THE POLICY EDGE
Expert Commentary

29 July 2026

IMF's AI Warning and India's Financial Stability Challenge

Shared AI models, cloud and digital dependencies are changing cyber risk, raising important questions about how India's regulatory framework should evolve

Pramod Mane is an Assistant Professor at the National Institute of Bank Management (NIBM). Debasis Pati is an Enterprise Security Architect at Persistent Systems. 

Listen to the article

Views are personal.

Expert Commentary image

A background note can be accessed here: IMF Finds AI Could Turn Cybersecurity into a Financial Stability Challenge

The IMF report argues that AI-driven cyber threats should no longer be viewed solely as operational risks for individual financial institutions, but as potential sources of systemic financial instability. To what extent should India's financial regulators incorporate cybersecurity into macroprudential oversight?

Although Indian regulators have cybersecurity frameworks and IT outsourcing policies in place, these frameworks were primarily developed prior to AI-enabled cyber threats. At present, the RBI's supervisory approach assesses cybersecurity largely at the level of individual institutions. Unlike credit or liquidity risk, cyber risk is not yet monitored as a system-wide threat across the financial sector.

A proportionate and phased expansion of macroprudential oversight would be appropriate.

A sensible first step would be to test whether the broader financial system can withstand a serious cyberattack instead of assessing institutions solely in isolation. This would be similar to how the ECB tested 109 banks together in 2024 and examined whether they could recover, alongside their ability to prevent attacks.

Given that AI-enabled attacks could disrupt banks, stock markets, payment systems and other financial services, cyber risk warrants inclusion within India's macro-financial surveillance. Regulators should also monitor concentration risks associated with common cloud providers, source code, AI models and shared software so that a single failure does not spread quietly across the system.

Cyber risk should therefore feature in India's Financial Stability Report. It would allow regulators to assess whether common cloud services, software, code or AI models could transmit disruption across multiple institutions.

However, at this stage, it might be premature to directly tie cyber risk to the capital requirements of banks since these losses are hard to quantify. Instead, the immediate priority should be system-wide cyber stress testing, oversight of critical technology providers, and stronger incident response and recovery arrangements. These measures represent the most proportionate next step before considering more intrusive prudential interventions.


The report highlights that the growing reliance on shared cloud providers, common software platforms, and AI-enabled financial services could amplify correlated cyber risks across the financial system. How should India balance rapid adoption of AI in financial services with the need to prevent new forms of systemic concentration?

The IMF warns that AI adoption could make financial institutions dependent on the same models, cloud platforms and providers. The RBI's FREE-AI report raises a similar concern, noting that vendors and subcontractors can create service failures, software defects and concentration risk. The report finds that nearly 14 percent of AI applications are in credit underwriting, suggesting caution in a high-stakes area. Of particular concern is the rapid adoption of GenAI, with 67 percent of regulated entities reporting its use.

As GenAI adoption widens, many institutions may come to rely on the same underlying model, cloud platform or hardware supplier. The AI supply chain is concentrated at three levels: model training, cloud services and hardware. A disruption at any one level could therefore affect several institutions simultaneously.

RBI recommends institutions to report confidentially the models, cloud services, hardware platforms and major subcontractors used for critical functions. This would reveal common dependencies and allow closer oversight of critical providers. Model and technology providers should be subject to stronger audit, incident-reporting and recovery requirements. Banks should also demonstrate that they can shift services, restore data and continue essential operations if a shared provider fails.

The challenge, therefore, is to preserve the benefits of AI adoption while preventing concentration in critical digital infrastructure from becoming a source of systemic financial vulnerability.


The IMF argues that preventing every cyberattack will become increasingly difficult as AI accelerates the speed and scale of attacks, making resilience and recovery as important as prevention. How should India's financial sector prepare for this shift? 

The IMF highlights that AI may make it harder to prevent cyberattacks in certain cases, so financial institutions must give equal attention to continuing and restoring essential services. Recent advances in AI-assisted vulnerability discovery and exploit generation illustrate how rapidly these cyber capabilities are evolving.

A known ability of such systems is to discover zero-day vulnerabilities. Zero-day risks are already familiar to Indian financial institutions. Assessing these weaknesses is a routine task for banks. What is concerning is the ability of these systems to combine vulnerabilities and produce working exploits much faster than conventional testing. This substantially increases the operational pressure on financial institutions.

Rather than reacting defensively, banks should assess their performance across the five primary risk management categories recommended by leading cyber resilience frameworks: governance, identification, protection, detection, and response and recovery. Routine health checks of IT infrastructure should become more frequent to identify vulnerabilities before they are exploited.

Regulators should monitor sector-wide preparedness, strengthen incident reporting, map dependencies on critical service providers, and run severe but plausible cyber stress tests. Regulatory frameworks already recommend monitoring, incident response, business continuity and recovery as core elements of cyber operations.

The government also has a role in providing testing infrastructure, skilled personnel, secure facilities, and coordination across finance, telecom, cloud and public agencies. The objective is to keep essential financial services running, recover quickly, and continuously strengthen resilience through lessons learned from each incident. Increasingly, resilience will be measured by how quickly the financial system restores critical services after disruption, rather than by its ability to prevent every cyberattack.

Rethinking Public Policy Through Insight | Inquiry | Impact

Opinion • Grassroots Voices • Policymakers Perspectives • Expert Analysis • Policy Briefs