Why in the News
Artificial Intelligence (AI) is now amplifying cyber threats across the cyber kill chain at speed, scale and sophistication, and is developing the ability to act as an autonomous agent that identifies, plans, adapts and carries out offensive cyber operations. The shift follows the fastest technology adoption on record: the Internet took 15 years to reach a billion users, and ChatGPT did so in three. The tension is that AI capability is concentrated in very few countries, so the same technology that raises the threat also determines who can defend against it. India’s indigenous AI ecosystem lags the United States and China across the entire AI stack, leaving it exposed on both sides of that equation.
What is the cyber kill chain?
- Definition: The cyber kill chain is the sequence of stages an attacker must complete to succeed, running from reconnaissance on a target, through weaponisation of malicious code, to command and control of the compromised system.
- Why the framework matters: Defence has traditionally worked by breaking any one link in that chain, since an attack that fails at one stage cannot proceed to the next.
- What AI changes: AI is now compressing or automating several stages at once, so breaking a single link no longer stops the sequence.
How is AI amplifying offensive cyber operations?
- Reconnaissance is automated: Gathering information about a target once depended on humans, and research shows ChatGPT models being used to mine social media for precise details to craft AI generated phishing emails.
- Deepfakes are now real time: AI is generating real time deepfakes, deepening confusion about what is authentic online.
- Social engineering scales: AI enabled social engineering, the use of AI to trick or persuade people into taking harmful actions, no longer requires a human operator per target.
- Malware no longer holds a fixed shape: Large language models (LLMs) can autonomously generate, modify and restructure polymorphic malware to suit the situation, unlike traditional malware, which relies on fixed signatures and predictable patterns.
- An AI has already run an attack chain: In September 2025 Anthropic claimed a Chinese state sponsored group, GTG-1002, had used Claude Code as an autonomous cyber agent across multiple stages of an attack, in what the company called the first reported case of an AI orchestrated cyber espionage campaign.
Why does autonomous vulnerability discovery change the risk?
- Zero-days are being found at scale: Anthropic’s latest frontier model, Claude Mythos Preview, has identified thousands of zero-day vulnerabilities, meaning flaws previously unknown to developers, across major operating systems and browsers, many of them critical.
- It builds the exploits too: The model developed related exploits largely without human intervention, collapsing the gap between finding a flaw and being able to use it.
- Hardened systems are not exempt: It found a 27 year old vulnerability in OpenBSD, an operating system reputed to be highly security hardened and widely used to run firewalls and critical infrastructure.
- Industrial systems are the exposed surface: Such vulnerabilities are especially dangerous for Operational Technology (OT) and Industrial Control Systems (ICS), the computing that governs nuclear facilities, energy grids, pharmaceutical manufacturing, chemical processing, oil refineries and communication networks.
- Exposure grows with integration: That infrastructure becomes more exposed as it integrates further with AI, so the adoption that improves efficiency also widens the attack surface.
Why do old cyber defences no longer hold?
- Signature matching fails against shape shifting code: Traditional antivirus looks for known malware fingerprints, which malware that constantly changes and adapts no longer presents.
- Static patching is too slow: Security patches written for known vulnerabilities are far less effective when new flaws are discovered and weaponised faster than patch cycles run.
- AI defence works differently: AI in cybersecurity enables real time threat detection, automated response and large scale data analysis, mitigating risks faster than human led triage.
- The divide has shifted: The real AI divide is not about who uses AI but about who builds it and who controls its development, which is why cybersecurity capability now tracks AI capability.
How exposed is India?
- A nuclear plant’s data was posted: The ransomware group World Leaks claimed to have stolen and posted data related to India’s largest nuclear plant, Kudankulam, including blueprints of facility parts and supplier details.
- The ranking moved sharply: Cyber intelligence firm CloudSEK’s 2024 report placed India as the second most cyber attacked nation after the United States, and its 2025 report placed India sixth.
- State backed actors targeted defence during a conflict: During Operation Sindoor, Pakistan backed threat actors such as APT36 targeted India’s critical sectors, including the Ministry of Defence, the Army, the Navy and the Defence Research and Development Organisation (DRDO).
- A new target class appeared: The same campaign targeted Bharat Operating System Solutions (BOSS) Linux for the first time, extending the attack surface to India’s indigenous operating system.
Can India defend a cyberspace built on an AI stack it does not own?
- The ecosystem is incremental: India’s indigenous AI ecosystem remains incremental and lags well behind the United States and China across the AI stack.
- The gap is at every layer: The shortfall runs across foundational models, graphics processing units, chip design and large scale data centre infrastructure, so no single procurement closes it.
- Dependence is the security problem: The lag leaves India heavily dependent on the United States and other technologically advanced countries for the very tools its defence now requires.
- Capability determines both roles: Countries with leading AI ecosystems gain a greater ability both to conduct sophisticated cyber campaigns and to defend against them, so dependence caps India’s ceiling on defence as well as deterrence.
What has India done so far?
- CERT-In has shifted its methods: The Indian Computer Emergency Response Team (CERT-In), the national agency for responding to cyber security incidents, has since 2025 adopted AI driven threat detection, cyber resilience measures, trusted AI frameworks and citizen centric malware mitigation.
- A specific advisory was issued: In April 2026 it issued an advisory for organisations on defending against AI driven cyber risks.
- The advisory’s operative instructions: Recommendations included “removing unnecessary internet-facing services” and treating every newly discovered vulnerability as something that “could be exploited within hours, not weeks”.
- Governance work is at the framework stage: The Ministry of Electronics and Information Technology (MeitY) is exploring a consent based framework for synthetically generated content, alongside curbs on agentic AI autonomy and clearer liability frameworks for AI models.
Challenges to India’s AI-enabled cyber defence
- Defence rests on advisories rather than obligations: CERT-In’s guidance to organisations is recommendatory, so a private operator of critical infrastructure faces no penalty for ignoring it. Eg. The April 2026 advisory asked organisations to remove unnecessary internet facing services, with no compliance audit attached. Fix. Convert the advisory content into mandatory, audited security baselines for power, banking, telecom and healthcare operators under the Information Technology Act, 2000.
- Compute dependence caps defensive AI: Running real time detection models at national scale needs domestic graphics processing unit capacity that India does not have. Eg. India’s shortfall spans foundational models, chip design and large scale data centre infrastructure alike. Fix. Prioritise sovereign compute for security workloads specifically, reserving a share of publicly funded AI infrastructure for CERT-In and sector CSIRTs.
- Attribution is harder when the attacker is an agent: An AI orchestrated campaign leaves a machine’s traces rather than an operator’s, which weakens the evidentiary basis for a state response. Eg. The GTG-1002 campaign was identified by the model provider, not by a victim’s own forensics. Fix. Mandate model providers serving Indian users to report detected misuse of their systems for offensive operations, on the six hour breach reporting model already in force.
- Legacy industrial systems cannot be patched quickly: Control systems in refineries and grids run on decade old software where a patch requires a plant shutdown. Eg. A 27 year old OpenBSD flaw survived in software widely used to run firewalls and critical infrastructure. Fix. Require network segmentation and one way data diodes between industrial control networks and corporate networks, so an unpatched system is not internet reachable.
- The skills base is thin at the state level: Cyber investigation and forensics capacity is concentrated in central agencies, while most first response happens at state police stations. Eg. Citizen fraud complaints route through the national helpline before reaching local police with the capacity to act. Fix. Establish State Computer Emergency Response Teams and cyber forensic laboratories with dedicated cyber police training academies in every State.
Conclusion
AI has moved cyber conflict from a contest between attackers and defenders to a contest between countries that build AI and countries that buy it. India sits on the wrong side of that line while carrying one of the world’s largest attack volumes, from a ransomware posting of Kudankulam plant data to state backed targeting of its defence establishment. India cannot build the AI stack quickly, so the immediate requirement is that AI and cybersecurity stop being treated in silos and are handled as interconnected strands of policymaking: AI for cyber defence, and cybersecurity for AI.
Matching Previous Year Question
“[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”
