-
India’s market regulator SEBI has set up a special task force called cyber-suraksha.ai.
-
The team will study how AI tools, including one called Claude Mythos, could speed up cyberattacks.
-
SEBI has told finance firms to patch systems fast and join a live threat-monitoring platform.
The Securities and Exchange Board of India (SEBI) built a new task force this month. It goes by the name cyber-suraksha.ai. The team’s job is to study fresh cyber risks that come from fast-moving AI tools.
SEBI pointed to AI-driven programs that can spot weak points in computer systems. Claude Mythos was named as one example of this kind of tool. According to India’s SEBI’s circular, these tools bring new kinds of risk for regulated firms. The regulator said such technology moves fast and can find gaps in a system quicker than before. That speed could also let bad actors misuse the same tools.
Markets in India connect many firms and systems together. A breach in one place can spread trouble to others fast. SEBI said this connected setup means everyone must work as one team. Firms need to share information and watch their systems non-stop.
Why SEBI Built this Task Force
SEBI issued a circular on May 5, 2026, from its office in New Delhi. The circular carries the number HO/13/19/12(1)2026-ITD-1. It laid out the plan for the new task force.
The team brings together several groups. These include Market Infrastructure Institutions, known as MIIs, and Qualified Registrars and Transfer Agents, called QRTAs. Regulated entities and other stakeholders also joined the group.
Their job covers several tasks. They will study cyber risks tied to AI models closely. They will also build one shared plan to lower those risks. The task force will share threat information and best practices across all member firms. This includes real cases and response guides for future threats.
On the other side of the world, the U.S. government has taken a different approach to tackling cybercrime. In August 2026, President Donald Trump signed a National Security Presidential Memorandum that authorizes vetted private companies to conduct offensive cyber operations, including surveillance and disruption, against foreign cybercriminal networks.
SEBI also wants firms to report cyber incidents fast. Any strange activity or new weak spot must go up the chain right away. The regulator called this a priority step for every firm involved.
New Rules for Firms to Follow
SEBI held a meeting where the task force looked closely at AI-based risks. The group also talked about ways to lower those risks. After that meeting, SEBI released fresh guidance for regulated firms.
Firms must patch their systems right away. Old software often carries known weak spots that attackers can find fast. SEBI wants every firm to close those gaps without delay.
Regular checks matter too. SEBI told firms to run vulnerability tests often, and it said firms can use AI tools for this work as well. Vendor risk checks made the list too. A firm’s outside partners can open a door for attackers if left unchecked.
Change management also needs stronger rules. Any update to a system should follow a clear, safe process. SEBI also pushed for tighter API security. APIs let different systems talk to each other, so a weak API can expose whole networks.
SEBI wants firms to join the Market Security Operations Centre too. People call this the Market-SOC. The platform gives real-time alerts about new threats as they happen. Stock exchanges NSE and BSE built and run this system.
What Comes Next for India’s Markets
SEBI does not want this to be a one-time fix. The regulator asked firms to run risk checks on a regular schedule going forward. Firms should also work on system hardening over time. Keeping asset records updated matters too. A firm needs to know exactly what systems and devices it runs. Old or forgotten records can hide real risks.
SEBI also asked firms to think long term. It wants each firm to build a lasting plan for using AI safely in cyber defense work. This is not just about today’s threats, but about staying ready for new ones.
This story is still developing, and firms are only beginning to act on the new guidance. No confirmed cyberattack tied to Claude Mythos or any other AI tool has been reported so far. SEBI named the tool only as an example of the kind of technology that raises new risks.
For now, the message from SEBI stays simple. Patch fast, watch closely, and work together. In a market this connected, one weak link can affect everyone.