Commentary connecting AI governance, data privacy, cybersecurity, space law, and litigation — grounded in one recurring argument: institutions consistently substitute general assurance for a specific, checkable standard, wherever one is available. Each piece opens in a new tab.
Why public FIR portals disclosing name, phone number, and caste data raise a live constitutional privacy question, and what relief a PIL could realistically seek.
Read →How the 'digital arrest' scam pattern exploits the gap between what the law actually permits and what victims believe is happening to them.
Read →ISO/IEC 42001 certification is a floor, not a ceiling — why certified companies still fail regulator and investor scrutiny.
Read →A consent screen with separate toggles is not the same as a backend that actually honors them — and DPDPA's Section 8 obligations turn on the latter.
Read →CERT-In's 2022 directions compress incident response into a window most global frameworks don't require — and that compression changes what 'ready' actually means.
Read →For many Indian space-tech companies, the binding constraint on international partnerships isn't launch technology — it's export-control licensing nobody planned for.
Read →As Hyderabad's global capability center corridor scales hiring, a specific, recurring dispute pattern is emerging around departing employees and system access.
Read →Banks routinely classify fraud-induced UPI transfers as 'authorized' because an OTP was used — that classification is often legally wrong, and challenging it is where recovery actually happens.
Read →Credit-scoring models that never use protected characteristics can still reproduce discriminatory outcomes through proxy variables — and regulators are no longer accepting that distinction at face value.
Read →The argument underneath this practice's positioning, made explicit: law consistently fails in the same place, regardless of which frontier it's trying to govern.
Read →