Economy · Explained
Artificial intelligence can make financial services faster and safer - but it can also make fraud, cyberattacks and market disruption faster, cheaper and harder to detect. India’s financial regulators are responding by strengthening cyber resilience, incident reporting, fraud controls and oversight of AI-enabled systems.
In one line
AI adds a new layer to risks that financial institutions already understand. It can amplify identity fraud, phishing, malware, market manipulation, data theft and operational failures by allowing attackers to automate tasks and adapt much faster. RBI is tightening the cyber and technology-resilience framework for banks, while SEBI is building stronger resilience, incident reporting and AI-related oversight for the securities market.
Why AI changes the financial-sector cyber threat
Financial institutions have always been attractive targets because they hold money, sensitive personal data and market-moving information. What AI changes is the speed, scale and sophistication of the attack.
A fraudster no longer needs to write every phishing message, create every fake document or manually study every target. Generative AI can produce convincing messages, translate them into local languages, imitate writing styles and help attackers adapt their approach quickly. Voice cloning and synthetic video can also make a fraudulent caller appear to be a customer, senior executive or other trusted person.
At the institutional level, the risk is broader. Banks, brokers, exchanges, clearing corporations, depositories and fintech firms increasingly depend on interconnected technology, cloud services, application programming interfaces and automated decision systems. A compromise in one part of the chain can therefore create disruption elsewhere.
The major AI threats to financial systems
The Mythos episode shows why the concern is no longer theoretical
One recent development helps put the issue in perspective. In April 2026, Anthropic announced Claude Mythos Preview, a frontier AI model whose cybersecurity capabilities were considered too powerful for a normal public release. The model demonstrated a much stronger ability to find software vulnerabilities and carry out parts of complex cyber operations. Anthropic also reported that some of these capabilities emerged from general improvements in coding, reasoning and autonomy rather than from a narrowly designed cyber programme.
Mythos was not a financial-sector attack. That distinction matters. But the episode showed what could happen when advanced AI is combined with the large digital attack surface of banks, exchanges and payment systems. A faster vulnerability-discovery process can reduce the time available to detect, patch and contain an attack. In July 2026, Reuters reported that Canada's banking regulator had specifically cited the Mythos threat when warning financial institutions about the changing cyber-risk environment.
Interactive: Explore the main AI-enabled threats
Select a threat to see what it means in the financial sector.
1. Deepfakes turn trust into an attack surface
Consider a simple example. An employee receives a video call that appears to come from a senior executive asking for an urgent transfer. The voice sounds familiar and the face looks genuine. Traditional awareness training may not be enough when the deception occurs through a convincing voice or video.
This is why the response has to move beyond identifying suspicious messages. Financial institutions increasingly need stronger authentication, transaction controls, anomaly detection, employee awareness and rapid transaction-blocking mechanisms.
2. AI can industrialise phishing and cyberattacks
AI can help attackers create many variations of the same scam, personalise messages and respond to victims in real time. The threat becomes an adaptive campaign rather than a single suspicious email.
3. AI can attack the market-information environment
Financial markets depend heavily on information. A coordinated flood of false news, fake research, fabricated corporate announcements or manipulated social-media narratives can influence investor behaviour even when no trading system itself has been hacked.
4. AI itself can become a source of operational risk
A financial institution may use an AI model for fraud detection, customer service, compliance, risk assessment or investment processes. If the model is poorly trained, manipulated, unavailable or supplied by a weak third-party provider, the institution inherits a new operational dependency.
Why this matters for financial stability
A cyberattack on an ordinary business can be damaging. A cyberattack on a bank, exchange or payment system can have wider consequences because other institutions, businesses and households depend on it.
The concern is therefore not only whether a bank loses money. It is whether a technology failure can interrupt payments, expose customer data, distort market information, prevent trading or settlement, or create a loss of confidence that spreads to other institutions.
RBI: Strengthening the cyber and technology-resilience framework
The risk is not only that a customer may be tricked by a deepfake. A successful attack on a bank, payment system or technology provider can disrupt financial services at scale. RBI has therefore been moving from a largely technology-specific approach towards a broader cybersecurity, technology-risk and resilience framework. A major step came on 31 July 2026, when RBI issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
The framework places cybersecurity firmly inside bank governance. It covers board oversight, IT governance, information-security and cybersecurity policies, risk assessment, baseline cyber controls, incident response, business continuity and resilience. RBI has also issued sector-specific 2026 cybersecurity directions for other regulated categories.
Board-level accountability
Banks are expected to have clear governance structures for IT and cyber risk, including a Board-level IT Strategy Committee and an Information Security Committee.
Continuous cyber surveillance
The framework strengthens security monitoring and requires institutions to maintain the ability to detect, respond to and recover from cyber incidents.
Testing and resilience
Critical systems require regular vulnerability assessment and penetration testing, alongside business continuity and disaster-recovery arrangements.
Incident reporting
Commercial banks are required to report cyber incidents to RBI through the DAKSH platform within six hours of detection under the 2026 framework.
This matters for AI because an AI-enabled attack ultimately has to exploit a real financial institution. Better identity controls, access management, vulnerability testing, monitoring, incident response and recovery reduce the room in which an attacker can operate.
RBI is also building AI capability on the defensive side
RBI's response is not limited to putting more controls around banks. It is also using AI and developing an AI governance framework for the financial sector.
1. FREE-AI: a framework for responsible use of AI
In August 2025, RBI published the report of its Framework for Responsible and Ethical Enablement of Artificial Intelligence, or FREE-AI, committee. The report is important because it treats AI as both an opportunity and a risk. It does not call for simply restricting AI. Instead, it sets out a framework for allowing useful innovation while putting stronger safeguards around it.
The framework is built around seven Sutras: Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; and Safety, Resilience and Sustainability. Its recommendations are organised under six areas: Infrastructure, Policy, Capacity, Governance, Protection and Assurance.
Governance
Regulated entities should have clear responsibility for the AI systems they deploy, including board-approved AI policies and lifecycle controls.
Protection
The framework focuses on consumer protection, cybersecurity, red-teaming and safeguards against harmful or unreliable AI outputs.
Assurance
It points towards AI inventories, audits, disclosures and incident reporting so that AI use can be monitored rather than left as a black box.
Innovation
It also proposes an AI innovation sandbox and financial-sector-specific AI models, showing that RBI's approach is not simply defensive.
2. MuleHunter.AI: using AI against mule accounts
RBI is also using AI to fight a very practical banking problem: mule accounts. These are accounts used to receive and move money obtained through fraud.
RBIH has developed MuleHunter.AI, a supervised machine-learning model designed to identify mule accounts in near real time by learning patterns of suspicious account activity. RBI said the model was being tested and deployed with large public-sector banks and that early results were encouraging. The idea is straightforward: use the same technology that can help criminals scale fraud to help banks identify suspicious money movement earlier.
RBI and the fight against digital-payment fraud
AI-enabled scams are only one part of the wider digital-fraud problem. RBI has therefore also been strengthening customer protection around electronic banking transactions.
In June 2026, RBI finalised a revised framework for limiting customer liability in fraudulent electronic banking transactions. For specified small-value fraudulent electronic banking transactions of up to ₹50,000, the framework provides a compensation mechanism, subject to conditions. The framework is scheduled to take effect from 1 January 2027.
The revised approach also introduced a shadow reversal mechanism for certain fraudulent credit-card transactions, strengthened transaction alerts and expanded protections to areas such as cross-border fraud and sole proprietors.
The proposed “kill switch”
RBI has also been exploring a “kill switch” or switch-on/switch-off facility that could allow customers to rapidly stop digital-payment activity when they suspect fraud. This should be described as an RBI proposal/exploration, not as a universal facility already available across all payment channels.
The idea is simple: when a customer realises that an account or payment credential may have been compromised, the time between suspicion and the next transaction can be critical. A rapid blocking mechanism can create a window for banks and authorities to intervene.
SEBI: Protecting the securities-market technology layer
The Securities and Exchange Board of India faces a different but equally important problem. The securities market depends on stock exchanges, clearing corporations, depositories, brokers, market intermediaries and technology platforms. A disruption to critical systems can affect trading, clearing, settlement and investor confidence.
SEBI’s response in 2026 has increasingly focused on resilience, coordinated cyber response and responsible AI use.
1. IT Resilience Index for Market Infrastructure Institutions
On 24 August 2026, SEBI operationalised an IT Resilience Index (ITRI) framework for Market Infrastructure Institutions (MIIs). Instead of discussing “IT health” vaguely, the regulator wants a system-driven measure of how resilient critical technology systems are.
| ITRI parameter | Weight | What it captures |
|---|---|---|
| Availability | 20% | Whether critical systems remain available |
| Security | 20% | Protection against cyber threats and unauthorised access |
| Integrity | 10% | Whether systems and data remain accurate and trustworthy |
| Governance | 10% | Oversight, accountability and control structures |
| Reliability & monitoring | 10% | Stable performance and continuous visibility |
| Business continuity | 10% | Ability to continue or recover critical operations |
| Modularity & flexibility | 10% | Ability to adapt without creating new vulnerabilities |
| Scalability | 5% | Ability to handle changes in system load |
| Others, including incident handling | 5% | Additional resilience and response capabilities |
MIIs are to compute the index on a half-yearly basis, compare consecutive periods and report corrective action. The first submission is for the half-year ending 30 September 2026. This turns resilience into something that can be monitored over time rather than checked only after an outage.
2. FIRE format for cyber-incident reporting
SEBI has also aligned its cyber-incident reporting portal with a standardised Format for Incident Reporting Exchange (FIRE). A cyber incident is often still unfolding when it is first detected, so the staged reporting approach allows an initial report, intermediate updates and final closure.
3. Cyber Suraksha Portal
On 24 August 2026, SEBI launched the Cyber Suraksha Portal. The platform brings together cyber-related reporting, advisories, incident information and learning resources for the securities-market ecosystem. SEBI’s Cyber Suraksha initiative also includes material on AI-driven emerging cyber threats and defences.
SEBI and responsible use of AI
SEBI’s AI approach is broader than simply stopping hackers. The regulator also has to answer a different question: What happens when a regulated entity itself uses AI?
SEBI’s 2025 consultation on responsible use of AI/ML proposed principles around model governance, continuous risk assessment, exception handling, fallback arrangements, senior-management oversight, third-party vendor management, periodic testing and data governance.
SEBI’s regulatory framework has also placed responsibility on regulated entities using AI/ML applications: the entity remains responsible for protecting investor and stakeholder data, ensuring the accuracy of outputs and complying with applicable laws and regulations, even when the technology is developed or supplied by a third party.
SEBI is also using AI defensively
The relationship between AI and cybersecurity is not one-sided. AI can help defenders identify vulnerabilities, detect unusual behaviour and prioritise security risks.
In May 2026, SEBI issued an advisory on emerging advanced AI tools for vulnerability detection. Its Cyber Suraksha initiative has also focused on AI-driven emerging cyber threats and defences for securities-market participants.
This is an important shift in regulatory thinking: AI is both a risk and a security tool. The objective is not to stop financial institutions from using AI, but to make sure that AI adoption does not outrun governance and resilience.
RBI vs SEBI: What is each regulator focusing on?
| Area | RBI | SEBI |
|---|---|---|
| Core ecosystem | Banks, payment systems and other regulated financial institutions | Exchanges, clearing corporations, depositories and securities-market intermediaries |
| Cyber resilience | 2026 cybersecurity, technology-risk and resilience directions; governance, monitoring, testing and recovery | CSCRF, IT Resilience Index and Cyber Suraksha initiatives |
| Incident response | Six-hour cyber-incident reporting for commercial banks under the 2026 framework | Standardised and staged reporting through the FIRE format |
| Consumer/investor protection | Digital-fraud liability and compensation framework; faster fraud response | Market-integrity, cyber resilience and investor-protection controls |
| AI focus | AI-enabled fraud analytics, digital-payment security and technology resilience | Responsible AI/ML use, market surveillance, vulnerability detection and cyber resilience |
What lies ahead?
The regulatory challenge is that AI is evolving faster than traditional compliance cycles. A rule written for one technology can become less effective when the underlying attack method changes.
Continuous monitoring
Cybersecurity cannot be treated as an annual audit. Institutions need continuous detection, testing, threat intelligence and incident-response exercises.
Accountability for third-party AI
Cloud providers, model providers and fintech vendors can become concentration points. Contracts, access controls, audit rights, fallback systems and exit plans matter.
Human oversight
AI can flag, predict and automate. High-impact financial decisions need clear accountability, escalation routes and the ability to override or disable a system when necessary.
Systemic resilience
Regulators increasingly have to ask not only “Can this institution withstand an attack?” but also “What happens if several interconnected institutions face the same disruption?”
The bigger picture: AI changes the speed of financial risk
The important point is that AI can strengthen both sides of the financial system. It can improve defence, but it can also make an attack faster, cheaper and more difficult to contain.
It can make fraud more convincing, cyberattacks more scalable and misinformation more persistent. At the same time, it can improve fraud detection, vulnerability discovery, surveillance and operational resilience.
That is why RBI and SEBI are moving in a similar direction even though they regulate different parts of the financial system: more technology, but also more governance; more automation, but stronger controls; faster systems, but faster detection and recovery.

Artificial Intelligence and Financial System Risks
Q. Artificial Intelligence is creating new opportunities as well as new risks for the financial sector. Discuss the emerging AI-related threats to financial systems and examine the measures being taken by the RBI and SEBI to strengthen cyber resilience and regulatory oversight. (15 Marks | 600 Words)
Artificial Intelligence (AI) is rapidly transforming the financial sector through automated decision-making, fraud detection, customer service, trading and risk management. However, the same technology can also make financial fraud more sophisticated, accelerate cyberattacks and create new risks for financial institutions and markets. Recognising these challenges, the Reserve Bank of India (RBI) and the Securities and Exchange Board of India (SEBI) are strengthening their regulatory and technological frameworks.
Emerging AI Threats to the Financial Sector
1. Deepfakes and identity-based fraud: Generative AI can create convincing fake voices, videos and documents. Fraudsters may impersonate customers, senior bank officials or regulators to bypass authentication and KYC processes.
2. Automated and personalised financial fraud: AI allows criminals to generate highly convincing phishing messages, fake customer-support interactions and social-engineering attacks at scale. This can increase the speed and reach of digital financial fraud.
3. Synthetic identities: AI can combine genuine and fabricated personal information to create synthetic identities. Such identities can potentially be used to open accounts, obtain credit or conduct fraudulent transactions.
4. Market manipulation: AI can generate large volumes of misleading information, fake news or coordinated trading signals. If used maliciously, this could distort investor behaviour and undermine market integrity.
5. AI and model risk: Financial institutions increasingly depend on algorithms for lending, investment and risk assessment. Errors, biased data, poor model design or insufficient human oversight can therefore translate into large financial losses.
6. Cascading cyber risk: A successful attack on a critical financial institution, payment system or market infrastructure could spread quickly through interconnected institutions. AI can make such attacks faster and more adaptive.
The Mythos AI scare also illustrates why AI-related risks cannot be treated merely as a future possibility. It highlighted concerns around the interaction of advanced AI systems with financial markets, cybersecurity and autonomous decision-making, making regulatory preparedness increasingly important.
RBI's Response
1. Comprehensive cyber-resilience framework: The RBI has strengthened requirements relating to governance, cyber-risk management, monitoring and institutional preparedness for banks and financial institutions.
2. Board-level accountability: Cybersecurity is increasingly treated as a responsibility of senior management and the board rather than merely an IT function.
3. Incident reporting: Financial entities are required to report cyber incidents within prescribed timelines, enabling quicker regulatory response.
4. Fraud protection: The RBI has expanded safeguards and compensation-related measures for victims of digital fraud and newer forms of electronic scams.
5. MuleHunter.AI: The RBI has promoted the use of AI-based technology to identify and track mule accounts, which are frequently used to receive and transfer proceeds of financial fraud.
6. FREE-AI Framework: The RBI has also encouraged responsible and secure adoption of AI in the financial sector through its framework focused on responsible, ethical and effective use of AI.
7. Kill-switch mechanism: The RBI has explored mechanisms that could allow customers to rapidly halt transactions when they suspect that their accounts have been compromised.
SEBI's Response
1. IT Resilience Index (ITRI): SEBI has introduced an index for Market Infrastructure Institutions such as stock exchanges and clearing corporations to assess IT resilience across parameters including availability, security, integrity, governance, monitoring, business continuity and scalability.
2. Continuous monitoring: The framework provides for periodic assessment and corrective action, helping institutions identify vulnerabilities before they become major disruptions.
3. FIRE format: SEBI has standardised cyber-incident reporting through the Format for Incident Reporting Exchange (FIRE), allowing incidents to be reported progressively from initial disclosure to final closure.
4. Cyber Suraksha Portal: The regulator has strengthened technology-enabled mechanisms for reporting and managing cybersecurity incidents.
5. Responsible AI and ML: SEBI is moving towards guidelines for responsible use of AI and machine learning in securities markets, while also using AI-based surveillance to identify suspicious trading patterns.
6. AI-based vulnerability detection: Greater use of technology for identifying weaknesses can help regulators and market institutions respond to threats before they are exploited.
Way Forward
AI-related financial risks cannot be addressed through regulation alone. India needs continuous regulatory adaptation, stronger information sharing, regular stress testing, human oversight of critical AI systems, better digital literacy and greater coordination between the RBI, SEBI, financial institutions and cybersecurity agencies.
In Conclusion, AI is neither inherently a threat nor a solution. Its impact depends on how safely it is designed, deployed and supervised. For India, the objective should therefore be to promote responsible financial innovation while ensuring cyber resilience, consumer protection and market integrity. The evolving approach of the RBI and SEBI shows that financial regulation must become as adaptive as the technology it seeks to regulate.
Sources and regulatory references
- SEBI, IT Resilience Index for Market Infrastructure Institutions (MIIs), August 24, 2026.
- SEBI, Alignment of Cyber Incident Reporting Portal with FIRE Format, August 24, 2026.
- SEBI, Launch of Cyber Suraksha Portal, August 24, 2026.
- SEBI, Advisory on Emerging Advanced AI Tools for Vulnerability Detection, May 5, 2026.
- SEBI, Consultation Paper on Guiding Principles for Responsible Usage of AI/ML in Indian Securities Markets, June 20, 2025.
- RBI, Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, July 31, 2026.
- RBI, Information Technology Governance, Risk, Controls and Assurance Practices Directions, November 7, 2023.
- RBI, revised framework on limiting customer liability / compensation for fraudulent electronic banking transactions, June 2026.
- RBI, FREE-AI Committee Report - Framework for Responsible and Ethical Enablement of Artificial Intelligence, August 13, 2025.
- RBI Annual Report 2024-25, including FREE-AI, MuleHunter.ai and RBIH's AI/ML initiatives for fraud detection and supervision.
- RBI, Statement on Developmental and Regulatory Policies, December 24, 2024, announcing the FREE-AI committee and MuleHunter.AI initiative.
- Anthropic, Claude Mythos Preview and related safety documentation, April 2026; the episode is used here as an international example of the changing cyber capability of frontier AI.
- Reuters, July 13, 2026, reporting that Canada's banking regulator had cited Anthropic's Mythos in a warning to financial institutions about AI-driven cyber risks.
- RBI Annual Report 2025-26, including discussion of digital-payment fraud, AI-enabled fraud analytics and the proposed kill-switch/switch-on/switch-off approach.
