AI and Critical Infrastructure Protection in India: Legal Gaps and Regulatory Reform - Lessons from the EU

Authors

  • Kavita Ajay Joshi Department of PDP, Graphic Era Hill University, Bhimtal, Uttarakhand, India
  • Shikha Dimri School of Law, UPES, Dehradun, Uttarakhand, India.
  • Lalit Singh Department of PDP, Graphic Era Hill University, Bhimtal, Uttarakhand, India.
  • Vishesh Yadav High Court of Judicature at Allahabad, Lucknow Bench; Department of Law, Amity Law School, Amity University, Lucknow, Uttar Pradesh, India.

DOI:

https://doi.org/10.70917/ijcisim-2026-4240

Keywords:

Critical Information Infrastructure, Artificial Intelligence Regulation, EU AI Act, Cybersecurity Governance, Information Technology Act

Abstract

India’s Critical Information Infrastructure (CII) has been subjected to a series of high-profile cyber-attacks that have collectively exposed fundamental legal, regulatory, and systemic gaps within its protection framework-gaps that are being dangerously amplified by the accelerating and institutionally fragmented deployment of Artificial Intelligence (AI) across critical sectors. The 2019 Kudankulam Nuclear Power Plant (KKNPP) Dtrack malware intrusion revealed a complete accountability vacuum regarding third-party contractors operating within nuclear-critical IT networks. The 2022 AIIMS New Delhi ransomware attack paralysed India’s premier healthcare institution for fifteen days, exposing the absence of mandatory network micro-segmentation and ex-ante penetration testing requirements. The 2020 Mumbai power grid collapse, linked to the Chinese state-sponsored RedEcho group’s ShadowPad malware campaign, demonstrated how Indian law treats energy-sector cybersecurity as a static compliance checklist while ignoring the algorithmic manipulation of automated load-balancing systems. The 2023 CoWIN data leak, involving automated API scraping of vaccination records of millions of citizens, revealed the absence of any Data Protection by Design mandate in public-utility software architectures. Compounding these sector-specific failures is a deeper structural pathology: AI governance in India is not regulated by a single, statutory authority but by a mosaic of at least eleven distinct bodies, each with overlapping, uncoordinated, and non-binding jurisdiction to govern AI, with no single statutory body having any overarching rule-making or enforcement authority. This paper assesses these gaps using a doctrinal and comparative legal approach, by comparing the Indian regulatory framework with the harmonised legal framework of the European Union (EU) consisting of the NIS 2 Directive, the EU AI Act and the GDPR. The paper outlines a blueprint for legislative change that can be achieved over five pillars: a Tiered AI-Risk Classification Model for Indian CII, a requirement for cyber-auditing obligations in supply chains, a requirement for human-in-the-loop kill-switches, Data Protection by Design requirements, and a statutory coordinating authority for AI-CII responsibilities, directly following the diagnosis in the mosaic-model approach to AI-CII oversight. The analysis highlights that India's sectoral, reactive, fragmented and notification-dependent approach is structurally weak to tackle the AI-specific threat landscape and recommends for an inter-sectoral, proactive, risk-proportionate legislative reform which can pre-emptively address the threat landscape of AI.

Downloads

Download data is not yet available.

Downloads

Published

2026-08-04

How to Cite

Kavita Ajay Joshi, Shikha Dimri, Lalit Singh, & Vishesh Yadav. (2026). AI and Critical Infrastructure Protection in India: Legal Gaps and Regulatory Reform - Lessons from the EU. International Journal of Computer Information Systems and Industrial Management Applications, 18(14s), 416–437. https://doi.org/10.70917/ijcisim-2026-4240

Issue

Section

Original Articles