Summary: With artificial intelligence increasingly driving the personalisation of skincare and beauty products in India, businesses operating at this intersection must navigate a complex and evolving regulatory landscape. This post examines the key legal considerations that arise when AI is used to design customised cosmetic regimens. It explores the classification risk where AI-driven analysis and tailored recommendations risk crossing the line from cosmetics into drugs or even software as a medical device. It then considers the interplay between product and service liability under the Consumer Protection Act, 2019, particularly where harm results not from a defective product per se, but from an AI algorithm’s failure to account for individual user characteristics.
Indian beauty and personal care companies are increasingly using AI to design personalised serums, moisturizers and skincare regimens. Usually, the consumer completes a questionnaire, sometimes uploads a picture, or takes a skin scan and the algorithm recommends actives, concentrations, or a customised routine. Several well-known Indian platforms have already launched AI-based skin analysis tools that generate tailored recommendations basis facial scans. It is quickly becoming a mainstream way for beauty brands to go to market.
A business running this model sits at the intersection of several existing laws:
- the Drugs and Cosmetics Act, 1940 (“D&C Act”), and the Cosmetics Rules, 2020 (“Cosmetics Rules”), govern what constitutes as “cosmetic”, and what it may claim to do; and
- the Consumer Protection Act, 2019 (“CP Act”), which governs product and service liability.
Against this backdrop, the Central Drugs Standard Control Organization (“CDSCO”) has previously clarified that a cosmetic is defined by its intended external, non-therapeutic use, and products supplied for injectable use fall outside the ambits of cosmetics. Additionally, cosmetics carrying misleading or treatment-related claims violate the D&C Act and the Cosmetics Rules.
Classification Risk: Cosmetic or Drug?
A cosmetic under the D&C Act is defined by its intended purpose, being an article meant to be applied to the human body for cleansing, beautifying, promoting attractiveness or altering appearance. The definition of cosmetics does not include product design or formulation. An AI designed routine, which contains a serum that claims to brighten the skin or improve texture usually sits within this definition. The issue arises when marketing materials make therapeutic claims, such “reduces acne”, “fades melasma”, “controls rosacea”, “repairs an eczema prone barrier”, etc. The CDSCO guidance[1] reiterates that cosmetics cannot carry a drug claim, and a product making a therapeutic claim falls within the statutory definition of a “drug” and must go through the drug regulatory pathway instead, not the lighter cosmetic registration process (see our thoughts on the regulation of ‘cosmeceuticals’ in India here). The grey area begins when AI personalisation starts to resemble clinical decision support—for example, by using a detailed skin or lifestyle history, mapping conditions such as acne severity, pigmentation type, or sensitivity, creating a tailored regimen that reads more like a treatment plan than a product recommendation. Such AI software, which is intended to assist in diagnosis and treatment of health conditions, may also fall within the ambit of software as medical device (refer to our blog post on software as medical device here).
Product vs Service Liability
The related question is whether the consumer is really buying a product (e.g. a serum), a service (e.g. the AI-driven personalisation), or an inseparable bundle of the two. This distinction is important because the CP Act addresses both product defects and service deficiencies, and an AI personalisation model can trigger either kind of claim. To compensate a consumer for the harm caused by a defective product or by a deficiency in services relating to that product, under the CP Act, “product liability” is considered the responsibility of a product manufacturer, product seller, or product service provider. “Harm” includes personal injury, illness, and mental agony or emotional distress arising from injury or illness squarely covering the kind of harm an unsuitable AI-recommended formula could cause.
While a formula may be generally safe for use, an AI-recommended routine may be unsuitable for a particular individual and could potentially cause harm. This could arise, for example, where the formula itself is safe for general use, but becomes unsuitable for a particular user because the underlying algorithm misclassified their skin type or condition, failed to account for a declared allergy, pregnancy, or existing prescription treatment. It could also recommend a combination or concentration of active ingredients that is too aggressive for that user’s profile. In such cases, a manufacturer may face liability for manufacturing or design defects, or for failing to provide adequate warnings. Sellers and service providers may also be held liable if their own conduct, or deficiency in the service provided by them, is the proximate cause of harm.
Human Oversight: How Much is Enough?
This relates to how much human review sits in the loop. In some implementations, an AI generates the plan directly, with no qualified reviewer involved at any stage. In others, a human reviewer may check for contraindications, can override the AI, and document the reasoning behind a decision. Neither the Cosmetics Rules nor any other current statute sets a minimum level of human oversight for AI-designed cosmetics. Brands, therefore, have discretion over how they incorporate human oversight into the development process. Where an adverse event does occur, a regulator, consumer forum, or court is likely to look at how the workflow operated, including whether the brand treated the AI’s output as binding or as decision support, and whether extra care was taken for users such as minors or pregnant users. A well-documented, meaningfully applied review process tends to be viewed more favorably than one that exists only theoretically.
Minimising Potential Risks
This is an evolving space. From a company’s perspective, key considerations include—how a brand presents the AI platform, language/ claims that presents the AI as a recommendation engine (as opposed to clinical analysis), suggesting suitable products based on general preferences such as skin type or stated concerns, and keeping the tool and the product it recommends within the cosmetic regime. Language that presents the AI as identifying or reading skin conditions, rather than general skin concerns, is closer to diagnostic or therapeutic framing, and can trigger drug-level scrutiny.
The degree of human involvement in the process is a separate but related consideration. Building a review step directly into the AI’s workflow, so that a qualified person can verify a recommendation before it reaches the consumer is one way of managing this risk, as against a consumer receiving an AI generated output without any additional check. This is a key area, one which the regulator is likely to pay closer attention to as AI personalised products become more common. Businesses that keep their claims aligned with a defensible cosmetic-only posture, build meaningful human oversight into higher risk workflows and maintain SOPs/ documentation in relation to AI solutions being deployed from safety and governance perspectives, tend to be in a stronger position generally, both in how they manage day-to-day risks and in how they are able to respond if a question or challenge does arise.

For further information, please contact:
Biplab Lenin, Partner, Cyril Amarchand Mangaldas
[1] General-Non-compliances-Observed-converted.pdf and Q. 53 Central Drugs Standard Control Organization Directorate General of Health Services Ministry of Health and Family Welfare, Government of India




