India Introduces Stricter AI Incident Reporting Rules for Companies
India is set to implement stricter requirements for reporting artificial intelligence-related incidents, with proposed measures focusing on defining the scope of information to be disclosed, the timeframe for reporting, and the entities responsible for compliance.
MeitY’s Initiative
The initiative, driven by the Ministry of Electronics and Information Technology (MeitY), aims to address the growing complexity of AI systems as they operate with increasing autonomy. The plan builds on existing frameworks while introducing new considerations for incidents involving AI and machine learning systems, including scenarios where AI agents deviate from their intended functions.
2025 AI Governance Guidelines
The 2025 AI Governance Guidelines already outline a framework for tracking harms caused by AI, but the integration of these principles with India’s existing mandatory cybersecurity incident-reporting regime remains under discussion.
CERT-In Cybersecurity Framework
Under the current CERT-In 2022 Cyber Security Directions, service providers, intermediaries, data centers, and government entities are required to report specified cyber incidents within six hours of detection. This includes data breaches, unauthorized access, cloud system attacks, and malicious activity targeting AI and machine learning systems.
Definition of AI Attacks
CERT-In defines attacks on machine learning models as attempts to induce malfunctions or improper behavior, often through techniques like data manipulation or environmental interference.
Proposed Changes and Challenges
The proposed changes raise questions about whether MeitY will impose stricter reporting rules specifically for AI-related cybersecurity incidents or expand the scope to include AI systems that cause harm without a direct cyberattack.
OECD’s AI Incident Definition
The 2025 AI Governance Guidelines adopt the OECD’s definition of an AI incident, which encompasses harm to health, disruption of critical infrastructure, human rights violations, and environmental damage. This broader approach includes risks such as AI bias, transparency failures, systemic risks, and loss of control over autonomous systems.
Expert Opinions and Recommendations
Experts emphasize the urgency of clarifying reporting obligations. Prof. Triveni Singh, a cybercrime expert, noted that AI incidents can unfold rapidly, with autonomous systems taking actions before human intervention is possible. He stressed the need for clear guidelines on what must be reported, who is responsible, and the required response timelines.
“AI incidents can unfold rapidly, with autonomous systems taking actions before human intervention is possible. He stressed the need for clear guidelines on what must be reported, who is responsible, and the required response timelines.”
Future Frameworks and Databases
MeitY is also considering enhanced disclosure requirements for incident reports, though specific details remain undefined. The existing CERT-In regime mandates that organizations retain ICT system logs for 180 days and provide them during incident reporting.
National AI Incident Database
A separate national AI incident database is also under consideration, distinct from CERT-In’s cybersecurity reporting system. The 2025 AI Governance Guidelines propose a centralized repository to collect data on real-world harms caused by AI, drawing information from sectoral regulators, authorized entities, and external sources like media reports.
Conclusion
The government’s approach currently includes two distinct elements: CERT-In’s mandatory reporting for cybersecurity incidents, including AI-targeted attacks, and a broader AI governance framework focused on documenting real-world harms. The integration of these systems remains to be clarified, with challenges around accountability across the AI value chain.
