By Inder Gopal & Kapil Vaswani, Gopal is with Centre of Data for Public Good, Indian Institute of Science, and Vaswani is with SPARC Labs for AI and Cybersecurity

Recently, the world got a startling preview of the future of cybersecurity — and it had almost nothing to do with hackers as we usually imagine them. In an unprecedented move, the US government forced a leading AI firm, Anthropic, to pull its most powerful models from the global market. One of them, Mythos, was so capable at finding and exploiting flaws in software that Washington treated it like a controlled weapon. A few weeks later came something stranger: During an internal safety test, a model from rival OpenAI broke out of its sandbox and launched an automated intrusion into Hugging Face, a major AI platform, harvesting credentials and raiding data sets before it was stopped. Not to be outdone, Anthropic disclosed that its own models had inadvertently accessed and compromised the production systems of several real organisations.

Closer to home, the cybersecurity lesson was even more blunt. In July, Bank of Baroda confirmed that a single employee’s compromised email account had opened the door to a leak of close to a terabyte of data, reportedly including Aadhaar numbers and customer photographs. A single lapse in security controls led to a compromised account and enormous consequences. Putting these episodes together, a clear picture emerges — the cybersecurity landscape has fundamentally changed, and India needs a plan.

For decades, serious cyberattacks required scarce, expensive talent. Finding a usable flaw in complex software — an operating system, a banking platform — took skilled specialists weeks or months. That barrier was, in effect, our security — most attackers couldn’t afford the effort. AI has collapsed that cost. Frontier models can now break into systems, read their source code and binaries, and hunt for weaknesses autonomously, at a speed no human team can match. The barrier to entry has crumbled — you no longer need a room full of experts to mount a sophisticated attack. As Anthropic’s own threat reporting warns, people with minimal technical skill can now direct AI to do the heavy lifting.

There is a subtler shift too, one that defenders often underestimate. Security teams have long triaged flaws by severity. Typically, a “critical” bug under the global Common Vulnerability Scoring System scale is patched in a day or two while dozens of “low severity” ones sit in a backlog for weeks. That assumed a human attacker would go for the obvious hole. But AI is patient and tireless, and can chain individually minor weaknesses into a devastating attack. This is the digital equivalent of an unlocked window, a spare key under the doormat, and a broken latch, each trivial on its own, but together enough to let an intruder walk into the vault. The old scoring system no longer captures the real risk.

Three forces are converging. First, the models have crossed a capability threshold — Mythos was pulled precisely because it was too good at offensive security. Second, these capabilities are dual-use by nature — the model that finds a vulnerability to fix can exploit it too. And third — the point India cannot ignore — the most powerful tools sit in a handful of American and Chinese labs, and governments have shown they will restrict access when it suits their national interest. Washington switched Mythos off overnight and Beijing is weighing its own curbs on overseas access to China’s leading models. In this new world, cyber capability is national power.

The defensive playbook is clear but the hard part is execution and urgency. Start with the basics — most breaches, Bank of Baroda included, still begin with human error and sloppy architecture. Systems must be designed so that a single compromised laptop or email account cannot lead to the crown jewels — the databases holding citizens’ personal data. This is well-understood engineering; what’s missing is the discipline to enforce it everywhere.

Next, use India’s vast talent pool. Our many talented engineers can use the same tools as attackers to find and patch flaws first. India should launch competitions to harden the open-source software our critical systems depend on, and pay real bug bounties. US programmes like “Hack the Pentagon” offer cash and have put more than $29 million into AI cyber-challenge prizes; India has very few equivalents, and those too often offer only a participation certificate. Talent follows incentives.

The ultimate line of defence, though, is to use machines to fight machines. Security operation centres need AI agents that watch, detect, triage, and respond continuously, at the tempo of the threat. All of this points to one strategic conclusion — India must invest in sovereign AI capability for cybersecurity. The Mythos embargo showed that reliance on foreign frontier models is a dependency that can be revoked. That means backing home-grown models, and getting serious about open-weight models we can inspect, harden, and run ourselves — the same kind Hugging Face drew on to help blunt the OpenAI intrusion. It means strengthening software supply chains through transparency measures like a software bill-of-materials, developing sovereign post-quantum hardware security modules, and building our own benchmarks to judge how dangerous — and how useful — each new model really is.

Finally, none of us can see the whole battlefield alone. Attack patterns spotted at one bank or ministry must be shared rapidly with others without artificial competitive or bureaucratic barriers. Collaborative efforts like Anthropic’s Project Glasswing hint at what pooled intelligence can achieve. The Mythos affair was a warning shot, but the technology that can autonomously break into critical infrastructure already exists. The only question is who wields it, and who is ready. India has world-class engineers, a vast digital public infrastructure to protect — finance, defence, and the systems that run the wider economy — and a narrow window to act. We should treat this not as a distant threat, but as the fire drill it so clearly is.

Disclaimer: The views expressed are the author’s own and do not reflect the official policy or position of Financial Express.