In short
SEBI's Cybersecurity and Cyber Resilience Framework sets binding controls for regulated entities. Its data-localisation control has been held in abeyance since 31 December 2024 but was not repealed. AI that runs on infrastructure you operate in India meets the binding controls and needs no change if localisation is reinstated.
What CSCRF is
SEBI issued the Cybersecurity and Cyber Resilience Framework (CSCRF) in August 2024 for regulated entities in the securities market. It organises controls around governance, identification, protection, detection, response and recovery, with requirements scaled by the size and type of entity.
The localisation control is paused, not gone
One control, PR.DS.S2, required regulated entities to host securities-market data within India's legal boundaries. SEBI placed it in abeyance from 31 December 2024. No later circular reinstated it, but abeyance is not repeal: SEBI can bring it back by circular, potentially with little notice.
What this means for AI
An AI assistant or automation is just another system under CSCRF. It needs to sit inside your asset inventory, follow your access and hardening standards, feed your monitoring and be covered by your incident and recovery plans.
- Identify: document the AI components, models and data flows.
- Protect: role-based access, hardening and encryption on the hosts.
- Detect: logs and alerts into your SOC.
- Respond and recover: the AI system in your incident playbooks and backups.
Why deploy in India anyway
If the AI runs on infrastructure you operate in India, the localisation question is answered whatever SEBI decides next. It also keeps the system inside the controls you already evidence for every other critical system.
Source: SEBI CSCRF data localisation status. See also our SEBI CSCRF page.
General information, not legal advice. Questions? Write to sales@deepvox.ai.