Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Regulatory Framework on AI, Cyber Security and Cyberspace

This chapter covers how India governs AI, cyber security and cyberspace, mainly through the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. To solve questions, identify the provision, apply it to the facts, and conclude on liability, penalty or compliance duty. Sections 69B and 66F are core.

What this chapter covers

This chapter is the legal base of Elective 4.4. It explains who governs cyberspace in India, what the Information Technology Act, 2000 covers, and how the law deals with monitoring, cyber terrorism and other offences. It also introduces the institutions that deal with cyber security, and how AI is regulated in India at present.

The IT Act applies to the whole of India. Unless the Act provides otherwise, it also applies to any offence or contravention under it committed outside India by any person. It does not apply to documents or transactions in the First Schedule, which the Central Government can amend by notification. Two sections need close reading. Section 69B lets the Central Government authorise an agency to monitor and collect traffic data for cyber security. Section 66F defines and punishes cyber terrorism. Sections 69 and 77 sit nearby and are often tested together with them.

The chapter links to the rest of the paper. The data protection part builds on the DPDP Act, 2023, which also amended the IT Act: section 43A was omitted. Cyber security practice, data analytics and AI governance all rely on the definitions and powers set out here. Treat this chapter as the vocabulary and the legal authority for later topics.

The paper is written and case-based, and cyber law questions ask you to apply a section to facts and reach a conclusion. This chapter gives you the sections, definitions and penalties that those answers rest on. Exact wording matters, for example who may authorise monitoring, what the intermediary must do, and what the penalty is. Students who know the text precisely can write short, accurate answers and gain marks in the cyber law questions. The chapter is also compact, so effort here pays back quickly.

Regulatory Framework on AI, Cyber Security and Cyberspace: topics in the order to study them

  1. 1Overview of AI Regulation and Cyberspace Governance in IndiaStart with the big picture so every later section has a place in the framework.
  2. 2Information Technology Act, 2000: Key Definitions and ScopeExtent, extraterritorial reach, the First Schedule exclusion and definitions are needed before any section is read.
  3. 3Section 69B: Monitoring and Collecting Traffic Data for Cyber SecurityA short, text-heavy section with a clear structure; learn it before the harder offence provisions.
  4. 4Section 66F: Punishment for Cyber TerrorismIt builds on the definitions and uses terms like computer contaminant and critical information infrastructure.
  5. 5Cyber Offences, Penalties and Adjudication under the IT ActWith 69B and 66F understood, you can compare other offences, penalties and how section 77 lets other laws apply too.
  6. 6Cyber Security Framework and Institutions in IndiaFinish with the institutions and practice that put these legal powers to work, which suits case-based answers.

How to prepare Regulatory Framework on AI, Cyber Security and Cyberspace

Prepare this chapter by reading the bare text first, then practising application. Keep the Act open while you study.

  1. Read the overview topic once to see how the IT Act, the DPDP Act and AI policy fit together.
  2. Learn the scope of the IT Act: whole of India, offences outside India, and the First Schedule exclusion.
  3. For section 69B, write the structure in your own words: who authorises, what is collected, the duty of the intermediary, the prescribed safeguards and the penalty. Note the definition of traffic data.
  4. For section 66F, split it into the two limbs, (A) and (B), and note the intent, the conduct and the effect needed in each. Remember the punishment is imprisonment which may extend to life.
  5. Compare sections 69 and 69B in a two-column note: purpose, who acts, who must assist, and penalty.
  6. Solve at least five case-style questions in the format provision, facts, conclusion. Then review the institutions topic for practical drafting points.
  7. Revise the list of quick points the day before the exam.

Common mistakes in Regulatory Framework on AI, Cyber Security and Cyberspace

  • Mixing up sections 69 and 69B.

    Fix: Remember that 69 covers interception, monitoring and decryption of information for stated public interest grounds, while 69B covers traffic data for cyber security.

  • Quoting the old penalty under section 69B(4).

    Fix: Use the current text: imprisonment up to one year, or a fine up to one crore rupees, or both, as substituted in 2023.

  • Applying section 66F without checking intent and effect.

    Fix: Check the intent or the restricted-information limb, then the conduct, then the effect. Without these elements, another offence may apply.

  • Forgetting that other laws can also apply.

    Fix: Cite section 77 and note that punishment under other laws is not barred.

  • Ignoring the extraterritorial scope of the IT Act.

    Fix: In facts with a foreign offender, state that the Act can apply to offences or contraventions committed outside India.

  • Writing general theory without a conclusion.

    Fix: Use the format provision, application to the facts, and a clear conclusion on liability or compliance.

Last-day revision: Regulatory Framework on AI, Cyber Security and Cyberspace

  • The IT Act, 2000 extends to the whole of India and applies to offences or contraventions committed outside India by any person, unless the Act provides otherwise.
  • The Act does not apply to documents or transactions in the First Schedule; the Central Government can amend that Schedule by notification.
  • Section 69B: the Central Government may, by notification, authorise any Government agency to monitor and collect traffic data for cyber security.
  • Section 69B purpose: to enhance cyber security and to identify, analyse and prevent intrusion or spread of computer contaminant.
  • Section 69B(2): the intermediary or person in charge must give technical assistance and facilities to the authorised agency.
  • Section 69B(4): an intermediary who intentionally or knowingly contravenes sub-section (2) may face imprisonment up to one year, or a fine up to one crore rupees, or both.
  • Traffic data includes origin, destination, route, time, date, size, duration or type of underlying service of a communication.
  • Section 69 allows directions to intercept, monitor or decrypt information; failure to assist can mean imprisonment up to seven years and a fine.
  • Section 66F covers cyber terrorism: intent to threaten India's unity, integrity, security or sovereignty, or to strike terror, plus the prescribed conduct and effect.
  • Section 66F punishment: imprisonment which may extend to life, for committing or conspiring to commit cyber terrorism.
  • Section 77: compensation, penalty or confiscation under the IT Act does not prevent punishment under any other law.
  • The DPDP Act, 2023 omitted section 43A of the IT Act.

Regulatory Framework on AI, Cyber Security and Cyberspace practice questions

Regulatory Framework on AI, Cyber Security and Cyberspace in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Regulatory Framework on AI, Cyber Security and Cyberspace: frequently asked questions

Which sections of the IT Act matter most in this chapter?

Sections 69B and 66F are the core, with section 69 and section 77 as close companions. Also know the scope in section 1. Read the exact text, since questions test conditions and penalties.

What is traffic data under section 69B?

It is any data identifying or purporting to identify any person, computer system, network or location to or from which a communication is or may be transmitted. It includes origin, destination, route, time, date, size, duration or type of underlying service, and any other information.

What is the punishment for cyber terrorism?

Under section 66F(2), whoever commits or conspires to commit cyber terrorism is punishable with imprisonment which may extend to imprisonment for life.

Does the IT Act apply to offences committed outside India?

Yes, unless the Act provides otherwise, it applies to any offence or contravention under it committed outside India by any person. State this when facts involve a foreign party.