Cars today aren’t just machines with an engine and four wheels anymore. They’ve quietly turned into computers on wheels loaded with apps, sensors, cloud connections, and constant software updates. Features like remote engine start, live GPS tracking, driver-assist systems, and over-the-air (OTA) updates have made everyday driving smoother and smarter. But along with that convenience comes a risk most buyers never think about: what happens if someone hacks your car’s software?
That’s exactly the concern the Indian government is stepping in to address. Through a new set of proposed vehicle cybersecurity rules in India, authorities are working to make sure connected vehicles are protected against hacking, malware, and software loopholes before these issues become widespread. The framework is built around two key technical standards: AIS-189, which deals with cybersecurity management, and AIS-190, which governs secure software updates. Together, they’re meant to bring Indian vehicles in line with the kind of digital safety standards already being adopted in more mature auto markets abroad.
Why This Matters Now
A modern car isn’t controlled by one system; it runs on dozens of small computers called Electronic Control Units (ECUs), each managing something different: braking, steering, battery health, infotainment, and more. Add smartphone connectivity, voice assistants, and OTA updates into the mix, and you get a vehicle that’s incredibly convenient but also exposed to new kinds of digital threats. Security researchers around the world have already shown that poorly protected connected car systems can be exploited. India’s new rules are essentially a preventive step, aiming to close these gaps before they turn into real-world problems.
What AIS-189 Actually Covers
AIS-189 shifts the entire mindset of vehicle safety. It’s no longer just about crash protection; it’s about digital protection too. Under this standard, manufacturers will be expected to:
- Identify potential cybersecurity risks right from the design stage
- Build strong safeguards against hacking attempts
- Continuously monitor for emerging threats
- Respond quickly if a vulnerability is found
- Maintain security support even after the car is sold
In short, it pushes the industry from a “fix it when it breaks” approach to a “prevent it before it happens” mindset.
AIS-190: Making Software Updates Trustworthy

Since many cars now receive updates remotely, improving things like navigation, battery performance, and ADAS features, it’s crucial that these updates are genuine and tamper-proof. AIS-190 focuses on exactly that. It requires a proper Software Update Management System (SUMS) to ensure every update sent to a vehicle is authenticated, traceable, and safe from external interference.
Who Will These Rules Apply To?
The rollout is expected to happen in phases, gradually covering passenger vehicles, commercial vehicles, goods carriers, and any vehicle equipped with ECUs or higher-level automation. OTA-enabled cars are also expected to fall under this framework as adoption increases over the coming years.
What This Means for Buyers
For everyday car owners, this development brings some clear advantages:
Stronger digital protection – Cars will be built with tighter safeguards against hacking and malware from day one.
Safer connected features – Things like digital keys, remote start, and mobile app controls will come with better underlying security.
More reliable updates – OTA software updates will follow verified, authenticated channels, reducing the risk of corrupted or malicious updates.
Quicker security responses – If a vulnerability does surface, manufacturers will be required to patch it faster through structured response systems.
Greater buyer confidence – As vehicles become more software-dependent, cybersecurity will start mattering as much as airbags or crash ratings.
The Trade-Off to Consider

Naturally, none of this comes without a cost. Manufacturers will need to invest more in secure software development, ongoing testing, and long-term monitoring systems, and some of that expense could eventually be passed on to buyers through a modest price increase. That said, most industry experts see this as a small trade-off compared to the long-term benefit of safer, more reliable vehicles.
What Buyers Should Ask Before Purchasing
As connected features become standard, it’s worth asking a few practical questions before buying your next car:
- Does the vehicle support OTA software updates?
- How long will the manufacturer continue providing software support?
- Is the companion app updated regularly?
- Does the brand have a clear cybersecurity policy?
- How frequently are security patches released?
The Road Ahead
India’s move toward structured vehicle cybersecurity rules through AIS-189 and AIS-190 marks an important shift in how we think about car safety. It’s no longer just about surviving a crash; it’s about protecting the software that now runs almost every part of the vehicle. As cars continue evolving into intelligent, connected platforms, cybersecurity is quickly becoming just as essential as seatbelts and airbags in defining what “safe” really means.
Rajababu Kushwaha is the Founder and Editor of AutoCrest. He covers the latest car news, reviews, comparisons, EV updates, and buying guides for Indian car buyers.