Quick Take
- India is drafting auto cybersecurity rules for all new vehicles, ready in about six months, officials told ET.
- The push follows viral cases of hackers stopping moving e-rickshaws through unsecured Bluetooth battery apps.
- New rules will cover data collection by connected cars, with roadworthy nods only for safe models.
In This Article
India is building strict auto cybersecurity rules that will apply to every new vehicle sold in the country, with the framework set to be ready in about six months, officials told The Economic Times. The government is also in talks over data collection by new-age connected vehicles.
The move follows a wave of incidents where attackers tampered with e-rickshaw batteries through mobile apps. Officials said the proposed framework will stress hacking-proof compliance for all new vehicles. The Ministry of Electronics and Information Technology (MeitY) had earlier ordered the removal of unsafe Battery Management System apps from app stores on 3 July 2026, per an official government release.
StartupFeed Insight
The real signal here is not the e-rickshaw fix, it is data. The Centre is examining whether carmakers store and use commuter and driver location data, which drags every connected-car maker into DPDP compliance early. That is a bigger cost line than a Bluetooth patch. Tata Motors, Mahindra, Ola Electric, and importers of low-cost Chinese EVs should read the fine print now, because retrofitting security into shipped fleets is far costlier than building it in. Expect a near-final draft rule with public comments closing before December 2026, ahead of the first mandatory compliance dates in 2027. By Harshvardhan Jain.
What do the new auto cybersecurity rules cover?
The new auto cybersecurity rules will make hacking-proof ability a condition for selling any new vehicle in India. Officials said the framework will be ready in roughly six months and will cover both locally made and fully imported models.
The rules target connected features where drive data is collected, processed, and used to send commands back to the vehicle. StartupFeed learns the government is examining the safety of over-the-air (OTA) updates, the same channel that pushes remote software fixes but can also open a door for attackers if left unsecured.
Deal Breakdown: Key Facts
| Metric | Detail | Notes |
|---|---|---|
| Framework readiness | About 6 months | Officials cited by ET |
| Scope | All new vehicles | Includes fully imported EVs |
| Core standards | AIS-189, AIS-190 | Cybersecurity and software updates |
| First trigger | App removal, 3 July 2026 | MeitY order |
| ADAS projection | 90% of new cars by 2030 | NITI Aayog assessment |
| Data angle | Commuter, driver location | Under DPDP Rules, 2025 |
The most striking part is the data question. The government wants to know if carmakers store and process the location and travel patterns of commuters and drivers, and whether that data is safeguarded.
About the Framework
The proposed framework is led by MeitY with inputs from the Ministry of Heavy Industries and the Ministry of Road Transport and Highways (MoRTH). It builds on India’s existing cyber defence bodies, including the Indian Computer Emergency Response Team (CERT-In) under the IT Act, 2000. The aim is one coordinated rulebook for connected and autonomous vehicles, tied to roadworthy certification for new models.
Why did e-rickshaw hacking trigger this move?
E-rickshaw hacking exposed a glaring gap in low-cost EVs. Certain Bluetooth-enabled Battery Management System apps, many tied to imported Chinese batteries, ran with default or no passwords, letting strangers connect and cut power to a moving vehicle.
CERT-In received reports that attackers could abruptly switch off a running e-rickshaw. Viral prank videos showed content creators stranding drivers and passengers mid-route, and Delhi Police arrested a suspect on charges of tech-based extortion.
“The software security vulnerability will be plugged,” a senior official told The Economic Times.
For a driver who rents a tirri for roughly Rs 400 to Rs 500 a day, one remote shutdown can wipe out a full day of earnings. That real-world harm, not a lab test, pushed the Centre to act fast and widen the fix to every new vehicle.
The Standards and Timeline
India’s vehicle cybersecurity standard is AIS-189, and software updates fall under AIS-190. MoRTH issued a draft notification in June 2026 proposing two new provisions, Rule 125-T and Rule 125-U, in the Central Motor Vehicles Rules, 1989, as reported by Autocar India.
The rules follow a phased rollout by risk. Vehicles with Level 3 or higher automated driving must comply first, from October 2026 for new models and April 2027 for existing ones. These standards apply until the Bureau of Indian Standards (BIS) notifies its own specifications.
What does this mean for EV owners?
For EV owners, the auto cybersecurity rules promise safer connected cars but may raise prices. Adding secure hardware and software lifts costs, and older e-rickshaws on plain lead-acid batteries stay safe because they lack wireless links.
| Vehicle type | Cyber risk | Compliance load |
|---|---|---|
| Low-cost e-rickshaw (Bluetooth BMS) | High | Heavy retrofit |
| Premium EV (encrypted software) | Low | Mostly ready |
| Legacy lead-acid e-rickshaw | Minimal | Largely exempt |
What sets this framework apart is its reach. Unlike a one-off app ban, it ties cybersecurity to the roadworthy certificate itself, so no compliant certificate means no sale.
What’s Next
The government is expected to firm up the draft rules and close public comments before the first mandatory compliance dates arrive in 2027. Watch for how the Centre defines data-storage duties for carmakers under the Digital Personal Data Protection (DPDP) Rules, 2025. Will low-cost EV makers absorb the added security cost, or pass it on to buyers?
Frequently Asked Questions
Disclaimer: This article is for informational purposes only and does not constitute investment advice. StartupFeed and its authors are not SEBI-registered investment advisors. The analysis above is based on publicly available information and should not be the sole basis for any investment decision. Please consult a SEBI-registered financial advisor before making investment decisions.
Have a tip? Write to us at editorial@startupfeed.in.
