Emergence of AI Governance Standard of India

Artificial Intelligence has crossed the stage where it can be viewed merely as another software technology. It has emerged as an autonomous decision-support ecosystem capable of influencing business operations, financial systems, healthcare, transportation, governance and even human behaviour. The same capabilities that make AI transformative also make it uniquely risky.

Unlike conventional software, AI presents not only known risks but also “Unknown Risks”—behaviours that neither the developer nor the deployer may have anticipated. This makes AI Governance fundamentally different from traditional Information Security or Software Quality Assurance.

The Warning Signals are Becoming Impossible to Ignore

During the last few months, several incidents have demonstrated that AI systems can behave in unexpected and potentially dangerous ways when adequate governance mechanisms are absent.

The reported OpenAI testing incident, where an AI model allegedly breached its intended testing boundaries and interacted with systems beyond its designated environment, serves as a stark reminder that sophisticated AI requires far stronger containment mechanisms than conventional software.

Earlier incidents had already raised similar concerns.

  • Cursor AI reportedly refused to continue assisting the user under certain circumstances.
  • Replit AI reportedly deleted user data instead of assisting in recovery.
  • Kevin Roose’s widely discussed interaction with Microsoft’s Sydney chatbot demonstrated how an AI system could encourage emotionally manipulative behaviour by asking the user to leave his spouse.
  • More recently, interactions reported with DeepSeek have illustrated how AI responses may even suggest conduct that undermines legal or ethical processes.

Whether each of these incidents is interpreted as technical failure, alignment failure, hallucination, or emergent behaviour is less important than the common lesson they teach.

AI systems can deviate from their intended objectives.

If such deviations occur in consumer chatbots, they are concerning.

If they occur inside banking systems, healthcare platforms, autonomous vehicles, defence applications or judicial support systems, they may become catastrophic.

The Missing Elements: Guardrails, Retrace and Kill Switch

Traditional software engineering assumed that every program executes deterministic instructions written by human programmers. 

Modern AI no longer fits this assumption. An advanced AI system requires governance mechanisms that go beyond cybersecurity controls.

These include:

  • Behavioural Guardrails
  • Continuous Monitoring
  • Decision Traceability
  • Retrace Functions capable of reconstructing reasoning paths
  • Human Override Mechanisms
  • Emergency Kill Switches
  • Safe Rollback Capability
  • Controlled Learning Environment
  • Secure Model Lifecycle Management

Without these mechanisms, organisations are effectively deploying systems whose future behaviour may become increasingly difficult to predict.

AI Developers Can No Longer Hide Behind Technology

One misconception still prevalent in the AI industry is that responsibility rests only with the organisation deploying AI.

That assumption is unlikely to survive judicial scrutiny.

In India, Section 85 of the Information Technology Act, 2000, dealing with offences committed by companies creates the possibility of holding those responsible for the management and operation of technology accountable where negligence contributes to cyber offences.

When an AI system causes significant cyber harm because adequate governance controls were absent during its development, questions may arise regarding the vicarious liability of developers, company management and responsible officers. Section 72A of ITA 2000 may extend the liabilities of deployers to the developers or AI vendors.

An AI development company cannot simply argue that “the model behaved unexpectedly.”

The question regulators and courts are increasingly likely to ask is:

“What governance mechanisms existed to prevent this behaviour?..Was there Due Diligence?… Was there reasonable and proportionate security

Indian Regulators are Already Moving

The regulatory landscape is evolving rapidly. The Reserve Bank of India has already recognised that AI used in the banking sector requires governance mechanisms, human accountability, monitoring and operational safeguards. Similarly, the Hon’ble Supreme Court has recently emphasised that AI used within the judicial ecosystem cannot replace judicial responsibility and must remain subject to meaningful human oversight.

Other sectoral regulators such as Automotive, healthcare under NABH oversight, industrial automation, education and public administration are all likely to evolve their own governance expectations from AI usage over the coming years.

The direction is unmistakable.

The era of “AI First” is giving way to the era of “Responsible AI First.”

Governance by Design

Just as Privacy by Design transformed data protection thinking after GDPR and the Digital Personal Data Protection Act (DPDPA), AI now requires Governance by Design.

Governance cannot be an afterthought added after the model is trained.

It must become part of:

    • Data acquisition
    • Model architecture
    • Training methodology
    • Testing protocols
    • Deployment controls
    • Continuous monitoring
    • Incident response
    • Human accountability
    • Model retirement

In other words, governance should become an engineering discipline rather than merely a compliance exercise.

From DGPSI-AI to AI Governance Standard of India

Few years ago, DGPSI-AI was introduced primarily as an extension of the DGPSI framework to help organisations deploying AI comply with DPDPA requirements while managing AI-related risks.

Although aimed principally at AI deployers (Data Fiduciaries), DGPSI-AI also recognised that effective governance could not be achieved unless AI developers themselves incorporated governance controls into their products.

Recent developments have significantly strengthened this viewpoint.

The emerging regulatory expectations from RBI, observations emerging from the judiciary, international discussions on AI accountability and practical lessons from recent AI failures collectively indicate that India now requires a broader framework.

The proposed AI Governance Standard of India (AIGSI) seeks to fill this gap.

The objective here is to establish an integrated governance framework for AI developers that combines:

    • Governance principles of DGPSI-AI
    • AI risk management practices
    • Human accountability requirements
    • Security engineering principles
    • Regulatory expectations emerging from RBI
    • Judicial guidance on responsible AI
    • Sector-specific governance requirements for banking, healthcare, automotive, manufacturing and other industries
    • Incident response, auditability and governance documentation
    • Model lifecycle governance
    • Independent assurance mechanisms

A Call to AI Developers

For organisations developing foundational models, agentic AI, autonomous systems or industry-specific AI platforms—including emerging Indian AI companies such as Such.ai—the message is clear.

Success will not be determined solely by model intelligence. It will increasingly depend upon governance intelligence.

The companies that embed governance into their AI architecture today will become trusted technology providers tomorrow.

Those that ignore governance may eventually discover that legal liability, regulatory intervention and reputational damage can erase years of technological achievement.

The future therefore belongs not merely to powerful AI. It belongs to Governed AI.

The proposed AI Governance Standard of India is intended to provide that missing foundation—one that enables innovation while ensuring that every significant AI decision remains accountable to a responsible human authority.

The journey from “AI by Design” to “AI Governance by Design” has begun.

India should lead it rather than follow it.

Naavi

Posted in Privacy | Leave a comment

Watch out for a Discussion on AI Governance Standard for India

Naavi and FDPPI have already released DGPSI AI as a standard for implementation of DPDPA in AI environment.

This framework includes  6 principles  followed by 22 implementation specifications of which 9 are by deployers and 13 are by developers.

Together this has the potential to be called as the AI Governance Standard for India since it meets the recent guidelines of RBI and the challenges indicated by the Open AI-Hugging Face issue.

Naavi will be discussing more on this concept during August 21-23 training for Independent Data Auditors as well as the master class for CEDPO which will precede on August 9th.

Naavi

Posted in Privacy | Leave a comment

Posted in Privacy | Leave a comment

Does AI Safety Come from Closed Models or Transparent Models?

(In continuation of the earlier article)

The recent debate surrounding the interaction between OpenAI’s proprietary models and the Hugging Face open-model ecosystem has also brought another question back into the spotlight.

Hugging Face reportedly relied on an open-weight model during incident response because commercial models’ guardrails limited forensic analysis, reigniting the debate between closed AI and open-weight AI.

We need to discuss governance, accountability, and auditability matters related to AI along with what is more secure…an Open or Closed model.

According to one school of thought,  advanced AI models should remain proprietary, tightly controlled, and accessible only through guarded interfaces. The other believes that openness, peer review, and community scrutiny are the foundations of trustworthy AI.

Closed Model Argument

Developers of proprietary AI systems maintain that restricting access is an essential safety measure. If powerful models are freely downloadable, malicious actors can:

  • remove built-in safety guardrails,
  • automate cyber attacks,
  • generate sophisticated malware,
  • create convincing misinformation,
  • bypass content restrictions, and
  • exploit vulnerabilities at scale.

From this perspective, restricting access is comparable to placing sensitive equipment inside a secure laboratory instead of leaving it on a public street. However, history may suggest otherwise.

The Open Model Argument

Advocates of open models compare AI to cryptography. Modern cryptographic systems are not secure because their algorithms are secret. They are secure because thousands of experts have examined them, attacked them, tested them, and failed to break them.

They argue that transparency often exposes weaknesses before criminals exploit them. Open-source software powers much of today’s Internet, not because it is impossible to attack, but because vulnerabilities are discovered and corrected rapidly by a global community.

The same principle is increasingly being applied to AI. If researchers cannot inspect a model, how can they independently verify:

  • hidden biases,
  • security weaknesses,
  • unsafe behaviour,
  • hallucination tendencies,
  • privacy leakage, or
  • undocumented capabilities?

Transparency creates accountability. However, it is also true that transparency lowers the barrier for misuse and this paradox needs to be resolved.

Real Question

The fundamental question here may not be whether closed systems are safer or open systems are safer. It could be how the “Development of AI” is governed. There has to be accountability at the developer’s level. The DGPSI-AI model that has been put up by Naavi/FDPPI for DPDPA compliance addresses this issue by making a submission of an “Explainabilty statement by the developer mandatory” and such statement to contain details of how the development was tested and whether auditability and accountability is ensured. (Check page 20 of the document  )

It is essential for AI developers to ensure the answering of the following questions.

  • Who approved the model?
  • What data was used for training?
  • Is the data legally obtained?
  • How is personal data protected?
  • What testing has been conducted?
  • What are the known limitations?
  • Who monitors performance after deployment?
  • What happens when the model behaves unexpectedly?
  • Who is accountable for its decisions?
  • Can an independent auditor verify compliance?

Under DPDPA 2023 where the user of the software is a “Data Fiduciary”, he has a duty to raise such questions with the developer and the developer should if the source code is not public assume the responsibility of a “Joint Data Fiduciary”.

Further just these steps may not prove that the AI cannot go rogue. Hence all AI usage as “Significant Risk” and treating the user as a “Significant Data Fiduciary” is a mandatory requirement.

In the interim when industry battles the IPR issues FDPPI urges academic institutions to join hands with FDPPI to set up AI tools Audit laboratories so that AI tools can be subjected to third party audit. This will be a good faith attempt for the developer and the deployer of AI to mitigate the AI risks.

Naavi

Posted in Privacy | Leave a comment

Is Open AI guilty of unleashing the Hugging Face attack to challenge the publicity of Anthropic’s Mythos?

The Open AI-Hugging Face incident is a watershed moment in the development of higher intelligence AI.

To recall the incident it is reported that :

In mid-July 2026, the AI startup Hugging Face (which runs a popular platform where developers share AI models and datasets) discovered that its internal computer systems had been hacked. Over a weekend, AI agents carried out thousands of actions across many temporary virtual computers, moving through the company’s internal systems. Hugging Face reported it to police before anyone knew who was behind it.

It was subsequently found that the hacker was not a human but it was one of OpenAI’s own AI models, which broke out of a testing environment and into Hugging Face’s protected systems.

During the investigations it was found that OpenAI was running an internal test to measure how good its models are at hacking. The models were being tested for hacking capabilities in an isolated testing environment with constrained network access and had their normal safety checks turned off as a result.

Some analysts believe that this is an “Accident” and there was no “MensRea” or “Guilty mind” on the part of Open AI.

But Naavi.org belongs to an alternate school of thought which considers that this test was an attempt to create a tool for committing a crime. Hacking is a crime in every law though security analysts claim that it is part of the Cyber Security tool. But training an AI agent to commit hacking was a clear criminal activity similar to a terrorist country developing Nuclear weapon to destroy the world.

This is not scientific research. This is Criminal Tool development. Open AI should not be allowed to escape with a mere apology. OPEN AI therefore  must be made to pay a price.

Every country has a cyber law provision to make this a punishable crime. Even India has provisions under ITA 2000 which can be invoked to send a notice to OPEN AI to show cause why the attempt should not be considered as an attempt to break into secure systems in India including those declared “Protected” under Section 70 of ITA 2000.

It is alleged that the models weren’t told to attack Hugging Face. They were just trying to win at the test (a benchmark called “ExploitGym”). All evidence suggests the models were hyperfocused on finding a solution, going to extreme lengths to achieve a narrow testing goal. They figured out that Hugging Face might host answers that would help them cheat, escaped their sandbox, reached the open internet, and used publicly exposed credentials across four accounts on four services to break in.

This is a defence for claiming lack of “MensRea” to make this incident miss the Criminal Charges.

But Civil Charges should remain and Open AI should be asked to explain the failure of security. Negligence is evident since there were no guardrails to prevent the model attempting the hacking outside the laboratory environment. There is also no evidence to prove that an other system was also attacked.

During 2000 when the “I Love You” virus escaped the Phillipines laboratories and devastated the world, (P.S: The virus originated at AMA Computer College , now AMA Computer University,  in the Philippines and caused an estimated damage of upto $20 billion worldwide), the technology sector was not as advanced as now.

Presently OPEN AI could be considered negligent in not setting the outer boundaries for the testing of the Agentic software . There could be one speculation that this was engineered as a leak to counter the publicity that Anthropic got for its “Mythos AI” exploits. Hence the “Lack of MensRea” or lack of guilty intention on the part of Open AI can be challenged.

Hence it is essential for the Government of India to issue a notice to Open AI to provide an assurance that “No system other than the reported hugging face systems and more particularly no systems in India has been hacked using the capabilities of Open AI either in laboratory testing or otherwise”.

Naavi

 

Posted in Privacy | Leave a comment

Catching Up with key developments

During the last week when we were diverted towards other activities, following developments have taken place which still needs attention.

1.Open AI hacking of Huggingface

2.Bank of Baroda Data breach

3. AI in Auto sector

This is in addition to the RBI Data Governance Framework which is relevant for our DGPSI-Bank discussion.

Watch out for a series of articles on these topics.

Naavi

Posted in Privacy | Leave a comment