2026 AI Agent Risk Assessment Template: India Context

In the Indian context, the shift toward agentic AI recruitment coincides with the full enforcement of the Digital Personal Data Protection Act (DPDPA), 2023 and the recently released IndiaAI Governance Guidelines (2025-26).

For an Indian HR or Legal head, "Agentic Liability" isn't just a global concept; it is a direct collision with the "Seven Sutras of Trust" and the mandate for "People First" technology.

2026 AI Agent Risk Assessment Template: India Edition

Section 1: Data Sovereignty & DPDPA Compliance

India’s DPDPA is consent-centric. An autonomous agent that "scrapes" or "re-purposes" data without a clear "Notice" violates Section 5 and 6.

  • [ ] Dynamic Consent Notice: Does the agent trigger a fresh consent notice (in the candidate's preferred scheduled language) if it decides to use their data for a role other than the one originally applied for?

  • [ ] Purpose Limitation (Vesting): Is the agent restricted from "remembering" sensitive personal data (like Aadhaar numbers or medical history) beyond the specific hiring transaction?

  • [ ] Data Principal Rights: Does the system provide an automated way for a candidate to exercise their "Right to Erasure" directly through the agent interface?

  • [ ] Significant Data Fiduciary (SDF) Audit: If your organization is an SDF, does the agent provide the necessary logs for the Data Protection Officer (DPO) to conduct the mandatory periodic audit?

Section 2: Navigating the "Socio-Economic" Bias

In India, bias often hides in proxies like pincodes, alma maters, or language fluency. The IndiaAI Guidelines mandate "Fairness & Equity."

  • [ ] Vernacular Inclusion: Has the agent’s natural language processing (NLP) been tested for "Linguistic Bias" against candidates from non-metro cities or those using Indian-English dialects?

  • [ ] Tier-2/3 City Neutrality: Does the agent’s sourcing logic penalize candidates based on "Pincode Proxies" (often used by agents to calculate commute ease, which can inadvertently filter out marginalized communities)?

  • [ ] Reservation & Diversity Logic: Is the agent explicitly coded to respect the organization’s Diversity, Equity, and Inclusion (DEI) quotas, ensuring it doesn't "optimize out" candidates that help meet statutory or internal diversity goals?

Section 3: Legal Liability & Intermediary Status

Under the IT Act and the proposed Digital India Act, the "Safe Harbour" protection for AI intermediaries is shrinking.

  • [ ] Human-in-the-Loop (Section 79 IT Act): Does a human "Orchestrator" review the agent’s final shortlist? Note: Without meaningful human intervention, your company may lose "Intermediary" immunity and become 100% liable for the agent's "speech" or "decisions."

  • [ ] Contractual Indemnity: Does your agreement with the AI vendor include an "India-Specific Indemnity" clause for fines levied by the Data Protection Board of India (DPBI)?

  • [ ] Offer Letter Validity: Is the agent barred from "signing" an offer letter without a digital signature from a registered human authorized signatory?

Section 4: The "48-Hour" Operational Risk

Indian labor updates in 2026 place immense pressure on speed, particularly for Fixed-Term Employment (FTE).

  • [ ] FTE Conversion Logic: Does the agent automatically flag when a "Gig Worker" or "Consultant" meets the criteria to be classified as a "Deemed Employee" under the New Labor Codes?

  • [ ] Gratuitous Liability: Does the agent calculate and display the long-term Gratuity and PF liability for every "Autonomous Hire" it recommends, so HR can track the true cost of acquisition?

Summary of Risk Tiers (India 2026)

Risk CategoryThresholdIndian Regulatory Trigger
Data BreachFailure to notify DPBI within 72 hrs₹250 Crore Penalty (max)
Bias/DiscriminationSystematic exclusion of protected groupsConstitutional Writs / Civil Suit
Agentic ErrorUnauthorized salary/offer commitmentContractual Breach / Estoppel

The "Sutra" Check: > Before deploying any AI agent in India, ask: "If this agent were a human recruiter in our Mumbai or Bengaluru office, would its actions stand up to a High Court scrutiny?"

No comments:

Post a Comment