Skip to main content
Device SecurityPolicy PushbackAug 27, 2026, 3:50 AM· 3 min read· in technology

India Proposes Mandatory Source Code Sharing for Smartphones, Drawing Pushback from Apple and Samsung

A sweeping new regulatory draft in India would require smartphone manufacturers to submit their operating system source code to government labs for security review. The proposal has sparked intense resistance from major tech companies over intellectual property and privacy concerns.

By Naina Verma

Global Device Manufacturers 45%Indian Regulatory Authorities 30%Cybersecurity Analysts 25%
Global Device Manufacturers
Maintains that mandatory source code sharing compromises intellectual property and introduces severe security vulnerabilities.
Indian Regulatory Authorities
Argues that deep access to device software is necessary to protect consumers and national infrastructure from rising cyber threats.
Cybersecurity Analysts
Warns that requiring government approval for security patches will delay critical updates and leave users exposed to zero-day exploits.

Why it matters

If implemented, these regulations would force global tech giants to choose between compromising their core security architecture or exiting the world's second-largest smartphone market. The mandate could also set a global precedent, encouraging other nations to demand similar access and fracturing the unified security models that currently protect consumer devices.

India has drafted a sweeping set of security regulations that would force smartphone manufacturers to hand over their operating system source code to government-designated testing labs. The proposal, part of a broader 83-point security framework, has triggered intense, behind-the-scenes resistance from Apple, Samsung, and other major device makers who view the mandate as an unprecedented risk to their intellectual property and global security architecture.[1][2]

The draft framework, known as the Indian Telecom Security Assurance Requirements (ITSAR), is positioned by the government as a necessary defense against rising online fraud in a market of nearly 750 million smartphone users. Under the proposed rules, manufacturers would have to submit their source code—the foundational instructions that dictate how iOS and Android operate—for "vulnerability analysis" and "source code review."[2][3]

While the government frames this as a consumer protection measure, the reality of implementation tells a different story. Handing over proprietary source code to third-party labs expands the attack surface, creating new potential leak points for trade secrets and zero-day vulnerabilities. The industry consortium MAIT, representing Apple, Samsung, Google, and Xiaomi, explicitly told the government that compliance is "not possible" due to secrecy and privacy constraints.[1][4][5]

The proposed framework would require companies to submit their operating systems to government-designated testing labs for vulnerability analysis.

Beyond the source code handover, the ITSAR draft includes a requirement that could fundamentally alter how devices are maintained. Manufacturers would be forced to notify the National Centre for Communication Security about major software updates and security patches before releasing them to users, giving the agency the right to test them first.[1][4]

Beyond the source code handover, the ITSAR draft includes a requirement that could fundamentally alter how devices are maintained.

This creates a glaring paradox: a policy marketed as enhancing security would actively delay the deployment of critical, time-sensitive patches. If a zero-day vulnerability is actively being exploited, waiting for a government lab to approve the patch leaves millions of users exposed during the bureaucratic review process.[3][4]

The 83-point framework doesn't stop at code review. It also mandates that devices perform automatic, periodic malware scanning—a process that manufacturers warn would significantly drain battery life. Furthermore, the rules would require phones to store digital logs of system activity locally for at least 12 months, a demand that companies argue exceeds the storage capacity of many entry-level devices.[1][5]

Security experts warn that requiring government approval for software updates could delay critical patches and leave users exposed.

Not all of the proposed changes are hostile to users. The framework includes mandates that would allow consumers to completely uninstall pre-loaded applications—often referred to as bloatware—and block apps from accessing cameras and microphones in the background. These specific provisions align with broader global trends toward user empowerment, even as the source code demands diverge sharply from international norms.[1][4]

The pushback highlights the global stakes of localized tech regulation. There is currently no precedent in North America, Europe, or Australia for mandating source code disclosure as a baseline regulatory requirement for consumer electronics. While India's IT ministry has publicly stated that consultations are ongoing and denied that the source code mandate is finalized, the existence of the draft has forced the industry to draw a hard line. If implemented, the framework could fracture the global smartphone ecosystem, forcing companies to choose between compromising their core security architecture or exiting the world's second-largest market.[2][3][5]

What to know

  • India has drafted an 83-point security framework that would require smartphone makers to share their operating system source code with government labs.
  • The proposal mandates that companies notify authorities and seek approval before releasing major software updates and security patches.
  • Industry consortium MAIT, representing Apple and Samsung, has strongly opposed the rules, citing severe risks to intellectual property and user privacy.
  • Additional requirements include mandatory local storage of system logs for 12 months and built-in, periodic malware scanning.
  • The government has publicly denied that the source code mandate is finalized, though confidential drafts indicate it remains under active consideration.

Where opinion splits

The Regulatory Stance

India's push for sovereign oversight of digital infrastructure.

Indian authorities frame the ITSAR draft as a necessary evolution of national security in an era of rampant data breaches. With nearly 750 million smartphone users, the government argues that relying entirely on the opaque security assurances of foreign corporations is no longer sufficient. By demanding the ability to independently verify source code and test security patches in state-designated labs, regulators aim to ensure that devices operating within their borders do not contain hidden backdoors or unpatched vulnerabilities that could compromise national infrastructure.

The Manufacturers' Dilemma

The existential risk to intellectual property and global security models.

For Apple, Samsung, and Google, the proposal represents a red line that threatens their entire operational model. Source code is the foundational intellectual property of these companies; distributing it to third-party testing facilities exponentially increases the risk of leaks and corporate espionage. Furthermore, manufacturers argue that the mandate to pre-clear security updates with a government agency fundamentally breaks the modern cybersecurity paradigm. In a landscape where zero-day vulnerabilities must be patched globally within hours, a bureaucratic approval bottleneck could leave millions of devices defenseless while regulators review the code.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Global Device Manufacturers 45%Indian Regulatory Authorities 30%Cybersecurity Analysts 25%
  1. [1]The Economic TimesIndian Regulatory Authorities

    India proposes requiring smartphone makers to share source code with the government

    Read on The Economic Times
  2. [2]International Business TimesGlobal Device Manufacturers

    Global smartphone manufacturers are pushing back against a sweeping set of proposed security rules in India

    Read on International Business Times
  3. [3]CybernewsCybersecurity Analysts

    A reported proposal to tighten smartphone security standards in India has put the spotlight on an unusual demand

    Read on Cybernews
  4. [4]Gadget HacksCybersecurity Analysts

    India Demands Source Code: Apple, Samsung Push Back Hard

    Read on Gadget Hacks
  5. [5]CGTNIndian Regulatory Authorities

    India proposes requiring smartphone makers to share source code with the government

    Read on CGTN
  6. [6]The StreetGlobal Device Manufacturers

    India's proposed rules put Apple, Google, and Samsung in a compliance bind

    Read on The Street

Comments

Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.