Article
CERT-In’s New AI-Vulnerability Guidelines: A Quick-Reference For OEMs, Tech Vendors And In-House Counsel
Cybersecurity regulation in India has, until now, largely spoken to the entity that suffers the breach. The 2022 CERT-In Directions issued under Section 70B of the Information Technology Act, 2000 fixed a six-hour reporting clock on the organisation that detects an incident. The new Guidelines flip the lens onto the entity upstream of that breach, the OEM or technology provider that built the product in the first place. For the first time, vendors supplying software, firmware, cloud platforms, or APIs into India carry direct, time-bound, and independently verifiable obligations of their own and not obligations that are merely passed through a customer contract, but obligations CERT-In itself may enforce.
S.S. Rana & Co. Advocates