RBI Identifies AI Driven Cyberattacks as Leading Risk for Banks and NBFCs
The Reserve Bank of India has highlighted a significant shift in the cybersecurity landscape facing the country’s financial institutions. In its June 2026 Financial Stability Report the central bank noted that artificial intelligence enabled cyber threats have emerged as the most prominent near term risk for banks and non banking financial companies. The finding is based on a survey of thirty three scheduled commercial banks and ten upper layer NBFCs that ranked these sophisticated attacks ahead of more familiar concerns.
Respondents placed AI powered cyberattacks at the top of the risks they expect to encounter over the next twelve months. Nearly ninety five percent of those surveyed included AI enabled threats among their three most significant concerns. This placed the issue well above ransomware and malware, phishing and social engineering, third party supply chain vulnerabilities, and application related weaknesses. The results mark a clear change in how the sector views its exposure, moving beyond conventional attack methods toward threats that leverage advanced artificial intelligence capabilities.
The report explains that progress in AI technology can increase the speed, scale and sophistication of cyber operations. Attackers may use these tools to craft more convincing phishing attempts, automate reconnaissance, or generate novel forms of intrusion that traditional defences find harder to detect. While banks and NBFCs have already invested in strengthening their cyber resilience frameworks, the central bank stressed that continuous improvement in threat monitoring, incident response and overall preparedness remains essential.
Beyond the immediate operational risks, the Financial Stability Report also touched on wider implications of the rapid growth in global AI investment. Heavy reliance on common technology platforms and the expanding use of artificial intelligence across financial services could introduce new forms of systemic exposure if not carefully managed. Institutions are therefore encouraged to assess these technology related risks as part of their broader stability and operational resilience planning.
The survey findings arrive at a time when digital adoption in Indian banking and finance continues to deepen. Online and mobile channels handle large volumes of customer activity every day, creating both efficiency gains and an expanded attack surface. The RBI’s emphasis on AI driven threats reflects an effort to keep regulatory attention aligned with the evolving nature of cyber risk rather than remaining focused solely on older patterns of attack.
Overall the June 2026 report presents a measured assessment. It acknowledges the progress already made by regulated entities while underscoring that the threat environment is changing. AI enabled cyberattacks now stand as the primary concern for the coming year according to the institutions themselves. This recognition is expected to shape internal risk priorities, technology investments and supervisory discussions in the months ahead as the financial sector works to maintain the confidence and security of its systems.