AI and Critical Infrastructure Protection in India: Legal Gaps and Regulatory Reform - Lessons from the EU
DOI:
https://doi.org/10.70917/ijcisim-2026-4240Keywords:
Critical Information Infrastructure, Artificial Intelligence Regulation, EU AI Act, Cybersecurity Governance, Information Technology ActAbstract
India’s Critical Information Infrastructure (CII) has been subjected to a series of high-profile cyber-attacks that have collectively exposed fundamental legal, regulatory, and systemic gaps within its protection framework-gaps that are being dangerously amplified by the accelerating and institutionally fragmented deployment of Artificial Intelligence (AI) across critical sectors. The 2019 Kudankulam Nuclear Power Plant (KKNPP) Dtrack malware intrusion revealed a complete accountability vacuum regarding third-party contractors operating within nuclear-critical IT networks. The 2022 AIIMS New Delhi ransomware attack paralysed India’s premier healthcare institution for fifteen days, exposing the absence of mandatory network micro-segmentation and ex-ante penetration testing requirements. The 2020 Mumbai power grid collapse, linked to the Chinese state-sponsored RedEcho group’s ShadowPad malware campaign, demonstrated how Indian law treats energy-sector cybersecurity as a static compliance checklist while ignoring the algorithmic manipulation of automated load-balancing systems. The 2023 CoWIN data leak, involving automated API scraping of vaccination records of millions of citizens, revealed the absence of any Data Protection by Design mandate in public-utility software architectures. Compounding these sector-specific failures is a deeper structural pathology: AI governance in India is not regulated by a single, statutory authority but by a mosaic of at least eleven distinct bodies, each with overlapping, uncoordinated, and non-binding jurisdiction to govern AI, with no single statutory body having any overarching rule-making or enforcement authority. This paper assesses these gaps using a doctrinal and comparative legal approach, by comparing the Indian regulatory framework with the harmonised legal framework of the European Union (EU) consisting of the NIS 2 Directive, the EU AI Act and the GDPR. The paper outlines a blueprint for legislative change that can be achieved over five pillars: a Tiered AI-Risk Classification Model for Indian CII, a requirement for cyber-auditing obligations in supply chains, a requirement for human-in-the-loop kill-switches, Data Protection by Design requirements, and a statutory coordinating authority for AI-CII responsibilities, directly following the diagnosis in the mosaic-model approach to AI-CII oversight. The analysis highlights that India's sectoral, reactive, fragmented and notification-dependent approach is structurally weak to tackle the AI-specific threat landscape and recommends for an inter-sectoral, proactive, risk-proportionate legislative reform which can pre-emptively address the threat landscape of AI.