AI’s real test isn’t how fast an organization spots a threat. It’s whether it can decide, act, and later prove it acted correctly — inside a regulatory clock it no longer controls. That kind of speed only survives contact with regulation when governance is structural; not a checklist applied after the fact.
It was the third slide of the presentation when the chairman stopped her.
The CISO of a Mumbai-based BFSI conglomerate had just shown the board a heat map: 14,000 new vulnerabilities discovered across the group’s digital estate in the previous quarter, mapped by an AI-augmented scanning tool that had replaced the legacy vulnerability management platform. The number was not shocking. The shock was the annotation in the corner: ‘Estimated financial exposure if 5% of critical vulnerabilities are exploited within 72 hours of discovery: ₹340 crore.’
‘Where does that number come from?’ the chairman asked. ‘And why are we only seeing this now?’
The CISO had prepared for this. The financial model had been trained on breach-cost datasets from the Indian market, adjusted for DPDP Act 2023 penalty exposure—up to ₹250 crore for failure to maintain reasonable security safeguards, ₹200 crore for failure to notify the Data Protection Board within 72 hours. The tool had not just found the holes. It had priced them.
But the chairman’s second question was the one that mattered. ‘If we can see this, who else can?’
That question is now echoing through boardrooms across India. Anthropic’s Project Glasswing—deploying Claude Mythos Preview to 150 organizations across 15+ countries—is the current benchmark. Whether it delivers on its promise at scale remains to be seen. What is certain is that the capability category it represents is now irreversible. Within 6–12 months, multiple AI vendors will field comparable offensive and defensive capabilities. Some will arrive with safeguards. Others will not. The open-source replication is already underway.
For Indian enterprises, this is not a single-vendor story. It is a structural shift. AI models can now discover vulnerabilities at machine scale, generate patches, simulate attacks, and refactor legacy code. The bottleneck is no longer discovery. It is triage, validation, and remediation capacity—and the compliance of velocity required to act before liability crystallizes.
The 12-month warning is simple: the enterprises that move now will define the defensive standards. The rest will inherit the risk. And the risk is not technical. It is financial, regulatory, and competitive.
“I would frame AI-security maturity to the board as a business trust and resilience capability, not as a cybersecurity technology project. Boards do not need technical fear. They need business clarity. The language should not be, ‘AI attacks are coming and we are at risk.’ The more effective board-level message is: ‘AI is changing the speed of cyber risk. Our competitive advantage will depend on whether we can make trusted decisions faster than the threat can turn into business loss.’ A simple way to explain this to the board is: ‘Cybersecurity today is like air-traffic control. We have many signals coming from endpoints, email, cloud, identity, SaaS, network, applications, and third parties. Some are routine, some are duplicates, some are false alarms, and some are real threats. AI can help us read the radar faster, but faster radar alone will not make us safer unless we can also decide and act faster.’”
— Sudipta Biswas, Chief Information Security Officer, Emami
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
THE FIVE QUESTIONS
Every Indian board must ask its CISO before the next audit cycle.
- What is the estimated financial exposure of our unremediated vulnerabilities, and how does it compare to our AI-security investment?
- If an AI-augmented attacker maps our external attack surf ace in hours rather than weeks, which control fails first—and have we tested this?
- What is our compliance velocity under the DPDP Act 2023 and CERT-In directives: can we detect, validate, and report within the mandated windows?
- What is the minimum viable AI-security stack for our organization size, and what manual processes does it replace in year one?
- What governance structure ensures AI-security investment survives beyond the pilot phase—and who owns the business case?
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
The Frontier AI Landscape
Anthropic’s expansion of Project Glasswing is the headline. The subtext is what happens next. Within 6–12 months, at least four other major AI vendors are expected to field comparable capabilities, including two with significant India presence. Some will arrive with the safeguards Anthropic has built into Mythos—restricted model access, audit logging, human-in-the-loop requirements. Others will not.
The open-source replication is already underway. Independent research groups have demonstrated models with 70% of Mythos-class performance using publicly available datasets, and the timeline for ungoverned deployment is measured in months, not years. That democratization cuts both ways. Attackers will acquire these capabilities faster than enterprises, with fewer constraints and no compliance overhead.
For Indian enterprises, the vendor-selection dilemma has strategic consequences. The organization that adopts a well-governed AI security platform in Q3 FY26 will build institutional knowledge, tune detection models to local threat patterns, and integrate with existing SOC workflows. The organization that waits for a perfect standard will face the same threat of landscape with the same legacy tools—and a smaller talent pool to operate them.
The India-specific maturity gap is stark. Tier, I bank and large IT/ITES firms have piloted AI-augmented vulnerability management since late 2024. Mid-market manufacturers, PSUs, and critical infrastructure operators are still evaluating whether their on-premises and OT environments can accommodate AI security tools at all.
The Changed Risk Calculus
Here’s the equation every CISO learned in certification school: probability × impact = residual risk. It is now wrong.
Not because math has changed. Because the variables changed non-linearly. A human-led vulnerability assessment might identify 200–400 issues in a mid-sized enterprise estate over a quarter. An AI-augmented scan can surface 10,000–15,000 in the same period, with severity scoring that correlates exploitability to business-critical asset exposure. The bottleneck is no longer discovery. It is triage, validation, and remediation capacity.
Boards don’t need to understand the cost structure. They need to understand that the cost structure has changed. Every unremediated critical vulnerability is a contingent of liability. Under the DPDP Act 2023, that liability has a statutory price. The penalties are severe: up to ₹250 crore for failure to maintain reasonable security safeguards; up to ₹200 crore for failure to notify the Data Protection Board within 72 hours of becoming aware of a personal data breach. The Act’s phased implementation—core provisions effective 13 May 2027—means boards have a compliance runway, but also a countdown.
The risk is not that you will be breached. The risk is that you will know you are breachable and fail to act in time to avoid liability. That is a governance risk. Governance failures are director liabilities. The CISO’s job is to ensure directors have the information to avoid them.
“We are entering a phase where AI is redefining not just the scale of cyber risk, but the speed of consequence. In India, frameworks like CERT-In’s 6-hour reporting and the DPDP Act’s 72-hour mandate signal a clear shift—from reactive cybersecurity to continuous, accountable readiness. The question is no longer whether you can detect a breach, but whether you can act decisively and explain that action with confidence. AI compresses the time to exploit; regulation compresses the time to accountability. The board’s mandate is to ensure trusted speed—where the organisation can act fast and prove it acted correctly.”
— Dr. Siraj Rahim, DGM – Operation Technology & Information Security, MRF
The Cost of AI Security
The investment case for AI security tooling is a capital allocation decision with competing claims on limited budget. CISOs will need to make this case without assuming a net budget increase, because for most organizations, there is none.
The matrix is simple: spend here, avoid cost there. For a large enterprise with ₹5,000 crore annual revenue, a single DPDP Act penalty at the upper threshold (₹250 crore) represents 5% of revenue. The cost of an AI-augmented vulnerability management platform, including infrastructure upgrade and workforce transition, typically falls in the range of ₹8–15 crore annually for a comparable estate. Math is not subtle.
But the hidden costs are where boards are surprised. Infrastructure upgrade for AI security tools is not a software purchase. It is a compute, storage, and network architecture decision. AI-scale scanning generates data volumes that strain the legacy of SIEM deployments. On-premises estates require GPU or TPU capacity that most Indian enterprises have not provisioned. Hybrid and multi-cloud environments need API integration and data sovereignty compliance that add 20–30% to implementation timelines.
Workforce transition costs are equally underestimated. AI security tools do not eliminate SOC analysts. They redeploy them from detection to validation, from alert triage to threat hunting, from manual patching to automated remediation oversight. Retraining ROI typically turns positive in the second year, though few organizations measure it. The transition period requires parallel staffing that mid-market organizations cannot afford.
For mid-market CISOs, cost modeling is more constrained. Annual cybersecurity spend as a percentage of IT budget in Indian mid-market firms averages 6–8%, against 12–15% in large enterprises. The minimum viable AI-security stack—a combination of open-source AI-augmented scanning, managed detection and response (MDR) with AI overlay, and cloud-native SIEM—can be deployed for ₹80 lakh–₹2 crore annually. But it replaces only a subset of manual processes in year one, and the break-even point depends on whether the organization avoids even one material breach.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
What Does It Cost?
AI-security investments and constraints vary by industry.
BFSI (Tier I/II Banks): RBI mandates 24×7 SOC, half-yearly VAPT, 6-hour CIMS reporting. AI tools compress VAPT from months to weeks, but RBI does not yet recognize AI-generated reports as audit-compliant. Parallel human-validated assessments with double short-term cost. Typical AI-security investment: ₹10–18 crore/year.
IT/ITES: Client trust is a revenue driver. AI-security maturity is a competitive differentiator in RFPs. Typical investment: ₹6–12 crore/year. Hidden cost: client-mandated penetration testing that duplicates AI findings.
Manufacturing & Critical Infrastructure: OT environments with 20-year asset lifecycles require network segmentation and proxy architectures before AI tools can deploy. Additional infrastructure cost: ₹3–5 crore. Typical total investment: ₹8–15 crore/year.
PSUs: Government procurement rules privilege lowest-cost compliant bids. Premium AI tools struggle against commodity alternatives that meet baseline CERT-In requirements but lack predictive capability. Typical investment: ₹4–8 crore/year, often via phased tender.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
“We translate technical vulnerabilities into business risk by estimating potential financial impact across operational disruption, regulatory exposure, incident response costs, and reputational damage. For board discussions, vulnerability counts are less effective than metrics such as ‘risk reduction achieved,’ ‘time-to-remediation,’ and ‘potential business loss avoided.’ The conversation resonates most when framed in terms of business resilience, regulatory compliance, and financial exposure rather than technical severity alone.”
— Utkarsh Sawant, Global Head of Cyber Strategy & Risk, Diageo
The Boardroom Playbook
The CISO’s job in the boardroom is not to explain how AI finds vulnerabilities. It is to explain why the organization’s risk of posture has changed in ways that require immediate capital allocation, governance restructuring, or competitive repositioning. Here is the language for three conversations that matter.
To the Chairman: Risk Translation
Boards understand financial exposure, not CVSS scores. A critical vulnerability in a customer-facing payment gateway is not a ‘9.8 CVSS. It is a ‘₹45 crore contingent liability with a 72-hour regulatory notification obligation to the Data Protection Board. The language changes the conversation from IT operations to risk management.
To the CFO: Investment Justification
The CFO does not care about MTTD. The CFO cares about avoiding costs. Frame this way: AI-augmented threat detection reduces mean time to detect from 197 days to 24 hours. At India’s average breach cost of ₹18.4 crore, every month of detection delay costs ₹1.5 crore in containment and response. The platform pays itself if it prevents one material breach in 36 months. We have had three near-material incidents in the past 24 months.’
One IT/ITES CISO framed the ask to his CFO as: ‘This is not a technology purchase. It is an insurance premium with a known payout structure. The alternative is self-insurance against a liability we cannot quantify.’
To the Audit Committee: Compliance Velocity
The audit committee understands deadlines. What they often miss is velocity—the speed at which the organization can detect, validate, report, and remediate. The CERT-In 6-hour breach of reporting requirement is not an abstract obligation. It is an operational reality that AI security tools can either accelerate, or complicate, depending on whether the organization’s logging, detection, and reporting infrastructure was designed for machine-scale output. A SOC that generates 10,000 alerts per day cannot manually report within 6 hours.
One manufacturing CISO addressed her audit committee: Compliance velocity is now a function of automation maturity. We are currently at 40% automation. The regulator expects 6-hour reporting. The gap is a governance risk, not a technical one.’
Governance Structures That Sustain Investment
Three models have proven effective for sustaining AI-security investment beyond pilot phase, scaled to organization size:
• Board Cyber Committee with quarterly AI-risk review (large enterprise, 5,000+ employees): DPDP Act penalty exposure as standing agenda item; CISO reports directly to committee, not through CIO.
• CISO-CFO collaboration model with joint ownership of security ROI metrics (mid-market, 500–5,000 employees): Shared dashboard of avoided cost, MTTD/MTTR trends, and regulatory compliance velocity. If there is no joint ownership, who owns the business case for AI security to spend?
• Third-party risk framework with AI-security maturity scoring (all sizes): Vendor contracts include SBOM review, AI-assisted security validation, and breach of liability clauses.
Regulatory Anticipation
Boards must be briefed on compliance with velocity, not just deadlines. The DPDP Act 2023’s core provisions take effect on 13 May 2027. CERT-In’s 2025 Cyber Security Audit Guidelines mandate annual audits with CVSS + EPSS scoring, red teaming, and SBOM review. RBI’s cybersecurity framework is expected to incorporate AI-assisted security tool guidance by Q4 FY26. The CISO who flags these obligations before compliance deadlines positions security as proactive governance, not reactive compliance.
“Balancing compliance speed with legal liability in the age of frontier AI and accelerated regulatory mandates—like the CERT-In 6-hour reporting and DPDP Act 72-hour notification—requires shifting from a reactive ‘checkbox’ mentality to an embedded, automated governance model. To meet tight compliance windows without increasing liability, compliance must be embedded into the technology lifecycle. The proliferation of AI tools has also changed the hiring narrative: it allows us to hire bright minds in tier-2 cities who can be upskilled into ‘AI Security Analysts’ rather than traditional SOC analysts.”
— Namrata Bhise, Director – Cybersecurity, FIS Global
CISO Takeaways
The 12-month warning is not uniform instruction. It is a differentiated imperative. Here is where to start, by organization size.
For Large Enterprises (5,000+ employees)
- Commission for an AI-security readiness assessment by Q2 FY26. Use CERT-In’s 2025 audit guidelines as the baseline, not as a ceiling.
- Pilot AI-augmented vulnerability management on a non-critical estate to build institutional knowledge before regulatory mandates require it.
- Establish board cyber committee quarterly review of AI-risk metrics, with DPDP Act 2023 penalty exposure as a standing agenda item.
- Negotiate AI-security maturity clauses into third-party vendor contracts, with SBOM review requirements.
For Mid-Market Organizations (500–5,000 employees)
- Define the minimum viable AI-security stack by Q1 FY26: open-source AI-augmented scanning + MDR with AI overlay + cloud-native SIEM.
- Identify the three manual processes that consume the most SOC analyst hours and evaluate AI replacement feasibility.
- Engage a managed security service provider (MSSP) with AI capability rather than building in-house, given talent constraints.
- Map DPDP Act 2023 obligations to current data handling practices and identify notification workflow gaps before the 13 May 2027 deadline.
For All Organizations
• Test your existing controls against AI-augmented adversary speed. If an attacker can map your external attack surface in hours, which control fails first?
- Build a skeptic diagnostic into your AI-security procurement.
- Frame AI security investment as competitive positioning, not cost center management. The board that sees security as a revenue protector allocates differently than the board that sees it as a compliance cost.
“Effective governance models include board-level cyber oversight, strong CISO-CFO collaboration for risk-based budgeting, cross-functional AI governance committees, and structured third-party risk management using frameworks such as NIST AI RMF and ISO 27001. These approaches help sustain AI-security investment by aligning security initiatives with business objectives, risk reduction, and compliance requirements.”
— Pragnesh Mistry, Head – IT & Cybersecurity, RPG Enterprises
Looking Ahead
The frontier will not stay frontier for long. AI-augmented vulnerability management will be standard tooling across Indian enterprises by 2028 — the real question is who is in the room when the standard gets written. Three trajectories will decide that.
General Access. AI security capabilities are getting cheaper as open-source models close the gap with frontier ones; independent groups already claim roughly 70% of Mythos-class performance, with broader availability expected by late 2026. For India’s mid-market, the constraint will stop being cost and start being capacity — can the SOC actually act on machine-scale intelligence, or does it just drown in a faster stream of alerts?
Regulatory Maturation. By 2027, the DPDP Act’s core provisions will be in force, CERT-In’s 2025 audit guidelines will have run a full compliance cycle, and the RBI is expected to have folded AI-assisted security tooling into its supervisory framework. None of these standards exist in finished form yet. The enterprises piloting AI security today are, whether they intend it or not. Supplying the case studies, regulators will lean on when they finish writing the rules.
Defender-Attacker Equilibrium. The least settled question is who the arms race actually favors. AI tools could give defenders a durable edge — or attackers, unconstrained by procurement cycles, audits, or board sign-off, could simply out-iterate them. CERT-In’s AI-driven situational awareness systems, cited in the World Economic Forum’s Global Cybersecurity Outlook 2025, point toward one answer: collective defense, with enterprises sharing threat intelligence in something closer to real time. That only works once participation stops being voluntary — and for most sectors, it still is.
Back in that Mumbai boardroom, the chairman’s real question — “If we can see this, who else can?” — was never about the scanning tool. It was about whether the organization could move at the speed of its own visibility now demanded of it. That is the test every Indian board will face over the next twelve months: not whether they can see the risk, which AI has made almost unavoidable, but whether they can act on it before the law, the market, or an adversary forces the question for them.
| Trend | Focus | Impact |
| Capability Diffusion | Multiple vendors will field Mythos-class models within 6–12 months; some without safeguards | Urgency for budget allocation |
| The Asymmetric Threat Reality | Attackers will acquire comparable capabilities, likely faster and with fewer constraints | Need for preemptive defensive investment |
| The Legacy Infrastructure Trap | AI security tools expose gaps in on-premises, OT, and hybrid environments | Capital expenditure and modernization required |
| The Workforce & Operating Model Shift | SOC analyst redeployment, new AI-ops functions, retraining ROI; limited AI-security skills | Human capital and organizational design decisions |
| The Regulatory & Liability Frontier | Emerging standards for AI-assisted security, data sovereignty, breach disclosure obligations under DPDP Act 2023 and CERT-In directives | Compliance risk and director liability exposure |
| The Supply Chain Cascade | Third-party and open-source risk amplification when vendors lack AI-security maturity | Procurement policy and vendor risk management |
| The Skeptic’s View | AI-generated false positives at scale, alert fatigue, degraded human analytical skills, vendor lock-in to AI security platforms | Balanced risk assessment and prudent investment framing |
