Key Points
- CERT-In conducts 10 cyber security exercises with 1,470 participants from 345 organisations
- New June 2026 guidelines mandate AI-accelerated vulnerability protection for all OEMs
- Exercises covered power, telecom, banking, transport, education, health and space sectors
The Centre has deployed artificial intelligence-driven systems to detect and counter cyber threats that themselves use AI technologies, the government told the Lok Sabha on Wednesday.
The Indian Computer Emergency Response Team (CERT-In), the nodal agency for cyber security incidents, has rolled out AI-powered tools for three core functions: detecting malicious domains and phishing attempts, assessing vulnerabilities in government-facing digital assets and sharing threat intelligence with organisations across sectors.
Union minister of state for Electronics and Information Technology Jitin Prasada said in a written reply that these measures respond to a new generation of attacks where AI enables automated reconnaissance, a process by which attackers map target systems to identify weaknesses, rapid exploitation of security flaws and highly convincing phishing campaigns in multiple languages.
Between June and July 2026, CERT-In conducted 10 cyber security exercises on the theme of building resilience against frontier AI-driven cyber threats. The exercises brought together 1,470 participants from 345 government and private organisations spanning power, telecom, banking, financial services and insurance, transport, education, health and space sectors.
The exercises tested how organisations would respond to attacks where AI accelerates every stage of an intrusion, from initial compromise to data extraction. AI-enabled attacks lower costs for threat actors, speed up the weaponisation of discovered vulnerabilities and make social engineering campaigns, where attackers manipulate people into revealing sensitive information, harder to detect.
Mandate AI Security Testing for OEMs
CERT-In issued guidelines in June 2026 requiring all original equipment manufacturers and technology providers to implement AI-accelerated vulnerability protection. The guidelines mandate AI-assisted security testing, continuous monitoring, patch management and incident response frameworks designed specifically to counter AI-driven threats.
A separate blueprint released in May 2026 focuses on protecting digital infrastructure against rapidly evolving AI-driven attacks. An April 2026 advisory titled Defending Against Frontier AI Driven Cyber Risks outlined comprehensive measures for organisations, micro, small and medium enterprises and individuals to strengthen protection.
Technical guidelines issued in July 2025 require a Bill of Materials, a detailed inventory of all components in a system, for software, hardware, AI systems and quantum computing implementations. The requirement aims to improve transparency in supply chains and help organisations track potential vulnerabilities across their technology stack.
Advertisement
CERT-In has also published guidance on responsible use of generative AI solutions, cyber security standards for smart city infrastructure that use AI and machine learning and measures to counter deepfake threats. A whitepaper published with Mastercard in August 2023 examined increasing attacks on application programming interfaces, the sets of rules that allow different software systems to exchange data, and how AI can help mitigate these attacks.
CERT-In is a co-signatory to a joint risk analysis report on AI published by the National Cybersecurity Agency for France in February 2025. The report, titled Building trust in AI through a cyber-risk-based approach, examines how organisations can adopt AI while managing associated cyber risks.
By the numbers
- 1,470
- participants in AI cyber threat exercises
- 345
- organisations across critical sectors involved
- 10
- cyber security exercises conducted in June-July 2026
A professional certification programme launched in September 2024 in partnership with SISA aims to equip cyber security professionals with skills to secure AI systems.
The Certified Security Professional in Artificial Intelligence programme has received accreditation from the American National Standards Institute National Accreditation Board. CERT-In also runs ongoing cyber security training programmes with industry partners to upskill the workforce across government, public and private sectors.
Your Questions, Answered
What AI tools has CERT-In deployed for cyber security?
CERT-In has deployed AI-driven systems for three functions: detecting malicious domains and phishing, assessing vulnerabilities in public-facing digital assets in sandbox environments and sharing automated threat intelligence with organisations across sectors.
How many organisations participated in the AI cyber threat exercises?
The exercises conducted between June and July 2026 involved 1,470 participants from 345 government and private organisations across power, telecom, banking, financial services, insurance, transport, education, health and space sectors.
What do the new June 2026 guidelines require from technology providers?
The guidelines require all OEMs and technology providers to implement AI-accelerated vulnerability protection, including AI-assisted security testing, continuous monitoring, patch management and incident response frameworks to defend against AI-driven threats.
What is the CSPAI certification programme?
The Certified Security Professional in Artificial Intelligence is a programme launched by CERT-In and SISA in September 2024 to train cyber security professionals in securing AI systems. It has ANSI National Accreditation Board approval.


