
India's capital markets regulator has taken concrete steps to address AI security concerns, with SEBI issuing a circular on cybersecurity risks associated with advanced AI-based vulnerability detection tools, applicable to all regulated entities in the securities market ecosystem. The circular sets out comprehensive requirements including prompt system patching with interim virtual patching, regular vulnerability assessments and security audits using conventional and AI tools, vendor risk management, and structured change management. This development comes as part of SEBI's broader framework for safe and responsible AI adoption across capital markets, with the regulator emphasizing that AI will form a key pillar of its future agenda.
The SEBI chief stressed that the regulator supports the use of 'secure and safe AI' with a Human-in-the-Loop (HITL) approach, ensuring that critical decisions continue to involve human supervision. As reported by ET Now, Pandey said AI will be an important part of the regulatory agenda, with the regulator working on a framework that balances technological advancement with human oversight. This approach reflects SEBI's commitment to maintaining regulatory control while embracing AI's potential benefits for market operations, particularly as global regulators increasingly focus on age assurance mechanisms and child protection measures in AI applications.
The remarks from the SEBI chief come at a time when market participants, including stock exchanges, brokers, mutual funds and investment advisers, are increasingly adopting AI-driven tools for surveillance, compliance, customer onboarding and investment services. According to ET Now, these AI-driven tools are being used across various aspects of financial market operations, from operational efficiency to customer service delivery. The growing adoption of AI technologies in capital markets has prompted regulatory attention to ensure safe and responsible implementation, with global regulators now focusing on safety-by-design measures, age assurance mechanisms for age-restricted services, and measures to prevent the generation and distribution of child sexual abuse material and non-consensual intimate images, including those generated using AI.
SEBI's AI framework development occurs within a broader global context of digital policy evolution. Recent developments include the G7 Industry, Digital, and Technology Ministers adopting common principles for a safer and more secure digital space for minors, with focus on child protection measures in AI applications. Additionally, the European Commission opened consultations on two draft guidelines under the AI Act, clarifying classification of high-risk AI systems and transparency obligations, while the European Parliament and Council of the EU reached a provisional agreement on the Digital Omnibus on AI Regulation, prohibiting AI systems that generate non-consensual sexually explicit content by December 2, 2026. These global initiatives provide regulatory frameworks that SEBI can leverage in its own AI guidelines development.