Nirmala Sitharaman has raised a serious alarm over emerging cybersecurity risks linked to advanced artificial intelligence, warning that cutting-edge models like Claude Mythos could pose unprecedented threats to India’s banking infrastructure. The warning came after a high-level meeting with top bank executives, where the focus was on strengthening defenses against a new generation of AI-powered cyberattacks.
What Is Claude Mythos and Why It Matters
Developed by Anthropic, Claude Mythos is an experimental AI model designed with extraordinary capabilities in cybersecurity. Unlike traditional systems, Mythos can autonomously identify and exploit “zero-day” vulnerabilities—hidden flaws in software that even developers may not yet know exist.
In internal testing, the model reportedly uncovered thousands of critical weaknesses across operating systems and web browsers, accomplishing in hours what would typically take human experts months. While such capability can be used for defensive purposes, the concern is clear: if accessed by malicious actors, it could dramatically accelerate cyberattacks, enabling sophisticated phishing campaigns, malware creation, and coordinated system breaches.
Recognizing these risks, Anthropic has restricted access to Mythos under its “Glasswing” program, limiting its use to select partners working on critical infrastructure. Even so, the mere existence of such technology has raised alarms among governments worldwide.
Why It Is Considered Dangerous
The danger of Mythos lies not just in its power, but in its speed and scalability. Traditional cyberattacks often require time, expertise, and coordination. AI models like Mythos compress this process, allowing attackers to identify vulnerabilities, generate exploits, and launch attacks almost simultaneously.
For a country like India, with a vast and interconnected digital financial ecosystem, this presents a serious challenge. Core banking systems, payment gateways, and digital platforms could become targets for rapid, large-scale attacks. The risk is amplified by the increasing digitization of financial services, which, while improving efficiency, also expands the attack surface.
Sitharaman’s warning reflects a broader concern: that AI is shifting the balance in cybersecurity from reactive defense to proactive, high-speed offense.
India’s Immediate Response in the Financial Sector
In response, the finance ministry has initiated a coordinated push to strengthen cyber defenses across the banking sector. The Indian Banks’ Association has been tasked with creating a real-time threat intelligence-sharing framework in collaboration with CERT-In.
Banks have been urged to establish specialized cybersecurity teams and deploy advanced monitoring systems capable of detecting AI-driven anomalies. The focus is on staying ahead of threats rather than merely responding to them after the fact.
Long-Term Strategy: Building AI-Resilient Systems
Looking ahead, India is expected to adopt a more comprehensive regulatory and technological framework to address AI-driven cyber risks. This includes tighter controls on access to high-risk AI models, clearer guidelines for AI-assisted security testing, and the integration of “defense-by-design” principles into financial systems.
Such an approach emphasizes embedding security at every stage—through threat modeling, continuous testing, and real-time response mechanisms—ensuring resilience against evolving threats.
Preparing for an AI-Driven Security Era
The emergence of tools like Claude Mythos marks a turning point in cybersecurity. While AI offers immense potential for innovation, it also introduces risks that are faster, smarter, and harder to contain.
India’s proactive stance signals an awareness that the future of financial security will depend on anticipating threats before they materialize. As AI continues to evolve, the challenge will be to harness its benefits while building robust safeguards—ensuring that technological progress does not come at the cost of systemic vulnerability.
(With agency inputs)