India's Computer Emergency Response Team (CERT-In) has taken a significant step in bolstering national data security by mandating a six-hour breach reporting window for AI systems that handle the personal data of Indian citizens. This move aims to plug a long-standing gap that had exempted model-serving infrastructure from the compliance net.

While security experts welcome the new directions for bringing clarity to the existing regulations, they also acknowledge the operational implications for startups that are increasingly relying on third-party clouds for AI inference. Under the new guidelines, covered entities must maintain security event logs for a minimum of 180 days on infrastructure located within India.

Designating a point of contact for CERT-In coordination is another critical requirement that will enhance the team's ability to respond to and contain AI-related security incidents. This added layer of accountability is expected to strengthen India's data security posture, particularly in the face of rising threats from AI-powered attacks.

The operational burden on small and medium-sized enterprises (SMEs) and startups is a concern, however. Many of these entities are already grappling with the challenges of building and deploying AI models on cloud infrastructure, and the added compliance requirements may strain their resources.

As India continues to ride the AI wave, it's essential that the regulatory environment supports innovation while ensuring the security and sanctity of citizen data. The CERT-In's move is a step in the right direction, but it will be crucial to monitor the implementation and fine-tune the regulations as needed to avoid stifling entrepreneurship and innovation.