India's Digital Push Hits a Wall: Government Flags AI Payment Risks, WhatsApp Usernames, and Data Leaks in One Week

AI AgentsEthics
Illustration generated by AI: Editorial image for India's Digital Push Hits a Wall: Government Flags AI Payment Risks, WhatsApp Usernames, and Data Leaks in One Week

The Core · TL;DR

  • CERT-In's Digital Threat Report 2025-26 proposes mandatory human oversight and audit trails for agentic AI payments above set thresholds, responding to protocols like Coinbase's x402, Cloudflare's agent-payment tools, Pine Labs' P3P, and NPCI's upcoming Unified Agent Protocol.
  • MeitY has formally opposed WhatsApp's proposed username feature, warning it could enable impersonation, fraud, and digital arrest scams while hampering law enforcement, even as the ministry pursues common messaging standards.
  • Researchers Akshay C.S. and Viral Vaghela found vulnerabilities in the UMANG government services app that exposed EPFO UANs, LPG booking data, and Aadhaar numbers in plaintext; MeitY has confirmed the issue and is deploying encryption fixes.
  • Security researcher Karan Saini independently reviewed the UMANG findings and called the flaws significant, highlighting a gap between India's forward-looking AI payment regulation and its existing platform security.

Three separate developments out of India's technology policy apparatus this week point to the same underlying anxiety: as digital infrastructure grows more autonomous and interconnected, the country's regulators are struggling to keep oversight mechanisms in step with it.

The most forward-looking of the three comes from CERT-In, India's national cybersecurity agency, which has proposed mandatory human-in-the-loop checkpoints for agentic AI systems making payments above certain financial thresholds. The recommendation, buried in the agency's Digital Threat Report 2025-26, would require full audit trails whenever an AI agent initiates a transaction past a defined limit, effectively inserting a human veto point before money moves.

The timing is not incidental. Coinbase introduced its x402 protocol in May 2025, letting AI agents autonomously find and pay for cloud resources, data, and API tools without a person clicking "confirm." Cloudflare has since built on that model, letting publishers charge agents for access to their content using x402 payments. Domestically, the picture is moving just as fast: Pine Labs has rolled out P3P, an agentic payment protocol layered on UPI, while the National Payments Corporation of India is separately developing a Unified Agent Protocol to let AI agents transact directly over UPI rails. CERT-In's proposal reads as an attempt to get ahead of a wave of autonomous commerce before it becomes unmanageable rather than react to it after the fact.

A Parallel Fight Over WhatsApp Usernames

MeitY, India's IT ministry, is also pushing back against a WhatsApp feature still in the proposal stage: usernames that would let people message each other without exchanging phone numbers. The ministry's objection centers on traceability. Officials argue that decoupling chat identities from verified phone numbers would make impersonation, fraud, and so-called "digital arrest" scams easier to run, while complicating law enforcement's ability to trace bad actors. The dispute is unfolding as MeitY separately works toward common technical standards for messaging platforms operating in India, suggesting the ministry wants uniform, traceable identity rules across the messaging ecosystem rather than platform-specific exceptions.

UMANG's Plaintext Problem

The third thread is less about future risk and more about a present failure. Security researchers Akshay C.S. and Viral Vaghela uncovered vulnerabilities in UMANG, the government's flagship app for accessing services like EPFO and LPG cylinder bookings, that exposed Universal Account Numbers, cylinder booking details, and Aadhaar numbers, all stored and transmitted in plaintext. Independent researcher Karan Saini, who reviewed the findings, called the flaws "significant." MeitY has acknowledged the issue and says it is rolling out fixes, including encrypting the plaintext data in the affected APIs.

Taken together, the three stories describe a government trying to write rules for AI-driven payments and platform identity at the same moment it is still patching basic encryption gaps in its own citizen-facing infrastructure. The UMANG disclosure, in particular, underscores why CERT-In's insistence on audit trails and human oversight for agentic payments isn't abstract caution: the same ministry proposing safeguards for tomorrow's autonomous transactions is currently cleaning up plaintext exposure in a platform used by hundreds of millions today.

WK

WAKIB Editorial Team

This review was prepared and summarized by the WAKIB AI intelligence engine and vetted by our editorial board for accuracy and reliability.

Subscribe to Newsletter

Get a weekly summary of the most promising AI research and tools delivered to your inbox.

Telegram Channel

Join our active community on Telegram for real-time tracking of AI models and trends.

Join us on Telegram