
The Indian government is establishing a unified cybersecurity command centre to tackle emerging AI threats, with the new body expected to function under the Ministry of Electronics and Information Technology (Meity). According to Business Standard, this command centre will be responsible for driving the government's overall policy response to emerging AI threats and coordinating with various departments across central and state governments for their preparedness. The centre will also be tasked with ensuring that latest cybersecurity measures are implemented well within stipulated time periods. The need for such a unified cybersecurity command centre emerged because the government believes reaction time to threats from general-purpose models and frontier AI will shrink drastically over the next few months.
The Indian government is developing a comprehensive AI risk framework to establish guardrails for artificial intelligence tools and services launched in the country. According to reports from Business Standard, the framework will define the broad contours including dos and don'ts for AI tools and services, and establish a regulatory sandbox within which such products should be developed and operated. Recent developments show ASCI proposing labeling standards for AI-generated advertising content, with the Draft ASCI Guidelines observing that the obligation to label AI-generated content depends on the potential risk to consumers. Brands may use standard labels such as "Audio/Video created using AI" or "Audio/Video enhanced using AI" under this new framework. Additionally, following the National Institute of Standards and Technology's AI Risk Management Framework is emerging as a practical approach to ensure governance for principled, ADA-compliant AI.
The AI risk framework will provide the Centre with legal authority to establish accountability when AI tools and services are found to be in violation of prescribed norms. As reported by Business Standard, while the framework will be largely prescriptive, it will give the Centre certain emergency powers to issue directions for stopping a particular AI tool or service. Recent regulatory developments include SEBI's advisory on Emerging Advanced Artificial Intelligence Tools for vulnerability detection, recommending immediate updates of all operating systems and applications with latest patches. The advisory also mandates conducting vulnerability assessments using AI-based tools and regular security audits in line with SEBI's Cyber Security and Cyber Resilience Framework.
International developments highlight growing AI security concerns as Canon Business Services launches an AI and Security Advisory for Australian organizations. According to recent reports, Australian businesses face significant risks as staff adopt AI tools faster than employers can implement controls, with research from RMIT Online showing that fewer than one in 10 Australian workers have advanced AI skills. The advisory addresses critical gaps where employees use public AI tools without internal oversight, potentially uploading sensitive information beyond corporate technology teams' view. Mimecast research indicates that up to 95% of cyber security breaches involve human error, underscoring the central role of staff behavior in organizational security profiles.
The work on the AI risk framework, along with the proposed AI law, is being carried out by the Artificial Intelligence Governance and Economic Group (AIGEG). According to Business Standard, this inter-ministerial body coordinates AI policy across key ministries and their respective departments, as well as sectoral regulators. Formed in April this year, the AIGEG is also expected to sharpen India's broader AI strategy by funnelling the bulk of funding into a limited number of use cases capable of delivering measurable outcomes within the next 12 to 18 months. Priority sectors are likely to include healthcare, agriculture and education.
India currently lacks a unified law on AI. As reported by Business Standard, the Information Technology Act, 2000, and the Information Technology Rules, 2022 govern most AI-led tools and services in the country. Recent regulatory initiatives include CERT-In's AI-focused cybersecurity blueprints introducing enhanced organizational awareness of AI-driven cyber threats and phishing. The blueprint strengthens cybersecurity governance, enhances technical controls, and promotes continuous security validation through adversarial testing. Additionally, NBFCs are now required to establish comprehensive recovery policies covering loan collection procedures and engagement of recovery agencies, with policies mandating due diligence processes and maintaining up-to-date lists of empanelled recovery agencies.