RBI Orders Banks to Complete AI Cyber Risk Assessments by Month-End

RBI Orders Banks to Complete AI Cyber Risk Assessments by Month-End

The Reserve Bank of India has directed banks and other regulated entities to complete board‑approved gap assessments of their preparedness against cybersecurity threats posed by advanced artificial intelligence models and submit time‑bound remediation plans by the end of June.

This push comes after growing worries about “frontier” AI systems—like Anthropic’s Claude Mythos. Recent tests showed Mythos can pull off multi-step attack chains that spot and exploit software flaws much quicker than any hacker. The UK’s AI Safety Institute even ran a scenario where Mythos handled a 32-step corporate network breach on its own, which made regulators everywhere sit up and rethink their approach to AI risks.

The RBI’s directive adds a fresh AI focus to its existing Cyber Security Framework for Banks. Now, banks have to run assessments signed off by their boards, put their defenses to the test using AI-led tactics, scan for current weaknesses, and—most importantly—lay out quick, specific plans to fix whatever they find. Business Standard first broke the news about these new rules. People in the industry say the timeline is tight.

“Banks and financial firms regulated by the RBI and SEBI need to measure themselves against the Mythos advisories—in practice, that means doing adversarial AI testing, scanning for AI-powered vulnerabilities, and more,” one cybersecurity executive told Business Standard.

This order follows the RBI’s June 5 Monetary Policy Committee meeting. At the time, Governor Sanjay Malhotra kept the repo rate steady at 5.25 percent but openly warned the RBI is ready to handle cybersecurity threats from cutting-edge AI. Security experts were glad to see the RBI move quickly but stressed that banks shouldn’t just go through the motions.

The real work involves tough, realistic penetration tests (“red-teaming”) and making real fixes where they count—network segmentation, zero-trust security, multifactor authentication, tight logging, and fast patching. Regulators and industry voices also agree: India needs coordinated rules on how far AI red-teaming should go, what to report, and who takes responsibility if an AI-aided cyberattack happens. They want the RBI, SEBI, CERT-IN, and industry groups pulling in the same direction.

Some banks actually see opportunities with AI—they think it can help them spot threats faster, automate routine defenses, and speed up their response. But experts are clear: defensive AI tools need to be open to audits and always under human watch. Smaller banks might struggle with the deadline and limited resources. Analysts say those institutions will need extra help and maybe a phased approach to compliance.

At bottom, the RBI’s new requirements show that cybersecurity and AI oversight are quickly coming together. Regulators don’t want Indian financial systems caught off guard by rapidly advancing threats.

Kanhaiya Suthar

Content Editor at Primex Media

Comments are closed