New Delhi: The rapid adoption of artificial intelligence is changing the cybersecurity strategy of Indian companies, with businesses now looking beyond traditional networks, computers and applications to protect AI models, agents, APIs and the data connected to them.
Large Indian technology companies, including Infosys, TCS, HCLTech, Cognizant, Hexaware, Mphasis and Persistent Systems, are reviewing their security frameworks as AI becomes more deeply integrated into enterprise operations. The focus is increasingly shifting towards controlling what AI systems can access and how they interact with internal applications and sensitive information.
One of the major changes is the extension of the Zero Trust security model to AI. Under the traditional approach, a user or application inside a company’s network may receive a certain level of trust. Zero Trust works differently by requiring access to be continuously verified. Companies are now applying the same principle to AI agents that can access databases, cloud systems, APIs and business software.
The shift is important because AI can create both defensive and security risks. Companies are using AI to detect unusual activity, identify threats and automate parts of cybersecurity operations. At the same time, attackers can use AI to create convincing phishing messages, automate reconnaissance and find vulnerabilities more quickly.
A 2026 report by BCG found that 76% of Indian BFSI chief information security officers surveyed ranked AI-enabled attacks among their top four cybersecurity priorities. The report also noted that India’s highly digital financial system creates additional security challenges as AI becomes embedded across banking and financial operations.
Businesses are also increasing their cybersecurity spending. PwC’s 2026 Global Digital Trust Insights survey found that 87% of organisations expected their cyber budgets to increase over the following 12 months, while AI was identified as the top investment priority by 46% of respondents. Among Indian enterprises, nearly one-fourth reported losses of more than $1 million from their most serious cyber breach during the previous three years.
The emergence of AI agents has created another concern. Unlike traditional software, autonomous AI agents can make decisions and take actions across multiple systems. If such an agent is given excessive access, a security failure could affect several connected systems at once.
This has led companies to focus on tighter identity controls, continuous monitoring, AI governance and regular testing of models. Security teams are also examining training data and model outputs for possible vulnerabilities.









