India’s Strategic Pivot: Building Sovereign AI Defenses to Secure Critical Infrastructure

indias-strategic-pivot-building-sovereign-ai-defenses-to-secure-critical-infrastructure

In a significant move toward achieving digital sovereignty, the Indian government has commissioned homegrown AI unicorn Sarvam AI and the government-backed BharatGen initiative to develop advanced, cybersecurity-focused AI models. This mandate aims to replicate the capabilities of cutting-edge foreign tools—specifically Anthropic’s "Mythos"—to fortify India’s critical information infrastructure against an increasingly sophisticated landscape of global cyber threats.

By transitioning away from reliance on foreign frontier models for sensitive national security tasks, New Delhi is signaling a shift toward an "on-premises" strategy. This approach ensures that the digital armor protecting India’s power grids, financial networks, and telecommunications remains within the country’s sovereign control, housed on isolated, government-managed compute infrastructure.

The Strategic Imperative: Why India Needs a Domestic Mythos

The rapid digitization of the Indian economy has transformed the nation into a primary target for state-sponsored and criminal cyber syndicates. As AI-powered attacks become the new norm, the government has recognized that relying on external, black-box models carries inherent risks—not only in terms of data privacy but also regarding the reliability of the tools themselves.

Anthropic’s Mythos, a model specifically engineered for cybersecurity tasks such as vulnerability research and code analysis, has become the global gold standard. While India has been in active discussions with the US and Anthropic to gain access to such technology, the government is wary of the limitations inherent in depending on external vendors.

The Dual-Edged Sword of AI

The dilemma facing the Indian government is one shared by major powers worldwide: the same AI that can identify a security flaw in seconds can be weaponized by adversaries to exploit that very flaw with equal speed. Anthropic’s cautious rollout of Mythos through its "Project Glasswing" initiative highlights the sensitivity of these tools. If the technology is powerful enough to fix a system, it is powerful enough to break it. By developing indigenous capabilities through Sarvam AI and BharatGen, India aims to cultivate a "Defensive AI" ecosystem that operates under strict national oversight.

Chronology: India’s Path to Sovereign Cybersecurity

The push for indigenous AI-driven defense is the culmination of a multi-year strategy to harden India’s digital borders.

  • FY22–FY24 (The Alarm Bell): As cyberattacks surged—doubling from 1.4 million to nearly 2.9 million incidents—the government noticed a terrifying trend: the "mean time to exploit" a vulnerability plummeted from 745 days to just 44 days. The traditional, human-led response was no longer sufficient.
  • Early 2024 (Testing the Waters): The Indian Computer Emergency Response Team (CERT-In) began experimenting with a mix of open-source and indigenous models within a controlled "sandbox" environment to gauge their efficacy in identifying security gaps.
  • Mid-2024 (The Mythos Dialogue): India formally engaged with US counterparts and Anthropic to explore access to the Mythos model. While India was included in the expansion of Project Glasswing, the depth of access for critical public sector entities remained limited.
  • Late 2024 (The Policy Shift): A directive issued by a department under the Ministry of Electronics and Information Technology (MeitY) advised central ministries to exercise extreme caution, warning against the premature deployment of foreign commercial models like OpenAI and Anthropic for cybersecurity purposes.
  • Present Day (The Sovereign Mandate): The government officially tasked Sarvam AI and BharatGen with the development of a domestic, high-capability cybersecurity AI, marking the formal launch of India’s "Sovereign Cybersecurity AI" mission.

Supporting Data: The Rising Tide of Cyber Risk

The urgency behind this initiative is rooted in cold, hard data. According to reports from the Data Security Council of India (DSCI) and the Boston Consulting Group (BCG), the threat environment for India is evolving at an unprecedented pace.

  1. Velocity of Attacks: The drop in the time-to-exploit (from 745 to 44 days) indicates that hackers are increasingly using automated AI tools to find "Zero Day" vulnerabilities. Defenders who rely on manual patching processes are effectively playing a game of catch-up they cannot win.
  2. Volume of Threats: With 2.9 million cyber incidents recorded in recent years, the sheer scale of the attack surface—ranging from the Unified Payments Interface (UPI) to the national power grid—requires an automated, AI-native response mechanism.
  3. Current AI Efficacy: MeitY Secretary S. Krishnan recently noted that the existing combination of models currently utilized by CERT-In provides roughly 60% to 70% of the capability offered by Mythos. While this is a commendable start, the objective of the new partnership with Sarvam and BharatGen is to close the remaining 30–40% gap and achieve parity or superiority.

Official Responses and Policy Stance

The Ministry of Electronics and Information Technology (MeitY) has been clear about its roadmap. Secretary S. Krishnan has emphasized that while international collaboration remains a priority, "on-premises" deployment is non-negotiable for sensitive sectors.

"Clearly, getting access to Mythos and similar advanced frontier models is very high on the priority of the government," Krishnan stated, confirming that high-level diplomatic efforts are ongoing. However, he balanced this by stressing that for the most critical infrastructure, the intelligence must reside within Indian borders.

The government’s decision to involve Sarvam AI—a unicorn known for its focus on Indic-language models and efficient, indigenous AI stacks—and BharatGen—the nation’s comprehensive initiative for generative AI—demonstrates a commitment to leveraging the best of India’s private and public research talent.

Implications for the Future of Indian Tech

The mandate to build a domestic "Mythos" has profound implications for the Indian technology landscape:

1. Strengthening the "Defensive Stack"

By hosting these models on isolated, government-controlled infrastructure, India is creating a "trusted zone." This prevents sensitive vulnerability data from leaving the country or passing through foreign-owned cloud servers, which could theoretically be compromised or subpoenaed by foreign jurisdictions.

2. Boosting the Indigenous AI Ecosystem

Tasking companies like Sarvam AI with national-security-grade projects acts as a massive stimulus for the domestic AI industry. It provides these firms with unique datasets and use cases, allowing them to iterate and improve their models at a scale that purely commercial ventures might not reach.

3. Diplomatic Leverage

India’s move to build its own tools is not an abandonment of international cooperation, but a strategic hedge. By showing that India has the internal technical capacity to build sophisticated cybersecurity models, the government gains leverage in future negotiations for advanced technology transfers from the West. It transitions the relationship from one of "dependence" to one of "peer-to-peer collaboration."

4. A New Standard for Critical Infrastructure

The deployment of these models will eventually set a new compliance standard for banks, utilities, and public sector enterprises. Expect to see a future where "Sovereign AI-verified" code becomes a mandatory requirement for any vendor supplying software to the Indian government.

Conclusion: The Road Ahead

Building a domestic equivalent to Mythos is a formidable challenge that will require not only significant computational resources but also a constant supply of high-quality cybersecurity data for model training. While there is no official timeline for the delivery of these capabilities, the urgency expressed by MeitY suggests that this is a high-priority project.

As the lines between physical and digital infrastructure continue to blur, India’s ability to defend its critical systems will determine its economic stability and national security. By betting on Sarvam AI and BharatGen, India is not just buying insurance against cyberattacks—it is investing in the digital architecture of the next century, ensuring that its future is built on a foundation of sovereign, secure, and resilient technology.