India’s government has begun work on a stringent cybersecurity compliance framework that will apply to every new vehicle sold in the country, with a draft expected within six months, The Economic Times reported July 29.
The push follows recent incidents in which e-rickshaw batteries were tampered with remotely through mobile applications. The government has already banned the apps used in those attacks, but officials now want hacking-proof compliance built into the vehicle approval process itself.
Officials said the government is still weighing which interventions are needed, and that the safeguards will stress hacking-resistant design for every new vehicle. Regulators are also examining how drive data is collected, processed and used to issue commands to vehicles, and whether existing connected vehicles could be hardened through over-the-air updates.
Concerns extend beyond e-rickshaws. Officials flagged possible sabotage of semi-autonomous vehicles equipped with driver assistance features such as automatic parking, braking and lane assist. A Niti Aayog assessment projects that 90% of passenger vehicles sold in 2030 will carry ADAS technology, widening the attack surface considerably.
The Centre is also reviewing whether automakers store and use driver and commuter data in line with the Digital Personal Data Protection Rules, 2025, after noting that connected vehicles share location over the internet and process large volumes of surrounding information.
The move builds on earlier work: India’s AIS-189 standard, aligned with UN R155, is being phased in, with OTA-enabled vehicles required to comply by 2029. The new framework would go further, mandating cybersecurity safeguards for all new vehicles rather than waiting for the phased rollout. For global OEMs selling in India, the six-month clock on a nationwide rulebook is now ticking.