**Executive Summary:**
The Ministry of Electronics and Information Technology addresses questions regarding the use of Generative AI, AI research hubs, support for startups, data protection audits, and the National Data Governance Framework. The government has adopted an inclusive approach to AI governance, supported by advisories and institutional setups. Data protection audits have been conducted for citizen services like DigiLocker and UMANG. The implementation of the National Data Governance Framework is ongoing, with the sharing of non-sensitive data governed by existing policy.
**Key Points / Main Content:**
* **AI Governance and Security:**
* The government adopts an inclusive and innovation-friendly approach to AI governance.
* CERT-In issued advisories on AI security, including:
* Advisory on Security Implications of AI Language-Based Applications (May 9, 2023)
* Advisory on Best Practices Against Vulnerabilities in Generative AI Solutions (March 26, 2025)
* Technical Guidelines for Bill of Materials (BoM) for Software, Hardware, AI, and Quantum and Cryptography requirement (July 9, 2025)
* CERT-In launched the Certified Security Professional in Artificial Intelligence (CSPAI) program.
* An Advisory Group on AI, chaired by the Principal Scientific Advisor, has been constituted to develop an India-specific regulatory framework for AI.
* **AI Research Hubs:**
* 25 Technology Innovation Hubs (TIHs) have been established in reputed institutes.
* Hubs at IIT Kharagpur, IIIT Hyderabad, and IIT BHU are working in AI and Data Science.
* **Startup Support:**
* Support is provided to approximately 1,600 technology startups in Tier II and Tier III cities under the GenNext Support for Innovative Startups (GENESIS) scheme.
* **Data Protection Audits:**
* DigiLocker has undergone ISO 27001:2022 ISMS audit and is duly certified.
* Regular annual internal audits and separate cybersecurity audits by STQC are conducted for UMANG.
* UMANG does not store user data except for the mobile number, and data transfers are encrypted.
* **National Data Governance Framework:**
* The Draft National Data Governance Framework Policy was published on May 26, 2022, for public consultation.
* The sharing of non-sensitive data will continue to be governed by the National Data Sharing and Accessibility Policy (NDSAP), 2012.
**Impact Analysis:**
* **Citizens:**
* *Impact:* Enhanced data privacy and security in public services like DigiLocker and UMANG.
* *Action Required:* Be aware of the data protection measures in place and utilize the platforms securely.
* **Technology Startups (Tier II and Tier III cities):**
* *Impact:* Access to support and funding under the GENESIS scheme.
* *Action Required:* Apply for and utilize the resources provided by the GENESIS scheme for innovation and growth.
* **Cybersecurity Professionals:**
* *Impact:* Opportunity to enhance skills through the CSPAI program.
* *Action Required:* Participate in the CSPAI program to improve expertise in securing AI systems.
* **AI Researchers and Institutions:**
* *Impact:* Collaboration and innovation opportunities through the established Technology Innovation Hubs (TIHs).
* *Action Required:* Engage with the TIHs to contribute to AI and Data Science research and development.
* **Government and Policymakers:**
* *Impact:* Guidance for developing and implementing AI regulations and data governance policies.
* *Action Required:* Consider the advisories and guidelines issued by CERT-In and the recommendations of the Advisory Group on AI.
Key Entities Referenced
Ministry of Electronics and Information Technology: The Indian government ministry responsible for electronics and information technology policy.
Artificial Intelligence: A general term used throughout the document to refer to AI technologies and governance.
Digital India Programme: A Government of India initiative to transform India into a digitally empowered society and knowledge economy.
DigiLocker: A citizen service providing a secure cloud-based platform for storage, sharing and verification of documents and certificates.
Unified Mobile Application for New-age Governance (UMANG): A citizen service providing a unified platform for accessing various government services.
National Data Governance Framework: A framework by the Government of India for governing data and promoting data sharing.
CERT-In: Indian Computer Emergency Response Team, responsible for cybersecurity and issuing advisories.
National Mission on Interdisciplinary Cyber-Physical Systems: A national mission focused on cyber-physical systems and establishing Technology Innovation Hubs.
GOVERNMENT OF INDIA
MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY
LOK SABHA
UNSTARRED QUESTION NO. 1632
TO BE ANSWERED ON: 30.07.2025
GUIDELINES FOR USE OF GENERATIVE AI
1632. SHRI AMRINDER SINGH RAJA WARRING:
Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state:
(a) whether the Government has developed ethical guidelines for the use of generative Artificial
Intelligence (AI) in public services;
(b) the details of the progress on setting up AI research hubs under Digital India Programme;
(c) whether the startups in Tier 2/3 cities receiving support under MeitY’s innovation funds;
(d) if so, whether any data protection audit been conducted for citizen services like DigiLocker or
Unified Mobile Application for New-age Governance (UMANG); and
(e) the status of National Data Governance Framework implementation?
ANSWER
MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY
(SHRI JITIN PRASADA)
(a) to (c): The government has taken an inclusive and innovation-friendly approach to Artificial
Intelligence (AI) governance. It is backed by an institutional setup to protect citizens’ rights,
ensure data privacy, and promote innovation.
The Government, through CERT-In, has issued several advisories to ensure the secure use of AI.
These include:
● Advisory on Security Implications of AI Language-Based Applications (9th May 2023)
● Advisory on Best Practices Against Vulnerabilities in Generative AI Solutions (26th
March 2025)
● Technical Guidelines for Bill of Materials (BoM) for Software, Hardware, AI, and
Quantum and Cryptography requirement (9th July 2025)
Additionally, CERT-In has launched the Certified Security Professional in Artificial Intelligence
(CSPAI) program. It equips cybersecurity professionals with the skills to secure AI systems,
address AI-related threats, and ensure the trustworthy deployment of AI.
An Advisory Group on AI, chaired by the Principal Scientific Advisor to the Prime Minister, has
also been constituted to develop an India-specific regulatory framework for AI.The government has established 25 Technology Innovation Hubs (TIHs) in reputed institutes
under the National Mission on Interdisciplinary Cyber-Physical Systems. Hubs at IIT Kharagpur,
IIIT Hyderabad and IIT BHU are working in the field of Artificial Intelligence and Data Science.
Under the Gen-Next Support for Innovative Startups (GENESIS) scheme, support is being
provided to about 1,600 technology startups in tier II and tier III cities.
(d): DigiLocker has undergone ISO 27001:2022 Information Security Management System
(ISMS) audit. It has been duly certified in accordance with the prescribed standards, security
policy and applicable regulatory and contractual requirement.
Regular annual internal audit is carried out for UMANG. In additional, a separate cybersecurity
audit is also conducted by STQC. UMANG does not store any user data except for the mobile
number. All data transfers are carried out through encrypted APIs, ensuring secure
communication.
(e): Government published the Draft National Data Governance Framework Policy on 26th May
2022 for public consultation. After deliberations, it was decided that the sharing of non-sensitive
data would continue to be governed by the National Data Sharing and Accessibility Policy
(NDSAP), 2012.
*******