Skip to content
Mumbai · Monday, 24 August 2026

National Revealed

The Truth can never be hidden

Editors Choice

India is one of the most cyber-attacked nations. Here’s how AI adds another layer to the threat

By Sohail Khan 24 August 2026, 6:06 am

Artificial Intelligence (AI) has reached mass adoption faster than any prior technology — the Internet took 15 years to reach a billion users, while ChatGPT did so in three.

This rapid adoption has major consequences for cybersecurity. AI is amplifying cyber threats at unprecedented speed, scale and sophistication across the cyber kill chain, from automated vulnerability discovery to AI-generated deepfakes and AI-enabled social engineering (using AI to trick/persuade people to take harmful actions). More significantly, AI is developing the ability to act as an autonomous agent that can identify, plan, adapt and carry out offensive cyber operations.

Story continues below this ad

Thus, countries with leading AI ecosystems gain a greater ability both to conduct sophisticated cyber campaigns and to defend against them.

But AI capabilities remain concentrated in very few countries. This raises pressing questions for India: how prepared is it to address AI-enabled cyber threats? What should India do to build the AI capabilities needed to secure its cyberspace?

AI is transforming cybersecurity

Cybersecurity was already lopsided, with a few countries holding far superior capabilities than the rest. Advances in frontier AI systems have pushed this further.

Reconnaissance, once dependent on humans gathering information about a target, is now automated and faster: research shows ChatGPT models being used to mine social media for precise details to craft AI-generated spear-phishing emails. AI is also generating real-time deepfakes, deepening confusion about what online content is authentic.

Story continues below this ad

More dangerous capabilities have emerged at the weaponisation and command-and-control stage. One novel method is LLM-generated polymorphic malware — code that large language models can autonomously generate, modify and restructure to suit the situation, unlike traditional malware, which relies on fixed signatures and predictable patterns. In September 2025, Anthropic claimed a Chinese state-sponsored group, “GTG-1002,” had allegedly used Claude Code as an autonomous cyber agent across multiple stages of an attack — what Anthropic called the first reported case of an AI-orchestrated cyber-espionage campaign.

Perhaps most consequential is the emerging ability of frontier AI models to autonomously identify software vulnerabilities at scale. Anthropic’s latest frontier model, Claude Mythos Preview, has identified thousands of zero-day vulnerabilities — flaws previously unknown to developers — across major operating systems and browsers, many of them critical, and developed related exploits largely without human intervention.

It found a 27-year-old vulnerability in OpenBSD, an operating system reputed to be highly security-hardened and widely used to run firewalls and critical infrastructure.

Such vulnerabilities are especially dangerous for the Operational Technology and Industrial Control Systems that govern nuclear facilities, energy grids, pharmaceutical manufacturing, chemical processing, oil refineries and communication networks — infrastructure that grows more exposed as it integrates further with AI.

Story continues below this ad

Old cyber defences will not hold against these new threats. Traditional antivirus, which looks for known malware fingerprints, and static security patches for known vulnerabilities are far less effective against malware that constantly changes and adapts.

AI Geopolitical imbalances in the global AI ecosystem.

AI in cybersecurity, by contrast, enables real-time threat detection, automated response and large-scale data analysis, mitigating risks faster than traditional approaches.

The real AI divide, then, is not only about who uses AI but who builds it, and which countries control its development.

Questions for India

Last month, the ransomware group World Leaks claimed to have stolen and posted data related to India’s largest nuclear plant, Kudankulam, including blueprints of facility parts and supplier details. Cyber intelligence firm CloudSEK’s 2024 report placed India as the second-most cyber-attacked nation after the US; its 2025 report placed India sixth.

Story continues below this ad

During Operation Sindoor, Pakistan-backed threat actors such as APT36 targeted India’s critical sectors, including the Ministry of Defence, Army, Navy and DRDO, and for the first time, Bharat Operating System Solutions (BOSS) Linux. They also disrupted government IT infrastructure such as the National Informatics Centre and targeted state-level educational and government portals — exposing the vulnerability of India’s critical infrastructure to coordinated offensive cyber operations.

Yet India’s indigenous AI ecosystem remains incremental, lagging well behind the US and China across the AI stack — foundational models, GPUs, chip design and large-scale data-centre infrastructure — leaving it heavily dependent on the US and other technologically advanced countries.

Efforts made

Indian policymakers are aware of these stakes and have begun taking steps. Agencies like CERT-In have, since 2025, adopted AI-driven threat detection, cyber resilience measures, trusted AI frameworks and citizen-centric malware mitigation. In April, it issued an advisory for organisations to defend against AI-driven cyber risks. Some of the recommendations were about “removing unnecessary internet-facing services” and treating every newly discovered vulnerability as something that “could be exploited within hours, not weeks.”

At the governance level, the Ministry of Electronics and Information Technology is exploring a consent-based framework for synthetically generated content, alongside curbs on agentic AI autonomy and clearer liability frameworks for AI models.

Story continues below this ad

India cannot build the AI stack overnight, but its strength lies, as Nitin Pai says, in “agile adoption and efficient diffusion” of AI capabilities — paired with supply-chain scrutiny, security assessments, accountability mechanisms and liability provisions suited to its strategic and developmental interests. India should also earn its place in strategic groupings like Pax Silica.

AI and cybersecurity can no longer be treated in silos — they must be seen as interconnected strands of policymaking: AI for cyber defence, and cybersecurity for AI.

The author is research associate, Indian Council of World Affairs, New Delhi.

Leave a Reply

Your email address will not be published. Required fields are marked *