Technology

Chinese E-Rickshaw Apps Banned in India Over Remote Disable Risk

The Centre has ordered the removal of three Chinese apps — BAT-BMS, Lossigy and Epoch-i-ion — over fears they could remotely disable battery-run e-rickshaws, turning mobility software into a public safety concern.

Arjun Nair

Commentary & Analysis ·

7 min read
An electric rickshaw on an Indian street with a smartphone battery-management app interface overlaid, suggesting remote control risk

The Union government has ordered the removal of three Chinese apps — BAT-BMS, Lossigy and Epoch-i-ion — after concerns that they could be misused to remotely disable battery-operated e-rickshaws. What might once have been a niche software advisory has become a public safety story about India's fast-growing electric mobility fleet. The apps in question are battery-management tools that connect to the control systems of electric three-wheelers. The worry flagged by authorities is stark: software with remote access to a vehicle's battery could, in the wrong hands, immobilise it — not one rickshaw at a time, but potentially across a fleet.

On the surface, this reads like one more entry in a long-running list of Chinese-origin apps that Indian regulators have restricted over the past several years. But the details matter. Earlier rounds of app bans were concerned chiefly with data — where user information travelled, who could see it, and whether it could be harvested for purposes unrelated to the app's stated function. This order is different in kind. It is not about data leaving India; it is about control over physical machines operating on Indian roads. That shift, from information risk to operational risk, changes the stakes considerably.

Software is now transport infrastructure

India's mobility transition rides on batteries, connected control units and the apps that manage them. E-rickshaws have become the workhorse of last-mile transport in hundreds of towns, ferrying passengers and goods over short distances where buses do not run and larger vehicles cannot easily manoeuvre. Most of their battery-management stack traces back to imported components and companion software, often bundled together as a package deal by manufacturers or resellers who may have limited insight into what the software actually does once installed.

This is the quiet reality of the affordable end of the EV market. Higher-end electric cars attract scrutiny over their software architecture, over-the-air update mechanisms and data practices because they are visible, expensive and politically prominent. E-rickshaws attract none of that attention, even though they are arguably more exposed. They are cheap, mass-produced, sold through informal and semi-formal supply chains, and rarely subject to the kind of security audit that a passenger car or a public transit bus might undergo. When the software managing their batteries answers to servers outside India's jurisdiction, a cybersecurity question quietly becomes a livelihood and commuter-safety question, because the person most affected by a remote shutdown is not a wealthy car owner but a driver whose daily income depends on the vehicle starting each morning.

What the removal order signals

The order fits a broader pattern of New Delhi treating Chinese-origin apps as potential security exposures, but this case extends the logic from data privacy to physical control of vehicles. That is a meaningful escalation in how regulators are framing the risk. It suggests officials are no longer satisfied with asking whether an app collects excessive data; they are now asking whether an app, or the server infrastructure behind it, could reach into a piece of physical infrastructure and switch it off.

It also puts EV supply chains on notice: regulators are beginning to look past the hardware label to ask who actually controls the code running India's electric fleet. This is a subtle but important distinction. A battery pack, motor controller or charging unit might be assembled or badged domestically, yet still run on firmware and companion software developed and maintained abroad, with update channels and remote-access privileges that Indian buyers rarely scrutinise at the point of sale. The removal order implies that provenance of components alone is not enough; the software layer sitting on top of that hardware needs its own scrutiny.

Why remote disable capability matters so much

The specific fear here — a battery-management app being used to remotely disable vehicles — is not hypothetical paranoia. Connected battery-management systems are, by design, built to communicate with a controller, often over the internet, to monitor charge levels, protect against overcharging, and sometimes to enforce usage terms such as lease payments. That same connectivity, which exists for legitimate operational reasons, is precisely what creates the exposure. Any system capable of issuing a command to throttle or cut power to a battery can, in principle, be triggered by an unauthorised party if the access controls, authentication or server-side security around it are weak or if the operator of that server chooses to act against the interests of the vehicle's owner.

Scaled across a fleet, the implications extend well beyond individual inconvenience. Last-mile transport networks in Indian towns depend on the reliable, simultaneous availability of thousands of small vehicles. A coordinated or even accidental disabling event across a battery-management platform's user base could disrupt local transport, commerce and daily commutes for large numbers of people who have no direct relationship with the app in question and no way of knowing their mobility depends on it.

Stakeholders caught in the middle

Drivers and small fleet owners who bought these e-rickshaws are the most immediate stakeholders, and the most powerless in this equation. Many will not have chosen the battery-management app themselves; it likely came pre-installed or was bundled by the dealer or component supplier. For them, a government order to remove the app raises practical questions about whether their vehicles will continue to function normally, whether alternative software exists, and who bears the cost of any transition.

Manufacturers and importers of e-rickshaw components face a different pressure: greater scrutiny of their supply chains and, potentially, a requirement to demonstrate that the software running on their products does not carry the same remote-control risk. Regulators, meanwhile, are navigating unfamiliar territory, having to build technical capacity to assess embedded and connected vehicle software rather than relying solely on the data-privacy frameworks that shaped earlier app bans.

The NE Times View

The e-rickshaw is the most humble vehicle on Indian roads, which is precisely why this order matters — cyber risk has reached the bottom of the mobility pyramid, where drivers can least afford a bricked battery. Banning three apps treats the symptom; the disease is an EV ecosystem assembled on opaque imported software with no disclosure of what it can do remotely. India needs baseline security standards for battery-management systems, mandatory local audits, and clear liability when connected components fail or are misused. The mobility transition should not mean handing a kill switch for lakhs of livelihoods to unvetted foreign code.

Looking ahead, the real test will be whether this order remains an isolated administrative action or becomes the starting point for a systematic framework governing connected vehicle software in India. A single ban addresses three named apps; it does nothing about the dozens of similar battery-management tools that may be running, largely unnoticed, across the e-rickshaw fleet and other categories of electric two- and three-wheelers. Sustained oversight would require India to build the technical capacity to audit embedded vehicle software, not merely react to specific security flags as they surface. It would also require manufacturers to disclose, at the point of sale, exactly what remote-access capabilities their battery-management systems possess, so that buyers and regulators alike are not discovering these risks after the fact.

Key takeaways

  • The government has ordered removal of three Chinese battery-management apps — BAT-BMS, Lossigy and Epoch-i-ion — over fears they could remotely disable e-rickshaw batteries.
  • The order marks a shift from earlier Chinese-app bans focused on data privacy to concerns about physical control over vehicles operating in India.
  • E-rickshaws sit at the affordable, informally supplied end of India's EV market, making them especially exposed to opaque imported software with little independent audit.
  • Regulators are beginning to scrutinise who controls the software layer on EV components, not just where the hardware is manufactured.
  • The NE Times argues India needs baseline security standards, mandatory local audits and clear liability rules for connected battery-management systems, rather than one-off app bans.
Share

You may also like to read

More from this section

More