💥Mains Ready By December. Smash Mains & Smash PYQ Admissions Open

Subject: Internal Security

  • Govt. to spend Rs 24,000 crore to modernise police force

    Govt. to spend Rs 24,000 crore to modernise police force

    Why in the News

    The Union government has told the Supreme Court that it has begun implementing an umbrella Police Modernisation Mission worth Rs 24,000 crore over the next five years.

    What is the Police Modernisation Mission?

    1. Its form: It is an umbrella scheme, meaning several police modernisation components are funded through a single mission rather than as separate schemes.
    2. Its size and horizon: The outlay is Rs 24,000 crore, to be spent over five years.
    3. Who it covers: It targets the internal security capabilities of both State police forces and the Central Armed Police Forces.
    4. Its stated route: The capability gain is to come through greater use of technology, which is the only delivery mechanism named in the submission.

    Why was the disclosure made in a court proceeding?

    1. The proceeding was begun by the Court itself: The suo motu case was initiated in 2025 after the Court took note of a media report on non functional CCTV cameras at Udaipur police stations.
    2. The Court widened it into a compliance review: It sought compliance reports from the Centre, the States and the Union Territories on the installation and functioning of cameras.
    3. The Bench: The matter is before a Bench of Justices Vikram Nath and Sandeep Mehta, with the Centre represented by an Additional Solicitor-General.
    4. The mission answers the compliance question with an outlay: The Centre’s response to a record of equipment not working is a larger programme to buy equipment, and no separate maintenance or functioning guarantee was placed before the Court.

    What did Paramvir Singh Saini versus Baljit Singh require?

    1. Cameras at specified locations: The 2021 judgment mandated CCTV cameras at key locations in police stations, including lock ups and the rooms of inspectors and sub-inspectors.
    2. Cameras of a specified capability: The directions required night vision and audio recording, so that an interrogation is recorded and not merely observed.
    3. Footage retention: Recordings were to be preserved for a stated minimum period, so that a complaint filed months later can still be tested against the record.
    4. Oversight bodies: State level and district level oversight committees were to be constituted to purchase, maintain and monitor the systems and to review footage.
    5. Notice to the public: Police stations were to display notices telling visitors that the premises are under camera cover and that a complaint of human rights violation may be made.

    Challenges to the Police Modernisation Mission

    1. Modernisation money has historically gone unspent: Releases under police modernisation schemes stall on State matching shares and pending utilisation certificates. Eg. Successive Comptroller and Auditor General audits have flagged underutilisation of police modernisation grants by States.
      The Fix: Release tranches against verified physical milestones, meaning equipment installed and functioning, rather than against expenditure statements.
    2. Central money buys equipment, not reform: Police is a State subject under Entry 2 of the State List, so a central mission can fund hardware without touching recruitment, tenure or accountability. Eg. Directions in Prakash Singh versus Union of India (2006) on fixed tenure and a State Security Commission remain only partly implemented across States.
      The Fix: Condition a share of each State’s mission grant on enactment of the police board and fixed tenure directions.
    3. Technology fails at the point of maintenance: Installed systems stop working for want of annual maintenance contracts, spares and power backup, and the capital grant does not cover them. Eg. Audits have found Crime and Criminal Tracking Network and Systems terminals installed but not in use at a large number of police stations.
      The Fix: Fund a five year maintenance and consumables line inside each equipment sanction, instead of leaving it as a separate State liability.
    4. Manpower shortfall caps what technology can deliver: A camera or a database still needs an officer to operate, review and act on it, and State forces run well below sanctioned strength. Eg. Bureau of Police Research and Development data records an actual police strength close to 150 personnel per lakh population, against the United Nations recommended figure of 222.
      The Fix: Tie mission approval to a State recruitment schedule closing sanctioned vacancies across the same five years.
    5. Surveillance capacity grows faster than the oversight around it: Equipment installed for accountability also expands the force’s own recording and identification capability, with no independent auditor of its use. Eg. Access logs for police station footage are held and reviewed by the same force whose conduct the footage records.
      The Fix: Place footage access logs and retention compliance under an independent State level oversight body publishing an annual report.

    Conclusion

    The mission has moved from announcement to implementation, and it was disclosed in a proceeding about equipment already mandated and not functioning. Buying capability and sustaining it are different problems, and only the first has an outlay attached to it. The next point to watch is the compliance reports the Court has sought from the Centre, the States and the Union Territories, which is where the gap between equipment sanctioned and equipment working becomes visible.

    Back2Basics: Central Armed Police Forces

    1. What they are: Seven armed forces of the Union under the Ministry of Home Affairs, distinct both from the armed forces under the Ministry of Defence and from State police.
    2. The seven forces: Central Reserve Police Force, Border Security Force, Central Industrial Security Force, Indo-Tibetan Border Police, Sashastra Seema Bal, Assam Rifles and the National Security Guard.
    3. How they are used: They are deployed to States on requisition for internal security duty, election duty and disaster response, and guard specified international border sectors.
    4. Command and recruitment: Each is headed by a Director General, with officer recruitment through the Union Public Service Commission and other ranks through the Staff Selection Commission.

    [2023, GS3, 15 marks] What are the internal security challenges being faced by India? Give out the role of Central Intelligence and Investigative Agencies tasked to counter such threats.

  • US settlement with Meta is a start. India must protect itself

    US settlement with Meta is a start. India must protect itself

    Why in the News

    Meta has agreed to pay up to $17.1 billion to resolve child harm claims brought by a bipartisan coalition of attorneys general across the United States, its territories and the District of Columbia.

    What does the settlement require Meta to do?

    1. The scale and the date: The agreement was reached on 26 August and ranks among the largest consumer protection settlements in internet history.
    2. Default time limits and night restrictions: Users under 18 get default limits on time spent and restrictions on night time use.
    3. Limits on notifications during school hours: The company must curb notifications sent to minors while school is in session.
    4. Age assurance: The settlement requires enhanced measures to establish whether a user is a minor before the account is treated as an adult account.
    5. Independent compliance oversight: Compliance with the safeguards is monitored by an independent party rather than reported by the company itself.

    Why does the penalty carry little punitive weight?

    1. The sum is small against the revenue base: The company generated $201 billion in revenue in 2025, and the settlement is payable over 10 years.
    2. The market read it as a cost, not a shock: The stock rose 5 per cent after the settlement was announced.
    3. The reforms are the substance, not the money: The mandated safety changes go to how Facebook and Instagram are allowed to operate for minors, and they are overdue rather than novel.

    Why has India’s own debate produced no comparable outcome?

    1. The cycle is episodic and self closing: A tragedy occurs, outrage follows, a platform issues a statement, a parliamentary question may be asked, and silence returns.
    2. The harm is not less serious here: The absence of Indian legal action reflects the absence of a process capable of compelling answers, not a smaller problem.
    3. Regulatory attention has been lighter than in the West: Global platforms have operated in India with weaker oversight and lower public awareness than they face in other large markets.

    What did the American case produce that India lacks?

    1. Court compelled discovery: The litigation forced the company to produce internal research, design documents and executive communications about child safety, under oath, in public and subject to cross examination.
    2. The questions India cannot currently ask: What internal research shows about the mental health impact on Indian teenage girls, how the recommendation engine behaves in Hindi, Tamil and Bengali for a fourteen year old at 11 pm, and how many Indian children under 13 are active on platforms that legally prohibit their membership.
    3. The unmeasured scale of abuse material: The scale of child sexual abuse material affecting Indian users and the manner of its reporting are not on any public record. Eg. In the United States alone, 7.5 million such materials were under internal review.
    4. Whether the same design was applied here: If the addictive design features at issue in the American cases were applied to Indian users, those users have been exposed to the same harm with none of the protection.

    What legal tools does India already hold?

    1. The statutory base already exists: The Consumer Protection Act, 2019, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Protection of Children from Sexual Offences (POCSO) Act, 2012, the Juvenile Justice (Care and Protection of Children) Act, 2015 and the Constitution together cover the conduct alleged.
    2. A regulator level inquiry: The National Commission for Protection of Child Rights (NCPCR), the statutory body for child rights, can open a formal inquiry compelling platforms to produce India specific safety research, algorithm documentation, data on underage users and internal harm research.
    3. Direct recourse for families: Affected families can approach consumer forums and High Courts directly, without waiting for a regulator to act first.
    4. Coordinated State litigation: State governments can file consumer protection and child safety suits in Indian courts, and a single State moving first can trigger a wider set of filings.
    5. The policy standard is already stated: The Safe, Trusted and Accountable framework developed in 2021 was built so that platforms operating at scale bear legal responsibility for the consequences of their design choices.

    Why is new legislation still needed?

    1. Existing law compels disclosure only case by case: Each of the routes above produces documents inside one proceeding, so nothing survives the case that produced it.
    2. A statutory right to algorithmic disclosure: Parliament can create an obligation on platforms to reveal their content moderation policies, recommendation engine parameters and child safety research for Indian users.
    3. A standing recipient rather than a court: The disclosure would run to a designated Indian authority, which turns a litigated exception into a continuing duty.

    Challenges to compelling platform disclosure in India

    1. No child rights regulator holds standing discovery power: A statutory commission can summon information, and it cannot compel sworn production of internal research open to cross examination. Eg. Platform responses to Indian regulators are routinely filed as written submissions rather than as evidence tested in a hearing.
      The Fix: Give the child rights commission discovery powers with a stated penalty for non production, on the model available to a commission of inquiry.
    2. Consumer forums cannot read algorithmic evidence: A district or State consumer commission has no technical assessor able to interpret recommendation engine documentation. Eg. Consumer adjudication in India is built around defective goods and deficient services, not around product design telemetry.
      The Fix: Attach a standing panel of technical assessors to the National Consumer Disputes Redressal Commission for platform cases.
    3. The evidence sits outside Indian process: Internal research and design documents are held on servers abroad and reached through mutual legal assistance. Eg. Mutual legal assistance requests to the United States for platform records routinely take more than a year to return.
      The Fix: Write a production obligation for India specific safety research into intermediary due diligence, so the duty attaches to operating in India rather than to where a server sits.
    4. Safe harbour blunts liability for design: Section 79 of the Information Technology Act, 2000 shields intermediaries for third party content, and design and ranking choices are argued into that shelter. Eg. Platforms have defended recommendation ranking as an automated function rather than as an editorial act.
      The Fix: Separate design and ranking decisions from hosting in the due diligence rules, so safe harbour covers content and not product architecture.

    Conclusion

    Platform accountability in India has been argued at the level of statements and outrage, never at the level of evidence. The material that would establish whether Indian children were exposed to the same design choices sits with the platforms, and no Indian process currently compels its production. Legislation would convert that into a standing duty, and litigation would produce it once. The marker to watch is whether any Indian regulator or State government files an action carrying discovery powers, rather than another request for information.

    Online child safety in India

    1. What the domain covers: It governs how platforms design products for users below 18, across age of access, consent, exposure to content and collection of data.
    2. The regulatory age is higher than the platform age: Indian data protection law treats anyone below 18 as a child, while platforms set their own account creation floor at 13.
    3. States have moved before the Centre: Karnataka announced plans to bar social media for those under 16, and Andhra Pradesh announced restrictions for those under 13.
    4. The evidence base cited officially: Research highlighted in the Economic Survey 2025-26 records that adolescents lack the neurological brakes needed to resist addictive features such as infinite scroll.

    Laws and Rules Governing Online Child Safety

    1. Digital Personal Data Protection Act, 2023: It treats any individual below 18 as a child, requires verifiable parental consent before processing a child’s data, and prohibits behavioural tracking and targeted advertising directed at children.
    2. The Data Protection Board of India adjudicates breaches and imposes penalties under the Act, with appeals lying to the Telecom Disputes Settlement and Appellate Tribunal.
    3. Information Technology Act, 2000: Section 67B criminalises publishing or transmitting material depicting children in sexually explicit acts, and extends to browsing and downloading such material.
    4. Indian Penal Code and Bharatiya Nyaya Sanhita provisions on obscenity: They cover sale and circulation of obscene material to a person under 20, and operate alongside the specialised child protection statutes.

    Key Facts about Online Child Safety

    1. Australia set a minimum age of 16 for social media accounts through the Online Safety Amendment (Social Media Minimum Age) Act 2024, enforced from December 2025.
    2. Indonesia became the first Southeast Asian country to enforce a ban for under 16s, in March 2026.
    3. Gaming disorder is classified as a health condition in the World Health Organization’s International Classification of Diseases, Eleventh Revision (ICD-11).
    4. Kerala runs Digital De-Addiction centres, known as D-DAD centres, for children showing signs of compulsive device use.

    Challenges in Online Child Safety

    1. Age verification is easily circumvented: A minimum age holds only where the platform can establish age, and self declared dates of birth cannot be checked. Eg. Children open accounts on platforms barring under 13s using a false year of birth or an adult family member’s account.
      The Fix: Move to privacy preserving age estimation processed on the device, rather than to identity document uploads.
    2. Verification itself creates a new privacy risk: Establishing age through selfies, identity documents or bank details assembles a fresh database of minors’ sensitive data. Eg. Document based age checks require a child to hand a platform the exact identifiers the law is trying to keep from it.
      The Fix: Require age signals to be discarded once the check is complete, with a bar on retaining the underlying document.
    3. A ban pushes use underground: Restriction moves minors to less regulated services and to tools that hide their location. Eg. Teenagers migrate to smaller platforms or route access through virtual private networks.
      The Fix: Replace a binary ban with a graduated model, strict restriction under 13, supervised access from 13 to 15, and full access at 16.
    4. Restriction removes support networks for some children: Online communities are the only peer support available to some minors, and a blanket bar cuts that too. Eg. LGBTQ+, neurodivergent and disabled children frequently depend on such communities.
      The Fix: Exempt verified support, counselling and helpline services from minor account restrictions.

    [2025, GS2, 15 marks] The National Commission for Protection of Child Rights has to address the challenges faced by children in the digital era. Examine the existing policies and suggest measures the Commission can initiate to tackle the issue.”

  • Police camera ‘caught’ murder, rape accused at Jantar Mantar protest

    Police camera ‘caught’ murder, rape accused at Jantar Mantar protest

    Why in the News

    The Delhi Police has told the Supreme Court that its Facial Recognition System (FRS) spotted 2,873 people with criminal antecedents at the main protest site at Jantar Mantar between 20 and 26 July. The submission follows a Supreme Court order quashing every First Information Report (FIR) arising from the exam leak student protests.

    What is the Delhi Police’s Facial Recognition System?

    1. What the software does: It places boxes around faces detected in a camera feed and compares them against images held in police databases.
    2. The threshold for a positive match: A match is treated as positive at an accuracy rate of 80 per cent, a figure the force disclosed in a 2022 reply under the Right to Information (RTI) Act, 2005.
    3. What it searches against: Of the 2,873 flags, 2,402 were attributed to Crime Kundli, the force’s own biometric database, and 471 to criminal records.
    4. What the output is not: A match is not by itself proof of identity, and performance varies with the algorithm, camera angle, lighting, image quality, masks and the database being searched.

    What does the offence-wise breakdown in the affidavit show?

    1. The residual category is the largest by far: 1,884 of the 2,873, close to two thirds, sit under other Indian Penal Code, Bharatiya Nyaya Sanhita and special law entries rather than under any named serious offence.
    2. The legal status of those flagged is unstated: The affidavit does not specify whether the people identified were accused, convicts, or merely named in criminal cases.
    3. The database is claimed to hold only serious offenders: The affidavit states that the face and other material of only those accused facing serious offences are in the police record, and not those facing petty offences such as traffic violations.
    4. The geographic concentration: The North district recorded the highest count at 285, followed by Outer at 257, North West at 256, North East at 174, East at 173 and South West at 166. Railways, Crime Branch, IGI Airport, Metro and the Special Cell were among the other units listed.

    What did the record check of 205 flagged individuals find?

    1. The sample examined: The 205 comprised 101 murder accused, 61 rape accused, 6 accused under the Protection of Children from Sexual Offences (POCSO) Act, 2012, and 37 of the 62 listed under attempt to murder.
    2. The finding: At least 25 of them were lodged in the Tihar, Mandoli or Rohini prison complexes at the time the system flagged them, according to police, jail and court records.
    3. The composition of the 25: 17 were accused in murder cases, 4 in rape cases of which 3 were under the POCSO Act, and 4 in attempt to murder cases.
    4. The dates of the flags: Three of the 25 were identified on 24 July, 21 on 25 July and one on 26 July, the final day of the protest.

    Why does the police assurance not settle the question?

    1. Verification is the only safeguard on record: The stated position is that action follows only after field verification establishes that the person was in fact present at the site, and no verification standard, timeline or reporting duty accompanies that assurance.
    2. Verification is still pending at scale: The force has stated that further verification of the identified individuals is pending, which leaves 2,873 names on a list that a court has already permitted the government to act on.
    3. The accuracy threshold is an internal setting, not a legal standard: An 80 per cent match is a configuration choice inside the software, and no statute, rule or judicial direction fixes what confidence level may be relied on before a person is named.
    4. The error is not random noise: People held in custody were placed at a protest site by the system, which points to database and matching failure rather than to a borderline image.

    Challenges to facial recognition in policing

    1. No statutory basis governs deployment: India has no law authorising or limiting police use of facial recognition, so procurement, matching thresholds and retention are set administratively. Eg. The Delhi Police’s 80 per cent threshold became public only through a Right to Information reply, not through a published rule.
      The Fix: Require prior legislative authorisation and a published operating standard for any biometric identification system before it is deployed in a public space.
    2. Accuracy falls sharply for some groups: Error rates in facial recognition are higher for darker skin tones, women and younger faces, so the burden of a false match is not evenly spread. Eg. The United States National Institute of Standards and Technology’s evaluation of commercial algorithms recorded higher false positive rates across demographic groups.
      The Fix: Mandate a published demographic error audit of the deployed algorithm before each operational use, with results filed with the sanctioning authority.
    3. The system was built for one purpose and used for another: A database assembled to trace missing persons or match crime scene images becomes a crowd screening tool without any fresh authorisation. Eg. The Delhi Police’s facial recognition capability was originally acquired for tracing missing children.
      The Fix: Attach a statutory purpose limitation to each biometric database, so any new use requires a separate written sanction that is placed on record.
    4. Surveillance at a protest changes who turns up: Recording and matching faces at an assembly deters lawful participation independently of any action that follows. Eg. Cameras mounted on police vans at the Jantar Mantar site were visible to those attending.
      The Fix: Bar identification of participants at a lawful assembly except on a written order naming a specific cognisable offence under investigation.
    5. There is no route to contest a match: A person flagged by the system is not told, so the error surfaces only if a journalist or a court checks the records. Eg. The 25 custodial mismatches came to light through a newspaper’s record check, not through any internal review.
      The Fix: Require written notice to every individual against whom a biometric match is acted on, with a stated procedure to seek correction of the underlying record.

    Conclusion

    A facial match is being treated as a sufficient basis to proceed against a named list, while the force’s own position is that a match establishes nothing on its own. Both cannot hold at once. Nothing on record fixes what field verification must consist of, who performs it, or who checks that it happened. The point to watch is whether the Court requires the verification outcome for each flagged individual to be filed before any action follows.

    [2024] Under which of the following Articles of the Constitution of India, has the Supreme Court of India placed the Right to Privacy?

    (a) Article 15

    (b) Article 16

    (c) Article 19

    (d) Article 21

  • SC seeks govt. explanation on IPS deputation in CAPFs

    SC seeks govt. explanation on IPS deputation in CAPFs

    Why in the News

    The Supreme Court has sought an explanation from the Union Home Secretary on the implementation of its judgment of 23 May 2025, which directed the Centre to progressively reduce the deputation of Indian Police Service (IPS) officers to senior posts in the Central Armed Police Forces (CAPFs).

    What did the 2025 judgment direct?

    1. The direction: Deputation posts held by IPS officers in the Senior Administrative Grade (SAG), the level up to the rank of Inspector General, in the CAPFs were to be progressively reduced over a period of time, within an outer limit of two years.
    2. The Bench: The ruling was delivered by a two judge Bench, one of whose members has since retired.
    3. The direction has been tested once already: The Union Home Ministry’s review petition against the judgment was dismissed on 28 October 2025.

    What has the Centre reported as compliance?

    1. A cadre review across every force: Following the dismissal of the review petition, all CAPFs were directed to submit detailed cadre review proposals, which the Ministry examined and forwarded to the Department of Personnel and Training (DoPT) with the Home Minister’s approval.
    2. The proposals are in the pipeline, dated: Cadre review proposals for the CRPF, BSF, CISF, ITBP and SSB were sent between 27 July and 3 August 2026, and were forwarded to the Department of Expenditure with the DoPT’s observations and recommendations on 17 August.
    3. The remaining steps have not been taken: After the Department of Expenditure comments, the proposals go to the Cadre Review Committee headed by the Cabinet Secretary, whose recommendations are then to be considered for approval by the competent authority.
    4. Other measures claimed: The Ministry stated that it had also examined the issue of IPS deputation and undertaken statutory changes.

    Why does the Court read the compliance record differently?

    1. Deputations continued after the judgment: An affidavit informed the Court that 46 IPS officers have been brought on deputation to the CAPFs up to the SAG level since the 2025 ruling.
    2. The Bench questioned the premise of the practice: It asked whether there are no competent officers within the CAPFs to hold responsible positions, and described the position as totally wrong.
    3. The service record cited against the practice: Officers with over 25 years of service defend the borders and have made supreme sacrifices, and the Bench held that a strong lobby leaves those cadre officers completely stifled.

    How does the CAPFs (General Administration) Act, 2026 change the dispute?

    1. A statute now occupies the ground the judgment covered: The Central Armed Police Forces (General Administration) Act, 2026 was published in the Gazette on 9 April, and the stated effect is to circumvent the 2025 judgment.
    2. The Act is itself under challenge: Five writ petitions challenging the legislation have been filed and are listed for hearing on 18 November.
    3. The affected constituency is organised: Members of the All Ex-Paramilitary Forces Welfare Association staged protests against the Bill before its enactment.
    4. The next date on the compliance track: The contempt matter is listed for hearing on 22 September.

    Challenges to reducing IPS deputation in the CAPFs

    1. The forces were designed around an officer shortfall they never closed: Direct entry recruitment into CAPF cadres has not kept pace with sanctioned strength at senior levels, which is the stated justification for deputation in the first place. Eg. Vacancies across CAPF officer ranks have been reported repeatedly to Parliament by the Ministry of Home Affairs.
      The Fix: Fix a dated recruitment and promotion calendar in each cadre review, so the shortfall that justifies deputation is closed rather than carried forward.
    2. Cadre review is an executive process with no judicial deadline attached: Every stage between a force’s proposal and the competent authority’s approval is discretionary in timing. Eg. The proposals here moved between three departments over several months without reaching the Cadre Review Committee.
      The Fix: Attach an outer time limit to each stage of the cadre review chain, reported to the Court as a compliance schedule rather than as a status update.
    3. Command experience is concentrated where promotion is blocked: Officers who spend a full career in one force acquire the operational knowledge that senior posts need, and are then passed over at exactly that level. Eg. Border guarding, counter insurgency and industrial security each demand force specific expertise that a short deputation tenure cannot build.
      The Fix: Reserve a fixed proportion of Inspector General level posts in each force for cadre officers, notified in the recruitment rules rather than settled case by case.
    4. A statute can displace a judicial direction unless the underlying defect is cured: New legislation on the same subject shifts the dispute from contempt to constitutional validity and restarts the litigation clock. Eg. The five writ petitions against the 2026 Act put the question back at the beginning after a judgment and a dismissed review.
      The Fix: Amend the recruitment rules of each force to give effect to the direction, so compliance rests on subordinate legislation the Court has already read rather than on a fresh statute.
    5. Organisational identity is unresolved in law: The forces are described as paramilitary in public and as police organisations in service rules, and the ambiguity drives the parity claims on pay, pension and command. Eg. The demand for organised group A service status for CAPF cadres was itself settled only through litigation.
      The Fix: Settle the service classification of each force explicitly in the rules framed under the governing statute, so command structure follows from a stated status.

    Conclusion

    The question before the Court has changed shape since it was first answered. It began as a service dispute about who commands a force, moved to whether a direction on that dispute was being implemented, and now turns on whether a statute passed after the judgment can occupy the same ground. That last question is the one that decides the other two, and it is the pending challenge to the new Act, not the contempt proceeding, that will settle it. What to watch is whether the recruitment rules of the individual forces are amended at all, because a direction that never reaches the rules governing promotion has not been implemented whatever the affidavits record.

    Back2Basics: Central Armed Police Forces

    1. What they are: Seven armed forces of the Union under the Ministry of Home Affairs, distinct from the armed forces under the Ministry of Defence and from the State police, raised for internal security and border guarding duties.
    2. The seven forces: Assam Rifles, Border Security Force, Central Industrial Security Force, Central Reserve Police Force, Indo-Tibetan Border Police, National Security Guard and Sashastra Seema Bal.
    3. Command structure: Each force has its own directly recruited cadre, and senior posts are filled by a combination of that cadre and IPS officers on deputation from State cadres.
    4. Constitutional basis: They are raised under Entry 2A of the Union List, which covers deployment of any armed force of the Union in a State in aid of the civil power.

    [2023, GS3, 15 marks] What are the internal security challenges being faced by India? Give out the role of Central Intelligence and Investigative Agencies tasked to counter such threats.”

  • In India, a hard limit for X’s transparency pledge

    In India, a hard limit for X’s transparency pledge

    Why in the News

    X has pledged to publicly disclose government censorship and content-removal requests, while MeitY has warned that such disclosures may violate India’s Section 69A blocking framework.

    What is the Section 69A blocking framework?

    1. Statutory basis: Section 69A of the Information Technology Act, 2000 empowers the Union government to direct an intermediary to block public access to online content on specified grounds.
    2. The operative rules: The Information Technology (Blocking) Rules, 2009 are the framework under which a blocking direction is issued and acted on.
    3. Rule 16 mandates secrecy: It requires strict confidentiality over all blocking requests and the actions taken on them.
    4. Non-compliance is a criminal offence: An intermediary that fails to comply attracts imprisonment up to seven years.

    What exactly does the pledge collide with?

    1. The pledge names three disclosures: X proposes to publish that an order exists, which body issued it, and on what basis it was issued.
    2. Rule 16 forbids each of the three: The confidentiality mandate covers the existence of a request, its author and its stated grounds alike.
    3. Secrecy is what enables an unreasoned block: Confidentiality lets the executive block content without a reasoned public order and without notifying the person whose content is blocked.
    4. The liability lands on individuals: X’s Indian entity carries resident compliance and grievance officers, so criminal consequences attach to identifiable people inside the country.

    Does the announced mechanism do what was claimed?

    1. The release paired two separate things: X open-sourced its “Phoenix” recommendation code alongside a pilot feature called “Under the Hood”.
    2. Under the Hood shows platform labels, not state orders: It gives selected users visibility labels on their own accounts, such as spam flags and reach restrictions.
    3. A blocking order runs on a separate track: A Section 69A order operates outside that feature entirely.
    4. The user still sees only the old notice: The withheld content carries a “withheld in India” label naming neither the order nor the agency.

    Why does Section 69A no longer describe the whole takedown picture?

    1. Order volumes have roughly quadrupled: Section 69A orders rose from about 6,000 a year through 2023 to about 24,300 in 2025.
    2. A second route now carries a growing share: Since a 2023 MeitY memorandum, ministries, States and police issue orders under Section 79(3)(b) of the same Act.
    3. The Sahyog portal is the channel: Those orders are routed through the Ministry of Home Affairs portal, which X calls a censorship portal.
    4. An unreasoned order leaves nothing to publish: Where an order arrives without a stated basis, X has little to surface even if it intended to.

    What does X’s own compliance record show about the pledge?

    1. The stated identity is free speech absolutism: X brands itself in those terms.
    2. Actual compliance runs between 83 and 99 per cent: That is the share of demands the platform acts on.
    3. One order covered 2,355 accounts: In July 2025 X said the government ordered that many accounts blocked, including Reuters, within an hour.
    4. Objection was followed by compliance: X objected loudly and then complied, restoring the Reuters account only after a public outcry.

    Where does the litigation now stand?

    1. The Karnataka High Court dismissed the challenge: In September 2025 it rejected X’s petition against the Sahyog portal and called the portal “an instrument of public good”.
    2. Parallel proceedings ran in Bombay: X’s appeal and its Bombay petitions were consolidated.
    3. The Supreme Court stayed all four in July 2026: No court has ruled on the merits of the disclosure question.

    Challenges to the Section 69A blocking framework

    1. Blocking orders are never published: The framework produces no public record of what was blocked or why, so its use cannot be reviewed by anyone outside the executive. Eg. Directions issued during the farmers’ protest in 2021 covering over a thousand accounts were never published in any form.
      The Fix: Publish a redacted version of every blocking direction carrying the ground invoked, withholding only operational detail.
    2. The person whose content is blocked is rarely heard: The 2009 Rules provide for notice to the originator where identifiable, and in practice the intermediary alone appears before the committee. Eg. In Shreya Singhal v. Union of India (2015) the Supreme Court upheld Section 69A partly on the strength of that hearing, which originators seldom receive.
      The Fix: Make service of notice on an identifiable account holder a condition of validity of a blocking direction.
    3. Emergency powers bypass the review committee: An interim block can be ordered by the Secretary, Information Technology, before the committee that is meant to examine it has met. Eg. The 2020 ban on 59 Chinese applications was issued as an interim emergency measure under this framework.
      The Fix: Cap an emergency block at 48 hours unless the committee ratifies it within that period.
    4. Section 79(3)(b) carries none of the 69A safeguards: Safe harbour is lost on a government notification alone, with no committee, no periodic review and no defined issuing authority. Eg. Thousands of police units and State departments can issue takedown notices through a single portal.
      The Fix: Extend the 2009 Rules’ committee examination and periodic review to every order issued under Section 79(3)(b).
    5. Enforcement is aimed at individuals rather than the company: Criminal liability on a resident grievance officer converts a corporate regulatory dispute into personal jeopardy for an employee. Eg. The resident officer requirements of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were challenged on exactly this ground.
      The Fix: Confine non-compliance penalties to corporate monetary fines, and reserve imprisonment for wilful obstruction established in court.

    Conclusion

    A platform cannot publish what a statute makes an offence to publish, whatever it announces. The pledge and the confidentiality mandate are not two competing policies. They are a company’s stated practice set against a criminal provision, and only a court can move one of them. What remains unresolved is whether transparency about a restriction on speech is itself part of the speech that is being restricted, since no Indian judgment has answered that question. The marker to watch is the disposal of the consolidated challenge now before the Supreme Court.

    Laws and Rules Governing Online Content Regulation in India

    1. Information Technology Act, 2000: The parent statute governing electronic records, cyber offences and the obligations of intermediaries.
    2. Section 69A grounds: Blocking is permitted on grounds of sovereignty and integrity of India, defence, security of the State, friendly relations with foreign States, public order, and preventing incitement to a cognisable offence relating to these.
    3. Section 79 safe harbour: An intermediary is not liable for third party content it hosts, provided it observes due diligence, and it loses that protection where it fails to act on a government notification.
    4. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: Impose due diligence on intermediaries, require significant platforms to appoint a resident grievance officer, and fix timelines to acknowledge and resolve complaints. Amended in 2023.
    5. Digital Personal Data Protection Act, 2023: Governs the processing of digital personal data and establishes the Data Protection Board of India to adjudicate breaches.
    6. Telecommunications Act, 2023: Provides for interception and for suspension of telecommunication services on grounds of public emergency and public safety.
    7. Bharatiya Nyaya Sanhita, 2023: Criminalises circulation of false information likely to cause public disorder and speech promoting enmity between groups.
    8. Cable Television Networks (Regulation) Act, 1995: Regulates television content through a Programme Code barring material that threatens communal harmony or national security.

    [2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023.

  • Need to break Manipur’s cycle of reprisal (Editorial)

    Need to break Manipur’s cycle of reprisal (Editorial)

    Why in the News

    More than three years after the Meitei-Kuki clashes began, Manipur now faces a deepening Kuki-Naga fault line. Four Naga civilians were killed this week in Kuki-dominated Kangpokpi district, an episode that follows the killing of Kuki-Thadou church pastors in May, retaliatory abductions on both sides, and the recovery a month later of the bodies of six Naga men.

    How has the conflict widened beyond the original Meitei-Kuki fault line?

    1. A second, distinct fault line has opened: What began as Meitei-Kuki violence in 2023 has produced a separate Kuki-Naga confrontation, evident in this week’s killing of four Naga civilians in Kangpokpi, a district that sits between Naga-dominated Senapati to the north and Meitei-dominated valley districts to the south.
    2. A traceable chain of retaliation: The killing of Kuki-Thadou pastors in May was followed by retaliatory abductions from both communities, and the subsequent recovery of six Naga men’s bodies a month later, establishing a pattern of reprisal rather than an isolated incident.
    3. Blockades have turned roads into contested territory: Meitei, Kuki and Naga groups have separately imposed blockades that disrupt supplies, raise the cost of food and fuel, and restrict access to healthcare, with Kangpokpi the worst affected due to its position between rival-dominated districts.

    Why has the return of an elected government failed to restore order?

    1. A power-sharing arrangement has not translated into reconciliation: The state government led by Yumnam Khemchand Singh, a Meitei chief minister with deputy chief ministers from the Kuki and Naga communities, returned in February after almost a year of President’s Rule, but has found little success pulling the state back from the brink.
    2. Social segregation has outpaced political representation: The communities remain socially segregated, so political representation across the three groups in government has not by itself addressed the everyday separation that sustains distrust and enables further violence.
    3. Displacement has produced a significant, undercounted toll: Right to Information data has revealed that more than 700 internally displaced people have died in relief camps, a toll separate from and additional to deaths from direct violence.

    Challenges to a political settlement in Manipur

    1. Security forces have struggled to secure supply routes: Security forces have had very little success ensuring the safe movement of convoys carrying essential supplies through blockaded areas. Eg. Blockades imposed by Meitei, Kuki and Naga groups have repeatedly disrupted the movement of food, fuel and medical supplies into Kangpokpi and surrounding districts. Fix. Establish dedicated, jointly monitored humanitarian corridors for essential supplies, with monitoring involving representatives from all three communities rather than security forces alone.
    2. Armed groups remain undisbanded: Militant groups from multiple communities continue to operate, and a crackdown on extremist elements has not kept pace with the scale of continuing violence. Eg. The killing of four Naga civilians in Kangpokpi this week, alongside the earlier killing of Kuki-Thadou pastors, shows armed actors from more than one community remain capable of carrying out attacks. Fix. Pursue simultaneous, verifiable disarmament commitments from armed groups across all three communities rather than sequencing disarmament by community.
    3. No agreed framework exists for resolving land and identity claims: Every claim over land and identity cannot be resolved overnight, and the absence of an interim framework leaves communities without a safe basis for movement, trade or daily coexistence. Eg. The overlapping blockades by all three communities show there is currently no shared understanding of which areas each community can safely access. Fix. Prioritise an interim framework guaranteeing safe movement, trade and access to essential services, deferring final land and identity settlements to a later, dedicated political process.

    Conclusion

    The editorial’s position is that political representation alone, through a Meitei chief minister and Kuki and Naga deputy chief ministers, cannot resolve a conflict sustained by social segregation and repeated cycles of reprisal. It calls for sustained dialogue empowering civil society leaders, an interim framework for safe movement and trade, and simultaneous disarmament and action against extremist elements, alongside the immediate arrest of those responsible for this week’s killings.

    Back2Basics: What is President’s Rule?

    Central takeover of state governance: President’s Rule, imposed under Article 356 of the Constitution, allows the Union government to assume direct control of a state’s administration when its constitutional machinery is deemed to have broken down, as occurred in Manipur for nearly a year before the elected government returned in February.

    1. How social media hooks children — Meta’s $17-billion settlement over addictive design

      Why in the News

      Meta, the owner of Facebook and Instagram, has agreed to pay up to $17.1 billion in penalties to 47 US states, Washington DC and other territories, and to make binding changes to its products, over claims that it endangered children through addictive design and violated child privacy norms. The settlement follows a March jury verdict in KGM v. Meta et al, where a Los Angeles jury held Meta and Google liable for $6 million in damages after finding that platform features contributed to a young user’s mental health harm. Indian regulators are studying the settlement as a possible template even as the Centre weighs age-based restrictions, usage limits and stronger parental consent requirements for children’s access to social media, discussions that remain at an early stage.

      What has Meta agreed to change, and why does the design focus matter?

      1. A default two-hour daily cap across both apps: Meta will impose a combined two-hour daily limit on Facebook and Instagram for under-18 users, cumulative across multiple accounts, changeable only by a verified parent, with direct messaging excluded.
      2. Time-boxed access at night and during school hours: Teen users will be blocked from most parts of the platforms between midnight and 6 am, with most push notifications disabled between 10 pm and 7 am and muted between 8 am and 3 pm on school weekdays.
      3. Engagement features are curbed by default: The settlement provides a non-personalised feed option, hides like and reaction counts by default, restricts cosmetic-procedure filters, and requires usage prompts after every 15 minutes of continuous scrolling.
      4. Compliance is externally audited: Meta must hire an independent auditor to assess compliance with the safeguards for five years, addressing an issue exposed at the KGM trial, where only 1.1 percent of teen users had activated an existing optional daily-use limit.

      Why do experts see the design-focused approach as more significant than the payout?

      1. The settlement forces architectural change, not just policy change: A US legal academic notes this is the first US instance of a major platform being forced to change the “architecture of its product” rather than only its stated policies, arguing the design changes matter more than the settlement figure.
      2. Default settings determine real-world reach: A researcher at Common Sense Media expects the universal, default time and night-mode limits to have real effect, while the optional recommendation and engagement changes will reach fewer teens because a parent must actively enable them.
      3. Compliance is not the same as harm reduction: A policy scholar cautions that measuring compliance with a feature checklist is different from measuring actual outcomes, and argues independent researchers need real data access on sleep, wellbeing and compulsive-use patterns to know if the changes work.
      4. Recommendation algorithms remain the open question: Critics note the changes do not fully address the recommendation systems that encourage continued scrolling, with one researcher’s biggest unresolved question being how removing algorithmic recommendations changes what teens are shown and re-engage with.

      What evidence links social media design to youth mental health harm?

      1. Large-scale studies link engagement to anxiety and depression: A 2024 meta-analysis of 143 studies involving over one million adolescents found greater social media engagement associated with higher levels of anxiety and depression.
      2. Specific design features have identifiable mechanisms of harm: A Johns Hopkins researcher identifies appearance-based social comparison, visible like counts and overnight notifications as features with clear mechanisms of psychological impact.
      3. Reducing use shows measurable benefit: A 2025 randomised controlled trial of 220 young people found that cutting smartphone-based social media use to about one hour a day for three weeks reduced depression, anxiety and fear of missing out, and improved sleep; a 2026 trial found a similar reduction in loneliness after cutting use by about 78 minutes a day.
      4. Academic performance is also affected: A 2025 systematic review of 34 studies found off-task social media and smartphone use generally associated with lower academic achievement among children and adolescents.

      What does the settlement leave unresolved, and what does it mean for India?

      1. A financial incentive, not a mandate, for industry-wide adoption: About 30 percent of the $17 billion payout is contingent on YouTube and TikTok adopting comparable safeguards and matching payments, with stricter limits following only if Snap, TikTok and YouTube all comply.
      2. No admission of wrongdoing or binding precedent: The consent judgment explicitly states the settlement does not establish a standard of care or serve as precedent in any non-participating US state or international jurisdiction, including India.
      3. A legal question on platform liability remains open in the US: A Stanford law professor notes Meta’s attempt to invoke Section 230 immunity against design-based claims could still reach the US Supreme Court, since the settlement does not resolve roughly 2,900 other pending cases.
      4. India’s own discussions remain preliminary: The Centre is weighing age-based restrictions, usage-hour limits and stronger parental consent requirements for children’s social media access, but these discussions are still at an early stage, with the US settlement offered as a possible design-regulation template.

      Back2Basics

      1. Section 230: A provision of the US Communications Decency Act, 1996, that shields online platforms from liability for content posted by users, now being tested against claims that target a platform’s product design rather than the content it hosts.
      2. Digital Personal Data Protection Act, 2023: India’s framework law on personal data processing, which includes provisions requiring verifiable parental consent before processing a child’s personal data.
      3. Multidistrict litigation: A US federal court procedure that consolidates similar lawsuits filed in different districts, such as the roughly 2,900 other cases against social media platforms, for coordinated pre-trial proceedings.

      (GS3-22, 2024, 10 marks, Microtheme: Data Protection) “Describe the context and salient features of the Digital Personal Data Protection Act, 2023”

    2. Smart glasses highlight gaps in privacy laws

      Why in the News

      Meta’s smart glasses, which can discreetly record video and audio of anyone around the wearer, have renewed concerns over surveillance and consent, and over how far the Digital Personal Data Protection Act, 2023 actually protects a bystander who never agreed to be recorded. The Supreme Court’s nine-judge Bench in Justice K.S. Puttaswamy v. Union of India (2017) held privacy to be a fundamental right intrinsic to Article 21, developing a three-part legality-necessity-proportionality test for any restriction on it. Wearable recording devices normalised for everyday use test that framework in a setting the 2017 judgment did not anticipate: a bystander with no relationship to the device’s owner, and no practical way to know they are being recorded.

      Why do smart glasses expose a specific gap in India’s privacy framework?

      1. The Digital Personal Data Protection Act, 2023 is built around consent, which a bystander cannot give: The Act’s core protection mechanism requires a data principal’s consent before personal data is processed, a structure that assumes a data subject who is a party to the transaction, not a bystander recorded without their knowledge by someone else’s device.
      2. No dedicated framework for covert or discreet recording devices: Existing privacy protections address data processing by an identifiable data fiduciary, typically a company or platform, not the diffuse, device-level recording enabled by consumer wearables carried by private individuals.
      3. Enforcement depends on the bystander detecting the recording: Because smart glasses are designed to record discreetly, a bystander has no practical way to exercise any of the rights the 2023 Act grants a data principal, since exercising those rights first requires knowing that one’s data was processed at all.
      4. Cybercrime figures already show a rising surveillance-adjacent harm pattern: National Crime Records Bureau data has recorded a rising trend in cybercrime cases involving unauthorised recording and image-based harassment, a pattern smart-glasses-style wearables are positioned to accelerate.

      Conclusion

      Smart glasses expose a structural gap between a consent-based data protection framework and a recording technology that operates on people who never consented to anything. Closing that gap requires provisions specific to covert or ambient recording devices, rather than relying on the same consent architecture built for data fiduciaries processing information from their own users.

      What is the Right to Privacy, and what does it protect?

      1. About: The Right to Privacy is a fundamental right, read into Article 21’s guarantee of life and personal liberty, protecting an individual’s control over personal information, bodily integrity, and personal decisions from unjustified interference by the State.
      2. Rationale: The right exists because personal autonomy, from choice of partner to control over one’s own data trail, is treated as intrinsic to human dignity rather than a privilege the State may withdraw.
      3. Named typology: The Supreme Court in Puttaswamy (2017) recognised several strands within the right: informational privacy over personal data, decisional autonomy over intimate personal choices, bodily integrity against intrusive procedures, and digital privacy against online surveillance.
      4. Proportionality test for restrictions: Any state action restricting privacy must meet a three-part test: legality (backed by law), a legitimate aim, and proportionality between the means used and the aim pursued.
      5. Institutional gap in independent oversight: Agencies such as the Intelligence Bureau, the Research and Analysis Wing, and the National Investigation Agency operate without a dedicated, independent body reviewing their surveillance activity for privacy compliance.
      6. Colonial-era laws still authorise interception: Provisions in the Telegraph Act continue to authorise phone tapping under standards that predate the Puttaswamy proportionality test, creating a mismatch between old authorisation powers and the newer constitutional standard.
      7. Corporate data harvesting outside individual awareness: Technology platforms collect and monetise personal data at a scale most users do not track or understand, a form of privacy erosion the Digital Personal Data Protection Act, 2023 only partially addresses through its consent and purpose-limitation provisions.
      8. Low digital literacy limits the exercise of privacy rights: Citizens frequently do not know what data they have given consent to share, or how to invoke the correction and erasure rights the 2023 Act grants them.

      Challenges in protecting the right to privacy

      1. Mass surveillance without independent judicial oversight: Interception and surveillance decisions in India are authorised through executive processes rather than prior judicial warrant. Eg. Allegations around the use of Pegasus spyware against journalists and activists in 2021 raised exactly this oversight gap. Fix. Introduce a judicial or quasi-judicial warrant requirement before any interception order takes effect, replacing the current executive-only authorisation.
      2. National-security exemptions in the 2023 Act draw criticism: The Digital Personal Data Protection Act, 2023 permits government agencies to be exempted from several of its obligations on national security and public-order grounds. Eg. Government bodies notified under the Act’s exemption provisions are not bound by the same data-minimisation and purpose-limitation duties private data fiduciaries face. Fix. Require any national-security exemption to be time-bound and reviewed periodically by an independent oversight body rather than granted as a standing exemption.
      3. Corporate surveillance through data-driven advertising: Large technology platforms build detailed behavioural profiles from data users hand over without meaningfully understanding the trade-off. Eg. Targeted political and commercial advertising built on granular user profiling has drawn regulatory scrutiny in multiple jurisdictions. Fix. Mandate clear, layered consent disclosures under the 2023 Act’s rules that separate necessary data use from optional profiling-based use.
      4. Health data retention concerns from pandemic-era tools: Contact-tracing and health applications built during the COVID-19 pandemic raised unresolved questions about how long the government retains the health data those apps collected. Eg. Aarogya Setu’s data retention and sharing practices drew sustained criticism from privacy researchers. Fix. Set a statutory data-retention ceiling for any health-emergency application, with automatic deletion once the stated public-health purpose ends.
      5. No dedicated authority solely focused on privacy enforcement: The Data Protection Board established under the 2023 Act adjudicates complaints but does not function as a proactive privacy regulator auditing surveillance practices across government and industry. Fix. Expand the Data Protection Board’s mandate to include periodic, unprompted audits of large-scale surveillance and data-processing systems, government and private alike.

      Back2Basics: Digital Personal Data Protection Act, 2023

      1. India’s first standalone law on personal data processing, built around consent as the primary legal basis for processing, with defined exceptions for legitimate uses such as employment and government functions.
      2. Creates the Data Protection Board of India as the adjudicatory body for data-protection complaints and penalties.
      3. Grants data principals rights to access, correct, and erase their personal data, and imposes purpose-limitation and data-minimisation duties on data fiduciaries.
      4. Permits the government to exempt specified agencies from several of the Act’s obligations on national security and public-order grounds, a provision that has drawn criticism for its breadth.

      Matching Previous Year Question

      “[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023”

    3. What has fuelled the backlash against Flock cameras in the U.S.?

      Why in the News

      A backlash has grown in the United States against Flock Safety, a company supplying Automated License Plate Reader (ALPR) cameras, after reports that local police departments used the company’s camera network for purposes beyond its stated public-safety mandate, including tracking individuals without a warrant. Flock’s cameras were adopted by thousands of US municipalities on the promise of solving vehicle-related crime through license-plate matching. Evidence that police departments used the same network for broader surveillance, including in ways that reached beyond a single jurisdiction’s own authority, has turned a crime-fighting tool into a symbol of unchecked surveillance expansion.

      Why has Flock Safety specifically drawn this backlash?

      1. Scale of camera deployment across US municipalities: Flock Safety’s automated license-plate-reader cameras are installed across thousands of towns and cities in the United States, giving the company’s network a national footprint that few individual police departments could have built on their own.
      2. Cross-jurisdiction data sharing without matching oversight: Police departments using Flock’s network can search license-plate data captured by cameras in other jurisdictions, a capability that expands what a single local force can track well beyond its own legal boundary, without matching cross-jurisdiction oversight.
      3. Reported misuse beyond stated crime-fighting purpose: Instances have emerged of the camera network being used to track individuals in contexts such as reproductive-healthcare-related travel and immigration enforcement, uses that go well beyond the vehicle-theft and hit-and-run cases the system was marketed to solve.
      4. Absence of a federal framework governing ALPR use: The United States has no single federal law governing how automated license-plate-reader data can be collected, retained, or shared, leaving oversight to a patchwork of local ordinances and police department policy.

      What does this suggest for India’s own camera-based surveillance rollout?

      1. India is expanding AI-linked camera surveillance in parallel: Indian cities have been expanding networks of AI-enabled cameras for traffic and law-enforcement purposes, a rollout that mirrors the scale-up Flock’s network underwent in the United States before the current backlash.
      2. India’s privacy law does not yet address law-enforcement camera data specifically: The Digital Personal Data Protection Act, 2023 governs personal data processing generally but does not set out a dedicated framework for retention limits, access logging, or cross-agency sharing of camera surveillance data collected for law enforcement.
      3. The US backlash offers a design lesson before scale, not after: The concern in the United States surfaced only after the network had scaled to thousands of jurisdictions with data-sharing already built into the product, a sequencing that leaves oversight design catching up to deployment rather than preceding it.

      Conclusion

      The backlash against Flock Safety’s cameras in the United States is a warning about what happens when a surveillance network scales faster than the oversight framework governing its use. India’s own camera-based surveillance expansion is at an earlier stage, leaving room to build retention, access, and sharing safeguards into the framework before, rather than after, the network reaches a comparable scale.

      Back2Basics: Automated License Plate Reader (ALPR)

      1. A camera system that automatically captures and reads vehicle license plates, converting the image into searchable text data matched against watchlists or databases.
      2. Originally marketed for narrow uses such as locating stolen vehicles or vehicles linked to an active crime.
      3. Data captured by one camera can be pooled into a shared network, allowing a search across cameras operated by multiple, unconnected police jurisdictions.
      4. Raises retention and access-control questions distinct from a single fixed CCTV camera, because the data is structured, searchable, and easily aggregated across locations.

      Matching Previous Year Question

      “[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023”

    4. AI is transforming cyber attacks as well as defences: What this means for India

      AI is transforming cyber attacks as well as defences: What this means for India

      Why in the News

      Artificial Intelligence (AI) is now amplifying cyber threats across the cyber kill chain at speed, scale and sophistication, and is developing the ability to act as an autonomous agent that identifies, plans, adapts and carries out offensive cyber operations. The shift follows the fastest technology adoption on record: the Internet took 15 years to reach a billion users, and ChatGPT did so in three. The tension is that AI capability is concentrated in very few countries, so the same technology that raises the threat also determines who can defend against it. India’s indigenous AI ecosystem lags the United States and China across the entire AI stack, leaving it exposed on both sides of that equation.

      What is the cyber kill chain?

      1. Definition: The cyber kill chain is the sequence of stages an attacker must complete to succeed, running from reconnaissance on a target, through weaponisation of malicious code, to command and control of the compromised system.
      2. Why the framework matters: Defence has traditionally worked by breaking any one link in that chain, since an attack that fails at one stage cannot proceed to the next.
      3. What AI changes: AI is now compressing or automating several stages at once, so breaking a single link no longer stops the sequence.

      How is AI amplifying offensive cyber operations?

      1. Reconnaissance is automated: Gathering information about a target once depended on humans, and research shows ChatGPT models being used to mine social media for precise details to craft AI generated phishing emails.
      2. Deepfakes are now real time: AI is generating real time deepfakes, deepening confusion about what is authentic online.
      3. Social engineering scales: AI enabled social engineering, the use of AI to trick or persuade people into taking harmful actions, no longer requires a human operator per target.
      4. Malware no longer holds a fixed shape: Large language models (LLMs) can autonomously generate, modify and restructure polymorphic malware to suit the situation, unlike traditional malware, which relies on fixed signatures and predictable patterns.
      5. An AI has already run an attack chain: In September 2025 Anthropic claimed a Chinese state sponsored group, GTG-1002, had used Claude Code as an autonomous cyber agent across multiple stages of an attack, in what the company called the first reported case of an AI orchestrated cyber espionage campaign.

      Why does autonomous vulnerability discovery change the risk?

      1. Zero-days are being found at scale: Anthropic’s latest frontier model, Claude Mythos Preview, has identified thousands of zero-day vulnerabilities, meaning flaws previously unknown to developers, across major operating systems and browsers, many of them critical.
      2. It builds the exploits too: The model developed related exploits largely without human intervention, collapsing the gap between finding a flaw and being able to use it.
      3. Hardened systems are not exempt: It found a 27 year old vulnerability in OpenBSD, an operating system reputed to be highly security hardened and widely used to run firewalls and critical infrastructure.
      4. Industrial systems are the exposed surface: Such vulnerabilities are especially dangerous for Operational Technology (OT) and Industrial Control Systems (ICS), the computing that governs nuclear facilities, energy grids, pharmaceutical manufacturing, chemical processing, oil refineries and communication networks.
      5. Exposure grows with integration: That infrastructure becomes more exposed as it integrates further with AI, so the adoption that improves efficiency also widens the attack surface.

      Why do old cyber defences no longer hold?

      1. Signature matching fails against shape shifting code: Traditional antivirus looks for known malware fingerprints, which malware that constantly changes and adapts no longer presents.
      2. Static patching is too slow: Security patches written for known vulnerabilities are far less effective when new flaws are discovered and weaponised faster than patch cycles run.
      3. AI defence works differently: AI in cybersecurity enables real time threat detection, automated response and large scale data analysis, mitigating risks faster than human led triage.
      4. The divide has shifted: The real AI divide is not about who uses AI but about who builds it and who controls its development, which is why cybersecurity capability now tracks AI capability.

      How exposed is India?

      1. A nuclear plant’s data was posted: The ransomware group World Leaks claimed to have stolen and posted data related to India’s largest nuclear plant, Kudankulam, including blueprints of facility parts and supplier details.
      2. The ranking moved sharply: Cyber intelligence firm CloudSEK’s 2024 report placed India as the second most cyber attacked nation after the United States, and its 2025 report placed India sixth.
      3. State backed actors targeted defence during a conflict: During Operation Sindoor, Pakistan backed threat actors such as APT36 targeted India’s critical sectors, including the Ministry of Defence, the Army, the Navy and the Defence Research and Development Organisation (DRDO).
      4. A new target class appeared: The same campaign targeted Bharat Operating System Solutions (BOSS) Linux for the first time, extending the attack surface to India’s indigenous operating system.

      Can India defend a cyberspace built on an AI stack it does not own?

      1. The ecosystem is incremental: India’s indigenous AI ecosystem remains incremental and lags well behind the United States and China across the AI stack.
      2. The gap is at every layer: The shortfall runs across foundational models, graphics processing units, chip design and large scale data centre infrastructure, so no single procurement closes it.
      3. Dependence is the security problem: The lag leaves India heavily dependent on the United States and other technologically advanced countries for the very tools its defence now requires.
      4. Capability determines both roles: Countries with leading AI ecosystems gain a greater ability both to conduct sophisticated cyber campaigns and to defend against them, so dependence caps India’s ceiling on defence as well as deterrence.

      What has India done so far?

      1. CERT-In has shifted its methods: The Indian Computer Emergency Response Team (CERT-In), the national agency for responding to cyber security incidents, has since 2025 adopted AI driven threat detection, cyber resilience measures, trusted AI frameworks and citizen centric malware mitigation.
      2. A specific advisory was issued: In April 2026 it issued an advisory for organisations on defending against AI driven cyber risks.
      3. The advisory’s operative instructions: Recommendations included “removing unnecessary internet-facing services” and treating every newly discovered vulnerability as something that “could be exploited within hours, not weeks”.
      4. Governance work is at the framework stage: The Ministry of Electronics and Information Technology (MeitY) is exploring a consent based framework for synthetically generated content, alongside curbs on agentic AI autonomy and clearer liability frameworks for AI models.

      Challenges to India’s AI-enabled cyber defence

      1. Defence rests on advisories rather than obligations: CERT-In’s guidance to organisations is recommendatory, so a private operator of critical infrastructure faces no penalty for ignoring it. Eg. The April 2026 advisory asked organisations to remove unnecessary internet facing services, with no compliance audit attached. Fix. Convert the advisory content into mandatory, audited security baselines for power, banking, telecom and healthcare operators under the Information Technology Act, 2000.
      2. Compute dependence caps defensive AI: Running real time detection models at national scale needs domestic graphics processing unit capacity that India does not have. Eg. India’s shortfall spans foundational models, chip design and large scale data centre infrastructure alike. Fix. Prioritise sovereign compute for security workloads specifically, reserving a share of publicly funded AI infrastructure for CERT-In and sector CSIRTs.
      3. Attribution is harder when the attacker is an agent: An AI orchestrated campaign leaves a machine’s traces rather than an operator’s, which weakens the evidentiary basis for a state response. Eg. The GTG-1002 campaign was identified by the model provider, not by a victim’s own forensics. Fix. Mandate model providers serving Indian users to report detected misuse of their systems for offensive operations, on the six hour breach reporting model already in force.
      4. Legacy industrial systems cannot be patched quickly: Control systems in refineries and grids run on decade old software where a patch requires a plant shutdown. Eg. A 27 year old OpenBSD flaw survived in software widely used to run firewalls and critical infrastructure. Fix. Require network segmentation and one way data diodes between industrial control networks and corporate networks, so an unpatched system is not internet reachable.
      5. The skills base is thin at the state level: Cyber investigation and forensics capacity is concentrated in central agencies, while most first response happens at state police stations. Eg. Citizen fraud complaints route through the national helpline before reaching local police with the capacity to act. Fix. Establish State Computer Emergency Response Teams and cyber forensic laboratories with dedicated cyber police training academies in every State.

      Conclusion

      AI has moved cyber conflict from a contest between attackers and defenders to a contest between countries that build AI and countries that buy it. India sits on the wrong side of that line while carrying one of the world’s largest attack volumes, from a ransomware posting of Kudankulam plant data to state backed targeting of its defence establishment. India cannot build the AI stack quickly, so the immediate requirement is that AI and cybersecurity stop being treated in silos and are handled as interconnected strands of policymaking: AI for cyber defence, and cybersecurity for AI.

      “[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”