Technology

Connected Car Rules: India Plans Vehicle Software Update Norms

With cars increasingly run by software, the government is reportedly preparing update and security norms aimed at preventing vehicle hijacking and governing how connected cars in India are patched and protected.

Arjun Nair

Commentary & Analysis ·

6 min read
A modern connected car on an Indian highway with a glowing digital dashboard and software update icons overlaid on the windscreen.

India's government is planning norms for vehicle software updates as cars grow steadily more connected, according to a Times of India report on July 5. The move, which reportedly includes measures to thwart digital hijacking of vehicles, signals a new phase in Indian auto regulation, one where the code inside a car matters as much as the machinery bolted around it. For a country that has spent decades building crash-test standards, emission norms and safety ratings around physical hardware, the idea that a line of software could be as safety-critical as a brake pad is a genuine shift in regulatory thinking.

Cars are becoming rolling computers

Connected vehicles are no longer a luxury niche in India. Software now runs infotainment, safety systems, diagnostics, navigation and increasingly sophisticated driver-assistance features. Many models already receive over-the-air updates, meaning a car's behaviour can change overnight without a visit to the workshop. This is a profound change from how Indian consumers have historically related to their vehicles: a car bought in showroom condition was, for the most part, the same car mechanically for its entire life unless a part physically failed or was replaced. Now, a car can gain new features, lose old ones, or have its underlying logic altered entirely through a remote update pushed while it sits in a driveway.

That capability cuts both ways. Well-governed updates can fix defects quickly and improve safety at scale, in much the same way that smartphone manufacturers patch vulnerabilities without requiring users to visit a store. Poorly secured connected systems, on the other hand, could expose owners to data theft or even operational interference, the hijacking scenario regulators are reportedly keen to shut down. The stakes here are not abstract: a compromised infotainment system might leak location data or personal information, while a compromised safety-critical system, in a worst case, could affect how a vehicle actually behaves on the road. It is this second category, the possibility that a car's core functions could be manipulated remotely, that appears to be driving the urgency behind the government's planning.

What the norms may need to cover

The core policy question is how India should regulate security, accountability and update quality for vehicles that talk to external systems. Automakers may face clearer standards on update logs, user consent, vulnerability disclosure and emergency fixes. Each of these elements addresses a distinct failure mode. Update logs would let owners, regulators and investigators establish exactly what changed in a vehicle's software and when, which becomes essential if an accident or malfunction needs to be traced back to a particular patch. User consent provisions would determine whether owners must be informed, or must actively approve, before a manufacturer alters how their vehicle operates. Vulnerability disclosure rules would set out how quickly and how transparently a manufacturer must report a discovered security flaw, rather than quietly patching it and hoping no one asks questions. And emergency fix protocols would clarify how fast a genuinely dangerous flaw must be resolved once it is known, and what obligations a manufacturer has to owners in the interim.

The next concrete milestone to watch is the release of draft norms or a public consultation from the government. Until that draft appears, it is difficult to know how prescriptive the rules will be, whether they will set hard technical requirements or simply outcome-based principles that manufacturers must satisfy in their own way. That distinction will matter enormously for how the industry responds.

Why this matters for consumers

For the ordinary car buyer, these norms touch on questions that have so far been left almost entirely to manufacturers to decide for themselves. Who is responsible if a faulty software update disables a safety feature. What recourse does an owner have if their vehicle's data is compromised through a poorly secured connected system. Should owners be told, in plain terms, what a software update actually changes, rather than a vague release note. At present, these questions are largely answered by the terms and conditions bundled into a vehicle purchase, terms that are rarely read and rarely negotiated. Clear regulatory standards would shift at least some of that burden away from individual consumers and onto manufacturers, who are far better placed to manage cybersecurity risk at scale.

There is also a broader trust dimension. As more Indian buyers move toward connected and increasingly autonomous-leaning vehicles, public confidence in the safety of that technology becomes a precondition for adoption. A single high-profile incident involving a hijacked or remotely manipulated vehicle could set back consumer trust in connected car technology for years, regardless of how rare such an event might statistically be. Proactive regulation, in that sense, is not just about closing a security gap; it is about protecting the market itself.

The industry's likely concerns

Automakers, particularly smaller players and newer entrants, will likely watch the compliance burden closely. Established, well-resourced manufacturers with large engineering teams may find it relatively straightforward to build out formal update logging, consent workflows and vulnerability disclosure processes. Smaller automakers and startups, by contrast, could face a disproportionate cost in building the same infrastructure, particularly if the norms are drafted with highly specific technical requirements rather than flexible, outcome-based standards. This is a familiar tension in technology regulation generally: rules designed to rein in the largest players can inadvertently entrench their dominance by raising the cost of entry for everyone else.

How the government calibrates this balance, through phased timelines, scaled requirements based on company size, or simplified compliance pathways for smaller manufacturers, will determine whether these norms strengthen the overall market or simply consolidate it around a handful of large players.

The NE Times View

This is regulation catching up with reality, and it is overdue. Indian buyers are adopting connected cars faster than the rulebook has evolved, leaving questions of liability, data ownership and patch quality to fine print written by manufacturers. Done well, these norms could become a template: mandatory update logs and vulnerability reporting would give consumers real protection without stifling innovation. Done clumsily, they could bury smaller automakers and startups in compliance while the biggest players absorb the cost.

The government should consult widely and set outcome-based standards, because a car that can be updated remotely is a car that can, in the wrong hands, be attacked remotely. Outcome-based regulation, focused on what a manufacturer must achieve in terms of security and transparency rather than dictating the precise technical means of achieving it, tends to age better as technology evolves. Rigid, overly specific technical mandates risk becoming obsolete within a few product cycles, forcing repeated amendments. A principles-based framework, backed by meaningful enforcement and genuine consultation with both large manufacturers and smaller innovators, offers the best chance of rules that protect consumers today and remain workable as vehicle software grows more complex tomorrow.

Key takeaways

  • India's government is reportedly planning norms for vehicle software updates, including measures against digital hijacking of connected cars, per a Times of India report on July 5.
  • Modern vehicles increasingly rely on over-the-air software for infotainment, safety systems, diagnostics and driver-assistance, meaning a car's behaviour can change without a workshop visit.
  • Likely areas of regulation include update logs, user consent, vulnerability disclosure and emergency fix protocols.
  • The next milestone to watch is the release of draft norms or a public consultation.
  • The NE Times argues for outcome-based standards that protect consumers and enable innovation, rather than rigid rules that could burden smaller automakers disproportionately.
Share

You may also like to read

More from this section

More