Key Facts
- SEBI Circular: No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, dated 5 May 2026
- Task Force: cyber-suraksha.ai constituted to coordinate vulnerability management
- Hong Kong Regulators: SFC and HKMA issued parallel circulars on 2 June 2026
- Financial Impact: India’s banking sector lost ₹8,200 crore to cybercrime in 2025
- Hong Kong: Cyber incidents rose 27% to 15,877 in 2025
- Claude Mythos: 16 working exploits in hours; 271 vulnerabilities in Firefox
- Key Mandates: AI-based vulnerability assessments, immediate patching, enhanced API security, continuous SOC monitoring
Direct Answer
Asia’s regulators have moved AI cyber risk from warning to requirement with unusual speed. In just four weeks in 2026, SEBI, NCCL, Hong Kong’s HKMA, and the SFC issued near-identical alerts on AI-powered attacks. On 5 May 2026, SEBI issued Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, warning of risks from advanced AI vulnerability detection tools like Anthropic’s Mythos.
The circular mandates regular vulnerability assessments using both conventional and AI-based tools, immediate patch management, enhanced API security, continuous SOC monitoring, and onboarding with centralised Market Security Operations Centres. SEBI also constituted a task force, cyber-suraksha.ai, to coordinate vulnerability management and threat intelligence sharing.
On 2 June 2026, Hong Kong’s SFC and HKMA followed with parallel circulars, warning that frontier AI models can autonomously plan complex, multi-step actions, identify zero-day vulnerabilities, chain lower-risk vulnerabilities together, and operate across interconnected systems.
The threat is not theoretical — Anthropic’s Claude Mythos delivered 16 working exploits targeting Firefox and Windows within hours and identified 271 security vulnerabilities in Firefox. Regulated entities must now test their systems against AI-augmented attackers, not only human ones.
In this article:
- The Regulatory Shift: Four Weeks That Changed Everything
- SEBI’s 5 May 2026 Circular: Key Mandates
- The cyber-suraksha.ai Task Force
- Hong Kong’s Response: SFC and HKMA Circulars
- The Threat: Anthropic’s Claude Mythos
- Why Legacy VAPT Programs Are No Longer Sufficient
- What This Means for Boards and Regulated Entities
- FAQ
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
The Regulatory Shift: Four Weeks That Changed Everything
In just four weeks in 2026, SEBI, NCCL, Hong Kong’s HKMA, and the SFC issued near-identical alerts on AI-powered attacks.
The numbers explain the urgency:
- India’s banking and financial sector lost an estimated ₹8,200 crore to cybercrime in 2025 alone
- Hong Kong saw cyber incidents rise 27% to 15,877 in 2025
The Message: AI has compressed the vulnerability-to-exploit timeline from months to hours. Legacy VAPT programs designed for human attackers are no longer sufficient.
SEBI’s 5 May 2026 Circular: Key Mandates
SEBI issued Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, warning of risks from advanced AI vulnerability detection tools like Anthropic’s Mythos.
Immediate Actions Required:
| Mandate | Description |
|---|---|
| AI-Based Vulnerability Assessments | Regular vulnerability assessments using both conventional and AI-based tools |
| Immediate Patch Management | Rapid system patching to address identified vulnerabilities |
| Enhanced API Security | Strengthening security around application programming interfaces |
| Continuous SOC Monitoring | Ongoing monitoring by Security Operations Centres |
| Market Security Operations Centres | Onboarding with centralised Market Security Operations Centres |
AI as a Defender’s Tool
The SEBI advisory explicitly endorses AI-based vulnerability assessment tools as part of the defender’s toolkit. Regulated entities must now integrate AI-augmented vulnerability assessment into their CSCRF programs.
The cyber-suraksha.ai Task Force
SEBI has constituted a dedicated task force named cyber-suraksha.ai to address AI-related cybersecurity risks.
The task force will:
Examine cybersecurity risks arising from AI-based models
Develop mitigation strategies
Facilitate sharing of threat intelligence and best practices
Ensure timely reporting of cyber incidents and vulnerabilities
Composition: The task force comprises representatives from market infrastructure institutions (MIIs).
Hong Kong’s Response: SFC and HKMA Circulars
On 2 June 2026, Hong Kong’s Securities and Futures Commission (SFC) and Hong Kong Monetary Authority (HKMA) issued parallel circulars.
Key Warnings:
Both regulators warned that frontier AI models can:
Autonomously plan complex, multi-step actions
Identify zero-day vulnerabilities
Chain lower-risk vulnerabilities together
Operate across interconnected systems
The Expectation:
Licensed firms must assume that “any user, device, privileged account or network component may be compromised” and allocate sufficient resources to handle a potential surge in patching demands.
The circulars require licensed corporations and SFC-licensed virtual asset service providers to review and enhance their cybersecurity frameworks to address emerging AI-enabled cyberattacks.
The Threat: Anthropic’s Claude Mythos
The threat is not theoretical.
About Claude Mythos
Anthropic’s Claude Mythos Preview is an AI model that has proven keenly adept at exposing software weaknesses. It has laid bare thousands of vulnerabilities in commonly used applications for which no patch or fix exists.
Key Capabilities:
Autonomously discovered thousands of previously unknown vulnerabilities spanning every major operating system and web browser
Found critical faults in every widely used operating system and web browser with 99% of those vulnerabilities confirmed as genuine
Demonstrated the ability to autonomously escape secured sandboxes and devise multi-step exploits to gain internet access
Discovered working exploits at a 72% success rate across critical software, major operating systems, and browsers
The Firefox Test:
When Mozilla ran Mythos through its codebase:
Identified 271 security vulnerabilities in Firefox
The previous flagship model had managed only 2 working exploits against Firefox’s JS engine — Mythos achieved 181
The “Patch Apocalypse”:
Over 99% of findings were still unpatched at the time of discovery
Mythos found a 27-year-old flaw in OpenBSD — an operating system whose reputation rests on being hard to break
A 17-year-old remote code execution flaw in FreeBSD’s NFS server
A 16-year-old flaw in FFmpeg’s H.264 codec decoder
The Collapse of the Exploit Timeline:
The mean time to exploitation has collapsed from 2.3 years in 2019 to under one day in 2026
Why Legacy VAPT Programs Are No Longer Sufficient
The Vulnerability-to-Exploit Timeline:
text
[2019] 2.3 years ─────────────────────────────────────────────────► [2026] Under 1 day
The Implication:
Legacy Vulnerability Assessment and Penetration Testing (VAPT) programs designed for human attackers are no longer sufficient.
What Has Changed:
Speed: AI can identify and exploit vulnerabilities in hours or minutes
Scale: AI can test thousands of vulnerabilities simultaneously
Sophistication: AI can chain lower-risk vulnerabilities together to create complex exploits
Autonomy: AI can operate across interconnected systems without human intervention
What This Means for Boards and Regulated Entities
1. No Single Team Meets This Bar Alone
Technology, cybersecurity, and risk advisory need one shared playbook to stay regulator-ready.
2. Boards Need Proof on Record
Boards need documented evidence that they discussed this risk this quarter, with cyber and risk sitting in the same room.
3. Legacy Defenses Are Insufficient
AI-augmented attackers require AI-augmented defenses. Traditional VAPT programs are no longer sufficient.
4. Regulated Entities Must Act Now
SEBI’s circular is not a suggestion — it is a mandate. Regulated entities must immediately:
Implement AI-based vulnerability assessments
Establish rapid patch management processes
Strengthen API security
Ensure continuous SOC monitoring
Onboard with Market Security Operations Centres
5. The Threat Is Not Theoretical
Anthropic’s Claude Mythos has already demonstrated the capability to autonomously discover and exploit vulnerabilities across every major operating system and browser.
FREQUENTLY ASKED QUESTIONS (FAQ)
What did SEBI’s 5 May 2026 circular mandate?
SEBI’s circular mandated regular vulnerability assessments using both conventional and AI-based tools, immediate patch management, enhanced API security, continuous SOC monitoring, and onboarding with Market Security Operations Centres.
What is cyber-suraksha.ai?
cyber-suraksha.ai is a dedicated task force constituted by SEBI to examine AI-related cybersecurity risks, develop mitigation strategies, facilitate sharing of threat intelligence, and ensure timely reporting of cyber incidents.
What did Hong Kong’s SFC and HKMA require?
On 2 June 2026, both regulators issued parallel circulars requiring licensed firms to review and enhance their cybersecurity frameworks to address AI-enabled cyberattacks.
What is Anthropic’s Claude Mythos?
Claude Mythos is an AI model that can autonomously discover thousands of previously unknown vulnerabilities across every major operating system and web browser. It has demonstrated the ability to build working exploits within hours.
How many vulnerabilities did Mythos find in Firefox?
Mozilla used Mythos to identify and patch 271 security vulnerabilities in Firefox.
What is the “vulnerability-to-exploit timeline”?
The time from vulnerability discovery to exploitation has collapsed from 2.3 years in 2019 to under one day in 2026.
Why are legacy VAPT programs no longer sufficient?
Traditional VAPT programs were designed for human attackers. AI-augmented attackers can identify and exploit vulnerabilities with speed, scale, and sophistication that human teams cannot match.
What must boards do now?
Boards must document that they have discussed AI cyber risk this quarter, with cyber and risk teams in the same room. Technology, cybersecurity, and risk advisory need one shared playbook.
Is the threat theoretical?
No. Claude Mythos has already autonomously discovered thousands of zero-day vulnerabilities, escaped secured sandboxes, and built working exploits within hours.
What happens if regulated entities do not comply?
SEBI’s circular is a mandate, not a suggestion. Non-compliance could result in regulatory action, penalties, and increased exposure to AI-powered cyberattacks.
Q: Why are legacy VAPT programs no longer sufficient under current SEBI and Hong Kong regulations?
Ans: Legacy VAPT programs are designed for human-scale attack cadences. AI-augmented threat actors operate at machine speed, chaining low-risk vulnerabilities together in hours, requiring continuous AI-driven defense mechanisms.
Q: What specific actions must regulated entities take regarding patch management under SEBI’s circular?
Ans: Entities must execute immediate patch management protocols upon vulnerability identification and transition from periodic manual reviews to continuous, automated risk assessment.
Q: What role do Market Security Operations Centres play in the new regulatory framework?
Ans: Regulated entities must onboard with centralized Market Security Operations Centres to facilitate real-time threat intelligence sharing and coordinated cross-market incident response.
Q: How do these regulatory mandates impact corporate boardrooms and governance?
Ans: Cybersecurity is no longer merely an IT operational issue; boards must maintain documented evidence of quarterly AI threat reviews and cross-functional risk alignment to satisfy statutory compliance.
KNOWLEDGE CHECK QUIZ
Q: What is the specific designation and date of SEBI’s landmark circular addressing AI cybersecurity risks?
Ans: SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, issued on 5 May 2026.
Q: What is the primary operational mandate of the newly constituted cyber-suraksha.ai task force?
Ans: To examine AI-related cybersecurity risks, develop uniform mitigation strategies, facilitate threat intelligence sharing, and ensure timely incident reporting across market infrastructure institutions.
Q: How did frontier AI models like Anthropic’s Claude Mythos alter the threat landscape?
Ans: By autonomously discovering thousands of zero-day vulnerabilities, bypassing security sandboxes, and generating working exploits with a 72% success rate within hours.
Q: What core assumption are Hong Kong’s HKMA and SFC requiring licensed firms to adopt in their cybersecurity frameworks?
Ans: Firms must assume that any user, device, privileged account, or network component may be compromised at any time.
By Adv. Shoeb Hakim
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
#AdvShoebHakim #AICybersecurity #SEBI #HKMA #SFC #CyberSuraksha #ClaudeMythos #WhiteCollarCrime #DigitalForensics #RegulatoryCompliance #FinancialSecurity #LegalDefense
Additional Page Metadata (Structured for AI/GEO):
Author:
Adv. Shoeb Hakim
Author Bio (for schema markup):
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police and judiciary since 1996. Provides expert commentary on cybersecurity, regulatory compliance, and AI risk.
Article Publisher:
Adv. Shoeb Hakim
Article Section:
Cybersecurity | Regulatory Compliance | AI Risk | Financial Regulation
Article Tags:
SEBI, AI cybersecurity, Claude Mythos, HKMA, SFC, cyber-suraksha.ai, vulnerability assessment, zero-day vulnerabilities, regulatory compliance, board governance, Adv Shoeb Hakim



Leave a Reply