Digital Law Weekly Tracker: W33 2026 — TRAI Extends the Verified Calling Regime Beyond BFSI with the 1601 Numbering Series, DoT Warns Handset Sellers on IMEI Registration and Tampering, CERT-In Issues Apple Threat Notifications Advisory

Weekly Tracker cross-pillar 10 Aug 2026 Status: published
2026-W33
2026-08-10 to 2026-08-16
TL;DR

India's digital-law week of 10 to 16 August 2026 is anchored by TRAI's Direction of 10 August 2026 on allocation and operationalisation of the 1601 numbering series for service and transactional voice calls by entities in sectors other than BFSI and Government, issued under the Telecom Commercial Communications Customer Preference Regulations, 2018 — extending India's verified-calling architecture beyond the 1600-series BFSI cohort to utilities, courier and logistics entities on a phase-wise basis (Press Release No. 113). On 12 August the Department of Telecommunications cautioned manufacturers, importers and resellers on mandatory IMEI registration and the consequences of IMEI tampering under the Telecommunications Act, 2023. CERT-In issued advisory CIAD-2026-0039 on Apple Threat Notifications on 14 August and CIAD-2026-0038 on Microsoft product vulnerabilities on 12 August, alongside thirteen vulnerability notes including a remote-code-execution flaw in the Langflow open-source AI orchestration framework. SEBI modified the Online Bond Platform Provider framework on 14 August. The RBI data-governance consultation closes 17 August 2026.

Veritect
Veritect Legal Intelligence
Legal Intelligence Agent
21 min read
Continue with Veritect

Search the gazette text behind every digital-law update.

Try Veritect free Book a demo

India's digital-law week of 10 to 16 August 2026 extended the country's verified-calling regime beyond finance. On 10 August TRAI issued a Direction on allocation and operationalisation of the 1601 numbering series for service and transactional voice calls by entities in sectors other than BFSI and Government, under the Telecom Commercial Communications Customer Preference Regulations, 2018, with phase-wise implementation starting for utilities, courier and logistics entities. On 12 August the Department of Telecommunications cautioned handset manufacturers, importers and resellers on mandatory IMEI registration and the consequences of IMEI tampering. CERT-In issued CIAD-2026-0039 on Apple Threat Notifications (14 August) and recorded a remote code execution flaw in the Langflow AI orchestration framework (CIVN-2026-0407, 12 August), a month after the 60-day CERT-In AI Blueprint roadmap under CISG-2026-02 closed on 24 July 2026 for entities that began on the 25 May issue date.


At a Glance — W33 Scoreboard

# Pillar Development Issuer Date Score
1 telecom-emerging Direction on allocation and operationalisation of the 1601 numbering series for service and transactional voice calls outside BFSI and Government, under TCCCPR 2018; phase-wise start for utilities, courier and logistics (PR No. 113) TRAI 10 Aug 2026 12
2 telecom-emerging Caution to handset manufacturers, importers and resellers on mandatory IMEI registration and consequences of IMEI tampering DoT 12 Aug 2026 9
3 cybersecurity CIAD-2026-0039 — Apple Threat Notifications; CIAD-2026-0038 — multiple vulnerabilities in Microsoft products CERT-In 12–14 Aug 2026 9
4 ai-governance CIVN-2026-0407 — remote code execution in Langflow OSS AI orchestration framework; lands after the AI Blueprint 60-day roadmap closed on 24 Jul 2026 — a test of the Phase 2 Step 6 AI inventory CERT-In 12 Aug 2026 8
5 platforms-intermediaries Modification of the Online Bond Platform Provider (OBPP) regulatory framework, including ease-of-doing-business measures SEBI 14 Aug 2026 7
6 cybersecurity CIVN-2026-0398 to 0410 — macOS auth bypass, Veeam, cPanel/WHM, TeamCity RCE, Cisco IMC, Microsoft, Drupal, Kemp LoadMaster, ClamAV, WordPress, Metabase, Chrome CERT-In 10–14 Aug 2026 6
7 fintech-payments Draft Guidance on Regulatory Expectations for Data Governance — final week; comments close 17 Aug 2026 RBI 16 Aug 2026 6
8 data-protection DPBI — no Tier 1 notification of Section 18(1) constitution traced; Rule 4 consent-manager registration expected ~Nov 2026 MeitY 16 Aug 2026 5

TL;DR for Founders

Three things to act on this week:

  1. If you make outbound service or transactional calls in utilities, courier or logistics: the 1601 numbering series direction of 10 August starts a phase-wise migration for your sector. Treat it as a dated project. Migrate numbering and fix consent, template and preference-scrubbing hygiene under TCCCPR 2018 in the same workstream — moving the number without fixing consent moves the problem.

  2. If you import, manufacture, refurbish or resell handsets: DoT's 12 August caution on IMEI registration and tampering puts identifier provenance on the seller. If you cannot evidence registration per unit, or you source refurbished stock without identifier history, the exposure is yours under the Telecommunications Act, 2023.

  3. If you run any LLM or agent stack: the Langflow remote code execution note (CIVN-2026-0407, 12 August) is a reminder that the orchestration layer holds your credentials and tool integrations. The CERT-In AI Blueprint 60-day roadmap under CISG-2026-02 closed on 24 July 2026 for 25-May starters, so the question a supervisor asks now is whether the Phase 2 Step 6 AI/ML system inventory exists and whether it covers orchestration frameworks. You cannot assess what you have not inventoried.


Top 3 Developments

1. Who Must Adopt the 1601 Numbering Series, and What Does Verified Calling Change Outside BFSI? (Telecom-Emerging / Platforms)

What changed: On 10 August 2026 TRAI issued a Direction on Allocation and operationalization of 1601 numbering series for Service and Transactional Voice Calls by entities in sectors other than BFSI and Government sector, under TCCCPR, 2018, from the Authority's Quality of Service division. By Press Release No. 113 of the same date, TRAI initiated phase-wise implementation of the 1601-series for service and transactional calls by utilities, courier and logistics sector entities.

Context: The design was established with the 1600 numbering series, assigned by the Department of Telecommunications for allocation to Banking, Financial Services and Insurance entities and Government organisations, so that a consumer could distinguish a genuine service or transactional call from other commercial communication. TRAI has rolled that mandate out sector by sector — a direction on phase-wise mandatory adoption by RBI, SEBI and PFRDA regulated entities, with commercial banks including public sector, private sector and foreign banks onboarding by 1 January 2026 and mutual funds and asset management companies by 15 February 2026; and a direction of 16 December 2025 requiring IRDAI-regulated entities to adopt the series by 15 February 2026. Roughly 485 entities had adopted the 1600 series across more than 2,800 numbers.

Why it matters: The 1601 Direction is the point at which verified calling stops being a financial-sector control and becomes general infrastructure. Three consequences follow for businesses outside BFSI. Evidential — once a sector is inside the mandate, a service call placed from an ordinary ten-digit mobile number becomes anomalous, which matters when a customer later disputes that a call originated from the business or when a fraud complaint alleges impersonation. Regulatory — the series sits inside the TCCCPR 2018 machinery, so migration touches sender registration, consent records, preference-register scrubbing and the resource-barring mechanism TRAI uses against unsolicited commercial communication. Sequencing — the Telecom Commercial Communications Customer Preference (Third Amendment) Regulations, 2026 remain under finalisation after the Open House Discussion of 17 July 2026, carrying AI-based UCC detection, 15-day resource barring and a 7-day consent window. A business that migrates numbering in Q3 and rebuilds consent architecture in Q1 next year will do the work twice.

Practitioner takeaway: Identify whether each client entity falls inside the first phase (utilities, courier, logistics) or a later one, and obtain the phase date from the Direction text rather than from the press release. Then run numbering migration, consent-record remediation and template registration as one programme. For platforms that place calls on behalf of principals, allocate contractual responsibility for series adoption and consent provenance explicitly — the regulatory exposure and the commercial relationship do not sit with the same party by default.

Link: TRAI — Directions | TRAI — Press Releases

Score: 12/15.


2. Why Is DoT Warning Handset Sellers About IMEI Registration and Tampering? (Telecom-Emerging / Cybersecurity)

What changed: On 12 August 2026 the Department of Telecommunications issued a press release cautioning mobile handset manufacturers, importers and resellers about mandatory IMEI registration and the consequences of IMEI tampering.

Why it matters: The International Mobile Equipment Identity is the load-bearing identifier for several Indian control regimes at once. It is the key on which the Central Equipment Identity Register operates when a citizen blocks a lost or stolen handset through the Sanchar Saathi platform. It is a correlation key for the Digital Intelligence Platform through which DoT coordinates with law enforcement, financial-sector entities and telecom service providers against misuse of telecom resources in cybercrime and financial fraud. And under the Telecommunications Act, 2023 (Act 44 of 2023) tampering with a unique telecommunication identifier — and dealing in devices carrying tampered identifiers — sits inside the statutory offence and penalty structure, in addition to exposure under general criminal law.

The commercial exposure runs down the distribution chain rather than up it. An importer or reseller that cannot evidence registration for each unit, or that sources refurbished or grey-market stock without identifier provenance, carries the risk directly — and increasingly visibly, because the identifier is checkable against a central register rather than dependent on inspection. Two adjacent items make this a live operational question rather than a background one. First, the Government's decision not to make Sanchar Saathi pre-installation mandatory for manufacturers — following the directions of 28 November 2025 requiring manufacturers and importers to facilitate availability and accessibility of the app, subsequently rolled back — signals that DoT's device-side lever is shifting from mandated software toward identifier enforcement. Second, the Reserve Bank's device-restriction rule effective 1 January 2027 assumes a stable, registered device identity: a financed handset with a tampered identifier undermines both the lender's control and the borrower's protections.

Practitioner takeaway: For device businesses, treat IMEI provenance as a supply-chain control with documentary evidence per unit, not as a compliance statement. For device-financing lenders, add identifier verification at origination. For marketplaces, review seller-onboarding terms and takedown processes for listings without verifiable identifier provenance.

Link: DoT — Telecom eServices Portal | DoT — Acts and Policies

Score: 9/15.


3. Apple Threat Notifications, the Microsoft Patch Cycle and a Remote Code Execution Flaw in the AI Orchestration Layer (Cybersecurity / AI-Governance)

What changed: Three CERT-In items in one week. Advisory CIAD-2026-0039 of 14 August 2026 on Apple Threat Notifications. Advisory CIAD-2026-0038 of 12 August 2026 on multiple vulnerabilities in Microsoft products. And Vulnerability Note CIVN-2026-0407 of 12 August 2026 recording a remote code execution vulnerability in Langflow OSS, an open-source framework for building large-language-model and agent workflows — one of thirteen vulnerability notes (CIVN-2026-0398 to 0410) issued between 10 and 14 August.

Why the Apple advisory matters: Apple Threat Notifications are directed at individuals whose devices are assessed as having been targeted by sophisticated, highly targeted intrusion rather than ordinary cybercrime. That routing is the compliance problem: the notification arrives to the person, not to the security function. For an organisation, a targeted-compromise notification on a device used for work can be the first signal of an incident within the reporting categories under the CERT-In Directions of 28 April 2022 issued under Section 70B of the Information Technology Act, 2000, which run on a six-hour clock. For a Reserve Bank-regulated entity, a confirmed compromise of a device with access to entity systems also engages the six-hour DAKSH report under the entity-wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 of 31 July 2026, measured from detection. Very few incident-response plans currently define an intake path for a notification that lands on an employee's personal Apple ID.

Why the Langflow note matters: Remote code execution in an AI orchestration layer is a different class of risk from model misbehaviour. Orchestration frameworks hold API credentials, retrieval connections to internal data stores and tool integrations that reach production systems — so an RCE there is a lateral-movement primitive, not a content problem. The governance frame is inventory, not a live deadline. Advisory CISG-2026-02 of 25 May 2026 prescribes a three-phase, 60-day roadmap: Phase 2 (Days 8–30) Step 6 requires an AI/ML system inventory capturing training-data provenance, inference environment and access controls, and drift monitoring per model — an artefact CERT-In notes also discharges the AI-risk-assessment requirement under SEBI CSCRF (2024) and the RBI IT Governance Master Direction (2023) — while Phase 3 (Days 31–60) is red-team exercises across the five key threat areas at Section 4.1 to 4.5 plus adversarial AI simulations with model-integrity validation. For an entity starting on the issue date, Day 60 fell on 24 July 2026.

Correction (29 August 2026): this section as originally published stated that Phase 3 closed on 23 August 2026 and described Phase 3 as an external AI supply-chain assessment. Neither is supported by CISG-2026-02. The correct position is the 60-day roadmap set out above, with Day 60 at 24 July 2026 for 25-May starters and Phase 3 consisting of red-teaming and adversarial AI simulation. The compliance deliverables are unchanged; only the date and the characterisation were wrong. Readers who treated 23 August as an open window should note it had in fact closed a month earlier.

An organisation that cannot enumerate the orchestration frameworks, model-serving components and agent libraries running in its estate cannot complete the Step 6 inventory. The same inventory demand is arriving from the financial-sector side: the Reserve Bank's draft Guidance on Regulatory Principles for Model Risk Management (Press Release 2026-2027/528, comments closed 24 July 2026) requires a comprehensive inventory of active, inactive, under-development and retired models expressly covering AI/ML, generative-AI and third-party models.

Practitioner takeaway: Write a targeted-notification intake path into the incident-response plan, with a named owner and a defined escalation to both the CERT-In and DAKSH filing decisions. Separately, build the AI component inventory now — it is the common prerequisite for CERT-In AI Blueprint Phase 3, for RBI model-risk governance, and for answering a customer's AI due-diligence questionnaire.

Link: CERT-In — Advisories 2026 | CERT-In — Vulnerability Notes 2026

Score: 9/15.


Beyond this Brief Preview — Veritect Legal AI

The full text and phase schedule of the 10 August 2026 TRAI 1601-series Direction, the complete 1600-series direction chain across RBI, SEBI, PFRDA and IRDAI regulated entities, the TCCCPR 2018 enforcement architecture with the pending Third Amendment package, and the CERT-In AI Blueprint CISG-2026-02 three-phase control mapping against RBI model-risk governance are available in Veritect Legal AI.


Regulatory Action Log — Items 4-8

Date Regulator Pillar Action Source
14 Aug 2026 SEBI platforms-intermediaries Modification in the regulatory framework for Online Bond Platform Providers (OBPPs) including measures for promoting ease of doing business — the framework governing digital platforms through which listed debt securities are offered to non-institutional investors sebi.gov.in
11–12 Aug 2026 SEBI platforms-intermediaries Amendment to the SEBI (Issue and Listing of Municipal Debt Securities) Regulations, 2015 (11 Aug); Review of Inclusion of Historical Scenarios in Stress Testing for the Commodity Derivatives Segment (12 Aug) sebi.gov.in
10–14 Aug 2026 CERT-In cybersecurity Vulnerability Notes CIVN-2026-0398 (Apple macOS authentication bypass), 0399 (Veeam Service Provider Console), 0400 (cPanel and WHM privilege escalation), 0401 (JetBrains TeamCity RCE), 0402 (Cisco Integrated Management Controller), 0403 (Microsoft products), 0404 (Drupal plugins), 0405 (Progress Kemp LoadMaster), 0406 (ClamAV), 0408 (WordPress XSS), 0409 (Metabase SQL injection), 0410 (Google Chrome for Desktop). The TeamCity and cPanel entries reach build and hosting infrastructure — credential-bearing systems where a compromise propagates cert-in.org.in
16 Aug 2026 RBI fintech-payments Final week of the draft Guidance on Regulatory Expectations for Data Governance consultation (Press Release 2026-2027/677); comments close 17 August 2026 to dor.datagovfed@rbi.org.in, addressed to the Chief General Manager, Operational Risk Group, Department of Regulation, Central Office, Mumbai 400 001 rbi.org.in
14 Aug 2026 TRAI telecom-emerging Press Release No. 114 — Independent Drive Test assessments across Shimla and nearby areas and Solan and nearby areas, continuing the 2026 quality-of-service measurement programme that underpins the 5 August consultation paper on the Quality of Service Regulations, 2024 trai.gov.in

Veritect daily-news cross-check: Veritect's daily-news output for 10-16 August 2026 carried no technology-law items for this window. No duplication with this tracker.


What's Next

  • 17 August 2026RBI data-governance consultation closes. Last day to comment on the Data Function at not below Chief General Manager rank, the Data Owner / Data Steward / Data Custodian roles, and the metadata, lineage, quality and third-party data-sharing expectations across 11 regulated-entity categories.
  • Already closed — 24 July 2026 — the CERT-In AI Blueprint 60-day roadmap under CISG-2026-02 reached Day 60 for 25-May starters. Phase 3 (Days 31–60) was red-team exercises and adversarial AI simulations with model-integrity validation. Corrected 29 August 2026: this edition originally listed a 23 August 2026 Phase 3 close and an external AI supply-chain assessment.
  • ~August–September 20261601-series phase dates for utilities, courier and logistics entities begin to bite; watch for sector-specific follow-on directions on the 1600 and 1601 series, as TRAI has issued these regulator by regulator.
  • ~August–September 2026first OGAI Rule 10 determination orders and online-register entries under the Promotion and Regulation of Online Gaming Rules, 2026 (G.S.R. 303(E), 22 April 2026).
  • Q3–Q4 2026TRAI TCCCPR (Third Amendment) Regulations, 2026 final notification post-Open House, in force thirty days after Gazette publication; RBI final Model Risk Management guidance following the 24 July consultation close; DoT authorisation transition mechanics and any clarification on the Rule 25(3) localisation perimeter under the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026.
  • ~November 2026DPDP consent-manager registration window opens under Rule 4 of the Digital Personal Data Protection Rules, 2025; RBI Q-SAFE quantum-safe roadmap due.
  • 1 January 2027Responsible Business Conduct Fourth Amendment Directions, 2026 take effect (device-restriction gating, Rs 250-per-hour compensation, IIBF-certified recovery agents, 08:00-19:00 contact window), alongside the RBI Customer Liability Amendment Directions (Rs 500 SMS alert threshold, 45/60-day fraud investigation, five-day credit-card shadow reversal).
  • ~13 May 2027 — end of the 18-month DPDP phased-compliance runway.

Founder Action Items

  • Find your 1601-series phase date in the Direction text, not the press release. If you are in utilities, courier or logistics and you place outbound service or transactional voice calls, this is a dated migration. Run it together with consent-record remediation, template registration and preference scrubbing under TCCCPR 2018.
  • If you place calls through a vendor, allocate the obligation in writing. Series adoption, sender registration and consent provenance are separate duties that do not attach to the same party by default in a call-centre or communications-platform arrangement.
  • Put IMEI provenance into supplier and marketplace terms. Evidence registration per unit, refuse refurbished stock without identifier history, and verify identifiers at origination if you finance devices — the Reserve Bank's device-restriction regime from 1 January 2027 assumes a stable registered identity.
  • Write a targeted-notification intake path into your incident-response plan. Apple Threat Notifications (CIAD-2026-0039) arrive to individuals. Name the owner, define the escalation, and pre-decide who makes the Section 70B and DAKSH filing calls under the six-hour clocks.
  • Inventory your AI stack — the roadmap has already closed. CERT-In AI Blueprint Step 6 (Phase 2, Days 8–30) requires an AI/ML system inventory, and the 60-day roadmap reached Day 60 on 24 July 2026 for 25-May starters. The Langflow remote code execution note (CIVN-2026-0407) shows why the orchestration layer belongs in scope, not just the model.
  • Patch build and hosting infrastructure first from this week's cluster. JetBrains TeamCity remote code execution (CIVN-2026-0401) and cPanel and WHM privilege escalation (CIVN-2026-0400) sit on credential-bearing systems from which compromise propagates; Chrome (0410) and Microsoft (0403, CIAD-2026-0038) cover the endpoint estate.
  • Submit on the RBI data-governance draft today if you have not. Comments close 17 August 2026.

Practitioner Watch-List

  • 1601-series phase schedule and sectoral follow-ons. Obtain the Direction text for the phase table and the compliance-reporting mechanism. Expect the same sector-by-sector pattern TRAI used for the 1600 series, where separate directions were issued for RBI, SEBI and PFRDA regulated entities and then for IRDAI-regulated entities. Advise clients to secure numbering allocations early; the 1600 rollout showed adoption bunching against deadlines.
  • IMEI enforcement as a distribution-chain risk. Watch for follow-on DoT instructions specifying registration mechanics and for the interaction with the Central Equipment Identity Register and Digital Intelligence Platform. The shift away from mandated Sanchar Saathi pre-installation toward identifier enforcement is a directional signal worth tracking in device-sector advice.
  • Targeted-intrusion notifications and reporting duties. The unresolved question for Indian practice is when a threat notification, without confirmed compromise, becomes a reportable incident under Section 70B of the Information Technology Act, 2000 and the CERT-In Directions of 28 April 2022. Advise a documented triage standard with a bias to early engagement, and preserve the device forensically before wiping — the reflex to reimage destroys the evidence on which the reporting decision depends.
  • AI supply-chain assurance converging from three directions. The CERT-In AI Blueprint Step 6 inventory (60-day roadmap closed 24 July 2026), the Reserve Bank's pending Model Risk Management guidance with its third-party-model strand, and customer due-diligence questionnaires are all asking for the same artefact — a maintained inventory of AI components with owners, versions and external dependencies. Build it once.
  • DPBI constitution and consent-manager readiness. No Tier 1 notification constituting the Data Protection Board of India under Section 18(1) of the Digital Personal Data Protection Act, 2023 was traced as at 16 August 2026; the Rule 17 Search-cum-Selection process under the DPDP Rules, 2025 continues, with composition fixed at a Chairperson plus four Members by G.S.R. 845(E). Consent-manager registration under Rule 4 is expected to open around November 2026. Confirm Board status against the Official Gazette before asserting it in a filing or client note.

FAQ

Who has to move to the 1601 numbering series and by when?

TRAI's Direction of 10 August 2026 covers service and transactional voice calls by entities in sectors other than BFSI and Government, issued under the Telecom Commercial Communications Customer Preference Regulations, 2018. Press Release No. 113 of the same date initiates phase-wise implementation for utilities, courier and logistics sector entities. The phase dates are in the Direction, not the press release, and should be read from the notified text. The architecture mirrors the 1600 series, assigned by DoT for BFSI entities and Government organisations, which TRAI mandated regulator by regulator — commercial banks by 1 January 2026, mutual funds and asset management companies by 15 February 2026, and IRDAI-regulated entities by 15 February 2026 under a direction of 16 December 2025. Around 485 entities had adopted the 1600 series across more than 2,800 numbers.

Under the Telecommunications Act, 2023 (Act 44 of 2023), tampering with a unique telecommunication identifier and dealing in devices carrying tampered identifiers fall inside the statutory offence and penalty structure, alongside exposure under general criminal law. The International Mobile Equipment Identity underpins the Central Equipment Identity Register used through the Sanchar Saathi platform to block lost and stolen handsets, and is a correlation key for DoT's Digital Intelligence Platform for coordination against misuse of telecom resources in cybercrime and financial fraud. The Department's press release of 12 August 2026 cautioned manufacturers, importers and resellers on mandatory registration and the consequences of tampering — a signal that enforcement is moving toward the distribution chain, where identifier provenance is documentable per unit.

Does receiving an Apple Threat Notification trigger a CERT-In report?

Not automatically — the reporting duty under Section 70B(6) of the Information Technology Act, 2000 read with the CERT-In Directions of 28 April 2022 attaches to the occurrence of a listed cyber incident, on a six-hour clock from noticing it. A threat notification is an indicator, not by itself a confirmed incident. But where the device is used for work and triage indicates compromise, the incident categories are readily engaged, and for a Reserve Bank-regulated entity a confirmed compromise of a device with system access also engages the six-hour DAKSH report under the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 of 31 July 2026, measured from detection. CERT-In's advisory CIAD-2026-0039 of 14 August 2026 makes this a live operational question. Two practical points: define an intake path, because these notifications reach the individual rather than the security team; and preserve the device forensically before reimaging.

Why is a Langflow vulnerability an AI-governance item and not just a patch?

Because AI orchestration frameworks hold the credentials, retrieval connections and tool integrations that reach production systems, so a remote code execution flaw there is a lateral-movement primitive rather than a model-quality defect. CERT-In recorded the issue as CIVN-2026-0407 on 12 August 2026. The governance link is inventory: Step 6 of advisory CISG-2026-02 of 25 May 2026 (Phase 2, Days 8–30) requires an AI/ML system inventory, and Phase 3 (Days 31–60) is red-team exercises and adversarial AI simulations with model-integrity validation — neither of which is possible without an enumeration of orchestration frameworks, model-serving components and agent libraries in the estate. The 60-day roadmap reached Day 60 on 24 July 2026 for entities that began on the issue date. (Corrected 29 August 2026: this answer originally stated a 23 August 2026 Phase 3 close and described Phase 3 as an external AI supply-chain assessment.) The Reserve Bank's draft Guidance on Regulatory Principles for Model Risk Management (Press Release 2026-2027/528) makes the same demand from the financial-sector side, requiring a comprehensive model inventory covering AI/ML, generative-AI and third-party models irrespective of whether the entity itself treats the artefact as a model.

What changed for Online Bond Platform Providers on 14 August 2026?

SEBI issued a circular titled Modification in the regulatory framework for Online Bond Platform Providers (OBPPs) including measures for promoting ease of doing business on 14 August 2026. The OBPP framework governs digital platforms through which listed debt securities are offered to non-institutional investors — a regulated-intermediary category defined by the fact that the distribution happens through an online interface. For digital-law purposes the significance is that SEBI continues to regulate the platform layer of securities distribution as a discrete licensed activity rather than through the issuer or the broker alone, and any modification changes onboarding, disclosure and interface obligations for platform operators. Read alongside SEBI's circular of 31 July 2026 extending Digital Accessibility compliance timelines and the 3 August 2026 extension of the PaRRVA enrolment timeline for verified performance claims, the direction of travel is consistent: interface-level obligations on SEBI-regulated digital platforms are expanding, with timelines being paced.


Primary Sources

Tier 1 sources only: TRAI (trai.gov.in), DoT (dot.gov.in, eservices.dot.gov.in), CERT-In (cert-in.org.in), SEBI (sebi.gov.in), RBI (rbi.org.in), MeitY (meity.gov.in), eGazette (egazette.gov.in). All developments reported as of 16 August 2026 unless stated. Items flagged 'expected' or 'due' carry that qualifier explicitly. DoT items are recorded as displayed on the Department's portals; confirm gazette citations against the Official Gazette before citing in filings. Where a Tier 1 source did not confirm a status — notably the constitution of the Data Protection Board of India and the publication of OGAI determination orders — that is recorded as an absence of confirmation rather than inferred either way. Reconfirm against primary-source URLs before acting.

Beyond this Brief Preview — Veritect Legal AI

Veritect Legal AI carries the research-grade layer behind this tracker: the full 1600 and 1601 numbering-series direction chain with sector-wise phase tables, the TCCCPR 2018 enforcement architecture and pending Third Amendment package, device-identifier obligations under the Telecommunications Act, 2023 with the Central Equipment Identity Register and Digital Intelligence Platform interfaces, and the CERT-In AI Blueprint CISG-2026-02 three-phase control mapping read against RBI model-risk and data-governance expectations.

Next edition: W34 tracker covering 17-23 August 2026 — the close of the RBI data-governance consultation on 17 August, first OGAI Rule 10 determination orders if published, and further 1601-series and DoT authorisation-portal developments.


Corrections

29 August 2026 — This edition originally recorded that Phase 3 of the CERT-In AI Blueprint (advisory CISG-2026-02, 25 May 2026) "closes on 23 August 2026" for organisations that began the 60-day implementation on the issue date, and described Phase 3 as an "external AI supply-chain assessment and board reporting" phase. Neither statement is supported by the advisory. CISG-2026-02 prescribes a three-phase, 60-day roadmap — Phase 1 Days 1–7, Phase 2 Days 8–30, Phase 3 Days 31–60 — with Phase 3 comprising Step 8 (red-team exercises built around the five key threat areas at Section 4.1 to 4.5) and Step 9 (adversarial AI simulations and model-integrity validation per model, with board or audit-committee reporting where the model operates in a regulated context). For an entity commencing on 25 May 2026, Day 60 fell on 24 July 2026. The error was identified while compiling the W34 tracker and is corrected at every occurrence in this file: the ai_summary-adjacent item entry, the FAQ, the opening BLUF, the scoreboard, the founder TL;DR, Development 3, the What's Next list, the Founder Action Items and the Practitioner Watch-List. The compliance deliverables described in this edition are unchanged; only the date and the characterisation of Phase 3 were wrong. Because the error pointed in the direction of telling a reader a window was still open when it had closed a month earlier, it is recorded here rather than silently amended.

5 September 2026 — CERT-In AI Blueprint threat taxonomy. This edition described Phase 3 of CISG-2026-02 as red-team exercises built around the advisory's nine AI-threat categories. The advisory has no nine-category threat taxonomy. Section 4 sets out five key threat areas — 4.1 AI-Enabled Reconnaissance and Vulnerability Exploitation, 4.2 AI-Driven Phishing, Impersonation, and Social Engineering, 4.3 AI-Generated Malware and Automated Attack Operations, 4.4 Adversarial Threats Against AI Systems, 4.5 Risks to Vital Infrastructure and Digital Ecosystems — with 4.6 a forward-looking note rather than a sixth area. The nine-item list in the advisory's Executive Summary enumerates the framework's defensive coverage areas, not threats. Red-team scenarios map to the five Section 4 areas. Corrected at every occurrence in this file. The Phase 3 timing stated in this edition (Days 31–60, Day 60 falling on 24 July 2026 for 25-May starters) is unaffected and remains correct.

Primary source

Title: Direction on Allocation and operationalization of 1601 numbering series for Service and Transactional Voice Calls by entities in sectors other than BFSI and Government sector, under TCCCPR, 2018 (10 August 2026)
Issuer: Telecom Regulatory Authority of India
Effective: 2026-08-10

Frequently asked

What is the 1601 numbering series and who has to adopt it?

The 1601 series is the next phase of India's verified-calling architecture. On 10 August 2026 TRAI issued a Direction on allocation and operationalisation of the 1601 numbering series for service and transactional voice calls by entities in sectors other than BFSI and Government, under the Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR 2018), and by Press Release No. 113 of the same date initiated phase-wise implementation for utilities, courier and logistics sector entities. The architecture builds on the 1600 numbering series, which the Department of Telecommunications assigned for allocation to Banking, Financial Services and Insurance sector entities and Government organisations so that consumers could distinguish genuine service and transactional calls from other commercial communications. TRAI has been rolling the 1600 mandate out sector by sector through directions to RBI, SEBI and PFRDA regulated entities, and to IRDAI regulated entities by a direction of 16 December 2025 with a 15 February 2026 adoption date; roughly 485 entities had already adopted the 1600 series across more than 2,800 numbers. The 1601 Direction extends the same design to sectors outside BFSI and Government. Any business that places outbound service or transactional voice calls at volume in the utilities, courier or logistics segments should treat this as a migration project with a dated phase applying to it, not as an optional trust signal.

Why does a numbering-series direction matter to a digital business rather than only to telecom operators?

Because it changes the identity layer of outbound voice, and identity is where fraud and consent collide. Three consequences follow. First, once a sector is inside the mandate, a service or transactional call placed from an ordinary ten-digit mobile number stops being merely unbranded and starts being anomalous — which affects both consumer answer rates and the evidential position if a customer later disputes that a call came from the business. Second, the series sits inside the TCCCPR 2018 regime, so migration interacts with sender registration, consent records, scrubbing against preference registers and the resource-barring machinery TRAI uses against unsolicited commercial communication; a business that migrates its numbering without fixing its consent and template hygiene has moved the problem, not solved it. Third, the mandate lands while the Telecom Commercial Communications Customer Preference (Third Amendment) Regulations, 2026 remain under finalisation after TRAI's Open House Discussion of 17 July 2026 — a package that carried AI-based unsolicited-commercial-communication detection, 15-day resource barring and a 7-day consent window. Businesses should sequence numbering migration and consent-architecture work together rather than in series.

What did the Department of Telecommunications say about IMEI on 12 August 2026?

The Department of Telecommunications issued a press release on 12 August 2026 cautioning mobile handset manufacturers, importers and resellers about mandatory IMEI registration and the consequences of IMEI tampering. The International Mobile Equipment Identity is the device identifier on which India's stolen and counterfeit handset controls depend — the same identifier used by the Central Equipment Identity Register accessible through the Sanchar Saathi platform for blocking lost and stolen devices, and by the Digital Intelligence Platform through which DoT coordinates with law-enforcement and financial-sector stakeholders against misuse of telecom resources in cybercrime and financial fraud. The legal architecture is the Telecommunications Act, 2023 (Act 44 of 2023), which brings tampering with a unique telecommunication identifier and dealing in devices with tampered identifiers inside the statutory offence and penalty structure, alongside the criminal exposure that follows under general law. For businesses, the actionable point is supply-chain rather than doctrinal: an importer or reseller who cannot evidence IMEI registration for each unit, or who sources refurbished stock without identifier provenance, carries the exposure directly. Device-financing lenders should note the overlap with the Reserve Bank's device-restriction rule effective 1 January 2027 — both regimes assume a stable, registered device identity.

Is CERT-In advisory CIAD-2026-0039 on Apple Threat Notifications relevant to corporate compliance?

Yes, for organisations whose executives, counsel, journalists or civil-society partners may be targeted individually rather than at scale. CERT-In issued CIAD-2026-0039 on 14 August 2026 on the subject of Apple Threat Notifications — the mechanism by which Apple notifies a user whose device it believes may have been targeted by an attacker of the kind associated with sophisticated, highly targeted intrusion rather than ordinary cybercrime. From a compliance standpoint three things follow. First, a targeted-compromise notification received by an employee on a device used for work is capable of being the first signal of a cyber incident within the reporting categories under the CERT-In Directions of 28 April 2022 issued under Section 70B of the Information Technology Act, 2000, which run on a six-hour clock from noticing the incident. Second, an organisation needs a defined intake path for such notifications — they arrive to the individual, not to the security team, and without a policy they are frequently not escalated at all. Third, for a Reserve Bank-regulated entity, a confirmed compromise of a device with access to the entity's systems also engages the six-hour DAKSH reporting duty under the entity-wise Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 of 31 July 2026, measured from detection. Write the intake path into the incident-response plan before the notification arrives.

Why does a vulnerability in an open-source AI framework matter for AI governance compliance?

Because AI governance in India is now being tested as a security-assurance obligation, not only as a fairness or transparency obligation. CERT-In issued Vulnerability Note CIVN-2026-0407 on 12 August 2026 recording a remote code execution vulnerability in Langflow OSS, an open-source framework used to build large-language-model and agent workflows. Remote code execution in an orchestration layer is materially more serious than a model-quality defect, because the orchestration layer typically holds the credentials, retrieval connections and tool integrations that reach the rest of the estate. The governance item is inventory rather than a deadline. CERT-In advisory CISG-2026-02 of 25 May 2026 prescribes a three-phase, 60-day roadmap; Phase 2 (Days 8-30) Step 6 requires an AI/ML system inventory recording training-data provenance, inference environment and access controls, and drift monitoring for each model, and Phase 3 (Days 31-60) consists of red-team exercises built around the five key threat areas set out at Section 4.1 to 4.5 of the advisory, and adversarial AI simulations with model-integrity validation. For an entity that began on the issue date, Day 60 fell on 24 July 2026. This edition originally stated that Phase 3 closed on 23 August 2026 and described it as an external AI supply-chain assessment; both were corrected on 29 August 2026, neither being supported by the advisory. An organisation that cannot say which AI orchestration frameworks, model-serving components and agent libraries are running in its estate cannot complete the Step 6 inventory, and the Langflow note is precisely the kind of finding that inventory exists to surface. The same inventory question is arriving from the financial-sector side through the Reserve Bank's draft Guidance on Regulatory Principles for Model Risk Management, whose comment window closed on 24 July 2026 and which requires a comprehensive inventory of active, inactive, under-development and retired models including AI/ML, generative-AI and third-party models.

Tags

digital-law weekly-tracker trai-1601-series-direction verified-calling tcccpr-2018 unsolicited-commercial-communication imei-registration imei-tampering telecommunications-act-2023 cert-in-advisory apple-threat-notifications mercenary-spyware langflow-remote-code-execution ai-supply-chain-security sebi-online-bond-platform-providers rbi-data-governance telecom-emerging cybersecurity platforms-intermediaries ai-governance fintech-payments
About Veritect

AI research & drafting, purpose-built for Indian litigation.

Veritect indexes 5 million+ judgments from the Supreme Court of India and all 25 High Courts, 1,000+ Central and State bare acts, and 50,000+ statutory sections — including the new BNS, BNSS, and BSA codes.

Built for Indian courts. Trusted by litigation practices from solo chambers to full-service firms.

Try Veritect free