India has expanded cyber security exercises and AI-based threat detection as governments worldwide grapple with the growing cyber risks posed by artificial intelligence (AI).

The Indian Computer Emergency Response Team (CERT-In) held 10 cyber security exercises during June and July, bringing together 1,470 participants from 345 government and private organisations. According to information submitted to Parliament, the exercises focused on preparing organisations to respond to cyber attacks driven by artificial intelligence.

The participants came from sectors including power, telecom, banking, financial services, transport, education, healthcare and space, highlighting growing concern over the potential impact of cyber attacks on essential services.

The update underscores how governments are shifting from treating AI as a future cyber security challenge to addressing it as an immediate national security and public safety issue. As generative AI makes phishing, fraud, deepfakes and other cyber attacks faster, cheaper and more convincing, countries are strengthening both their cyber defences and regulatory frameworks. India’s latest measures signal a move toward combining AI-powered security tools, stricter obligations for technology providers and tighter rules for online platforms in an effort to protect critical infrastructure, businesses and citizens from increasingly sophisticated AI-enabled threats.

“The government is cognizant of the evolving cyber security threats and challenges, including those arising from artificial intelligence (AI) enabled cyber threats. AI technologies may increase systemic cyber risks by enabling automated reconnaissance, rapid vulnerability exploitation, credential compromise and highly convincing multilingual social engineering campaigns,” the Ministry of Electronics & IT said in the statement. The information was submitted by minister of state for electronics and information technology, Jitin Prasada, in the Lok Sabha, the lower house of India’s bicameral Parliament.

“These capabilities lower attack costs, accelerate weaponization, and make phishing and impersonation attacks more scalable and difficult to detect. The government is committed to ensuring an open, safe, trusted and accountable cyberspace. Several legal, technical and administrative policy measures have been implemented to address the risks posed by AI-enabled cyber threats, enhance cyber resilience, and strengthen incident response capabilities,” it added.

The Ministry said AI can help attackers identify security weaknesses more quickly, automate phishing campaigns and make impersonation attacks more convincing and harder to detect.

To strengthen its defences, CERT-In has deployed AI-based systems to detect malicious websites and phishing campaigns. It has also expanded AI-powered vulnerability assessments for public-facing digital assets to help identify and fix security flaws before they can be exploited.

The agency also runs an automated threat intelligence platform that shares cyber alerts with organisations across sectors, allowing them to respond more quickly to emerging threats.

The government has also introduced new security requirements for technology providers. “CERT-In has issued guidelines in June 2026 requiring all Original Equipment Manufacturers (OEMs) and technology providers to implement AI-accelerated vulnerability protection, requiring AI-assisted security testing, continuous monitoring, patch management, and incident response frameworks to defend against AI-driven cyber threats,” the Ministry informed.

The measures add to a series of CERT-In advisories issued over the past two years on topics including deepfakes, generative AI and software supply chain security.

Strengthening deepfake defences

India is also stepping up the implementation of measures to tackle AI-generated deepfakes, with the government highlighting faster content removal rules, new research on deepfake detection and wider public awareness efforts. The update comes as governments and technology companies seek to curb the spread of AI-generated content used in fraud and impersonation.

The Ministry of Electronics & IT said 13 Responsible AI projects have been approved under the IndiaAI Mission to develop tools that can detect deepfakes and other forms of manipulated content. The projects include systems being developed by the Indian Institutes of Technology in Jodhpur, Madras and Kharagpur to identify fake videos, audio and voice recordings.

“The Safe & Trusted AI pillar of the IndiaAI Mission aims to promote the responsible development, deployment and adoption of AI through indigenous governance frameworks, standards, tools and evaluation mechanisms. 13 Responsible AI projects have been approved in educational institutions across the country including deepfake detection,” the Ministry informed in a statement.

The update comes months after amendments to the Information Technology Rules took effect in February 2026, requiring online platforms to strengthen their handling of AI-generated content.

Under the revised rules, intermediaries are required to label permissible AI-generated content with clear identifiers and traceable metadata to help users recognise synthetic material. Platforms must also deploy appropriate technical measures to detect unlawful AI-generated content and act more quickly on complaints involving harmful material, including deepfakes, impersonation and non-consensual intimate images.

The Ministry said the revised rules have shortened the time available to remove unlawful content following valid government or court orders from 36 hours to three hours. Timelines for handling user complaints have also been reduced, with platforms required to address sensitive cases such as nudity and impersonation within two hours.

Alongside the regulatory measures, the government said cyber security awareness campaigns have continued to expand. More than 6,650 workshops have been conducted across the country under the Information Security Education and Awareness programme, reaching over 1.137 million participants, including students, teachers, law enforcement personnel, government officials and members of the public.

The government has also continued issuing advisories to online platforms on complying with the Information Technology Act and the Information Technology Rules. This includes guidance on handling AI-generated content and non-consensual intimate imagery.