
Government organisations have begun implementing stricter safeguards around artificial intelligence usage in official work, with employees being advised not to use unapproved external AI platforms for processing or sharing official, confidential or sensitive information. According to internal communications reviewed by Moneycontrol, government offices have been specifically asked to restrict the use of unapproved external AI platforms while handling official data. The directions do not constitute a blanket ban on generative AI services for government work, as reported by Moneycontrol.
The government's move follows recent advisories issued by the Indian Computer Emergency Response Team (CERT-In), which warned government entities about emerging cyber threats posed by advanced artificial intelligence models. In an advisory issued in April, CERT-In stated that attackers were using AI to automate vulnerability discovery, generate exploits and accelerate cyber attacks. The agency warned that organisations now have much less time to detect and fix security flaws, as reported by Moneycontrol. CERT-In has specifically warned that rapidly advancing AI models such as Claude Mythos are capable of automating sophisticated cyber attacks, significantly shortening the time available to patch vulnerabilities in systems.
Government organisations have been instructed to implement comprehensive security measures including strengthening multi-factor authentication, installing security patches, conducting regular vulnerability assessments and security audits, monitoring internet-facing systems and maintaining secure offline backups. They have also been told to report cyber incidents to CERT-In and appoint nodal officers to oversee cyber security preparedness. According to Moneycontrol, these measures are designed to address growing concerns over the ability of frontier AI models to automate sophisticated cyber attacks.
CERT-In has issued separate guidelines for technology providers and equipment makers, asking them to conduct AI-assisted vulnerability assessments, strengthen secure software development practices, maintain updated software bills of materials, implement multi-factor authentication and rapidly disclose critical vulnerabilities to affected organisations and CERT-In. The guidelines also call for accelerated patch management and stronger incident response mechanisms as AI-powered cyber threats continue to evolve. The guidance aligns with a broader push within the government to establish safeguards around AI use in public administration as adoption of generative AI tools accelerates across ministries and departments.