October 7, 2026 5:39 pm

ARTIFICIAL INTELLIGENCE AND THE CRISIS OF MENS REA: RETHINKING CRIMINAL ACCOUNTABILITY FOR AI-DRIVEN HARM IN INDIA

AUTHOR: Srrijal Srivastava, BA LLB, United University, Prayagraj

ABSTRACT

Artificial intelligence systems now diagnose disease, price insurance, screen job applicants and drive cars — decisions that once belonged exclusively to human judgment now carry, embedded in code, the capacity to injure, discriminate and kill. Indian criminal law, however, remains built around a single actor: the human being with a guilty mind. This article examines the resulting accountability gap in the Indian context. It argues that the Bharatiya Nyaya Sanhita, 2023, despite replacing the Indian Penal Code, 1860, transplants rather than resolves this difficulty, and that algorithmic bias in particular escapes the vocabulary of intention, knowledge and negligence around which Indian criminal doctrine is organised.

Drawing on India’s emerging regulatory response — the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the India AI Governance Guidelines released by the Ministry of Electronics and Information Technology in November 2025 — the article contends that a distributed, risk-tiered liability model offers a more workable path forward than either strict liability or AI legal personhood.

KEYWORDS

Artificial Intelligence; Mens Rea; Criminal Liability; Bharatiya Nyaya Sanhita 2023; Algorithmic Bias; AI Governance.

I. INTRODUCTION

Artificial intelligence systems today screen loan applications, flag suspects for police attention, drive vehicles through crowded streets, and moderate what millions of people see online. When one of these systems causes harm — an autonomous vehicle strikes a pedestrian, a facial-recognition match sends an innocent person to a police station, a generative model manufactures a non-consensual deepfake — the question that follows is stubbornly old-fashioned: who is criminally responsible? Indian criminal law answers that question through a requirement that has stood since 1860: a guilty mind.

This article argues that the difficulty is not merely rhetorical. The Bharatiya Nyaya Sanhita, 2023[1] (‘BNS’), which replaced the Indian Penal Code, 1860 (‘IPC’) with effect from 1 July 2024, carries forward the same mens rea architecture that has governed Indian criminal law for over a century and a half. Nothing in the BNS was drafted with autonomous decision-making systems in mind, and the statute offers no vocabulary for attributing intention, knowledge or recklessness to code.

The result, this article contends, is not that AI-driven harm escapes law altogether — developers, deployers and users remain human, and human liability can often be constructed around them — but that the fit is loose, inconsistent, and increasingly unable to answer for the most distinctive AI-specific harm of all: algorithmic bias, a wrong authored not by any single decision but accreted silently across data and design choices.

Part II of this article sets out the anthropocentric structure of Indian criminal law. Part III examines the accountability gap that autonomous systems create. Part IV isolates algorithmic bias as a harm that traditional mens rea categories struggle to capture. Part V shows that the BNS, 2023 offers continuity rather than reform. Part VI surveys India’s emerging regulatory response. Part VII draws a brief comparative lesson from the European Union. Part VIII proposes a distributed, risk-tiered framework better suited to Indian conditions, before Part IX concludes.

II. THE ANTHROPOCENTRIC ARCHITECTURE OF INDIAN CRIMINAL LAW

Indian criminal law rests on the maxim actus non facit reum nisi mens sit rea — an act does not make a person guilty unless the mind is also guilty. The Supreme Court has treated this as the default position for over sixty years. In State of Maharashtra v Mayer Hans George[2], the Court examined whether a foreign national who smuggled gold through Bombay without declaring it could be convicted despite being unaware of the notification that made his conduct an offence; the following year, in Nathulal v State of Madhya Pradesh[3], the Court reaffirmed that a statute creating an offence should ordinarily be read as requiring a guilty mind unless the legislature expressly or by necessary implication excludes it. Together, these decisions entrenched a presumption that runs through the IPC and, unaltered, into the BNS: guilt requires a subjective mental state, not merely a harmful outcome.

That mental state takes four recognised forms — intention, knowledge, recklessness and negligence — each demanding a progressively lower level of subjective awareness on the part of the accused. Exceptions exist: children below a prescribed age, persons of unsound mind, and a narrow category of strict-liability offences where the legislature has deliberately dispensed with proof of a guilty mind in the interest of some overriding public welfare objective. But these exceptions are precisely that — exceptions, carved out of a rule whose default position remains subjective culpability.

An artificial intelligence system has no subjective state to examine. It does not intend, does not know in any legally cognisable sense, and cannot be reckless or negligent as those terms have been judicially understood, because recklessness and negligence still presuppose a human capacity for foresight and a human standard of care. When harm originates in a model’s own statistical inference rather than in a line of code a person can be shown to have written with a particular objective, the entire doctrinal apparatus described above has nothing to attach to.

III. THE ACCOUNTABILITY GAP: ATTRIBUTING BLAME FOR AUTONOMOUS HARM

The practical difficulty is not that no human being can ever be held responsible for AI-driven harm — it is that several human beings could plausibly be held responsible, and existing doctrine gives little guidance on how to choose between them. A harmful output may trace back to the developer who designed the model’s architecture, the organisation that trained it on a particular dataset, the deployer who integrated it into a decision-making pipeline without adequate safeguards, or the end user who relied on its output without independent verification.

Commentators examining this problem in the Indian context have observed that, because artificial systems presently lack legal personality, the only available route is to attribute liability to the human creators, procurers and users behind the system[4] — an approach that becomes increasingly artificial as systems act with diminishing human intervention.

Proposals for distributing responsibility across developers, procurers, trainers and users according to their degree of control have gained support as an alternative to insisting on a single culpable individual, and composite models that vary the standard applied — user liability for narrow, low-autonomy tools; a more exacting standard for highly autonomous systems — have also been suggested as context-sensitive solutions.

A further complication is opacity. Many contemporary machine-learning systems, particularly deep neural networks, do not permit even their own developers to state with confidence why a specific output was produced in a specific case. Where the actus reus itself is difficult to trace to an identifiable human decision, the prosecution’s burden of proving a contemporaneous guilty mind — already demanding under ordinary evidentiary standards — becomes close to unworkable.

The temptation this creates is to fall back on strict liability, dispensing with proof of mens rea altogether wherever an AI system is involved. That temptation should be resisted as a general solution: strict liability sacrifices exactly the culpability-based distinctions — between a reckless deployer and a diligent one, between a system tested rigorously and one rushed to market — that criminal law exists to draw.

IV. ALGORITHMIC BIAS AS A DISTINCT SPECIES OF HARM

Algorithmic bias deserves separate treatment because it does not resemble the discrete, identifiable act that criminal law is accustomed to punishing. A predictive-policing tool that disproportionately flags a particular neighbourhood, a facial-recognition system that misidentifies certain groups at higher rates, or a credit-scoring algorithm that systematically disadvantages certain applicants, does not produce its harm through any single culpable decision. The harm is distributed across thousands of training examples, feature choices and threshold settings made over months of development, frequently by teams no single member of whom intended, or perhaps even foresaw, the discriminatory pattern that later emerges in production.

Recklessness — conscious disregard of a known risk — and even ordinary negligence, both require some point at which a reasonable person ought to have foreseen the specific harm. Where bias emerges from the statistical interaction of a large dataset with a complex model, that point may simply not exist in any form a court could identify.

This does not mean algorithmic bias should escape accountability altogether. It suggests, instead, that the relevant culpability question shifts from the moment of harm to the moment of design: did the developer test the system for disparate impact before deployment, and did it maintain the auditing infrastructure necessary to detect bias once the system was in use? A negligence standard pegged to these process failures — the absence of reasonable bias-testing and monitoring, rather than the occurrence of a biased outcome as such — offers a more doctrinally honest basis for liability than either strict liability or an unworkable search for individual intention.

V. THE BHARATIYA NYAYA SANHITA, 2023: CONTINUITY, NOT REFORM

The BNS, 2023 was framed as a wholesale re-imagining of Indian criminal law, replacing colonial-era terminology and introducing new offences relating to organised crime, terrorism and cyber-enabled fraud. Yet on the specific question this article addresses, the BNS changes nothing. Commentary on the new code has observed that it preserves the fundamental mens rea-based architecture of the IPC without disturbance[5] — the same four mental states, the same general exceptions, the same default presumption in favour of subjective culpability.

No provision of the BNS addresses the allocation of liability among a developer, a deployer and a user of an autonomous system, and none defines a standard of care applicable to the design or auditing of such systems. The legislature, in other words, modernised the vocabulary of Indian criminal law without addressing the one development most likely to strain its foundational assumptions in the coming decade.

This is not a criticism unique to India. Commentators examining the same gap have called for a dedicated statutory instrument — whether a standalone enactment or comprehensive amendments within existing law — that clarifies mens rea standards for AI-assisted offences, addresses evidentiary difficulties specific to algorithmic systems, and fixes intermediary obligations with precision[6]. Until such an instrument exists, prosecutors and courts are left to stretch inherited doctrine over facts it was never designed to fit.

VI. INDIA’S EMERGING REGULATORY RESPONSE

Outside the criminal code proper, India has not been entirely without response. Before any AI-specific reform, harms arising from AI-generated content — impersonation, obscene deepfakes, identity theft — were addressed through general provisions of the Information Technology Act, 2000, including section 66C on identity theft, section 66D on cheating by personation, section 66E on privacy violation, and sections 67 and 67A on obscene and sexually explicit material[7].

The Digital Personal Data Protection Act, 2023, subsequently introduced obligations on entities processing personal data, including automated processing, though its enforcement architecture is principally administrative rather than criminal[8].

More recently, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 have introduced binding obligations on significant social media intermediaries to label synthetically generated content and to implement traceability measures capable of identifying the origin of such content, as a condition for retaining safe-harbour protection under the IT Act[9].

Separately, the Ministry of Electronics and Information Technology released the India AI Governance Guidelines in November 2025, adopting a ‘do no harm’ principle and a governance framework built on existing law rather than a standalone AI statute[10]. The guidelines propose a risk-linked liability model that ties responsibility to an actor’s function, degree of control and the risk level of the system concerned, alongside a proposed Technology and Policy Expert Committee and an AI Safety Institute tasked with testing systems, advising regulators and developing standards for bias mitigation and explainability[11].

These are meaningful developments, but none of them is a criminal statute. The IT Act provisions predate generative AI and were not designed with autonomous systems in mind; the DPDP Act addresses data protection, not criminal culpability; and the AI Governance Guidelines are, by MeitY’s own description, a voluntary and administrative framework rather than a binding liability regime enforceable through prosecution. The accountability gap identified in Parts III and IV of this article therefore persists at the level of substantive criminal law, even as India’s administrative and data-protection architecture around AI matures.

VII. A COMPARATIVE GLIMPSE: THE EUROPEAN UNION

The European Union’s Artificial Intelligence Act[12] offers one comparative reference point, though its lessons must be applied cautiously. The AI Act classifies systems into tiers of risk — from prohibited uses to high-risk applications subject to conformity assessment, transparency and human-oversight obligations, down to minimal-risk systems left largely unregulated — and calibrates obligations on providers and deployers accordingly. Crucially, however, the AI Act is principally a product-safety and administrative-penalty regime, not a criminal statute; it does not itself define offences or prescribe imprisonment.

Its value for Indian reform lies less in its enforcement mechanism than in its methodology: tying the intensity of an actor’s legal obligations to the function they perform and the risk their system poses, rather than searching for a single culpable mind, is precisely the reorientation Indian criminal law needs if it is to engage meaningfully with autonomous systems.

VIII. TOWARDS A WORKABLE FRAMEWORK

Two extreme positions should be rejected at the outset. Granting AI systems legal personhood for the purpose of criminal liability is premature: it would require legislative recognition Indian law does not presently extend, and would risk becoming a liability shield behind which the humans actually directing a system’s design and deployment could hide. Equally, imposing blanket strict liability on every human associated with an AI system sacrifices the culpability-based distinctions that give criminal law its moral force. Between these extremes, four more modest reforms merit consideration.

First, Parliament should clarify, whether through amendment to the BNS or a dedicated statute, the mens rea standard applicable to AI-assisted offences — specifying, for instance, that a negligence standard applies to the design and deployment of high-risk autonomous systems, while ordinary intention-based standards continue to apply where a human deliberately misuses an AI tool to commit an offence such as generating a defamatory deepfake or a fraudulent voice clone.

Second, liability should be distributed according to function and control, broadly along the lines the India AI Governance Guidelines already gesture toward: developers bearing responsibility for design-stage failures such as inadequate bias testing, deployers bearing responsibility for integration-stage failures such as inadequate human oversight, and users bearing responsibility only where they knowingly misuse a system for an unlawful purpose.

Third, mandatory bias-audit and documentation obligations should be imposed on developers of high-risk systems, breach of which would itself constitute the negligence necessary to ground liability for downstream discriminatory harm — converting an otherwise unprovable mental state into a provable process failure.

Fourth, an evidentiary framework specific to AI-related prosecutions is needed, requiring developers and deployers of high-risk systems to maintain and disclose decision logs and model documentation sufficient to reconstruct, after the fact, how a particular output was produced — without which the opacity problem identified in Part III will continue to defeat prosecution regardless of how liability is formally allocated.

IX. CONCLUSION

Indian criminal law is not broken by artificial intelligence; it is stretched thin by it. The doctrine of mens rea that has governed Indian criminal liability since the IPC, and which the BNS, 2023 carries forward unchanged, remains sound for the overwhelming majority of offences it was designed to address. Its limits become visible only at the margin — where harm originates in an opaque, statistically-driven system rather than a discrete human decision, and most acutely where that harm takes the form of algorithmic bias accreted across design choices rather than a single culpable act.

India’s administrative response to AI, from the IT Act’s inherited provisions to the 2025 AI Governance Guidelines, shows an awareness of this margin without yet closing it in criminal law. A distributed, risk-tiered framework — clarifying mens rea standards, allocating liability by function and control, and mandating the documentation needed to make that liability provable — offers the most realistic route to closing it, without abandoning the culpability principle that has anchored Indian criminal justice for over a century and a half.

TABLE OF CASES

Nathulal v State of Madhya Pradesh AIR 1966 SC 43

State of Maharashtra v Mayer Hans George AIR 1965 SC 722

TABLE OF LEGISLATION

Bharatiya Nyaya Sanhita 2023 (Act 45 of 2023)

Digital Personal Data Protection Act 2023

Information Technology Act 2000

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026

Regulation (EU) 2024/1689 laying down harmonized rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 1689

BIBLIOGRAPHY

  1. Karape VV, ‘Artificial Intelligence and Criminal Liability in India: Addressing the Legal Vacuum in the Era of Deepfakes and Synthetically Generated Information’ (Record of Law) https://recordoflaw.in/artificial-intelligence-and-criminal-liability-in-india-addressing-the-legal-vacuum-in-the-era-of-deepfakes-and-synthetically-generated-information accessed 7 August 2026
  2. ‘Criminal Liability of AI In India’ (LawFoyer) https://lawfoyer.in/criminal-liability-of-artificial-intelligence-machines-in-india accessed 7 August 2026
  3. ‘Mens Rea in Indian Criminal Law: Its Centrality, Its Limits, and Offences Where It Is Excluded’ (De Facto Judiciary, 2 May 2026) https://www.defactojudiciary.in/notes/mens-rea-in-indian-criminal-law-its-centrality-its-limits-and-offences-where-it-is-excluded accessed 7 August 2026
  4. Ministry of Electronics and Information Technology, India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation (Government of India, November 2025) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf accessed 7 August 2026
  5. Saikrishna & Associates, ‘Decoding the India AI Governance Guidelines’ (12 November 2025) https://www.saikrishnaassociates.com/decoding-the-india-ai-governance-guidelines accessed 7 August 2026
  6. ‘India’s AI Governance Model — MeitY’s AI Guidelines and the Evolving Copyright Landscape’ (Lexology, 30 March 2026) https://www.lexology.com/library/detail.aspx?g=ffc0c58c-3727-4472-9914-5fa6a33ffffd accessed 7 August 2026

[1]Bharatiya Nyaya Sanhita 2023 (Act 45 of 2023).

[2]State of Maharashtra v Mayer Hans George AIR 1965 SC 722.

[3]Nathulal v State of Madhya Pradesh AIR 1966 SC 43.

[4]‘Criminal Liability of AI In India’ (LawFoyer) <https://lawfoyer.in/criminal-liability-of-artificial-intelligence-machines-in-india/> accessed 7 August 2026.

[5]‘Mens Rea in Indian Criminal Law: Its Centrality, Its Limits, and Offences Where It Is Excluded’ (De Facto Judiciary, 2 May 2026) https://www.defactojudiciary.in/notes/mens-rea-in-indian-criminal-law-its-centrality-its-limits-and-offences-where-it-is-excluded accessed 7 August 2026.

[6]Vaishnavi Vikas Karape, ‘Artificial Intelligence and Criminal Liability in India: Addressing the Legal Vacuum in the Era of Deepfakes and Synthetically Generated Information’ (Record of Law) https://recordoflaw.in/artificial-intelligence-and-criminal-liability-in-india-addressing-the-legal-vacuum-in-the-era-of-deepfakes-and-synthetically-generated-information accessed 7 August 2026.

[7]Information Technology Act 2000, ss 66C, 66D, 66E, 67, 67A.

[8]Digital Personal Data Protection Act 2023.

[9]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026; see ‘India’s AI Governance Model — MeitY’s AI Guidelines and the Evolving Copyright Landscape’ (Lexology, 30 March 2026) https://www.lexology.com/library/detail.aspx?g=ffc0c58c-3727-4472-9914-5fa6a33ffffd accessed 7 August 2026.

[10]Ministry of Electronics and Information Technology, India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation (Government of India, November 2025) https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf Accessed 7 August 2026.

[11]Saikrishna & Associates, ‘Decoding the India AI Governance Guidelines’ (12 November 2025) https://www.saikrishnaassociates.com/decoding-the-india-ai-governance-guidelines accessed 7 August 2026.

[12]Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 1689.

Disclaimer: This article is published for educational and informational purposes only and does not constitute legal advice, legal opinion, or professional counsel. It does not create a lawyer–client relationship. All views and opinions expressed are solely those of the author and represent their independent analysis. Times Law does not endorse, verify, or assume responsibility for the author’s views or conclusions. While editorial standards are maintained, Times Law, the author, and the publisher disclaim all liability for any errors, omissions, or consequences arising from reliance on this content. Readers are advised to consult a qualified legal professional before acting on any information herein. Use of this article is at the reader’s own risk.