THE POLICY EDGE
Expert Commentary

27 July 2026

What the IMF's AI Warnings Mean for RBI and India's Financial Regulation

The growing convergence of AI, digital finance, and shared technology infrastructure is changing what it means to protect financial stability

Neha Gupta is a Manager (CISO Office) at Union Bank of India. 

Listen to the article

Views are personal.

Expert Commentary image

A background note can be accessed here: IMF Finds AI Could Turn Cybersecurity into a Financial Stability Challenge

The IMF report argues that AI-driven cyber threats should no longer be viewed solely as operational risks for individual financial institutions, but as potential sources of systemic financial instability. To what extent should India's financial regulators incorporate cybersecurity into macroprudential oversight? 

Artificial intelligence is transforming cyber risk from an operational concern for individual financial institutions into a potential threat to financial stability. AI-enabled cyberattacks are faster, more sophisticated, and capable of exploiting shared digital infrastructure, allowing disruptions to spread rapidly across interconnected financial systems.

For India, this shift is particularly significant given the rapid expansion of digital finance through UPI, RTGS, NEFT, digital banking, and cloud-based services. While these innovations have strengthened efficiency and financial inclusion, they have also increased systemic interdependencies. A cyberattack on a critical financial institution or technology provider could therefore have cascading effects across the broader financial ecosystem.

India’s regulators should embed cybersecurity within macroprudential oversight rather than treating it solely as an operational issue. The RBI, together with SEBI, IRDAI, IFSCA, and CERT-In, should introduce system-wide cyber stress testing that simulates AI-driven attacks on payment systems, financial market infrastructure, and shared technology platforms. Macroprudential surveillance should further incorporate indicators that capture cyber-related vulnerabilities arising from common digital infrastructure, third-party technology dependencies, and interconnected financial networks, alongside traditional measures such as liquidity and capital adequacy.

Stronger coordination among regulators, cybersecurity agencies, and the private sector will be equally important. Integrating cyber resilience into financial stability assessments will help identify vulnerabilities before they evolve into systemic crises and strengthen the resilience of India’s financial system.


The report highlights that the growing reliance on shared cloud providers, common software platforms, and AI-enabled financial services could amplify correlated cyber risks across the financial system. How should India balance rapid adoption of AI in financial services with the need to prevent new forms of systemic concentration?

Artificial intelligence is already improving fraud detection, customer service, credit assessment, compliance, and operational efficiency across India’s financial sector. It will continue to play a key role in supporting financial inclusion and digital innovation.

However, increasing reliance on a small number of cloud providers, AI platforms, and technology vendors also creates concentration risk. If multiple financial institutions depend on the same provider, a cyberattack or operational failure could simultaneously disrupt banks, payment operators, and fintech firms, creating systemic consequences.

The policy objective is to ensure that AI adoption is accompanied by appropriate safeguards against systemic concentration. Regulators should strengthen oversight of critical third-party technology providers by requiring financial institutions to identify key outsourcing arrangements, assess concentration risks, and regularly evaluate vendor resilience. Institutions should also maintain contingency plans, including exit strategies and workload portability where practical, to reduce dependence on any single provider.

At the same time, India should encourage a diversified digital ecosystem through multi-cloud strategies, interoperable technology standards, and responsible domestic innovation. India’s experience with initiatives such as UPI and the Account Aggregator framework demonstrates that innovation and effective regulation can progress together. Applying similar design principles to AI governance will support transparency, accountability, competitive digital markets, and operational resilience.


The IMF argues that preventing every cyberattack will become increasingly difficult as AI accelerates the speed and scale of attacks, making resilience and recovery as important as prevention. How should India's financial sector prepare for this shift? 

As AI increases the speed and sophistication of cyberattacks, preventing every incident is becoming increasingly unrealistic. The focus should therefore expand from prevention alone to ensuring that essential financial services can withstand disruptions and recover quickly.

India’s financial sector has made significant investments in cybersecurity, but equal emphasis must now be placed on resilience. Regulators should require regular sector-wide cyber resilience exercises that simulate coordinated attacks on payment systems, financial market infrastructure, and major technology providers. These exercises would help identify operational interdependencies and strengthen coordinated crisis response.

Business continuity planning should also evolve to address AI-driven threats. Financial institutions should establish clear recovery objectives, maintain secure backups, regularly test failover arrangements, and ensure the rapid restoration of critical services such as UPI, RTGS, and NEFT following cyber disruptions. Recovery capability should become a core element of operational resilience rather than simply being a compliance requirement.

Greater collaboration across the financial ecosystem is equally essential. Timely information sharing among the RBI, SEBI, IRDAI, IFSCA, CERT-In, financial institutions, and critical infrastructure operators, supported by standardised incident reporting and coordinated crisis management, will improve preparedness and response.

Ultimately, cyber resilience should be viewed as a strategic capability. Embedding resilience and recovery into institutional preparedness will enable the financial system to respond more effectively when cyber incidents occur. This approach will be critical to sustaining public confidence in India's increasingly digital financial system.

Rethinking Public Policy Through Insight | Inquiry | Impact

Opinion • Grassroots Voices • Policymakers Perspectives • Expert Analysis • Policy Briefs