AI is reshaping cyber warfare. Is India ready?
Rapid advances in autonomous AI are making cyberattacks faster and more sophisticated, exposing India’s critical infrastructure to new risks

Artificial intelligence is being adopted faster than any previous major technology, but its rapid development is also transforming the cybersecurity landscape, enabling increasingly sophisticated attacks while creating new opportunities for countries to strengthen their cyber defences.
The internet took about 15 years to reach one billion users, while ChatGPT reached the milestone in just three years. The speed of AI adoption has significant implications for cybersecurity as AI systems become capable of automating tasks across the cyberattack chain, from identifying vulnerabilities to generating phishing campaigns and deepfakes.
More significantly, frontier AI systems are increasingly developing the ability to operate as autonomous agents capable of identifying targets, planning operations, adapting to changing circumstances and executing parts of cyberattacks with limited human intervention.
This is creating a widening strategic divide between countries that develop advanced AI systems and those that primarily consume them.
AI changes the cyber threat landscape
Traditional cyber operations often required substantial human effort to conduct reconnaissance, identify vulnerabilities and develop attack tools. AI can automate many of these processes and carry them out at far greater speed and scale.
AI models can analyse large volumes of publicly available information to identify details about potential targets and generate highly personalised spear-phishing messages. Generative AI can also produce convincing deepfakes, making it increasingly difficult to distinguish authentic digital content from manipulated material.
The risks increase further when AI is used to develop malware.
One emerging capability is AI-generated polymorphic malware, which can modify and restructure its code to evade conventional security systems. Unlike traditional malware that often leaves recognisable signatures, such malicious software can potentially adapt continuously to its environment.
In September 2025, Anthropic said a Chinese state-sponsored group it identified as GTG-1002 had allegedly used Claude Code as an autonomous cyber agent during multiple stages of a cyber-espionage campaign. Anthropic described the incident as the first reported example of an AI-orchestrated cyber-espionage operation.
Frontier AI systems are also increasingly capable of identifying previously unknown software vulnerabilities. Anthropic's Claude Mythos Preview, for instance, has reportedly identified thousands of zero-day vulnerabilities across major operating systems and browsers, including critical flaws, and developed related exploits with limited human intervention.
Among the vulnerabilities identified was a 27-year-old flaw in OpenBSD, an operating system known for its security architecture and used in systems including firewalls and critical infrastructure.
Such capabilities could pose particular risks to operational technology and industrial control systems used in energy grids, nuclear facilities, chemical plants, pharmaceutical manufacturing, oil refineries and communications networks.
As these systems become more connected, vulnerabilities that can be discovered and exploited automatically could have consequences beyond conventional data breaches.
Traditional defences face new challenges
The emergence of adaptive AI-powered attacks is exposing limitations in traditional cybersecurity measures.
Conventional antivirus systems often rely on identifying known malware signatures, while security teams typically respond to vulnerabilities through patches and manual investigations. These approaches become less effective when malicious code can rapidly change or when AI agents can identify and exploit vulnerabilities before organisations have time to respond.
AI can also strengthen the defensive side of cybersecurity by analysing enormous volumes of data, detecting anomalies in real time and automating responses to threats.
The strategic competition is therefore increasingly about more than who uses AI. It is also about which countries can develop frontier models, produce advanced chips, build computing infrastructure and control the wider AI supply chain.
India faces growing risks
The challenge is particularly significant for India because of the country's dependence on critical digital infrastructure and its still-developing indigenous AI ecosystem.
Last month, ransomware group World Leaks claimed to have stolen and published information related to the Kudankulam Nuclear Power Plant, including alleged facility blueprints and supplier information.
CloudSEK's 2024 report ranked India as the world's second-most targeted country for cyberattacks after the US, although its 2025 report placed India sixth.
India also faced increased cyber activity during Operation Sindoor. Pakistan-backed threat actors, including the group identified as APT36, targeted critical Indian sectors including the Defence Ministry, Army, Navy and Defence Research and Development Organisation.
The campaign also reportedly targeted Bharat Operating System Solutions (BOSS) Linux and disrupted or attempted to disrupt government digital infrastructure, including systems associated with the National Informatics Centre and state-level government and education portals.
These incidents highlighted the vulnerability of critical infrastructure to coordinated cyber operations.
India still trails in AI capabilities
India has made progress in adopting and deploying AI but remains behind the US and China across several parts of the AI technology stack.
The gaps include foundational AI models, advanced GPUs, semiconductor design and large-scale data-centre infrastructure. This leaves India dependent on foreign technology and supply chains for several strategically important capabilities.
That dependence creates an additional security concern: vulnerabilities in foreign hardware, software, cloud infrastructure or AI models can potentially become national-security vulnerabilities when they underpin critical systems.
Government steps up cyber preparedness
Indian policymakers have increasingly recognised the connection between AI and cybersecurity.
CERT-In has adopted AI-based threat detection and cyber-resilience measures and has promoted frameworks for trusted AI and citizen-focused malware mitigation. In April, it issued an advisory warning organisations about AI-driven cyber risks.
Among its recommendations was reducing unnecessary internet-facing services and treating newly discovered vulnerabilities as threats that could potentially be exploited within hours rather than weeks.
The Ministry of Electronics and Information Technology is also examining a consent-based framework for synthetically generated content, alongside possible restrictions on the autonomy of AI agents and clearer liability rules for AI developers.
Building indigenous capability
India is unlikely to close every gap in the AI stack immediately, but its large technology workforce and ability to rapidly adopt new technologies provide an opportunity to build domestic capabilities.
The priority should be to combine faster AI adoption with stronger supply-chain scrutiny, security assessments, accountability standards and liability mechanisms.
India also needs to participate more actively in strategic technology partnerships and groupings such as Pax Silica to strengthen access to critical semiconductor, computing and AI technologies.
The emerging security environment means AI and cybersecurity can no longer be treated as separate policy areas.
For India, the challenge is twofold: develop AI capabilities that can strengthen cyber defences while ensuring that increasingly powerful AI systems themselves remain secure, accountable and resistant to misuse.
Join our official telegram channel (@nationalherald) and stay updated with the latest headlines
