Author(s): Archana Santhosh
Paper Details: Volume 4, Issue 5
Citation: IJLSSS 4(5) 01
Page No: 01 – 10
ABSTRACT
Artificial intelligence now mediates a substantial share of cross-border e-commerce, from dynamic pricing and personalised recommendations to automated content moderation and algorithmic dispute resolution. This transformation has outpaced both domestic consumer-protection law and the multilateral trade law framework designed for an earlier, non-algorithmic internet. India regulates AI-driven e-commerce practices only indirectly, through the Digital Personal Data Protection Act, 2023, the Consumer Protection Act, 2019, and the Central Consumer Protection Authority’s advisory Guidelines for Prevention and Regulation of Dark Patterns, 2023 an architecture that remains sectoral, consent-centric and largely non-binding. At the multilateral level, the lapse of the WTO Moratorium on Customs Duties on Electronic Transmissions on 30 March 2026, following the failure of the Fourteenth Ministerial Conference to reach consensus, has reopened foundational questions about how algorithmically generated digital transmissions are to be classified and taxed across borders. This paper examines the resulting regulatory gap through the lens of Indian consumer and data law read alongside international trade law instruments, situates the Indian position comparatively against the European Union’s risk-tiered Artificial Intelligence Act and China’s algorithmic recommendation regime, and argues for a coordinated, enforceable framework addressing algorithmic accountability, jurisdiction and the tariff treatment of AI-enabled digital trade.
Keywords: Artificial Intelligence, Cross-Border E-Commerce, WTO Moratorium, Digital Personal Data Protection Act, Dark Patterns, EU AI Act, International Trade Law
I. INTRODUCTION
Electronic commerce has, over the last decade, become substantially algorithmic. Search rankings, price displays, credit and eligibility screens, chat-based customer service and post-sale dispute resolution on major platforms are today generated or materially shaped by artificial intelligence systems rather than by static, human-authored rules. Where such platforms operate across borders — a seller in one country, a cloud infrastructure and AI model in a second, and a consumer in a third the resulting transaction sits simultaneously within domestic consumer-protection law, domestic data-protection law, and the international trade law regime governing cross-border digital flows. Each of these bodies of law developed largely independently of the others, and none was designed with algorithmic decision-making specifically in view.
The urgency of this misalignment has grown sharply in 2026. On 30 March 2026, the WTO Moratorium on Customs Duties on Electronic Transmissions, a standing practice since 1998 under which members refrained from taxing cross-border digital transmissions, lapsed after members meeting at the Fourteenth Ministerial Conference in Yaoundé, Cameroon, failed to agree on its renewal.[1] For the first time in the history of multilateral trade governance, WTO members are now free, subject to other treaty commitments, to impose customs duties on electronic transmissions, including the AI-enabled digital services that now underpin much of cross-border retail.[2] This paper asks how Indian law and international trade law together address or fail to address the legal challenges that AI-driven e-commerce poses, and what a more coherent regulatory response would require.
Part II maps the principal forms AI takes in cross-border e-commerce and the classification difficulties they generate. Part III examines India’s domestic regulatory response. Part IV turns to the international trade law dimension, centred on the lapse of the moratorium. Part V situates India comparatively against the European Union and China. Part VI draws out the resulting legal challenges, and Part VII offers recommendations.
II. ARTIFICIAL INTELLIGENCE IN CROSS-BORDER E-COMMERCE: MAPPING THE PHENOMENON
AI systems perform at least five distinct functions in contemporary cross-border e-commerce: personalised recommendation and search ranking; dynamic or algorithmic pricing that varies by user, device or location; conversational commerce through AI chatbots handling pre-sale queries and post-sale grievances; automated content moderation and product-listing review; and profiling-based credit, fraud or eligibility scoring used to gate access to buy-now-pay-later credit or marketplace seller status. Each of these functions typically draws on data collected in one jurisdiction, is trained or hosted on infrastructure located in a second, and produces an output a price, a ranking, a denial of credit that is experienced by a consumer in a third.
This dispersion creates two related classification problems. The first is a conflict-of-laws problem: it is often unclear which jurisdiction’s consumer-protection or data-protection standard governs a given algorithmic output. The second, and the newer of the two, is a trade law classification problem: instruments such as the WTO’s electronic-transmissions moratorium and the General Agreement on Trade in Services (GATS) were negotiated around the categories of “goods,” “services” and “electronic transmissions” as they existed at the turn of the century, and do not squarely address whether an AI-generated price, recommendation or credit decision delivered across a border is itself a taxable or regulable “transmission” distinct from the underlying good or service being sold.
III. INDIA’S DOMESTIC REGULATORY RESPONSE
India does not have a standalone artificial intelligence statute. Its approach, in common with several jurisdictions, has been policy-driven and sectoral, relying on the extension of existing legal frameworks — principally the Information Technology Act, 2000,[3] the Digital Personal Data Protection Act, 2023, and the Consumer Protection Act, 2019 — rather than a single omnibus AI law.[4]
The Digital Personal Data Protection Act, 2023 (“DPDP Act”) establishes a consent-based framework for processing personal data, built around the roles of “data fiduciary” and “data principal.” The Act itself illustrates its application to e-commerce directly: it contemplates a data principal who consents to an online platform’s processing of her personal data for the purpose of fulfilling a supply order, and clarifies that withdrawal of that consent may permit the platform to stop enabling further orders without disturbing the processing already required to complete a pending supply.[5] What the DPDP Act does not do is single out AI-driven decision-making, such as automated pricing or profiling-based personalisation, for any distinct standard of transparency or contestability, nor does it recognise a category of sensitive personal data attracting heightened protection.[6] The subordinate DPDP Rules, 2025 remain at the consultation stage, leaving significant operational detail, including safeguards around algorithmic processing, still to be settled.
Consumer protection law supplies the second strand. Section 2(47) of the Consumer Protection Act, 2019 defines “unfair trade practice” broadly enough to capture deceptive digital design,[7] and the Central Consumer Protection Authority (“CCPA”) has used this power to issue the Guidelines for Prevention and Regulation of Dark Patterns, 2023, which identify thirteen specific manipulative design practices — including false urgency, basket sneaking, confirm shaming, drip pricing and disguised advertisements — as unfair trade practices when deployed on platforms offering goods or services in India.[8] In June 2025 the CCPA followed up with an advisory directing e-commerce platforms to complete a self-audit for dark patterns within three months.[9] Enforcement has followed in at least two visible instances: an order dated 19 June 2024 directed against an airline’s web check-in interface, and a notice issued to a ticketing platform over a pre-ticked optional donation.[10] Yet commentators have observed that the CCPA’s approach remains an advisory and interpretive exercise rather than a binding regulatory one: the Guidelines carry no dedicated penalty structure and no independent audit mechanism, leaving enforcement dependent on ad hoc CCPA notices issued under the residual unfair-trade-practice power.[11]
Taken together, the DPDP Act addresses consent and data handling, and the Dark Patterns Guidelines address manipulative interface design, but neither instrument speaks directly to the use of AI systems to steer consumer decisions once data has lawfully been obtained — the point at which recommendation, pricing and profiling algorithms actually operate.[12] The result is a framework that is comparatively strong on notice and consent and comparatively weak on algorithmic accountability.
IV. INTERNATIONAL TRADE LAW DIMENSIONS: THE LAPSE OF THE WTO MORATORIUM
Since 1998, WTO members have maintained, through successive ministerial decisions, a standing practice of not imposing customs duties on electronic transmissions.[13] The practice was last extended at the Thirteenth Ministerial Conference in Abu Dhabi in 2024, until the earlier of the Fourteenth Ministerial Conference or 31 March 2026.[14] At the Fourteenth Ministerial Conference, held in Yaoundé, Cameroon in March 2026, members were unable to reach the consensus required for renewal, and the moratorium — together with the associated Work Programme on Electronic Commerce — lapsed on 30 March 2026.[15]
The immediate legal consequence is that WTO members are no longer bound by a multilateral commitment to refrain from taxing electronic transmissions; the matter now falls to be governed by a patchwork of bilateral and regional free trade agreements, together with the plurilateral Agreement on Electronic Commerce concluded under the Joint Statement Initiative, by which a subset of participating members has confirmed an intention to continue not imposing such duties among themselves.[16] Because the plurilateral commitment binds only its signatories, cross-border AI-enabled retail platforms now face a jurisdiction-specific and potentially shifting landscape of digital tariffs rather than a single global default.[17]
India’s own position at the WTO is relevant here. Along with Indonesia and South Africa, India had for several years opposed a permanent moratorium, arguing that it deprives developing countries of customs revenue on digital imports and entrenches the digital divide by foreclosing the tariff-based industrial policy tools that developed economies historically used to build domestic industries.[18] Economic studies commissioned by proponents of renewal — including analysis associated with the European Centre for International Political Economy — had projected that reintroducing such duties would raise prices, reduce digital trade volumes and disproportionately burden small and medium enterprises reliant on affordable cross-border digital tools.[19] Both positions bear directly on AI-enabled e-commerce: cloud-based AI pricing, translation, and recommendation services consumed by Indian sellers on cross-border marketplaces are, in principle, now within the class of “electronic transmissions” that importing members may choose to tax.
A further difficulty is definitional. Neither the lapsed moratorium nor GATS resolves whether an AI system’s output — a computed price, a generated product description, an automated translation, a recommendation ranking — constitutes a distinct “electronic transmission,” is subsumed within the underlying service being supplied, or falls outside the goods/services taxonomy altogether. The absence of a settled classification increases the risk that different WTO members will treat functionally identical AI-mediated transactions inconsistently, generating both compliance uncertainty for platforms and forum-shopping incentives for the digital tariffs that now become possible.
V. COMPARATIVE PERSPECTIVES: THE EUROPEAN UNION AND CHINA
The European Union has taken the most direct regulatory route. Under Regulation (EU) 2024/1689 (the “AI Act”), an AI system falling within the Annex III categories is always classified as high-risk where it performs profiling of natural persons, regardless of any contrary self-assessment by its provider — a rule squarely applicable to the personalisation and credit-scoring functions common in e-commerce.[20] High-risk classification triggers conformity assessment, technical documentation and registration obligations, with the main tranche of obligations for standalone high-risk systems phased in from December 2027 following a 2026 revision to the original timeline.[21][22] Critically, the AI Act applies extraterritorially: a provider or deployer outside the European Union is nonetheless covered if its AI system’s output is placed on the EU market or used in a decision affecting an EU resident, mirroring the earlier “Brussels effect” produced by the General Data Protection Regulation.[23]
China has regulated algorithmic recommendation systems directly since 1 March 2022, requiring transparency and specific user protections wherever such systems are deployed, a model that brings recommendation engines under explicit ex ante state oversight rather than the ex post, complaint-driven enforcement characteristic of the Indian approach.[24]
Set against these models, India’s reliance on advisory guidelines and a general unfair-trade-practice power represents a materially softer form of intervention — sufficient to name and shame specific dark-pattern practices, but without the binding conformity obligations of the EU model or the direct algorithmic-transparency mandate of the Chinese model.
VI. EMERGING LEGAL CHALLENGES
A. Jurisdiction and Conflict of Laws. Where an algorithm is trained in one state, deployed by a platform incorporated in a second, and produces an output affecting a consumer in a third, existing conflict-of-laws rules — largely built around the place of contract formation or the seller’s place of business — struggle to identify a single governing law for the algorithmic decision itself, as distinct from the underlying sale.
B. Liability and the Black-Box Problem. Where an AI system produces a discriminatory price or a manipulative recommendation, responsibility may plausibly rest with the platform deploying the model, the developer that built it, or the data fiduciary that supplied the training data. Neither the DPDP Act nor the Consumer Protection Act allocates liability among these actors for algorithmic harm specifically, leaving claimants to proceed under general unfair-trade-practice or tortious principles not designed for opaque, self-updating systems.
C. Classification Uncertainty in Trade Law. As discussed in Part IV, the absence of a settled multilateral definition of “electronic transmission” inclusive of AI-generated outputs creates both compliance risk for platforms and an opening for inconsistent national tariff treatment following the moratorium’s lapse.
D. Soft-Law Enforcement Gaps. India’s Dark Patterns Guidelines apply to “all platforms systematically offering goods or services in India,”[25] which in principle reaches foreign-domiciled cross-border marketplaces, but the absence of a dedicated penalty provision or independent audit mechanism means enforcement depends on the CCPA’s residual unfair-trade-practice power, exercised case by case.[26][27]
E. Data Localisation versus Global AI Supply Chains. The DPDP Act’s cross-border data transfer provisions, still being operationalised through the pending DPDP Rules, sit in tension with the reality that large AI models used for personalisation and pricing are typically trained and hosted outside India, raising compliance questions for Indian sellers and platforms that rely on such models.
F. Disproportionate Impact on MSMEs. Studies associated with the WTO moratorium debate found that customs duties on electronic transmissions raise costs disproportionately for small and medium enterprises, which rely on affordable cross-border digital and AI-enabled tools to reach export markets; the moratorium’s lapse accordingly carries a distributive dimension that domestic Indian MSME policy will need to account for.[28][29]
VII. RECOMMENDATIONS
First, India should move beyond sectoral extension toward a dedicated legal framework — whether a standalone statute or a substantial amendment to the Consumer Protection Act — that expressly allocates responsibility among AI developers, deploying platforms and data fiduciaries for algorithmic harm in e-commerce, rather than leaving such harm to be addressed only indirectly through consent-based data law.
Second, the Dark Patterns Guidelines, 2023 should be placed on a binding statutory footing, with a defined penalty structure and an independent audit or certification mechanism, so that compliance does not depend solely on case-by-case CCPA notices.
Third, within the WTO’s Joint Statement Initiative and any successor negotiation on electronic commerce, India should press for a clear, agreed definition of “electronic transmission” that expressly addresses AI-generated outputs, while continuing to advance its longstanding position on preserving policy space and customs revenue for digital industrialisation in developing economies.
Fourth, Indian regulators should study the European Union’s risk-tiered classification methodology, and China’s transparency-first model for recommendation algorithms, not for wholesale adoption but as templates for calibrating a proportionate Indian regime that binds high-risk uses, such as credit-scoring and profiling-based personalisation, more tightly than low-risk uses such as basic search ranking.
Fifth, given the extraterritorial reach of both the EU AI Act and India’s own Dark Patterns Guidelines, Indian authorities should pursue cross-border regulatory cooperation arrangements with counterpart consumer and data protection authorities to enable coordinated enforcement against platforms that operate across multiple markets simultaneously.
VIII. CONCLUSION
Artificial intelligence has become integral to how cross-border e-commerce transactions are priced, presented and adjudicated, yet the legal frameworks meant to govern that commerce were built for an earlier and less algorithmic internet. India’s domestic response — a consent-based data protection statute, a general unfair-trade-practice power, and advisory dark-pattern guidelines — addresses important pieces of the problem without squarely reaching algorithmic decision-making itself. At the multilateral level, the lapse of the WTO Moratorium on Customs Duties on Electronic Transmissions on 30 March 2026 has removed a settled baseline just as AI-generated content and decisions complicate the very classification questions the moratorium was meant to sidestep. A coherent response will require India to strengthen algorithmic accountability domestically while working, within the fragmented post-moratorium trade architecture, toward a clearer and more equitable multilateral treatment of AI-enabled digital trade.
[1]World Trade Organization, Work Programme on Electronic Commerce, Moratorium, available at https://www.wto.org/english/tratop_e/ecom_e/ecom_work_programme_e.htm (last visited 30 July 2026).
[2]World Trade Organization, Post-MC14 Briefing Note: E-Commerce, 14th Ministerial Conference (2026).
[3]The Information Technology Act, 2000, No. 21 of 2000 (India), as amended by the Information Technology (Amendment) Act, 2008, No. 10 of 2009.
[4]ReedSmith LLP, India in Focus: Data Protection and AI in India (2026).
[5]The Digital Personal Data Protection Act, 2023, No. 22 of 2023 (India), Illustration to s. 6, Ministry of Electronics and Information Technology.
[6]Digital Personal Data Protection Act, 2023, supra note 7, ss. 4-9 (consent-based processing framework; no distinct category for sensitive personal data).
[7]The Consumer Protection Act, 2019, No. 35 of 2019 (India), s. 2(47).
[8]Central Consumer Protection Authority, Guidelines for Prevention and Regulation of Dark Patterns, 2023, F. No. J-24/34/2023-CPU (Reg), issued under s. 18, Consumer Protection Act, 2019.
[9]Press Information Bureau, Government of India, Central Consumer Protection Authority Issues Advisory to E-Commerce Platforms for Self-Audit within Three Months to Detect Dark Patterns (2025).
[10]AZB & Partners, Regulatory Crackdown on Dark Patterns: CCPA’s Enforcement Actions and Emerging Compliance Landscape in Indian E-Commerce (Oct. 2025), discussing In re IndiGo, CCPA Order dated 19 June 2024, and the notice issued to BookMyShow.
[11]International Association of Privacy Professionals, India’s CCPA Guidelines on Dark Patterns: Welcome Signal, but Law is Still Soft (2026).
[12]Policy Circle, India’s Digital Marketplace Needs Its Own AI Consumer Safeguards (2026).
[14]White & Case LLP, WTO Extends E-Commerce Tariff Moratorium as Broader Negotiations Continue (7 March 2024).
[16]WTO, Post-MC14 Briefing Note, supra note 2 (noting the proposal to extend the moratorium and Work Programme to 31 December 2030, and the Joint Statement Initiative among willing members to continue the practice inter se).
[17]Konrad-Adenauer-Stiftung, Online Tariffs? What the End of the E-Commerce Moratorium Means for Digital Trade (2026).
[18]White & Case LLP, supra note 4 (noting India, South Africa and Indonesia’s objections that the moratorium deprives developing countries of customs revenue on digital imports).
[19]European Centre for International Political Economy, cited in White & Case LLP, supra note 4.
[20]Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act), art. 6(3), fourth subparagraph.
[21]Faegre Drinker Biddle & Reath LLP, EU AI Act High-Risk Systems — European Commission Issues Draft Guidelines (2026).
[22]European Commission, AI Act, Shaping Europe’s Digital Future (2026).
[23]EchelonGraph, EU AI Act Compliance: The Complete Guide to August 2, 2026 Enforcement (2026).
[24]Policy Circle, supra note 13 (noting that China’s algorithmic recommendation provisions took effect on 1 March 2022).
[25]Guidelines for Prevention and Regulation of Dark Patterns, 2023, supra note 9, Annexure I (listing thirteen specified dark patterns: false urgency, basket sneaking, confirm shaming, forced action, subscription trap, interface interference, bait and switch, drip pricing, disguised advertisement, nagging, trick wording, SaaS billing and rogue malware).
[26]IAPP, supra note 12.
[27]AZB & Partners, supra note 11.
[28]International Chamber of Commerce, The WTO Moratorium on Customs Duties on Electronic Transmissions: Frequently Asked Questions (Aug. 2025).
