Home India Securities and Exchange Board of India Advisory on Emerging Advanced Artificial Intelligence (AI) T...
Date: 2026-05-05 Category: Not Applicable State: Union Government Country: India

Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection

Issued by Securities and Exchange Board of India · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task
Official Source Record View Original Source →
See Full Document Text
परिपत्र / CIRCULAR HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 05.05.2026 To, प्रति, All Alternative Investment Funds (AIFs) सभी ऑल्टिनेटटव इनवेस्टमेंट फंड )एआईफ( All Bankers to an Issue (BTI) and Self- सभी बकैं ि टू इश्य ू औि सल्े फ-सटटिफाइड ससडं ीकेट Certified Syndicate Banks (SCSBs) बकैं )एससीएसबी( All Clearing Corporations सभी क्लीयरिगं कािपोिेशन All Collective Investment Schemes (CIS) सभी कलेक्क्टव इनवेस्टमेंट स्कीमें )सीआईएस( सभी क्रेडडट िेटटगं एजेंससया ाँ )सीआिए( All Credit Rating Agencies (CRAs) सभी कस्टोडडयन All Custodians All Debenture Trustees (DTs) सभी डडबेंचि ट्रस्टी )डीटी( All Depositories सभी डडपॉक्िटिी All Designated Depository Participants सभी डसे सग्नेटेड डडपॉक्िटिी पाटटिससपेंट )डीडीपी( (DDPs) सभी डडपॉक्िटिी पाटटिससपेंट )डडपॉक्िटिीि के All Depository Participants through Depositories जरिए( All Investment Advisors (IAs) / Research सभी ननवेश सलाहकाि )आईए( / अनसु धं ान Analysts (RAs) ववश्लेषक )आिए( सभी केवाईसी िक्जस्ट्रेशन एजेंससयााँ )केआिए( All KYC Registration Agencies (KRAs) सभी मचेंट बकैं ि )एमबी( All Merchant Bankers (MBs) सभी म्यचू ुअल फंड )एमएफ( / असेट मनै ेजमेंट All Mutual Funds (MFs)/ Asset Management Companies (AMCs) कंपननयााँ )एएमसी( All Portfolio Managers सभी पोटिफोसलयो प्रबधं क सभी िक्जस्ट्राि टू इश्य ू औि शये ि ट्रांसफि एजेंट All Registrar to an Issue and Share Transfer Agents (RTAs) )आिटीए( All Stock Brokers through Exchanges सभी स्टॉक ब्रोकि )एक्सचेंजों के जरिए( सभी स्टॉक एक्सचेंज All Stock Exchanges सभी वेंचि कैवपटल फंड )वीसीएफ( All Venture Capital Funds (VCFs) पष्ृ ठ स.ं 1 (कुल पष्ृ ठ 7) Page 1 of 7महोदय/महोदया, Dear Sir/Madam, Subject: Advisory on Emerging Advanced ववषय: खासमयों )वल्निेबबसलटी( का पता लगाने के Artificial Intelligence (AI) Tools सलए आए नए-नए एडवांस्ड एआई टूल for Vulnerability Detection (like )जैसे Mythos( के सबं धं में एडवाइििी Mythos) A. The rapid evolution of emerging क. खाममयों (वल्नरेबिमलटी) का पता लगाने वाले technologies including AI-driven नए-नए एआई टूल (जैस े Claude Mythos) vulnerability identification tools (E.g. आने लग े हैं, जजनकी िदौलत ववननयममत Claude Mythos) has introduced new (रेग्यलू ेटेड) एटं टटटयों के सामने नए-नए dimensions of risks for Regulated Entities. जोखखमों की आशकं ाएँ पदै ा हो रही हैं । जैसा Such tools may give rise to heightened risk कक ये टूल िड़ी तजे ़ी से और िड े पमै ाने पर exposure by enabling identification and काम करत े हैं, तो यह ममु ककन है कक इनकी िदौलत जोखखमों की आशकं ा भ़ी काफी िढ़ potential exploitation of existing जाए । इसके अलावा, यह भ़ी ममु ककन है vulnerabilities using speed and scale. It कक डाटा की गोपऩीयता भ़ी खतरे में आ जाए, may also introduce concerns relating to ऐजललकेशन की ववश्वसऩीयता पर भ़ी सवाल data confidentiality, application integrity खडा हो, और तो और उसके नत़ीजों को लेकर and reliability of outputs. भ़ी भरोसा न हो । B. Due to the interconnectedness and ख. जैसा कक मसक्यरू रटीज़ माकेट की समचू ़ी interdependency of market participants in व्यवस्था में सभ़ी माकेट पाटटिमसपेंट्स का the Securities Market Ecosystem, a एक-दसू रे से सरोकार भ़ी रहता है और उनकी periodic coordinated approach for एक-दसू रे पर ननभरि ता भ़ी रहत़ी है, इस़ीमलए vulnerability management, information यह जरूरी है कक इनकी खाममयों sharing and monitoring/assessment is (वल्नरेबिमलटी) को दरू करने, जानकारी एक- दसू रे से साझा करने और इन पर नज़र रखन े required to prevent a cascading impact. / इनका आकलन करने के मलए एक साझा प्रयास ककया जाए, ताकक कहीं ऐसा न हो कक ककस़ी एक जगह या ककस़ी एक पर अगर आचँ आए तो उसका असर ताश के पत्तों की तरह दसू री जगह या दसू रों पर भ़ी बिखरता नज़र आए । पष्ृ ठ स.ं 2 (कुल पष्ृ ठ 7) Page 2 of 7C. In view of the above, a task force, namely ग. उपरोक्त के मद्देनज़र, एक काय-ि दल (टास्क cyber-suraksha.ai, (email id: project- फोस)ि , जजसका नाम cyber-suraksha.ai है (ईमेल आईड़ी: project-cyber- cyber-suraksha.ai@sebi.gov.in) has been suraksha.ai@sebi.gov.in) िनाया गया है, constituted comprising representatives जजसमें MIIs, QRTAs, सभ़ी QREs और दसू रे from MIIs, QRTAs, all QREs, and other related stakeholders with the following सिं धं ित स्टेकहोल्डस ि के प्रनतननधियों को शाममल ककया गया है । इस काय-ि दल के mandate to: मख्ु य काय ि इस प्रकार हैं: i. िारीकी से यह जाँचना कक एआई वाल े i. Closely examine the cybersecurity risks मॉडल से साइिर सरु क्षा को लेकर क्या- posed by AI based models and devise a क्या जोखखम हो सकत े ह ैं और ऐस े मॉडल uniform mitigation strategy against the की वजह से पदै ा हो सकन े वाले जोखखमों risks posed by such models. से ननपटने के मलए एकसमान ऩीनत ननिाररत करना । ii. अगर ककस़ी खतरे की आशकं ा की कोई ii. Facilitate sharing of threat intelligence, best practices on vulnerability जानकारी ममले, तो उस े साझा करना; management, use cases and playbooks खाममयों (वल्नरेबिमलटी) को दरू करने के to respond to the threat vector etc. मलए अपनाए जाने वाले िहे तरीन तरीकों की जानकारी साझा करना; यह जानकारी साझा करना कक खतरों से कैसे ननपटा जाए। iii. मसक्यरू रटीज़ माकेट में साइिर सरु क्षा की iii. Report on a priority basis, cyber incidents or malicious activities, व्यवस्था को और पख्ु ता करने के मलहाज से साइिर हमलों की, गडिड़ी की हो रही significant attack vectors, information कोमशशों की या िड े हमलों की तत्काल on vulnerabilities etc. that may be सचू ना देना, खाममयों (वल्नरेबिमलटी) आटद relevant to strengthen the cyber security की तत्काल सचू ना देना । posture of the securities markets. iv. यह सम़ीक्षा करना कक थड ि पाटी ऐललीकेशन iv. Review the cyber security posture of the third party application service providers सववसि प्रोवाइडस ि (सचू ़ी में शाममल वेंडरों including empaneled vendors. सटहत) के यहाँ साइिर सरु क्षा की व्यवस्था कैस़ी है । पष्ृ ठ स.ं 3 (कुल पष्ृ ठ 7) Page 3 of 7D. A meeting of the task force cyber- घ. Mythos जैस े एआई ललेटफॉम ि की वजह स े suraksha.ai was convened (with MIIs and पदै ा हो सकने वाल े जोखखमों की सम़ीक्षा करन े QRTAs) to review the risks posed by AI और उनसे ननपटने के मलए उठाए जाने वाल े platforms like Mythos and discuss the कदमों के िारे में चचाि करने के मलए MIIs mitigation measures. Based on the और QRTAs के साथ काय-ि दल (टास्क फोस)ि consultation with the said task force, an cyber-suraksha.ai की एक िठै क िलु ाई गई advisory is enclosed at Annexure-A. थ़ी । काय-ि दल (टास्क फोस)ि की इस िठै क में हुए ववचार-ववमश ि के आिार पर, एक एडवाइज़री सलं ग्नक-क )Annexure-A) के रूप में सलं ग्न है । E. This advisory should be read in ङ. इस एडवाइज़री के साथ-साथ सेि़ी के लाग ू conjunction with the applicable SEBI पररपत्रों (सकुिलस)ि [जजनमें साइिर सरु क्षा और circulars (including but not limited to साइिर हमलों से ननपटने की क्षमता के ढाचँ े Cybersecurity and Cyber Resilience के सिं िं में जारी ककया गया पररपत्र शाममल framework) and any subsequent updates है] और सेि़ी द्वारा िाद में समय-समय पर issued by SEBI from time to time. ककए जाने वाल े अपडटे पर भ़ी अवश्य गौर ककया जाए । च. यह पररपत्र (सकुिलर) भारत़ीय प्रनतभनू त और F. This circular is issued in exercise of powers conferred under Section 11 (1) of ववननमय िोड ि अधिननयम, 1992 (सेि़ी एक्ट, the Securities and Exchange Board of 1992) की िारा 11(1) [जो मसक्यरू रटीज़ India Act, 1992, to protect the interests of माकेट में ननवेश करने वाले ननवेशकों के टहतों investors in securities and to promote the की रक्षा करने और मसक्यरू रटीज़ माकेट के development of, and to regulate the ववकास को िढ़ावा देने और उसे ववननयममत (रेग्यलू ेट) करने स े सिं धं ित है] के तहत प्रदान securities market. की गई शजक्तयों का प्रयोग करत े हुए जारी ककया जा रहा है । भवदीया Yours Faithfully, ममता िॉय Mamata Roy उप महाप्रबंधक Deputy General Manager दिू भाष / Phone: 022-26449599 ईमेल / Email: mamtar@sebi.gov.in पष्ृ ठ स.ं 4 (कुल पष्ृ ठ 7) Page 4 of 7Annexure-A 1. Update all operating systems and applications with the latest patches on immediate basis to mitigate any identified/known vulnerabilities. As an interim measure for the vulnerabilities where patches are not available, virtual patching can be considered for protecting systems and networks. 2. Conduct Vulnerability Assessment (Using conventional and suitable AI based Vulnerability Assessment Tools where possible) and undertake security audits on a regular/continuous basis in accordance with Cyber Security and Cyber Resilience Framework of SEBI. 3. Engage with the respective RE’s third party vendors to release timely patches and deploy them appropriately. Exchanges and Depositaries shall direct their empaneled application vendors (providing COTS solution to respective members) to undertake comprehensive assessment of the risks arising from the use of AI-led vulnerability detection models. Based on the assessment, vendors shall implement appropriate safeguards including updating patch, VAPT, continuous monitoring, hardening measures etc. 4. Change Management: Any change in the systems (including minor changes) should encompass full documentation, thorough impact analysis, structured review, rigorous testing and secure deployment to ensure operational resilience and system stability. 5. API Security: a) Inventory of all APIs and the applications using the APIs should be updated regularly. b) Ensure strong authentication and authorization mechanisms to enable secure verification of end-user client identity as well as limit the information access/ transfer to users/ systems based on least privilege. c) API rate limiting and throttling to prevent and detect abuse. d) Connections through APIs to be strictly on a whitelist-based approach. पष्ृ ठ स.ं 5 (कुल पष्ृ ठ 7) Page 5 of 76. SOC Monitoring: a) Regular day-to-day monitoring of the systems and networks must be carried out vigorously. SOC alerts should be adequately examined including the low-priority alerts. b) Implement enhanced security orchestration and Automated Response (SOAR) playbooks integrated with Security Incident and Event Management (SIEM) solutions, after thorough testing wherever feasible. c) The Market SOC (M-SOC), established by NSE and BSE, which serves as a centralized security platform, provides 24x7 real-time monitoring and threat detection across digital infrastructure. In the view of enhanced risks posed by AI-driven attacks, all eligible REs (not on boarded with any M- SOC) shall expedite the onboarding. d) MIIs are required to conduct awareness and handholding programs, including periodic workshops to ensure a smooth onboarding process and integration with M-SOC. 7. Risk Assessment: The Cyber Security and Cyber Resilience Framework (CSCRF) of SEBI has mandated periodic Risk Assessment of the REs including their Third Party Service Providers to enhance visibility and conduct a reasonably accurate assessment of the overall cybersecurity risk posture. Risk assessment shall include comprehensive scenario-based testing for assessing risks (including both internal and external risks) related to cybersecurity in REs’ IT environment. The capability of AI based models may also be considered as one of the risk scenarios. 8. Implement system hardening by adopting secure configurations, disabling unnecessary services and default accounts, and enforcing solutions like least privilege, Zero Trust Network (ZTNA) to minimize the attack surface. 9. Periodically update Asset Inventory and Software Bill of Materials for all critical applications including open source stack. पष्ृ ठ स.ं 6 (कुल पष्ृ ठ 7) Page 6 of 710. MIIs and other Regulated Entities shall seek guidance from their respective IT committees for mitigating risks emanating from AI-led vulnerability detection models. Further, all REs need to prepare a long-term plan for usage of AI in detection and autonomous/agentic mitigation. Also, undertake other measures including recalibration of risks for AI accelerated threats, AI augmented SOC transformation, and continuous vulnerability management using AI tools. ********************** पष्ृ ठ स.ं 7 (कुल पष्ृ ठ 7) Page 7 of 7

Continue your research