AI Governance and Cybersecurity: India's Regulatory Challenges in the Mythos Era

Updated 1 May 2026

Contents4

Indian Express - Opinion · 1 May 2026 · 2 min read
Prelims · Science and technology Mains · GS3 Science and technology High relevance

Anthropic's Mythos AI poses unprecedented cybersecurity threats, prompting CERT-In to issue advisories and RBI to engage with banks, highlighting the need for strategic cybersecurity enhancements without excessive regulation.

Key points

Anthropic’s Mythos AI can identify and exploit software vulnerabilities, scaling cyberattacks on critical infrastructure, necessitating urgent regulatory and security responses.

CERT-In issued an advisory on advanced AI cyber risks, emphasizing reinforcement of baseline cybersecurity measures to counter growing threats.

RBI identified cooperative banks as particularly vulnerable due to resource constraints and lower security maturity, requiring targeted support.

[GS3-Economy] Cybersecurity compliance costs are prohibitive for smaller entities, suggesting financial support mechanisms like corpus funds and trusted vendor lists to mitigate risks.

Digital Competition Bill risks increasing vulnerabilities by prohibiting restrictions on sideloading, expanding pathways for malicious applications, as seen in the Rs 11.5 crore Himachal Co-operative Bank fraud.

AI Governance and Economic Group may classify AI use cases, but access-based restrictions could be counterproductive as bad actors bypass legal frameworks.

[GS2-Governance] Traditional cybersecurity approaches must evolve to address interconnected digital systems, focusing on systemic weaknesses rather than discrete vulnerabilities.

Way Forward: India should establish a cybersecurity corpus fund for smaller entities, create a trusted vendor list, and review laws like the Digital Competition Bill to eliminate inadvertent vulnerabilities, ensuring holistic cyber resilience.

Key terms

CERT-In
The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for cybersecurity, responsible for responding to cyber incidents, issuing advisories, and enhancing security measures. Its role is critical in safeguarding India's digital infrastructure against emerging threats like AI-enabled attacks.
Anthropic’s Mythos
Anthropic’s Mythos is an advanced AI system capable of identifying software vulnerabilities and simulating cyberattacks, posing significant security risks. Its emergence underscores the need for robust AI governance and cybersecurity frameworks to mitigate threats to critical infrastructure.
Digital Competition Bill
The Draft Digital Competition Bill aims to regulate digital markets by prohibiting restrictive practices like blocking sideloading. However, it may inadvertently increase cybersecurity risks by expanding avenues for malicious applications, highlighting the need for balanced regulation.
AI Governance and Economic Group
A recently constituted group tasked with classifying AI use cases into categories like 'deploy', 'pilot', and 'defer'. Its mandate includes shaping India's AI governance framework, but over-regulation could stifle innovation while failing to curb malicious use.

Practice question

Critically analyze the cybersecurity challenges posed by advanced AI systems like Anthropic's Mythos and suggest measures to enhance India's regulatory framework to mitigate these risks. (250 words, 15 marks)

GS3 15 marks 250 words Mains

Key terms to include: Anthropic's Mythos CERT-In Digital Competition Bill AI Governance and Economic Group cybersecurity corpus fund trusted vendor list systemic weaknesses critical infrastructure

Answer framework

Introduction

Briefly introduce the emergence of advanced AI systems like Anthropic's Mythos and their potential to exploit cybersecurity vulnerabilities. Mention the need for robust regulatory frameworks.

Cybersecurity Challenges Posed by Advanced AI

AI systems can identify and exploit software vulnerabilities at scale, leading to increased cyberattacks on critical infrastructure.

The prohibitive cost of cybersecurity compliance for smaller entities, such as cooperative banks, exacerbates vulnerabilities.

The Digital Competition Bill may inadvertently expand pathways for malicious applications by prohibiting restrictions on sideloading.

Current Regulatory Responses

CERT-In's advisories on advanced AI cyber risks and the reinforcement of baseline cybersecurity measures.

RBI's identification of cooperative banks as vulnerable and the need for targeted support.

The AI Governance and Economic Group's role in classifying AI use cases to shape India's AI governance framework.

Suggested Measures for Enhanced Regulation

Establish a cybersecurity corpus fund to support smaller entities in meeting compliance costs.

Create a trusted vendor list to ensure the adoption of secure technologies.

Review and amend laws like the Digital Competition Bill to eliminate inadvertent vulnerabilities.

Focus on systemic weaknesses in interconnected digital systems rather than discrete vulnerabilities.

Conclusion

Emphasize the need for a balanced approach that enhances cybersecurity without stifling innovation. Suggest a holistic strategy involving financial support, regulatory reviews, and systemic improvements.

Fact check

All facts verified