caalley logoThe alley for Indian Chartered Accountants

Banks to tap 25 OEMs in battle against AI-led cybersecurity threats

New Delhi, Jul 23, 2026

Synopsis
Indian banks are identifying twenty-five original equipment manufacturers for AI risk mitigation partnerships. A working group is developing a framework to identify and strengthen safeguards against cyberattacks. Banks will reduce network attack surface area by deploying defensive AI agents. Internal controls may not prevent exposure through weak vendors or third-party components. Vulnerabilities in embedded code can spread flaws across multiple financial institutions.

India's banks have identified 25 original equipment manufacturers (OEMs), whose tools and applications are widely deployed across the sector, for partnerships aimed at addressing risks arising from emerging artificial intelligence (AI) models, said people with knowledge of the matter.

The development comes against the backdrop of the banking regulator flagging AI-enabled cyber threats as the top perceived systemic risk to the domestic financial sector.

Separately, a working group led by the State Bank of India is developing a broader framework to help lenders identify potential gaps and vulnerabilities that could be exploited while strengthening safeguards against cyberattacks, according to the people.

The working group has representation from nine banks besides the finance ministry, the Reserve Bank of India (RBI), the National Payments Corporation of India and the Indian Computer Emergency Response Team (CERT-In).

Despite Internal Controls

“Banks have been told to work towards reducing the network attack surface area through various mechanisms, including deploying defensive AI agents,” a bank executive said on condition of anonymity, adding that a periodic review of the mitigating steps taken by each bank will be undertaken.

According to a working paper by the National Institute of Banking Management published earlier this month, a bank may have strong internal controls but its exposure can still increase via a weak vendor, fintech partner or cloud provider. “Banks often don’t know what open source libraries, AI-generated code or third-party components are embedded inside the products they’ve licensed. We’ve seen this pattern in previous supply- chain incidents, not knowing precisely where a vulnerable component, such as Log4j, was embedded and was the core operational problem then,” it said, adding that an AI generated code can be reused across many products built in the same way, spreading a single flaw across institutions that have no reason to suspect a common point of failure.

[The Economic Times]

Don't miss an update!
Subscribe to our email newsletter
Important Updates