The Indian government has asked banks to begin work on a sector-wide quantum transition plan alongside an artificial intelligence resilience framework, underscoring rising concern that the country's financial system must prepare for a new generation of cyber threats before they become operational realities.
According to an official familiar with the discussions, the finance ministry has told banks to assess their exposure to post-quantum vulnerabilities and initiate mitigation measures. The official, who did not wish to be identified, said the idea is not for each lender to work in isolation, but to develop common industry parameters that can guide the transition. "Each bank can prepare its internal strategy, but there has to be some common industry parameters," the official said.
Quantum Risk Grows
The immediate concern is the so-called "harvest now, decrypt later" threat model, in which cyber adversaries intercept and store encrypted banking data today with the expectation that future quantum machines may be able to break currently trusted cryptographic protections. In practical terms, that means account records, transaction histories, customer credentials and other sensitive financial data could be compromised years after they were originally captured.
For banks, the risk is not theoretical. The financial sector depends heavily on encryption to protect digital payments, online banking, interbank messaging, identity verification and internal communications. If the cryptographic foundations of those systems weaken, the consequences could be systemic, affecting not only customer trust but also operational continuity and regulatory compliance.
The push from the finance ministry suggests that policymakers want the sector to move early, rather than wait for quantum computing to mature into a direct attack capability. That is significant because large financial institutions typically operate on long technology refresh cycles, with legacy systems, vendor dependencies and complex integrations that make security transitions slow and expensive.
AI Adds New Pressure
The ministry's request also includes an AI resilience framework, reflecting the growing use of artificial intelligence in banking operations and the parallel rise in AI-enabled fraud, phishing, deepfakes and automated attack tools. While AI can improve fraud detection, customer service and credit assessment, it also expands the attack surface and can be used to scale malicious activity with greater speed and sophistication.
A resilience framework would likely require banks to map where AI is being used, test how those systems behave under stress, and define controls for model governance, data integrity and human oversight. In the context of cyber defence, that could include safeguards against manipulated training data, adversarial prompts, synthetic identity attacks and AI-assisted social engineering.
The dual focus on quantum readiness and AI resilience points to a broader policy shift: regulators and ministries are no longer treating cyber risk as a narrow IT issue, but as a strategic infrastructure concern. For India's banking system, which has rapidly expanded digital payments and online financial access, the stakes are especially high.
Industry Coordination Needed
The challenge now is execution. Banks will need to inventory where vulnerable cryptographic systems are embedded, identify which applications are most exposed, and plan a phased migration toward post-quantum cryptography. That process will require coordination across banks, technology vendors, payment networks and regulators, because a fragmented transition could create interoperability problems and new security gaps.
Industry experts have long warned that post-quantum migration cannot be handled as a last-minute patch. It involves testing new algorithms, updating hardware and software, validating performance impacts and ensuring that new standards are compatible with existing financial infrastructure. For large banks, the work will likely extend across core banking systems, mobile apps, cloud services, data archives and third-party service providers.
The finance ministry's intervention indicates that the government wants to shape the transition early, possibly to avoid uneven preparedness across the sector. A common framework could also help smaller lenders and fintech-linked institutions, which may lack the resources to independently develop sophisticated quantum-readiness programmes.
For now, the directive is a signal rather than a deadline. But it is a clear one: India's banking system is being asked to prepare for a future in which both quantum computing and AI could redefine the threat landscape. The message from policymakers is that resilience must be built before the disruption arrives, not after it has already begun.
