India is set to tighten requirements for reporting AI-related incidents, including stricter timelines and expanded information disclosure, according to sources in the Ministry of Electronics and Information Technology (MeitY) cited by The Economic Times on September 21. The move aims to enhance the current framework under CERT-In’s 2022 Cyber Security Directions, which mandates reporting specified cyber incidents within six hours of detection or notification.
The tightening of norms will focus on cybersecurity threats and incidents involving AI systems acting autonomously beyond their intended tasks. MeitY sources highlighted that while an obligation to report such incidents already exists, the government is working to refine the timeframe and content of these reports. This development aligns with the broader 2025 India AI Governance Guidelines, which propose a comprehensive system for tracking harms caused by AI technologies.
Currently, CERT-In’s directions require service providers, intermediaries, data centres, corporates, and government bodies to report incidents such as data breaches, unauthorized access, and malicious activities affecting AI-related systems within six hours. The enhanced rules are expected to integrate these existing mandates with the new governance guidelines, potentially expanding the scope and detail of incident reporting to better address risks posed by AI and machine learning systems.
The next step involves finalizing how the updated reporting requirements will coexist with the 2025 AI Governance Guidelines. This integration will shape India’s regulatory approach to AI safety and accountability, with the government already engaged in revising the reporting framework to ensure timely and comprehensive disclosure of AI-related cyber incidents.