SEBI Orders Cybersecurity Overhaul as Mythos AI Threatens Indian Securities Markets

2 Sources

Share

India's Securities and Exchange Board has issued a red alert circular naming Anthropic's Claude Mythos, ordering every regulated entity in Indian securities markets to immediately overhaul their cybersecurity infrastructure. The move makes SEBI the first Indian financial regulator to name a specific AI model in a formal directive, but creates a paradox: Indian firms must defend against a model they cannot access.

SEBI Issues Red Alert for Indian Securities Markets

The Securities and Exchange Board of India has taken an unprecedented step by issuing a formal circular dated May 5 that names Anthropic's Claude Mythos as an imminent threat to the nation's financial infrastructure

2

. The directive orders every regulated entity in Indian securities markets to immediately revisit their information security systems and implement a comprehensive cybersecurity overhaul

1

. SEBI becomes the first Indian financial markets regulator to name a specific AI model in a formal circular, following CERT-In's initial warning across all sectors on April 26

2

.

Source: The Register

Source: The Register

The advisory targets 19 different classes of companies across the equities industry, ranging from stock exchanges and depositories to mutual funds, brokers, credit rating agencies, custodians, merchant bankers, portfolio managers, and even niche software vendors who store know-your-customer information

1

. SEBI's concern centers on how Mythos can identify and exploit vulnerabilities using speed and scale, threatening data confidentiality, application integrity, and reliability of outputs across interconnected market players

2

.

Task Force Established to Combat AI-Driven Cybersecurity Risks

SEBI has constituted a specialized task force called cyber-suraksha.ai, comprising representatives from market infrastructure institutions, qualified registrars and transfer agents, and other regulated entities

2

. This task force will examine the risks posed by advanced AI models like Mythos, share threat intelligence, report cyber incidents on priority, and initiate a comprehensive review of third-party software vendors who supply the regulator and the entities it oversees

1

. Because all market participants are interconnected, SEBI warns that one breach can trigger a domino effect across the entire ecosystem

2

.

Mandatory Security Measures and SOC Transformation

The circular mandates immediate action across multiple fronts. Regulated entities must ensure patches are up to date, conduct comprehensive audits of potential vulnerabilities, maintain complete inventories of APIs and secure them, and harden systems by adopting principles such as Zero Trust Network Architecture while running only essential services

1

. Organizations must overhaul their Security Operations Centre monitoring to track threats around the clock, explicitly model AI capabilities as a threat scenario in periodic risk assessments, and periodically update their Software Bill of Materials for all critical applications

2

.

SEBI also directed IT committees to issue guidance on mitigating risks created by AI-led vulnerability management models, then develop AI-driven strategies for using AI as part of their infosec arsenal

1

. The regulator specifically calls for recalibration of risks for AI-accelerated threats, AI-augmented SOC transformation, and continuous vulnerability management using AI tools, including autonomous agentic mitigation where AI systems independently identify and respond to potential cyber threats without waiting for human instruction

2

.

A Structural Paradox in Defense Strategy

SEBI's directive creates a significant contradiction for Indian financial institutions. No Indian company, bank, or government agency has secured access to Mythos under Project Glasswing, Anthropic's $100 million restricted access programme

2

. MeitY Secretary S. Krishnan confirmed on April 28 that India is still working out logistics with US authorities

2

. This means SEBI is ordering Indian financial institutions to defend against a model they cannot access to test their own defenses.

Claude Security, Anthropic's enterprise defensive tool, gives Indian firms an indirect path through Infosys as a named partner, but runs on Opus 4.7, which produces two working exploits on the Firefox 147 benchmark against Mythos's 181—a 90x capability gap

2

. MediaNama founder Nikhil Pahwa identified the core problem: "A tool that compresses attack timelines without compressing defense timelines increases systemic risk before it improves security"

2

.

The data localization conflict also remains unresolved. India's 2018 rules require payment system providers to store all transaction data on servers within India, while Mythos is hosted on US-based servers

2

. India's approach stands out globally for effectively putting entities on alert to an imminent threat and ordering them to take action to prevent problems, while other regulators like the US Treasury Secretary Scott Bessent and Singaporean authorities have convened emergency meetings with banks

1

.

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved