158. Cybersecurity Risks Of Ai Systems
158. Cybersecurity Risks of AI Systems – Detailed Explanation With Case Laws
1. Meaning
Cybersecurity risks of AI systems means the dangers created when Artificial Intelligence (AI) systems are attacked, manipulated, misused or used to attack other systems.
AI is increasingly used in:
Smart grids
Electricity demand forecasting
Energy trading
Smart meters
Nuclear facilities
Renewable-energy management
Banking and financial systems
Transport and smart cities
Because AI depends on data, software, networks and algorithms, a cyberattack can create serious legal and economic consequences.
2. Major Cybersecurity Risks
1. Data Poisoning
Attackers may put false or harmful information into AI training data.
Example: If false electricity-demand data is entered, an AI system may incorrectly predict electricity requirements.
2. Hacking of AI Systems
Hackers may obtain unauthorised access and change AI outputs.
Example: An attacker could manipulate an AI-controlled electricity system and cause incorrect power distribution.
3. Adversarial Attacks
An attacker gives specially designed input to confuse an AI system.
Example: A small change in sensor information may cause an AI system to wrongly identify a fault.
4. Privacy Risk
AI systems can process large amounts of personal information.
Smart electricity systems may reveal:
When a person is at home
Electricity-use habits
Appliance usage
Behavioural patterns
Therefore, privacy can be affected.
5. Automated Decisions
AI may automatically make decisions such as detecting electricity theft or identifying suspicious transactions.
The problem arises when the AI makes a wrong decision and there is no human review.
3. Legal Framework in India
Information Technology Act, 2000
The IT Act provides the basic legal framework for various forms of cyber offences and unauthorised access.
Digital Personal Data Protection Act, 2023
Where AI systems process digital personal data, data-protection obligations become important.
Article 21 of Constitution
Article 21 protects life and personal liberty and has been interpreted to include the right to privacy.
Article 14
AI-based government decisions should not be arbitrary or discriminatory.
4. Important Case Laws
1. K.S. Puttaswamy v. Union of India (2017)
The Supreme Court recognised privacy as a fundamental right under the Constitution.
Relevance to AI
AI systems collect and analyse huge quantities of personal data. Therefore:
AI data collection → privacy risk → constitutional protection
AI systems must have a legitimate purpose and appropriate safeguards.
2. K.S. Puttaswamy v. Union of India (2018)
The Court considered privacy, data protection and proportionality in the Aadhaar context.
Relevance
Government use of AI involving personal data should satisfy principles such as:
Legality
Legitimate purpose
Necessity
Proportionality
Safeguards
3. Shreya Singhal v. Union of India (2015)
The Supreme Court examined provisions of the Information Technology Act and constitutional protection of online speech.
Relevance
Digital technologies must operate within constitutional limits. AI systems used for online monitoring or content decisions should therefore be subject to lawful authority and constitutional safeguards.
4. Anuradha Bhasin v. Union of India (2020)
The Supreme Court examined restrictions affecting internet access and emphasised legality and proportionality.
Relevance
Modern AI systems often depend on digital networks. Government restrictions or cybersecurity measures affecting digital systems should have a proper legal basis and must be proportionate.
5. AI in Energy Systems
Cybersecurity becomes especially important when AI controls critical energy infrastructure.
For example:
AI system → Smart grid → Electricity distribution
If hackers manipulate the AI system, consequences may include:
Wrong electricity forecasting
Grid instability
Incorrect billing
Electricity shortages
Damage to infrastructure
Consumer financial loss
Therefore, AI cybersecurity is also an energy-security issue.
6. Responsibility for AI Cyberattacks
A difficult question is:
Who is legally responsible if an AI system is hacked?
Possible parties include:
AI developer
Energy company
Software provider
Cloud-service provider
Cybersecurity contractor
Government regulator
System operator
Responsibility depends on the contract, applicable legislation, negligence, security obligations and actual cause of the damage.
7. Important Safeguards
AI systems should use:
Strong authentication
Encryption
Regular security testing
Continuous monitoring
Secure software development
Data-quality controls
Human supervision
Incident-response plans
Audit trails
Regular updating of AI models
For critical infrastructure, AI should not be allowed to operate without appropriate human and regulatory oversight.
8. Main Legal Principle
A useful approach is:
AI decision → cybersecurity check → human verification → legal review → action
Instead of:
AI decision → automatic action
This is particularly important where an AI error can affect electricity supply, financial rights, privacy or public safety.
9. Conclusion
Cybersecurity risks of AI systems are becoming increasingly important because AI is being connected with critical infrastructure, personal data and financial systems.
The main risks include hacking, data poisoning, adversarial attacks, privacy violations, manipulation of algorithms and incorrect automated decisions.
Indian constitutional law, the IT framework and data-protection law provide important safeguards. The principles developed in Puttaswamy, Shreya Singhal and Anuradha Bhasin are useful for ensuring that AI systems respect privacy, legality and proportionality.
Direct Supreme Court case law specifically dealing with cybersecurity attacks on AI systems is still limited. Therefore, existing constitutional and cyber-law cases are mainly used for broader legal principles.
Exam Line
“Cybersecurity regulation of AI systems seeks to prevent hacking, data manipulation, privacy violations and harmful automated decisions while ensuring that AI remains secure, transparent, accountable and subject to human and legal oversight.”

comments