Advisory on Heightened Cyber Security Risks arising from Frontier Artificial Intelligence Models
IFSCA-CSD/MSC/3/2026-DCS
The record
| Reference | IFSCA-CSD/MSC/3/2026-DCS |
|---|---|
| Issued by | International Financial Services Centres Authority (IFSCA) |
| Instrument type | Circular |
| Date of issue | 4 June 2026 |
| Status | In force |
| Binds | All regulated entities in the IFSCs, read alongside the 2025 Guidelines and, for an MII, the 2026 MII Guidelines — it expressly dilutes neither. Titled an advisory, but six of the eleven Annexure A items are drafted with “shall”: SBOM coverage, an API inventory with rate-limiting, frontier AI as a named board-level risk scenario, and critical-service-provider assurance among them. |
| Dates it sets |
|
What it says
- Requires regulated entities to presume newly disclosed critical vulnerabilities are exploitable within hours.
- Requires frontier AI to be carried as a named scenario in the cyber risk assessment, reviewed periodically and put before the Board — before the Standing Committee on Technology at an MII.
- Requires a Software Bill of Materials covering open-source components, and a comprehensive inventory of APIs and the applications consuming them, with rate-limiting and a whitelist.
- Requires critical service providers to assess frontier-AI risk and furnish evidence of preparedness.
- Requires monitoring tuned for attack sequences that exceed plausible human-operated timelines, and human oversight plus security testing of AI-generated code before production.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- IFSCA Cyber Security Guidelines, 2025 IFSCA-CSD0MSC/13/2025-DCS — Any entity licensed, recognised, registered or authorised by IFSCA in GIFT City.
- IFSCA MII Cyber Security Guidelines, 2026 IFSCA-CSD/MSC/2/2026-DCS — IFSC stock exchanges, clearing corporations and depositories, on top of the 2025 baseline.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .