Executive summary
Engineering teams tend to think of themselves as building infrastructure, not selling a consumer service. GST law disagrees — and that mismatch is where most AI, API, and cloud companies get their OIDAR position wrong.
- Almost every AI tool, API, and cloud service delivered over the internet qualifies as OIDAR — the law looks at what the user receives, not what your team calls the product internally.
- The rate is the same as any other OIDAR service: 18% IGST on B2C supplies to Indian users.
- There is currently no dedicated HSN/SAC code for "AI services" specifically — a genuine classification grey zone this guide addresses directly.
- Most AI/API/cloud businesses are majority B2B, but individual developers, indie hackers, and freelancers paying by card create a real B2C (NTOR) tail that's easy to miss.
- A December 2024 CBIC circular now requires recording the recipient's state on invoices for OIDAR and digital services — a procedural detail that affects billing system design.
- Real AI companies handle this differently today — some register and localise pricing, others bill in USD with GST added on top. Both are legitimate; the difference is a compliance choice, not a legal exemption.
Why your API is an OIDAR service (even if it doesn't feel like one)
The single most common blind spot for engineering-led companies: OIDAR looks at the output the user receives, not how your team internally categorises the product.
Most APIs enable access to stored data, computing power, automation, analytics, authentication, or workflow triggers. Every one of these matches the OIDAR definition — a service delivered over the internet, mediated by information technology, impossible without that technology. It does not matter that your servers sit outside India, that you see yourselves as "pure infrastructure," or that a human never touches an individual request. If an Indian user receives an automated digital output from your API, GST law treats that as a service supplied to them.
What's covered: AI, API, and cloud, specifically
The breadth here is genuinely wide. Here's how the main categories map onto OIDAR.
AI tools & LLM access
Chat assistants, AI writing/coding tools, and API-based model access (chat completions, embeddings, fine-tuning endpoints) all qualify. The 2023 amendment removing the "minimal human intervention" test closed off any argument that AI-assisted output is somehow less automated than plain software.
Developer APIs
Data access, compute, automation, analytics, and authentication APIs all qualify — the mode of consumption (an API call rather than a UI) doesn't change the classification.
Cloud infrastructure (IaaS/PaaS/SaaS)
Compute, storage, hosting, CDN, and managed platform services are all treated uniformly as OIDAR when delivered to India, regardless of the "as-a-Service" layer they sit at.
AI training data & datasets
Training datasets delivered via API, download, or cloud storage qualify as OIDAR — including curated, human-annotated datasets, following the same 2023 amendment logic. See Section 3 for the genuine classification grey zone here.
The AI training data grey zone
This is a genuine, current gap in Indian tax guidance — worth understanding rather than assuming it's settled.
India's GST framework has no dedicated HSN or SAC code for "AI training data" specifically. Businesses must classify by analogy — to database licensing, IT services, or online information supply — each carrying different practical compliance implications. As of this guide's publication, there is no Authority for Advance Ruling decision, CBIC circular, or GST Council recommendation addressing AI training data as a distinct category.
The closest verified precedents, and what they do (and don't) settle
Nothing directly addresses AI training data, but two verified rulings address closely analogous questions and are worth knowing:
Neither ruling addresses AI training data directly — they are cited here as the closest verified analogies, not as settled answers to the training-data question itself.
The B2B tail problem
Most AI/API/cloud businesses genuinely are majority B2B — which is exactly what makes the B2C tail easy to overlook.
If a customer provides a valid GSTIN, the reverse charge mechanism applies and you have no liability on that revenue (see our calculator to see the impact this distinction makes). But developer-focused businesses in particular accumulate a long tail of individual developers, indie hackers, students, and freelancers who pay by personal card and never enter a GSTIN — because nobody asked, and because the checkout flow was built for speed, not tax classification.
How real AI companies handle it today
Different major AI providers have made different, equally legitimate compliance choices — useful to see in practice.
Registered non-resident provider, local currency pricing
One well-known consumer AI provider operates as a registered non-resident OIDAR supplier, pricing its consumer tiers directly in rupees with GST handled as part of that registration. Indian users see a single INR price; the GST obligation is absorbed into the provider's own compliance rather than left for the user to work out.
Foreign-currency billing with GST added at checkout
Another major AI provider continues to bill its consumer subscription in US dollars, with 18% GST added on top of the converted price at checkout — the default treatment for most individual and small-team subscribers who never enter a GSTIN.
Company examples above describe publicly observable billing practices as general illustrations of compliance approaches, not a statement about any company's complete or current tax position.
Invoicing requirements: the December 2024 update
A procedural change that affects how your billing system should be built, not just how your finance team files.
Worked scenarios
A US-based LLM API company with 3,000 Indian developer accounts
Most accounts are funded startups paying via invoiced contracts with GSTINs on file. But roughly 2,400 are individual developers and small teams on a self-serve, pay-as-you-go plan billed directly to a personal card — no GSTIN ever captured.
The 2,400 self-serve accounts are NTORs. The company must register under REG-10, charge 18% IGST on that self-serve revenue, and file GSTR-5A monthly. The funded-startup contracts are reported under reverse charge in Table 5B.
A cloud storage platform with a free tier and paid upgrade
Thousands of Indian users are on the free tier — no transaction, no current obligation. A subset converts to paid plans each month via card, all unregistered individuals.
The conversion moment is the trigger point: each newly paid Indian user is a new NTOR from that billing cycle forward. The company's obligation scales with paid conversions, not total signups — but must be tracked from the point of conversion, not discovered retrospectively.
A data licensing company selling curated datasets via API to Indian AI labs
All customers are Indian AI companies, several of which are GST-registered. One is an early-stage startup that hasn't yet registered for GST despite genuine business use.
The registered customers fall under reverse charge. The unregistered startup customer is technically an NTOR despite being a genuine business — GST law does not create a "business but unregistered" exception. The provider should still validate GSTIN status rather than assume business intent equals B2B treatment.
Compliance checklist for AI, API & cloud providers
- Confirm your product is internet-delivered and automated enough to qualify — for AI/API/cloud, assume yes by default
- Build GSTIN capture into signup and billing, regardless of whether your product is "B2B" by positioning
- Identify your self-serve / pay-as-you-go tier specifically — this is where NTOR exposure concentrates
- Capture recipient state at signup/checkout per the December 2024 invoicing requirement
- Track free-to-paid conversion moments as the trigger point for new Indian tax obligations
- For genuine AI-training-data classification grey areas, document your reasoning proactively
- Register via Form GST REG-10 once any NTOR revenue exists, and file GSTR-5A monthly thereafter
Glossary
Not sure how your product classifies?
AI, API, and cloud products often have genuinely ambiguous edges. Get a specific classification assessment for your product — free, no obligation.