Key Details
The September 2026 discussion paper, Enabling Cross-Border Data Interoperability for AI Systems, proposes four illustrative access pathways, with safeguards determined by data sensitivity, intended use and risk.
Data category | Proposed treatment |
|---|---|
Aggregate: summarised or statistical data | Lower-friction exchange with aggregation and de-identification |
Functional: detailed, non-identifiable data | Commercial or research access with privacy-preserving techniques |
Controlled: identifiable data | Restricted access through agreements, legal safeguards and audit trails |
Sovereign: strategic or national-security data | Raw data remains domestic; analysis occurs in a controlled environment, with only approved outputs leaving where permitted |
The paper is a basis for discussion, not an adopted policy or formal position of the PSA Office. Its proposed framework would complement existing governance arrangements.
Keeping data local does not contain every AI risk
Trained models, model parameters and analytical outputs can carry information across borders without moving the underlying dataset. AI can also infer sensitive attributes from apparently non-sensitive information. The paper therefore proposes assessing what users can access and produce, alongside where data is stored.
For higher-risk uses, model-to-data processing would bring analysis to the dataset while keeping raw records in a controlled environment. Access conditions could be reviewed when model capabilities, purposes or data combinations change.
Compatible systems need shared meaning and enforceable safeguards
Drawing on national and regional approaches, the framework combines three pillars:
Compatibility: common technical requirements and data definitions, allowing different domestic systems to work together.
Accountability: agreements, certification and continuing checks covering authorised purposes, subsequent transfers and derived outputs.
Coordination: cooperation between regulators and institutions, including recognition of relevant certifications and assessments.
The approach preserves domestic regulatory authority while seeking workable arrangements between countries, without requiring identical laws or systems.
Health data illustrates both the foundations and the gaps
India’s health-data ecosystem provides an application of the framework. Existing electronic health-record and imaging standards support exchange, while ICMR’s emerging Metric-based Integrity and Data Assessment System (MIDAS 2.0) offers approaches to assessing dataset quality, AI readiness and residual privacy risk.
The paper also cites India–France cooperation to test the Data Empowerment and Protection Architecture (DEPA)for secure, purpose-specific and traceable health-data access. These initiatives illustrate potential building blocks; existing standards and approvals do not yet provide a single coordinated route covering cross-border AI research, secondary use and model outputs.
Policy Relevance
For India, the proposal shifts attention towards governing access throughout the AI lifecycle. Research institutions and firms would need clarity on permitted uses, responsibility for derived models, and the conditions that trigger reassessment.
The paper identifies two institutional priorities:
Coordinated decisions: an interdisciplinary AI-data mechanism within the National Data Governance Committee could connect sectoral, legal, ethical and cybersecurity expertise while retaining existing regulators’ authority.
Testable standards: the Bureau of Indian Standards and sectoral bodies could coordinate minimum technical requirements and sector-specific testing. Evidence of reliable data interpretation, enforceable use restrictions and manageable compliance costs would be needed before wider adoption.
Relevant Question for Policy Stakeholders: What division of responsibility between the National Data Governance Committee and sectoral bodies would make cross-border AI access conditions enforceable when data uses and model capabilities change?
Follow the Full Paper Here: PSA: Enabling Cross-Border Data Interoperability for AI

