India's finance ministry has asked banks to draw up a coordinated transition plan for the quantum era and to build an AI resilience framework, signalling that the country's financial system is beginning to treat next-generation cyber risk as a board-level priority rather than a distant technical issue.
The directive comes amid rising anxiety over so-called "harvest now, decrypt later" attacks, in which cyber adversaries collect encrypted banking data today with the expectation that future quantum computers may be able to break current cryptographic protections. An official, speaking on condition of anonymity, said the ministry has asked lenders to assess post-quantum vulnerabilities and start mitigation measures. "Each bank can prepare its internal strategy, but there has to be some common industry parameters," the official said.
Quantum Risk Rising
The warning is significant because the banking sector sits at the centre of India's digital economy. Banks, payment networks and fintech platforms process vast volumes of sensitive financial information, from account credentials and transaction histories to authentication keys and customer identity records. Much of that data is protected by encryption standards that are considered robust today but may not be sufficient in a post-quantum environment.
The concern is not limited to future transactions. Data stolen now could remain valuable for years if it is stored and later decrypted when quantum capabilities advance. That makes the issue especially urgent for institutions with long data-retention cycles, including banks, insurers and payment processors that maintain archives of customer and compliance records.
Industry observers say the ministry's intervention is aimed at preventing a fragmented response, where each institution upgrades at its own pace and with different technical assumptions. A common framework would help banks identify critical systems, classify cryptographic dependencies and prioritise the replacement of vulnerable algorithms in a coordinated manner.
AI Adds New Exposure
The request for an AI resilience framework reflects a second layer of concern. Banks are increasingly deploying AI for fraud detection, customer service, credit assessment and operational automation, but the same tools can create new attack surfaces if they are not properly governed. Adversaries can exploit model weaknesses, manipulate training data, or use AI-enabled phishing and social engineering to bypass controls.
For financial institutions, the convergence of AI and quantum risk creates a more complex security challenge. AI systems depend on trusted data and secure infrastructure, while quantum threats target the cryptographic foundations that protect that infrastructure. Together, they force banks to think beyond traditional perimeter security and toward a broader resilience model that includes cryptography, data governance, model integrity and incident response.
The ministry's ask suggests that regulators and policymakers are moving to align India's financial sector with emerging global discussions on post-quantum cryptography. In several advanced markets, financial regulators and central banks have already begun urging institutions to inventory cryptographic assets, test migration paths and prepare for long transition timelines. Such transitions are expected to be costly and operationally complex, requiring updates to core banking systems, vendor contracts, hardware security modules and customer authentication flows.
Sector-Wide Coordination
A sector-wide approach is likely to be essential because banks do not operate in isolation. Their systems are deeply interconnected with payment rails, cloud providers, fintech partners, card networks and insurance platforms. If one part of the ecosystem lags behind, the weakest link can undermine the security of the whole chain.
That is why the official's reference to "common industry parameters" matters. Standardised guidance could help define which cryptographic protocols should be phased out, what timelines banks should follow, how to test post-quantum readiness, and what minimum controls should be in place for AI systems. It could also reduce duplication of effort and give smaller institutions a clearer roadmap, especially those that lack large in-house cybersecurity teams.
For India's banking and fintech sector, the challenge is to move early without waiting for a crisis. Quantum computers capable of breaking widely used encryption are not yet a day-to-day operational threat, but the migration to quantum-safe systems can take years. The ministry's message appears to be that the preparation window is now, not later.
The broader implication is that cybersecurity in finance is entering a new phase. The focus is shifting from defending against known threats to preparing for technologies that may not yet be fully commercialised but could reshape the risk landscape once they are. For banks, that means the next resilience programme may need to protect not only against today's hackers, but also against tomorrow's machines.
