AI Cybersecurity Threats: India's Preparedness for the Mythos Era
Contents4
Indian Express - Opinion · 30 Apr 2026 · 2 min read
Prelims · Science and technology Mains · GS3 Science and technology High relevance
Anthropic's AI model, Claude Mythos, has demonstrated unprecedented capability in identifying software vulnerabilities, prompting India to reassess its cybersecurity framework and legal architecture to mitigate national security risks.
Key points
Claude Mythos by Anthropic has identified thousands of vulnerabilities in major operating systems and web browsers, raising concerns about economic, public safety, and national security impacts.
Project Glasswing is a US defence cybersecurity initiative restricting Mythos access to a consortium of major tech companies, highlighting strategic control over AI capabilities.
[GS3-Science and Technology] The dual-use nature of AI models like Mythos poses risks as defensive tools can be repurposed for offensive cyber operations, necessitating robust governance frameworks.
India's Digital Public Infrastructure (DPI) resilience must be prioritized in talks with Anthropic to safeguard critical sectors like power, telecom, and finance.
CERT-In mandates and Section 79 Safe Harbour provisions are outdated for the Mythos era, requiring legal reforms to incentivize vulnerability remediation over penalization.
[GS2-Governance] The current legal framework lacks provisions for AI-driven patching, underscoring the need for adaptive cybersecurity laws to address emerging threats.
Open-weight AI models, though lagging behind frontier models, will democratize access to similar capabilities, increasing the risk landscape for malicious actors.
Way Forward: India should establish a legal safe harbour for AI-driven patching, strengthen CERT-In and AI Safety Institute capacities, and integrate AI cybersecurity into national defence strategies.
Key terms
- CERT-In
- The Indian Computer Emergency Response Team, the national nodal agency for cybersecurity threats. Its current six-hour reporting mandates and rigid frameworks are inadequate for addressing AI-driven vulnerabilities, necessitating reforms.
- Section 79 Safe Harbour
- A provision under India's IT Act offering legal immunity to intermediaries for third-party content. Its conditional nature is incompatible with AI-era cybersecurity needs, requiring updates to incentivize proactive vulnerability remediation.
- Claude Mythos
- An advanced AI model by Anthropic capable of identifying and exploiting software vulnerabilities at scale, posing significant risks to global cybersecurity infrastructure. Its restricted access under Project Glasswing underscores strategic control over AI capabilities.
- Project Glasswing
- A US defence cybersecurity initiative forming a consortium of major tech companies to restrict access to Claude Mythos, reflecting geopolitical control over cutting-edge AI technologies and their national security implications.
Practice question
Critically analyze the implications of AI models like Claude Mythos for India's cybersecurity framework. Discuss the necessary legal and institutional reforms to address these challenges. (250 words, 15 marks)
GS3 15 marks 250 words Mains
Key terms to include: Claude Mythos Project Glasswing CERT-In Section 79 Safe Harbour Digital Public Infrastructure AI Safety Institute dual-use technology vulnerability remediation
Answer framework
Introduction
Briefly introduce Claude Mythos and its capabilities in identifying vulnerabilities. Mention the dual-use nature of AI and its implications for cybersecurity.
National Security Risks
Potential for AI-driven cyber attacks on critical infrastructure (power, telecom, finance)
Dual-use nature of AI tools: defensive capabilities can be repurposed for offensive operations
Need for integrating AI cybersecurity into national defence strategies
Legal Framework Gaps
Outdated CERT-In mandates and Section 79 Safe Harbour provisions
Lack of provisions for AI-driven patching and vulnerability remediation
Need for legal safe harbour to incentivize proactive measures
Institutional Reforms
Strengthening CERT-In's capacity to handle AI-driven threats
Establishing an AI Safety Institute for monitoring and response
Collaboration with international frameworks like Project Glasswing
Conclusion
Emphasize the need for a balanced approach: robust legal reforms, institutional capacity building, and international cooperation to safeguard India's digital infrastructure in the AI era.
Fact check
All facts verified