Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

including the preservation of logs, internal breach documentation, post-incident remediation, and evi - dence of compliance with security safeguards. 6.2 Cybersecurity and AI India does not have a comprehensive standalone AI legislation yet. However, the government has intro - duced AI-specific governance frameworks and guide - lines that interact with the existing cybersecurity and data protection regime. In November 2025, the MeitY released the India Artifi - cial Intelligence Governance Guidelines (the “AI Gov - ernance Guidelines”), introducing a comprehensive framework to promote safe, inclusive and responsible AI adoption across sectors. The AI Governance Guidelines emphasise security-by- design and secure-by-default principles across the AI lifecycle, requiring developers and deployers to inte - grate safeguards at the design, training, deployment and update stages. These include controls to ensure the integrity and confidentiality of training datasets, secure access to model development environments, protection against adversarial attacks, data poison - ing, model inversion and unauthorised model extrac - tion, and continuous monitoring of deployed systems. Where AI systems are used in government systems or critical sectors, these expectations are reinforced through mandatory audits, monitoring and resilience requirements under the NCIIPC framework. The AI Governance Guidelines also highlight supply- chain and model component security as a material risk area. Organisations are expected to undertake due diligence on third-party datasets, pre-trained or foundational models, cloud infrastructure providers and outsourced AI development partners. This aligns with existing vendor and outsourcing risk manage - ment obligations under sectoral regulations, particu - larly in banking, telecoms and insurance, requiring contractual safeguards on information security, audit rights, incident reporting and restrictions on onward subcontracting. These expectations extend to soft - ware dependencies, model updates and embedded AI components that could affect system integrity or service continuity.

On 10 February 2026, the MeitY notified the much- needed amendments to the IT Rules to address the growing spread of digitally manipulated or AI-generat - ed content (commonly referred to as deepfakes), that may distort reality, mislead citizens or cause reputa - tional harm. The amended IT Rules define Synthetically Generated Information as “audio, visual or audio-visual informa - tion which is artificially or algorithmically created, gen - erated, modified or altered using a computer resource, in a manner that such information appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be per - ceived as indistinguishable from a natural person or real-world event”. The amendments mandate intermediaries that pro - vide a synthetic content creation platform to ensure that such content is prominently labelled and embed - ded with permanent metadata or other identifiers that allow it to be traced back to its origin. Intermediaries are also required to block synthetic content involving Child Sexual Abuse Material (CSAM), non-consensual intimate imagery, false documents, deceptive imper - sonation and similar unlawful material. The timelines for compliance have been significantly tightened. Intermediaries must remove unlawful mate - rial (such as material or information that is obscene, defamatory, harmful to children, threatens national security and public order, etc), within three hours of receiving notice, as compared to the earlier 36 hour window. The grievance redressal timeline has also been reduced from 15 days to seven days. Failure to comply with these obligations may result in the loss of safe harbour protection. The amended IT Rules also introduce an obligation on intermediaries to report offences under the Bharatiya Nagarik Suraksha Sanhita, 2023 and the Protection of Children from Sexual Offences Act, 2012 committed on its platform to the appropriate authorities to enable timely investigation and enforcement action. Additionally, AI-related cybersecurity incidents must be reported to CERT-In within the prescribed six-hour timeline, where applicable. Where intermediaries form

204 CHAMBERS.COM

Powered by