Anantam IASCurrent Affairs · 11 June 2026

Securing India Against AI-driven Threats: The Case for a National AI Accountability Framework

General Studies · Governance · GS II · GS III · Internal Security · Science & Tech

Why in News?

Through 2026, AI vendors released models tuned for offensive and defensive cyber work, and showed these systems can surface thousands of high-severity software flaws by reading source code directly. Read together with a domestic debate on algorithmic exclusion, this is building the case for a national AI accountability framework layered on top of the IndiaAI Mission and the data-protection regime.

The development matters in the context of:

UPSC Relevance

Prelims Relevance

Mains Relevance

GS Paper 3 (Science & Tech, Internal Security):

GS Paper 2 (Governance):

GS Paper 4 (Ethics):

Essay

Background and Context

The static anchor is India’s emerging AI-and-cyber architecture — built on three pillars.

The IndiaAI Mission — the institutional backbone

The governance choice — principles, not a statute

The security institutions — CERT-In and NCIIPC

The data-protection substrate

The global reference points

What a national framework would cover

The accountability gap — the real problem

Institutional design — the deciding factor

Challenges and concerns

Way Forward

Adopt a risk-tiered framework

Build state capacity in parallel

Conclusion

A model that defends a power grid, a model that decides who gets a subsidy, and a model a hostile actor weaponises all raise the same governance question — when the system acts, who carries the responsibility, and how does the affected person seek redress.

India has chosen a principles-based, development-friendly path deliberately. The risk is that principles without teeth become voluntary; the workable middle is risk-tiering, with hard rules only where stakes are high.

Capacity, not panic, is the right response. Accountability that protects only critical infrastructure, and not the citizen at the ration shop, is half a framework.

UPSC Practice Questions

Prelims MCQ 1

With reference to India’s AI and cyber-security architecture, consider the following statements:

  1. CERT-In functions as the national nodal agency for cyber-incident response under MeitY.
  2. NCIIPC, the agency for protecting Critical Information Infrastructure, functions under the NTRO.
  3. Section 70 of the IT Act, 2000 empowers the government to declare a computer resource a protected system.

How many of the above statements are correct?

(a) Only one (b) Only two (c) All three (d) None

Answer: (c)

Explanation:

Prelims MCQ 2

The Bletchley Declaration, signed by India along with other states and the EU, is associated with which of the following?

(a) A risk-tiered statute regulating AI within the EU (b) The first global AI Safety Summit, held in the United Kingdom in November 2023 (c) The OECD’s set of trustworthy-AI principles adopted in 2019 (d) India’s domestic AI Governance Guidelines released by MeitY

Answer: (b)

The Bletchley Declaration on managing frontier-AI risk emerged from the first global AI Safety Summit held at Bletchley Park, UK, in November 2023. The EU AI Act (2024), the OECD AI Principles (2019) and the MeitY Guidelines (2025) are distinct instruments.

UPSC Mains Questions

Frontier AI models can discover software vulnerabilities at scale, aiding both attackers and defenders. Examine the implications for India’s Critical Information Infrastructure and suggest institutional measures to manage the risk. (GS3, 15 marks, 250 words)

“India has chosen principles-based AI governance over a comprehensive statute.” Critically evaluate this approach against the regulation-versus-innovation trade-off, with reference to the IndiaAI Mission. (GS3, 15 marks, 250 words)

What is an AI accountability framework?

It is a set of rules and institutions that fix who is answerable when an AI system causes harm, require high-stakes systems to be transparent, audited and contestable, and provide affected people a route of redress. The aim is to make accountability real without blocking useful innovation.

How does AI threaten critical infrastructure?

Modern AI models can read code and find software flaws at machine speed, which attackers can use to build exploits against banking, energy and telecom systems faster than defenders can patch. The same capability also helps defenders — so the advantage goes to whoever detects and patches first.

What is the IndiaAI Mission?

It is a Rs 10,371.92 crore programme approved in 2024 and run under MeitY to build India’s AI capacity — shared compute, curated datasets, applications, skilling and a “safe and trusted AI” pillar covering bias-testing and deepfake detection. It is the backbone any accountability framework would sit on.

Who protects India’s critical information infrastructure?

NCIIPC, under the NTRO, is the nodal agency for Critical Information Infrastructure, while CERT-In, under MeitY, handles national cyber-incident response. Section 70 of the IT Act, 2000 provides the legal power to notify and protect such systems as protected systems.

How do algorithms harm the poor?

Opaque systems used in welfare, biometric authentication and credit scoring can wrongly exclude people — a failed fingerprint at a ration shop or a hidden eligibility rule — with no easy appeal. Because the excluded rarely complain, the harm stays invisible, which is exactly why accountability and redress matter.

Why not just copy the EU AI Act?

India has chosen a lighter, principles-based path to avoid the cost and rigidity a heavy statute can impose on a young AI ecosystem. The trade-off is enforceability, so the workable answer is risk-tiering — hard rules only where stakes are high, keeping innovation cheap where harm is low.