India's finance ministry has asked banks to start work on a coordinated quantum transition strategy and an artificial intelligence resilience framework, underscoring the growing urgency around next-generation cyber threats in the financial system.
The directive, according to an official who did not wish to be identified, calls on lenders to assess their exposure to post-quantum vulnerabilities and begin mitigation measures. The emphasis is not only on individual preparedness but also on common industry parameters that can guide a sector-wide response. "Each bank can prepare its internal strategy, but there has to be some common industry parameters," the official said.
Quantum Risk Rising
The push comes as the banking industry increasingly worries about so-called "harvest now, decrypt later" attacks, a threat model in which cyber adversaries collect encrypted banking data today with the expectation that future quantum computers may be able to break current cryptographic protections. For banks, the risk is not limited to transactional data. It extends to customer records, payment instructions, internal communications, and long-lived archives that may remain sensitive for years.
That concern is especially relevant for financial institutions, which depend heavily on encryption to secure digital payments, online banking, interbank messaging, and regulatory data flows. While large-scale quantum computers capable of breaking widely used public-key cryptography are not yet operational, security planners increasingly view the migration to quantum-resistant standards as a long-term necessity rather than a distant theoretical issue.
The finance ministry's intervention suggests policymakers want the sector to move before the threat becomes immediate. A fragmented approach, industry participants say, could leave weaker institutions exposed and create uneven security across the financial ecosystem. A common framework would allow banks to align on risk assessment, migration timelines, and technical standards, reducing the chance of incompatible or delayed upgrades.
AI Adds New Exposure
Alongside quantum preparedness, the ministry has asked banks to develop an AI resilience framework, reflecting a second layer of concern: the rapid adoption of artificial intelligence across banking operations. AI is increasingly used in fraud detection, customer service, credit assessment, compliance monitoring, and internal automation. But the same tools can also introduce new vulnerabilities, including model manipulation, data poisoning, automated fraud, and overreliance on opaque decision systems.
For regulators and policymakers, the challenge is to ensure that AI improves efficiency without weakening operational controls or amplifying cyber risk. Banks are likely to be asked to examine how AI systems are trained, where sensitive data is stored, how outputs are validated, and what safeguards exist against misuse or malfunction. The resilience framework may also need to address third-party dependencies, since many banks rely on external vendors for AI-enabled services and cloud infrastructure.
The dual focus on quantum and AI reflects a broader shift in financial-sector supervision from reactive cybersecurity to anticipatory resilience. Rather than waiting for a major breach or technology disruption, authorities appear to be pushing banks to map future threats now and build transition plans that can be executed over time.
Sector Coordination Needed
The scale of the challenge makes coordination essential. Banks vary widely in digital maturity, legacy system complexity, and cybersecurity budgets. Large private lenders may be better positioned to begin cryptographic inventory and migration planning, while smaller institutions could struggle with the cost and technical burden of replacing older systems. A sector-wide framework could help establish minimum expectations, shared terminology, and phased implementation milestones.
Industry experts have long argued that post-quantum migration will require more than a software update. It will involve identifying every system that relies on vulnerable cryptography, testing replacement algorithms, updating hardware where necessary, and ensuring that new standards do not disrupt payment flows or customer access. The process is likely to be gradual and resource-intensive, making early planning critical.
The ministry's request also signals that India is treating financial cyber resilience as a strategic policy issue, not merely a compliance exercise. As digital banking deepens and data volumes grow, the cost of inaction could rise sharply. By asking banks to prepare for both quantum-era threats and AI-related risks, policymakers are effectively telling the sector to modernize its security architecture before the next wave of technology-driven disruption arrives.
