Securing India Against AI-driven Threats: The Case for a National AI Accountability Framework
Why in News?
Through 2026, AI vendors released models tuned for offensive and defensive cyber work, and showed these systems can surface thousands of high-severity software flaws by reading source code directly. Read together with a domestic debate on algorithmic exclusion, this is building the case for a national AI accountability framework layered on top of the IndiaAI Mission and the data-protection regime.
- Frontier AI models can now find software vulnerabilities at machine speed — defenders use them to patch, attackers use them to break in.
- Threat-intelligence teams reported attackers using AI to build working exploits, including one that bypassed two-factor authentication on widely used admin tooling.
- Commentators (e.g. VARINDIA) argued India was absent from vetted vendor-run vulnerability-disclosure programmes and called for a sovereign equivalent on Indian-origin models under Indian law (advocacy claims, not settled fact).
- A parallel domestic debate (e.g. Countercurrents) flagged how algorithmic systems in welfare, biometric authentication and credit scoring already exclude the poor with no easy route of appeal.
The development matters in the context of:
- An AI-enabled threat environment that rewards states with coordinated detection, disclosure and patching — and penalises those without.
- An “accountability gap” from the citizen’s side: who is answerable when an autonomous or AI-augmented system causes loss, and how the affected person seeks redress.
- India’s deliberate choice of a lighter, principles-based path over a heavy standalone AI statute like the EU’s.
UPSC Relevance
Prelims Relevance
- IndiaAI Mission — Rs 10,371.92 crore programme approved in 2024, implemented under MeitY via the IndiaAI Independent Business Division.
- India’s AI Governance Guidelines (MeitY, 2025) — principles-based, light-touch approach over a standalone AI Act.
- CERT-In — national nodal agency for cyber-incident response, under MeitY; its 2022 directions mandate reporting specified incidents within 6 hours.
- NCIIPC — nodal agency for protecting Critical Information Infrastructure (CII), under the NTRO.
- Section 70, IT Act, 2000 — empowers government to notify any computer resource as a protected system / CII.
- Digital Personal Data Protection (DPDP) Act, 2023 — India’s first horizontal data-protection law; DPDP Rules notified for phased rollout in 2025.
- EU AI Act, 2024 — world’s first comprehensive, risk-tiered AI law.
- OECD AI Principles, 2019 — standard vocabulary of trustworthy AI.
- Bletchley Park, UK (Nov 2023) — first global AI Safety Summit; produced the Bletchley Declaration, signed by India.
- Explainable AI (XAI) — methods that make a model’s decisions interpretable to humans.
- Data fiduciary (DPDP Act) — entity that determines the purpose and means of processing personal data.
Mains Relevance
GS Paper 3 (Science & Tech, Internal Security):
- Links the IndiaAI Mission and AI governance to cyber security, CII and CERT-In/NCIIPC.
- Automated vulnerability discovery compresses defenders’ response time — argues for capacity (tooling, coordinated disclosure), not just prohibitions.
GS Paper 2 (Governance):
- Regulation of an emerging technology — institutions, accountability, and the regulation-versus-innovation trade-off.
- State’s duty to provide redress for algorithmic exclusion in welfare and identity systems.
GS Paper 4 (Ethics):
- Accountability for autonomous systems; algorithmic bias against the vulnerable; explainability and contestability as ethical duties.
Essay
- Governing a general-purpose technology that is at once economic opportunity, cyber-weapon and source of algorithmic harm.
Background and Context
The static anchor is India’s emerging AI-and-cyber architecture — built on three pillars.
The IndiaAI Mission — the institutional backbone
- Rs 10,371.92 crore programme, approved March 2024, to build sovereign compute, datasets and safe-and-trusted AI capacity.
- Funds shared computing, curated datasets, application development and skilling.
- Carries a “safe and trusted AI” pillar — bias-testing tools, deepfake detection, governance research.
- The financial and institutional base any accountability framework would sit on.
The governance choice — principles, not a statute
- MeitY’s 2025 AI Governance Guidelines set a principles-based path: accountability, transparency, fairness, safety, human oversight.
- Enforced through existing sectoral laws rather than a single new AI Act.
- The bet: adaptable principles age better than rigid statutes in a fast-moving field.
The security institutions — CERT-In and NCIIPC
- CERT-In (under MeitY): national agency for cyber-incident response, alerts and coordination; 2022 directions tightened incident-reporting and log-retention duties.
- NCIIPC (under NTRO): protects CII in banking, power, telecom, transport, defence and government.
- Section 70, IT Act, 2000: legal hook to notify such systems as protected.
- India’s broader cyber-security framework rests on the IT Act backbone plus a National Cyber Security Policy and sectoral CERTs.
The data-protection substrate
- The DPDP Act, 2023 gives individuals rights over personal data and imposes purpose-limitation and security duties on data fiduciaries.
- Most algorithmic harm flows from how personal data is collected, processed and acted upon — making this the legal substrate for any accountable AI.
- Notice-and-consent design, data-principal rights of access/correction, and security obligations are India’s closest built-in check on automated processing, even though it was not written as an AI law.
The global reference points
- EU AI Act (2024): first comprehensive AI statute; sorts systems into risk tiers — bans a few uses, strict duties on high-risk, low-risk largely free.
- OECD AI Principles (2019): human-centred values, transparency, robustness, accountability.
- AI Safety Summit / Bletchley Declaration (Nov 2023): managing frontier-AI risk; India signed.
- India used the IndiaAI Impact Summit to position itself as a Global South voice — governance must not become a moat locking developing economies out.
What a national framework would cover
- Accountability: a clear answer to “who is liable” — developer, deployer or operator — so harm has a named owner.
- Transparency and explainability: high-stakes systems (credit, welfare, policing) must be auditable and contestable, not black boxes.
- Algorithmic-bias testing: mandatory fairness and impact assessment before deployment in sensitive domains, with redress for wrongly excluded citizens.
- Critical-infrastructure security: AI-augmented threat detection for banking, energy and telecom, tied into CERT-In and NCIIPC reporting.
- Human oversight: human-in-the-loop or human-on-the-loop for consequential and autonomous decisions.
- Coordinated vulnerability disclosure: a national channel for reporting AI-found flaws so defenders patch before adversaries weaponise them.
The accountability gap — the real problem
- AI makes decisions at a scale and speed no human can review case by case.
- It diffuses responsibility across model builders, fine-tuners and the deploying agency — older liability law assumes one clear actor and traceable causation.
- When a welfare algorithm wrongly drops a beneficiary or an AI-found exploit takes down a payment system, the citizen needs one answerable party and one route of redress.
- A framework’s first job: fix liability in advance, then make decisions contestable. Everything else (bias-testing, incident reporting) is downstream.
Institutional design — the deciding factor
- Choice: a new dedicated AI regulator vs accountability distributed across sectoral regulators (RBI for finance, sectoral bodies for health, CERT-In/NCIIPC for infrastructure, Data Protection Board for personal-data harms).
- A single super-regulator risks becoming a bottleneck and single point of capture; a fully distributed model risks gaps and inconsistency.
- Pragmatic answer for India’s federal, sector-heavy administration: a coordinating spine (common principles, shared audit standards, central incident-reporting) with enforcement inside the regulators that already understand each sector.
- Sovereignty matters: more critical systems depend on foreign models and cloud jurisdictions, the weaker domestic accountability becomes.
Challenges and concerns
- Liability is genuinely hard to assign across a chain of developers, fine-tuners and deployers; current law was not written for autonomous decisions.
- A heavy compliance regime can entrench incumbents and price out Indian start-ups, defeating the IndiaAI Mission’s growth goal.
- Explainability is technically limited — many high-performing models are not fully interpretable.
- Capacity is thin: CERT-In, NCIIPC and sectoral regulators need far more AI-skilled staff and tooling.
- Algorithmic harm to the poor is hard to detect — the excluded rarely complain, and biometric or eligibility failures get blamed on the citizen, not the system.
Way Forward
Adopt a risk-tiered framework
- Light obligations for low-stakes AI; hard requirements — audits, human oversight, clear liability, incident reporting — for high-stakes uses in finance, health, policing and critical infrastructure.
- Layer it on the IndiaAI Mission, the DPDP Act and the IT Act, rather than a fresh standalone law.
Build state capacity in parallel
- Equip CERT-In and NCIIPC — e.g. building on the CERT-In Cyber Defender Program — with AI-enabled monitoring and a national coordinated-vulnerability-disclosure channel.
- Mandate algorithmic-bias and impact assessments for public-facing systems.
- Guarantee a simple, lawyer-free route of appeal so accountability protects both the payment system and the citizen at the ration shop.
Conclusion
A model that defends a power grid, a model that decides who gets a subsidy, and a model a hostile actor weaponises all raise the same governance question — when the system acts, who carries the responsibility, and how does the affected person seek redress.
India has chosen a principles-based, development-friendly path deliberately. The risk is that principles without teeth become voluntary; the workable middle is risk-tiering, with hard rules only where stakes are high.
Capacity, not panic, is the right response. Accountability that protects only critical infrastructure, and not the citizen at the ration shop, is half a framework.
UPSC Practice Questions
Prelims MCQ 1
With reference to India’s AI and cyber-security architecture, consider the following statements:
- CERT-In functions as the national nodal agency for cyber-incident response under MeitY.
- NCIIPC, the agency for protecting Critical Information Infrastructure, functions under the NTRO.
- Section 70 of the IT Act, 2000 empowers the government to declare a computer resource a protected system.
How many of the above statements are correct?
(a) Only one (b) Only two (c) All three (d) None
Answer: (c)
Explanation:
- CERT-In is the national nodal agency for cyber-incident response under MeitY — correct.
- NCIIPC protects Critical Information Infrastructure and operates under the NTRO — correct.
- Section 70 of the IT Act, 2000 allows the government to notify a computer resource as a protected system / CII — correct.
Prelims MCQ 2
The Bletchley Declaration, signed by India along with other states and the EU, is associated with which of the following?
(a) A risk-tiered statute regulating AI within the EU (b) The first global AI Safety Summit, held in the United Kingdom in November 2023 (c) The OECD’s set of trustworthy-AI principles adopted in 2019 (d) India’s domestic AI Governance Guidelines released by MeitY
Answer: (b)
The Bletchley Declaration on managing frontier-AI risk emerged from the first global AI Safety Summit held at Bletchley Park, UK, in November 2023. The EU AI Act (2024), the OECD AI Principles (2019) and the MeitY Guidelines (2025) are distinct instruments.
UPSC Mains Questions
Frontier AI models can discover software vulnerabilities at scale, aiding both attackers and defenders. Examine the implications for India’s Critical Information Infrastructure and suggest institutional measures to manage the risk. (GS3, 15 marks, 250 words)
“India has chosen principles-based AI governance over a comprehensive statute.” Critically evaluate this approach against the regulation-versus-innovation trade-off, with reference to the IndiaAI Mission. (GS3, 15 marks, 250 words)
What is an AI accountability framework?
It is a set of rules and institutions that fix who is answerable when an AI system causes harm, require high-stakes systems to be transparent, audited and contestable, and provide affected people a route of redress. The aim is to make accountability real without blocking useful innovation.
How does AI threaten critical infrastructure?
Modern AI models can read code and find software flaws at machine speed, which attackers can use to build exploits against banking, energy and telecom systems faster than defenders can patch. The same capability also helps defenders — so the advantage goes to whoever detects and patches first.
What is the IndiaAI Mission?
It is a Rs 10,371.92 crore programme approved in 2024 and run under MeitY to build India’s AI capacity — shared compute, curated datasets, applications, skilling and a “safe and trusted AI” pillar covering bias-testing and deepfake detection. It is the backbone any accountability framework would sit on.
Who protects India’s critical information infrastructure?
NCIIPC, under the NTRO, is the nodal agency for Critical Information Infrastructure, while CERT-In, under MeitY, handles national cyber-incident response. Section 70 of the IT Act, 2000 provides the legal power to notify and protect such systems as protected systems.
How do algorithms harm the poor?
Opaque systems used in welfare, biometric authentication and credit scoring can wrongly exclude people — a failed fingerprint at a ration shop or a hidden eligibility rule — with no easy appeal. Because the excluded rarely complain, the harm stays invisible, which is exactly why accountability and redress matter.
Why not just copy the EU AI Act?
India has chosen a lighter, principles-based path to avoid the cost and rigidity a heavy statute can impose on a young AI ecosystem. The trade-off is enforceability, so the workable answer is risk-tiering — hard rules only where stakes are high, keeping innovation cheap where harm is low.