
SEBI Launches AI Cybersecurity Task Force to Safeguard India’s Financial Markets
SEBI launches an AI cybersecurity task force to strengthen digital security, address emerging threats, and protect India’s financial markets from cyber risks.
The Securities and Exchange Board of India (SEBI) has established a dedicated task force, called “cyber-suraksha.ai”, to strengthen cybersecurity across India’s securities market ecosystem. This is done in response to the growing risks posed by advanced artificial intelligence (AI) tools. The initiative comes after SEBI’s 5 May 2026 Advisory on Emerging Advanced AI Tools for Vulnerability Detection, which cautioned entities that while AI-powered vulnerability identification tools improve defensive capabilities, their deployment without proper governance and oversight may introduce new cyber risks.
The task force includes representatives from Market Infrastructure Institutions (MIIs), Qualified Registrars and Transfer Agents (QRTAs), regulated entities, and other key stakeholders. Its mandate includes examining risks associated with AI-based models, developing a uniform mitigation strategy, sharing threat intelligence and vulnerability management best practices, preparing response playbooks for emerging threat vectors, and ensuring the priority reporting of cyber incidents and malicious activities. SEBI has emphasised that monitoring and sharing of information are essential to prevent cyber incidents from escalating into systemic disruptions.
In addition to the formation of the task force, SEBI has advised regulated entities to improve their cybersecurity posture by promptly applying security patches, conducting regular vulnerability assessments, security audits, and ensuring a safe integration of AI-based security tools into the existing cyber resilience frameworks.
READ MORE -> SEBI Launches AI Cybersecurity Task Force to Safeguard India’s Financial Markets.
📰 MINI HEADLINES

Supreme Court Reinforces Consent and Privacy Safeguards for APAAR IDs
The Supreme Court has directed the CBSE to implement the safeguards prescribed by the Orissa High Court for the Automated Permanent Academic Account Registry (APAAR) programme throughout India. The Court noted that the Aadhaar-linked student identification system must give parents and students a genuine opportunity to refuse consent or opt out. It also directed CBSE to investigate issues relating to the collection, storage, and processing of student's personal data. The directions were issued when the proceedings challenging the constitutional validity of APAAR were ongoing. The petitioners contended that a programme which was supposed to be voluntary had, in practice, become mandatory.
The development reinforces the importance of meaningful consent within large-scale public digital initiatives. The Orissa High Court had previously held that consent for APAAR IDs must be informed, voluntary, and free from coercion, particularly when processing personal data of children. By extending these safeguards nationwide, the Supreme Court has underscored that participation in digital public infrastructure should not come at the expense of individual autonomy or privacy rights. The ruling is expected to influence the implementation of future government digital identity programmes by placing greater emphasis on privacy-by-design, transparency, and accountability. It also highlights the growing relevance of the DPDPA in shaping public-sector data governance, particularly where children’s personal data is involved.
READ MORE- Supreme Court Reinforces Consent and Privacy Safeguards for APAAR IDs.
Strengthening India’s Privacy Workforce Through Industry-Academia Collaboration
The Foundation of Data Protection Professionals in India (FDPPI) and MYRA School of Business have entered a strategic collaboration to strengthen data protection education and professional capacity building in India. The partnership will introduce co-branded certification programmes for Data Protection Officers (DPOs) and Data Auditors, combining FDPPI’s industry expertise with MYRA’s academic framework. The initiative aims to equip professionals with practical knowledge of privacy governance, regulatory compliance, and data protection practices as organisations prepare for the implementation of the DPDPA.
The collaboration addresses the growing demand for qualified privacy professionals across industries. The certification programmes are expected to bridge the gap between academic learning and practical implementation by focusing on emerging privacy challenges, governance frameworks, compliance strategies, and risk management. As the country’s data protection framework continues to mature, organisations will require skilled professionals capable of translating legal obligations into effective operational practices. Industry-academia collaborations such as this are expected to play a significant role in developing a competent privacy workforce by strengthening organisational compliance capabilities.
READ MORE - Strengthening India’s Privacy Workforce Through Industry-Academia Collaboration
India Debates Regulatory Data Protection to Foster Pharmaceutical Innovation

The Organisation of Pharmaceutical Producers of India (OPPI) has renewed its call for the introduction of a Regulatory Data Protection (RDP) framework, proposing that the protection period for clinical trial and safety data should commence from the date a pharmaceutical product receives marketing approval in India, rather than its first approval anywhere in the world. OPPI argues that the current absence of a dedicated regulatory data protection regime, coupled with lengthy approval timelines, significantly reduces the effective period during which innovators can benefit from the exclusivity of the data they generate. The proposal remains under consideration following consultations with the Department for Promotion of Industry and Internal Trade (DPIIT), the Ministry of Health and Family Welfare, and the Central Drugs Standard Control Organisation (CDSCO).
Regulatory Data Protection safeguards the proprietary clinical and pre-clinical data submitted to regulators for obtaining marketing approval by preventing competitors from relying on that data for a specified period. While OPPI has advocated a 10-year protection period, it has indicated a willingness to consider a shorter duration, provided the exclusivity period begins upon approval in India. The industry contends that such an approach would align regulatory protection with the realities of India’s approval process and encourage greater investment in pharmaceutical research and development. The proposal highlights the growing intersection between data governance, regulatory policy, and innovation.
READ MORE - India Debates Regulatory Data Protection to Foster Pharmaceutical Innovation




