As frontier AI models from the US and China approach parity, enterprises face a new strategic question: what happens when your entire security architecture depends on a single provider? In this conversation, Ashish Tandon, Founder & CEO of Indusface, argues that model diversification isn’t just about cost or performance; it’s about resilience. From comparing outputs across models to catch missed vulnerabilities, to the risks of unmonitored AI-to-system connections, he unpacks why the real vulnerability often lies not in the model itself, but in the sprawling web of APIs, agents, and integrations around it and why remediation speed, not detection, is the next battleground.

Founder & CEO
Indusface
CISO Forum: GLM-5.2 claims to match Anthropic’s Mythos on cybersecurity tasks. Does this surprise you, or was AI parity at the frontier always inevitable?
Ashish Tandon: China has always been catching up. But, you know, I think one has to understand the structure, right? The models, these are all very large language models, you know, which are, you know, needing a lot of investment and, you know, a lot of hardware and a lot of capabilities to do it.
And both the U.S. and now China are clearly demonstrating that they can create these large language models, frontier models, which are extremely capable. And I think from an industry or from a business perspective, I’m pretty excited that, you know, one has options now, right? Especially given the geopolitical situation, you know, it is important to have options.
And I think it’s a very positive thing that, you know, we have equivalent options for businesses to leverage them and take advantage of that. Am I surprised? I don’t think so. I think everybody is working on it.
Everyone realises the power and the value of this capability. And hence, this is going to catch up and keep getting better, bigger, faster, and more efficient as we go forward.
CISO Forum: If capability gaps between AI models close this fast, what does “competitive advantage” even mean for enterprises betting on a single provider?
Ashish Tandon: The way one should look at them is that, you know, when you do business, you need the business to be resilient, right? So, when I say resilient, you don’t have a single point of failure, right? We want to make sure we’ve heard about business continuity and all those aspects.
Having comparable models available from a business perspective is great. Because, you know, you would generally want to have multiple options with you so that if there is any challenge—for example, some time back, one of the models was not available, or the government of that country took a decision that, you know, this model should not be available to anybody in the world.
I have built the entire business on that, and I have no other option. That’s the challenge, right? So I feel this is a good thing: we have multiple options. It improves resilience. It ensures business continuity.
And I personally feel that, from a competitive perspective, the creators of the model will have a challenge commanding or demanding a higher price. But from a consumer and business perspective, I think it’s great news for those leveraging this model.
For example, we leverage models, right? So, for us, it’s good that we have options too, and we don’t have a single point of failure because we don’t depend on any one model.
CISO Forum: What is the single biggest continuity risk for an enterprise that has built critical security workflows around one AI model?
Ashish Tandon: Exactly what I mentioned. If you depend only on one model and if that model is not available to you within 90 minutes, think about where your security architecture and the entire thing you have planned on it, where do you stand?
Reliance on a single model- forget models; reliance on any- in this day and age, especially anything critical to you, one needs to have an option. My strong recommendation is that you have multiple options.
CISO Forum: How should a CISO structure a multi-model AI strategy without increasing integration complexity or the attack surface?
Ashish Tandon: It depends from business to business. But I think the most important thing from a security officer’s mindset is that he can use this to, first, compare results from two models.
These days, you are finding differences between models in terms of vulnerabilities. For example, when we tested three different models, each one came up with unique vulnerabilities that differed from the others.
It gives them an option. Always, a business is built, and the security guy, the security officer, always thinks about how he can make sure that he finds enough or make sure he has his attack surface properly covered and having multiple models helps him because he gets more information and more attack-surface information he can use.
How does he integrate it? I think it depends on how the business works. For example, for anything we test or use to detect vulnerabilities, we generally leverage two models.
First, we compare them to ensure we haven’t missed anything, then integrate both findings into a single system where we review the outcome and take action. Security officers would follow a similar strategy.
CISO Forum: Machine-speed attacks now demand machine-speed detection. What does “fast enough” actually look like in 2026 and are Indian enterprises there yet?
Ashish Tandon: Fast, the models are working at machine speed. So, with GLM-5 and my thoughts and all that, they’re clearly demonstrating that they can detect vulnerabilities at machine speed, and what took days or months is now done in a few hours.
There is no doubt vulnerabilities exist, and these are often critical business-logic vulnerabilities a hacker can exploit; there is no debate that vulnerabilities and the discovery of weaknesses in systems are moving at machine speed.
I think what is really required is this: how do businesses first accept that vulnerabilities are being exposed at machine speed? How do they identify them and make that the protection mechanism? Meaning, whatever vulnerabilities are found, how do they protect them at machine speed as well?
For example, on our platform, as soon as we detect a vulnerability, we build autonomous virtual patching that humans verify, helping them virtually patch those vulnerabilities at similar speed and in a similar motion.
The answer now lies in how fast you can remediate. Detection at machine speed is a foregone conclusion.
Every CISO, every security officer, is thinking about how we can build a protection mechanism that also runs at machine speed.
CISO Forum: When sensitive data and IP move across multiple AI platforms, where does the security architecture most commonly break down?
Ashish Tandon: One has to realise that we keep talking about models, but a model doesn’t work in isolation. It is connecting to an MCP server; it talks to an API, it talks to your application, it talks to your database.
It has a lot of connections within that to come up with an outcome. I think the challenges with the models are that the agents or the model, the machine itself, is talking to all these systems and coming up with an action.
Every point, every agent, every aspect of AI that talks to various systems must be monitored; the right kind of access must be ensured; they must be tested; data leakage and any DLP mechanisms must be put in place; and humans must verify the outcome. An audit trail is in place.
It is a system that has to be put in place, considering what humans did earlier; now agents and machines do it at machine speed. How do you ensure compliance and regulatory mechanisms are in place so every agent action is monitored and audited, and it isn’t doing something it is not supposed to?
Because at the end of the day, the business owner or the people running the business are responsible for the outcome that comes out of the system.
The model itself isn’t the risk. The risk is whether it works across the system, and whether the outcome is audited, consistent, and monitored. So, putting a compliance mechanism around each one of them, and monitoring everything, is going to be critical. I would say that is the weakest link in the architecture, not the model itself.
CISO Forum: Open source and regional models are closing the gap with frontier players. Does this reduce enterprise risk, or does it just relocate the risk elsewhere?
Ashish Tandon: It is the same philosophy. It’s great that you have open-source models.
Open-source models or regional models help you mitigate risk. For example, you might focus on a model; you might use an open-source model, maybe a smaller one. They are doing a particular… I think it fits the de-risking criteria, where you can leverage multiple models and make sure your business isn’t dependent on just one.
It is a very good aspect. Enterprises should embrace them and leverage each one depending on what works and what fits. More options are a very positive thing, and I am glad it is moving so quickly.
CISO Forum: For an enterprise still evaluating vendor lock-in versus model diversification, what is the first architectural decision they should get right?
Ashish Tandon: Have an enterprise contract or zero down on them. I think when you clearly understand and identify it, you might start looking at enterprise contracting. Still, I think everyone is in the phase of figuring out what the models are, what the strategy should be, what’s best for business continuity, how to put an option in place, and so on. I would lean on the enterprise still moving, looking at that aspect before finalising the contract.
The global narrative and the information show that most people are using it and trying it out, so enterprise contracts are still a little bit away.
CISO Forum: As AI capabilities commoditise across providers, what should differentiate a genuinely resilient enterprise from one that’s diversified on paper?
Ashish Tandon: Everybody started realising that there is a genuine power with AI. It has the capabilities which you all want to leverage.
But I think a lot of companies, including us, have started realising that the model becomes richer and better with the data you provide to it, the prompts you give it, the kind of information you put in, and the quality of the data we have.
Everybody thinks everything is fed into a global model, and that the information becomes available to everybody. So how do I, as a business or cybersecurity product company, keep delivering the capabilities we have built over the years to our customers?
We have started deploying models within our data centres, using our data to train them and leveraging them to provide value to our customers. We have years of data specific to our security capabilities, vulnerabilities, and attack vectors.
How do we leverage that, give it back, use it to improve our model, and keep it as our IP while leveraging it more?
That’s where most businesses will start moving toward. How do we, as you rightly said, avoid commoditising it and still retain our IP while leveraging the model?
I think that’s where the switch and the shift would start. I see people moving and businesses moving, especially technology companies like us.
CISO Forum: Twelve months from now, what will separate the enterprises that treated this AI diffusion as a wake-up call from those that didn’t?
Ashish Tandon: You won’t exist if you don’t wake up today. AI is real.
AI is reality. It has phenomenal benefits. It also comes with its challenges. But I feel the benefits far outweigh the challenges.
And I feel that if you’re not going to join the bandwagon quickly, you might not be a part of it. In my view, AI will remain relevant and ahead of the curve if you adopt it quickly.
But they and that stay won’t face serious challenges—existential challenges, I’d say.
