AI Cybersecurity Threats: India's Preparedness for the Mythos Era

Updated 30 Apr 2026

Contents4

Indian Express - Opinion · 30 Apr 2026 · 2 min read
Prelims · Science and technology Mains · GS3 Science and technology High relevance

Anthropic's AI model, Claude Mythos, has demonstrated unprecedented capability in identifying software vulnerabilities, prompting India to reassess its cybersecurity framework and legal architecture to mitigate national security risks.

Key points

Claude Mythos by Anthropic has identified thousands of vulnerabilities in major operating systems and web browsers, raising concerns about economic, public safety, and national security impacts.

Project Glasswing is a US defence cybersecurity initiative restricting Mythos access to a consortium of major tech companies, highlighting strategic control over AI capabilities.

[GS3-Science and Technology] The dual-use nature of AI models like Mythos poses risks as defensive tools can be repurposed for offensive cyber operations, necessitating robust governance frameworks.

India's Digital Public Infrastructure (DPI) resilience must be prioritized in talks with Anthropic to safeguard critical sectors like power, telecom, and finance.

CERT-In mandates and Section 79 Safe Harbour provisions are outdated for the Mythos era, requiring legal reforms to incentivize vulnerability remediation over penalization.

[GS2-Governance] The current legal framework lacks provisions for AI-driven patching, underscoring the need for adaptive cybersecurity laws to address emerging threats.

Open-weight AI models, though lagging behind frontier models, will democratize access to similar capabilities, increasing the risk landscape for malicious actors.

Way Forward: India should establish a legal safe harbour for AI-driven patching, strengthen CERT-In and AI Safety Institute capacities, and integrate AI cybersecurity into national defence strategies.

Key terms

CERT-In
The Indian Computer Emergency Response Team, the national nodal agency for cybersecurity threats. Its current six-hour reporting mandates and rigid frameworks are inadequate for addressing AI-driven vulnerabilities, necessitating reforms.
Section 79 Safe Harbour
A provision under India's IT Act offering legal immunity to intermediaries for third-party content. Its conditional nature is incompatible with AI-era cybersecurity needs, requiring updates to incentivize proactive vulnerability remediation.
Claude Mythos
An advanced AI model by Anthropic capable of identifying and exploiting software vulnerabilities at scale, posing significant risks to global cybersecurity infrastructure. Its restricted access under Project Glasswing underscores strategic control over AI capabilities.
Project Glasswing
A US defence cybersecurity initiative forming a consortium of major tech companies to restrict access to Claude Mythos, reflecting geopolitical control over cutting-edge AI technologies and their national security implications.

Practice question

Critically analyze the implications of AI models like Claude Mythos for India's cybersecurity framework. Discuss the necessary legal and institutional reforms to address these challenges. (250 words, 15 marks)

GS3 15 marks 250 words Mains

Key terms to include: Claude Mythos Project Glasswing CERT-In Section 79 Safe Harbour Digital Public Infrastructure AI Safety Institute dual-use technology vulnerability remediation

Answer framework

Introduction

Briefly introduce Claude Mythos and its capabilities in identifying vulnerabilities. Mention the dual-use nature of AI and its implications for cybersecurity.

National Security Risks

Potential for AI-driven cyber attacks on critical infrastructure (power, telecom, finance)

Dual-use nature of AI tools: defensive capabilities can be repurposed for offensive operations

Need for integrating AI cybersecurity into national defence strategies

Legal Framework Gaps

Outdated CERT-In mandates and Section 79 Safe Harbour provisions

Lack of provisions for AI-driven patching and vulnerability remediation

Need for legal safe harbour to incentivize proactive measures

Institutional Reforms

Strengthening CERT-In's capacity to handle AI-driven threats

Establishing an AI Safety Institute for monitoring and response

Collaboration with international frameworks like Project Glasswing

Conclusion

Emphasize the need for a balanced approach: robust legal reforms, institutional capacity building, and international cooperation to safeguard India's digital infrastructure in the AI era.

Fact check

All facts verified