SEBI chief flags AI-driven cyber threats as top risk to market integrity
Synopsis
Key Takeaways
Securities and Exchange Board of India (SEBI) Chairman Tuhin Kanta Pandey on 18 May identified artificial intelligence-driven cybersecurity threats as one of the gravest risks confronting India's financial markets, urging regulators and market participants to adopt aggressive defensive measures across all software systems — including those supplied by third-party vendors.
What SEBI's Chairman Said
Speaking during an interaction with a financial news channel, Pandey drew a sharp distinction between the types of AI-related risks currently on SEBI's radar. Rather than market manipulation or algorithmic trading abuses, he said the immediate concern lies squarely in cybersecurity vulnerabilities.
'Most of the recent concerns around AI tools are related to cybersecurity. As you know, markets rely heavily on software systems, and if cybersecurity is threatened or vulnerabilities are found in the software, there is a risk of attacks. If such attacks are successful, they can pose a serious threat to market integrity,' Pandey said.
Key Safeguards SEBI Is Pushing For
The SEBI chairman outlined a multi-layered defensive posture that he believes must become standard practice across the financial ecosystem. He called for aggressive patch management, continuous vulnerability assessments, and the extensive use of conventional security tools to detect and close weaknesses before they can be exploited.
'We have to proactively ensure that all the software we deploy, including those provided by third-party vendors, is well protected. There has to be aggressive patch management and extensive use of conventional tools to identify vulnerabilities, so that any weaknesses are immediately patched,' Pandey added.
The Broader AI Threat Landscape
Pandey's remarks arrive amid escalating global and domestic concern over the rapid advancement of AI systems with offensive capabilities. Regulatory attention has recently focused on Anthropic's Mythos AI model, which has reportedly demonstrated the ability to autonomously identify and exploit vulnerabilities in major operating systems and internet browsers — a development that has alarmed policymakers across sectors.
Notably, Union Finance Minister Nirmala Sitharaman had previously raised concerns about the potential risks associated with Mythos, signalling that AI-linked cyber threats are now a cross-ministerial priority at the highest levels of the Indian government.
Why This Matters for Indian Markets
India's financial market infrastructure — spanning stock exchanges, depositories, brokerages, and clearing corporations — runs on interconnected software stacks, many of which depend on third-party vendors for critical functions. A successful cyberattack on any node in this chain could cascade into settlement failures, data breaches, or manipulated price discovery.
This is not the first time SEBI has flagged technology risk, but the explicit naming of AI-driven threats marks a sharper escalation in regulatory language. As AI tools grow more capable of autonomous exploitation, the window between vulnerability discovery and weaponisation is shrinking — a reality that market participants can no longer treat as a distant risk.
What Comes Next
SEBI is expected to tighten its cybersecurity framework for market infrastructure institutions in the coming months. Industry observers anticipate updated guidelines that mandate third-party vendor audits, real-time threat monitoring, and mandatory incident reporting timelines. The regulator's stance signals that compliance with basic patch cycles will no longer be sufficient — proactive, intelligence-led defence is the new baseline.