💥Mains Ready By December. Smash Mains & Smash PYQ Admissions Open

For AI governance, hard laws and strong guardrails

Why in the News

A 154 page threat intelligence report published by Anthropic has documented nine months of artificial intelligence (AI) misuse, covering December 2025 to August 2026 across seven harm categories, from state sponsored operations to lone actors. Two days later the company’s chief executive published a blog post calling on the industry to slow the development of frontier AI, and the heads of two rival AI firms agreed within hours. The report’s significance is structural rather than evidentiary. AI is described as having moved from a tool that generates harmful content to an orchestration layer connected to other software and running multiple stages of an operation at once. The tension is that a voluntary slowdown is being proposed by the same firms whose competitive position it would protect, in a field where one major jurisdiction sits outside any such agreement.

What is AI ‘uplift’?

  1. The term: Uplift is the capability boost AI gives to an attacker, measured in the speed, scale and depth of the harm produced.
  2. The mechanism: AI sits as an orchestration layer across other software, running several stages of an operation simultaneously rather than performing a single task.
  3. What it changes: Sophisticated attacks become possible with fewer people and less expertise than were previously required.

What did the threat intelligence report document?

  1. A near fully automated disinformation operation: A flagged operation in Bangladesh was almost entirely automated. AI generated the content, other software turned it into videos, and scheduling algorithms published them at optimised times.
  2. The scale one person achieved: That single operation ran one person, 29 accounts and 1,500 fabricated stories.
  3. A distillation campaign: An Alibaba campaign used 151 million AI exchanges to copy a competitor’s capabilities.
  4. Surveillance uses: The report records AI being used as an instrument of control by those who possess it, rather than as a means of communication.
  5. The biological weapons admission: The company states that for its most capable current models it can no longer assure that a sophisticated actor could not receive meaningful assistance in biological weapons research.
  6. An incomplete picture: What was caught is a subset of what was attempted, so the documented cases set a floor rather than a total.

Why is the voluntary slowdown the wrong frame?

  1. The stated warning: The slowdown call rested on the claim that AI has been advancing far faster since the middle of the year, and that swarms of rogue AI agents could take over the internet within six to 12 months.
  2. Three obstacles to a unilateral slowdown: Competitive pressure, capital and geopolitics make a one sided pause difficult to sustain, with China operating outside any such agreement.
  3. The incentive problem: A market leader calling for a slowdown is also calling for an arrangement that protects its own lead, a point made publicly by a venture capitalist during the exchange.
  4. The reframing: The operative question is not how to slow development but how to accelerate governance, since voluntary disclosure is not a governance system.

Why is the Bangladesh case directly relevant to India?

  1. Transferable techniques: Automated account creation, AI generated content at scale and optimisation for rural low literacy audiences apply to any democracy with a large and linguistically diverse electorate.
  2. The Indian exposure: India has 950 million eligible voters and continuous State elections, so the target surface is permanent rather than episodic.
  3. Detection asymmetry: AI generated disinformation in multiple Indian languages is easy to produce and difficult to detect, which places the burden on platforms rather than on individual users.
  4. Distillation and surveillance: The Alibaba style distillation campaign will be run against Indian AI models, and the surveillance cases bear directly on the right to privacy under Article 21 of the Constitution.

What guardrails are proposed for India?

  1. Mandatory misuse reporting: Every AI platform above a defined scale threshold would be required to report detected misuse to the Indian Computer Emergency Response Team (CERT-In) and to a designated AI Safety Authority.
  2. Watermarking in political contexts: Mandatory watermarking of AI generated content in political and public interest contexts is proposed as the direct answer to the Bangladesh style operation.
  3. Covering agentic AI: Platform accountability rules must explicitly cover agentic AI, meaning systems that act in the world rather than only generate text.
  4. Criminalising distillation and API abuse: New legislation would explicitly prohibit and criminalise systematic distillation and fraudulent mass API access.
  5. A statutory regulator: A statutory body is proposed with powers to compel disclosure, audit systems and impose restrictions, on the position that governance risks can only be addressed by law.

What do the American and European positions show about India’s opening?

  1. The United States: The American position is described as constrained by a deregulatory administration, so federal statutory guardrails are not the near term route there.
  2. The European Union: The European position is described as one where regulatory ambition has at times outrun technical understanding, which limits it as a model to copy.
  3. India’s claimed advantage: India is presented as the world’s largest democracy with a record of building technology policy at scale, naming Digital Public Infrastructure (DPI), Unified Payments Interface (UPI), Aadhaar and the Information Technology Rules of 2021, and with a direct stake in AI serving 1.4 billion citizens.

Challenges to AI governance through hard law

  1. Compute and models sit outside national jurisdiction: A statutory duty binds the platform’s Indian operations while the model weights, training compute and developer sit abroad. Eg. The most capable frontier models in use in India are trained and hosted by firms headquartered in the United States and China.
    The Fix: Anchor obligations to the point of service to Indian users, so scale in India rather than location of training triggers the duty.
  2. Watermarks are removable: Provenance marking on AI generated media can be stripped by re encoding, cropping or screen capture before redistribution. Eg. Synthetic political audio clips circulate on messaging platforms as re recorded files carrying no original metadata.
    The Fix: Pair content watermarking with cryptographic provenance at capture and upload, so an absent signature is itself a detectable signal.
  3. Open weight models escape platform duties: Rules written for large platforms do not reach a model downloaded and run privately on local hardware. Eg. Open weight large language models are distributed freely and fine tuned offline without any platform intermediary.
    The Fix: Place release stage obligations on the entity publishing model weights, including safety evaluation and disclosure before public release.
  4. Regulatory capacity lags the technology: A statutory authority needs evaluation infrastructure and staff able to audit frontier systems, which is scarce and expensive. Eg. Existing Indian technology regulators depend heavily on deputation and contractual staffing for specialised roles.
    The Fix: Fund a standing model evaluation facility attached to the authority, so audits rest on in house testing rather than on developer self reporting.
  5. Overbroad drafting reaches lawful speech: A duty to detect and disrupt coordinated content operations can be applied to ordinary political campaigning and satire. Eg. Content takedown obligations under existing intermediary rules have been contested in court for their effect on lawful expression.
    The Fix: Define the triggering conduct by automation and inauthenticity of accounts rather than by the content’s subject matter.

Conclusion

The governance question has shifted from what a model outputs to what a system does across other software, and no Indian statute currently addresses that second thing. A statutory authority with audit and disclosure powers is the route proposed, and it would need enforcement reach over entities whose models are built outside India. The live tension is between a detection duty broad enough to catch automated influence operations and one narrow enough to leave political speech alone. The near term marker is whether a scale threshold and an AI specific reporting duty appear in Indian law rather than in advisories.

Government Initiatives on AI Governance in India

  1. IndiaAI Mission: Approved in 2024 under the Ministry of Electronics and Information Technology, it funds shared computing capacity, datasets, application development and a safety pillar for trusted AI.
  2. National Strategy for Artificial Intelligence: Released by NITI Aayog in 2018 under the framing of AI for All, it identified healthcare, agriculture, education, smart cities and mobility as priority sectors.
  3. Digital Personal Data Protection Act, 2023: It governs the processing of digital personal data, which is the input layer for model training and for profiling.
  4. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: These create due diligence and grievance obligations for intermediaries and significant social media intermediaries operating at scale.
  5. Indian Computer Emergency Response Team: Designated under the Information Technology Act, 2000 as the national agency for cyber incident response, collection and reporting.

Back2Basics: Distillation of AI models

  1. What it is: Distillation trains a smaller model to reproduce the behaviour of a larger one by learning from the larger model’s outputs.
  2. Legitimate use: It is a standard technique for producing cheaper and faster models for deployment on limited hardware.
  3. The misuse form: Systematic querying of a competitor’s model at very large volume can be used to copy its capabilities without access to its weights or training data.
  4. Why it is hard to police: The queries are individually ordinary, so the abuse is visible only in the aggregate pattern of account and API use.

Matching Previous Year Question

“[2023, GS3, 10] Introduce the concept of Artificial Intelligence (AI). How does AI help clinical diagnosis? Do you perceive any threat to privacy of the individual in the use of AI in healthcare?”


Join the Community

Free Daily News, Daily Prelims and Mains questions.