AI finds the flaw first. Diagram of three stages: 01 Discover, where an AI scanner probes code and APIs at machine speed; 02 Defend, SEBI's Annexure-A shield of ten controls; 03 Contain, a connected capital market of exchanges, clearing and depositories monitored by the Market-SOC.
Research report · Capital markets cyber resilience Compiled 27 Sep 2026
Research report · SEBI advisory on AI vulnerability-detection tools

When AI finds the flaw first, defence has to move at machine speed.

Frontier AI models now find, triage and weaponise software flaws in hours. On 5 May 2026, SEBI told every regulated entity in India's securities market to prepare for that. This report reads the advisory against Anthropic's own published figures, exploitation telemetry and the responses of other regulators, then turns the 10-point Annexure-A into an operating plan.

01 · SPEED
Discovery to exploit in hours
Exploits now often land before patches
02 · SCALE
Thousands of codebases at once
Near-zero marginal cost per scan
03 · SYSTEMIC
One shared flaw, many firms
COTS, APIs and settlement chains
By the numbers · Published 2026 data

What frontier AI changed in 2026, measured

The first four figures come from Anthropic's own reporting on Claude Mythos Preview and Project Glasswing. The rest are exploitation telemetry and regulator guidance. The source line under each figure says who measured it and how.

23,019
potential vulnerabilities flagged across more than 1,000 open-source projects, 6,202 of them rated high or critical.
90.6%
of 1,752 high or critical findings assessed so far proved to be true positives (1,587). 62.4% were confirmed at high or critical severity.
Anthropic, Glasswing update · sample, not all findings
181 vs 2
working exploits developed against the Firefox 147 JavaScript engine by Mythos Preview, compared with two for Claude Opus 4.6 over several hundred attempts.
27 yrs
age of an OpenBSD TCP SACK bug, now patched, that decades of human review and static analysis had missed. It allowed remote denial of service.
−7 days
estimated mean time-to-exploit: exploitation now typically starts before a patch exists. Exploits were the top initial infection vector for the sixth year, at 32% of intrusions.
23.43%
of the 495 known exploited vulnerabilities added in the first half of 2026 were exploited on or before the day their CVE was published.
VulnCheck 1H-2026 · Jul 2026
~20 / day
critical CVEs published after 1 April 2026, up from about 7 a day in 2018–21 and about 10 a day in 2022–25.
12 hrs
CERT-In's recommended window to patch or mitigate known exploited flaws on internet-facing systems, "where feasible". The guidance is advisory, not statutory.
CERT-In Blueprint v1.0 · 25 May 2026
01 · Regulatory context

One advisory, the whole securities market

On 5 May 2026, SEBI's Information Technology Department issued an Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection (like Mythos). It was issued under Section 11(1) of the SEBI Act, 1992, which charges SEBI with protecting investors and regulating the securities market. Deputy General Manager Mamata Roy signed it. The title names Anthropic's Claude Mythos, which Anthropic announced on 7 April alongside Project Glasswing, a restricted-access programme for defenders.

The advisory is addressed to 19 lines of regulated entities, from stock exchanges to investment advisers. Some lines cover two entity types, such as Bankers to an Issue and SCSBs. It does two things: it sets up a task force, and it attaches ten controls in Annexure-A that build on SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) of August 2024.

ReferenceHO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026
Date5 May 2026
Legal basisSection 11(1), SEBI Act, 1992
Builds onCSCRF, 20 Aug 2024
Who the advisory reaches 19 addressee lines, grouped
MARKET INFRASTRUCTURE · 3
Stock exchangesClearing corporationsDepositories
ASSET MANAGERS & FUNDS · 5
MFs / AMCsAIFsVCFsCISPortfolio managers
INTERMEDIARIES · 5
Stock brokers (via exchanges)Depository participants (via depositories)IAs / RAsMerchant bankersRTAs
BANKING & FIDUCIARY · 4
BTIs & SCSBsCustodiansDebenture trusteesDDPs
MARKET SUPPORT · 2
Credit rating agenciesKYC registration agencies

Grouping is ours. The circular lists the addressees alphabetically and does not use the term "MII". Qualified RTAs appear only as task force members, not as addressees.

02 · Threat vector · The Mythos paradigm shift

From signature matching to reasoning about code

Earlier automated scanners matched signatures, looked up known CVEs or fuzzed inputs. They produced noisy results, and a person still had to build the exploit. Anthropic reports that Mythos Preview reasons across a codebase, finds flaws in both source and closed-source binaries, and turns known "N-day" vulnerabilities into working exploits. Its examples include a Linux kernel root exploit built in under a day for under $2,000 (Anthropic).

Traditional automated scanners
Legacy
  • Signature and template matching
  • Known CVE lookup (N-days only)
  • High false-positive noise
  • Exploits built manually by specialists
  • Research cycles of weeks to months
Frontier AI models (Mythos-class)
2026
  • Reasoning across the whole codebase and call graph
  • Zero-day discovery in source and closed-source binaries
  • 90.6% true positives in a 1,752-finding sample
  • Exploits generated autonomously, including from N-day patches
  • Discovery-to-exploit compressed to hours or days
The Glasswing funnel: from raw findings to fixes Bar length is logarithmic · Anthropic, 22 May 2026
Potential vulnerabilities
23,019
Rated high or critical
6,202
Assessed by humans
1,752
Valid true positives
1,587
Confirmed high / critical
1,094
Disclosed to maintainers
530
Patched
75

The gap that matters. Finding has outrun fixing. Anthropic projects nearly 3,900 valid high or critical bugs in the full set, but only 75 were patched by 22 May, and it says over 99% of what it found was not yet patched when it published. Defenders inherit that backlog, and attackers with similar tools can work through it too.

WORKING EXPLOITS · FIREFOX 147 JS ENGINE
Mythos Preview
181
Opus 4.6
2

Mythos also reached register control 29 more times. These are JavaScript-shell exploits in a test harness, not success rates against production systems (Anthropic).

CRITICAL CVEs PUBLISHED PER DAY
~7 ~10 ~20 2018–21 2022–25 After 1 Apr 2026

The BIS also estimates that a full attack chain costs about $5,000–10,000 on frontier models and $50–100 on cheaper ones (BIS Bulletin 129).

03 · What SEBI is worried about

Three risks, named in the circular

"Such tools may give rise to heightened risk exposure by enabling identification and potential exploitation of existing vulnerabilities using speed and scale. It may also introduce concerns relating to data confidentiality, application integrity and reliability of outputs."SEBI advisory, para A · 5 May 2026

Speed and scale asymmetry

AI agents can scan broker endpoints, API gateways and open-source dependencies continuously, at almost no marginal cost. Defenders still patch through change windows and people.

Data confidentiality

Sending proprietary source code, logs or API telemetry into external or unvetted AI tools risks leaking data and intellectual property. That is a concern for defenders using the tools as well as for attackers.

Integrity and output reliability

Hallucinated findings, flawed AI-generated patches or unverified automatic fixes can introduce new defects into trading systems. SEBI's Chairman put it plainly in September: "An AI-generated alert is not a finding" (MediaNama).

04 · Institutional response

The cyber-suraksha.ai task force

SEBI set up a task force of representatives from MIIs, Qualified RTAs, all Qualified Regulated Entities and "other related stakeholders". Its contact address, as printed in the circular, is project-cybersuraksha.ai@sebi.gov.in. It has four mandates.

cyber-suraksha.ai SEBI task force MANDATE 1 AI risk assessment Uniform mitigation strategy MANDATE 2 Threat intelligence Best practices and use cases MANDATE 3 Priority reporting Incidents and vulnerabilities MANDATE 4 Vendor posture review Third-party application vendors

Mandates paraphrased from the circular. It sets no reporting deadlines for the task force and no timelines for regulated entities.

05 · Systemic interconnectedness

One shared flaw, many institutions

A trade moves from an investor's app, through a broker's API, to an exchange's matching engine, then on to clearing and the depository, all within milliseconds. Many brokers and asset managers also run the same third-party order-management and back-office software. A flaw in a shared component therefore affects many firms at the same moment. The BIS makes the same point about concentration in its July 2026 bulletin.

ORDER AND SETTLEMENT FLOW · MILLISECONDS Investor appRetail and institutional Stock broker APIOMS, risk checks Stock exchangeMatching engine Clearing corp.Netting, margins DepositoryDPs, custodians Shared COTS vendors · OMS · back-office · middleware · cloud One AI-found zero-day here reaches every firm running the same binary Dependency paths
PROPAGATION 01
Single point of failure in COTS

When dozens of brokers and asset managers run the same order-management or settlement package, one zero-day in that vendor's binary opens many networks at once. This is why Annexure-A item 3 puts COTS vendors in scope.

PROPAGATION 02
API mesh exposure

Broker–exchange and algorithmic trading integrations run on APIs. An AI-found authentication bypass or rate-limit defect could be used to disrupt order books or inject orders before SOC analysts spot the anomaly.

PROPAGATION 03
Settlement contagion

An incident at a clearing corporation or depository can halt settlement and freeze liquidity across exchanges, funds and custodians. Such institutions carry a heavy attack load: Business Standard reported NSE facing around 170 million attempted attacks a day (Oct 2025).

06 · Annexure-A · The 10-point blueprint

From SEBI's wording to a working control

The second column paraphrases the circular. The third and fourth columns are Intellinative's recommended implementation and targets. SEBI sets no numeric deadlines: its only words of urgency are "immediate" for patching and "expedite" for M-SOC onboarding.

Read the badges: SEBI in the circular Recommended Intellinative practice, not a SEBI requirement
#SEBI directive SEBIImplementation RecommendedTarget Recommended
01 Patch on an immediate basis; virtual patching where no patch exists Vendor OS and application patches first. Where none exists, WAF rules, IPS signatures or virtual patches in the interim. Mitigate exploited internet-facing flaws within 12 hours, in line with CERT-In's blueprint; apply virtual patches the same day
02 Vulnerability assessment with conventional and AI-based tools, on a regular or continuous basis under CSCRF SAST, DAST and SCA in pipelines, plus vetted AI scanners run inside the entity's own environment so code does not leave it. Continuous automated scanning; human validation of every high or critical AI finding
03 Vendors and COTS providers assess risk from AI vulnerability tools Contract clauses covering AI-tool risk assessments, patch-delivery commitments, VAPT evidence and hardening baselines. Written patch SLAs from every critical vendor; evidence reviewed at least annually
04 Robust change management Documented impact analysis, peer review, static analysis and secure CI/CD with signed builds, covering AI-suggested fixes too. No unreviewed change reaches production; security gates are mandatory in pipelines
05 API security: inventory, authentication and authorisation, rate limiting, whitelist-based connections Automated API discovery; mTLS and OAuth2/OIDC with scoped tokens; token-bucket rate limits at the gateway; allow-lists by IP and client identity. No wildcard (0.0.0.0/0) access; every API in the live inventory
06 SOC alerts examined, including low-priority ones; SOAR playbooks; expedite M-SOC onboarding 24x7 SIEM with SOAR containment; correlation of low-severity alerts to catch AI reconnaissance; telemetry feeds to the NSE/BSE Market-SOC. 24x7 coverage; automatic containment for known-bad patterns
07 Include AI-led exploitation in CSCRF risk assessment and scenario-based testing Cyber drills and DR tests that simulate an adversary moving at AI speed: mass N-day exploitation, API fuzzing, vendor compromise. At least one AI-adversary scenario in each drill cycle
08 System hardening and Zero Trust CIS Benchmarks; no default accounts, ports or services; ZTNA for access; microsegmentation between trading, back-office and corporate zones. No flat networks; least privilege enforced everywhere
09 Periodically update the asset inventory and SBOM for all critical applications, including the open-source stack Automated inventory and SBOMs generated from built artifacts and running workloads, not only from manifests. See our Shift-Left Gap Report. SBOM regenerated on every release; transitive dependencies tracked
10 IT Committee guidance and a long-term plan for AI in threat detection and response A board-approved roadmap for AI-augmented SOC operations, governed agentic response and recalibrated cyber risk registers. IT Committee review every quarter; the plan refreshed every year
07 · Deep dive · Items 5 and 6

Slowing the scanner down, and catching the quiet probes

AI reconnaissance depends on being able to map an API quickly. Each gate below makes that slower, noisier or impossible. The SOC pipeline underneath is designed to notice the low-severity signals that such probing leaves behind.

API REQUEST PATH · FIVE GATES
GATE 1 mTLS client certificate No certificate, no TCP session
GATE 2 OAuth2 / JWT scope check Least privilege for each token
GATE 3 Token-bucket rate limit Throttles schema mapping and fuzzing
GATE 4 IP / identity allow-list No 0.0.0.0/0, ever
TARGET Core trading services Only verified, scoped, metered calls

Behind all five gates sits an automated API discovery process that finds shadow, orphaned and deprecated endpoints, because an API that is missing from the inventory has none of these controls.

SOC PIPELINE · ANNEXURE-A ITEM 6 TelemetryNetwork · endpoint · API SIEM detectionRules + analytics High severitySOAR: isolate, revoke, block Low priorityAI triage: spot probing patterns Market-SOC (NSE / BSE)Market-wide correlation
Why low-priority alerts matter

AI probing tends to look like edge-case parameters and odd protocol flags, which SIEM rules often score as noise. SEBI asks for low-priority alerts to be "adequately examined" for exactly this reason.

Why containment is automatic

If exploitation starts before the patch (Mandiant's −7 days), waiting for a person to approve isolating a host or revoking a token costs the lead defenders have left.

Why the Market-SOC

SEBI mandated NSE and BSE to set up the M-SOC for smaller regulated entities. NSE launched its M-SOC in January 2025. Probing seen at one firm becomes a warning for all the others.

08 · Adversary vs defence

Every AI attack vector has a named counter in Annexure-A

AI-driven adversaryDefensive controlItem
High-speed zero-day scanning
Continuous VA with conventional and AI scanners
#2
Rapid N-day exploit generation
Immediate patching plus interim virtual patching
#1
Multi-tenant COTS targeting
Vendor AI-risk assessments and COTS VAPT
#3
Automated API fuzzing and probing
Rate limiting, throttling and allow-listing
#5
Silent, low-and-slow reconnaissance
SIEM and SOAR review of low-priority alerts; M-SOC
#6
Supply-chain dependency exploits
Current asset inventory and SBOM
#9
09 · How regulators responded · 2026

SEBI was early, and it was not alone

Within eight weeks of the Mythos announcement, securities, insurance, banking and national cyber authorities in India had each acted. Items marked "secondary" are reported by the press; we did not find the regulator's own document.

  1. 7 Apr 2026 Anthropic announces Mythos Preview and Project Glasswing. Access is restricted to launch partners and open-source maintainers (Anthropic).
  2. 10 Apr 2026 US Treasury and Federal Reserve brief bank executives on Mythos-related cyber risk, according to Reuters citing Bloomberg secondary (Malay Mail / Reuters).
  3. 5 May 2026 SEBI issues the advisory and sets up the cyber-suraksha.ai task force primary (SEBI).
  4. 19 May 2026 IRDAI tells insurers to file action-taken reports on frontier-AI threats by 22 May secondary (MediaNama).
  5. 25 May 2026 CERT-In publishes its blueprint on AI-assisted exploitation: 12 hours for exploited internet-facing flaws, 1 day for critical external flaws, 5 days for high severity, all "where feasible" primary (CERT-In).
  6. Jun 2026 RBI asks banks for board-approved AI-risk gap assessments by the end of June secondary (Business Standard).
  7. 10 Sep 2026 SEBI Chairman at Global Fintech Fest: "Enforcement and adjudication cannot be delegated to the black box", and "Technology may be outsourced but regulatory responsibility cannot" (MediaNama).
10 · Roadmap · Intellinative recommendation

A 90-day path to an AI-resilient operating model

SEBI sets no timeline, so these phases are our recommendation. They are ordered by how quickly each control reduces exposure.

D1D16D46D90+
1 · Contain
2 · Supply chain
3 · Automate & harden
4 · Agentic defence
PHASE 1 · DAYS 1–15
Immediate containment
  • Emergency patch cycle across OS and core software
  • Virtual patches or WAF rules where no patch exists
  • Audit API endpoints and enforce rate limits
PHASE 2 · DAYS 16–45
Supply chain and vendors
  • AI-risk assessment requests to every COTS vendor
  • Validate SBOMs for the open-source stack
  • Start or complete M-SOC onboarding
PHASE 3 · DAYS 46–90
SOC automation and hardening
  • SOAR playbooks connected to the SIEM
  • ZTNA and least privilege enforced
  • A cyber drill that includes an AI-speed adversary
PHASE 4 · DAY 90+ · CONTINUOUS
Agentic defence and board alignment
  • IT Committee long-term AI defence plan
  • Cyber risk register recalibrated under CSCRF
  • Continuous scanning with defensive AI
THIS WEEK · 1Export SBOMs and an asset map for every production binary, cloud account and open-source library
THIS WEEK · 2Close every public API route that is not on the allow-list; enforce mTLS for institutional connections
THIS WEEK · 3Complete an internal posture review and open a line to the cyber-suraksha.ai task force
Claim check

Figures commonly repeated about Mythos and this advisory

Several numbers circulating in industry write-ups do not match the primary sources. Each was checked against Anthropic's publications and the SEBI circular itself.

ClaimStatusBasis
23,019 findings across 1,000+ projects, 6,202 high or critical Supported Stated in Anthropic's Glasswing update of 22 May 2026.
"Over 90% accuracy" Partial 90.6% true positives, but only among the 1,752 high or critical findings assessed so far. It is not a precision figure for all 23,019.
"72.4% of scenarios produced working RCE or privilege-escalation exploits" Not sourced This figure does not appear in Anthropic's publications. It seems to come from secondary blogs. The primary comparison is 181 working exploits against 2 on the Firefox 147 JS engine (Anthropic).
27-year-old OpenBSD TCP bug Qualify Real and now patched, but it is a remote denial-of-service bug in the SACK code, not a code-execution flaw.
The advisory covers "20 entity classes", including QRTAs Partial The circular has 19 addressee lines, some combining two entity types. QRTAs are task force members, not addressees.
SEBI mandates 24–48 hour zero-day mitigation and daily VAPT Qualify The circular sets no numeric deadlines. "Immediate" patching and "regular/continuous" assessment are its words. Specific SLAs are good practice, not SEBI requirements.
CERT-In "mandates" 12-hour patching Qualify The blueprint recommends 12 hours "where feasible". It is guidance. CERT-In's binding duties, such as 6-hour incident reporting, come from its April 2022 Directions.
What the sources establish
  • Frontier AI models find real, high-severity flaws at a scale and precision earlier tools did not reach, including in decades-old, heavily reviewed code.
  • Exploitation increasingly starts before patches exist: Mandiant's mean time-to-exploit is −7 days, and nearly a quarter of 2026 KEVs were exploited on or before disclosure.
  • SEBI's advisory covers the whole securities market and ties AI risk directly to existing CSCRF obligations.
  • Indian regulators across securities, insurance, banking and national cyber defence acted within weeks of each other.
What this report infers
  • Shared COTS software and API meshes make AI-found flaws a systemic risk for capital markets, not only a risk to individual firms. No source here measures that concentration directly.
  • The binding constraint is fix speed, not find speed. Controls that cut exposure without a patch (virtual patching, allow-lists, rate limits, segmentation) buy the most time.
  • Defensive AI scanning must run inside controlled environments, with every result validated by a person, or it creates the confidentiality and integrity risks SEBI names.
Conclusion

SEBI's advisory moves Indian capital-market cybersecurity from periodic checklists towards a continuous posture. It accepts that Mythos-class models change how fast and how widely flaws are found. Regulated entities that combine continuous assessment, Zero Trust APIs, firm vendor governance and market-wide monitoring through the M-SOC and cyber-suraksha.ai will be ready for this advisory and for whatever SEBI issues next.

Frequently asked questions

What is SEBI's advisory on AI tools for vulnerability detection?

It is SEBI circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, issued on 5 May 2026 under Section 11(1) of the SEBI Act. It warns that advanced AI tools such as Claude Mythos can find and exploit vulnerabilities at speed and scale, sets up the cyber-suraksha.ai task force and lists ten controls in Annexure-A for regulated entities.

Which entities does the SEBI advisory apply to?

It is addressed to 19 lines of regulated entities: stock exchanges, clearing corporations, depositories, depository participants, stock brokers, mutual funds and AMCs, AIFs, VCFs, collective investment schemes, portfolio managers, investment advisers and research analysts, merchant bankers, RTAs, bankers to an issue and SCSBs, custodians, debenture trustees, designated depository participants, credit rating agencies and KYC registration agencies.

What are the 10 controls in Annexure-A?

Immediate and virtual patching; vulnerability assessment with conventional and AI-based tools; vendor and COTS risk assessment; change management; API security (inventory, authentication, rate limiting and whitelisting); SOC review including low-priority alerts, SOAR and M-SOC onboarding; AI scenarios in CSCRF risk assessment and testing; hardening and Zero Trust; asset inventory and SBOM; and IT Committee oversight of a long-term AI strategy.

Does SEBI set deadlines for these controls?

No. The circular sets no numeric deadlines. It asks for patching on an immediate basis and for M-SOC onboarding to be expedited. Specific targets such as 12-hour mitigation come from CERT-In's May 2026 blueprint, which is itself advisory, or from good practice.

What did Anthropic's Project Glasswing find?

Anthropic reported 23,019 potential vulnerabilities across more than 1,000 open-source projects, 6,202 rated high or critical. Of 1,752 high or critical findings assessed by 22 May 2026, 90.6% were true positives and 62.4% were confirmed high or critical. 530 had been disclosed and 75 patched.

What is the cyber-suraksha.ai task force?

A SEBI task force of representatives from MIIs, Qualified RTAs, Qualified Regulated Entities and other stakeholders. Its four mandates are to assess AI-model cyber risk and set a uniform mitigation strategy, share threat intelligence and best practices, report incidents and vulnerabilities on priority, and review the security posture of third-party application vendors.

Sources linked in this report

  1. Anthropic, Glasswing update
  2. Anthropic, Mythos Preview
  3. Google Mandiant M-Trends 2026
  4. VulnCheck 1H-2026
  5. BIS Bulletin No. 129
  6. CERT-In Blueprint v1.0
  7. Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection (like Mythos)
  8. Project Glasswing
  9. Cybersecurity and Cyber Resilience Framework (CSCRF)
  10. Circular PDF (sebi.gov.in)
  11. MediaNama
  12. Oct 2025
  13. M-SOC
  14. January 2025
  15. Malay Mail / Reuters
  16. MediaNama
  17. Business Standard