India's digital-law week of 17 to 23 August 2026 turned on a single clause in a tax statute. The Taxation and Other Laws (Amendment) Act, 2026 received Presidential assent on 17 August 2026 and rewrites Section 10A of the Payment and Settlement Systems Act, 2007: the zero-MDR mandate no longer runs through Section 269SU of the repealed Income-tax Act, 1961 but through electronic payment modes the Central Government may specify by notification, effective on Gazette publication. CERT-In recorded CIVN-2026-0416 on 20 August — a CRITICAL unauthenticated server-side request forgery flaw in MLflow before 3.15.0 (CVE-2026-64849). SEBI issued Press Release No. 48/2026 on live trading strategies on social media and, on 20 August, two circulars on digitally signed FPI Powers of Attorney and KRA data sharing with IFSCA-regulated entities.
At a Glance — W34 Scoreboard
| # | Pillar | Development | Issuer | Date | Score |
|---|---|---|---|---|---|
| 1 | fintech-payments | Taxation and Other Laws (Amendment) Act, 2026 assented — Section 10A PSS Act 2007 zero-MDR mandate decoupled from repealed IT Act 1961 §269SU; covered modes now move by Central Government notification; limb effective on Gazette publication | President of India / MoF | 17 Aug 2026 | 10 |
| 2 | ai-governance | CIVN-2026-0416 — CRITICAL unauthenticated SSRF in MLflow < 3.15.0 (CVE-2026-64849); credential exfiltration and internal-service reconnaissance recorded | CERT-In | 20 Aug 2026 | 9 |
| 3 | platforms-intermediaries | Press Release No. 48/2026 — caution on live trading strategies on social media; unregistered advice in parallel live chats; 30-day market-data lag restated | SEBI | 17 Aug 2026 | 8 |
| 4 | fintech-payments | Digitally signed Powers of Attorney from FPIs accepted; KRA information sharing with IFSCA-regulated entities enabled — two circulars | SEBI | 20 Aug 2026 | 7 |
| 5 | cybersecurity | CIAD-2026-0040 (SAP), CIAD-2026-0041 (Apple), CIAD-2026-0042 (Windows Server 2022 end of mainstream); CIVN-2026-0414 — CRITICAL arbitrary file upload in WordPress Forminator Forms < 1.56.2 (CVE-2026-15748) | CERT-In | 18–20 Aug 2026 | 7 |
| 6 | cybersecurity | CIVN-2026-0411 to 0417 — Cisco SSL VPN DoS, Adobe, MongoDB, Forminator, Wireshark, MLflow, Cisco BroadWorks blind XXE | CERT-In | 17–21 Aug 2026 | 6 |
| 7 | fintech-payments | RBI draft Data Governance guidance consultation closed (PR 2026-2027/677) — Data Function at not below CGM rank; Owner / Steward / Custodian roles across 11 RE categories | RBI | 17 Aug 2026 | 6 |
| 8 | data-protection | DPBI — no Tier 1 notification of Section 18(1) constitution traced as at 23 Aug; MeitY, PIB, DoT, UIDAI, NPCI and IRDAI surfaces not retrievable for the window (403 / 404 / unrendered) | MeitY | 23 Aug 2026 | 4 |
TL;DR for Founders
Three things to act on this week:
If you run a payments business: the zero-MDR perimeter is now an executive-notification perimeter. Section 10A of the Payment and Settlement Systems Act, 2007 no longer borrows its list of covered modes from a repealed tax statute — the Central Government specifies them by notification. Put "Section 10A notifications" on your standing regulatory-watch list, and read the operative date off the gazetted Act, because that limb commences on Gazette publication rather than on the Act's 1 April 2026 deemed commencement.
If you run any ML platform: MLflow before 3.15.0 carries a CRITICAL unauthenticated SSRF (CVE-2026-64849). Upgrade to 3.15.0 or later. Then ask the harder question: your model registry and experiment tracker hold your object-store credentials. Two consecutive CERT-In notes — Langflow on 12 August, MLflow on 20 August — have landed on AI infrastructure, not models.
If you host or monetise financial content: SEBI's Press Release No. 48/2026 records unregistered advice moving through live chats attached to education-styled trading streams. The thirty-day market-data lag under the 8 May 2026 circular is the line. Review monetisation, promotional placement and record-retention for trading-call content now, not when the notice arrives.
Top 3 Developments
1. Zero MDR Just Became an Executive-Notification Regime (Fintech-Payments)
What changed: The Taxation and Other Laws (Amendment) Act, 2026 received Presidential assent on 17 August 2026. Introduced in the Lok Sabha as Bill No. 150 of 2026 with a Statement of Objects and Reasons dated 31 July 2026, it completes the Article 123(2) replacement of the Income-tax (Amendment) Ordinance, 2026, promulgated on 5 June 2026. The Act is deemed to have come into force on 1 April 2026 save as otherwise provided — and the digital-payments limb is one of the exceptions.
The clause that matters: Section 10A of the Payment and Settlement Systems Act, 2007 carries India's no-charge mandate — the provision under which no bank or system provider may impose a charge on a payer or a payee for a transaction through prescribed electronic modes. Until now that section identified the covered modes by cross-reference to Section 269SU of the Income-tax Act, 1961. The 1961 Act has been replaced by the Income-tax Act, 2025, which commenced on 1 April 2026. A live mandate was therefore hanging off a provision of a repealed statute. The Amendment Act substitutes a reference to one or more electronic modes of payment that the Central Government may specify by notification, and that substitution takes effect from the date of publication of the Act in the Official Gazette.
Why it matters: This reads as housekeeping and is not. Three consequences follow.
The perimeter became mobile. The set of payment modes inside the zero-MDR mandate previously moved only when a tax provision moved; it now moves when the Central Government issues a notification under Section 10A. Every acquirer, payment aggregator, PSP bank and card network in India prices against this perimeter, and a notification adding or removing a mode now changes unit economics on a merchant book without a Finance Bill.
A drafting risk closed. A mandate whose operative scope depends on a section of a repealed Act is an argument waiting to be run in an enforcement proceeding or a merchant dispute. That argument is foreclosed prospectively; conduct between 1 April 2026 and Gazette publication remains to be assessed on its own facts.
Commencement is not uniform. The Act's default is deemed commencement on 1 April 2026, but the Section 10A limb runs from Gazette publication and two new Schedule IV exemption entries run from 1 October 2026.
Provenance and gap (§5.10, §5.11): the assent date of 17 August 2026 is taken from the President's Secretariat record of Central Bills assented to by the President, which lists "The Taxation and Other Laws (Amendment) Bill, 2026" against that date under the Ministry of Finance. The clause detail is read from the Bill as introduced. Veritect had not retrieved the gazetted Act text or the 2026 Act number from egazette.gov.in as at 29 August 2026. The Act number, the exact Gazette publication date, and therefore the exact commencement date of the Section 10A limb are unconfirmed. Do not cite an Act number for this statute until the gazetted version is read.
Practitioner takeaway: Reopen merchant and network agreements that define "prescribed electronic modes" or "no-MDR modes" by reference to Section 269SU of the Income-tax Act, 1961 — that reference is now a dangling pointer, and the drafting should track Section 10A as amended, not the tax provision. For clients advised on MDR-bearing product design, note that the classification question has moved from a tax-prescription question to an executive-notification question, and build the watch accordingly.
Link: Rashtrapati Bhavan — Central Bills assented to by the President | Gazette of India (eGazette)
Score: 10/15.
2. The Second CERT-In Note in Two Weeks to Land on the AI Platform Layer (AI-Governance / Cybersecurity)
What changed: On 20 August 2026 CERT-In issued Vulnerability Note CIVN-2026-0416, recording a CRITICAL server-side request forgery vulnerability in MLflow versions prior to 3.15.0, tracked as CVE-2026-64849. The flaw arises from improper input validation; an unauthenticated attacker can craft malicious URLs targeting internal resources. CERT-In records unauthorised internal-service access, credential exfiltration, and reconnaissance within enterprise or cloud environments as consequences. The remedy is an upgrade to MLflow 3.15.0 or later.
Why it matters: MLflow is the experiment-tracking and model-registry layer of a very large share of Indian enterprise ML estates. Its server typically holds — or can reach — the object-store credentials where artefacts live, the backing database connection string, and, in cloud deployments, the instance metadata endpoint. Server-side request forgery in that position is a credential-harvesting primitive. It is not a model-behaviour problem, and no amount of fairness, bias or explainability testing will find it.
This is the second consecutive week in which a CERT-In note has landed on AI infrastructure rather than on a model: on 12 August 2026 CERT-In recorded CIVN-2026-0407, a remote code execution vulnerability in Langflow OSS, an orchestration framework for large-language-model and agent workflows. Orchestration frameworks and model registries occupy the same structural position — the credential-bearing connective tissue between the model and the estate.
The governance link is inventory, and the inventory is already mandated. Step 6 of CERT-In's Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure — advisory CISG-2026-02 of 25 May 2026 — requires, within Phase 2 (Days 8 to 30), an AI/ML system inventory recording for each model the training-data source and provenance, the inference environment and access controls, and the model-drift and anomalous-output monitoring regime. CERT-In expressly notes that this single inventory discharges the AI-system-risk-assessment requirement of both the SEBI Cybersecurity and Cyber Resilience Framework (2024) and the RBI IT Governance Master Direction (2023). The uncomfortable observation is that most inventories built to that instruction list models — and neither Langflow nor MLflow is a model. An inventory stopping at the model boundary would have surfaced neither of this month's two critical findings.
A correction on the Blueprint timeline (§5.11): Veritect's W33 tracker recorded that Phase 3 of CISG-2026-02 "closes on 23 August 2026" for entities that began on 25 May, and described Phase 3 as an external AI supply-chain assessment. Neither is supported by the advisory's sixty-day roadmap as captured in Veritect's research corpus. The phases run Days 1–7, Days 8–30 and Days 31–60; for an entity commencing on the issue date of 25 May 2026, Day 60 fell on 24 July 2026. Phase 3 is Step 8, red-team exercises built around the five key threat areas at Section 4.1 to 4.5 of the advisory rather than generic penetration testing, and Step 9, adversarial AI simulations and model-integrity validation per model, with board or audit-committee reporting where the model sits in a regulated context. The deliverables are unchanged by the correction, and they remain audit-relevant.
On penalties (§5.3): CISG-2026-02 is a guideline, not a binding direction under Section 70B(6) of the Information Technology Act, 2000, so non-adoption does not by itself engage Section 70B(7). Where a binding direction is breached, Section 70B(7) carries imprisonment up to one year and a fine up to one crore rupees — that figure substituted for "one lakh rupees" by the Jan Vishwas (Amendment of Provisions) Act, 2023 with effect from 30 November 2023, as the footnote in the statute records.
Practitioner takeaway: Instruct clients to extend the CISG-2026-02 Step 6 inventory beyond models to the platform layer — orchestration frameworks, model registries, experiment trackers, vector databases, feature stores and inference gateways — with owner, version, network exposure and credential scope recorded for each. Then run this month's two notes against it as a test. An inventory that cannot answer "do we run MLflow, and at what version, reachable from where" is not yet an inventory.
Link: CERT-In — Vulnerability Notes 2026 | CERT-In
Score: 9/15.
3. SEBI Draws the Line Between Investor Education and Unregistered Advice on Live Streams (Platforms-Intermediaries)
What changed: On 17 August 2026 SEBI issued Press Release No. 48/2026, "Caution to Investors regarding display of Live trading strategies on Social Media Platforms". SEBI cautioned investors against acting on "live trading strategies" and "real-time strategies" offered on social media, recorded that such sessions attract substantial viewership, that live chats running alongside them carry unregistered advisory services, and that presenters portray themselves as market experts showing entry and exit calls, index positions and claimed real-time performance. Investors were advised to deal only with SEBI-registered intermediaries.
The operative baseline: SEBI reiterated that live market data may not be shared by any entity except for the orderly functioning of the securities market or to fulfil regulatory requirements. Under SEBI circular HO/47/17/12(11)2025-MRD-POD3/I/11107/2026 dated 8 May 2026, market price data may be shared for investor education and awareness without any monetary incentive to participants and subject to a lag of thirty days; a person engaged solely in education must not use market price data of the preceding thirty days, must not indicate future price, and must not provide advice or a recommendation relating to any security.
Why it matters: This is a caution, not a direction against named persons, and enforcement against an individual still requires separate proceedings. Its value is that it identifies where the education carve-out stops — and the answer lies not in the main stream but in the parallel chat. The regulatory hooks are Regulation 3(1) of the SEBI (Investment Advisers) Regulations, 2013 and Regulation 3(1) of the SEBI (Research Analysts) Regulations, 2014, both attaching to the activity rather than the label, with Regulation 4 of the SEBI (Prohibition of Fraudulent and Unfair Trade Practices relating to Securities Market) Regulations, 2003 behind them where performance claims are false.
For the platform, the press release imposes nothing directly. Platform exposure is an intermediary-law question under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, where safe harbour under Section 79 of the Information Technology Act, 2000 depends on due diligence including action on actual knowledge — a court order or notification by the Appropriate Government or its agency. The practical consequence is evidentiary before it is doctrinal: monetisation, promotional-placement and stream-retention records are what a later proceeding asks for, and they are usually the first thing a platform cannot produce at the depth requested.
Practitioner takeaway: For content-creator clients, the safe structure is hard separation — no live market data inside the thirty-day window, no live chat channel attached to an education session, no monetary incentive tied to participation, no security-specific commentary. For platform clients, build the regulator-communication intake path and raise retention on streams, chat logs and monetisation records for financial content above the default. For registered intermediaries whose staff appear on such streams, advise on the attribution risk to the entity.
Link: SEBI — Press Release No. 48/2026 (17.08.2026)
Score: 8/15.
Beyond this Brief Preview — Veritect Legal AI
The full gazetted text of the Taxation and Other Laws (Amendment) Act, 2026 with the Section 10A Payment and Settlement Systems Act commencement chain, the complete CERT-In CISG-2026-02 nine-category threat taxonomy with the three-phase evidence set mapped against SEBI CSCRF and the RBI IT Governance Master Direction, the CERT-In Vulnerability Notes tracker with AI-platform-layer classification, and the SEBI investor-education and market-data-dissemination circular chain are available in Veritect Legal AI.
Regulatory Action Log — Items 4-8
| Date | Regulator | Pillar | Action | Source |
|---|---|---|---|---|
| 20 Aug 2026 | SEBI | fintech-payments | Acceptance of digitally signed Power of Attorney from FPIs — circular HO/19/34/14(8)2026-AFD-POD2/I/19251/2026. Digital execution of the instrument on which an FPI's custodian mandate rests; read with Section 5 of the Information Technology Act, 2000 and the Second Schedule electronic-signature techniques. Header and reference number retrieved; the page body renders client-side, so operative text, signature standards and effective date were not read — open the attached PDF before advising | sebi.gov.in |
| 20 Aug 2026 | SEBI | data-protection | Enabling sharing of information by KYC Registration Agencies (KRAs) with entities regulated by the International Financial Services Centres Authority — circular HO/38/15/(7)2026-MIRSD-POD/I/19255/2026. A new authorised recipient class for KRA-held KYC records, which are personal data in the hands of a data fiduciary; the DPDP Act, 2023 notice and purpose-limitation analysis runs alongside the securities-law authorisation. Operative text not retrieved — same rendering issue | sebi.gov.in |
| 18–20 Aug 2026 | CERT-In | cybersecurity | Advisories CIAD-2026-0040 (SAP products, 18 Aug), CIAD-2026-0041 (Apple products, 19 Aug — the second Apple item in consecutive weeks after CIAD-2026-0039), CIAD-2026-0042 (end of mainstream support for Windows Server 2022, 20 Aug). Lifecycle is a compliance surface: an unsupported server platform is a standing finding in a SEBI CSCRF or RBI IT Governance audit | cert-in.org.in |
| 17–21 Aug 2026 | CERT-In | cybersecurity | Vulnerability Notes CIVN-2026-0411 (Cisco SSL VPN DoS), 0412 (Adobe), 0413 (MongoDB), 0414 (CRITICAL — unauthenticated arbitrary file upload via a public submission handler in the WordPress Forminator Forms plugin before 1.56.2, CVE-2026-15748, leading to arbitrary code execution), 0415 (Wireshark), 0416 (MLflow — Item 2), 0417 (blind XXE in Cisco BroadWorks). Forminator sits on the marketing and lead-capture sites where personal data is collected, so a compromise is a Section 8(6) DPDP Act, 2023 breach-notification event as well as a CERT-In reportable incident | cert-in.org.in |
| 17 Aug 2026 | RBI | fintech-payments | Comment window closed on the draft Guidance on Regulatory Expectations for Data Governance (PR 2026-2027/677): a dedicated Data Function headed by an officer not below Chief General Manager rank, Data Owner / Data Steward / Data Custodian roles with documented lifecycle responsibility mapping, and data-architecture, metadata-and-lineage, quality and third-party data-sharing expectations across 11 regulated-entity categories. Final guidance pending | rbi.org.in |
| 17–23 Aug 2026 | TRAI / RBI | telecom-emerging, cybersecurity | TRAI issued no direction and no press release dated within the window — the most recent entries were the 1601-series Direction of 10 August and PR No. 114 of 14 August. RBI's notification surface carried only Section 51A UAPA sanctions-list updates (IDs 13676–13678, 18–19 Aug); no IT, cyber, outsourcing or payments-security notification issued | trai.gov.in |
Veritect daily-news cross-check: Veritect's daily-news output for 17–23 August 2026 carried two items within this tracker's scope — the Taxation and Other Laws (Amendment) Act assent (Item 1) and SEBI Press Release No. 48/2026 (Item 3). Both are cross-linked in related_articles and are treated here at tracker altitude rather than re-reported.
Research Gaps and Unretrieved Sources
Recorded under CLAUDE.md §5.10 — an absence of retrieval is not a finding of inactivity.
- MeitY returned HTTP 403 on the press-release and what's-new surfaces and HTTP 404 on the notifications listing; PIB returned HTTP 403; the DoT what's-new surface rendered without dated content. No MeitY or DoT instrument dated 17–23 August 2026 was confirmed either way, and the status of the draft IT (Intermediary Guidelines and Digital Media Ethics Code) Second Amendment Rules, 2026 circulated in March 2026 remains unverified.
- UIDAI (404 at the circulars path), NPCI (HTTP 403 on the UPI circular listing) and TDSAT (404 on the Delhi judgments listing; case-management search not exercised) yielded nothing for the window. IRDAI was readable and showed no circular dated between 17 and 23 August 2026, the nearest being 27 and 28 August.
- eGazette not retrieved: the Act number and Gazette publication date of the Taxation and Other Laws (Amendment) Act, 2026 — and with them the commencement date of the Section 10A limb — are unconfirmed.
- Data Protection Board of India: no Tier 1 notification of constitution under Section 18(1) of the Digital Personal Data Protection Act, 2023 traced as at 23 August 2026. The Rule 17 Search-cum-Selection process under the DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) continues; composition is fixed at a Chairperson plus four Members. Confirm against the Gazette before asserting Board status.
- SEBI circular bodies for both 20 August circulars render client-side; only headers and reference numbers were retrieved, so operative provisions, conditions and effective dates are not characterised here.
What's Next
- Immediate — Gazette publication of the Taxation and Other Laws (Amendment) Act, 2026, fixing the commencement date of the Section 10A PSS Act 2007 amendment and supplying the Act number; then the first notification specifying electronic payment modes under the amended Section 10A.
- ~September 2026 — RBI final Guidance on Regulatory Expectations for Data Governance after the 17 August consultation close, and the final Model Risk Management guidance after the 24 July close, whose third-party and generative-AI model perimeter overlaps the AI inventory in Item 2.
- ~August–September 2026 — 1601-series phase dates under the TRAI Direction of 10 August 2026; first OGAI Rule 10 determination orders under the Promotion and Regulation of Online Gaming Rules, 2026 (G.S.R. 303(E), 22 April 2026) — neither traced at the time of writing.
- Q3–Q4 2026 — TRAI TCCCPR (Third Amendment) Regulations, 2026 final notification after the Open House Discussion of 17 July 2026, in force thirty days after Gazette publication; DoT authorisation transition mechanics under the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026; status of the draft IT (Intermediary Guidelines) Second Amendment Rules, 2026.
- ~November 2026 — DPDP consent-manager registration opens under Rule 4 of the DPDP Rules, 2025; RBI Q-SAFE quantum-safe roadmap due.
- 1 January 2027 — Responsible Business Conduct Fourth Amendment Directions, 2026 take effect, alongside the RBI Customer Liability Amendment Directions. ~13 May 2027 — end of the 18-month DPDP phased-compliance runway.
Founder Action Items
- Add "Section 10A notifications" to your regulatory watch. The zero-MDR perimeter now moves by Central Government notification rather than tax prescription. Any contract, pricing schedule or product spec defining no-MDR modes by reference to Section 269SU of the Income-tax Act, 1961 is a dangling pointer — reword it to track Section 10A of the Payment and Settlement Systems Act, 2007 as amended.
- Upgrade MLflow to 3.15.0 or later today, then check what credentials the tracking server can reach — object store, backing database, cloud metadata endpoint — and scope them down. CVE-2026-64849 is CRITICAL and unauthenticated.
- Extend your AI inventory past the model boundary: orchestration frameworks, model registries, experiment trackers, vector databases, feature stores, inference gateways — owner, version, network exposure, credential scope. Two CERT-In notes in two weeks (Langflow, MLflow) both sat outside the model.
- Patch Forminator Forms to 1.56.2 or later on every WordPress property, and plan the Windows Server 2022 lifecycle exit. Unauthenticated arbitrary file upload (CVE-2026-15748) sits on the marketing and lead-capture sites where you collect personal data, making a compromise a Section 8(6) DPDP Act, 2023 breach-notification event as well as a CERT-In reportable incident; an unsupported server platform (CIAD-2026-0042) is a standing audit finding under SEBI CSCRF and the RBI IT Governance Master Direction long before it is a breach.
- If you host or monetise trading content, separate education from advice structurally, and raise retention on streams, chat logs and monetisation records above your default.
- Do not assert the DPDP Board's constitution. No Section 18(1) notification had been traced as at 23 August 2026. Check the Gazette before it goes in a client note.
Practitioner Watch-List
- The Section 10A commencement question. Until the Gazette is read, three things are unfixed: the Act number, the publication date, and therefore the date the amended Section 10A perimeter begins to operate. Advice given between 1 April 2026 and that date on zero-MDR scope rests on the unamended cross-reference to a repealed provision — flag it in the opinion rather than let it be discovered later.
- AI platform inventory as the converging artefact. CERT-In CISG-2026-02 Step 6, SEBI CSCRF, the RBI IT Governance Master Direction, 2023, the pending RBI Model Risk Management guidance and customer AI due-diligence questionnaires all demand the same object. Build it once, and build it to include infrastructure — the August notes are the argument for the wider scope. Correct the Blueprint timeline in client-facing material at the same time: Day 60 for a 25 May starter was 24 July 2026, and Phase 3 is red-teaming and adversarial AI simulation, not an external supply-chain assessment.
- KRA data sharing and the DPDP overlay. SEBI's 20 August circular authorises a new recipient class for KRA-held KYC records under securities law. Securities-law authorisation is not, by itself, a DPDP Act, 2023 lawful basis — the notice, purpose-limitation and, where relevant, cross-border analysis run alongside, and the IFSCA-regulated recipient sits in a distinct regulatory perimeter.
- Electronic execution of custodial instruments. SEBI's acceptance of digitally signed FPI Powers of Attorney is a small circular with a long tail: it puts Section 5 of the Information Technology Act, 2000 and the Second Schedule electronic-signature techniques into the operating workflow of the custody chain. Read its signature standards against what the client's foreign signatories can actually produce before promising paperless onboarding.
- The intermediary-law question the SEBI press release does not answer. Where a securities regulator publicly identifies a category of unlawful conduct on platforms without notifying specific URLs, no Rule 3(1)(d) clock starts. Whether continued monetisation of such content after the caution affects a platform's due-diligence position under the IT Rules, 2021 is open in Indian practice, and worth a documented position.
FAQ
What exactly did the Taxation and Other Laws (Amendment) Act, 2026 change about zero MDR?
It changed the mechanism, not the rate. Section 10A of the Payment and Settlement Systems Act, 2007 carries India's no-charge mandate and previously identified covered modes by cross-reference to Section 269SU of the Income-tax Act, 1961 — a provision of a statute replaced by the Income-tax Act, 2025, which commenced on 1 April 2026. The Amendment Act, assented on 17 August 2026, substitutes a reference to one or more electronic modes of payment that the Central Government may specify by notification, and that limb takes effect from the date of publication of the Act in the Official Gazette rather than from the Act's 1 April 2026 deemed commencement. For a payments business, the perimeter of covered modes now moves by executive notification, so Section 10A notifications become a standing watch item and any contract defining "no-MDR modes" by reference to Section 269SU should be reworded. Veritect had not retrieved the gazetted Act text or the 2026 Act number as at 29 August 2026; the assent date is taken from the President's Secretariat record of Central Bills assented to.
Why does a CERT-In note about MLflow matter more than a routine patch advisory?
Because of where MLflow sits. CIVN-2026-0416 of 20 August 2026 records a CRITICAL server-side request forgery vulnerability in MLflow versions prior to 3.15.0 (CVE-2026-64849), arising from improper input validation and exploitable by an unauthenticated attacker crafting URLs against internal resources; CERT-In records unauthorised internal-service access, credential exfiltration and reconnaissance as consequences, with the fix an upgrade to 3.15.0 or later. An experiment-tracking and model-registry server holds or can reach object-store credentials, the backing database connection string and, in cloud deployments, the instance metadata endpoint — so SSRF there is a credential-harvesting primitive, not a model-quality defect. It is also the second consecutive week in which a CERT-In note has landed on AI infrastructure rather than a model, after the Langflow remote code execution note CIVN-2026-0407 of 12 August 2026. Answering either requires the Step 6 AI/ML system inventory mandated in Phase 2 (Days 8–30) of CERT-In advisory CISG-2026-02 of 25 May 2026, which CERT-In notes also discharges the AI-risk-assessment requirement under SEBI CSCRF (2024) and the RBI IT Governance Master Direction (2023).
Is it now illegal to run a live trading stream in India?
No. SEBI's Press Release No. 48/2026 of 17 August 2026 is a caution addressed to investors, not a prohibitory direction, and enforcement against any person still requires separate proceedings. What it does is mark the boundary. Live market data may not be shared by any entity except for the orderly functioning of the securities market or to fulfil regulatory requirements; and under SEBI circular HO/47/17/12(11)2025-MRD-POD3/I/11107/2026 of 8 May 2026, market price data may be shared for investor education without monetary incentive to participants only subject to a thirty-day lag, with the educator not using data of the preceding thirty days, not indicating future price, and not providing advice or a recommendation on any security. SEBI's specific finding was that unregistered advisory services were being exchanged in live chats running alongside education-styled sessions — the moment the education carve-out ceases to apply, because Regulation 3(1) of the SEBI (Investment Advisers) Regulations, 2013 and Regulation 3(1) of the SEBI (Research Analysts) Regulations, 2014 attach to the activity rather than to the label.
Did MeitY or DoT issue anything between 17 and 23 August 2026, and has the DPDP Board been constituted?
Unknown in both cases — which is not "no". Veritect's sweep could not retrieve content from meity.gov.in (HTTP 403 on press-release and what's-new, HTTP 404 on notifications) or pib.gov.in (HTTP 403), and the DoT what's-new page rendered without dated content, so the status of the draft IT (Intermediary Guidelines and Digital Media Ethics Code) Second Amendment Rules, 2026 circulated in March 2026 is unverified. TRAI, by contrast, was readable and carried no direction and no press release dated within the window. On the Board: no Tier 1 notification of constitution under Section 18(1) of the Digital Personal Data Protection Act, 2023 had been traced as at 23 August 2026 — a statement about what was retrieved, not a conclusion that none exists. The Rule 17 Search-cum-Selection process under the DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) continues, with composition fixed at a Chairperson plus four Members; consent-manager registration under Rule 4 is expected around November 2026. Because the Board's existence determines whether a complaint, a Section 8(6) breach intimation or a voluntary undertaking has anywhere to go, confirm its status against the Official Gazette before asserting it in a filing.
Primary Sources
Tier 1 sources only: President's Secretariat (rashtrapatibhavan.gov.in), CERT-In (cert-in.org.in), SEBI (sebi.gov.in), RBI (rbi.org.in), TRAI (trai.gov.in), IRDAI (irdai.gov.in), MeitY (meity.gov.in), eGazette (egazette.gov.in). All developments reported as of 23 August 2026 unless stated; the tracker was compiled on 29 August 2026 as a catch-up edition for a closed week. Items flagged 'expected', 'pending' or 'unconfirmed' carry that qualifier explicitly. Where a Tier 1 source could not be retrieved — notably MeitY, PIB, DoT, UIDAI, NPCI, TDSAT and eGazette — that is recorded in the Research Gaps section as an absence of retrieval and must not be read as an absence of regulatory activity. Reconfirm against primary-source URLs before acting.
- Rashtrapati Bhavan — Central Bills assented to by the President (Taxation and Other Laws (Amendment) Bill, 2026, assented 17.08.2026)
- Gazette of India (eGazette)
- CERT-In — Vulnerability Notes 2026 (CIVN-2026-0411 to 0417)
- CERT-In — Advisories List 2026 (CIAD-2026-0040, 0041, 0042)
- CERT-In — home
- SEBI — Press Release No. 48/2026 (17.08.2026), Caution to Investors regarding display of Live trading strategies on Social Media Platforms
- SEBI — Acceptance of digitally signed Power of Attorney from FPIs (20.08.2026)
- SEBI — Enabling sharing of information by KRAs with entities regulated by IFSCA (20.08.2026)
- SEBI — Circulars listing
- RBI — Press Release 2026-2027/677: draft Guidance on Regulatory Expectations for Data Governance
- RBI — Notifications listing
- TRAI — Directions
- TRAI — Press Releases
- IRDAI — Circulars
- MeitY — Digital Personal Data Protection Rules, 2025
Beyond this Brief Preview — Veritect Legal AI
Veritect Legal AI carries the research-grade layer behind this tracker: the Payment and Settlement Systems Act, 2007 Section 10A amendment chain with the Income-tax Act 1961-to-2025 transition, the CERT-In CISG-2026-02 nine-category AI-threat taxonomy with the full three-phase evidence set mapped against SEBI CSCRF and the RBI IT Governance Master Direction, 2023, the CERT-In Vulnerability Notes tracker with AI-platform-layer classification, and the SEBI investor-education, market-data-dissemination and KYC Registration Agency circular chains.
Next edition: W35 tracker covering 24–30 August 2026 — the SEBI circulars of 24 and 28 August, CERT-In advisory CIAD-2026-0043 of 28 August, IRDAI's 27–28 August circulars, and any MeitY or DoT instrument recoverable once those portals are reachable again.
Corrections
5 September 2026 — CERT-In AI Blueprint threat taxonomy. This edition described Phase 3 of CISG-2026-02 as red-team exercises built around the advisory's nine AI-threat categories. The advisory has no nine-category threat taxonomy. Section 4 sets out five key threat areas — 4.1 AI-Enabled Reconnaissance and Vulnerability Exploitation, 4.2 AI-Driven Phishing, Impersonation, and Social Engineering, 4.3 AI-Generated Malware and Automated Attack Operations, 4.4 Adversarial Threats Against AI Systems, 4.5 Risks to Vital Infrastructure and Digital Ecosystems — with 4.6 a forward-looking note rather than a sixth area. The nine-item list in the advisory's Executive Summary enumerates the framework's defensive coverage areas, not threats. Red-team scenarios map to the five Section 4 areas. Corrected at every occurrence in this file. The Phase 3 timing stated in this edition (Days 31–60, Day 60 falling on 24 July 2026 for 25-May starters) is unaffected and remains correct.