A new report argues that India is assigning AI obligations to the wrong people, and offers a way to work out who can actually do anything about a given harm.

Functional Taxonomy of Actors in the AI Value Chain, published by The Quantum Hub in September, breaks the generative AI value chain into eight actor classes and five functional attributes. Mapping one against the other produces a matrix. It is meant to show which actor has the technical ability to prevent, mitigate or respond to a given risk.

Why it matters: India regulates this space through categories that were not built for it. “Intermediary” under the IT Act now covers an enormous range of businesses with very different capabilities. MeitY’s advisories have repeatedly landed on companies that could not comply if they wanted to. The report’s underlying claim is simple: an obligation placed on an actor without the matching control is not a safeguard. It is a compliance cost with no safety benefit.

What the taxonomy actually does

The report identifies eight actor classes. They are physical infrastructure providers, cloud and infrastructure access providers, data actors, foundation model developers, orchestration and middleware providers, model adaptors and deployers, distribution platforms, and end users.

Against those, it sets five functional attributes, each a form of control:

The insistence on function rather than entity is the report’s central move, and it is the right one. A single company may occupy several of these positions at once, and the controls available to it differ at each. Asking “what is this company” produces one answer. Asking “what can this company do about this specific output” produces several.

The most useful passage is on foundation model developers. Control after release, the report argues, is not absolute: it depends on how a model is released. With closed API models, a developer retains visibility and can push a fix downstream. With open-weight releases, that leverage falls sharply, and with fully open-source releases, it can disappear. A safety intervention at the model layer reaches everyone who uses a closed model. It reaches only those who choose to adopt it in an open one.

What it does not cover, and says so

The scope is generative AI output — text, audio and audiovisual content. Autonomous decision-making, autonomous action and real-world outcomes are outside it. Agentic systems are addressed only insofar as they produce output of that kind.

The report is candid about this. There is a reasonable argument that orchestration is where much agentic control sits, so the framework reaches further than its scope suggests. But the gap matters. The deployments Indian regulators are most exercised about sit inside a bank, a hospital or a trading desk. Those are agentic decision systems, not content generators. A taxonomy of who controls what a model says does not answer who is responsible for what a system does.

Three things the framework does not reach

It has no account of market power. The matrix records what each actor class can control. It does not record that one company may occupy five of the eight classes at once, and that occupying five is itself a governance fact. Applied to a vertically integrated firm, a functional taxonomy produces a tidy list of separate functions where a reader might see a single concentration of power. The report’s own logic is to assign responsibility where control sits. It does not obviously hold in a case where control sits everywhere.

Function-specific categories create exits. The sharper the definitions, the easier it is for a well-advised company to say the function belongs to a different corporate entity — possibly one with no Indian presence. Entity-based regulation is crude, but crudeness is what makes it hard to route around. Precision has a cost, and the report does not price it.

“Can” is not “should”. Where two actors are both technically capable of the same control, the matrix records capability at both. A guardrail can sit at the model layer or at the deployer’s. Participants at the launch pressed the point: the reason a model developer often cannot see the deployment context is a commercial arrangement, not a technical limit. Enterprise customers buy that opacity. A framework that reads control off current market practice describes the industry’s allocation of responsibility rather than testing it. A regulator asked to choose between two capable actors gets no help from the matrix.

The case the framework has to answer: open models

The sharpest challenge to the framework is a model nobody controls.

Take an open-weight model downloaded and run on a local server, fine-tuned by an individual, with an agentic layer on top calling other tools. Participants at the launch put this scenario directly to the authors. There is no cloud provider to serve and no deployer with a terms of service. Frequently, there is no way to identify who is running it at all. The framework answers that much of the relevant control sits at the orchestration layer, which is right and is one of the report’s better insights.

But it exposes a tension the report does not resolve. If control cannot be located downstream, the temptation is to move upstream and restrict release at the model layer instead. That is the opposite of what a functional taxonomy is for. It is also the outcome the report is implicitly arguing against. A framework built to push obligations toward whoever can act has no answer where nobody can be found.

What a functional framework could actually be used for

One proposal raised in discussion is worth more attention than it got. Rather than using the taxonomy to assign liability, use it to locate mandatory evaluation. A system would have to be assessed at defined points between actor classes, with the actors left to allocate the cost between themselves by contract.

That has two advantages. It does not require a regulator to adjudicate between two capable actors. And because evaluation obligations attach at every layer, they fall most heavily on whoever occupies the most layers. The market-concentration problem is addressed rather than ignored.

It runs into a gap India has not filled. India has no AI safety institute with access to frontier models for testing. It has no independent evaluation ecosystem either — no body of evaluators whose income does not depend on the companies whose systems they would assess. Participants noted that the United Kingdom’s institute has built both the technical capacity and the credibility with labs that such access requires. An evaluation mandate without evaluators is a clause, not a control.

A taxonomy is not a neutral object

The United Kingdom’s own AI taxonomy, produced for research coordination rather than liability, makes a point worth holding alongside this one. Its authors write that the complexity and interconnectedness of the layers is such that creating clear-cut boundaries is “exceedingly difficult and perhaps not even desirable”, comparing the exercise to identifying colours on a rainbow without being able to say where one ends.

That is a taxonomy built to help people talk to each other. TQH’s is built to help allocate obligations. The second use is more demanding than the first, because boundaries that are merely indicative in a research framework become the edges of liability in a regulatory one.

Others have gone the other way. Some companies, which represent enterprise software companies, have settled on three categories: developer, deployer and integrator. It treats even the third as a complication when explaining the ecosystem to regulators. Eight classes and five attributes are a more honest description of how these systems work. Whether it is a more usable one for a regulator drafting a rule is a different question, and the report does not argue it.

There is also a precedent for keeping functional distinctions inside a horizontal law. Article 50 of the European Union’s AI Act covers transparency obligations for synthetic content. It distinguishes providers from deployers, and leaves implementation to the AI Office. A single instrument can carry functional granularity without being built around it.

Who paid for it

The report discloses on its first page that it was produced with inputs from the Indian Governance and Policy Project and that it “would not have been possible without the generous funding support of OpenAI”.

TQH’s disclosure practice is better than the Indian norm. It publishes a standing policy of naming funders, states that the funder shaped research scope and provided methodological inputs, and asserts editorial independence and sole responsibility for the analysis. Most policy research in this country does not tell readers any of that.

It still needs saying plainly. The report’s central argument moves responsibility away from a single-point, upstream allocation and toward a distributed, function-specific one. The actor class that stands to gain most from that move is the foundation model developer. The report was funded by a foundation model developer. Both things can be true without anyone having acted improperly, and a reader deciding how much weight to give the framework is entitled to both.

The report’s closing line is the best sentence in it: durable AI governance depends on assigning responsibility where control actually sits, rather than assuming legal categories will always map neatly onto technical capabilities. The same scepticism is worth applying to the question of who is doing the assigning.

Questions MediaNama has sent

To The Quantum Hub:

  • What role did OpenAI play in shaping the research scope and the methodological inputs referred to in the disclosure?
  • Did the funder review or comment on drafts, and were any changes made as a result?
  • How would the framework handle an entity occupying several actor classes simultaneously?
  • Does TQH intend to extend the taxonomy to agentic and autonomous decision systems?

To MeitY:

  • Has the Ministry received or considered this report, and does it use any functional framework when framing obligations for AI systems?

This article will be updated when responses are received.

Also Read: