India Plans Tighter Rules for AI Incident Reporting
India is preparing to strengthen requirements for reporting AI-related incidents, specifying the information companies must provide and the timeframe for reporting.

India's Ministry of Electronics and Information Technology (MeitY) is planning to tighten regulations for reporting incidents involving artificial intelligence (AI). The proposed changes will affect the type of information companies are required to submit and the deadlines for reporting such incidents, according to reports citing sources within the ministry.
Currently, companies are already obligated to report certain cybersecurity incidents related to AI and machine learning systems within six hours of discovery under existing CERT-In directives. Alongside this, the government's proposed AI Governance Guidelines for 2025 suggest a broader framework for tracking harms caused by AI.
The precise integration of these two approaches remains unclear. While the ministry intends to tighten norms, it is yet to be specified whether the new rules will exclusively address cybersecurity incidents or also encompass harms stemming from AI system malfunctions or unintended behaviors without an underlying cyberattack.
The existing CERT-In framework mandates reporting for events like data breaches, unauthorized access, and attacks targeting AI models. The upcoming regulatory adjustments may broaden these requirements to include a wider range of AI system failures and their consequences, potentially necessitating enhanced monitoring and quicker response mechanisms from affected companies.