New Tech War? India Demands “Keys” to Smartphone OS for Security
The Indian government is reportedly moving forward with a sweeping security overhaul for smartphones that could fundamentally change how tech giants like Apple, Samsung, and Google operate in the country. At the heart of the debate is a controversial proposal: requiring manufacturers to share their proprietary source code for security audits.
The 83-Point Security Plan
The proposed “Indian Telecom Security Assurance Requirements” consist of approximately 83 security standards. While the government aims to curb rising digital fraud and data breaches in the world’s second-largest smartphone market, industry leaders are pushing back.
Key highlights of the proposal include:
- Source Code Disclosure: Manufacturers would provide OS source code to government-designated labs to identify vulnerabilities.
- Background Permission Blocks: Strict limits on apps accessing cameras, microphones, or location services while the phone is inactive.
- Pre-installed App Control: Requirements to allow users to delete pre-installed apps (bloatware) that are not essential to core functions.
- One-Year Log Retention: Devices would need to store system activity logs for at least 12 months for auditing purposes.
Why Tech Giants Are Worried
Industry groups, including MAIT (representing Apple, Samsung, and Xiaomi), have formally voiced concerns, stating that many of these requirements are “not possible” due to corporate secrecy and global privacy policies.
- Intellectual Property Risks: Sharing source code—the “secret sauce” of an operating system—is a line tech companies have historically refused to cross, even under pressure from major markets like the US and China.
- Lack of Global Precedent: Manufacturers argue that no other major economy (including the EU or North America) mandates such intrusive access to proprietary code.
- Performance Issues: Features like mandatory periodic malware scanning and one-year log retention could significantly drain battery life and slow down hardware.
Industry Insight: Tech firms argue that requiring government approval for every security patch is “impractical,” as critical fixes must be rolled out instantly to protect users from active hacks.
The Government’s Stance
The Indian government maintains that these measures are essential to protect its 750 million smartphone users. By verifying the security of the devices at a foundational level, they hope to eliminate “backdoor” vulnerabilities and reduce the prevalence of identity theft and financial scams.
IT Secretary S. Krishnan recently noted that the government has an “open mind” and is willing to address legitimate industry concerns as consultations continue.
What Happens Next?
This is the second major regulatory clash in recent months. In late 2025, the government briefly considered mandating the pre-installation of the Sanchar Saathi security app but revoked the order following a public outcry over privacy.
The Ministry of Electronics and Information Technology (MeitY) is scheduled to meet with tech executives this week (January 13, 2026) to find a middle ground. Whether India will soften its stance or set a new global precedent for digital sovereignty remains to be seen.






