Thursday, August 20, 2026

India's AI Labelling Rules Six Months On: Courts Still Needed

A video of a Union Minister pocketing money lands in your family WhatsApp group. It looks right. The voice is his, the office is his, the lighting is ordinary enough to pass. Nothing on the screen tells you a machine built it, and by the time anyone official says so, your uncle has forwarded it twice.

India's AI Labelling Rules Six Months On: Courts Still Needed
TL;DR: India's IT Amendment Rules 2026 have required visible labels on AI-generated media and fast takedowns since 20 February. Six months on, a Union Minister still needed a Bombay High Court order to get deepfakes of himself pulled down. The label arrived. The enforcement did not.

Why It Matters

The rules were notified on 10 February 2026 and came into force ten days later. They do two things worth caring about. Synthetically generated information, meaning audio or video created or altered by a machine so it reads as authentic, now has to carry a label an ordinary person can actually see. And platforms have to embed permanent provenance markers into that content wherever it is technically feasible, then stop anyone from stripping them out. It is the same regulatory instinct that produced 83 security standards aimed at the handset in your pocket: fix it at the device or the platform, because chasing individual bad actors across the open internet has never scaled.

The draft wanted something blunter. A watermark covering ten percent of the frame, fixed, non-negotiable. That died before notification and was replaced by a principle: the label must be clear and prominent. Good. A hard percentage would have been unreadable on a phone and ridiculous on a television, and every design team in the country would have spent a year gaming the geometry instead of improving the disclosure. But turn it around and the change reads as an admission. Nobody could describe what a good label looks like, so the rule now describes a feeling and leaves the rest to whoever ships the app.

Then there is the clock, and the clock is where the framework quietly hands the work back to you. Platforms now face a hard deadline to pull flagged unlawful synthetic content once a lawful notice reaches them, cut sharply from the old window. Cross the significant intermediary threshold and a second duty lands: ask uploaders whether their material is machine-made, then verify that answer with technical measures instead of taking it on trust. On paper, aggressive. In practice, none of it moves until somebody notices, reports, and is believed. McAfee's State of the Scamiverse survey, published in February 2026, found Indians now spend 102 hours a year working out whether the messages hitting their phones are genuine. That is the real bill, and a shortened takedown window does nothing to it.

Takedown deadline

3 hours

Down from thirty six

Average scam loss

₹93,915

Per affected Indian respondent

Strict-tier threshold

50 lakh users

Registered accounts inside India

Cannot spot a fake

1 in 3

Indians surveyed, November 2025

The tier threshold is the number to watch, because it is a cliff rather than a slope. Cross it and you inherit the declaration-and-verification duty, which in engineering terms means building a classifier that guesses whether an upload is synthetic and then owning every case it gets wrong. Stay under it and you inherit almost nothing. Every mid-sized Indian app now has a live commercial reason to keep its registered account count comfortably short of the line, and no regulator has said a word about what happens when they do. TRAI has spent years watching this exact arithmetic play out in telecom without moving on it.

"

A three hour takedown clock means nothing to the person it was written for, because the clock only starts once she has already found the video, reported it, and been believed.

August gave the framework its first properly public test, and it is worth setting the written rule beside what actually happened in a courtroom.

Category Detail Insight
Legal basis An amendment to the existing intermediary guidelines, not a standalone AI statute Existing framework extended, not rewritten
Scope Audio, visual and audio-visual material altered to appear authentic Text-only output sits outside the rule
Label test Clear and prominent, with the draft's fixed frame percentage dropped Flexibility bought at the cost of certainty
Provenance Permanent markers embedded where feasible, with removal blocked by design Traceability outlasts any visible badge
Exemptions Routine editing, good-faith technical correction, accessibility work Ordinary photo cleanup stays untouched
Verification Uploader declares, platform checks the declaration with technical measures Platforms now own the classification mistakes
Trigger A lawful order or notice from a court or an authorised government agency Nothing moves without an external complaint
August test Bombay High Court, 5 August 2026, before Justice Arif Doctor Meta and Google agreed after court intervention

Read down that Trigger row again. The entire machine is reactive. Provenance markers, declaration duties, a stopwatch on removals, and every one of them waits for a complaint to arrive from outside. Which is why the story of the last six months is not the rule failing. It is the rule working exactly as drafted, on a schedule set by whoever has the time and standing to complain.

More wary than a year ago · 82% Social account compromised · 70% Lost money to a scam · 51% Hit by a voice-clone scam · 20% 0% 100%

The same McAfee fieldwork, run across seven countries, puts the Indian exposure picture in one frame: most people have already been hit, and most of them know it.

Friction Points

Earlier this month the Bombay High Court heard Nitin Gadkari's application against Meta Platforms over face-swapped videos and fabricated quotes tying him to the E20 ethanol controversy. Justice Arif Doctor called the material absolutely vile and abusive and said it should have no place on a public platform accessible to everyone, including the young. Meta and Google agreed in court to remove the listed content and were directed to hand over basic subscriber information for the accounts behind it. The next hearing sits roughly four weeks out. Note what that sequence required: a sitting Union Minister, senior counsel, and a High Court listing, half a year after the deadline took effect. If that is the cost of entry, the rule is not built for the woman whose face was pasted into something at two in the morning.

Here is the part nobody in the drafting room seems to have answered, and I would put it as opinion rather than fact: a labelling regime binds the people who were already going to behave. The model that stamps provenance into its output and the platform that surfaces the badge are both following rules that a deliberate faker simply routes around, using an offshore tool, a screen recording, a re-encode. So the label ends up certifying the harmless half of the internet while the harmful half stays unmarked, and no one has told readers what they are supposed to conclude from a video that carries no label at all. Absence of a badge is not evidence of authenticity. It might just mean the rule was ignored.

And there is a cost on the other side that gets less attention than it deserves. Compressing removal into hours, with safe harbour hanging on compliance, pushes platforms toward automated over-removal, because deleting a borderline clip is cheaper than defending it. Satire, political commentary, parody accounts (and yes, that includes the stuff you actually wanted to see) all sit in the blast radius. The Internet Freedom Foundation has argued the shortened windows leave no room for meaningful human review, and on that narrow point the criticism looks right to me even if the underlying goal does not.

  • An unlabelled video proves nothing either way. Treat missing provenance as unknown, not clean.
  • The clock starts at the notice, not at the upload. Reporting fast matters more than knowing the law.
  • Text is out of scope, so machine-written fake quotes and fake screenshots carry no labelling duty at all.
  • Smaller apps sit below the strict tier and owe you far less, which is where a lot of this content will migrate.
  • Provenance markers survive the label. If a clip matters, the metadata is the thing worth preserving before you forward it.
Check · Report · Hold Look for provenance data, not a corner watermark. Screenshots strip it out. Use the in-app report flow, not a comment. Only a notice starts it. Do not forward while you are still checking. Reach beats correction.

Three habits, none of which require you to read a gazette notification.

The rules are a real improvement over having nothing, and they are nowhere near what the marketing around them implied. India moved faster than most countries here, which counts for something, in the same way moving first on credit through UPI counted for something before the fine print landed. If you want a version of this that protects your household rather than a minister, the move is not legal. Go into the settings on every account your family uses, turn on whatever synthetic-media reporting the platform already offers, and use it the first time rather than the fifth, the same discipline that makes switching off Shorts on the living room television actually stick. The label is not going to save you. The report button might.

Saturday, August 1, 2026

India Wants 83 Security Rules Baked Into Your Next Phone

Your phone finished installing a security patch last night while you slept. Under a draft rule India is still arguing over, that patch would have stopped at a government body for review before it ever reached you, and the code behind it would sit in a testing lab somewhere in India. Same phone, same update, one extra reader.

India Wants 83 Security Rules Baked Into Your Next Phone
TL;DR: India's draft ITSAR package bundles 83 security standards into one rulebook for every handset sold here. Source-code review, pre-release patch vetting, and a year of system logs stored on your device. Nothing is notified yet, and the real fight is over who gets to look.

Why It Matters

Start with what already happened, because it sets the pattern. India's Ministry of Communications gave handset makers 90 days to preinstall its Sanchar Saathi app in a December 2025 order, told them to make sure users could not disable it, and withdrew the whole thing two days later after the backlash. The app survived. The mandate did not. That sequence, order first and consultation afterwards, is the thing worth watching, not any single rule inside it.

The ITSAR package is a bigger version of the same instinct. Reuters reported in January 2026 that the draft would require device makers to open source code for review at designated labs in India, submit updates and security patches to a government body before public release, run periodic on-device malware scans, and keep system logs on the handset. India's IT ministry publicly refuted the source-code characterisation the next day. Both things are on the record, and neither has been resolved since.

And here is where I part company with most of the coverage. The patch-vetting clause worries me more than the source-code clause does. Source code review is a one-time exposure that vendors can negotiate, sandbox, and lawyer around. A standing approval queue between a security fix and your handset is different: it inserts a delay into the exact process that exists to remove delay. Every hour a patch waits in a review inbox is an hour the bug it fixes is still live on 750 million devices. That is not a privacy argument. It is an arithmetic one. The same tension showed up when credit lines quietly attached themselves to ordinary UPI payments, and again when EV charging fragmented into a hundred incompatible apps: the rulebook arrives after the behaviour, and consumers absorb the gap.

Draft Standards

83

Rules in one package

Log Retention

12 months

Kept on your handset

Average Phone Price

$282

Record India price, 2025

Yearly Price Rise

8%

Counterpoint's 2025 increase

Those price figures come from Counterpoint Research's 2025 India numbers, and they belong in this conversation for a plain reason. Compliance is never free. Testing, lab submissions, and a separate India build all land somewhere in the bill of materials, and in a market where the average handset already costs more than it did a year ago, the cheapest phones are where that cost shows up first. The people most likely to buy a device with a locked-down India-specific security build are also the people least able to pay another few hundred rupees for it.

"

A year of system logs sitting on your handset is not a security feature. It is an evidence locker, and you are holding the key on someone else's behalf.

What The Draft Actually Contains

Strip away the legal briefings and the exam-prep summaries, and the package resolves into a handful of concrete changes to the device in your pocket. Some of them are things privacy advocates have wanted for a decade. Others are the opposite.

Category Detail Why It Matters
Framework ITSAR, drafted in 2023, now weighed as binding Old text, brand new legal force
Source Code Reviewed and tested at designated Indian labs Vendors call it precedent-free globally
Update Path Patches submitted for review before public release A queue sits between fix and phone
Bloatware Every pre-installed app becomes removable The one clean consumer win here
Permissions Limits on what apps may run in background Fewer apps listening while idle
Scanning Periodic malware scans running on the handset Battery and performance cost falls on you
Status Consultations open, no rules notified so far Still a draft, not yet law

Read down that table and the split is obvious. Two rows help you. Four rows help someone else and bill you for the privilege. The removable-bloatware clause alone would do more for the average budget handset in India than anything a manufacturer has shipped voluntarily in five years, which is exactly why it should not be traded away as a sweetener for the rest.

1 Dec 2025 · 3 Dec 2025 · 11 Jan 2026 · Aug 2026 Preinstall order · Order withdrawn · ITSAR draft reported · Still unnotified

The timeline above tracks four moves in eight months: a preinstall order on 1 December 2025, its withdrawal on 3 December 2025, the ITSAR draft surfacing on 11 January 2026, and no notified rule as of August 2026.

The Friction Points Nobody Has Solved

Nobody has answered the question that actually matters: who audits the auditor. A state that can read source code and clear patches before release gains real defensive capability and real surveillance capability from the identical access, and the draft says nothing about which one it is buying. That is not a conspiracy claim. It is a design gap, and it is the kind of gap that gets filled quietly by whoever holds the keys, in whichever direction is convenient at the time. My position is that access this broad needs an independent oversight body named in the rule itself, before the rule exists, not bolted on after the first misuse.

There is a fair counter-argument and it deserves stating properly. India absorbs enormous volumes of device-level fraud, and regulators have limited leverage over handset makers headquartered elsewhere. Sitting on your hands is also a choice with a body count. The complaint here is not that India is regulating phones. It is that the sequencing keeps running backwards, the same way telecom oversight arrived years after market concentration had already set.

  • Patch latency compounds: a review queue that adds even days to an emergency fix hands attackers a window that scales with every device in the country.
  • Storage and battery are finite: continuous scanning plus a year of retained logs consumes exactly the resources that budget handsets have least of.
  • Log access is undefined: the draft says logs must exist, not who may request them, under what process, or how long a request stays secret.
  • Fragmentation risk: an India-specific build that diverges from the global one tends to receive updates last, which is the reverse of the stated goal.
  • Enforcement is untested: the same withdrawal that killed the preinstall order shows how fast a mandate can move, in both directions, without warning.

Key Takeaways

India shipped 152 million smartphones in 2025 on IDC's count, roughly flat year on year, so any device rule here lands on a market that is large but no longer growing.

Nothing in the package is enforceable today. Consultations are open and no standard has been notified, which means public comment still counts for something.

The removable pre-installed apps clause is worth defending on its own merits, separately from the surveillance-adjacent clauses it currently travels with.

Read the consultation notices when they appear and say something specific about the clause you object to, because a draft with no notified rule is the only stage at which any of this is still negotiable. Once 83 standards ship as one package, nobody gets to keep the two good ones and drop the rest.

Saturday, July 11, 2026

Credit On UPI Is Quietly Rewiring How India Spends Money

The vegetable seller's QR code looks identical to the one you scanned last week. You point your phone, approve ₹40 for a kilo of onions, and walk off before the change would have hit your palm. What you may not have registered is that the money never left your bank balance. It came from a pre-sanctioned line stitched invisibly behind your UPI ID, and the repayment clock started the second the code flashed green.

That quiet swap — savings out, borrowing in, at the level of onions and auto fares — is the biggest shift in Indian payments since the QR code itself arrived. And almost nobody agreed to it on purpose.

TL;DR: Credit on UPI now lets a pre-sanctioned line fund a ₹40 QR tap, so borrowing has quietly slipped into daily subsistence spending. New merchant fees and lender rules are arriving after the habit spread, which leaves ordinary households, not regulators, to feel the real cost of it first.

Why It Matters

India runs the largest real-time payment network on the planet, and it is now a core piece of the country's digital public plumbing. In February 2026 alone the system cleared 16.6 billion UPI transactions, a number the National Payments Corporation of India (NPCI) publishes every month. When a rail carrying that much volume starts moving revolving debt instead of stored cash, the behavioral stakes stop being a banking footnote and become a household problem.

Because credit on UPI settles instantly and invisibly, it strips out the small hesitation that used to guard everyday spending. Economists call that hesitation the pain of paying, and it is the reason a card buried in a wallet restrains an impulse more than a two-second tap ever will. A typical urban household that starts routing rent-adjacent essentials through a linked line can push ₹18,000 a month of ordinary spending onto borrowed money without once feeling like it took out a loan. The bill lands later, bundled, and detached from any single purchase that caused it.

Global Payment Share
49%
Of the world's real-time payments
Approval Speed
8 sec
To approve a tap-to-borrow buy
Rolling Cost
₹640
Monthly interest on a carried balance
Usage Jump
3.4x
Rise in small daily credit taps

The steepest rise in daily-use taps is not spread evenly. It concentrates among younger earners who treat the linked line as a bridge between paydays, and that is precisely the group least able to absorb a balance quietly compounding while they aren't watching it. What starts as a convenience for a bad week hardens into a baseline for every week.

  • Impulse control weakens: a tap carries none of the friction of opening a wallet, reading a card number, or counting out notes.
  • Debt hides inside essentials: borrowing for milk and auto rides looks nothing like a loan, so it escapes the mental budgeting people reserve for an EMI.
  • Repayment is deferred and bundled: dozens of tiny buys arrive as one statement, snapping the link between a specific purchase and its true price.
Credit On UPI Is Quietly Rewiring How India Spends Money

What The New Rules Actually Change

Regulators noticed the shift and began bolting fee scaffolding around it. The table maps what is changing, who it touches, and why each line matters for an ordinary payer rather than a bank's balance sheet.

Category Detail Why It Matters
New Fee Trigger 1.1%–2% MDR on RuPay credit above ₹2,000, from 1 June 2026 Small taps stay free, big ones cost
Free By Default Bank-funded UPI carries zero merchant charge (as of 2020) Free rails built the habit first
Where Credit Flows Milk, vegetables, auto rides under ₹100 Borrowing leaks into daily subsistence
Merchant Split Street vendors exempt, larger firms charged Protects the smallest sellers
Lender Exposure Pre-sanctioned lines, high-frequency low-ticket Distress signals get harder to spot
Access Driver Any QR can now draw a linked credit line Frictionless reach accelerates spending

Read together, the rows show a system being wired for revenue and lender comfort first, with consumer guardrails arriving as an afterthought instead of a founding principle. The fee logic is precise; the protection logic is still a sketch.

1
Link
A pre-sanctioned bank line attaches to your UPI ID.
2
Tap
Any QR, from a chai stall up, can draw on it.
3
Roll
Unpaid balances revolve, and interest starts stacking.

The flow above shows how a bank credit line quietly becomes the default funding source sitting behind an ordinary QR payment.

The Friction Points Nobody Has Solved

The politics are messier than the technology. A Parliamentary Standing Committee on Finance pushed in March 2026 to bring merchant charges back for large sellers, arguing the free model is financially unsustainable at national scale. As of July 2026 that push is still a proposal, not law, and the fight around it exposes a disagreement with no clean answer.

Nobody agrees who should shoulder the cost of running these rails. Charge merchants, and small sellers may quietly start refusing credit taps. Charge users, and adoption stalls. Let banks absorb it, and the incentive to lend loosely only grows. This is a real grey area where consumer protection, merchant survival, and platform economics pull in three different directions at the same time, and pretending one side is obviously right would be dishonest.

  • Lender accountability lags: when a single line funds hundreds of tiny buys, spotting early distress in a borrower's pattern is far harder than flagging one missed EMI.
  • Dispute resolution blurs: a failed tap that still books a charge now drags in the bank, the app, and the lender, and the payer waits while they argue over who dropped the handshake.
  • Inclusion cuts both ways: the same easy access that smooths a gig worker's bad week can trap a first-time borrower in a rolling balance they never planned to carry.

Scan Now, Reckon Later

Treat the linked line as exactly what it is — a loan that just bought your onions — and open the statement before it compounds into a number you never chose. The rails moved faster than the rulebook, and for now the person best placed to apply the missing brake is the one holding the phone.