Key facts
- Ministry of Road Transport and Highways to introduce vehicle cybersecurity laws
- New rules to cover software update management for connected vehicles
- Aimed at preventing remote hijackings of smart vehicles
- India follows EU and global trend toward software-defined vehicle regulation
India's Ministry of Road Transport and Highways is set to introduce dedicated cybersecurity and software update management regulations for vehicles, signalling that the government recognises the growing digital vulnerabilities in modern automobiles. As cars increasingly run on complex software stacks and receive over-the-air updates, the potential for remote exploitation — including hijacking of steering, brakes or engine systems — has moved from science fiction to a documented security concern globally.
The new legal framework is intended to address two distinct but related risks: unauthorised cyber intrusions into vehicle systems, and the need to standardise how manufacturers push software updates to vehicles already on the road. Without regulation, an over-the-air update could theoretically alter safety-critical functions without adequate testing or consumer disclosure.
India's automotive market is one of the world's largest, and the shift toward connected, electric and software-defined vehicles is accelerating rapidly. Regulators have been playing catch-up with the technology, and these proposed laws would bring India closer to frameworks already being implemented in the European Union and other markets.
For vehicle owners, the practical impact would include greater assurance that their car's software cannot be silently altered in ways that compromise safety, and that manufacturers are held accountable for the security of connected systems. The Ministry is expected to detail timelines and specific requirements as the draft regulations develop.
