Light Blue Arrow Right
Back to Publications & Events

SEBI Advisory on AI-Driven Vulnerabilities

0 mins read

Share

Background

Anthropic’s recent Artificial Intelligence (“AI”) model, Mythos, has quickly gained notoriety for being capable of autonomously identifying undiscovered vulnerabilities across IT systems and software. Mythos’ unprecedented ability to identify and exploit vulnerabilities has sent alarm bells ringing throughout financial institutions and regulators, as it raises serious concerns regarding the security of critical digital infrastructure, including financial market systems.

The Government of India has also taken cognisance of this, and a few weeks ago, on April 23, 2026, the Finance Ministry convened a high-level meeting with the Reserve Bank of India (“RBI”), bank heads, the National Payments Corporation of India (“NPCI”), the Ministry of Electronics and Information Technology, and CERT-In, directing that immediate pre-emptive measures be taken to secure IT systems, and to protect customer data.

SEBI’s Advisory

Against this backdrop, SEBI issued a circular dated May 5, 2026 (“Advisory”) addressed to regulated entities, including stock exchanges, depositories, clearing corporations, stockbrokers, mutual funds, alternative investment funds, portfolio managers, merchant bankers, and others (“REs”), cautioning them against cybersecurity risks posed by advanced “AI-driven vulnerability identification tools”, specifically citing Mythos. The following paragraphs provide an overview of the key aspects of the Advisory.

Risk Identified

SEBI identifies three dimensions of risk arising from AI-driven vulnerability detection tools. First, the speed and scale at which such tools operate heightens the risk of identification and exploitation of existing vulnerabilities in REs’ systems. Second, their use introduces concerns regarding data confidentiality and application integrity. Third, given the interconnectedness of market participants in the securities market ecosystem, a vulnerability at any single point risks a cascading impact across the ecosystem.

Constitution of the Cyber-Suraksha.ai Task Force

To coordinate efforts to mitigate risks arising out of such AI tools, SEBI has constituted a task force named cyber-suraksha.ai (email: project-cyber-suraksha.ai@sebi.gov.in), comprising representatives from market infrastructure institutions (“MIIs”), qualified registrars and transfer agents (“QRTAs”), all qualified regulated entities (“QREs”), and other stakeholders. A first meeting was convened with MIIs and QRTAs prior to the issuance of the Advisory.

The Task Force’s mandate

The mandate of cyber-suraksha.ai covers four functions.

• First, to examine the cybersecurity risks posed by AI-based models and devise a uniform mitigation strategy.

• Second, to facilitate sharing of threat intelligence, best practices on vulnerability management, and playbooks for responding to identified threat vectors.

• Third, to report on a priority basis any cyber incidents, malicious activities, significant attack vectors, and vulnerability disclosures relevant to the securities market.

• Fourth, to review the cybersecurity posture of third-party application service providers, including empanelled vendors.

Directions to Regulated Entities

The following actionables have been set out in the Advisory:

Patching and Vulnerability Assessment: All REs are required to update operating systems and applications with the latest patches immediately. Where patches are unavailable, virtual patching is to be adopted as an interim measure. REs must conduct vulnerability assessments using both conventional and AI-based vulnerability assessment tools (where possible), and undertake security audits on a regular or continuous basis in accordance with the CSCRF.

Third-Party Vendor Management: REs are to engage their third-party vendors to release and deploy timely patches. Stock exchanges and depositories are specifically directed to require their empanelled application vendors to undertake comprehensive assessments of risks arising from AI-led vulnerability detection models, and to implement appropriate safeguards including patching, vulnerability assessment and penetration testing, continuous monitoring, and hardening measures.

Change Management: Any change to systems, including minor changes, must include full documentation, impact analysis, structured review, rigorous testing, and secure deployment.

API Security: REs are required to maintain an updated inventory of all APIs and the applications using them, and to implement strong authentication and authorisation mechanisms on a least-privilege basis.

SOC Monitoring: Day-to-day monitoring of systems and networks must be carried out vigorously, with all Security Operation Centre (“SOC”) alerts including low-priority alerts adequately examined. All eligible REs not yet onboarded with the Market Security Operations Centre (“M-SOC”) established by the NSE and BSE are directed to expedite that onboarding. MIIs are required to conduct awareness programmes and periodic workshops to facilitate smooth onboarding and integration with M-SOC.

Risk Assessment: Risk assessments under the CSCRF must include scenario-based testing for AI-based cybersecurity risks, in addition to existing internal and external risk scenarios.

Our View

The Indian securities market has  previously witnessed data breaches, ransomware attacks, and system intrusions targeting stockbrokers, exchanges, and other institutions. These incidents reflect the growing sophistication of cyber threats, further aggravated by the increasing use of AI-based tools by malicious actors. The Advisory is SEBI’s response to this environment, and represents a renewed focus on cybersecurity within the securities market ecosystem.

In substance, the Advisory is a refresher to the obligations that already exist under the CSCRF. REs may consider treating it as a trigger for a review of their CSCRF compliance posture, particularly in view of the heightened threat posed by advanced AI-based tools. It remains to be seen whether SEBI will follow this Advisory with more granular directions on AI governance within the securities market ecosystem, and how SEBI approaches such aspects during inspection and / or enforcement actions.

You can mail us your queries and comments at Yash Vardhan.

No items found.

Recent

Trackers