India Faces a New Cybersecurity Challenge as AI Accelerates Threats
AI is making cyberattacks faster, more scalable and increasingly autonomous. For India, growing exposure of critical infrastructure and dependence on foreign AI capabilities raise urgent cybersecurity questions.
Xcademia Team
Xcademia Research Team

India Faces a New Cybersecurity Challenge as AI Accelerates Threats
Artificial intelligence is changing cybersecurity from both sides of the threat landscape. The same technologies that can help organisations detect attacks and respond faster can also help attackers automate reconnaissance, generate convincing social-engineering campaigns, discover vulnerabilities and adapt malicious code.
For India, the shift is particularly significant. The country faces a substantial cyber threat environment while still developing capabilities across the broader AI technology stack.
A recent analysis published by The Indian Express examines how AI is changing the speed and scale of cyber threats and what this means for India's cyber preparedness.
AI is increasing the speed and scale of cyber threats
The adoption of generative AI has happened remarkably quickly. The article notes that while the internet took around 15 years to reach one billion users, ChatGPT reached that level of adoption in three years.
That rapid diffusion also affects cybersecurity.
AI can support activities across multiple stages of a cyberattack. Tasks that previously required significant human effort can increasingly be assisted or automated, including gathering information about targets, creating phishing material, generating deepfakes and identifying potential vulnerabilities.
The change is not simply about making existing attacks faster. More advanced AI systems are increasingly capable of identifying objectives, planning actions and adapting to changing circumstances.
This introduces the possibility of cyber operations involving increasingly autonomous AI agents.
From reconnaissance to AI-generated social engineering
Reconnaissance is one area where AI can significantly reduce the amount of manual work required by attackers.
According to the article, AI models can be used to analyse publicly available information, including social media data, to gather details about potential targets. This information can then help create more convincing spear-phishing messages.
AI-generated content also makes social engineering more difficult to identify.
Deepfake technology can generate convincing audio, images and video, creating additional opportunities for impersonation and deception. As synthetic media becomes more difficult to distinguish from authentic content, organisations may need stronger processes for verifying digital communications and identities.

The rise of adaptive and autonomous cyber operations
One of the more concerning developments described in the article is the emergence of AI-generated polymorphic malware.
Traditional malware can often be identified through known patterns or signatures. Polymorphic malware is designed to change its code structure or characteristics, making detection more difficult.
Large language models could potentially assist with generating or modifying malicious code according to changing circumstances.
The article also points to Anthropic's September 2025 claim that a Chinese state-sponsored group identified as GTG-1002 allegedly used Claude Code as an autonomous cyber agent across multiple stages of an attack. Anthropic described the incident as the first reported example of an AI-orchestrated cyber-espionage campaign.
These developments illustrate a broader shift from AI being used simply as a tool toward AI systems potentially performing multiple connected tasks within an operation.
AI-assisted vulnerability discovery raises the stakes
Another major development is the ability of frontier AI models to identify software vulnerabilities at scale.
The article reports that Anthropic's Claude Mythos Preview identified thousands of zero-day vulnerabilities across major operating systems and browsers, including critical flaws, and developed related exploits largely without human intervention.
The article highlights the discovery of a 27-year-old vulnerability in OpenBSD, an operating system known for its security focus and used in environments such as firewalls and critical infrastructure.
The importance of this development extends beyond individual software products.
Many industrial environments depend on Operational Technology (OT) and Industrial Control Systems (ICS) to manage physical processes. These systems are used across sectors including energy, manufacturing, chemicals, oil and communications.
As these environments become increasingly connected and incorporate more digital and AI technologies, vulnerabilities could have consequences beyond conventional IT systems.
Why traditional cyber defences may face pressure
Many traditional security tools were designed around relatively predictable threats.
Antivirus technologies, for example, can rely on known malware signatures, while conventional vulnerability management often involves identifying a flaw, developing a patch and deploying it across affected systems.
AI-assisted attacks can potentially operate at a different speed.
Malicious code that changes its characteristics can make signature-based detection more challenging. Automated vulnerability discovery can also shorten the time between a vulnerability becoming discoverable and an attacker attempting to exploit it.
The Indian Express article cites CERT-In guidance warning organisations to treat newly discovered vulnerabilities as potentially exploitable within hours rather than weeks.
That change in timeframe is important for defenders.
Organisations may increasingly need continuous monitoring, rapid patching, automated detection and faster incident response rather than relying primarily on periodic security reviews.
India faces a complex AI and cybersecurity challenge
The issue is particularly important for India because the country already faces significant cyber threats.
The article cites CloudSEK reports that ranked India as the second-most cyber-attacked country after the US in its 2024 report and sixth in its 2025 report.
The article also refers to a ransomware group's claim that it had obtained data related to the Kudankulam nuclear plant, including facility blueprints and supplier information. Such claims should be treated as claims by the threat actor unless independently verified.
It also discusses cyber activity during Operation Sindoor, including attacks attributed to Pakistan-backed threat actors against Indian government and defence-related targets.

India's AI capability gap adds another dimension
Cybersecurity capabilities increasingly depend on access to advanced AI infrastructure.
The article argues that India's indigenous AI ecosystem remains behind the US and China in areas including foundational models, GPUs, chip design and large-scale data-centre infrastructure.
This creates a strategic challenge.
AI is becoming both a cybersecurity capability and a potential source of cyber risk. Countries with advanced AI ecosystems can potentially use those capabilities for defensive purposes, while also possessing greater potential to conduct sophisticated cyber operations.
For India, this means cybersecurity cannot be considered separately from AI development.
Building domestic capabilities across AI infrastructure, research, computing and security could become increasingly important to national cyber resilience.
India is already taking steps
Indian policymakers have recognised the connection between AI and cybersecurity.
The article highlights work by CERT-In involving AI-driven threat detection, cyber resilience measures, trusted AI frameworks and citizen-focused malware mitigation.
It also notes that CERT-In issued guidance in April on defending organisations against AI-driven cyber risks.
At the policy level, the Ministry of Electronics and Information Technology is exploring measures related to synthetically generated content, including a consent-based framework. The article also discusses potential controls around agentic AI autonomy and clearer liability frameworks for AI models.
These efforts indicate that India's response is developing across several areas: technical defence, governance, accountability and AI policy.

AI and cybersecurity can no longer be treated separately
The central issue is not whether AI will be used in cybersecurity. It is already being used on both sides.
Defenders can use AI to analyse large volumes of security data, identify suspicious activity and accelerate responses. Attackers can use similar technologies to automate reconnaissance, create convincing social engineering, identify vulnerabilities and potentially coordinate more complex operations.
This creates a constantly evolving security environment.
For enterprises, the development could mean that cybersecurity strategies need to place greater emphasis on rapid vulnerability management, identity verification, continuous monitoring, resilience and controls around AI systems themselves.
For governments, the challenge is broader. Building secure AI capabilities may increasingly be connected to national security, critical infrastructure protection and technological independence.
What India's next steps could look like
India cannot develop every component of the global AI technology stack overnight. However, the article highlights the country's ability to adopt and diffuse technologies rapidly.
The broader challenge is ensuring that adoption is accompanied by security.
That could involve stronger supply-chain scrutiny, security assessments, accountability mechanisms and liability frameworks suited to AI systems. It also means ensuring that AI adoption across critical sectors does not create new weaknesses faster than organisations can secure them.
The development of AI and cybersecurity therefore needs to happen together.
AI can strengthen cyber defence, but cybersecurity must also be built into the development, deployment and governance of AI.
The bigger picture
The emerging AI cybersecurity race is not simply about which organisations have the most advanced AI tools. It is increasingly about who can build secure AI systems, protect critical infrastructure and respond quickly when attackers use AI to increase the speed of their operations.
For India, that makes AI capability and cyber resilience closely connected strategic priorities.
The challenge will be balancing rapid AI adoption with stronger security, governance and accountability.
Source: The Indian Express
About the Author