
Top Indian banks are racing to assess their vulnerability to cyber attacks backed by artificial intelligence models, with consultants helping them meet an RBI deadline by June 30, 2026. According to reports from Mint, the Reserve Bank of India gave banks two months in April to submit a board-approved review on cyber security gaps and a time-bound action plan. The central bank also mandated banks to formulate a comprehensive AI governance and security framework as part of the regulatory push to boost cyber defences.
Major consultancy firms are playing a crucial role in helping banks identify potential vulnerabilities that advanced AI models could exploit. As reported by Mint, EY and Boston Consulting Group (BCG) are working with banks to conduct vulnerability assessments. Pratik Shah, national financial services leader at EY India, explained that banks in India do not have access to Mythos right now, but EY has built its own equivalent using several frontier AI models to assist banks with their assessments.
The primary concern driving this initiative is that AI has significantly reduced the cost of sophisticated cyber attacks while making them faster and harder to defend against. According to Mint reports, Deep Narayan Mukherjee, partner and director for risk management and data science at BCG India, noted that while AI is adept at recognizing cyber vulnerabilities, inflicting attacks from these vulnerabilities may not be as easy. However, the bigger threat is that AI has reduced the cost of sophisticated cyber attacks, making single lapses in proactive security postures very costly for organizations. Banks saw more than 493,000 cyberattacks last year, more than twice as many as in 2022, with each breach costing an average of $2.5 million to recover from.
Indian banks face significant resource constraints in addressing AI-enhanced cyber threats, with most institutions struggling with internal cyber security resources. As reported by Mint, Jayant Saran, partner at Deloitte, noted that most chief information security officers today carry managerial expertise rather than cyber engineering skills, which is crucial given AI's sophisticated nature. The Indian Banks' Association has been directed by the government to push this agenda and form a committee to address these cyber security concerns.
The urgency reflects broader regulatory and market concerns about AI cybersecurity threats. According to Mint reports, B.J. Jenkins, president of Palo Alto Networks, confirmed that India's financial services industry serves as one of the company's biggest sectoral clients, with the sector building increased preparedness against AI threats. RBI deputy governor Swaminathan J. told reporters that the issue has been engaging the attention of the government and financial sector inter-regulatory forums, highlighting the regulatory focus on cyber security enhancement.