India's Foray Into Algorithmic Governance
The MeitY's proposal to replace human intervention with machine readable laws is a tempting prospect, but comes with several constitutional risks.
The Ministry of Electronics and Information Technology (MeitY) is reportedly exploring a framework to convert legal provisions directly into software code, enabling automated enforcement of India’s data protection and privacy obligations with “minimal human intervention.” The proposal is framed as a response to the speed of AI-driven cyber threats: governance, the argument goes, must operate at machine speed to counter attacks that do so. This is a seductive logic. It is also a constitutionally dangerous one.
To understand why, it helps to think carefully about what “law-to-code” actually means, and what having a non-human enforcer is likely to look like.
The Conversion Problem
Lawrence Lessig’s insight that “code is law” was originally a warning. The architecture of the internet, he observed, regulates as effectively as any statute, constraining what people can and cannot do, not merely what they shall or shall not do. The crucial distinction is enforcement: legal rules operate ex post, through courts and police; technical rules operate ex ante, preventing breach before it occurs. Code does not punish; it forecloses.
MeitY’s proposal inverts this dynamic and then some. The “law-to-code” or “law is code” paradigm—explored extensively by De Filippi and Hassan (2016)—describes a further step: not just code assuming the function of law, but law being drafted as code, with legal provisions written in a formal language designed for machine interpretation. The ambiguity that characterises natural language, which courts have long recognised as a feature, not a defect, of sound legislation, is deliberately engineered out. What remains is a set of rigid, self-executing rules incapable of responding to the unpredictability of human circumstances.
The implications for Indian constitutional law are serious and must be addressed with emphasis in upcoming consultations.
Proportionality and the End of Judicial Arbitration
The Puttaswamy test requires that any limitation on a fundamental right satisfy three conditions: legality, legitimate aim, and proportionality—specifically, that the restriction be the least intrusive means available. This last requirement is not merely procedural. It presupposes that a human decision-maker, possessed of contextual judgment, will assess whether the measure is calibrated to the facts of the case. Code cannot do this. A self-executing compliance system applies its rules uniformly and absolutely, incapable of distinguishing the routine case from the edge case that demands a different result.
De Filippi and Hassan’s analysis is instructive here. They note that “blockchain-enabled devices (their version of the manner in which code is to be enforced) cannot distinguish between routine situations and edge-cases that might require a different type of treatment.” The same is true of any automated enforcement system. A door-lock that will not open without a valid cryptographic token does not know there is a fire. A compliance algorithm that flags a consent failure does not know that the consent mechanism was inaccessible due to a disability. Code enforces what it was programmed to enforce, and nothing else.
This is not a limitation that better engineering can solve. It is a structural feature of formalised rule systems. Lessig himself acknowledged it: technical rules are “highly formalized and leave little to no room for ambiguity, thereby eliminating the need for judicial arbitration.” In P U Sidhique & Ors Vs Zakariya (2025), a division bench of the SC observed: “This court is of the view that human beings, and not artificial intelligence or computers, are entrusted with the duties of administration of justice as laws are to be interpreted with empathy and pragmatism and as a force of justice, not absurdity.” Put simply, the idea of law as code treats the elimination of judicial arbitration as a feature but the Constitution treats it as a problem.
Who Is Writing the Code?
There is a further issue that the “machine speed” framing obscures entirely. The conversion of legal provisions into executable code is not a neutral act of translation. It is an interpretive exercise, and one in which every interpretive choice made by the engineer has the force of law, without the procedural safeguards that constrain legislative or judicial interpretation.
Bhumika Billa’s account of law as an information system is useful here. Drawing on Shannon’s communication theory, she argues that legal coding—the translation of social reality into juridical form—is controlled by the agents who encode and decode it. Their identities, lived experiences, and biases shape what gets transmitted and what gets filtered as “noise.” A shift from text-driven to code-driven law does not eliminate this problem; it compounds it, transferring interpretive power from legal experts to technical experts, with far less transparency and no democratic accountability. The legal expert at least operates within a system of institutional checks, such as appeals, precedent, published reasoning. The software engineer does not.
The Flexibility Argument in Reverse
Proponents of law-to-code frameworks often point to their adaptability: machine learning systems, unlike rigid rule-based code, can learn and evolve. This is precisely De Filippi and Hassan’s observation about ML, that it introduces “code-based rules which are inherently dynamic and adaptive, replicating some of the characteristics of traditional legal rules characterized by the flexibility and ambiguity of natural language.”
But the analogy fails at the question of legitimacy. When a judge adapts the application of a legal rule to novel circumstances, that adaptation is visible, reasoned, and subject to appeal. When a machine learning system adapts its enforcement parameters in response to new data, the adaptation is opaque, unreasoned, and effectively unreviewable. ML based systems are seen as “black boxes,” owing to their opacity—which itself may emerge for a variety of reasons. “As laws are incorporated into a code-based system whose rules dynamically evolve as new information is fed into the system,” De Filippi and Hassan note, “it might become difficult for people to not only understand, but also question the legitimacy of the rules that are affecting their lives on a daily basis.”
This is not an abstract concern. The Digital Personal Data Protection Act, 2023, already carries significant structural deficits in terms of state exemptions and the weakness of the Data Protection Board as an adjudicatory forum—as we will see. Automating enforcement within this framework accelerates these structural deficits, giving the state a machine-speed mechanism to process compliance determinations in a regime that already tilts heavily toward executive discretion.
Speed Is Not a Constitutional Value
The stated rationale for the proposal—that AI-powered cyberattacks operate at machine speed, so governance must too—is worth examining on its own terms. It conflates two different functions of law: the function of incident response (which can and does involve automated technical countermeasures) and the function of rights adjudication (which cannot). Rights adjudication, as we have established, requires human adjudication for subjective context interpretation—in the absence of which, constitutional rights may be compromised. The presumption that speed itself is an adequate reason to remove such human oversight is constitutionally unfounded.
The comparison to France and New Zealand’s deployments in taxation and welfare is also less reassuring than it appears. Those domains involve the calculation of entitlements under rule-bound schemes, functions where formalisation introduces efficiency without eroding fundamental rights. Data protection and privacy enforcement are categorically different. They involve the exercise of discretion over the rights of individuals against the state, where Puttaswamy demands the most rigorous application of proportionality review.
A Structural Critique
The law-to-code proposal does not emerge in a regulatory vacuum. It emerges against the specific backdrop of the DPDP Act and Rules which create a framework that has already made a series of deliberate structural choices that favour executive discretion over independent oversight. Click here for an analysis of the framework itself.
The most significant of these is the design of the Data Protection Board of India. The Board, which is the Act’s primary enforcement body, is established by the Central Government, staffed subject to Central Government approval, subject to Central Government control over service conditions, and its members are removable by the Central Government. It lacks suo motu powers to initiate inquiry and can act only in response to breach notifications filed by fiduciaries, or complaints filed by data principals. It cannot conduct raids, order forensic imaging, or enter premises. Its investigative capacity is entirely dependent on executive cooperation. As a structural matter, it cannot autonomously scrutinise the State, which is simultaneously the single largest data processor in the country and the authority that controls the Board’s budget, staffing, and tenure.
This appears to be a deliberate regulatory choice. S.17(2)(a) of the Act exempts entire classes of state processing on grounds as elastic as “public order” and “friendly relations with foreign states” without statutory safeguards, procedural constraints, or independent review. Rule 23 compounds this by permitting the Central Government to access essentially any personal data held by any fiduciary, while simultaneously barring the fiduciary from informing the data principal that such access has occurred. The data principal is thereby deprived of the very knowledge necessary to invoke whatever remedies nominally exist.
Into this architecture, MeitY now proposes to embed automated compliance enforcement. The effect is precisely the opposite of what the machine-speed framing implies. It is not that governance will become faster and more rigorous. It is that the enforcement of compliance will be delegated to systems whose parameters are set by the same executive that controls the regulator, without the residual check of a judge who have the power to apply a proportionality test. The law-to-code proposal, in the Indian context, is not a supplement to institutional capacity. It is a replacement for it.
What the MeitY proposal illustrates is a pattern that has appeared repeatedly in India’s digital governance architecture: the substitution of technical solutions for constitutional ones. The same impulse that produced a biometric-linked identity infrastructure as a substitute for targeted welfare delivery, and a mandatory certification regime as a substitute for self-determined gender recognition, is now producing a law-to-code framework as a substitute for institutional capacity-building in regulatory enforcement.
In each case, the technical mechanism appears to solve a real problem , from access, to speed or accuracy, while systematically eroding the rights of those it is meant to serve. Code, as Lessig observed, is never found; it is only ever made, and only ever made by someone. The question of who makes India’s compliance code, under what mandate, with what accountability, and subject to what review; that question is ought not to be answered by the speed of AI cyberattacks but by the Constitution.
India already has a data protection law. What it needs is a data protection regulator with genuine independence, adjudicatory capacity, and the institutional resources to function. Law-to-code is not a substitute for that. It is a way of avoiding the harder work of building it.

A very interesting read!