August 24, 2026, (Inside AI) — India faces a widening cyber threat gap as frontier AI systems turn from defensive tools into autonomous offensive weapons.
Recent disclosures show AI models can now discover zero-day vulnerabilities without human help. Anthropic's Claude Mythos Preview found thousands of flaws in major operating systems and browsers, including a 27-year-old vulnerability in OpenBSD, a hardened OS used in firewalls and critical infrastructure.
For India, the stakes are concrete. Last month, ransomware group World Leaks claimed to have stolen and posted data from the Kudankulam nuclear plant, including blueprints and supplier details. CloudSEK's 2024 report ranked India the second-most cyber-attacked nation; its 2025 report placed India sixth.
AI Turns Every Stage of an Attack Into an Automated Loop
The threat is not just faster malware. It is a different kind of attacker.
Reconnaissance now runs on AI. ChatGPT-class models mine social media to craft precise spear-phishing emails. Deepfakes are generated in real time, eroding trust in online content.
At the weaponization stage, large language models can produce polymorphic malware that changes its own code to evade signature-based antivirus. In September 2025, Anthropic said a Chinese state-sponsored group, GTG-1002, used Claude Code as an autonomous cyber agent across multiple stages of an attack. Anthropic called it the first reported case of an AI-orchestrated cyber-espionage campaign.
"GTG-1002", Anthropic
The most consequential shift is autonomous vulnerability discovery. Frontier models can find flaws developers never knew existed, then build exploits largely without human intervention. That collapses the window between discovery and attack.
Traditional defenses fail here. Antivirus looks for known fingerprints. Static patches address known flaws. Neither works well against malware that constantly adapts or vulnerabilities that are weaponized within hours.
AI-driven defense offers real-time threat detection, automated response, and large-scale data analysis. But the real divide is not who uses AI. It is who builds and controls it.
India's AI Stack Lags the Attackers Who Target It
India's critical infrastructure has already been tested. During Operation Sindoor, Pakistan-backed actors such as APT36 targeted the Ministry of Defence, Army, Navy, and DRDO. They hit BOSS Linux for the first time and disrupted the National Informatics Centre and state portals.
Yet India's indigenous AI ecosystem remains incremental. It lags the US and China across foundational models, GPUs, chip design, and data-center infrastructure. That leaves India dependent on foreign technology for both offense and defense.
Policymakers are responding. CERT-In has adopted AI-driven threat detection and cyber resilience measures since 2025. In April, it advised organizations to remove unnecessary internet-facing services and treat every new vulnerability as something that could be exploited within hours, not weeks.
The Ministry of Electronics and Information Technology is exploring a consent-based framework for synthetic content, curbs on agentic AI autonomy, and clearer liability rules for AI models.
Nitin Pai argues India's strength lies in agile adoption and efficient diffusion of AI capabilities, paired with supply-chain scrutiny, security assessments, and accountability mechanisms. India should also earn its place in strategic groupings like Pax Silica.
AI and cybersecurity can no longer be treated in silos. They are interconnected strands of policy: AI for cyber defense, and cybersecurity for AI. For India, the question is no longer whether AI will reshape cyber conflict. It is whether the country can build enough capability before the next attack lands.