Beyond Precedent
Consumer Law & Disputes

Why is AI not a ‘Product’ under Indian Consumer Law? An Evolutionary Enquiry

By Abhivardhan  |  Sep 05, 2026
Co-Authors: Nisha Singh
Why is AI not a ‘Product’ under Indian Consumer Law? An Evolutionary Enquiry

The embedded use of artificial intelligence (AI) in daily consumer interactions had become possible almost a decade ago, even in India. It started primarily with sophisticated credit card systems, and after the proliferation of UPI and the JAM Trinity of government schemes in India, thanks to India Stack (Aadhar and Digilocker, for example), data proliferation in the fintech industry (or BFSI) became more mainstream. Later on, a mass-level involvement of random categories of AI systems in a post-COVID world beyond transportation aggregators and fintech became more possible in food delivery apps, education resources & testing ecosystems and search engines & chatbots. While consumers are inclined to reduce generative AI and agents as mere “chatbots” and prompt dashboards, the mainstreaming of AI in India’s consumer economy became possible not just due to AI hype but also because the potential of organised data pipelines was finally achieved. Right now, the involvement of AI agents is being pushed vigorously, without due care or understanding of India’s data protection and consumer laws. However, the commoditisation of AI services as subscriptions, one-time payment “digital goods” and freemium deliverables is creating legal lacuna. For any deceptive or unreliable access to AI tools which should create the case for consumer redressal, might just not be possible due to some legal lacuna in the Consumer Protection Act, 2019. This article therefore unfolds those legal lacunae and explores the possibility to amend Section 2 of the Act.

Evolution of AI Product Liability in Indian Laws

The Consumer Protection Act, 2019 (CPA) provides remedies for defective products, deficient services and unfair trade practices. It therefore also creates a product-liability regime capable of imposing responsibility on manufacturers, sellers and product service providers for consumer harm. Now, AI systems, when implemented, are categorised as services, and invoke a different yet obvious chain of stakeholders - models, developers, platforms and deployers.

While traditional product liability is relatively linear, these chains of stakeholders may be categorised as upstream and downstream players. However, the elements of productisation and serviceability might differ, and we might see two categories of consumers - end-users or individual consumers and business end-users or B2B users.

For instance, a foundation-model developer A may create the underlying model and it is easily possible that another company B may fine-tune it as a B2B user or a business end-user. On the other hand, a software provider C may integrate the fine-tuned model into an application as a business end-user, while an entirely different business D deploys that application before consumers or individual end-users X, Y & Z. Cloud providers, data suppliers and other intermediaries may also be involved, provided they come within the ambit of consumer law. The table below provides an apt dissection of this instance.


Entity

Upstream / Downstream Position

Role in the Supply Chain

User Classification

Data Suppliers

Upstream (Foundational layer)

Provide raw training datasets and curated corpora

Input Provider / Non-user

Cloud Providers

Upstream (Infrastructure layer)

Host compute, training pipelines, and deployment environments

Infrastructure Intermediary

Foundation-Model Developer A

Upstream (Core model layer)

Trains and produces the underlying base model

Upstream Provider / Developer

Company B

Midstream / Relatively Downstream (from A)

Fine-tunes the base model for specific commercial tasks

B2B User / Intermediate Business User

Software Provider C

Downstream

Integrates the fine-tuned model into a software application

Business End-User / Integrator

Business D

Downstream

Procures, deploys, and operates the application for customer-facing use

Deployer / Commercial End-User

Individuals X, Y & Z

Ultimate Downstream

Use or interact with the final AI application

Consumers / Individual End-Users

Now, the CPA defines product liability as responsibility for harm caused by a defective product or deficiency in related services and separately recognises manufacturers, sellers and product service providers. However, identifying an actor to be liable under the Act becomes difficult when the consumer-facing company (as could be possible per above instance) did not develop the underlying model that produced the harmful behaviour.

In that case, Consumer Commissions may more readily proceed against a downstream business with which the consumer directly interacted by alleging a deficiency in service. Establishing responsibility further in the context of upstream players, however, may be considerably harder where there is no direct individual consumer relationship and liability has been contractually allocated across several commercial entities.

Now, Section 2(33) of CPA, 2019 defines a ‘product’, which refers to articles, goods, substances and raw materials capable of existing in gaseous, liquid or solid form. Standalone software and AI models were not included in this formulation. In addition, according to Chapter VI of the CPA, product liability is based on strict liability principles, which means that a manufacturer can be held responsible for a design flaw or failure to provide adequate warnings, regardless of whether they exercised “due care.” Taking in contrast, establishing a “deficiency of service” under Section 2(11) of the CPA automatically necessitates proving fault, negligence, or intentional neglect. Henceforth, in the case of non-deterministic AI systems with black-box architectures, where even the original developer of the foundation model cannot predict or clarify specific neural network outputs, placing the burden on individual consumers to demonstrate negligence in the model’s design or tuning parameters sets a vague & broad evidentiary challenge.

Furthermore, when an AI system is classified solely as a service, legal relationships are confined to the contractual connection between the downstream operator, Business D, and the end-user, X (taking the first instance & table as examples again). Downstream companies often dismiss claims of service deficiencies by showing they operated the software in good faith, following industry-standard procedures, or by citing End-User License Agreement / Terms & Conditions disclaimers. Meanwhile, upstream entities such as Foundation Developer A and Software Integrator C (for instance), those responsible for developing safety features or training datasets are shielded from consumer lawsuits through B2B indemnity agreements and lack direct privity with consumers. This does not imply that downstream operators should not be held liable. However, in the case of downstream and upstream entities, there could come instances where liability could be fragmented.

Here’s an example based on the first example. Say Consumer X utilizes "HealthBot," a diagnostic tool managed by Deployer D. Upon entering symptoms related to a problematic drug interaction, the AI incorrectly recommends increasing the blood thinner dosage. This error results in significant internal bleeding, leading to urgent hospitalization.

As Consumer X submits a compensation claim, the responsibility is distributed throughout the supply chain:

Entity

Role & Contribution to Harm

Legal Defense & Blame Shift

Legal Outcome Under CPA

Developer A

The base model contains some latent probabilistic hallucination bug under edge cases.

A blames entities C & D: A cites B2B contract stating the base LLM is “general purpose” and strictly prohibits unverified medical use.

Unreachable: Insulated from Consumer X by lack of contractual privity and B2B indemnity clauses.

Integrator C

C had fine-tuned the model using an outdated clinical database that missed safe dosage guidelines.

C blames A & D: Claims the hallucination originated in A’s core architecture, and D failed to add real-time guardrails.

Shielded: Protected behind its commercial software license agreement with D.

Deployer D

D had marketed "HealthBot" directly to consumers without medical-expert oversight.

D blames A & C: Asserts it acted in good faith using third-party tech, pointing to its app EULA disclaiming liability for AI errors.

Evades Liability: Escapes strict product liability because software is not a "product" under Section 2(33), and defeats service deficiency claims by demonstrating standard operational due care.

Since the Consumer Protection Act does not impose joint-and-several liability for digital supply chains, Consumer X is unable to hold Upstream A or C accountable in court. Conversely, Downstream D manages to avoid liability by citing service-deficiency standards and click-wrap disclaimers. As a result, accountability becomes fragmented across corporate agreements, leaving the harmed consumer without a clear pathway to compensation.

To resolve the legal lacunae created by multi-entity AI ecosystems, we suggest some statutory amendments across Section 2 and Chapter VI of the Consumer Protection Act, 2019:

  1. Redefining “Product” under Section 2(33): The statutory definition of a “product” must be expanded beyond physical items to explicitly include digital and intangible assets. This thereby must encompass standalone software, machine learning models, and autonomous AI applications, whether executed locally, embedded in hardware, or delivered remotely via cloud infrastructure and APIs. This can well-trigger strict product liability under Chapter VI, preventing tech firms from defeating claims by hiding behind “deficiency of service” fault standards.
  2. Codifying "Data-as-Consideration" under Section 2(42): Section 2(42) must be amended to eliminate the blind spot for “free-tier” and preview AI tools. The law must formally recognize that user prompt inputs, telemetry tracking, personal data extraction, and real-time interaction constitute valid non-monetary consideration. This ensures that users of freemium chatbots, ad-supported AI assistants, and preview models retain full legal standing as “consumers” before Consumer Commissions.
  3. Expanding the Scope of "Harm" under Section 2(22): The statutory definition of "harm" must evolve beyond physical injury and tangible property damage. It should explicitly incorporate tangible harms such as digital asset destruction, data corruption, and direct financial or economic losses resulting from automated decision-making and hallucinated outputs, provided the scope of harm is tangible and real.
  4. Establishing Joint-and-Several Supply Chain Liability: To resolve multi-entity supply chain fragmentation where foundation model creators, integrators, and deployers continuously shift blame, Chapter VI must introduce a statutory joint-and-several liability default. If an opaque "black box" AI system causes harm and the exact technical origin of the defect cannot be isolated by the end-user, downstream deployers and upstream developers must be held jointly liable to the consumer.