All insights

State Modernisation

State AI Policies Compared: A Working Map

· 9 minute read

A working map of state AI policies is a method — date, owner, audience, enforceable duty — not a frozen list. Policies change. Press notes are not PDFs.

Someone in a state IT society printed a two-year-old blog titled states with AI policies and used it as an annexure. Two of the listed PDFs had been superseded. One was an industry-incentive scheme with no departmental duty. One policy was a conference speech. The committee then argued about whether they were behind Telangana instead of about whether their own circulars were live.

India's states publish IT policies, ESDM policies, data-centre policies, AI missions, CoE announcements, and sometimes genuine internal-use guidance. The Union has also published India AI Governance Guidelines (MeitY, November 2025) — guidelines, not a state statute. None of this is a single map that stays still. This article is a method for drawing a working map, with examples that will age. We will hedge on purpose.

It is written on 17 August 2026 for departmental CIOs and society CEOs. It is not legal advice. Before you cite a state policy in an RFP, open the PDF on the state domain and write the download date in the file.

Four fields every entry needs

Date and status. Notified, draft, expired, superseded. A 2020 IT policy that mentions emerging technologies is not an AI policy. A 2025 mission that is only a press note is not notified. Owner. IT department, planning, a society, a mission office, a chief minister's task force. Owner tells you who can sign a deviation and who cannot.

Audience. Industry incentives (land, power, subsidies, CoEs) versus internal government use (how departments may buy, isolate, audit). Most AI policies are the first. Vendors love them. Departmental isolation lives in the second, or in a finance or e-governance circular that never uses the word AI. Duty. Does any sentence require a department to do something testable — security audit, data residency, human approval, Hindi or state-language, GeM route — or does it only encourage? Encouragement is not a specification.

Example readings, not a complete or current catalogue. Re-open the PDF.
Kind of instrument (examples)Typical audienceWhat a department can take from it
State IT / ITeS / ESDM policy (many states, rolling years)IndustryIncentives, definitions; rarely your isolation clause
Named AI mission or CoE (e.g. public Tamil Nadu / Gujarat-style announcements)Mixed: skills, industry, a few pilotsA political owner; still not a DPA
Collaboration / MoU announcements (often Maharashtra / Telangana-style headlines)Public narrativeAlmost nothing enforceable in an RFP
e-Governance / SDC / security circularsDepartmentsOften the real AI policy — hosting, audit, NIC path
MeitY India AI Governance Guidelines (Nov 2025)National guidancePrinciples; not a state purchase code

Examples that will age — treat them as illustrations

Tamil Nadu has publicly described an Artificial Intelligence Mission and a sequence of digital-service programmes. Read the current mission note for owner and duration. Do not assume every department inherited a duty. Telangana has been visible on data, emerging-tech and industry framing. Visibility is not the same as a line-department isolation rule. Open the live IT/data instrument.

Gujarat has announced AI centres of excellence in more than one sectoral framing (cities, health, agriculture appear in public notes). CoEs are capacity. They are not a mutation protocol for the revenue department. Maharashtra's public trail is often collaboration-led — partnerships, urban tech, departmental pilots. Partnerships need a DPA the day they touch PII. Karnataka's stack is industry-heavy; Uttar Pradesh's public digital programmes are volume-heavy. Neither fact writes your annexure. If by the time you read this a new state has notified a genuine internal AI use protocol, add it to your map with the four fields. If a listed example is dead, delete it. The method stays.

How to compare without a league table

Compare like with like. An industry subsidy policy versus another industry subsidy policy. An SDC circular versus another SDC circular. Do not score Gujarat's CoE press against Kerala's hosting circular and call it science. Prefer instruments that name hosting, logs, language, and human approval. Those transfer into an RFP. Adjectives do not. Note conflicts. A state AI brochure that says cloud first and an SDC circular that says this class of data stays here is a conflict the file must resolve. The newer circular with the more specific data class usually wins — but counsel, not a vendor, says so.

What to put in your RFP when the map is messy

Cite the instruments that actually bind the buying department: finance rules, SDC hosting note, language circular, security-audit habit, DPDP. If a state AI policy adds a testable duty, cite that paragraph. Do not cite another state's policy as if it bound you. As in Telangana is not a clause. Do not promise alignment to every guideline on IndiaAI's website. Name one or two, and say they are guidelines.

Two rooms you can walk into

Maps that aged versus files that did not.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note.

We need a simple list of states that have AI policies.

Lists go stale in a season. Publish the method and a dated snapshot if you must list, with a verify PDF warning. We will not ship a frozen roll-call as if it were current.

Union guidelines already replace state policy.

They do not. MeitY guidelines do not repeal a state finance rule or an SDC circular. Read both.

If our state has no AI policy we cannot buy agents.

You buy under existing procurement, hosting and privacy instruments. An AI policy is neither necessary nor sufficient.

Industry policy is enough to attract vendors.

It attracts incentive-shoppers. Departmental isolation language attracts people who can survive a pcap.

A two-week working map for one state

Do this for your state first. Add neighbours only if you are a vendor watching tenders.

  1. Week 1: download every live IT, ESDM, data, e-governance and AI-titled PDF from state domains. Ignore unsourced blogs. Fill the four fields.
  2. Week 2: pull SDC, language and security circulars — the unglamorous duties. Resolve conflicts in a one-page note. List what you will cite in the next RFP. Date the map and set a quarterly refresh.

How this shows up in the file

Subject: Working map of instruments relevant to departmental agents. Snapshot date recorded. Industry AI/IT policies listed for context only. Binding or practically binding duties for this department named (SDC hosting, language, security audit, DPDP, finance route). Union AI governance guidelines cited as guidance, not as a purchase code. This map will be refreshed quarterly; stale blog lists will not be annexed.

What we will and will not claim

Prcept AI will read your live PDF, not last year's listicle. We will not tell a committee they are behind a neighbouring mission. If your only AI policy is an incentive scheme, we will still ask for the SDC circular.

This article is informational field guidance for Indian universities and public institutions, not legal, procurement, audit or engineering advice. Confirm against the live Gazette, GFR, state financial rules, GeM terms, UGC text, GIGW, DPDP commencement, departmental manual and your counsel before you file it.

How to sequence this in a state, not a slide

“State AI Policies Compared: A Working Map” is a department problem. A P1 CIO/CTO should name the legacy system, the officer who owns the file, and the citizen charter clock before buying “state AI policy India”.

A working map of state AI policies is a method — date, owner, audience, enforceable duty — not a frozen list. Policies change. Press notes are not PDFs. Do not invent league tables of states. Read tenders and policies. Election Model Code of Conduct can freeze a rollout. NIC is a partner, not a villain. SDC readiness is GPU, power, ops and egress — not a logo.

  • Audit the legacy store first.
  • Keep mutation and money as officer actions.
  • Map SLAs to the citizen charter.
  • Budget change requests after go-live.

Close this loop before the next CAB

Put “State AI Policies Compared: A Working Map” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “state AI policy India” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

Which Indian states have an AI policy?
The list changes. Some have named missions or CoEs, many have IT policies that mention AI, and some of the binding language sits in e-governance circulars. Draw a four-field map from live PDFs. Do not rely on a blog roll-call.
Is an industry AI policy enough to write an RFP?
Usually no. You need procurement, hosting, security and privacy instruments. Cite a policy paragraph only if it creates a testable duty.
Do MeitY's November 2025 guidelines bind states?
They are governance guidelines, not a state purchase code. Useful as principles. They do not replace GFR, state rules or your SDC note.
Should we copy another state's AI policy into ours?
You can read it. You cannot paste it as if it knew your Act, language and SDC. Compare like with like; write your own duties.
How often should a working map be updated?
At least quarterly, and whenever you issue an RFP. Write the download date next to every citation.

Sources