SEBI

AI in Financial Cybersecurity 2026: New RBI and SEBI Rules Explained

AI in Financial Cybersecurity 2026 New RBI and SEBI Rules Explained

AI is becoming an important part of banking, payments, securities markets, and financial services in 2026. Many organizations are using AI for customer service, fraud detection, risk assessment, and other tasks. This is creating new cybersecurity risks.

Using AI, cybercriminals can now launch more sophisticated attacks. It confuses identity verification using deepfake voice and video. Automated phishing can be done faster and target specific individuals. AI can find vulnerabilities in software very quickly.

RBI and SEBI are tightening cybersecurity and data privacy rules. RBI’s AI and model-risk controls, six-hour cyber incident reporting, SEBI’s IT Resilience Index (ITRI), FIRE reporting, and kill-switch mechanisms are now becoming important parts of financial cybersecurity.

Why Has AI Become a Financial Cybersecurity Risk?

The previous cybersecurity system relied on finding specific vulnerabilities and fixing them. But due to AI, cyberattacks are now happening much faster. An attack can target many systems or users in a short period of time. So, just doing occasional security testing is no longer enough.

Key AI-related threats

  • Deepfakes: Identity and verification processes can be influenced using AI-generated voice and video.
  • Automated attacks: AI can help quickly find weaknesses or vulnerabilities in a system.
  • Advanced phishing: AI can create more convincing and targeted phishing messages.
  • Model and data risks: Financial decisions can be affected if AI models or their data are manipulated.
  • Third-party risks: Over-reliance on external AI, cloud, and technology providers can create new security risks.

So, financial institutions have to move towards continuous monitoring, regular testing, and rapid risk detection.

How Is RBI Strengthening AI and Cybersecurity?

RBI is no longer seeing cybersecurity as just an IT department issue. Senior management and the board are also responsible for AI and technology-related risks. The goal is to identify any major technology risks before they arise.

  1. Board-Level Responsibility

Financial institutions should have a clear governance structure for cybersecurity and AI risks. The board and senior management need to review these issues regularly.

The key issues are:

  • Maintaining a board-approved cybersecurity and AI risk framework.
  • Regularly review important technology and model risks.
  • Creating a time-bound remediation plan when risks are identified.
  • Clear senior management responsibilities and accountability.

In this, cybersecurity is becoming part of business risk rather than just a technical issue.

  1. AI and Model Risk Management

RBI’s model risk approach emphasizes more structured control over AI and machine learning models. It is important for institutions to know where and how each important model is being used.

The key issues are:

  • Maintaining an inventory of AI and other models.
  • Classifying models according to risk.
  • Risk assessment of individual models and the entire organization.
  • Independent validation.
  • Regular monitoring of the entire lifecycle of the model.
  • Human oversight for important automated decisions.
  • Additional security controls for generative AI systems.

So, an AI model should not be forgotten after deployment. Regular review and monitoring are required.

  1. AI Kill Switch

RBI’s draft approach also includes the idea of ​​quickly restricting or shutting down high-risk or compromised AI models.

  • If the AI ​​system behaves abnormally, a human operator can intervene.
  • If necessary, the operation of the model can be stopped or limited.
  • Its main objective is to control major financial or operational risks created by AI.

RBI’s Cyber ​​Incident Reporting and Customer Protection Measures

In addition to AI risk, RBI is also emphasizing rapid response in the case of cyber incidents and digital fraud. So, financial institutions have to put measures in place not only for prevention but also to take quick action after the incident occurs.

READ  SEBI Issues Circular on Modified SOP on Defaulting Members

Six-Hour Cyber ​​Incident Reporting

Applicable regulated entities are required to report significant cyber incidents to the RBI within six hours of detection.

This requires institutions to have:

  • Clear incident escalation process.
  • Defined reporting responsibility.
  • Internal mechanism for rapid decision-making.
  • Proper incident-response plan.
  • Rapid reporting enables the RBI to be aware of potential major risks to the financial system sooner.

Revised Fraud Compensation

The revised fraud compensation measures of June 2026 have enhanced customer protection in the case of new types of digital fraud. So, real-time fraud detection and rapid customer response have become more important.

Customer Transaction Kill Switch

RBI is also working on a customer-facing transaction kill switch. Customers will be able to quickly stop financial transactions if fraud is suspected.

This is different from the AI ​​kill switch. An AI kill switch controls a risky or compromised AI system, while a transaction kill switch is used to stop a customer’s financial transactions.

How is SEBI Strengthening Cyber Resilience?

SEBI is focusing on cyber resilience to make the securities market safer from cyber threats. Under this, the focus is on strengthening the IT systems and cybersecurity controls of Market Infrastructure Institutions (MIIs), brokers, and other regulated entities. This aims to prevent cyberattacks and detect them quickly and restore the system to normal.

SEBI IT Resilience Index (ITRI)

SEBI has launched the IT Resilience Index (ITRI) to measure the IT resilience of market infrastructure institutions. This index measures the cyber and IT readiness of an institution through various important parameters.

ITRI ParameterWeight
Availability20%
Security20%
Integrity10%
Governance10%
Reliability & Monitoring10%
Modularity & Flexibility10%
Business Continuity10%
Scalability5%
Others5%

MIIs will have to calculate ITRI twice a year. A comparative analysis will have to be submitted within 60 days of the end of each year. If any weakness is found, corrective action will also have to be reported.

An early-warning mechanism has been put in place with ITRI. Cyber risk can be monitored regularly through this. The framework is expected to be effective from early 2027.

AI-Focused Cybersecurity Measures

SEBI is also emphasizing:

  • AI-assisted vulnerability assessment.
  • Identified vulnerabilities should be patched quickly.
  • Regular security audits and testing.
  • Strengthening API and third-party security.
  • On SOC, SIEM, and SOAR-based monitoring.
  • Increasing market-level centralized cyber threat monitoring.

SEBI is looking at cybersecurity not just as a preventive measure but as part of continuous resilience.

SEBI’s FIRE Reporting System and Upcoming AI Rules

FIRE Incident Reporting

SEBI is using FIRE, or Format for Incident Reporting Exchange to standardize cyber incident reporting. So, in a cyber incident, the institution will not have to wait for all the information to be ready at once.

An initial report can be made first with the available information. Additional or intermediate updates can be given as the investigation progresses. Once all the information is clear, the final report will be submitted. This will reduce the reporting delay during the incident, and SEBI will be able to keep a regular eye on the situation.

Upcoming AI and ML Guidelines

SEBI is preparing to bring new guidelines on the responsible use of AI and machine learning in the securities market. This may focus on issues like AI governance, model risk, data quality, explainability, human oversight, and accountability. Clear controls will also be created for the use of AI in financial-market activities.

READ  Latest SEBI Guidelines for Overseas Investment by AIFs and VCFs

RBI Vs SEBI: What Is Changing?

Both RBI and SEBI are strengthening the cybersecurity of the financial sector. However, their focus is slightly different. RBI is mainly working on the risks of banks, NBFCs, payment systems, and other financial entities. On the other hand, SEBI is giving more importance to the resilience of the securities market and its critical infrastructure.

AreaRBISEBI
Main focusBanks, NBFCs, payments and financial entitiesSecurities markets and market participants
AI focusModel risk and AI governanceResponsible AI and market surveillance
Cybersecurity focusEnterprise and financial-system securityMarket-wide cyber resilience
Key measureAI/model risk controlsIT Resilience Index
Incident reportingSix-hour reportingFIRE-based staged reporting
Human controlAI oversight and kill-switch conceptResponsible AI governance
Main objectiveFinancial and customer protectionMarket integrity and resilience

However, there is a common direction in the approaches of the two regulators. Both are moving towards continuous monitoring, measurable resilience, faster response, and stronger accountability. So, cybersecurity for financial institutions is no longer just an IT responsibility; it is a critical part of overall business and regulatory compliance.

What Financial Institutions Should Do Now?

RBI and SEBI’s cybersecurity requirements are getting tougher. So instead of waiting for new rules to come out, financial institutions should review their systems and processes now. Compliance, risk, and technology teams should work together to identify AI-related risks.

AreaAction Required
AI InventoryIdentify all AI and ML systems in use
Risk AssessmentClassify AI systems according to risk
CybersecurityInclude AI-driven threats in security assessments
TestingConduct regular vulnerability and AI-led testing
Model ValidationIndependently validate important models
Human OversightEstablish clear intervention procedures
VendorsReview AI, cloud and technology-provider risks
Incident ResponseMaintain clear reporting and escalation procedures
MonitoringStrengthen continuous security monitoring
Board OversightDocument management and board-level review

These tasks need to be reviewed regularly. AI technology and its associated cyber risks are changing very quickly.

How Can Enterslice Help with Compliance?

AI and cybersecurity regulations are constantly changing. So, financial institutions need to understand which requirements apply and where compliance gaps exist. Enterslice can help businesses understand regulatory requirements and create the necessary compliance framework in this process.

Our Services:

  • Review existing AI and cybersecurity frameworks.
  • Identifying compliance gaps with applicable RBI and SEBI requirements.
  • Supporting AI and model-risk governance documentation.
  • Assisting in risk assessment and compliance gap analysis.
  • Providing support via cybersecurity audit.
  • Reviewing third-party AI, cloud, and technology vendor controls.
  • Supporting the creation of policies, procedures, and compliance documents.
  • Ongoing compliance reviews with regulatory changes.

Conclusion

AI is making the financial sector more efficient but creating new cybersecurity risks. RBI is emphasizing AI governance, model-risk management, incident reporting, and customer protection with this change. SEBI is also strengthening the cyber resilience of the securities market through ITRI, FIRE reporting, and responsible AI.

So, it is not enough for financial institutions to use technology. Continuous testing, strong governance, human oversight, vendor controls, and faster incident response are now important parts of cybersecurity strategy. As AI improves, financial cybersecurity also needs to be more proactive.

READ  Weekly Roundup of Significant Notifications issued by Various Authorities

If your organization has AI or technology-based financial systems, conduct a cybersecurity and regulatory readiness review now. Enterslice can help you identify potential compliance gaps and create the necessary controls for regulatory requirements. So, contact us today for hassle-free compliance.

Top Questions Regarding AI in Financial Cybersecurity

  1. Why is AI a cybersecurity concern for financial institutions?

    AI is making cyber threats faster and more sophisticated. Attackers can easily launch large-scale attacks through deepfakes, automated phishing, and AI-based vulnerability discovery. Financial institutions have sensitive customer data, payment systems, and market infrastructure. So, regulators are now emphasizing AI-related risks, continuous monitoring, and stronger risk management in the cybersecurity framework.

  2. What is RBI doing to regulate AI-related risks?

    RBI is emphasizing board-level accountability in AI risk management. Financial institutions will have to maintain an inventory of AI and other models, classify them according to risk, and independently validate important models. Human oversight is also important. Additional controls are also needed for third-party and generative AI models. Emphasis is also being placed on having a mechanism to restrict or deactivate high-risk or compromised AI systems.

  3. What is RBI’s six-hour cyber incident reporting requirement?

    Applicable RBI-regulated entities are required to report a significant cyber incident to RBI within six hours of detection. So, it is essential to have a clear escalation process, report responsibility, and an incident-response plan. Rapid reporting allows the regulator to be aware of the threat in a timely manner and take necessary action. This is important in interconnected financial systems, as a cyber incident can create risks for other institutions as well.

  4. What is an AI kill switch?

    An AI kill switch is a control that can be used to quickly restrict, suspend, or deactivate a high-risk or compromised AI system. A human operator can intervene if a model behaves abnormally. Its purpose is to quickly control significant financial or operational risk created by an AI system. It is different from a customer transaction kill switch, which is used to stop financial transactions in case of suspected fraud.

  5. What is SEBI’s IT Resilience Index?

    SEBI’s IT Resilience Index (ITRI) is a framework to measure the IT and cyber resilience of Market Infrastructure Institutions. It considers a total of nine parameters, including availability, security, integrity, governance, monitoring, and business continuity. MIIs are required to calculate ITRI twice a year. They are required to submit a comparative analysis and report on any weaknesses and corrective actions to be taken.

  6. What is FIRE reporting under SEBI?

    FIRE or Format for Incident Reporting Exchange, is a standardized approach to cyber incident reporting by SEBI. In case of an incident, the institution does not have to wait for all the information. An initial report can be made using the available information. Intermediate updates can be given as the investigation progresses, and final information can be given at the end. This makes reporting faster and more structured, and SEBI can be informed about the progress of the incident regularly.

  7. How does SEBI’s FIRE standard improve cyber incident reporting?

    The FIRE standard further structures cyber incident reporting. During a cyberattack, all technical details may not be available immediately. Through FIRE, a regulated entity can make an initial report with available information and later provide additional updates as per the investigation. This reduces reporting delays. So, SEBI gets regular information about the development of the incident and can take a faster regulatory response if needed.

  8. What are SEBI’s expectations around AI use in financial markets?

    SEBI is emphasizing the responsible use of AI and machine learning in the securities market. Issues such as governance, model risk, data quality, explainability, and human oversight will be important when using AI-based systems. Market participants need to have proper controls and security measures in their AI systems. SEBI is already using AI to identify suspicious trading patterns and is also increasing its use of AI in regulatory surveillance.

  9. What is a market SOC, and its importance?

    A Security Operations Centre, or SOC, helps an organisation monitor cyber threats. A Market-SOC is important for strengthening market-level monitoring in the securities market. It can help monitor and share cyber threat information from different market participants more effectively. If a new threat is detected in a single organization, it is easier to alert the broader market ecosystem. This enables a faster response to cross-firm cyber risks.

Trending Posted

Get Started Live Chat