India Plans Tighter AI Incident Reporting Rules for Companies

The420.in Staff
10 Min Read

India is planning tighter requirements for reporting artificial intelligence-related incidents, including clearer rules on what information companies must provide and how quickly they must report such events, as the government works to align existing cybersecurity obligations with its broader AI governance framework.

What Is India Planning to Change?

The proposed changes concern the reporting of AI-related incidents. Sources in the Ministry of Electronics and Information Technology (MeitY) indicated that the government intends to tighten the norms, timeframe and content of such reporting.

The issue has gained importance as AI systems increasingly operate with greater autonomy. The proposed approach could cover incidents involving AI and machine learning systems, including cases where AI agents act beyond their intended tasks.

India’s 2025 AI Governance Guidelines already propose a broader mechanism for tracking harms caused by AI. The emerging question is how that framework will work alongside the country’s existing mandatory cybersecurity incident-reporting regime.

What Must Companies Already Report?

Under CERT-In’s 2022 Cyber Security Directions, service providers, intermediaries, data centres, body corporates and government organisations are required to report specified cyber incidents within six hours of noticing them or being informed about them.

The mandatory list includes data breaches, data leaks, unauthorised access, attacks on cloud systems and other attacks. It also covers malicious or suspicious activity affecting systems, software or applications related to AI and machine learning.

CERT-In guidance describes attacks targeting machine learning models as including attempts to cause malfunction or improper behaviour. Such attacks may use techniques such as deceptive data or environment manipulation to corrupt a model and cause it to behave incorrectly.

The existing CERT-In framework therefore already covers cyberattacks targeting AI systems. What remains unclear is whether MeitY plans tighter reporting requirements specifically for AI-related cybersecurity incidents, or whether future rules could extend to AI systems that cause harm or behave unexpectedly without an underlying cyberattack.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

What Could Count as an AI Incident?

The 2025 AI Governance Guidelines take a broader approach to AI incidents than the existing CERT-In cybersecurity framework.

They adopt the OECD definition of an AI incident as an event or series of events in which the development, use or malfunction of an AI system directly or indirectly causes harm.

Such harm can include harm to health, disruption of critical infrastructure, human-rights violations, or damage to property, communities or the environment.

The guidelines separately identify risks including malicious use of AI, bias and discrimination, transparency failures, systemic risks, loss of control over AI systems and national-security threats.

This means the proposed AI governance approach extends beyond conventional cyberattacks. However, the guidelines are recommendations for India’s AI governance framework and do not themselves replace CERT-In’s mandatory cyber incident-reporting rules.

Who Could Be Required to Report?

Under the existing CERT-In Directions, reporting obligations apply to service providers, intermediaries, data centres, body corporates and government organisations. Individual citizens are not covered by these directions.

AI systems, however, often involve several organisations. One company may develop the underlying model, another may provide access to it, while another deploys it within a product or service.

The AI Governance Guidelines recommend clear accountability across the AI value chain, with liability linked to the function performed. They also state that responsibility should take account of the level of risk and whether an entity exercised due diligence.

The guidelines do not, however, create a new mandatory AI incident-reporting obligation specifying whether the developer, provider or deployer must make the report. Determining responsibility across the AI value chain is therefore one of the issues MeitY would have to address if it expands the reporting framework.

How Quickly Could AI Incidents Be Reported?

For cyber incidents covered by CERT-In’s existing directions, the current reporting deadline is six hours from the time an organisation notices the incident or is informed about it.

Companies do not need to have a complete investigation before making the initial report. CERT-In guidance allows entities to provide information available at the time of reporting and submit additional information later within a reasonable period.

MeitY’s reported plan to tighten the timeframe does not specify whether the existing six-hour requirement will change or whether a different deadline would apply to certain AI incidents.

That distinction could be significant. Some AI failures may require examination of system inputs, outputs, model behaviour and autonomous actions to establish what happened, rather than simply identifying a cyberattack.

Expert View

Prof. Triveni Singh, renowned cybercrime expert and former IPS officer, said:

“AI incidents can move much faster than traditional cyber incidents. An autonomous system may take actions before a human even understands what has happened. Companies should know exactly what must be reported, who is responsible and how quickly they must act. Clear reporting rules will help India identify AI risks early and prevent the same failures from spreading.”

What Information Could Companies Have to Disclose?

MeitY is also considering tighter requirements concerning the content of incident reports, although the precise additional information companies could be required to provide is not yet specified.

The existing CERT-In regime already imposes substantial information-retention requirements. Covered organisations must maintain ICT system logs for a rolling 180 days. They must provide those logs to CERT-In when reporting an incident or when directed to do so, and CERT-In can also seek additional information in a specified format and timeframe.

The OECD’s AI-specific framework offers one possible reference for more detailed reporting. It contains 29 criteria across eight areas, including basic information about the incident, its severity and type of harm, affected people, economic context, training data and inputs. It also includes information about the AI model, the system’s task and level of autonomy, and measures taken to stop, prevent or mitigate the harm. Seven criteria are mandatory under the OECD framework.

There is no indication, however, that India has decided to adopt those 29 criteria. The connection is that the Indian AI Governance Guidelines use the OECD definition of an AI incident while the government develops its proposed reporting framework.

How Could AI Reporting Fit With CERT-In?

India is also planning a national AI incident database, separate from CERT-In’s existing mandatory cybersecurity reporting system.

The 2025 AI Governance Guidelines recommend creating a national database to collect evidence about real-world harms caused by AI. The proposed database would operate as a central system capable of collecting information from smaller databases maintained by authorised entities or sectoral regulators under a common reporting structure.

The guidelines also recommend using existing mechanisms, such as CERT-In’s system, to monitor AI vulnerabilities in critical sectors.

Participation in the proposed AI incident database is envisioned differently from CERT-In’s mandatory cybersecurity reporting requirements. Organisations would be encouraged to report incidents through protocols protecting confidentiality, while the database would also draw information from other sources, including media reports and publicly available research.

The government’s approach therefore currently has two distinct elements: CERT-In’s mandatory reporting regime for specified cybersecurity incidents, including attacks and malicious or suspicious activity affecting AI and machine learning systems, and a broader AI governance framework designed to collect information about real-world AI harms.

How those systems will eventually work together, and whether mandatory CERT-In requirements will be expanded specifically for AI incidents, remains to be determined.

The420 Takeaway

India already requires specified cyber incidents affecting AI and machine learning systems to be reported under CERT-In rules. The next challenge is broader: deciding how to report AI failures that cause harm even without a conventional cyberattack. Clear rules on responsibility, reporting timelines and required information will be critical as AI systems become more autonomous.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected