security
May 6, 2026
By Teun
India warns equities firms to brace for AI-driven cyberattacks
India’s securities regulator has told market participants to review security controls and prepare for AI-assisted vulnerability exploitation, citing tools such as Anthropic’s Mythos. The advisory asks firms to strengthen basics like patching, API security, zero-trust networking, and SOC monitoring.
India’s Securities and Exchange Board has told companies in the country’s equities industry to immediately review their information security systems and practices, warning that AI tools designed to find vulnerabilities could fuel a wave of cyberattacks.
The regulator, which acts as India’s equivalent of the US Securities and Exchange Commission or the UK’s Financial Conduct Authority, issued an advisory on Tuesday. In it, the board said emerging technologies such as AI-driven vulnerability identification tools, citing Anthropic’s Claude Mythos as an example, have created “new dimensions of risks” for regulated entities.
According to the advisory, such tools can increase the risk of attacks by helping attackers identify and exploit weaknesses at speed and scale. The board also said the technology raises concerns around data confidentiality, application integrity, and the reliability of outputs.
To respond to those risks, the regulator has created a taskforce that will examine threats posed by models like Mythos, share threat intelligence, report incidents, and review the cybersecurity of third-party software vendors that supply the board and the entities it oversees.
The advisory also lays out a set of basic security measures. It tells firms to keep patches up to date, audit for vulnerabilities, inventory APIs and secure them, run a serious security operations center, or SOC, and harden systems using zero-trust networking and only essential services.
A SOC, or Security Operations Center, is the team and tooling used to monitor security alerts, investigate suspicious activity, and respond to incidents. The regulator said firms should take guidance from such teams rather than treat them as a back-office function.
India’s board also told market participants to have their IT committees issue guidance on how to reduce risks from AI-led vulnerability detection models. It asked them to develop a plan for using AI in their own security work as well.
The advisory specifically mentioned “AI accelerated threats,” “AI-augmented SOC transformation,” and continuous vulnerability management using AI tools. In practice, that means the regulator wants firms to prepare for faster attacks while also using AI to help spot and manage weaknesses.
The direction was sent to 19 classes of entity in India’s equities markets. Those include venture capital firms, merchant bankers, mutual funds, stock exchanges, and service providers such as agencies that store know your customer, or KYC, information.
Other regulators have also begun responding to the risks posed by Mythos. According to the article, US Treasury Secretary Scott Bessent held an emergency meeting with banks a few weeks ago, Singaporean regulators did the same yesterday, Australian regulators warned local banks to develop AI strategies that address the risks, and Hong Kong’s Monetary Authority is working on new security guidance.
India’s approach stands out because it directly tells regulated firms to assume the threat is immediate and act now to reduce exposure.