Building India's Cyber Shield ~ CERT-In's Sandbox, Sovereign AI, and the Push for Resilience
CERT-In, India's national cybersecurity agency, operates under mounting pressure. Cyberattacks in the country have doubled from 1.4 million in FY2022 to 2.9 million in FY2026, even as the window between a vulnerability's discovery and its exploitation continues to narrow. Rather than wait for access to the most advanced AI security tools, some of which face export restrictions, the agency has spent recent months building its own solution.
CERT-In has developed a new sandbox platform built with open-source AI, designed to identify cybersecurity gaps in public-sector systems. The sandbox functions as an isolated testing environment, allowing teams to safely evaluate software and applications without exposing the broader system to risk. Officials have framed this as a foundation rather than a substitute. MeitY Secretary S Krishnan described the platform as a step toward building a secure environment for eventual access to international AI models — suggesting the current approach is understood as an interim measure, not a permanent alternative to global tools.
This effort sits within a broader policy push: encouraging domestic AI development and tightening oversight of AI use in finance and online content. Taken together, these moves suggest a deliberate strategy of capacity-building through incremental, self-reliant steps, rather than a story about capability gaps or resource shortfalls.
A Crisis Measured in Millions
It helps to look at why this matters so much right now. A joint study by the Data Security Council of India and BCG found that recorded cyberattacks in the country roughly doubled in four years, from about 1.4 million in FY22 to 2.9 million in FY26. What's more worrying is how little time defenders now have to react to the average time it takes attackers to exploit a newly found vulnerability dropped from 745 days in FY22 to just 44 days in FY26, largely because attackers are using AI themselves to scout targets and build exploits faster. Banking, financial services, healthcare, telecom and government portals bear the brunt of this, with ransomware-as-a-service groups and state-linked actors increasingly slipping in through vendor portals and supply-chain weak points.
Turning Existing AI Into a Working Defence
CERT-In's Sandbox in Action
Instead of treating the lack of any one frontier model as a dealbreaker, CERT-In simply built its own closed trial platform officials have taken to calling it a "war room" where open-source and other AI models are set loose on software code to find vulnerabilities and shape secure workflows for India's top public sector companies, including in financial services. At a press conference, Meity secretary S. Krishnan pointed out that these substitute models already match roughly 60 to 70 per cent of the performance of the most advanced security-focused systems out there globally. That's a fairly substantial chunk of the capability, and it's coming from tools India can actually access today. The testing has stretched to core digital infrastructure like Aadhaar and government login systems, while some of the country's biggest tech firms are already using currently available AI models to patch widely used enterprise software, banking platforms included. The logic is simple enough: build the muscle now with whatever's on hand, so the enterprise environment is already in better shape by the time more capable tools eventually arrive.
Investing in Sovereign Capability
Arguably the more important move here is a longer-term one , India's bet on building its own frontier-grade security AI. The Centre has reportedly asked domestic AI developers Sarvam AI and BharatGen to build advanced cybersecurity capabilities of their own, hosted on the government's isolated computer infrastructure and eventually put to work protecting critical infrastructure. There's no public timeline yet for when these indigenous models will be ready, but the intent behind the move isn't hard to read: cut India's reliance on any single foreign provider for defending the systems that underpin banking, identity and public administration, while keeping sensitive testing and deployment on Indian soil. Officials have also signalled a preference for on-premises deployment of high-capability AI tools where the stakes are highest, rather than leaning entirely on overseas cloud infrastructure. It's a choice that points toward building lasting, self-reliant capacity rather than making a one-off purchase.
A Tightening Regulatory Net
RBI's Model Risk Guardrails
None of this is happening in a vacuum. On 24 June 2026, the Reserve Bank of India released draft guidance on model risk management that, for the first time, brings AI and machine learning systems used by banks, NBFCs and other regulated entities under a single, board-level governance framework. The draft asks institutions to keep a full inventory of every model they use, rank each one by risk, and build in human override and "kill-switch" mechanisms so a malfunctioning AI system can be shut down immediately. It also makes one thing very clear: banks can't shrug off accountability just because the technology came from a vendor.
MeitY's Deepfake and Synthetic-Content Rules
Around the same time, the Ministry of Electronics and Information Technology notified amendments to the IT Rules that formally define "synthetically generated information," require deepfakes and AI-altered media to carry clear, persistent labels and embedded provenance metadata, and cut the takedown window for unlawful synthetic content down to just three hours. Taken together, the RBI and MeitY rules form the regulatory backbone that CERT-In's technical sandbox is meant to plug into giving India a more coordinated response to both the defensive and the deceptive sides of AI.
One Chain of Command
Officials have gone out of their way to stress that all these moving parts aren't creating confusion in India's cybersecurity reporting structure. CERT-In director general Sanjay Bahl has said the National Security Council Secretariat remains the overarching body, with CERT-In as the top cyber reporting and investigations organisation across sectors, and that sectoral regulators like the RBI and SEBI still report into this one structure rather than running their own parallel systems.
Conclusion
Look at CERT-In's sandbox, the push for sovereign AI, and the tightening regulatory net together, and a clearer picture forms. This isn't really a story about a piece of technology India doesn't have. It's a story about capability being built, deliberately and in the open. The country is using the AI tools available right now to close real security gaps, backing homegrown alternatives for the long haul, and pairing both with governance rules that keep banks, platforms and public infrastructure honest. If there's a lesson in all this, it's that real resilience against a fast-moving cyberthreat landscape rarely arrives all at once. It gets built the way most lasting capability does piece by piece, mostly at home, without waiting for any single outside breakthrough to show up first.
References
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.newkerala.com/news/a/govt-prioritises-access-anthropics-mythos-ai-model-strengthen-475.htm
- https://blog.qualys.com/product-tech/2026/06/24/cert-in-ai-vulnerability-blueprint-machine-speed-risk-operations
- https://www.business-standard.com/technology/tech-news/mythos-threat-govt-tech-firms-test-their-softwares-for-vulnerabilities-126052700386_1.html
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.finextra.com/blogposting/32142/rbis-model-risk-management-guidance-2026--summary
- https://www.medianama.com/2026/06/223-rbi-ai-guidelines-2026-banks-kill-switch/
- https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/india-targets-deepfakes-and-ai-generated-content-key-changes-under-meitys-2026-102mjwn













