Contents
Introduction
The convergence of Artificial Intelligence (AI) and cybersecurity creates a “double-helix” security paradigm. Economic Survey 2025–26 identifies AI as a strategic growth frontier, while Budget 2026–27 strengthens the IndiaAI Mission. Simultaneously, AI-driven cyber threats necessitate resilient, sovereign, and intelligence-led national cybersecurity architecture.

AI-Cyber Convergence
- AI-Powered Offensive Cyber Operations: Autonomous vulnerability discovery enables machine-speed identification and exploitation of zero-day flaws. Frontier AI models demonstrate exploit chaining beyond human capability. Example: Anthropic Mythos.
- Hyper-Personalized Social Engineering: Generative AI produces multilingual phishing, synthetic identities, deepfake videos and cloned voices. Weakens traditional Identity & Access Management (IAM). Example: CEO voice fraud.
- Adaptive & Polymorphic Malware: Reinforcement learning enables malware to mutate continuously, bypassing signature-based antivirus systems. Traditional perimeter security becomes obsolete. Example: AI ransomware.
- Adversarial AI & Model Poisoning: Training-data poisoning and adversarial prompts manipulate AI systems controlling critical infrastructure. Risks extend to power grids, defence logistics and financial markets. Example: Smart-grid attacks.
- Autonomous Cyber Warfare: AI agents conduct reconnaissance, privilege escalation and lateral movement without human intervention. Shrinks cyber kill-chain timelines from weeks to hours. Example: Agentic AI.
- Cognitive Warfare & Information Manipulation: Deepfake campaigns distort elections, military narratives and public trust. AI blurs cyber warfare with psychological operations. Example: Election misinformation.
- Geopolitical AI Arms Race: AI sovereignty is becoming central to strategic competition among the US, China and Europe. AI infrastructure increasingly determines military and economic influence. Example: Compute controls.
India’s Cybersecurity Preparedness
Institutional Strengths
- CERT-In: Operates AI-enabled threat intelligence and incident response platforms.
- NCIIPC: Secures Critical Information Infrastructure (power, banking, telecom).
- DPDP Act, 2023: Mandates reasonable security safeguards.
- IndiaAI Mission (₹10,371 crore): Builds sovereign compute, datasets and responsible AI ecosystem.
Persisting Gaps
- Absence of an updated National Cyber Security Strategy.
- Heavy dependence on imported chips and network hardware.
- Acute shortage of AI-cybersecurity professionals.
- Fragmented cyber coordination between Centre, States and private operators.
- Shortage of specialized AI-cyber talent persists. Example: Certified Security Professional in Artificial Intelligence (CSPAI) program deficit.
Building a Resilient National Defence Framework
- Autonomous Threat Response: Institutionalise AI-enabled threat hunting, automated patching and predictive intelligence across government networks. Example: CERT-In automation.
- Zero-Trust Security Architecture: Replace perimeter security with “Never Trust, Always Verify” authentication across defence and critical infrastructure. Example: Continuous verification.
- Technological Sovereignty: Accelerate indigenous AI models, secure cloud infrastructure and semiconductor ecosystem under IndiaAI Mission. Example: IndiaAI Compute.
- Supply-Chains Integrity: Mandate Software Bills of Materials (SBOMs), hardware certification and periodic security audits. Example: Trusted hardware.
- Critical Asset Resilience: Conduct AI-enabled red-teaming, cyber range simulations and resilience audits for strategic sectors. Example: Power-grid drills.
- Human Capital Augmentation: Launch specialised AI-cybersecurity certification, defence AI fellowships and university Centres of Excellence. Example: Cyber skilling.
- Normative Governance Framework: Finalise National Cyber Security Strategy, strengthen DPDP implementation and deepen cooperation through Quad, BIMSTEC and UN cyber norms. Example: Quad cyber.
- Collaborative Innovation Ecosystem: Partner with startups, academia and industry to develop indigenous cyber defence solutions and threat intelligence exchanges. Example: Deep-tech ecosystem.
Way Forward
- Adopt AI-native cyber deterrence integrated across defence agencies.
- Establish a National AI Security Centre for frontier AI risk evaluation.
- Promote explainable and trustworthy AI for defence decision-making.
- Develop indigenous secure chips and quantum-safe cryptography.
- Embed cyber resilience within Digital Public Infrastructure and Smart Cities.
- Expand international cyber diplomacy while preserving digital sovereignty.
Conclusion
As AI and cyber capabilities become inseparable, national security depends on shifting from reactive incident response to proactive, AI-driven deterrence. Strengthening sovereign tech capabilities, enforcing robust data governance, and training skilled cybersecurity professionals will secure India’s digital public infrastructure against next-generation threats.

