When a government objects to a feature that has not yet launched, over harms that have not yet occurred, and demands the company justify its design choices, something unusual is happening. India’s Ministry of Electronics and Information Technology has done exactly this with WhatsApp’s incoming username feature, a rollout that would let users message one another without exchanging phone numbers. The notice arrived before any documented misuse existed to point at. It arrived before the feature was even live in the country — or anywhere else. And it arrived with parallel demands sent to Telegram and Signal, which have offered similar functionality for years without triggering the same alarm.

The conventional framing here would be familiar: a large democracy managing the fraud risks of a foreign-owned platform, in a country where WhatsApp is the operating layer for banking, small commerce, ticketing, and civic life. Fraud is real, digital arrest scams have harmed Indian citizens, and platform accountability is a legitimate policy question. But that framing misses what actually makes this notice different from previous confrontations between Delhi and Silicon Valley. This is a pre-emptive objection to a design decision, not a response to a documented pattern of abuse. And if it succeeds, the shape of secure communication tools worldwide could quietly reorganise around whatever Indian regulators will tolerate.

What the notice actually asks

On June 29, WhatsApp opened username reservations globally ahead of a phased launch later in 2026, letting users claim handles they will eventually be able to share instead of a phone number. Two days later, on July 1, India’s IT ministry issued a formal notice invoking the Information Technology Act, 2000, along with the IT Rules, 2021, classifying WhatsApp under a category that subjects large platforms to expanded due-diligence obligations.

The ministry directed the platform not to launch the feature until consultations were completed to government satisfaction. WhatsApp asked for more time, promised not to roll out usernames in India during discussions, and submitted its written reply on July 9. The ministry is now reviewing that response. Parallel notices went to Telegram and Signal a day after WhatsApp’s. Arattai, the homegrown app built by Zoho, received no formal notice; its co-founder Sridhar Vembu announced on X that the platform would disable its username feature voluntarily to align with what he called the regulatory change.

The specific concerns the ministry raised are conventional: pseudonymous accounts making phishing easier, impersonation attacks becoming harder to trace, digital arrest scams gaining a new vector. What is unconventional is the timing and the standard being invoked. The Internet Freedom Foundation has noted concerns about objecting to a design before any harm has occurred, and about asking companies to justify a feature to government satisfaction when no provision of the IT Act clearly authorises the ministry to pre-approve platform features.

The evidence gap

Telegram launched with optional public usernames and, for most of its history, without end-to-end encryption by default. Signal has offered username-based signup for years and, as its own transparency documentation shows, collects almost no user data that would be useful to attackers or to law enforcement. If usernames were a meaningful driver of cyberfraud, the pattern would be visible in the data from those platforms already. India’s notice does not cite that data. It does not cite any data.

The underlying logic collapses on inspection: WhatsApp can be misused for cybercrimes. So can email. So can your phone. So can everything. That’s pretty much the definition of infrastructure — it can be used for good and for bad. The question is not whether a communication tool can be abused, because every communication tool can be abused. The question is whether a specific design change materially expands the attack surface in a way that other, less privacy-protective changes would not.

Privacy advocates have noted the absence of evidence demonstrating that Telegram and Signal’s username features have led to a notable increase in cybercrime. The absence of that argument is the story. Governments regularly restrict platforms after harm is documented. Restricting a feature before it launches, in a market where it hasn’t been available, on the theory that it might cause harm not yet demonstrated in other markets, is a different kind of regulatory act.

What the feature actually does

The username rollout is not, technically, an anonymity feature. Users still need a phone number to register for WhatsApp. What changes is what other users can see and what they need to initiate a conversation. The company has held back high-profile names — public figures, government entities, celebrities, verified Meta accounts — so they can only ever be claimed by their legitimate owners, and lookalike derivatives of known names are held as well.

Beyond name-squatting protections, WhatsApp has built in rate limits on how many new contacts an account can initiate conversations with, blocks on repeated guessing of usernames, and detection systems designed to catch impersonation patterns. Someone who wants to message you for the first time via username has to know the exact string, not a fuzzy match. Law enforcement retains the same legal channels for identifying users behind a username that they have for identifying users behind a phone number, because the phone number is still tied to the account on WhatsApp’s side.

The feature protects people who face harassment or political retaliation and who need to separate an online identity from an offline one. Journalists working with sources. Domestic abuse survivors coordinating with support networks. Activists in jurisdictions where a phone number links directly to a state-issued ID. Members of minority communities whose numbers, once known, can be weaponised into doxxing campaigns.

The precedent problem

India is WhatsApp’s largest market by a wide margin, with over 850 million users by some estimates. When a market that large asks a platform to modify a core feature, the platform faces a hard commercial choice: ship a different version in India, ship the reduced-privacy version globally, or delay the feature everywhere while it negotiates.

The moment you concede something in one jurisdiction and make it known as something that is possible to do technically, other countries will follow suit. Most governments around the world are vying to co-opt the kind of power and access that technology companies have over people’s lives and personal data.

The pattern has played out before, in adjacent domains. Once a platform demonstrates it can geofence a feature for one regulator, every other regulator with a domestic political incentive to do the same discovers that the technical objection they were previously told about no longer applies. The refusal becomes a policy choice rather than an engineering constraint. And policy choices, unlike engineering constraints, can be litigated, lobbied, and pressured.

The architecture argument

Framing usernames as a discretionary feature toggle understates what the change involves. Contact discovery, spam prevention, key management, and abuse detection are all built around the assumption of a phone-number-anchored graph. Moving to optional usernames is a rather large overhaul from an architectural point of view. Shipping two versions of that architecture, one for India and one for everywhere else, means maintaining two security models, two threat surfaces, and two update cycles indefinitely.

Shipping different versions in different jurisdictions risks weakening privacy protections incrementally, one market at a time, and that does not bode well for citizens, journalists, and anyone who wants privacy without being treated as a suspect. The end state of that process is not a global standard for secure messaging. It is a patchwork of national dialects of security, each one shaped by whichever ministry pushed hardest at whichever moment.

India’s regulatory playbook

None of this is happening in isolation. India has spent several years building a distinctive posture toward global platforms, one that treats digital infrastructure as an extension of state policy rather than as a neutral utility. The success of UPI is the positive expression of that posture: a public rail that has scaled to the point where India’s UPI now processes more daily transactions than Visa and Mastercard combined globally. The confrontation with WhatsApp over encryption traceability is the harder edge.

In 2021, WhatsApp sued the Indian government over rules requiring traceability of who originally sent messages, a requirement the company argued was incompatible with end-to-end encryption. That case is still winding through the courts. The current notice sits inside the same broader regulatory arc: the state asserting the right to shape platform design decisions, with the IT Rules as the statutory anchor.

A public notice is a less harsh form of regulation than blocking or investigating the service. Historically, product design questions between governments and Big Tech have been hashed out privately. Doing it in the open, via formal notice, has some transparency benefits. But the question of government overreach and control remains.

The censorship-by-feature-review problem

What makes the WhatsApp notice worth watching outside India is not that it is uniquely aggressive by global standards. It is that it opens a new lane of regulatory action: not blocking a service, not demanding content takedowns, not requiring data localisation, but vetoing a design decision before deployment. The closest parallels are found in industries with formal pre-market approval regimes, like pharmaceuticals or aviation. Applied to communication tools, that model quietly reassigns the design authority from engineers and privacy teams to whichever ministry has the political appetite to invoke it.

There is a version of this argument that sounds reasonable on its face. Platforms have enormous power over public life; some public accountability for their design choices seems appropriate. The problem is the standard being applied: a requirement for government satisfaction is not a legal test, harm test, or proportionality test, but rather a discretionary veto, and the discretion sits with the same executive branch that would benefit most from being able to identify pseudonymous critics.

This pattern of regulatory tools with narrow stated purposes and broad practical uses is not confined to India. Silicon Canals has reported on how immigration law is becoming a quiet censorship tool in the United States, applied to speech that would be constitutionally protected if the speaker held a different passport. The mechanism differs. The dynamic — a legal instrument stretched beyond its stated purpose because the stretch happens to serve executive convenience — is the same.

What the fraud argument gets right, and what it gets wrong

The Indian government’s concern about digital fraud is not manufactured. Cybercrime reporting in India has risen sharply over the past five years, digital arrest scams have become a national phenomenon, and WhatsApp has been the delivery mechanism for a meaningful share of that harm. The company has responded, over time, by adding forwarding limits, labels on forwarded messages, and various law-enforcement compliance mechanisms. None of that is nothing.

But the fraud argument for delaying usernames rests on an assumption that phone numbers currently function as a meaningful identity check. They do not. Indian scammers routinely use burner SIMs, SIM-swap attacks, and international numbers. The phone number in a scam message is almost never the scammer’s real identity; it is a disposable input. Delaying usernames on WhatsApp does not remove the burner SIMs from the ecosystem. It only removes a privacy layer from the users who are not the scammers.

The people who lose the most from a phone-number-only identity requirement are the ones who need pseudonymity for legitimate reasons: sources, survivors, activists, minorities whose numbers double as identifiers to power. Scammers, by contrast, are already pseudonymous by design. A rule that tightens the identity requirement on the compliant platforms without touching the burner-SIM economy trades a real privacy protection against a marginal enforcement gain against fraud that will continue regardless.

That trade-off is the reason the WhatsApp notice matters beyond India. If a pre-launch feature veto becomes a normal tool of platform regulation, the platforms that survive best are the ones whose design accommodates whichever government has the strongest political incentive to intervene. The end state is not a safer messaging ecosystem. It is a slower and narrower one, shaped less by what protects users and more by what a ministry will tolerate.