Disclosure and Assurance document under DGPSI-AI

DGPSI-AI is a Pioneering and Forward thinking  framework which establishes India as a leader in AI deployment is an assessment of the leading LLMs such as ChatGPT, Gemini, Perplexity and DeepSeek.

It takes time for the Indian AI eco system to understand the reason why these LLMs place DGPSI-AI in high esteem. As we proceed to explain the DGPSI-AI in greater detail the reasons would present by themselves.

One of the implementation specifications envisaged by the DGPSI-AI framework is the classification of a software as “AI” and “Non -AI” through documentation.

 DGPSI starts with a classification of Data as “Non Personal” and “Personal” and further  “Personal Data” itself is classified as  “Covered under  DPDPA” and “Covered under other country laws”. Similarly, before DGPSI-AI implementation starts, it is necessary to classify the software as “AI” and “Non AI”. This also means that there has to be a “Process Inventory” and “Software Inventory” which are pre-requisites for identification of “AI-Process”.

In this process, it is intended that the Data Fiduciary who purchases a software which is branded as “AI Embedded” or “AI-Inside”, shall insist that the licensor incorporates a “Disclosure and Assurance” to the following effect.

“Original Code of this software developed by …………………… is capable/Not capable of modifying its code without human intervention from the outputs generated and has been tested and assured as safe for personal data processing for DPDPA Compliance”.

This declaration identifies the original accountability of the AI software (which is a requirement under ITA 2000 compliance) and incorporates the first requirement to identify the software as AI.

This may be one of the mandatory contract clauses recommended to be  used in every software supply contract.

I request the readers to add their comment on the feasibility and desirability of such a clause and whether it can be voluntarily adopted or requires a mandate from the Government. I look forward to your views.

Naavi

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.