CURRENT AFFAIRS | 23 APRIL 2026
Reports of unauthorised access to Anthropic’s Mythos model — a defensive cybersecurity AI — through a vendor compromise dubbed Project Glasswing have re-opened the global debate on model-weights security, AI governance, and the adequacy of existing data-protection law. For India, the incident is a timely prompt to revisit the Digital Personal Data Protection Act, 2023 (DPDP), the IT Act, and emerging AI regulation parallels.
Constitutional & Statutory Framework
- Article 21 — Right to Privacy as a Fundamental Right (Puttaswamy v UoI, 2017) — source of all data-protection jurisprudence.
- Article 19(1)(a) — Freedom of speech; AI-generated content, intermediary liability, and deepfakes sit here.
- DPDP Act 2023 — Data Principal rights, Data Fiduciary duties, cross-border transfer rules; Data Protection Board of India.
- IT Act 2000 — Section 43A (compensation for data protection failure); Section 66 (computer-related offences); Section 79 (intermediary safe harbour, Shreya Singhal).
- Bharatiya Nyaya Sanhita (BNS) 2023 — replaced IPC; retains identity-theft and cyber-fraud sections.
- MeitY Advisory (March 2024) — GenAI labelling and bias testing.
- India AI Mission 2024 — Rs 10,372 crore over 5 years (compute, datasets, innovation centres, safety).
CLAT Angle: Tech Law is the New Con Law
AI regulation is a first-order CLAT 2027 topic. Expect: Legal Reasoning on the “reasonable security practices” test under s.43A; Current Affairs MCQ on the Rs 10,372 cr figure; Polity on the scope of Art 21 privacy.
Global Parallels & Cases
| Regulation / Case | Core Rule |
|---|---|
| EU AI Act 2024 | Risk-based tiers: unacceptable / high / limited / minimal |
| Puttaswamy v UoI (2017) | Privacy is intrinsic to Art 21; proportionality test |
| Shreya Singhal v UoI (2015) | S.66A IT Act struck down for vagueness; intermediary safe harbour refined |
| Anuradha Bhasin v UoI (2020) | Proportionality test for internet shutdowns; reasoned orders mandatory |
| US Biden AI EO (2023, now expired) | Mandatory safety testing for frontier models; Trump admin rescinded |
Mnemonic: “DPDP = D3P”
Data Principal rights · Data Fiduciary duties · Data Protection Board · Penalties up to Rs 250 cr
Puttaswamy is always the first citation. 43A = data compensation. 66A = struck down.
Practice Quiz — Test Your Mastery
Practice Quiz — 10 CLAT-Style Questions
Click an option to reveal the answer and explanation.