
When AI finds the flaw first, defence has to move at machine speed.
Frontier AI models now find, triage and weaponise software flaws in hours. On 5 May 2026, SEBI told every regulated entity in India's securities market to prepare for that. This report reads the advisory against Anthropic's own published figures, exploitation telemetry and the responses of other regulators, then turns the 10-point Annexure-A into an operating plan.
What frontier AI changed in 2026, measured
The first four figures come from Anthropic's own reporting on Claude Mythos Preview and Project Glasswing. The rest are exploitation telemetry and regulator guidance. The source line under each figure says who measured it and how.
One advisory, the whole securities market
On 5 May 2026, SEBI's Information Technology Department issued an Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection (like Mythos). It was issued under Section 11(1) of the SEBI Act, 1992, which charges SEBI with protecting investors and regulating the securities market. Deputy General Manager Mamata Roy signed it. The title names Anthropic's Claude Mythos, which Anthropic announced on 7 April alongside Project Glasswing, a restricted-access programme for defenders.
The advisory is addressed to 19 lines of regulated entities, from stock exchanges to investment advisers. Some lines cover two entity types, such as Bankers to an Issue and SCSBs. It does two things: it sets up a task force, and it attaches ten controls in Annexure-A that build on SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) of August 2024.
Grouping is ours. The circular lists the addressees alphabetically and does not use the term "MII". Qualified RTAs appear only as task force members, not as addressees.
From signature matching to reasoning about code
Earlier automated scanners matched signatures, looked up known CVEs or fuzzed inputs. They produced noisy results, and a person still had to build the exploit. Anthropic reports that Mythos Preview reasons across a codebase, finds flaws in both source and closed-source binaries, and turns known "N-day" vulnerabilities into working exploits. Its examples include a Linux kernel root exploit built in under a day for under $2,000 (Anthropic).
- Signature and template matching
- Known CVE lookup (N-days only)
- High false-positive noise
- Exploits built manually by specialists
- Research cycles of weeks to months
- Reasoning across the whole codebase and call graph
- Zero-day discovery in source and closed-source binaries
- 90.6% true positives in a 1,752-finding sample
- Exploits generated autonomously, including from N-day patches
- Discovery-to-exploit compressed to hours or days
The gap that matters. Finding has outrun fixing. Anthropic projects nearly 3,900 valid high or critical bugs in the full set, but only 75 were patched by 22 May, and it says over 99% of what it found was not yet patched when it published. Defenders inherit that backlog, and attackers with similar tools can work through it too.
Mythos also reached register control 29 more times. These are JavaScript-shell exploits in a test harness, not success rates against production systems (Anthropic).
The BIS also estimates that a full attack chain costs about $5,000–10,000 on frontier models and $50–100 on cheaper ones (BIS Bulletin 129).
Three risks, named in the circular
"Such tools may give rise to heightened risk exposure by enabling identification and potential exploitation of existing vulnerabilities using speed and scale. It may also introduce concerns relating to data confidentiality, application integrity and reliability of outputs."SEBI advisory, para A · 5 May 2026
AI agents can scan broker endpoints, API gateways and open-source dependencies continuously, at almost no marginal cost. Defenders still patch through change windows and people.
Sending proprietary source code, logs or API telemetry into external or unvetted AI tools risks leaking data and intellectual property. That is a concern for defenders using the tools as well as for attackers.
Hallucinated findings, flawed AI-generated patches or unverified automatic fixes can introduce new defects into trading systems. SEBI's Chairman put it plainly in September: "An AI-generated alert is not a finding" (MediaNama).
The cyber-suraksha.ai task force
SEBI set up a task force of representatives from MIIs, Qualified RTAs, all Qualified Regulated Entities and "other related stakeholders". Its contact address, as printed in the circular, is project-cybersuraksha.ai@sebi.gov.in. It has four mandates.
Mandates paraphrased from the circular. It sets no reporting deadlines for the task force and no timelines for regulated entities.
One shared flaw, many institutions
A trade moves from an investor's app, through a broker's API, to an exchange's matching engine, then on to clearing and the depository, all within milliseconds. Many brokers and asset managers also run the same third-party order-management and back-office software. A flaw in a shared component therefore affects many firms at the same moment. The BIS makes the same point about concentration in its July 2026 bulletin.
When dozens of brokers and asset managers run the same order-management or settlement package, one zero-day in that vendor's binary opens many networks at once. This is why Annexure-A item 3 puts COTS vendors in scope.
Broker–exchange and algorithmic trading integrations run on APIs. An AI-found authentication bypass or rate-limit defect could be used to disrupt order books or inject orders before SOC analysts spot the anomaly.
An incident at a clearing corporation or depository can halt settlement and freeze liquidity across exchanges, funds and custodians. Such institutions carry a heavy attack load: Business Standard reported NSE facing around 170 million attempted attacks a day (Oct 2025).
From SEBI's wording to a working control
The second column paraphrases the circular. The third and fourth columns are Intellinative's recommended implementation and targets. SEBI sets no numeric deadlines: its only words of urgency are "immediate" for patching and "expedite" for M-SOC onboarding.
Slowing the scanner down, and catching the quiet probes
AI reconnaissance depends on being able to map an API quickly. Each gate below makes that slower, noisier or impossible. The SOC pipeline underneath is designed to notice the low-severity signals that such probing leaves behind.
Behind all five gates sits an automated API discovery process that finds shadow, orphaned and deprecated endpoints, because an API that is missing from the inventory has none of these controls.
AI probing tends to look like edge-case parameters and odd protocol flags, which SIEM rules often score as noise. SEBI asks for low-priority alerts to be "adequately examined" for exactly this reason.
If exploitation starts before the patch (Mandiant's −7 days), waiting for a person to approve isolating a host or revoking a token costs the lead defenders have left.
SEBI mandated NSE and BSE to set up the M-SOC for smaller regulated entities. NSE launched its M-SOC in January 2025. Probing seen at one firm becomes a warning for all the others.
Every AI attack vector has a named counter in Annexure-A
SEBI was early, and it was not alone
Within eight weeks of the Mythos announcement, securities, insurance, banking and national cyber authorities in India had each acted. Items marked "secondary" are reported by the press; we did not find the regulator's own document.
- 7 Apr 2026 Anthropic announces Mythos Preview and Project Glasswing. Access is restricted to launch partners and open-source maintainers (Anthropic).
- 10 Apr 2026 US Treasury and Federal Reserve brief bank executives on Mythos-related cyber risk, according to Reuters citing Bloomberg secondary (Malay Mail / Reuters).
- 5 May 2026 SEBI issues the advisory and sets up the cyber-suraksha.ai task force primary (SEBI).
- 19 May 2026 IRDAI tells insurers to file action-taken reports on frontier-AI threats by 22 May secondary (MediaNama).
- 25 May 2026 CERT-In publishes its blueprint on AI-assisted exploitation: 12 hours for exploited internet-facing flaws, 1 day for critical external flaws, 5 days for high severity, all "where feasible" primary (CERT-In).
- Jun 2026 RBI asks banks for board-approved AI-risk gap assessments by the end of June secondary (Business Standard).
- 10 Sep 2026 SEBI Chairman at Global Fintech Fest: "Enforcement and adjudication cannot be delegated to the black box", and "Technology may be outsourced but regulatory responsibility cannot" (MediaNama).
A 90-day path to an AI-resilient operating model
SEBI sets no timeline, so these phases are our recommendation. They are ordered by how quickly each control reduces exposure.
- Emergency patch cycle across OS and core software
- Virtual patches or WAF rules where no patch exists
- Audit API endpoints and enforce rate limits
- AI-risk assessment requests to every COTS vendor
- Validate SBOMs for the open-source stack
- Start or complete M-SOC onboarding
- SOAR playbooks connected to the SIEM
- ZTNA and least privilege enforced
- A cyber drill that includes an AI-speed adversary
- IT Committee long-term AI defence plan
- Cyber risk register recalibrated under CSCRF
- Continuous scanning with defensive AI
Figures commonly repeated about Mythos and this advisory
Several numbers circulating in industry write-ups do not match the primary sources. Each was checked against Anthropic's publications and the SEBI circular itself.
- Frontier AI models find real, high-severity flaws at a scale and precision earlier tools did not reach, including in decades-old, heavily reviewed code.
- Exploitation increasingly starts before patches exist: Mandiant's mean time-to-exploit is −7 days, and nearly a quarter of 2026 KEVs were exploited on or before disclosure.
- SEBI's advisory covers the whole securities market and ties AI risk directly to existing CSCRF obligations.
- Indian regulators across securities, insurance, banking and national cyber defence acted within weeks of each other.
- Shared COTS software and API meshes make AI-found flaws a systemic risk for capital markets, not only a risk to individual firms. No source here measures that concentration directly.
- The binding constraint is fix speed, not find speed. Controls that cut exposure without a patch (virtual patching, allow-lists, rate limits, segmentation) buy the most time.
- Defensive AI scanning must run inside controlled environments, with every result validated by a person, or it creates the confidentiality and integrity risks SEBI names.
SEBI's advisory moves Indian capital-market cybersecurity from periodic checklists towards a continuous posture. It accepts that Mythos-class models change how fast and how widely flaws are found. Regulated entities that combine continuous assessment, Zero Trust APIs, firm vendor governance and market-wide monitoring through the M-SOC and cyber-suraksha.ai will be ready for this advisory and for whatever SEBI issues next.
Frequently asked questions
What is SEBI's advisory on AI tools for vulnerability detection?
It is SEBI circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, issued on 5 May 2026 under Section 11(1) of the SEBI Act. It warns that advanced AI tools such as Claude Mythos can find and exploit vulnerabilities at speed and scale, sets up the cyber-suraksha.ai task force and lists ten controls in Annexure-A for regulated entities.
Which entities does the SEBI advisory apply to?
It is addressed to 19 lines of regulated entities: stock exchanges, clearing corporations, depositories, depository participants, stock brokers, mutual funds and AMCs, AIFs, VCFs, collective investment schemes, portfolio managers, investment advisers and research analysts, merchant bankers, RTAs, bankers to an issue and SCSBs, custodians, debenture trustees, designated depository participants, credit rating agencies and KYC registration agencies.
What are the 10 controls in Annexure-A?
Immediate and virtual patching; vulnerability assessment with conventional and AI-based tools; vendor and COTS risk assessment; change management; API security (inventory, authentication, rate limiting and whitelisting); SOC review including low-priority alerts, SOAR and M-SOC onboarding; AI scenarios in CSCRF risk assessment and testing; hardening and Zero Trust; asset inventory and SBOM; and IT Committee oversight of a long-term AI strategy.
Does SEBI set deadlines for these controls?
No. The circular sets no numeric deadlines. It asks for patching on an immediate basis and for M-SOC onboarding to be expedited. Specific targets such as 12-hour mitigation come from CERT-In's May 2026 blueprint, which is itself advisory, or from good practice.
What did Anthropic's Project Glasswing find?
Anthropic reported 23,019 potential vulnerabilities across more than 1,000 open-source projects, 6,202 rated high or critical. Of 1,752 high or critical findings assessed by 22 May 2026, 90.6% were true positives and 62.4% were confirmed high or critical. 530 had been disclosed and 75 patched.
What is the cyber-suraksha.ai task force?
A SEBI task force of representatives from MIIs, Qualified RTAs, Qualified Regulated Entities and other stakeholders. Its four mandates are to assess AI-model cyber risk and set a uniform mitigation strategy, share threat intelligence and best practices, report incidents and vulnerabilities on priority, and review the security posture of third-party application vendors.
Sources linked in this report
- Anthropic, Glasswing update
- Anthropic, Mythos Preview
- Google Mandiant M-Trends 2026
- VulnCheck 1H-2026
- BIS Bulletin No. 129
- CERT-In Blueprint v1.0
- Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection (like Mythos)
- Project Glasswing
- Cybersecurity and Cyber Resilience Framework (CSCRF)
- Circular PDF (sebi.gov.in)
- MediaNama
- Oct 2025
- M-SOC
- January 2025
- Malay Mail / Reuters
- MediaNama
- Business Standard