All insights

Security & Threats

CERT-In Reporting When an Agent Misbehaves

· 10 minute read

An agent that leaks, is owned, or is used as a path into ICT is a cyber incident if it matches the live annexure. There is no CERT-In 'AI type' to invent. Map the effect and start the clock.

A university SOC watched an assistant print a row of hostel records after a student pasted a role-play. Someone said 'file it as an AI incident'. Someone else opened the CERT-In portal and looked for a drop-down that did not exist. Two hours went into naming. The six-hour clock did not care about the name. The effect was a data leak. The annexure already had language for that.

On 28 April 2022, CERT-In issued directions under section 70B(6) of the Information Technology Act, 2000 — No. 20(3)/2022-CERT-In. Covered entities, including government organisations, must report cyber incidents listed in Annexure I within six hours of noticing them or being brought to notice. They must enable logs of ICT systems and keep them securely for a rolling 180 days, and those logs are to be maintained within Indian jurisdiction. The directions took effect after the stated transition. They are still the live floor in 2026.

This guide is for DPOs, CISOs and SOC leads. Dated 17 August 2026. It is not legal advice and it is not a CERT-In circular. We will not invent an official 'AI incident type' code. If CERT-In later publishes one, file that. Until then, map the effect to the annexure that exists.

Prcept AI will give you logs you own. We will not file your incident for you. The clock is yours.

What the 2022 directions actually say

Read the PDF, not a vendor paraphrase. Direction (ii) is the six-hour report for Annexure I incidents, via the methods CERT-In publishes — including the email and phone on the directions themselves, and the formats on cert-in.org.in as updated. Direction (iv) is the 180-day log floor in India. There are also clock-sync and, for certain providers, registration and customer-information duties. Know which of those attach to you. A department is not a VPN provider; do not copy the wrong paragraph into a standing order.

Annexure I is a list of cyber incident kinds: compromise, unauthorised access, malware, defacement, data breach, data leak, identity theft, attacks on applications and networks, and other listed items. It is not a catalogue of products. 'Agent' does not need to appear for the duty to attach.

The May 2022 FAQs clarify operational questions. They still do not create an AI taxonomy. If a consultant sells you a mapping titled 'CERT-In AI codes 1 through 9', ask for the URL on cert-in.org.in. If there is none, do not put those codes on a statutory report.

Map the effect, not the model

Ask what happened to information or systems. If another principal's personal data was disclosed, you are in leak or breach territory and also in a DPDP conversation. If a tool identity was used without authorisation, you are in unauthorised access. If a connector was used to change a register, you may have a targeted attack on an application. Write the facts. Then pick the annexure language that fits. Multiple types can be true.

Not every misbehaviour is a cyber incident. A model that invents a scheme name, with no access beyond its prompt, is usually a product-quality and governance failure. It may still need a public correction. It does not become a CERT-In report because someone is embarrassed. Over-reporting noise is how SOCs stop being believed; under-reporting leaks is how clocks are missed. The decision owner should be named before the night happens.

DPDP is a separate spine. A personal-data incident can be a DPDP problem, a CERT-In problem, both, or — rarely — neither. Do not let one statute hide the other. This page is the CERT-In spine. Counsel owns the overlap.

Effects we see on agent desks, mapped without invented codes. Confirm against the live annexure and counsel.
What you observedUsually maps towardUsually not a CERT-In event by itself
Other citizen's record in an answerData leak / unauthorised access (facts decide)A wrong but public circular paraphrase
Stolen connector token used at 2 a.m.Unauthorised access / compromiseA failed login that was blocked
Write tool changed a registerAttack on application / unauthorised accessA draft the officer never published
Public desk minted a fake approvalMaybe none; governance and fraud reviewDo not invent an 'AI hallucination' type
Ransom note on the inference nodeMalware / compromise of ICTA model refusing a question

The six hours and the 180 days

The clock starts when you notice or are brought to notice — not when you finish a root-cause essay. A councillor's email can start it. A SOC alert can start it. 'We were still classifying the AI type' does not stop it.

Have a one-page report kit: who reports, the live CERT-In channel, the facts you already know, the systems touched, the time of notice. Send what you have. Update. Perfection is how people miss 18:00.

Logs must already exist. You cannot create 180 days of ICT logs after the fact. Agent actions need grain: actor, time, tool, data class, retrieval ids, output id. Store them in India. Conversation text is often personal data; the logging article in this cluster is how you keep the duty without building a second leak. The 180-day floor is not permission to delete the administrative file on day 181.

  • Name the six-hour owner and a deputy on the roster.
  • Do not wait for the vendor's severity label.
  • Do not invent annexure codes.
  • Keep a copy of what you filed, in the department's store.
  • Sync system clocks as the directions require; skewed time wrecks both reports and audits.

Vendors and hosted models

If the model host or the SI noticed first, you are still 'brought to notice'. Write in the contract who must wake you, in minutes, not in a quarterly QBR. Third-party APIs and telemetry paths are how notice can live in another country while your clock runs in yours. That is a sovereignty problem and a reporting problem.

Do not assume the host will file for you. Know whether they are a covered entity for their own estate. Your government organisation's duty is not subcontracted by a status page.

On-prem does not remove the duty. It can make the logs yours, which is the point of a sovereign agent. Air-gap does not remove the duty either. Insiders and media still create incidents.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.

We need an official AI code or the filing will be rejected.

File the effect in the language CERT-In already published. If a channel later asks for more detail, add the tactic in prose. Do not wait for a taxonomy that is not on the site.

It was only a hallucination.

Hallucination is not a legal category. If the output disclosed personal data or changed a system, ignore the poetry and map the effect. If it only said a wrong office hour, fix the corpus.

The vendor said they reported it.

Ask for the acknowledgement and still know whether your organisation had an independent duty. Two filings with the same facts beat zero filings with a vendor assumption.

Our logs are in a foreign SIEM.

Then you have a live problem with the 180-day Indian-jurisdiction floor, independent of this agent. Fix the store. Do not add an agent until the floor exists.

A fourteen-day reporting readiness drill

Do this before the public desk. The first night is a bad time to find the annexure.

  1. Day 1–2: print the 28 April 2022 PDF and the current reporting page. Highlight Annexure I. Ban invented codes in a one-line standing instruction.
  2. Day 3–4: name the six-hour owner, deputy, and the channel they will use. Put numbers on the wall.
  3. Day 5–7: write five effect-to-annexure examples for your actual tools, including two that are not reportable.
  4. Day 8–10: prove 180-day ICT logs exist in India for the agent path. Time an export.
  5. Day 11–12: tabletop a leak at 17:40 on a Friday. Start the clock. File a dummy pack internally.
  6. Day 13–14: contract language — vendor notice in minutes, no waiting for their PR. CISO signs the runbook.

How this shows up in the file

Subject: CERT-In reporting — agent [name] — effect mapping.

We will report Annexure I incidents within six hours of notice through [channel], owner [post]. We will not invent CERT-In AI incident type codes. Agent tactics (injection, stolen tool token, poisoned chunk) will be written in the narrative. ICT logs for this path are retained 180 days in [Indian location] and exported by [runbook]. Quality failures without cyber effect follow the product path, not the CERT-In path. This note is not legal advice. The live PDF and reporting page govern.

Attach the five examples. A night roster should not be philosophising.

This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, GFR, GeM term, CVC instruction, CERT-In direction, DPDP text, departmental manual and your counsel before you file it.

Questions this usually raises

Has CERT-In published AI-specific incident types?
As of this writing we will not claim a special CERT-In AI taxonomy. Use Annexure I of the 28 April 2022 directions and any later official update on cert-in.org.in. Do not invent codes.
Does every prompt-injection attempt have to be reported?
No. Report when the effect matches a listed incident — for example a leak or unauthorised access — as counsel and the SOC map it. Attempts that fail and disclose nothing are usually a security-operations note.
Do the 2022 directions apply to government organisations?
The directions expressly include government organisations among the entities that must report listed incidents and maintain the specified logs. Read the text for your facts. This is not a coverage opinion.
What if we notice at hour five and do not have root cause?
Report the facts you have. Update. The clock is not a root-cause clock. Put that in the file next to “CERT-In AI incident reporting” so a stranger can reconstruct it. A one-line yes/no under “CERT-In Reporting When an Agent Misbehaves” is not an answer a secretary can defend. Confirm against the live Gazette, circular or GeM term; this is not legal advice.
Are conversation logs the 180-day logs?
They may be part of your ICT logs if they are how the system ran. They are often also personal data. Keep the statutory floor, redact, and do not treat a chat export as the whole incident file.
Will Prcept file CERT-In reports for us?
No. We will surface logs and wake you. The government organisation owns the filing. That allocation should be in the contract, not in a hope.

Sources