Telangana has become the first state to put binding rules around how its tax officers can use AI. Here's what Circular No. 1/2026 actually says — and why it matters even if you're not a government employee.
Telangana Just Drew a Hard Line Between AI and Taxpayer Data
On August 18, 2026, the Telangana Commercial Taxes Department issued Circular No. 1/2026 (Ref. No. A(1)/65/2026) — a detailed set of binding instructions governing how its officers and ministerial staff may use Artificial Intelligence tools and third-party online platforms in the course of their work. It's being described as a first-of-its-kind move by an Indian tax administration, and it's worth understanding in some detail because it's likely to be a template other states and departments follow.
The department's position isn't anti-AI. It explicitly acknowledges that AI tools can genuinely improve the speed, consistency, and quality of official work. But it draws a firm line: administrative efficiency cannot come at the cost of statutory data confidentiality, data security, or independent quasi-judicial assessment. Everything in the circular flows from that one sentence.
1. A Complete Bar on Uploading Taxpayer Data
The core restriction is unambiguous. Officers and staff are strictly barred from typing, pasting, scanning, photographing, or uploading any taxpayer particulars into public or commercial generative AI platforms, chatbots, summarizers, or browser extensions — unless expressly authorized in writing. That covers a wide net of information: GSTINs, PANs, taxpayer names, financial statements, returns, invoices, and audit records all fall within the prohibition.
In practice, this rules out a habit that's become common across many workplaces — dropping a document, a spreadsheet, or a screenshot into a chatbot to get a quick summary or draft. For a tax officer handling GST records, that convenience is now explicitly off the table unless there is written authorization first.
| Data Type | Status on Public AI Tools |
|---|---|
| GSTINs, PANs, taxpayer names | Barred |
| Financial statements, returns, invoices, audit records | Barred |
| Generic legal research, hypothetical fact patterns | Permitted |
| Drafting structure, grammar/language checks | Permitted |
2. Confidentiality Is a Personal Obligation, Not a Departmental One
Perhaps the sharpest point in the circular is who bears responsibility when something goes wrong. It states plainly that confidentiality obligations under Sections 152, 158, and 158A of the TGST Act, 2017, attach personally to public servants — not to the department as an institution. An officer cannot point to workload pressure or claim a subordinate uploaded the data on their behalf; the obligation travels with the individual, not the task.
The consequences for violations are laid out with unusual specificity for what is, on paper, an internal administrative circular:
- Disciplinary action under the Telangana Civil Services Rules
- Prosecution under Section 133 of the TGST Act — imprisonment up to six months, or a fine, or both
- Penalties under the Official Secrets Act
- Liability for data breaches under the Digital Personal Data Protection Act (DPDPA), 2023
Stacking a civil service rule, a GST Act prosecution provision, the Official Secrets Act, and the DPDPA together in one circular signals that the department is treating an AI-related data leak with the same seriousness as any other confidentiality breach — arguably more, given how easily a pasted document can leave an officer's control permanently once it's on a third-party server.
3. AI Cannot Substitute for Quasi-Judicial Judgment
GST officers don't just process paperwork — orders and notices issued under GST law are quasi-judicial acts that require personal application of mind. The circular is explicit that this cannot be outsourced to an AI draft, however polished it looks.
The reasoning given is one that's become familiar to anyone who has worked closely with generative AI: the risk of hallucination. The circular specifically calls out the danger of AI-generated content citing non-existent case laws, referencing incorrect statutory sections, or inventing facts that were never part of the record. An officer who signs off on such a proceeding is personally responsible for verifying every citation and every legal proposition against the original source — the AI output is a starting point at best, never a substitute for that verification.
Why this matters beyond Telangana: Fabricated case citations from AI tools have already caused embarrassment in courts and tribunals elsewhere. A tax notice built on an invented precedent isn't just an administrative error — it can unravel an entire proceeding on appeal. This clause is as much about protecting the department's legal position as it is about accountability.
4. What's Actually Allowed
The circular is careful to note that the department isn't opposed to AI as a category. Officers are encouraged to use it responsibly for a narrower set of purposes: generic legal research, abstract statutory interpretation, drafting structures, and grammar or language checks. The condition attached to all of this is important — every query must be framed in entirely hypothetical terms, with no identifying data included at all.
In effect, an officer can ask an AI tool to explain how a particular statutory provision has generally been interpreted, or to help structure a draft order, but cannot ask it to draft an order for a specific taxpayer using that taxpayer's actual figures, name, or GSTIN.
5. Clean-Up and Compliance Sign-Off
The circular doesn't stop at future conduct — it also addresses what may have already happened. Officers have been instructed to delete past search histories, uploaded files, and any residual taxpayer data that may currently sit on external AI platforms from earlier, unregulated use.
On top of that, every officer and staff member is required to submit a signed, dated acknowledgment confirming they have received and understood the directive, within 15 days of its issue. This turns the circular from a guidance note into something closer to a compliance mandate, with a paper trail attached to each individual.
The Bigger Picture
This circular sits at the intersection of two things that are both moving fast right now: the rapid, often informal adoption of generative AI tools inside government offices, and India's tightening data protection framework under the DPDPA, 2023. Tax administration in particular sits on an enormous amount of sensitive financial data — GST records alone touch nearly every registered business in the state — which makes it one of the more obvious places where an unregulated AI habit could cause real harm.
For taxpayers, the circular is arguably reassuring: it's a formal, public commitment that their GSTIN, invoices, and financial data won't casually end up inside a third-party chatbot's training or logging pipeline. For other government departments and even private-sector compliance teams handling similarly sensitive data, it's a useful reference point — a concrete example of what a responsible-AI-use policy can look like when it's actually backed by named statutory penalties rather than vague best-practice language.
The takeaway: AI is welcome in Telangana's tax offices for research and drafting help — but taxpayer data stays out of it entirely, quasi-judicial judgment stays human, and every officer is now personally on the hook for both.
This post summarizes Circular No. 1/2026 (Ref. No. A(1)/65/2026, dated August 18, 2026) issued by the Telangana Commercial Taxes Department, based on publicly reported details as of early September 2026. For the full text and any subsequent clarifications, refer to the official circular or consult a qualified tax professional.