broad relief, and sent a clear message that Indian courts will not wait for Parliament to legislate before protecting individuals from AI-powered personality exploitation.

 

DPDPA 2023 and the Rules That Changed Everything in Late 2025

The Digital Personal Data Protection Act of 2023 became substantially operational when MeitY notified the DPDP Rules in November 2025. Full compliance obligations attach 18 months from that notification, placing the hard deadline at 13 May 2027. But regulators and the government have already signaled active attention to violations, and enforcement warnings have accompanied the rules rollout.

For a vibe coder, the DPDPA creates risks at two distinct stages of the development process.

The first risk is during development itself. When developers feed real user data, customer records, employee information, or sensitive business data into AI prompts to generate context-specific code, they are transferring personal data to a third-party foreign service without the data principal's knowledge or consent. Under Section 4 of the DPDPA, any entity that determines the purpose and means of processing personal data is a Data Fiduciary and is accountable for compliance regardless of whether a third-party processor handles the actual processing. The developer who pastes patient data into a Claude prompt to generate a medical records module is a Data Fiduciary. The fact that Claude processed the data does not transfer the legal accountability.

The second risk is in the application that is produced. A vibe-coded app that collects Indian user data must be DPDPA-compliant in architecture. Algorithmic processing that affects significant decisions, such as creditworthiness assessments, hiring recommendations, or health diagnoses, attracts heightened obligations around transparency and fairness. A developer who does not understand the AI-generated code cannot certify that the application meets these obligations.

The penalty structure is serious. Inadequate security safeguards leading to a data breach can attract penalties up to 250 crore rupees. Processing children's data without adequate safeguards draws similar exposure. The Data Protection Board of India, established under the Act, has investigation and adjudication powers.

To understand what enforcement looks like in practice under analogous frameworks, consider that in November 2024 the Competition Commission of India fined Meta and WhatsApp 213 crore rupees for data-sharing practices that violated competition and data norms, and that was under pre-DPDPA law. The new regime expands both the scope of covered conduct and the severity of penalties.

The constitutional foundation for all of this enforcement traces to the Supreme Court's nine-judge bench ruling in K.S. Puttaswamy v. Union of India, reported at (2017) 10 SCC 1. That judgment established that privacy is a fundamental right under Article 21 of the Constitution. Any vibe-coded application that processes personal data without lawful basis and adequate safeguards is not merely breaking a statute. It is potentially infringing a fundamental right, which Indian courts treat with corresponding seriousness.

 

The IT Act and CERT-In: When Buggy Code Becomes a Criminal Problem

The Information Technology Act of 2000 and the CERT-In Directions of April 2022 together create a framework where security failures in deployed applications carry criminal and regulatory consequences, not just civil liability.

Section 43A of the IT Act, inserted by the 2008 amendment, makes any body corporate that handles sensitive personal data liable to pay compensation if it is negligent in implementing reasonable security practices and procedures. The question Indian courts have not yet fully answered, but will eventually face, is whether deploying AI-generated code without security review constitutes negligence under this section. Given the Veracode finding that 45 percent of AI-generated code contains vulnerabilities, the argument that a developer who skips security review was negligent is straightforward.

The CERT-In Directions of 2022 require organisations to report cybersecurity incidents within six hours. This six-hour window applies from the moment of detection. A startup operating a vibe-coded platform that suffers a breach must report it to CERT-In within six hours, maintain logs for 180 days, and cooperate with investigation. Failure carries regulatory consequences.

MeitY clarified in a parliamentary session response in February 2025 that web scraping of publicly available data for AI training is regulated under Section 43 of the IT Act, which penalizes unauthorized access, downloading, and extraction of data from computer systems. This positions AI training activities within existing cybersecurity law rather than treating them as a regulatory gap.

The vulnerabilities discovered in vibe coding tools themselves in 2025 compound this picture significantly. CVE-2025-54135, named CurXecute, was a critical vulnerability in the Cursor IDE allowing arbitrary command execution on a developer's machine through a connected MCP server. CVE-2025-53109, named EscapeRoute, appeared in Anthropic's MCP file server and allowed reading and writing of arbitrary files on a developer's disk. CVE-2025-55284 allowed data exfiltration from a developer's machine through DNS requests via Claude Code. These were not theoretical attack scenarios. They were discovered, documented, assigned CVE identifiers, and publicly disclosed. For an Indian developer using these tools on a sensitive client project, exploitation of one of these vulnerabilities could result in unauthorized access to client systems, triggering Section 66 of the IT Act, not as the perpetrator but as the company whose AI-assisted development environment was the vector.

 

The GitHub Copilot Lawsuit and Open Source Exposure in India

Indian developers who use GitHub Copilot should understand the case currently before the US Ninth Circuit that originated as Doe v. GitHub. A group of programmers sued Microsoft and OpenAI alleging that Copilot was trained on their open-source code and reproduces that licensed code in its suggestions without attribution, thereby violating open-source license terms and copyright.

While the district court dismissed most claims, the Ninth Circuit granted an interlocutory appeal that is being closely watched by legal communities globally, including in India.

The reason Indian developers are directly affected is this: if Copilot or similar tools reproduce GPL-licensed code in suggestions that a vibe coder accepts and ships, the vibe coder's product may inadvertently incorporate GPL-licensed code. Under GPL terms, that requires the developer to release their own code as open-source. Under the Copyright Act of 1957 in India, failing to comply with the license terms of software whose code is incorporated into your product constitutes copyright infringement, actionable under Sections 51 and 63, with criminal liability up to three years imprisonment.

A Bengaluru SaaS startup that has spent 18 months building a proprietary product using vibe coding tools, only to discover that the AI embedded GPL code throughout their codebase, faces an impossible choice: open-source the entire product or face infringement proceedings. Neither outcome was in anyone's  business plan.

IT Outsourcing, NDAs, and the Confidentiality Problem

India's IT services industry generates over 250 billion dollars annually and employs millions of developers who work under service contracts governed by Indian law. This sector has a specific and largely unacknowledged vibe coding problem.

When Indian developers working on client projects use AI coding tools, they routinely paste client source code, business logic, database schemas, API credentials, and proprietary algorithms into AI prompts to get useful, context-specific code. This is not malicious. It is the natural and intuitive way to use these tools effectively. But it creates a serious legal problem.

Most software service contracts contain three relevant provisions. First, a prohibition on sharing client code or proprietary information with third parties without written consent. Second, an NDA covering all client information encountered during the engagement. Third, an IP assignment clause vesting ownership of all code produced during the engagement in the client.

When a developer pastes client code into Claude or Cursor, they are transmitting that code to servers operated by a US-based company, outside the client's jurisdiction and control. Under the Indian Contract Act of 1872, this constitutes sharing information with a third party. If the contract prohibits this, it is a breach. If an NDA covers the information, it is a violation. Section 72A of the IT Act treats disclosure of information in breach of a lawful contract as a criminal offense carrying imprisonment up to three years and a fine up to five lakh rupees.

The Specific Relief Act of 1963 allows aggrieved clients to obtain injunctions preventing further unauthorized disclosure. The combination of civil breach remedies, injunctive relief, and criminal exposure under Section 72A creates a serious risk profile for Indian IT professionals who have not thought carefully about what they are pasting into AI prompts.

 

Financial Sector Obligations: SEBI and RBI

Indian fintech startups using vibe coding face regulatory layers that make the general IP and privacy risks look manageable by comparison.

SEBI's framework on algorithmic trading, established through its 2012 circular and subsequent updates, requires that any algorithm executing trades in Indian securities markets be audited, tested, and specifically approved. An AI-generated trading algorithm has not been audited by definition. It was produced by a language model in response to a prompt. Deploying it to execute real trades in Indian markets without regulatory approval violates SEBI's framework and exposes the deploying company and its principals to enforcement action.

RBI's IT Outsourcing Guidelines require banks and NBFCs to ensure that third-party technology services meet specified security and compliance standards. An RBI-regulated entity that vibe-codes a core banking feature and deploys it without proper review and audit is in violation of guidelines that carry significant supervisory consequences.

The Payment and Settlement Systems Act of 2007 requires payment system operators to maintain security and operational standards. Given the documented rates of security vulnerabilities in AI-generated code, a payment processing system built primarily through vibe coding and deployed without comprehensive security review is unlikely to satisfy these standards.

 

The MeitY AI Governance Guidelines of November 2025

On 5 November 2025, MeitY released the India Artificial Intelligence Governance Guidelines. These are currently non-binding but represent the government's most explicit statement yet of the principles that future binding regulation will encode.

The Guidelines address transparency, accountability, bias mitigation, and human oversight. On accountability, they are clear: human developers and deploying organizations are accountable for the outputs of AI systems they deploy. The guidelines do not contemplate an "the AI made a mistake" defense as a path to avoiding liability.

For vibe coders, this is the critical signal. The government is moving toward a framework where the human being who deployed AI-generated code is legally responsible for what that code does, regardless of the degree of human involvement in writing it. The productivity advantages of vibe coding do not reduce legal accountability. They simply mean you are responsible for outputs you did not personally create.

India has not yet passed a comprehensive AI Act comparable to the EU AI Act, which became fully enforceable in August 2025. But the direction is clear, and the interim period of relative regulatory ambiguity is finite. Developers and startups building under the assumption that AI-specific law will never arrive are making a bet that every observable government action suggest  they will lose.

What Indian Developers and Startups Must Actually Do

The legal landscape described above translates into practical obligations that are worth stating plainly rather than wrapping in legal hedging.

On intellectual property, treat AI-generated code as potentially unprotectable under current Indian law. Document your own creative contributions: the prompting strategy you developed, the architectural decisions you made, the edits and selections you performed on AI output. This human contribution is currently your best argument for copyright protection. Run license scanning tools such as FOSSA or Black Duck on all AI-generated code before shipping to check for embedded GPL or other copyleft-licensed code.

On data privacy, never input real personal data into AI prompts during development. Build DPDPA compliance into application architecture from the first design conversation, not as a retrofit before launch. For applications handling health, financial, or children's data, conduct a Data Protection Impact Assessment before deployment. Ensure development contracts with clients explicitly address AI tool usage and the boundaries of permissible data sharing.

On contracts and NDAs, update all client service agreements to disclose that AI coding tools are part of your development workflow. Get explicit written consent before using any AI tool that transmits code to external servers on a client project. Include clear limitation of liability clauses for AI-generated components in all service agreements.

On security, run mandatory static application security testing and software composition analysis on all AI-generated code before it reaches production. Establish an incident response plan that satisfies the CERT-In six-hour reporting requirement. Maintain documentation of what code was AI-generated and what human review it received.

On financial and sectoral regulation, if building fintech, healthtech, or any regulated product, obtain specialist legal advice specifically addressing whether the application requires regulatory pre-approval before AI-generated components can be deployed.

 

Where Indian Law Needs to Go

The gap between where Indian law is and where it needs to be is significant. Current frameworks were built for a world where software was written by humans, owned by identifiable authors, and failed in ways that could be traced to specific human decisions. Vibe coding disrupts all three assumptions simultaneously.

India needs clear rules on IP ownership for AI-assisted works, including what degree of human contribution is required to establish copyrightable originality. It needs a dedicated AI liability framework establishing accountability chains when AI outputs cause harm. It needs safe harbor provisions for developers who can demonstrate responsible AI use with documented human oversight. It needs standardized disclosure requirements for AI-generated software in commercial contracts. And it needs AI-specific security standards that go beyond generic IT security guidelines.

The expert panel on Copyright Act amendments and the MeitY AI Governance Guidelines are steps in the right direction. But steps move slowly, and code ships fast.

 

A Final Word

Vibe coding is real, it is here, and it is not going away. The 256 billion lines of AI-generated code from 2024, the Y Combinator startups with 95 percent AI codebases, the fintech founder who shipped a trading tool in a weekend using Cursor: these are not edge cases. They are the new center of how software gets built.

The Bombay High Court moved in a matter of weeks to protect Arijit Singh from AI exploitation of his voice. The Delhi High Court has framed four precise questions for OpenAI that will determine copyright rules for AI in India. The Data Protection Board of India will start enforcing DPDPA obligations with penalties that can end a company's existence. CERT-In already mandates a six-hour breach window. SEBI and RBI have existing frameworks that AI-generated financial software must satisfy.

The legal system is not waiting. Courts are moving. Regulators are watching. Legislation is coming.

The smartest thing an Indian vibe coder can do right now is understand that writing code with AI does not transfer the legal responsibility that comes with deploying that code. That responsibility remains exactly where it has always been. With the human being who put the product in front of users and said: this works, trust it.

Make sure it actually does.

🔗 Share this post: https://llmadvocates.com/blog/vibe-coding-and-legal-challenges-in-india-a-comprehensive-guide-2026-

About LLM Advocates

LLM Advocates is a specialized law firm registered with the Punjab & Haryana High Court, focusing on cyber law, AI governance, data privacy, and technology-related legal services. Our advocates hold LLM degrees in Cyber Law and are ISO 42001:2023 Certified Lead Auditors.

Meet Our Advocates →
Bot Avatar

LLMbot

Online