No Indian law today forces a hospital to tell a patient that the voice on an appointment call is an AI agent rather than a person. That is the plain reading as of August 2026. What has changed is that the question is now a live procurement decision: the global reference standard has teeth, the Indian direction of travel is visible, and the person on the other end of a hospital line is often elderly, anxious, or unwell.
This piece is for the CIO, the Chief Medical Officer, and the legal desk who decide the answer together. It sets out what the EU AI Act now requires, what Indian law actually says, where the elderly-audience threshold changes the calculation, and what a hospital should specify in a vendor contract before a single call goes live.
The global standard is now in force
The transparency rule everyone cites took effect on 2 August 2026. Article 50 of the EU AI Act obliges providers and deployers of AI systems that interact directly with people to make sure those people are informed they are dealing with an AI, unless it is obvious to a reasonably observant person (Source: European Commission, Article 50 obligations in force 2 August 2026). Non-compliance can draw penalties up to 15 million euro or 3 percent of worldwide annual turnover (Source: European Commission, July 2026 Guidelines on Article 50).
The Commission's own guidance, adopted 20 July 2026, closes the escape hatch most vendors reach for first. A vague reference to an "assistant" or a soft chime does not satisfy the duty. The exemption is tested against a reasonably observant person drawn from the actual audience, and the guidance sets a lower threshold where elderly people or persons with disabilities are present (Source: European Commission, July 2026 Guidelines on Article 50).
Two things follow for an Indian hospital group. Article 50 does not bind a deployment that serves only Indian patients on Indian soil: it is the reference standard, not the governing law. But the moment a hospital handles cross-border patients, EU medical tourism, or any EU-facing service line, the analysis shifts, because the Act reaches AI whose output is used inside the Union. A hospital that treats Article 50 as purely a European problem is making a jurisdictional bet it has not priced.
What Indian law says right now
India has no standalone AI statute. There is no clause anywhere in Indian law that reads "disclose AI on patient calls." What exists instead is a set of laws that already apply to AI systems the way they apply to any other software, and a policy direction that is starting to name AI explicitly.
The Ministry of Electronics and Information Technology issued its Governance Guidelines in November 2025. The stance there is voluntary compliance and self-certification, and the guidelines are explicit that the Digital Personal Data Protection Act 2023, the Information Technology Act, consumer protection law, and sector regulators already govern AI (Source: MeitY Governance Guidelines, November 2025). The message to a hospital board: the absence of an AI law is not the absence of law. It is a set of existing obligations that a voice agent has to satisfy on day one.
DPDP 2023 is the one that bears directly on this decision, through the concept of the Data Fiduciary. In a hospital voice deployment the hospital is the Data Fiduciary. It determines the purpose and means of processing the patient's personal data, and it owns the patient relationship. The vendor that builds and runs the agent is a Data Processor acting on the hospital's instructions. Consent, notice, and the patient's rights run to the hospital, not to the software company. That single fact settles a question hospitals often get backwards: the disclosure decision is the hospital's to make.
The Principal Scientific Adviser's white paper of January 2026 points to where this is heading. Its argument is that compliance should be embedded into the design of an AI system rather than bolted on after the fact (Source: Office of the Principal Scientific Adviser, January 2026). For a hospital procuring a voice agent, that reframes disclosure from a policy toggle debated after go-live into a requirement specified before build. A disclosure line retrofitted into a deployed call flow is a change request. A disclosure capability designed in from the start is a configuration.
The elderly-audience threshold is the part hospitals underweight
Strip away the jurisdictional argument and a harder question remains. Who actually picks up a hospital call. A large share of hospital contact touches older patients, patients managing chronic conditions, and family members under stress. This is precisely the group the Commission's guidance singles out when it lowers the bar for what counts as obvious, and the reasoning transfers cleanly to India even though the Act does not.
A synthetic voice that sounds warm and fluent in Hindi or a regional language is more convincing to a seventy-year-old patient, not less. The better the voice agent, the weaker the "it was obvious" defence, because the engineering goal was to make it not obvious. A hospital cannot buy a natural-sounding agent and also argue that no reasonable patient could have mistaken it for a person.
This is where the CMO's judgment matters more than the lawyer's. A patient who later learns the reassuring voice discussing their appointment was synthetic, with no one having said so, rarely files a regulatory complaint. They tell their family, and they carry the doubt into the next real clinical interaction. The downside is reputational and clinical before it is ever legal.
What a hospital should specify in the vendor contract
The decision to disclose is the deployer's. The obligation to make disclosure possible, auditable, and configurable is the vendor's, and that belongs in the contract. Five clauses earn their place.
Disclosure as a configurable capability. The agent must be able to state, at the start of a call, that the caller is speaking with an automated assistant working on the hospital's behalf, in the patient's language, and the hospital must be able to turn this on or off per line, per campaign, per language. If the vendor offers disclosure only as a hard-coded default or not at all, that is a limitation you are inheriting.
The exact disclosure wording, owned by the hospital. What the agent says is a clinical and legal artefact. The hospital's medical and legal desks should sign off the script, not the vendor's product team, and reserve the right to change it without a billable request.
An audit trail of what was disclosed and when. Every allocation of responsibility falls apart if no one can reconstruct the call. The contract should require logging of the disclosure state and the spoken disclosure on each call, retained and retrievable, so a later dispute is answered with a record rather than an assertion.
A written recommendation on file. A competent vendor gives the hospital its recommendation on disclosure in writing and records the hospital's decision either way. This protects both sides: the hospital's choice is documented as an informed one, and the vendor is not left carrying a decision that was never its to make.
Handling of the human handoff. When the agent transfers a caller to a human, or a human picks up mid-flow, the patient should not be left unsure who they are speaking to. Specify how the transition is signalled.
None of these clauses commits the hospital to disclosing. They commit the vendor to making the hospital's decision executable and provable. A hospital that has not decided yet can still procure correctly by insisting the capability exists and the record is kept.
The decision, stated cleanly
No Indian regulation compels disclosure on a domestic patient call today. The EU standard that does is in force and reaches any EU-facing service line a hospital runs. Indian law already governs the deployment through DPDP, the policy direction is toward compliance designed in rather than added later, and the audience most hospital calls reach is the one where the "obvious enough" defence is weakest.
So treat disclosure as a decision the board owns and makes deliberately, backed by a vendor contract that makes it a configurable, auditable, hospital-controlled capability. Decide it before go-live. Do not let it become the question you answer only after a patient has asked it first.
Frequently asked questions
Do hospitals have to disclose that a caller is an AI agent?
Under Indian law as of August 2026, no domestic regulation compels a hospital to tell a patient that a voice agent is an AI rather than a person. The EU AI Act requires this for systems interacting with people, but it binds EU-facing deployments, not purely Indian ones. Disclosure is a decision the hospital makes as the party that owns the patient relationship, informed by existing DPDP obligations and by reputational and clinical risk.
Does the EU AI Act apply to Indian hospitals?
Not to a deployment that serves only Indian patients in India. The AI Act's Article 50 transparency obligations took effect on 2 August 2026 and reach providers and deployers whose AI outputs are used inside the European Union. A purely domestic Indian voice deployment falls outside it, but an EU-facing service line, cross-border patients, or inbound EU medical tourism can bring it into scope. Treat Article 50 as the global reference standard rather than as irrelevant.
What does Indian law say about AI disclosure right now?
India has no standalone AI statute. The MeitY Governance Guidelines of November 2025 favour voluntary compliance and self-certification and confirm that DPDP 2023, the IT Act, consumer protection law, and sector regulators already apply to AI systems. Under DPDP the hospital is the Data Fiduciary and owns consent, notice, and patient rights. The Principal Scientific Adviser's January 2026 white paper argues for building compliance into AI system design rather than adding it afterward.
What should a hospital put in a vendor contract about disclosure?
Five things: disclosure as a capability the hospital can configure per line and language; the exact disclosure wording owned and approved by the hospital's clinical and legal teams; an audit trail logging what was disclosed and when; the vendor's written recommendation and the hospital's recorded decision; and a defined signal for the human handoff. These make the hospital's decision executable and provable without committing it to any particular choice.
Who decides whether to disclose, the hospital or the vendor?
The hospital. Under DPDP 2023 the hospital is the Data Fiduciary that determines the purpose and means of processing and owns the patient relationship, while the vendor operates as a Data Processor on the hospital's instructions. The vendor's job is to make disclosure a configurable, auditable capability and to record its recommendation in writing.
