SEBI circular HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 · 05 May 2026
Official title
Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection
Summary
Check the official recordSEBI has issued an advisory regarding the cybersecurity risks posed by advanced AI-driven vulnerability detection tools, such as Mythos, which enable rapid, large-scale identification and potential exploitation of vulnerabilities. To address these risks, SEBI has established a task force, 'cyber-suraksha.ai', to coordinate threat intelligence and mitigation strategies. Regulated entities are required to implement robust security measures, including immediate patching, regular vulnerability assessments, API security, and enhanced SOC monitoring. Entities must also review third-party vendor security and expedite onboarding to the Market SOC (M-SOC) where applicable. This advisory complements existing SEBI cybersecurity frameworks and mandates a long-term strategic approach to AI-augmented threat mitigation.
What you must do
Who is affected
परिपत्र / CIRCULAR
HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026
05.05.2026
प्रति, To,
सभी ऑल्टिनेटटव इनवेस्टमेंट फं ड (एआईफ) All Alternative Investment Funds (AIFs)
सभी बकैं ि टू इश्यूऔि सल्े फ-सटटिफाइड सस ंडीके ट बैंक (एससीएसबी) All Bankers to an Issue (BTI) and Self-Certified Syndicate Banks (SCSBs)
सभी क्लीयरिंग कािपोिेशन All Clearing Corporations
सभी कलेक्क्टव इनवेस्टमेंट स्कीमें (सीआईएस) All Collective Investment Schemes (CIS)
सभी क्रे डडट िेटटंग एजेंससयााँ (सीआिए) All Credit Rating Agencies (CRAs)
सभी कस्टोडडयन All Custodians
सभी डडबेंचि ट्रस्टी (डीटी) All Debenture Trustees (DTs)
सभी डडपॉक्िटिी All Depositories
सभी डेससग्नेटेड डडपॉक्िटिी पाटटिससपेंट (डीडीपी) All Designated Depository Participants (DDPs)
सभी डडपॉक्िटिी पाटटिससपेंट (डडपॉक्िटिीि के जरिए) All Depository Participants through Depositories
सभी ननवेश सलाहकाि (आईए) / अनसु धं ान ववश्लेषक (आिए) All Investment Advisors (IAs) / Research Analysts (RAs)
सभी के वाईसी िक्जस्ट्रेशन एजेंससयााँ (के आिए) All KYC Registration Agencies (KRAs)
सभी मचेंट बैंकि (एमबी) All Merchant Bankers (MBs)
सभी म्यचू ुअल फंड (एमएफ) / असेट मैनेजमेंट कं पननयााँ (एएमसी) All Mutual Funds (MFs)/ Asset Management Companies (AMCs)
सभी पोटिफोसलयो प्रबंधक All Portfolio Managers
सभी िक्जस्ट्राि टू इश्यूऔि शेयि ट्रांसफि एजेंट (आिटीए) All Registrar to an Issue and Share Transfer Agents (RTAs)
सभी स्टॉक ब्रोकि (एक्सचेंजों के जरिए) All Stock Brokers through Exchanges
सभी स्टॉक एक्सचेंज All Stock Exchanges
सभी वेंचि कै वपटल फं ड (वीसीएफ) All Venture Capital Funds (VCFs)
महोदय/महोदया, Dear Sir/Madam,
विषय: खामियों (वल्नरेबिमलटी) का पता लगाने के सलए आए नए-नए एडवांस्ड एआई टूल (जैसे Mythos) के संबंध में एडवाइििी Subject: Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection (like Mythos)
क. खाममयों (वल्नरेबिमलटी) का पता लगाने वाले नए-नए एआई टूल (जैसे Claude Mythos) आने लगे हैं, जजनकी िदौलत ववननयममत (रेग्यलू ेटेड) एटं टटटयों के सामने नए-नए जोखखमों की आशंकाएँ पैदा हो रही हैं। जैसा कक ये टूल िड़ी तेज़ी से और िडे पैमाने पर काम करते हैं, तो यह ममु ककन है कक इनकी िदौलत जोखखमों की आशंका भ़ी काफी िढ़ जाए । इसके अलावा, यह भ़ी ममु ककन है कक डाटा की गोपऩीयता भ़ी खतरे में आ जाए, ऐजललके शन की ववश्वसऩीयता पर भ़ी सवाल खडा हो, और तो और उसके नत़ीजों को लेकर भ़ी भरोसा न हो ।
A. The rapid evolution of emerging technologies including AI-driven vulnerability identification tools (E.g. Claude Mythos) has introduced new dimensions of risks for Regulated Entities. Such tools may give rise to heightened risk exposure by enabling identification and potential exploitation of existing vulnerabilities using speed and scale. It may also introduce concerns relating to data confidentiality, application integrity and reliability of outputs.
ख. जैसा कक मसक्यरूरटीज़ माकेट की समचू ़ी व्यवस्था में सभ़ी माकेट पाटटिमसपेंट्स का एक-दसू रे से सरोकार भ़ी रहता है और उनकी एक-दसू रे पर ननभरि ता भ़ी रहत़ी है, इस़ीमलए यह जरूरी है कक इनकी खाममयों (वल्नरेबिमलटी) को दरू करने, जानकारी एक दसू रे से साझा करने और इन पर नज़र रखने / इनका आकलन करने के मलए एक साझा प्रयास ककया जाए, ताकक कहीं ऐसा न हो कक ककस़ी एक जगह या ककस़ी एक पर अगर आँच आए तो उसका असर ताश के पत्तों की तरह दसू री जगह या दसू रों पर भ़ी बिखरता नज़र आए ।
B. Due to the interconnectedness and interdependency of market participants in the Securities Market Ecosystem, a periodic coordinated approach for vulnerability management, information sharing and monitoring/assessment is required to prevent a cascading impact.
ग. उपरोक्त के मद्देनज़र, एक कायि-दल (टास्क फोसि), जजसका नाम cyber-suraksha.ai है (ईमेल आईड़ी: project-cyber-suraksha.ai@sebi.gov.in) िनाया गया है, जजसमें MIIs, QRTAs, सभ़ी QREs और दसू रे संिंधित स्टेकहोल्डसि के प्रनतननधियों को शाममल ककया गया है । इस कायि-दल के मख्ु य कायि इस प्रकार हैं:
C. In view of the above, a task force, namely cyber-suraksha.ai, (email id: project-cyber-suraksha.ai@sebi.gov.in) has been constituted comprising representatives from MIIs, QRTAs, all QREs, and other related stakeholders with the following mandate to:
i. िारीकी से यह जाँचना कक एआई वाले मॉडल से साइिर सरुक्षा को लेकर क्या-क्या जोखखम हो सकते हैं और ऐसे मॉडल की वजह से पैदा हो सकने वाले जोखखमों से ननपटने के मलए एकसमान ऩीनत ननिाररत करना । i. Closely examine the cybersecurity risks posed by AI based models and devise a uniform mitigation strategy against the risks posed by such models.
ii. अगर ककस़ी खतरे की आशंका की कोई जानकारी ममले, तो उसे साझा करना; खाममयों (वल्नरेबिमलटी) को दरू करने के मलए अपनाए जाने वाले िेहतरीन तरीकों की जानकारी साझा करना; यह जानकारी साझा करना कक खतरों से कै से ननपटा जाए। ii. Facilitate sharing of threat intelligence, best practices on vulnerability management, use cases and playbooks to respond to the threat vector etc.
iii. मसक्यरूरटीज़ माकेट में साइिर सरुक्षा की व्यवस्था को और पख्ु ता करने के मलहाज से साइिर हमलों की, गडिड़ी की हो रही कोमशशों की या िडे हमलों की तत्काल सचू ना देना, खाममयों (वल्नरेबिमलटी) आटद की तत्काल सचू ना देना । iii. Report on a priority basis, cyber incidents or malicious activities, significant attack vectors, information on vulnerabilities etc. that may be relevant to strengthen the cyber security posture of the securities markets.
iv. यह सम़ीक्षा करना कक थडि पाटी ऐललीके शन सववसि प्रोवाइडसि (सचू ़ी में शाममल वेंडरों सटहत) के यहाँ साइिर सरुक्षा की व्यवस्था कै स़ी है । iv. Review the cyber security posture of the third party application service providers including empaneled vendors.
घ. Mythos जैसे एआई ललेटफॉमि की वजह से पैदा हो सकने वाले जोखखमों की सम़ीक्षा करने और उनसे ननपटने के मलए उठाए जाने वाले कदमों के िारे में चचाि करने के मलए MIIs और QRTAs के साथ कायि-दल (टास्क फोसि) cyber-suraksha.ai की एक िैठक िलु ाई गई थ़ी । कायि-दल (टास्क फोसि) की इस िैठक में हुए ववचार-ववमशि के आिार पर, एक एडवाइज़री संलग्नक-क (Annexure-A) के रूप में संलग्न है ।