Why this matters
If your firm is weighing a foreign-hosted legal AI tool — Harvey, Legora, or any cloud product that stores your documents abroad — the first question is always the same. Is that even legal in India?
The short answer today: yes, mostly. But "today" is carrying a lot of weight in that sentence.
India's data law is the DPDP Act, with rules notified in November 2025. Most people expect it to demand hard data localisation — Indian data kept on Indian soil. It does not.
How the rules actually work
DPDP uses a "negative list" for sending data abroad. In plain terms: you may transfer personal data to any country, unless the government specifically names that country as off-limits. This is the opposite of Europe's approach, which only allows transfers to a short list of pre-approved "safe" countries.
So the default is open. As of now, the government has not published any restricted-country list. A foreign legal AI tool can lawfully process your data abroad.
That sounds like a green light. It is not. Three things complicate it.
First, there is no grace period. When the government does name a restricted country, the ban takes effect the day it is published. There is no transition window written into the law. A tool that is compliant on Monday could be off-limits on Tuesday.
Second, sectoral rules already bite. DPDP lets existing regulators keep their stricter localisation rules. If your client is a bank, the RBI already requires certain payment data to stay in India. DPDP does not loosen that. So even inside a permissive regime, some of your matters carry hard localisation right now.
Third, large platforms face extra duties. Companies the government designates as "Significant Data Fiduciaries" — broadly, big or high-risk data handlers — may face additional localisation on certain data, decided by a government committee. Those details are still pending.
And underneath all of it sits a constant. Whatever the destination, you still need a lawful basis — usually consent — plus proper notice and contractual protections with the foreign processor. The cross-border provisions become fully operational around May 2027.
What this means for your firm
Put the pieces together and a clear picture appears. The risk is not that foreign legal AI is banned. The risk is that the ground can shift under you, quickly, with no warning.
So the smart question is not "is it allowed?" It is "what happens if it stops being allowed?"
That reframes the whole decision. You are not just choosing a tool. You are choosing an architecture — and how much room to manoeuvre it leaves you.
A tool that can only run on a foreign server leaves you exposed to a notification you cannot predict. A tool that can run locally, or in an Indian data centre, gives you a fallback. This is why the open-source option — something like Mike OSS, which runs on your own machines — is interesting beyond its price. It removes the cross-border question altogether.
Three practical moves, today:
Map your data. Know which matters involve regulated data — banking, insurance, health — where sectoral localisation already applies. Those cannot sit on a freely-foreign tool.
Read the contract. Your agreement with any legal AI vendor should state where data is stored, let you require it to move to India, and pass DPDP duties down the chain.
Keep an exit. Favour tools that can be redeployed inside India if the list changes. Room to manoeuvre is the whole game.
None of this is a reason to avoid Harvey or Legora. They are excellent products. It is a reason to deploy them with your eyes open — to treat the question as an engineering and contracting problem, not a yes or no.
That is where aircounsel comes in. We help firms and in-house teams pick, deploy, and paper their legal AI so that a change in the rules becomes a configuration change, not a crisis.