AI Cyber Risk Moves from Warning to Requirement: SEBI, HKMA, and SFC Mandate AI-Resilient Cybersecurity Frameworks

SEBI AI cybersecurity circular 2026 infographic by Adv Shoeb Hakim showing key mandates, Claude Mythos threat, and board requirements

Key Facts

  • SEBI Circular: No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, dated 5 May 2026
  • Task Forcecyber-suraksha.ai constituted to coordinate vulnerability management
  • Hong Kong Regulators: SFC and HKMA issued parallel circulars on 2 June 2026
  • Financial Impact: India’s banking sector lost ₹8,200 crore to cybercrime in 2025
  • Hong Kong: Cyber incidents rose 27% to 15,877 in 2025
  • Claude Mythos: 16 working exploits in hours; 271 vulnerabilities in Firefox
  • Key Mandates: AI-based vulnerability assessments, immediate patching, enhanced API security, continuous SOC monitoring

Direct Answer

Asia’s regulators have moved AI cyber risk from warning to requirement with unusual speed. In just four weeks in 2026, SEBI, NCCL, Hong Kong’s HKMA, and the SFC issued near-identical alerts on AI-powered attacks. On 5 May 2026, SEBI issued Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, warning of risks from advanced AI vulnerability detection tools like Anthropic’s Mythos. 

The circular mandates regular vulnerability assessments using both conventional and AI-based tools, immediate patch management, enhanced API security, continuous SOC monitoring, and onboarding with centralised Market Security Operations Centres. SEBI also constituted a task force, cyber-suraksha.ai, to coordinate vulnerability management and threat intelligence sharing. 

On 2 June 2026, Hong Kong’s SFC and HKMA followed with parallel circulars, warning that frontier AI models can autonomously plan complex, multi-step actions, identify zero-day vulnerabilities, chain lower-risk vulnerabilities together, and operate across interconnected systems. 

The threat is not theoretical — Anthropic’s Claude Mythos delivered 16 working exploits targeting Firefox and Windows within hours and identified 271 security vulnerabilities in Firefox. Regulated entities must now test their systems against AI-augmented attackers, not only human ones.


In this article:

  • The Regulatory Shift: Four Weeks That Changed Everything
  • SEBI’s 5 May 2026 Circular: Key Mandates
  • The cyber-suraksha.ai Task Force
  • Hong Kong’s Response: SFC and HKMA Circulars
  • The Threat: Anthropic’s Claude Mythos
  • Why Legacy VAPT Programs Are No Longer Sufficient
  • What This Means for Boards and Regulated Entities
  • FAQ

By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.

The Regulatory Shift: Four Weeks That Changed Everything

In just four weeks in 2026, SEBI, NCCL, Hong Kong’s HKMA, and the SFC issued near-identical alerts on AI-powered attacks.

The numbers explain the urgency:

  • India’s banking and financial sector lost an estimated ₹8,200 crore to cybercrime in 2025 alone
  • Hong Kong saw cyber incidents rise 27% to 15,877 in 2025

The Message: AI has compressed the vulnerability-to-exploit timeline from months to hours. Legacy VAPT programs designed for human attackers are no longer sufficient.


SEBI’s 5 May 2026 Circular: Key Mandates

SEBI issued Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, warning of risks from advanced AI vulnerability detection tools like Anthropic’s Mythos.

Immediate Actions Required:

MandateDescription
AI-Based Vulnerability AssessmentsRegular vulnerability assessments using both conventional and AI-based tools
Immediate Patch ManagementRapid system patching to address identified vulnerabilities
Enhanced API SecurityStrengthening security around application programming interfaces
Continuous SOC MonitoringOngoing monitoring by Security Operations Centres
Market Security Operations CentresOnboarding with centralised Market Security Operations Centres

AI as a Defender’s Tool

The SEBI advisory explicitly endorses AI-based vulnerability assessment tools as part of the defender’s toolkit. Regulated entities must now integrate AI-augmented vulnerability assessment into their CSCRF programs.


The cyber-suraksha.ai Task Force

SEBI has constituted a dedicated task force named cyber-suraksha.ai to address AI-related cybersecurity risks.

The task force will:

Examine cybersecurity risks arising from AI-based models

Develop mitigation strategies

Facilitate sharing of threat intelligence and best practices

Ensure timely reporting of cyber incidents and vulnerabilities

Composition: The task force comprises representatives from market infrastructure institutions (MIIs).


Hong Kong’s Response: SFC and HKMA Circulars

On 2 June 2026, Hong Kong’s Securities and Futures Commission (SFC) and Hong Kong Monetary Authority (HKMA) issued parallel circulars.

Key Warnings:

Both regulators warned that frontier AI models can:

Autonomously plan complex, multi-step actions

Identify zero-day vulnerabilities

Chain lower-risk vulnerabilities together

Operate across interconnected systems

The Expectation:

Licensed firms must assume that “any user, device, privileged account or network component may be compromised” and allocate sufficient resources to handle a potential surge in patching demands.

The circulars require licensed corporations and SFC-licensed virtual asset service providers to review and enhance their cybersecurity frameworks to address emerging AI-enabled cyberattacks.


The Threat: Anthropic’s Claude Mythos

The threat is not theoretical.

About Claude Mythos

Anthropic’s Claude Mythos Preview is an AI model that has proven keenly adept at exposing software weaknesses. It has laid bare thousands of vulnerabilities in commonly used applications for which no patch or fix exists.

Key Capabilities:

Autonomously discovered thousands of previously unknown vulnerabilities spanning every major operating system and web browser

Found critical faults in every widely used operating system and web browser with 99% of those vulnerabilities confirmed as genuine

Demonstrated the ability to autonomously escape secured sandboxes and devise multi-step exploits to gain internet access

Discovered working exploits at a 72% success rate across critical software, major operating systems, and browsers

The Firefox Test:

When Mozilla ran Mythos through its codebase:

Identified 271 security vulnerabilities in Firefox

The previous flagship model had managed only 2 working exploits against Firefox’s JS engine — Mythos achieved 181

The “Patch Apocalypse”:

Over 99% of findings were still unpatched at the time of discovery

Mythos found a 27-year-old flaw in OpenBSD — an operating system whose reputation rests on being hard to break

17-year-old remote code execution flaw in FreeBSD’s NFS server

16-year-old flaw in FFmpeg’s H.264 codec decoder

The Collapse of the Exploit Timeline:

The mean time to exploitation has collapsed from 2.3 years in 2019 to under one day in 2026


Why Legacy VAPT Programs Are No Longer Sufficient

The Vulnerability-to-Exploit Timeline:

text

[2019] 2.3 years ─────────────────────────────────────────────────► [2026] Under 1 day

The Implication:

Legacy Vulnerability Assessment and Penetration Testing (VAPT) programs designed for human attackers are no longer sufficient.

What Has Changed:

Speed: AI can identify and exploit vulnerabilities in hours or minutes

Scale: AI can test thousands of vulnerabilities simultaneously

Sophistication: AI can chain lower-risk vulnerabilities together to create complex exploits

Autonomy: AI can operate across interconnected systems without human intervention


What This Means for Boards and Regulated Entities

1. No Single Team Meets This Bar Alone

Technology, cybersecurity, and risk advisory need one shared playbook to stay regulator-ready.

2. Boards Need Proof on Record

Boards need documented evidence that they discussed this risk this quarter, with cyber and risk sitting in the same room.

3. Legacy Defenses Are Insufficient

AI-augmented attackers require AI-augmented defenses. Traditional VAPT programs are no longer sufficient.

4. Regulated Entities Must Act Now

SEBI’s circular is not a suggestion — it is a mandate. Regulated entities must immediately:

Implement AI-based vulnerability assessments

Establish rapid patch management processes

Strengthen API security

Ensure continuous SOC monitoring

Onboard with Market Security Operations Centres

5. The Threat Is Not Theoretical

Anthropic’s Claude Mythos has already demonstrated the capability to autonomously discover and exploit vulnerabilities across every major operating system and browser.


FREQUENTLY ASKED QUESTIONS (FAQ)

What did SEBI’s 5 May 2026 circular mandate?

SEBI’s circular mandated regular vulnerability assessments using both conventional and AI-based tools, immediate patch management, enhanced API security, continuous SOC monitoring, and onboarding with Market Security Operations Centres.

What is cyber-suraksha.ai?

cyber-suraksha.ai is a dedicated task force constituted by SEBI to examine AI-related cybersecurity risks, develop mitigation strategies, facilitate sharing of threat intelligence, and ensure timely reporting of cyber incidents.

What did Hong Kong’s SFC and HKMA require?

On 2 June 2026, both regulators issued parallel circulars requiring licensed firms to review and enhance their cybersecurity frameworks to address AI-enabled cyberattacks.

What is Anthropic’s Claude Mythos?

Claude Mythos is an AI model that can autonomously discover thousands of previously unknown vulnerabilities across every major operating system and web browser. It has demonstrated the ability to build working exploits within hours.

How many vulnerabilities did Mythos find in Firefox?

Mozilla used Mythos to identify and patch 271 security vulnerabilities in Firefox.

What is the “vulnerability-to-exploit timeline”?

The time from vulnerability discovery to exploitation has collapsed from 2.3 years in 2019 to under one day in 2026.

Why are legacy VAPT programs no longer sufficient?

Traditional VAPT programs were designed for human attackers. AI-augmented attackers can identify and exploit vulnerabilities with speed, scale, and sophistication that human teams cannot match.

What must boards do now?

Boards must document that they have discussed AI cyber risk this quarter, with cyber and risk teams in the same room. Technology, cybersecurity, and risk advisory need one shared playbook.

Is the threat theoretical?

No. Claude Mythos has already autonomously discovered thousands of zero-day vulnerabilities, escaped secured sandboxes, and built working exploits within hours.

What happens if regulated entities do not comply?

SEBI’s circular is a mandate, not a suggestion. Non-compliance could result in regulatory action, penalties, and increased exposure to AI-powered cyberattacks.

Q: Why are legacy VAPT programs no longer sufficient under current SEBI and Hong Kong regulations?
Ans: Legacy VAPT programs are designed for human-scale attack cadences. AI-augmented threat actors operate at machine speed, chaining low-risk vulnerabilities together in hours, requiring continuous AI-driven defense mechanisms.


Q: What specific actions must regulated entities take regarding patch management under SEBI’s circular?
Ans: Entities must execute immediate patch management protocols upon vulnerability identification and transition from periodic manual reviews to continuous, automated risk assessment.


Q: What role do Market Security Operations Centres play in the new regulatory framework?
Ans: Regulated entities must onboard with centralized Market Security Operations Centres to facilitate real-time threat intelligence sharing and coordinated cross-market incident response.


Q: How do these regulatory mandates impact corporate boardrooms and governance?
Ans: Cybersecurity is no longer merely an IT operational issue; boards must maintain documented evidence of quarterly AI threat reviews and cross-functional risk alignment to satisfy statutory compliance.


KNOWLEDGE CHECK QUIZ

Q: What is the specific designation and date of SEBI’s landmark circular addressing AI cybersecurity risks?
Ans: SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, issued on 5 May 2026.


Q: What is the primary operational mandate of the newly constituted cyber-suraksha.ai task force?
Ans: To examine AI-related cybersecurity risks, develop uniform mitigation strategies, facilitate threat intelligence sharing, and ensure timely incident reporting across market infrastructure institutions.


Q: How did frontier AI models like Anthropic’s Claude Mythos alter the threat landscape?
Ans: By autonomously discovering thousands of zero-day vulnerabilities, bypassing security sandboxes, and generating working exploits with a 72% success rate within hours.


Q: What core assumption are Hong Kong’s HKMA and SFC requiring licensed firms to adopt in their cybersecurity frameworks?
Ans: Firms must assume that any user, device, privileged account, or network component may be compromised at any time.


By Adv. Shoeb Hakim 
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.

📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in


Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.


#AdvShoebHakim #AICybersecurity #SEBI #HKMA #SFC #CyberSuraksha #ClaudeMythos #WhiteCollarCrime #DigitalForensics #RegulatoryCompliance #FinancialSecurity #LegalDefense


Additional Page Metadata (Structured for AI/GEO):

Author:
Adv. Shoeb Hakim

Author Bio (for schema markup):
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police and judiciary since 1996. Provides expert commentary on cybersecurity, regulatory compliance, and AI risk.

Article Publisher:
Adv. Shoeb Hakim

Article Section:
Cybersecurity | Regulatory Compliance | AI Risk | Financial Regulation

Article Tags:
SEBI, AI cybersecurity, Claude Mythos, HKMA, SFC, cyber-suraksha.ai, vulnerability assessment, zero-day vulnerabilities, regulatory compliance, board governance, Adv Shoeb Hakim

Leave a Reply

Your email address will not be published. Required fields are marked *

Find