SEBI chief flags AI-driven cyber threats as top risk to market integrity

Share:
Audio Loading voice…
SEBI chief flags AI-driven cyber threats as top risk to market integrity

Synopsis

SEBI Chairman Tuhin Kanta Pandey has named AI-driven cybersecurity threats — not algo manipulation — as the single biggest risk to India's financial markets, citing the danger of software vulnerabilities being autonomously exploited. With Anthropic's Mythos AI reportedly capable of breaching major operating systems, and Finance Minister Sitharaman already alarmed, this is no longer a fringe concern — it is a regulatory emergency in the making.

Key Takeaways

SEBI Chairman Tuhin Kanta Pandey identified AI-driven cybersecurity threats as the most significant risk to India's financial market integrity on 18 May .
Pandey called for aggressive patch management , continuous vulnerability assessments , and strong protection of third-party vendor software .
His concern centres on cybersecurity vulnerabilities, not market manipulation or algorithmic trading risks from AI.
Anthropic's Mythos AI model has reportedly demonstrated the ability to autonomously exploit vulnerabilities in major operating systems and browsers.
Finance Minister Nirmala Sitharaman had earlier raised concerns about risks associated with the Mythos model.
SEBI is expected to tighten its cybersecurity framework for market infrastructure institutions in the coming months.

Securities and Exchange Board of India (SEBI) Chairman Tuhin Kanta Pandey on 18 May identified artificial intelligence-driven cybersecurity threats as one of the gravest risks confronting India's financial markets, urging regulators and market participants to adopt aggressive defensive measures across all software systems — including those supplied by third-party vendors.

What SEBI's Chairman Said

Speaking during an interaction with a financial news channel, Pandey drew a sharp distinction between the types of AI-related risks currently on SEBI's radar. Rather than market manipulation or algorithmic trading abuses, he said the immediate concern lies squarely in cybersecurity vulnerabilities.

'Most of the recent concerns around AI tools are related to cybersecurity. As you know, markets rely heavily on software systems, and if cybersecurity is threatened or vulnerabilities are found in the software, there is a risk of attacks. If such attacks are successful, they can pose a serious threat to market integrity,' Pandey said.

Key Safeguards SEBI Is Pushing For

The SEBI chairman outlined a multi-layered defensive posture that he believes must become standard practice across the financial ecosystem. He called for aggressive patch management, continuous vulnerability assessments, and the extensive use of conventional security tools to detect and close weaknesses before they can be exploited.

'We have to proactively ensure that all the software we deploy, including those provided by third-party vendors, is well protected. There has to be aggressive patch management and extensive use of conventional tools to identify vulnerabilities, so that any weaknesses are immediately patched,' Pandey added.

The Broader AI Threat Landscape

Pandey's remarks arrive amid escalating global and domestic concern over the rapid advancement of AI systems with offensive capabilities. Regulatory attention has recently focused on Anthropic's Mythos AI model, which has reportedly demonstrated the ability to autonomously identify and exploit vulnerabilities in major operating systems and internet browsers — a development that has alarmed policymakers across sectors.

Notably, Union Finance Minister Nirmala Sitharaman had previously raised concerns about the potential risks associated with Mythos, signalling that AI-linked cyber threats are now a cross-ministerial priority at the highest levels of the Indian government.

Why This Matters for Indian Markets

India's financial market infrastructure — spanning stock exchanges, depositories, brokerages, and clearing corporations — runs on interconnected software stacks, many of which depend on third-party vendors for critical functions. A successful cyberattack on any node in this chain could cascade into settlement failures, data breaches, or manipulated price discovery.

This is not the first time SEBI has flagged technology risk, but the explicit naming of AI-driven threats marks a sharper escalation in regulatory language. As AI tools grow more capable of autonomous exploitation, the window between vulnerability discovery and weaponisation is shrinking — a reality that market participants can no longer treat as a distant risk.

What Comes Next

SEBI is expected to tighten its cybersecurity framework for market infrastructure institutions in the coming months. Industry observers anticipate updated guidelines that mandate third-party vendor audits, real-time threat monitoring, and mandatory incident reporting timelines. The regulator's stance signals that compliance with basic patch cycles will no longer be sufficient — proactive, intelligence-led defence is the new baseline.

Point of View

And third-party software is historically the weakest link in any cybersecurity chain. The reference to Anthropic's Mythos model — and Sitharaman's prior alarm — suggests the government has specific intelligence, not just general anxiety. SEBI's next cybersecurity circular will be closely watched; if it stops at patch-management advisories without binding audit requirements on vendors, it will fall well short of the urgency Pandey's own words imply.
NationPress
10 Aug 2026

Frequently Asked Questions

What cybersecurity risk did SEBI Chairman Tuhin Kanta Pandey warn about?
Pandey warned that AI-driven cybersecurity threats are the most significant risk facing India's financial markets. He said vulnerabilities in software systems — including those from third-party vendors — could be exploited by AI tools to launch attacks that directly threaten market integrity.
Why is AI seen as a cybersecurity threat to financial markets?
Financial markets depend on interconnected software systems for trading, settlement, and data management. Advanced AI models can reportedly identify and exploit software vulnerabilities autonomously, shrinking the time between a flaw being discovered and it being weaponised — a risk SEBI now considers more immediate than AI-driven market manipulation.
What is Anthropic's Mythos AI model and why is it a concern?
Anthropic's Mythos AI model has reportedly demonstrated the capability to autonomously identify and exploit vulnerabilities in major operating systems and internet browsers. Both SEBI and Finance Minister Nirmala Sitharaman have flagged it as a potential risk to financial and digital infrastructure.
What measures has SEBI called for to address AI cyber threats?
SEBI's chairman has called for aggressive patch management, continuous vulnerability assessments, and strong protection mechanisms for all deployed software, including systems provided by third-party vendors. The regulator is expected to update its cybersecurity framework for market infrastructure institutions in the coming months.
Who else in the Indian government has raised concerns about AI cybersecurity risks?
Union Finance Minister Nirmala Sitharaman had previously raised concerns about the potential risks associated with the Mythos AI model, indicating that AI-linked cybersecurity threats have become a priority at the highest levels of the Indian government, beyond just the financial regulator.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 3 weeks ago
  2. 1 month ago
  3. 3 months ago
  4. 3 months ago
  5. 9 months ago
  6. 10 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google