TL;DR
RBI's AI-Accelerated Cyber Threats and Related Safeguards advisory requires every regulated entity to submit a board-approved gap assessment and a time bound action plan to address the identified gaps by June’30.
The trigger for this action is Anthropic's Mythos. This frontier AI model found a vulnerability in OpenBSD that had gone undetected for 27 years
India is already the second most targeted country for email-based cyber threats. BFSI sector alone faced 4.1 million attacks a month in H1 2025
The advisory has three obligations most institutions are misreading: a framework that maps where AI already touches their data, AI-led adversarial testing (impossible while keeping AI entirely outside the perimeter), and a data exposure question nobody has a clean answer to — what happens to customer data when it touches publicly available AI models
This June 30 submission is just the beginning of a long battle against AI accelerated threats. What separates real compliance from paper compliance is whether names, deadlines, and test results sit behind the board sign-off.
30th JUNE'26 DEADLINE
RBI's AI-Accelerated Cyber Threats and Related Safeguards advisory (AI-ACT&RS) requires every regulated entity to submit a board-approved gap assessment and a timebound action plan by end of this month. The trigger is Anthropic's Mythos, a frontier AI model that found a vulnerability in OpenBSD that human researchers had missed for 27 years. OpenBSD is considered one of the world's most secure operating systems.The advisory is not about whether your institution uses AI. It is about whether your institution is prepared for adversaries who do.
01/WHY NOW?
The BFSI sector absorbed an average of 4.1 million attacks every month in the first half of 2025. With the increased use of the India stack, today UPI alone processes 22 billion+ transactions a month. Aadhaar underpins identity verification across the entire financial stack. The attack surface is not hypothetical. It is enormous, live, and deeply interconnected.
The attacks are not theoretical either. Earlier this week, Tata Electronics confirmed a cybersecurity incident in which ransomware group World Leaks posted over 200,000 files on the dark web. (Purportedly including Apple and Tesla manufacturing specifications, component designs, and employee passport scans. 630 gigabytes of data. A ransom demand received.) The JLR cyberattack last year shut UK production for six weeks. Tata is a manufacturing company, not a bank. Indian financial infrastructure, with its real-time settlement rails, live credit decisioning, and Aadhaar-linked KYC, carries a higher attack surface with considerably higher systemic stakes.
What Mythos changes is the speed and scale at which that surface can be probed. Frontier AI models can now identify previously unknown software vulnerabilities faster than human security teams can triage and patch them. Mythos found a flaw in OpenBSD undetected for 27 years. It can autonomously complete a 32-step corporate network attack. The same capability that makes it useful for defensive testing is dangerous in the wrong hands.
Anthropic has restricted Mythos access under Project Glasswing currently limited to Apple, JPMorgan Chase, and a small number of others. Indian fintechs including Paytm, Razorpay, and Pine Labs have requested access. Most are still waiting. In the meantime, Infosys and TCS are using Claude Opus 4.7 to test their systems including Finacle, the core banking software deployed across a large number of Indian financial institutions because Mythos itself is not yet available to them. And Fable has now been withdrawn.
RBI's position is clear: the threat does not wait for access approvals.
The Tata breach is a data point, not an outlier. India's digital infrastructure has been under sustained attack before Mythos. Mythos changes the calculus of how fast and how precisely that attack can be executed.

Figure 1: Cyber Threat is real
02/REQUIREMENTS UNDER AI-ACT&RS
Three obligations sit at the core of the directive.
1. A structured cybersecurity framework that accounts for AI
Not a policy document that mentions AI in passing. A framework built on knowing where AI touches the institution's data today. That includes the obvious surfaces e.g. any chatbot or copilot the bank has piloted. And the less visible ones like Employees pasting content into public tools from personal devices. Vendors quietly embedding AI into products the bank already runs. Analytics teams experimenting with models on live data that nobody formally approved.
The perimeter has already moved. The framework has to catch up to where it actually is, not where the last policy document assumed it was.
2. AI-led adversarial testing
The regulator expects institutions to use capable AI models to probe their own defences. RBI’s expectation is that the institutions can actually put AI to work. An institution that has kept AI entirely outside its perimeter cannot run AI-led tests against that perimeter. These two positions are not compatible.
3. Identifying existing vulnerabilities — including data exposure
Most compliance teams will read this as a network and application exercise. It is partly that. The more under-examined vulnerability class in any Indian bank today is data exposure and this is where the third obligation has no clean answer yet.
The moment an institution begins evaluating publicly available AI models for internal use cases (which is precisely what the advisory expects, given that access to the most advanced models remains restricted to a handful of global players), the first question every risk committee will face is straightforward: what happens to customer data when it touches these models? While the industry is still figuring out how to comply with DPDP act, this is an additional consideration that needs to be built in.
The three obligations assume AI is already inside the financial institution's perimeter. The gap assessment is just an exercise in ensuring that the institution knows where it is being used.

Figure 2: Obligations under AI-ACT & RS
03/WHERE WE STAND TODAY
India's information security spending is projected to reach $3.4 billion in 2026 . (11.7% YOY increase, as per Gartner.) The direction is right. The question is whether the composition of that spending matches what AI-ACT&RS actually requires.
A large portion of any small-sized Indian bank's technology estate cannot be patched on a modern cadence. These are often legacy systems that the vendor no longer actively supports, or workloads that cannot afford the downtime a patch requires. That unpatchable layer is the attack surface a Mythos-class model would find most productive. New security tooling does not reduce it.
Fintechs sit in a different position. Cleaner technology stacks, fewer legacy dependencies, but thinner security teams and deeper integration into the banking ecosystem through co-lending arrangements, partner bank rails, and shared API infrastructure. A vulnerability in a fintech's stack is a potential entry point into its partner bank's systems. The advisory's third-party AI risk requirements directly address fintech integrations.
The compliance picture is layered further. A fintech holding a payments aggregator licence or an insurance aggregator licence sits under three to five regulators for cyber questions alone — RBI, SEBI, IRDAI, MeitY, and CERT-In each carry overlapping but non-identical requirements. The AI-ACT&RS advisory adds a new set of controls across all of them. For most compliance teams, this is not one gap assessment. It is four.
India's cybersecurity spending is growing. But its cybersecurity architecture is not growing fast enough to match the threat that AI-accelerated attacks can create.

Figure 3: Building compliant architectures with multiple regulators
04/The UNSAID GAP
The June 30 deadline will be met. Board papers will be signed. Gap assessments will be submitted. Action plans will exist as documents.
I have witnessed this many times. A deadline arrives, a working group convenes, and what emerges is a policy framework that describes the threat accurately and prescribes the right controls. All on paper, mind you. It passes board review. It satisfies the immediate regulatory ask. And it tells you almost nothing about whether the institution can actually defend itself in the face of a challenge.
The difference between a compliance document and a compliance programme is diagnostic capability. A real gap assessment names specific systems, specific control failures, and specific remediation owners with specific deadlines. It produces evidence e.g. logs, test results, vulnerability reports and not just assertions. When the regulator returns in six months and asks how the institution's AI-led adversarial testing went, the answer cannot be a policy citation. It has to be a documented record.
The AI-ACT&RS advisory is very explicit on this. The action plan must be timebound. Timebound means ownership. And Ownership mean accountability. Accountability means someone's name is next to a remediation item that either got done or did not.
Two things will separate institutions that use this deadline productively from those that file and forget. The first is whether the board review includes actual test results — not a summary of what testing was planned, but what it found. The second is whether the compliance team has a mechanism to track remediation against the action plan between now and the next supervisory cycle.
A gap assessment with no follow-through is not a programme. It is a snapshot that ages badly.
The June 30 submission is the opening position. What regulators examine at the next cycle is what the institution did with it.
05/WHAT BOARDS NEED TO DO THIS WEEK
Three things separate a real response to AI-ACT&RS from a paper one.
The board review must include test results, not test plans. If the gap assessment going to the board describes what adversarial testing will cover rather than what it found, the exercise is incomplete. A board that approves a plan without seeing findings has not discharged its accountability under the advisory.
The action plan must have names, not functions. "The IT security team will remediate critical vulnerabilities by Q3" is not a timebound action plan. A named individual with a specific deadline for a specific system is. The distinction matters when the regulator returns.
Third-party exposure must be mapped, not assumed. Every partner bank, every co-lending arrangement, every API integration is a potential entry point. The advisory's third-party AI risk requirements are not a separate workstream. They are part of the gap assessment. An institution that completes its internal review without mapping its vendor and partner exposure has assessed half its attack surface.
The larger point: AI-ACT&RS is the first regulatory signal in India that AI governance is no longer an IT department function. The board-approval requirement is not procedural. RBI is telling regulated entities that the accountability chain for AI risk runs from the CISO to the board and that the board cannot delegate its way out of that chain.
