on the Telegram, WhatsApp and BitChat Executive Orders [Guest Post] – Constitutional Law and Philosophy

0
9
ADVERTISEMENT

[This is a guest post by Siddharth Aiyar.]


Between June and July 2026, multiple developments in the platform regulation space indicated a shift in how regulation is set to evolve in India. First, in June 2026, in the case of Telegram FZ LLC v. Union of India, the Delhi High Court upheld the Central Government’s decision to temporarily block the Telegram platform across India and disable its message editing feature in exercise of the powers granted under Section 69A of the Information Technology Act, 2000 (“IT Act”) on the grounds that the architecture of Telegram made dissemination of unlawful information possible in the context of the NEET Re-examination.

SPONSORED

In July, the Ministry of Electronics and Information Technology (“MeitY”) and the Indian Cybercrime Coordination Centre (“I4C”) both issued (separate and independent) notices to WhatsApp and Bitchat, invoking different provisions of the IT Act and Rules: (1) MeitY directed WhatsApp to hold off on introducing its “username” feature, and (2) I4C directed GitHub to remove code repositories of BitChat: a Bluetooth based messaging platform which operated despite internet shutdowns in response to the recent protests in New Delhi.

What is interesting here is the grounds on the basis of which these three distinct decisions were made. MeitY’s order cited concerns that anonymity offered as a function of the “username” feature could be exploited, leading to increasing cyber-crimes, such as phishing or impersonation. The I4C’s order stated that the architecture of BitChat would “impede lawful interception, attribution and investigation by law enforcement agencies” in relation to the protests in New Delhi. The Delhi HC judgment upheld the Central Government’s blocking order on the grounds that the definition of “information” under Section 2(1)(v) of the IT Act would extend to the architecture of the platform itself.

The constitutionality of these three actions has been hotly debated (see here, here and here), but what is worth observing is that all three decisions argue that the architecture of their respective platforms, and the possibility of misuse as a result of this architecture pose a threat sufficient to warrant restrictions on platform rights, although they invoke different provisions that enable restrictions on such content.

We must note that these three decisions are not equivalent: only the Telegram judgment reflects judicial endorsement of architecture as a constitutionally relevant nexus. The MeitY and I4C actions are, at present, exercises of executive power whose constitutional validity is yet to be tested. The risk we will discuss is that once a court validates architecture-as-nexus reasoning in one context, the same reasoning can potentially migrate into executive action, since platforms have every incentive to comply. So, what happens once architecture becomes the object of regulation?

Through this essay, I argue that this shift in constitutional scrutiny, from content to architecture, shifts the goalposts of proportionality of restrictions on free speech—giving the State far too much breadth in terms of regulatory discretion. For the purposes of this essay, “platform architecture” refers to technical design choices that determine how information flows, is stored, attributed or accessed, independent of the content carried.

Proximate Nexus, Proportionality and Everything in Between

The Supreme Court in Anuradha Bhasin v. UoI clarified that restrictions placed on free speech under Article 19(1)(a) of the Constitution—as is the case with the manner of platform regulation propounded through our case studies—must be: (1) in pursuance of a legitimate goal (such as the “reasonable restrictions” under Article 19(2)); (2) must have a proximate nexus to said goal; (3) must be the least restrictive measure to achieve said goal, and; (4) must be balanced proportionally with civil liberties. Of interest to us is point (2).

The idea of proximate nexus was most seminally introduced in Superintendent, Central Prison, Fatehgarh v. Ram Manohar Lohia, where the Supreme Court struck down a law that penalised instigating others not to pay government dues, holding that the State could not restrict speech based on “remote or fanciful” connections to public order. That is, the legitimate goal cited by the Government—i.e., protection of public order—must be genuinely at risk as a direct result of the speech/expression that is being limited. This idea of a direct risk was further developed by the Supreme Court across two judgments: Kedar Nath Singh v. State of Bihar, and S. Rangarajan v. P. Jagjivan Ram.

In Kedar Nath Singh, the Supreme Court, while upholding the constitutionality of sedition law, held that for a restriction on speech to be valid, such speech must have a “pernicious tendency or intention” of creating public disorder. That is, either the State must establish a high likelihood of public disorder, or an active intent on part of the accused to manufacture public disorder. Nonetheless, the evidentiary bar on the State was set very high, and even made distinctions between “mere discussion” or “advocacy” of even radical views (which is protected) and incitement to illegal acts. This logic was extended in S. Rangarajan, where the Supreme Court introduced the “spark in a powder keg” test, where the expression must be “inseparably locked up” with the harm that the restriction looks to prevent. Gautam Bhatia argues that this means that the “connection (between the expression and the harm) is proximate not only in the sense of statistical probability, but in a way that provides no scope for any different outcome that could have come about had the actor (the recipient of the expression) been able to meaningfully exercise her autonomous choice.”

In the digital space, the Supreme Court’s ruling in Shreya Singhal v. UoI is instructive. First, the Court established that freedom of expression online is entitled to the same level of constitutional protection as offline media, which ensured that the guardrails and tests introduced with respect to traditional media apply as is to the online space as well. Next, drawing on the ratio from Kedar Nath Singh, the Court distinguished between “discussion,” “advocacy,” and “incitement,” ruling that the State’s power to restrict free speech only “kicks in,” when the expression is of the nature of incitement—i.e., likely to lead to imminent lawless action—a holding that we must read alongside S. Rangarajan. Furthermore, the Court upheld the constitutionality of Section 69A of the IT Act—the Government’s blocking power, but interpreted it to be narrowly drawn.

Implications on Free Expression

So, a precedential analysis tells us that any form of restriction on free speech and expression, apart from being in pursuance of a legitimate goal and being balanced with existing civil liberties, must be so directly associated with the harm, that the only potential outcome of not imposing such restriction is the harm occurring. We must note that this is not the equivalent of harm being “likely”: the burden of proof on the government is far more stringent. Applying a burden that is any less stringent would enable enforcement of vague laws that capture protected and innocent speech to create an unconstitutional chilling effect. However, the Delhi HC in Telegram FZ LLC, departed from this logic and accepted the State’s argument that the architectural design of Telegram made enforcement futile (with no independent verification), thereby replacing the requirement of a nexus between a message and disorder with a nexus between software architecture and enforcement difficulty.

This ratio legitimizes an overbroad interpretation of the State’s blocking power under Section 69A, and runs the risk of being generalised to be applicable to blocking orders as under Section 79(3)(b). Another consequential risk is the upstream shift of scrutiny—i.e., instead of punishing unlawful conduct after it occurs, the state is now emboldened to question and block platform features (like WhatsApp’s username feature) based on the abstract possibility of future misuse before they are even deployed. At this point, the proximate nexus test ceases to be about whether the expression would inevitably cause an unlawful outcome and more about whether platform control and surveillance is possible in case of an abstract future threat.

From a purely architectural perspective, BitChat is an appropriate case study: the Order targets source code sitting in a repository, pre-deployment and pre-harm, which is a different level of pre-emption than traditional censorship or platform content moderation. The government is attempting to regulate an architectural layer of a platform that could – hypothetically – be used for something risky in the future. If the Telegram judgment is imported into regulatory logic through the BitChat example, it would mean, as Tanmay Durani argues, that the more a platform is architecturally resistant to State intervention or censorship, the easier it becomes for the State to argue that the architecture itself causes potential harm. Compounding this is the absence of a clear “stopping point.” Once resistance to surveillance becomes constitutionally relevant, there is no principled basis for distinguishing BitChat from end-to-end encryption, metadata minimisation, anonymity networks or federated communication protocols. The feature that attracts regulatory scrutiny is no longer unlawful conduct, but resilience to State intervention itself.

The extension of this “no stopping point” logic to proximate nexus creates the threat of a “license raj for software features,” as stated by Nikhil Pahwa. Evidence of this possibility may be gleaned from Arattai’s revocation of its username feature just one day after the MeitY sent its order to WhatsApp—pre-emptive compliance despite the absence of a legislative mandate, an executive order, or even any documented harm for that matter. Furthermore, the fact that WhatsApp had to pause rollout of the username until they could adequately “justify” it, if upheld by courts, would indicate a shift in platform liability, where governments can determine the presence of “potential” harms, and on that basis declare the invalidity of a software, even without any real harms.

One step further, platforms must seek permission from the government to implement software features. Any features that hamper the ability of the government to carry out “lawful surveillance” will not be granted permission to roll out—a regulatory feature that is fundamentally equivalent to the license raj. A problem that emerges from this is the term “lawful surveillance,” as used in the BitChat order. The question of whether or not surveillance (or any such form of intervention) is lawful or not generally emerges as an ex-post fact, after the surveillance is carried out, when it is questioned in a court of law (or any appropriate forum) on a case-by-case basis (see PUCL v. UoI (1997) and Justice (Retd.) K.S Puttaswamy v. UoI (2017)). The compliance requirement here is ex ante—prior to the surveillance and evaluation of lawfulness. Access for “lawful” surveillance cannot be encoded in its entirety as the term “lawful” is a matter for constitutional consideration. Therefore, a platform seeking to ensure regulatory compliance has every incentive to construct its systems so as to facilitate all forms of State access, irrespective of their eventual legality.

This reinterpretation of proximate nexus has consequences beyond the second limb of the Anuradha Bhasin test. Once architecture is accepted as the constitutionally relevant nexus to harm, architectural regulation becomes an “automatic” next step, rather than questioning whether architecture ought to be regulated at all. The proportionality analysis is likewise affected, as courts may balance competing architectural solutions instead of first considering whether less intrusive interventions directed at content, users or conduct would sufficiently achieve the State’s objective.

Addressing the State’s Concerns and Concluding Thoughts

However, dismissing the State’s concerns would be unwise. It is true that emerging technologies make regulation of unlawful content on platforms increasingly more difficult, but, as we have discussed, regulatory responses that shift enforcement from content-level to platform-level and architectural design are constitutionally suspect and disproportionate. The challenge, therefore, becomes to modify the existing constitutional baseline to ensure an appropriate balance. With this in mind, we propose a three-fold test that may be applied in situations where the State may perceive the architecture of the platform to be limiting its lawful powers to restrict free expression. This test presumes that the lawful object is already established.

First, on proximate nexus: Here, the State must be able to demonstrate that ordinary operations of the platform without the impugned restriction is inseparable from the harm that the State is attempting to prevent. The State may attempt to argue that S. Rangarajan’s “spark in a powder keg” test is too stringentgiven the architecture of the platform—a reasonable concern, but the SC’s ruling in Shreya Singhal is instructive, platform neutrality applies, and the protection remains just as stringent, irrespective of the architecture of the platform. Revising this test is a judicial matter.

Second, on “least restrictive means”: This test requires a layered approach, since the term “least restrictive” must be benchmarked against possible State actions. One of the arguments Telegram put forth was that it was able to disable 900 out of 1,300 flagged URLs communicated to them by the MeitY. The Court did not clarify why this procedure would be inadequate to address the relevant risks. In order to adequately determine whether a proposed restriction is truly the least restrictive means, the State must identify: (a) Can individual content be removed? (b) Can users be targeted? (c) Can platform moderation solve it? If these three questions are sufficiently answered in the negative, only then can alteration of platform architecture be considered.

Third, on proportionality and impact: Unlike content removal, architectural interventions affect every lawful user of the platform and may have lasting consequences for privacy, security, anonymity, innovation and free expression. These systemic costs must be expressly accounted for in the proportionality analysis.

This framework, however, does not fully resolve the concern identified in this piece. A doctrinal test, however rigorous, constrains the State only once it exercises its power; it cannot prevent platforms from redesigning or withdrawing features in anticipation of regulatory intervention, whether driven by commercial or political incentives. Arattai’s decision to revoke its username feature before receiving any formal direction from MeitY shows us this. That decision would remain commercially rational even under the proposed framework, as no constitutional safeguard operates upon a platform’s voluntary decision to avoid prospective regulatory scrutiny. The source of this incentive is not the absence of doctrine, but the existence of regulatory uncertainty itself, which, at best, can be limited by constitutional safeguards on State actions.

This article does not suggest that the answers proposed here are definitive. Rather, it argues that the questions themselves have changed. Indian free-speech jurisprudence was developed in an era where the object of regulation was expression; platform governance increasingly places software architecture in that position. If that shift is to be constitutionally sustainable, the principles articulated in Anuradha Bhasin will require a corresponding application to architecture. The framework suggested here is merely one possible starting point.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here