IFSCA circular IFSCA-CSD/MSC/3/2026-DCS · 04 Jun 2026
Summary
Check the official recordThe IFSCA has issued an advisory for all Regulated Entities (REs) in International Financial Services Centres regarding the accelerated cyber security risks posed by frontier Artificial Intelligence models. These models can rapidly identify vulnerabilities and generate exploits, significantly reducing the time between vulnerability disclosure and potential attack. REs are required to reassess their cyber security risk profiles, incorporate AI-driven threat scenarios into their assessments, and implement robust mitigating controls. Key measures include maintaining a Software Bill of Materials (SBOM), implementing phishing-resistant Multi-Factor Authentication, strengthening API security, and ensuring critical service providers are prepared for accelerated exploit timelines. REs must also enhance monitoring for AI-driven attack patterns and ensure rigorous human oversight when utilizing AI tools for vulnerability management.
What you must do
Key dates
Who is affected
CIRCULAR
IFSCA-CSD/MSC/3/2026-DCS June 04, 2026
To, All Regulated Entities in the International Financial Services Centres (IFSCs)
Dear Madam/Sir,
Sub: Advisory on Heightened Cyber Security Risks arising from Frontier Artificial Intelligence Models
IFSCA, vide circular dated March 10, 2025, issued the 'Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs', as amended vide circular IFSCA-CSD/MSC/1/2026-DCS dated March 10, 2026, prescribing a principles-based minimum baseline framework applicable to all Regulated Entities. Subsequently, vide circular IFSCA-CSD/MSC/2/2026-DCS dated April 20, 2026, IFSCA issued the 'Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions (MIIs) in IFSC'. This advisory shall be read in conjunction with the applicable guidelines, and does not dilute any obligation thereunder.
Recent advances in frontier Artificial Intelligence (AI) models represent an accelerated change in offensive cyber capabilities. Such models can analyse large and complex codebases, identify known and previously unknown (zero-day) vulnerabilities, reason about exploitability, and generate working exploits, at a speed, scale and cost that significantly lowers the barrier to mounting sophisticated attacks, compressing the time between disclosure of a vulnerability and its exploitation from weeks to hours.
Although the most capable of these models are presently subject to restricted availability, such capabilities are expected to diffuse rapidly. Accordingly, REs should strengthen their security posture ahead of the wider availability of such models and should reassess their cyber security risk and implement mitigating controls in accordance with the principle of proportionality.
REs are encouraged to comply with the measures set out in Annexure A.
This Circular is issued in exercise of the powers conferred by Sections 12 and 13 of the International Financial Services Centres Authority Act, 2019, to develop and regulate the financial services market in the International Financial Services Centre.
This Circular shall come into force with immediate effect. A copy of this circular is available on the website at www.ifsca.gov.in.
Yours Faithfully,
Praveen Kamat Chief General Manager Division of Cyber Security Email: praveen.kamat@ifsca.gov.in Tel: +91- 079 - 61809820
ANNEXURE A