Connected Car Rules: India Plans Vehicle Software Update Norms
With cars increasingly run by software, the government is reportedly preparing update and security norms aimed at preventing vehicle hijacking and governing how connected cars in India are patched and protected.
Commentary & Analysis ·

India's government is planning norms for vehicle software updates as cars grow steadily more connected, according to a Times of India report on July 5. The move, which reportedly includes measures to thwart digital hijacking of vehicles, signals a new phase in Indian auto regulation, one where the code inside a car matters as much as the machinery bolted around it. For a country that has spent decades building crash-test standards, emission norms and safety ratings around physical hardware, the idea that a line of software could be as safety-critical as a brake pad is a genuine shift in regulatory thinking.
Cars are becoming rolling computers
Connected vehicles are no longer a luxury niche in India. Software now runs infotainment, safety systems, diagnostics, navigation and increasingly sophisticated driver-assistance features. Many models already receive over-the-air updates, meaning a car's behaviour can change overnight without a visit to the workshop. This is a profound change from how Indian consumers have historically related to their vehicles: a car bought in showroom condition was, for the most part, the same car mechanically for its entire life unless a part physically failed or was replaced. Now, a car can gain new features, lose old ones, or have its underlying logic altered entirely through a remote update pushed while it sits in a driveway.
That capability cuts both ways. Well-governed updates can fix defects quickly and improve safety at scale, in much the same way that smartphone manufacturers patch vulnerabilities without requiring users to visit a store. Poorly secured connected systems, on the other hand, could expose owners to data theft or even operational interference, the hijacking scenario regulators are reportedly keen to shut down. The stakes here are not abstract: a compromised infotainment system might leak location data or personal information, while a compromised safety-critical system, in a worst case, could affect how a vehicle actually behaves on the road. It is this second category, the possibility that a car's core functions could be manipulated remotely, that appears to be driving the urgency behind the government's planning.
What the norms may need to cover
The core policy question is how India should regulate security, accountability and update quality for vehicles that talk to external systems. Automakers may face clearer standards on update logs, user consent, vulnerability disclosure and emergency fixes. Each of these elements addresses a distinct failure mode. Update logs would let owners, regulators and investigators establish exactly what changed in a vehicle's software and when, which becomes essential if an accident or malfunction needs to be traced back to a particular patch. User consent provisions would determine whether owners must be informed, or must actively approve, before a manufacturer alters how their vehicle operates. Vulnerability disclosure rules would set out how quickly and how transparently a manufacturer must report a discovered security flaw, rather than quietly patching it and hoping no one asks questions. And emergency fix protocols would clarify how fast a genuinely dangerous flaw must be resolved once it is known, and what obligations a manufacturer has to owners in the interim.
The next concrete milestone to watch is the release of draft norms or a public consultation from the government. Until that draft appears, it is difficult to know how prescriptive the rules will be, whether they will set hard technical requirements or simply outcome-based principles that manufacturers must satisfy in their own way. That distinction will matter enormously for how the industry responds.
Why this matters for consumers
For the ordinary car buyer, these norms touch on questions that have so far been left almost entirely to manufacturers to decide for themselves. Who is responsible if a faulty software update disables a safety feature. What recourse does an owner have if their vehicle's data is compromised through a poorly secured connected system. Should owners be told, in plain terms, what a software update actually changes, rather than a vague release note. At present, these questions are largely answered by the terms and conditions bundled into a vehicle purchase, terms that are rarely read and rarely negotiated. Clear regulatory standards would shift at least some of that burden away from individual consumers and onto manufacturers, who are far better placed to manage cybersecurity risk at scale.
There is also a broader trust dimension. As more Indian buyers move toward connected and increasingly autonomous-leaning vehicles, public confidence in the safety of that technology becomes a precondition for adoption. A single high-profile incident involving a hijacked or remotely manipulated vehicle could set back consumer trust in connected car technology for years, regardless of how rare such an event might statistically be. Proactive regulation, in that sense, is not just about closing a security gap; it is about protecting the market itself.
The industry's likely concerns
Automakers, particularly smaller players and newer entrants, will likely watch the compliance burden closely. Established, well-resourced manufacturers with large engineering teams may find it relatively straightforward to build out formal update logging, consent workflows and vulnerability disclosure processes. Smaller automakers and startups, by contrast, could face a disproportionate cost in building the same infrastructure, particularly if the norms are drafted with highly specific technical requirements rather than flexible, outcome-based standards. This is a familiar tension in technology regulation generally: rules designed to rein in the largest players can inadvertently entrench their dominance by raising the cost of entry for everyone else.
How the government calibrates this balance, through phased timelines, scaled requirements based on company size, or simplified compliance pathways for smaller manufacturers, will determine whether these norms strengthen the overall market or simply consolidate it around a handful of large players.
The NE Times View
This is regulation catching up with reality, and it is overdue. Indian buyers are adopting connected cars faster than the rulebook has evolved, leaving questions of liability, data ownership and patch quality to fine print written by manufacturers. Done well, these norms could become a template: mandatory update logs and vulnerability reporting would give consumers real protection without stifling innovation. Done clumsily, they could bury smaller automakers and startups in compliance while the biggest players absorb the cost.
The government should consult widely and set outcome-based standards, because a car that can be updated remotely is a car that can, in the wrong hands, be attacked remotely. Outcome-based regulation, focused on what a manufacturer must achieve in terms of security and transparency rather than dictating the precise technical means of achieving it, tends to age better as technology evolves. Rigid, overly specific technical mandates risk becoming obsolete within a few product cycles, forcing repeated amendments. A principles-based framework, backed by meaningful enforcement and genuine consultation with both large manufacturers and smaller innovators, offers the best chance of rules that protect consumers today and remain workable as vehicle software grows more complex tomorrow.
Key takeaways
- India's government is reportedly planning norms for vehicle software updates, including measures against digital hijacking of connected cars, per a Times of India report on July 5.
- Modern vehicles increasingly rely on over-the-air software for infotainment, safety systems, diagnostics and driver-assistance, meaning a car's behaviour can change without a workshop visit.
- Likely areas of regulation include update logs, user consent, vulnerability disclosure and emergency fix protocols.
- The next milestone to watch is the release of draft norms or a public consultation.
- The NE Times argues for outcome-based standards that protect consumers and enable innovation, rather than rigid rules that could burden smaller automakers disproportionately.
You may also like to read

India VPN Rules: Stricter Provider Norms Weigh Privacy vs Compliance
The government is reportedly weighing stricter rules for VPN providers, including a mandatory India office and compliance officers, reigniting the debate between cyber enforcement and digital privacy.

Chinese E-Rickshaw Apps Banned in India Over Remote Disable Risk
The Centre has ordered the removal of three Chinese apps — BAT-BMS, Lossigy and Epoch-i-ion — over fears they could remotely disable battery-run e-rickshaws, turning mobility software into a public safety concern.

IIT Madras, IIT Kanpur Launch Cybersecurity Degree With Field Training
IIT Madras and IIT Kanpur have jointly launched a practice-oriented Bachelor of Cybersecurity featuring two years of field deployment, a direct response to India's widening shortage of trained cyber defence professionals.

I4C Warns Indian Companies of Rising 'Boss Scam' CEO-Impersonation Cyber Fraud
India's cybercrime coordination agency has flagged an emerging 'Boss Scam' in which fraudsters impersonate regulators and executives to push urgent, fraudulent money transfers at companies.
More from this section
MoreCG Semi Sanand Plant Opens, Boosting India's Semiconductor Drive
Prime Minister Narendra Modi inaugurated CG Semi's chip assembly and test facility in Sanand, Gujarat, giving India's semiconductor mission a working manufacturing milestone rather than another policy promise.

Chinese E-Rickshaw Apps Banned in India Over Remote Disable Risk
The Centre has ordered the removal of three Chinese apps — BAT-BMS, Lossigy and Epoch-i-ion — over fears they could remotely disable battery-run e-rickshaws, turning mobility software into a public safety concern.

Gaganyaan Parachute Test Success Moves ISRO Closer to Crewed Flight
ISRO has completed successful integrated parachute tests for the Gaganyaan crew capsule, validating a critical part of the descent and recovery system as India's human spaceflight programme advances through key engineering milestones.