Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
TECHNOLOGY

Analysis: AI’s Uncharted Frontier in Government: Why Trump’s Test Plan Falls Short—and What States Are Doing Right...

AI Security in the Making: How Trump s Framework Ignores Open Models and Leaves Critical Gaps

The Trump administration s proposed framework for evaluating AI cybersecurity risks has sparked concern among tech experts and policymakers alike. By excluding open-source models and failing to clearly define what constitutes a national security threat, the plan risks leaving the nation vulnerable to both malicious actors and unregulated innovation. This approach not only undermines transparency but also creates a patchwork of security standards that could expose critical infrastructure to exploitation. For North East India, where digital transformation is accelerating rapidly, this oversight could have far-reaching implications from cyberattacks on financial systems to disruptions in healthcare and education platforms. The absence of a robust framework means that even well-intentioned open-source AI tools could inadvertently become vectors for cyber threats.

The Exclusion of Open-Source Models: A Strategic Blind Spot

The Trump administration s AI cybersecurity framework is notable for its exclusion of open-source models entirely. According to reports, this decision effectively bars developers who contribute to publicly accessible AI systems, which are often used for research, education, and community-driven innovation. Open-source AI tools are particularly valuable in the North East region, where institutions like the Indian Institute of Technology Guwahati and the North Eastern Regional Institute of Science and Technology rely on collaborative platforms to advance AI research. By excluding these models, the framework denies the government access to a critical layer of cybersecurity monitoring and threat detection that could have been provided by community-driven audits and vulnerability assessments. The lack of inclusion also means that potential risks from open-source AI remain untested, leaving the door wide open for exploitation by cybercriminals or state-sponsored actors.

A 2025 report by the Center for Strategic and International Studies (CSIS) highlighted that 68% of AI-driven cyberattacks in 2024 originated from open-source frameworks, either directly or through modified versions. This statistic underscores how critical it is for policymakers to engage with the open-source community rather than treating it as a liability. In the North East, where digital literacy is still evolving, the reliance on open-source tools for public services such as e-governance platforms could pose unique risks if these tools are not properly vetted. The absence of a framework that includes open-source models means that the region s growing digital economy may face unintended vulnerabilities, particularly in sectors like agriculture, where AI-driven monitoring systems are increasingly being adopted.

Lack of Definition for National Security Risks: A Loophole for Ambiguity

Beyond excluding open-source models, the Trump administration s framework suffers from a fundamental ambiguity: it does not define what constitutes a national security risk in the context of AI. Without clear criteria, the assessment process becomes subjective, allowing for inconsistencies in how different agencies interpret threats. This vagueness could lead to overregulation in some cases while leaving others unchecked, creating an uneven playing field for both domestic and foreign AI developers. For instance, a model that could be deemed a risk by one security agency might be deemed acceptable by another, depending on the context of its deployment.

This ambiguity is particularly concerning in the North East, where AI is being integrated into critical infrastructure such as power grids and telecom networks. A lack of standardized definitions could result in delays or outright bans on AI systems that are essential for modernizing these sectors. For example, the Meghalaya Power Distribution Company Limited (MPDCL) has been exploring AI-driven predictive maintenance to reduce outages, but without a clear security framework, the deployment of such systems could be hindered by bureaucratic hurdles. Similarly, in Manipur, where AI is being used to improve healthcare diagnostics, the absence of a defined risk assessment process could lead to unnecessary scrutiny or restrictions, stifling innovation.

The lack of a defined risk framework also raises concerns about foreign influence. In a region where digital connectivity is growing rapidly, AI systems developed in other countries could be deployed without proper scrutiny. This could expose North East India to cyber threats from adversarial nations, particularly if their AI models are designed with backdoors or malicious intent. The Trump administration s approach, which prioritizes exclusion over inclusion, could inadvertently create a security gap that foreign actors could exploit, especially in areas where AI is used for sensitive operations like defense coordination or financial transactions.

Practical Implications and What This Means for North East India

The implications of this framework extend beyond theoretical concerns. For North East India, where digital transformation is still in its early stages, the absence of a comprehensive AI security strategy could lead to several challenges. First, there is the risk of increased cyberattacks on critical infrastructure. For example, if an open-source AI tool used in a government-run e-voting system in Nagaland is compromised, it could lead to widespread disruptions. Second, there is the potential for stifled innovation, as developers may avoid deploying AI solutions due to uncertainty over compliance requirements. This could slow down progress in sectors like education and healthcare, where AI can be a game-changer.

The North East region is also home to several startups and research institutions that are leveraging AI to address local challenges. For instance, the Assam Science and Technology Council has been working on AI-driven solutions to combat deforestation, while the Mizoram State Council for Science and Technology is exploring AI for precision agriculture. Without a clear security framework, these initiatives could face delays or be forced to adopt overly restrictive measures, limiting their effectiveness. Additionally, the region s dependence on digital platforms for services like online education and remote healthcare could be compromised if AI systems are not properly secured.

The broader Indian context further highlights the urgency of addressing these gaps. India s National AI Strategy, launched in 2023, emphasizes the need for a balanced approach to AI regulation that encourages innovation while ensuring security. The Trump administration s framework, which prioritizes exclusion over collaboration, contrasts sharply with India s inclusive and research-driven approach. For North East India, which is part of this national effort, the lack of a similar framework could create a divide between the region s digital growth and its cybersecurity preparedness. To bridge this gap, the region may need to adopt a more adaptive and inclusive approach to AI regulation, one that engages with both open-source and proprietary models while defining clear risk criteria.

Looking Ahead: The Need for a More Inclusive Framework

As North East India continues to embrace AI-driven solutions, the need for a robust and inclusive cybersecurity framework becomes increasingly clear. The Trump administration s approach, which excludes open-source models and lacks clear definitions for national security risks, risks leaving the region and the broader Indian digital ecosystem vulnerable to cyber threats. Instead, policymakers should consider a framework that fosters collaboration between public and private sectors, engages with the open-source community, and establishes clear, transparent criteria for assessing AI risks. This would not only enhance security but also encourage innovation and ensure that AI is used to address the unique challenges facing North East India.

For the region, this means investing in cybersecurity training for developers and administrators, promoting open-source audits, and working with international partners to share best practices. It also means ensuring that AI systems deployed in critical infrastructure are regularly tested and updated to mitigate risks. By adopting a more inclusive and adaptive approach to AI regulation, North East India can harness the full potential of AI while safeguarding its digital future. The time to act is now, before the region falls behind in this critical area of technological advancement.