Artificial intelligence is no longer a future concept in Indian healthcare. AI-powered diagnostic tools — algorithms that analyse retinal photographs for diabetic retinopathy, ECG traces for cardiac arrhythmias, mammograms for breast lesions, and radiology images for pathological findings — are being deployed in Indian hospitals and diagnostics centres right now. Robotic surgical systems are in use at large tertiary care hospitals in Delhi, Mumbai, Chennai, and Bangalore. Clinical decision support systems integrated into EMRs are suggesting drug interactions and flagging abnormal lab values at scale.

Yet the legal framework governing these technologies in India is almost entirely absent. There is no dedicated AI liability statute, no sector-specific regulatory approval pathway equivalent to the US FDA's Software as a Medical Device (SaMD) framework, and no judicial precedent squarely addressing who bears responsibility when an AI tool in a clinical setting causes patient harm.

This article analyses the question that healthcare providers, patients, and lawyers in India are increasingly asking: when an AI diagnostic tool is wrong and a patient is harmed, who is liable?

"AI in medicine creates a genuinely new liability question — not because the law is entirely silent, but because the existing framework was designed for a world in which a human being always makes the final clinical decision. The challenge is applying established principles to a context where the line between 'tool' and 'decision-maker' is increasingly blurred. Courts will eventually settle this — but for now, the doctor and the hospital bear the risk, and they should plan accordingly."
— Dr. Namit Gupta, Senior Medico-Legal Expert, Medico Legal Services, New Delhi

The State of AI in Indian Healthcare

Several AI tools relevant to Indian clinical practice are already in deployment or actively being adopted:

  • Niramai (Thermalytix): An AI-based thermal imaging tool for breast cancer screening that has been validated in Indian populations and is deployed at multiple hospitals and cancer screening camps
  • Tricog Health: An AI-powered ECG analysis platform deployed at over 1,000 hospitals across India, providing near-real-time cardiac diagnosis support, including STEMI detection
  • Diabetic retinopathy screening AI: Multiple AI tools — including Google's RetinalAI and Indian equivalents — are being piloted through AYUSH and government screening programmes for early detection of diabetic eye disease
  • Radiology AI: Tools for detecting tuberculosis from chest X-rays (such as qXR by Qure.ai, developed in India) are used across government hospitals and private diagnostics chains
  • Robotic surgery: da Vinci surgical systems and similar robotic platforms are in active use at Apollo Hospitals, Fortis, Manipal, and several AIIMS centres for urological, gynaecological, and gastrointestinal procedures

These are not pilot projects. They are clinical tools making real-time contributions to diagnosis and treatment decisions affecting real patients.

The Legal Vacuum: India's Current Position

India has no dedicated AI liability legislation. The closest regulatory frameworks are:

  • Medical Devices Rules, 2017: AI-powered diagnostic software may qualify as a medical device under the definition of "software intended for medical purposes." The CDSCO has been developing a framework for Software as a Medical Device (SaMD), including AI/ML-based tools. As of 2026, this framework is not fully operationalised, creating a registration and post-market surveillance gap for many AI tools in clinical use.
  • Consumer Protection Act, 2019: Applies to defective products and deficient services. An AI tool that consistently produces wrong outputs is potentially a "defective product"; clinical care delivered using such a tool is potentially a "deficient service."
  • DPDP Act, 2023: Governs the use of patient data to train and run AI systems. Relevant to data governance but not to clinical liability directly.
  • IT Act, 2000: Governs electronic records and digital systems broadly but does not address AI liability specifically.

Liability Framework Analysis: Three Potential Defendants

1. The Treating Physician: The "Final Decision" Doctrine

Under established Indian and international law, AI is classified as a tool, not a practitioner. The treating physician who uses an AI tool retains full legal responsibility for the clinical decision. This is the "final decision" doctrine: however sophisticated the AI, a licensed human clinician is the one who integrates its output with clinical judgment and acts on it — and that clinician bears professional and legal accountability for the outcome.

The implications are significant. If a radiologist reads an AI-flagged report without independently reviewing the underlying image, and misses a finding that the AI also missed — and that a careful human radiologist would have caught — that radiologist may be liable for negligence. If a cardiologist acts on an AI-generated ECG interpretation without checking whether the clinical picture fits, and the AI was wrong, the cardiologist who signed the treatment order bears primary responsibility.

The Bolam test — whether a reasonably competent doctor of ordinary skill in that specialty would have made the same decision — does not disappear simply because AI is involved. Courts will ask: would a reasonably competent doctor, using the same AI tool, have exercised additional clinical caution given the clinical picture? If yes, and if the defendant doctor did not, negligence may be established notwithstanding the AI error.

2. The AI Developer: Product Liability Under the Consumer Protection Act 2019

The Consumer Protection Act 2019 contains an explicit product liability framework under Chapter VI. A "product manufacturer" is liable for harm caused by a defective product. A "product" includes software (the Act defines "product" broadly as any article or goods). If an AI diagnostic tool — as a product — has a manufacturing defect (the algorithm itself produces systematically wrong outputs), a design defect (the tool is not fit for its intended diagnostic purpose), or lacks adequate warnings about its limitations, the developer may be liable as a product manufacturer.

The challenge for plaintiffs is evidence. Establishing that an AI tool is defective — as opposed to simply having produced an incorrect output in a specific case — requires technical expert evidence about the algorithm, its validation dataset, its performance metrics (sensitivity, specificity, positive predictive value in the relevant population), and whether its output in the specific case was consistent with its known error characteristics.

Most AI medical tool developers insert disclaimers stating that their product is a "decision support tool" and not a diagnostic device — placing the diagnostic responsibility on the physician. Whether Indian courts will accept such disclaimers as a complete defence to product liability, or whether they will look past the contractual framing to the practical reality that clinicians rely heavily on these outputs, is an open question. The Consumer Protection Act does not permit product liability to be contractually excluded against consumers.

3. The Hospital: Institutional Liability

A hospital that deploys an AI tool is not a passive bystander. It has independent obligations:

  • Validation before deployment: A hospital that adopts an AI tool without verifying its performance characteristics in the hospital's own patient population (which may differ from the tool's validation dataset) may be independently negligent if the tool performs poorly in that population
  • Staff training: If clinical staff are not trained in the limitations of the AI tool — and in particular are not trained to exercise independent judgment rather than blindly accepting AI outputs — the hospital's failure to train may constitute vicarious or institutional negligence
  • Supervision: Deploying an AI tool with inadequate clinical governance (no protocol for when to override the AI, no audit of AI-assisted decisions, no escalation pathway for uncertain cases) creates institutional liability
  • Infrastructure: If the AI tool requires specific technical conditions to function accurately (image quality thresholds, integration with specific data formats) and the hospital's infrastructure does not meet those conditions, errors resulting from poor-quality inputs to the AI are attributable to the hospital's inadequate technical setup

The Bolam Test and AI: Evolving Standards of Care

The Bolam test asks what a "responsible body of medical opinion" regards as acceptable practice. AI creates an interesting evolution in this test: as AI tools become standard of care in a specialty, failing to use them may itself become negligence. A radiologist who does not use a validated AI assist tool for chest X-ray TB detection — when all competent radiologists in the specialty routinely use it — could face a claim that their practice was below standard.

Conversely, as the limitations of specific AI tools become known in the medical community, relying on them without independent clinical verification may also fall below standard. The standard of care will evolve with the technology, and courts will need expert evidence from clinicians in the relevant specialty about what constitutes reasonable AI-assisted practice at the time of the alleged negligence.

International Context: Lessons India Should Learn

IBM Watson for Oncology

IBM Watson for Oncology was deployed at several major cancer centres internationally, including one in India. Reports emerged that its treatment recommendations were sometimes inconsistent with established oncological guidelines, and the system was quietly withdrawn from many institutions. No successful liability claim was publicly reported, but the episode illustrated that AI deployed at scale in clinical settings without rigorous independent validation can produce systematically incorrect outputs — and that hospitals that deployed it without adequate oversight bore institutional responsibility for the outcomes.

FDA's SaMD Framework

The US FDA has developed a specific regulatory pathway for Software as a Medical Device, including AI/ML-based SaMD. Devices classified as Class II or Class III require pre-market notification or approval before clinical deployment. India's CDSCO framework is still developing, but the MedTech sector and hospital community should expect increasing regulatory oversight of AI clinical tools as the framework matures.

Robotic Surgery Liability: A Three-Party Problem

Robotic surgery systems — the da Vinci Surgical System being the most prevalent in India — create a distinctive liability triangle. When a complication occurs during a robotic procedure, liability may attach to:

  • The operating surgeon: Who controls the robotic arms and is responsible for all surgical decisions made during the procedure. The surgeon cannot blame the robot for a technical error that a skilled robotic surgeon would have avoided
  • The hospital: Which is responsible for ensuring the robot is properly maintained, calibrated, and serviced; that the surgical team is adequately trained; and that the robot is used within its validated clinical indications
  • The manufacturer: Where a mechanical failure, software malfunction, or design defect in the robotic system caused or contributed to the complication — product liability under the Consumer Protection Act 2019

In practice, most robotic surgery complications arise from surgeon technique rather than equipment malfunction — the same complications that can occur in laparoscopic or open surgery. But where a genuine equipment malfunction is alleged, the manufacturer's liability comes into play, and establishing this requires inspection of the robot's event log (which modern surgical robots record) and expert technical evidence.

India's Regulatory Path Forward: CDSCO and AI/ML SaMD

The Central Drugs Standard Control Organisation is working under the Medical Devices Rules 2017 to create a clear classification and approval pathway for AI-based medical software. The expected framework will:

  • Classify AI/ML SaMD by risk level (equivalent to Class I/II/III)
  • Require pre-market registration for higher-risk AI diagnostic tools
  • Mandate post-market performance surveillance and reporting of adverse events linked to AI tools
  • Address the specific challenge of continuously learning AI systems (which update their algorithms with new data) — creating a "predetermined change control plan" approach similar to the FDA's framework

Until this framework is fully in force, hospitals must exercise their own clinical governance over AI tool deployment.

What Hospitals Should Do Before Deploying an AI Tool

  • Validate performance in your patient population: An AI tool validated on a Western population may perform differently on Indian patients, who have different disease prevalence, comorbidity patterns, and presentation characteristics. Run a local validation study before full deployment
  • Review CDSCO registration status: Check whether the tool is registered as a medical device with CDSCO. If it is not, understand why — some developers claim their tools are not medical devices; hospitals deploying them take on additional governance responsibility
  • Update informed consent: Patients should know that AI is being used in their diagnosis and should have the opportunity to ask questions. Update consent forms to disclose AI use in relevant procedures
  • Document the clinical override: Establish a protocol for documenting when a clinician agrees with an AI output (and why), and — critically — when a clinician overrides the AI recommendation. These records are legally significant
  • Training and competency assessment: Ensure all clinical staff using AI tools are trained in their limitations and assessed for competency in AI-assisted clinical decision making
  • Vendor contracts: Ensure contracts with AI tool vendors address: performance warranties, what happens when the tool produces a wrong output, the vendor's indemnification position, and data handling under the DPDP Act

What Doctors Should Do When Using AI Tools

  • Treat AI output as one input among several — not as a replacement for clinical assessment
  • Do not accept an AI output that is inconsistent with the clinical picture without further investigation
  • Document your clinical reasoning separately from the AI output — this is what courts will examine
  • Understand the performance characteristics of the AI tools you use: their sensitivity, specificity, and known failure modes
  • When in doubt, revert to established clinical protocols — the fact that an AI tool suggested otherwise is not a defence to a departure from the standard of care

A Case Study Scenario

Consider a 52-year-old diabetic patient who attends a private hospital in Delhi for annual review. The hospital uses an AI-powered retinal screening tool to analyse fundus photographs for diabetic retinopathy. The AI tool reports "No clinically significant diabetic retinopathy detected." The report is reviewed by a technician who adds the AI output to the patient's file. No ophthalmologist independently reviews the image. Twelve months later, the patient presents with sudden visual loss. An ophthalmologist identifies severe proliferative diabetic retinopathy — changes that, in the retrospective view of an expert, were visible on the previous year's image and should have prompted laser treatment.

In this scenario, liability analysis points in three directions:

  • The AI tool developer — if the tool failed to detect changes a validated algorithm should have caught (potential product defect)
  • The hospital — for deploying a screening protocol in which no qualified clinician independently reviewed the image, relying entirely on the AI output
  • The treating physician — if they were responsible for the patient's annual review and accepted the AI-generated report without independent clinical review of the fundus image

A consumer forum or civil court would examine all three threads. The most defensible position for the hospital and physician would have been an independent expert review alongside the AI output — a "human in the loop" at the point of clinical consequence.

Conclusion

AI will not eliminate medical negligence — it may shift it, and it will certainly complicate liability analysis. The current Indian legal framework, built around the treating physician as the locus of clinical responsibility, will remain the primary framework for AI-related medical liability claims for the foreseeable future. That means doctors and hospitals bear the legal risk of AI errors unless and until a specific regulatory and liability framework places a proportionate share of that risk on developers.

In the meantime, hospitals and doctors who deploy AI tools thoughtfully — validating performance, training staff, maintaining clinical oversight, and documenting decision-making — are in a far better position than those who treat AI outputs as infallible. The patient harmed by an AI-assisted error has remedies. The question is who pays.

If you are a patient harmed by an AI-assisted diagnostic error, or a hospital or clinician seeking guidance on AI governance and liability exposure, contact our medico-legal team for expert assessment.