[Madhvendra Jha and Trayambak Pathak are third-year law students at Dr Ram Manohar Lohiya National Law University, Lucknow. In this piece, the authors interrogate whether India’s fragmented regulatory architecture can effectively govern GCCs as they evolve from back-office service centres into AI-driven innovation hubs. The piece argues that India needs a unified National GCC Framework to coordinate regulation of Agentic AI, data governance, intellectual property and cybersecurity, shifting the regulatory approach from convenience to coherence.]
Introduction
A Global Capability Centre (“GCC”) is a strategic offshore unit established by a multinational organisation in another jurisdiction to perform specific business and technology functions. For example, a US technology company may establish a GCC in India to manage its AI systems and data centre for global operations. By doing so, an organisation can reduce costs and a technological, logistical or regulatory load on itself. India currently hosts over 1,700 GCCs, generating a combined commercial revenue of USD 64.6 billion in FY2024, with an annual growth rate of 9.8%. The sector has witnessed a 60% growth since FY2019 and is projected to reach approximately US$110 billion by 2030. GCCs have become integral to global business operations, with more than 176 Fortune 500 companies and 67% of the Fortune 30relying on them to drive critical operations.
These GCCs are the key centres for software engineering, artificial intelligence (“AI”) development and cloud computing. As MNCs entrust Indian GCCs with greater responsibility over proprietary datasets and algorithmic systems, they have become integral components of the global technology value chain.
This transformation has raised broader legal questions concerning cross-border accountability, tax implications, labour structuring, cybersecurity and data governance. As GCCs evolve from service centres to innovation hubs, the existing fragmented legal architecture is increasingly struggling to address the complex technological risks they pose. Thus, arguably India should not continue to rely on a governance model that was designed for an earlier generation of GCCs and develop a unified framework that is not only convenient but supports the overall GCC ecosystem.
This article aims to address such gaps in legal architecture. It examines three interrelated regulatory challenges: intellectual property (“IP”) rights and cybersecurity, Agentic AI and intermediary liability, cross-border data governance and institutional fragmentation vis-a-vis GCC’s. These three faces of the same structural mismatch, create a regulatory overload. Ultimately, the piece introduces a national governance framework with core institutional features.
The Fragmented Model: Design, Not Default
India’s fragmented regulatory architecture is neither accidental nor irrational; it reflects a deliberate institutional choice. This is because, rather than creating a dedicated legal regime for GCCs, the law regulates entities according to the specific activities they perform. This approach assumes that GCCs primarily function as back-office service providers whose legal obligations can be compartmentalised across specialised regulatory domains. Consequently, sector-specific regulators have been able to preserve their expertise, avoid regulatory duplication and respond to technological developments through targeted statutory amendments instead of comprehensive legislative reform. However, this rationale is becoming increasingly inadequate as GCCs evolve into innovation-driven technology hubs.
For example, modern technologies such as Agentic AI, transcend traditional regulatory boundaries. A single AI system may simultaneously process personal data, generate intellectual property, make autonomous decisions and perform functions that influence its intermediary status. The compartmentalised assumptions underlying sectoral regulation therefore no longer correspond to the realities of contemporary GCC operations, creating overlapping compliance obligations and regulatory uncertainty.
Agentic AI Risks and The Limits of Safe Harbour
India’s value proposition for global enterprises has evolved from cost arbitrage to skill arbitrage and now further transformed into technology arbitrage. One of the key components of it is Agentic AI, autonomous software systems that perceive, reason and act in digital environments to achieve goals on behalf of human principals. They are capable of executing economic transactions, strategic interaction and interacting with digital environments to function as powerful components within larger workflows. According to EY’s GCC Pulse Survey 2025, 58 percent of Indian GCCs are investing in Agentic AI. Across industries, it is increasingly deployed for multilingual voice bots, cloud modernisation, smart contracting, fraud detection and anti-money laundering.
A White Paper released by Publicis Sapient and AIM Research identifies AI governance as a core challenge for GCCs. They are finding it difficult to ensure transparency and human-in-the-loop oversight to mitigate algorithmic bias, discriminatory outcomes and risks arising from opaque AI decision-making.
Likewise, Section 79 of the Information Technology Act, 2000 grants safe harbour protection to intermediaries; however, this immunity is conditional rather than absolute. An “intermediary” is defined as “any person who on behalf of another person receives, stores or transmits that record or provides any service,” which expressly includes search engines, online marketplaces, and payment platforms. The protection is available only where the intermediary performs a neutral or passive role.
The Supreme Court’s evolving jurisprudence also reflects a gradual narrowing of unconditional intermediary immunity. In Shreya Singhal v. Union of India, the Court interpreted Section 79 as protecting neutral intermediaries while recognising that immunity is contingent upon compliance with statutory obligations after receiving actual knowledge in accordance with law. [paras. 111–117]
Subsequently, in Christian Louboutin SAS v. Nakul Bajaj & Ors., the Delhi HC distinguished between active and passive intermediaries by laying down a comprehensive framework to determine whether a platform merely acts as a conduit or actively participates in the transaction, to remove the “ring of protection” provided by Section 79. It led to the framing of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, laying down clear obligations relating to content monitoring that need to be adhered to if they want to enjoy the protection of safe harbour.
The emergence of Agentic AI complicates this framework. Unlike conventional intermediaries, Agentic AI systems blur the distinction between an intermediary and a publisher. In IndiaMART InterMESH Ltd. v. OpenAI Inc., ChatGPT was argued to be an originator rather than an intermediary or search engine. Similarly, in response to concerns over Grok-generated content affecting the dignity of women and children, MeitY, through its Direction dated 2 January 2026, directed X to review Grok’s technical design, governance framework and safety guardrails.
Consequently, if an Agentic AI deployed by a GCC independently generates defamatory or IP-infringing content, the availability of Section 79 protection may depend on analysis of the “active-passive test” regarding the specific task performed by the specific AI model, which is quite ambiguous in nature and needs proper clarity. For example, cloud hosting would be considered a Passive task, while sending emails or negotiating contracts by AI models can be considered an Active task.
IP Registration and Cybersecurity Dilemma
The growing technological sophistication of GCCs has significantly increased their dependence on software and data infrastructure. Although the underlying R&D is often undertaken in India, legal ownership of the resulting IP generally rests with the foreign parent entity through contractual assignments. Foreign headquarters typically retain control over patent filing, commercialisation and litigation strategy, making IP a critical component of group valuation and operational control. This model creates an illusion of innovation by showcasing India’s technological capabilities while limiting domestic ownership of the IP created within its borders. This results in a substantial portion of high-value innovation bypassing India’s IP ecosystem, reducing opportunities for royalty income and tax revenues.
Unlike the earlier outsourcing model, where Indian IT companies like TCS largely patented their innovations domestically, multinational GCCs increasingly register patents in their home country. Experts, like Shridhar Vembu have therefore advocated that the government should not settle for “asymmetrical terms,” making it legally mandatory for GCCs and foreign AI-based corporations in India to register the resulting IP locally or license it to the parent entity abroad. Accordingly, these concerns cannot be adequately addressed through incremental amendments to fragmented IP related statutes alone. Instead, they warrant a coherent national framework providing certainty and consistent standards.
GCCs increasingly store proprietary datasets and IP in hybrid cloud environments, exposing them to sophisticated cyber threats, including the “toxic cloud trilogy”– publicly exposed, critically vulnerable and highly privileged assets. Their reliance on employee access to sensitive technological and business information further heightens the risk of trade secret leakage, particularly in high-attrition industries and through moonlighting. The rapid adoption of cloud computing and AI has further expanded the cyber risk landscape, making cybersecurity a strategic priority for 73% of GCCs in India. Increasing risk needs a regulatory safety net which can be implemented uniformly in the nation.
Navigating the Data Governance Rabbit Hole
Cross-border data governance presents another manifestation of the same regulatory gap, as most of the GCC firms are in the early stages in spite of the 14-month deadline. EY suggests that less than 10% of GCC firms currently perform dedicated privacy-focused functions.
The constitutional foundation of India’s data protection regime was laid by the Supreme Court in Justice K.S. Puttaswamy (Retd.) v. Union of India, where informational privacy was recognised as a facet of the fundamental right to privacy. DPDPA builds upon these principles. The enactment of the DPDPA with international obligations under the European Union’s General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”) has created compliance burdens for GCCs as they now have to align India-specific requirements with international frameworks. This overburdens the already existing regulatory overlap for GCCs.
The DPDPA adopts a consent-based framework with certain legitimate-use exceptions; the GDPR relies on multiple lawful bases for processing and imposes stringent requirements on data minimisation and cross-border data transfers. While the CCPA adopts an opt-out model, granting consumers extensive rights over the collection and sale of their personal information. These layers of regulations create prominent operational friction for GCCs.
Towards a Central GCC Governance Framework
The foregoing discussion demonstrates that these challenges are interconnected rather than isolated. Hence, the solution must also be institutional rather than sector-specific. Even though India now hosts more than half of the world’s GCCs, there is no single dedicated National GCC Framework across India. Several states have introduced GCC policies to attract investment. While this fosters healthy competition, the resulting regulatory fragmentation may create long-term governance challenges. The Ministry of Electronics and Information Technology (“MEITY”) formed a panel to discuss the possibility of building a national framework for GCCs. Similarly, the Confederation of Indian Industry also released a report on the National Framework on GCCs. It should be similar to the IFSCA (Global In-House Centres) Regulations, 2025 governing GIFT City, mandating a “Fit and Proper Test” for the Compliance Officer and Principal Officer. The framework should establish a dedicated National GCC Authority institutionalising public-private collaboration, functioning under the MEITY.
To increase patent filing locally, the government should provide Patent-Linked Tax Incentives, adopting Ireland’s Knowledge Development Box Model. India could introduce reduced corporate tax on income derived from patents registered in India, lower tax on royalties from Indian-owned IP and accelerated deductions for Indian patent portfolios. Mandatory registration requirements may cause difficulties in doing business for foreign entities; thus a co-ownership model must be introduced to encourage joint ownership, exclusive Indian licence and revenue-sharing. U.S. Chamber of Commerce’s 2024 International IP Index ranked India 42nd out of 55, showcasing that strong IP enforcement and financing are needed to build trust for companies voluntarily locating their valuable IP in India, as seen in Singapore.
The proposed Digital India Act, 2023, which will succeed the current IT Act, must adopt a risk-tiered regulatory approachsimilar to the European Union Artificial Intelligence Act, classifying Agentic AI according to the degree of autonomy and potential harm. Higher-risk systems, such as those undertaking financial transactions or contract negotiation, should be subject to stricter governance, mandatory human oversight, pre-deployment testing and periodic audits. The principal officer should oversee the functioning of Agentic AI, while high-risk deployments should undergo independent technical and legal conformity certifications.
MEITY should issue guidelines distinguishing passive AI functions (such as search, hosting and indexing) from active functions (such as contract execution and autonomous content generation), thereby clarifying the availability of safe harbour protection under Section 79 for GCCs deploying Agentic AI. It will bring clarity and reduce litigation proceedings
Establishing Privacy Centres of Excellence (“CoEs”) within India’s GCCs will ensure data privacy compliance with global data protection regulations. DPDP is not a constraint on India’s GCC growth but an upgrade. A Data Governance Sandbox for multinational GCCs must be established to issue sector-specific guidance on cross-border data processing and international data transfers. A pilot programme may be tested in GIFT City for initial review.
Conclusion
India has already entered the “GCC 3.0” phase with an innovative global strategy and is transitioning to the next phase, “GCC 4.0,” which is the Agentic-AI-first GCC model. Existing legislation addresses the issues individually, operating in institutional silos, which results in fragmentation rather than coherent governance. A unified national framework should therefore be understood not as an exercise in regulatory centralisation, but as an institutional mechanism for coordinating existing laws that increasingly operate upon the same technological ecosystem.
Such a framework would strengthen India’s credibility as a GCC destination. Therefore, India must act swiftly to strengthen its regulatory architecture; otherwise, its leadership ecosystem may gradually erode as emerging destinations such as the Philippines, Poland and Vietnam increasingly position themselves as competitive alternatives, contributing to the rise of a new “GCC growth triangle.” A simple change in principle is all it needs, from convenience to coherence.