India AI regulation

India's AI Incident Reporting Overhaul Will Test Whether a Six-Hour Cyber Rule Can Stretch to Cover Algorithmic Harm

MeitY plans to tighten AI incident reporting timelines and content, layering a new regime atop CERT-In's 2022 six-hour cyber rule.

India's Overlapping AI Incident Regimes People of Internet Research · India 6 hours CERT-In reporting window The 2022 mandate already covers AI… 7 principles AI Governance Guidelines principles MeitY's Nov 2025 framework rests o… Voluntary National AI incident database The proposed database currently in… Feb 2026 Deepfake labeling rules effective IT Amendment Rules 2026 already ad… peopleofinternet.com
India's Overlapping AI Incident Regime… People of Internet Research · India 6 hours CERT-In reporting window 7 principles AI Governance Guidelines princ… Voluntary National AI incident database Feb 2026 Deepfake labeling rules effective peopleofinternet.com

Key Takeaways

A cybersecurity rule stretched to fit AI

On September 21, 2026, Business Standard reported that India's Ministry of Electronics and Information Technology (MeitY) plans to tighten the rules governing how companies report AI-related incidents — expanding what must be disclosed, shortening the timelines, and clarifying the content of reports. Sources told the paper the trigger was a direct question about AI agents "acting autonomously beyond their intended tasks," and the ministry's answer was blunt: "We will have to tighten the norms, timeframe and content of the reporting, we are already doing that" (Medianama, Sept 22, 2026).

This isn't a new law. It's a retrofit. Since April 28, 2022, CERT-In's Cyber Security Directions under Section 70B of the IT Act have required intermediaries, data centres, cloud providers and body corporates to report specified cyber incidents within six hours of detection (CERT-In Directions, 70B, April 28, 2022). That list already sweeps in "malicious or suspicious activity" affecting AI and machine-learning systems. MeitY's plan, as described to Business Standard, is to sharpen that existing hook rather than legislate a standalone AI incident law — at least for now.

The steelman: six hours wasn't built for this

The case for tightening deserves to be taken seriously. CERT-In's six-hour clock was designed around classic cybersecurity events — breaches, ransomware, unauthorized access — where "noticing" the incident is usually unambiguous: a system goes down, data leaves the network, a log flags an intrusion. An autonomous AI agent that quietly executes actions outside its intended scope, or a model that produces systematically biased outputs over weeks, doesn't announce itself the same way. A generic breach-reporting form built for perimeter security genuinely may not capture what regulators need to know — root cause in training data versus deployment configuration, whether the failure is reproducible, how many downstream systems ingested a bad output. Given how fast agentic AI deployment is moving in India's financial services, healthcare and public-sector pilots, a government that waits for a legislative AI Act before demanding better incident data would be gambling with a fast-moving risk. MeitY's instinct to move via directive rather than wait for primary legislation is, on its own terms, defensible urgency.

Where the case weakens: two regimes, one undefined boundary

The problem is that India is now building two incident-reporting tracks that don't yet talk to each other. The 2025 India AI Governance Guidelines, published by MeitY on November 5, 2025, propose a national AI incident database — but as a voluntary mechanism, explicitly framed to invite reporting "without the threat of penalties," covering a far broader harm taxonomy than cybersecurity: bias and discrimination, transparency failures, systemic risk, loss of control (India AI Governance Guidelines, MeitY, Nov 2025). CERT-In's regime, by contrast, is mandatory and penalty-backed, but scoped to security incidents, not model behavior generally.

An agent that acts "beyond its intended tasks" might be a security event, a governance failure, both, or neither — and right now nothing in the public record says which door a company reports it through, what counts as a reportable AI incident versus routine model drift, or how a mandatory six-hour cyber deadline squares with a voluntary, penalty-free AI database sitting next to it. Medianama's reporting flags exactly this: MeitY "hasn't clarified how these frameworks will integrate or which entities bear reporting responsibility across the AI development chain." Layering stricter obligations onto an undefined boundary doesn't fix the ambiguity — it raises the stakes of guessing wrong.

Compliance debt is already compounding

This tightening doesn't land in a vacuum. Since February 20, 2026, the IT (Intermediary Guidelines) Amendment Rules 2026 have imposed binding synthetic-media obligations — mandatory labeling, embedded metadata, and user declarations for AI-generated content — backed by loss of safe-harbor protection for non-compliance (CMS Law, AI Regulation Scanner: India). A company operating in India today is already reconciling deepfake-labeling duties, the six-hour CERT-In clock, and a voluntary AI database, with a fourth, still-undefined AI-incident regime now layered on top. Each rule individually is defensible. The aggregate is a compliance surface with no single map.

The right fix is integration, not addition

None of this argues against tighter AI incident reporting on the merits — algorithmic harms genuinely need faster, more specific disclosure than a generic breach form provides, and MeitY is right to treat autonomous-agent failures as a live risk rather than a hypothetical one. But the fix that actually serves both safety and industry is publishing a single, scoped definition of a "reportable AI incident" that tells companies which of the two regimes applies, when, and why — before shortening any clock or expanding any content requirement. Absent that, tightening the norms without defining the boundary mostly guarantees that companies over-report defensively into whichever channel is mandatory, drowning CERT-In in noise, while the voluntary database — the one built to actually study AI-specific harm — stays thin because nothing requires anyone to use it.

"We will have to tighten the norms, timeframe and content of the reporting, we are already doing that." — MeitY sources, in a report carried by Business Standard, September 21, 2026

Sources & Citations

  1. CERT-In Cyber Security Directions, April 28, 2022
  2. India AI Governance Guidelines, MeitY, Nov 2025
  3. Medianama: India plans tighter AI incident reporting rules
  4. The420.in: India will not pause AI research, plans tighter incident reporting
  5. CMS Law: AI Regulation Scanner — India