Blog

Here you’ll find everything you need to learn about digital software technology, development trends and beyond

Categories

Cybercrime Through AI Agents: New Legal Risks for Indian Companies

AI cybercrime risks for Indian companies involving phishing, data theft, identity fraud, malware, and cybersecurity threats.

Introduction

AI Cybercrime is becoming a growing concern for Indian companies as artificial intelligence systems become more capable of automating research, communication, software analysis, and other tasks. AI agents can carry out tasks with limited human input, which can also increase the speed and scale of cyberattacks when attackers misuse these systems.

CERT-In reported in 2026 that advanced AI systems can support automated vulnerability discovery, reconnaissance, rapid exploitation, credential compromise, and highly convincing social-engineering activity. CERT-In also advised organisations to strengthen monitoring, patching, incident response, backup systems, and cyber exercises.

The Ministry of Home Affairs has also stated that the Government is taking measures to address AI-enabled cybercrime, including work through the Indian Cyber Crime Coordination Centre (I4C), the National Cyber Crime Reporting Portal, cyber-fraud mitigation systems, and coordination with banks, payment providers, telecom companies, technology platforms, and law-enforcement agencies.

For businesses, the key issue is not only the technology itself. Companies also need to consider legal responsibility, cybersecurity controls, data protection, employee awareness, vendor contracts, incident reporting, evidence preservation, and business continuity.

This guide explains AI Cybercrime risks for Indian companies, including AI-enabled phishing, impersonation, automated attacks, data theft, payment fraud, third-party risks, incident response, and important compliance considerations for 2026.

Why AI Cybercrime Matters

Traditional cyberattacks can already cause serious business disruption. AI can increase the speed and scale of some attack activities.

An attacker may misuse AI to support:

  • Phishing campaigns.
  • Social engineering.
  • Impersonation.
  • Credential theft.
  • Automated reconnaissance.
  • Vulnerability discovery.
  • Fraudulent communications.
  • Malicious code development.
  • Data-extraction attempts.

CERT-In’s July 2026 guidance states that AI-enabled cyber threats can make phishing and impersonation attacks more scalable and harder to detect.

Understanding AI Cybercrime can help companies:

  • Identify new cyber risks.
  • Protect sensitive information.
  • Strengthen employee awareness.
  • Improve access controls.
  • Review AI-related vendor risks.
  • Prepare incident-response plans.
  • Preserve important evidence.
  • Meet applicable cyber-incident obligations.
  • Improve business resilience.

Key Areas of AI Cybercrime Risks

1. AI-Enabled Phishing and Social Engineering

AI can make fraudulent messages more convincing.

Attackers may create messages that appear to come from:

  • Company executives.
  • Finance teams.
  • Suppliers.
  • Customers.
  • Banks.
  • Regulators.
  • Technology providers.

AI can also help tailor messages to specific employees or business functions.

Companies should therefore strengthen:

  • Employee awareness.
  • Email security.
  • Identity verification.
  • Payment approval controls.
  • Multi-factor authentication.
  • Suspicious-message reporting.

CERT-In has specifically identified AI-generated phishing, impersonation, and multilingual social-engineering campaigns as emerging risks.

2. AI-Driven Impersonation

AI can be used to imitate a person’s voice, image, or writing style.

This can create risks such as:

  • Fake executive instructions.
  • False payment requests.
  • Fake customer communications.
  • Fraudulent supplier messages.
  • Business-identity misuse.

Companies should not rely only on the appearance or tone of a message.

High-risk requests should be verified through a separate communication channel.

The Government has also highlighted AI-enabled cybercrime and digital-identity protection as important areas of cybercrime prevention.

3. Automated Vulnerability Discovery

Advanced AI systems may help attackers identify weaknesses in software and public-facing infrastructure more quickly.

CERT-In’s April 2026 advisory describes capabilities involving large-scale code analysis, vulnerability discovery, automated reconnaissance, and multi-stage attack planning.

Companies should therefore:

  • Maintain updated software.
  • Scan external systems regularly.
  • Patch critical vulnerabilities quickly.
  • Monitor internet-facing assets.
  • Test important applications.
  • Review API security.

A strong vulnerability-management programme can reduce the time available for attackers to exploit known weaknesses.

4. Credential Theft and Account Compromise

AI can support convincing attempts to obtain passwords, authentication codes, and other credentials.

Business accounts at risk may include:

  • Email.
  • Cloud platforms.
  • Banking systems.
  • HR systems.
  • Customer applications.
  • Developer environments.
  • Administrative accounts.

Companies should use:

  • Multi-factor authentication.
  • Strong access controls.
  • Privileged-access management.
  • Password protection.
  • Login monitoring.
  • Credential rotation.

Employees should also understand that an AI-generated message can appear highly professional and still be fraudulent.

5. Financial and Payment Fraud

AI-enabled attacks can target financial processes.

For example, criminals may attempt to:

  • Change supplier payment information.
  • Send fake invoices.
  • Impersonate senior executives.
  • Create fraudulent payment requests.
  • Manipulate procurement communications.

Companies should use additional verification for unusual or high-value payments.

Finance teams should also maintain clear approval procedures.

I4C’s 2026 work includes a Cyber Fraud Mitigation Centre that brings together banks, financial intermediaries, payment aggregators, telecom providers, technology intermediaries, and law-enforcement representatives for coordinated action against cybercrime.

6. Data Theft and Confidential Information

AI-enabled attacks can target valuable company information.

This may include:

  • Customer data.
  • Employee records.
  • Financial information.
  • Source code.
  • Trade secrets.
  • Contracts.
  • Product plans.
  • Intellectual property.

A data breach can create legal, financial, and operational consequences.

Companies should therefore protect sensitive information through:

  • Access controls.
  • Encryption.
  • Data-loss prevention.
  • Secure backups.
  • Employee training.
  • Vendor controls.

India’s data-protection framework includes the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. The Rules were notified by MeitY in November 2025 with a phased commencement structure.

7. AI Agent Access to Business Systems

An autonomous AI agent may be connected to company tools.

These tools can include:

  • Email.
  • Databases.
  • Cloud systems.
  • CRM platforms.
  • Payment systems.
  • Internal applications.
  • APIs.

This creates a new risk.

If an attacker compromises the AI agent or its credentials, connected systems may also be affected.

Companies should therefore:

  • Limit AI permissions.
  • Use least-privilege access.
  • Separate critical systems.
  • Monitor AI actions.
  • Restrict sensitive functions.
  • Require approval for high-risk actions.

8. Malicious Use of AI by Insiders

Cyber risks do not always come from outside the company.

An employee or contractor may misuse AI tools to:

  • Extract confidential information.
  • Generate fraudulent communications.
  • Bypass internal controls.
  • Misuse company credentials.
  • Share protected information with external systems.

Companies should maintain clear policies for AI use.

They should also monitor access to sensitive systems and data.

9. Third-Party AI and Technology Providers

Many companies use external AI services.

These providers may process:

  • Business documents.
  • Customer information.
  • Source code.
  • Operational data.
  • Financial information.

Vendor contracts should clearly address:

  • Data protection.
  • Security standards.
  • Incident notification.
  • Confidentiality.
  • Access controls.
  • Liability.
  • Audit rights.
  • Data deletion.
  • Business continuity.
  • Subcontractors.

A company should know what happens if an AI provider suffers a security incident.

10. AI-Generated Malware and Malicious Code

AI can also be used to assist in the development or modification of malicious software.

From a legal and risk-management perspective, companies should focus on prevention and detection.

Important controls include:

  • Secure software development.
  • Code review.
  • Endpoint security.
  • Application security testing.
  • Dependency monitoring.
  • Access controls.
  • Threat detection.

CERT-In’s 2026 materials emphasise stronger vulnerability assessment, monitoring, and incident response against AI-driven threats.

11. Incident Reporting and Legal Obligations

A company should know what it must do when an AI-enabled cyber incident occurs.

CERT-In’s directions under Section 70B of the Information Technology Act require covered entities to report specified cyber incidents within six hours of noticing the incident or being informed of it. CERT-In also states that additional information can be provided later when all details are not available at the time of the initial report.

Companies should therefore have a clear incident process covering:

  • Detection.
  • Containment.
  • Internal escalation.
  • Evidence preservation.
  • Legal review.
  • Regulatory reporting.
  • Customer communication.
  • Recovery.
  • Post-incident review.

The exact obligations can vary according to the organisation, sector, incident, and applicable law.

12. Digital Evidence and Evidence Preservation

AI-enabled incidents can generate large amounts of digital evidence.

Important records may include:

  • System logs.
  • Authentication records.
  • Email headers.
  • API logs.
  • Device information.
  • AI-agent activity logs.
  • Transaction records.
  • Security alerts.
  • Vendor communications.

Companies should preserve relevant evidence promptly.

This can help with:

  • Internal investigations.
  • Insurance claims.
  • Regulatory inquiries.
  • Dispute resolution.
  • Law-enforcement requests.

CERT-In’s 2026 advisory also advises organisations to preserve logs and maintain incident-response arrangements when suspicious activity is detected.

13. Business Continuity and Disaster Recovery

An AI-enabled cyberattack may affect critical business operations.

Companies should prepare recovery plans for:

  • Customer systems.
  • Financial systems.
  • Cloud services.
  • Data platforms.
  • Communication systems.
  • Internal applications.

Business continuity plans should identify:

  • Critical services.
  • Recovery priorities.
  • Backup systems.
  • Recovery responsibilities.
  • Communication procedures.
  • Testing schedules.

CERT-In’s 2026 guidance recommends stronger business continuity and disaster-recovery capabilities, including tested recovery procedures and backup validation.

14. Employee Training and Awareness

Employees remain an important part of cyber defence.

Training should cover:

  • AI-generated phishing.
  • Deepfake messages.
  • Fake executive instructions.
  • Suspicious links.
  • Fraudulent payment requests.
  • Credential theft.
  • Safe AI use.

Employees should know how to report suspicious activity quickly.

CERT-In’s 2026 guidance specifically recommends cybersecurity training to improve awareness of AI-generated content, scams, phishing, impersonation, and related risks.

15. Legal Responsibility and Accountability

A key point for businesses is that AI does not automatically become the legal decision-maker simply because an AI system was involved.

Responsibility may still depend on:

  • Who deployed the system.
  • Who controlled it.
  • Who authorised the action.
  • Whether reasonable security measures existed.
  • Whether contractual obligations were followed.
  • What underlying law applies to the conduct.

India’s AI governance discussions continue to consider how existing legal frameworks should apply to emerging AI systems and how accountability can be strengthened across the AI value chain.

Businesses should therefore document human and organisational responsibility around important AI systems.

Common AI Cybercrime Risks for Indian Companies

Indian companies may face AI Cybercrime risks through:

  • AI-generated phishing.
  • Executive impersonation.
  • Deepfake-based fraud.
  • Automated reconnaissance.
  • Credential theft.
  • Payment fraud.
  • Data breaches.
  • Malicious AI-assisted code.
  • Compromised AI agents.
  • Insider misuse.
  • Third-party AI vulnerabilities.
  • Weak access controls.
  • Poor incident response.
  • Incomplete evidence preservation.

These risks can lead to financial loss, service disruption, data exposure, contractual disputes, regulatory issues, and reputational damage.

Best Practices for Managing AI Cybercrime Risks

Indian businesses should consider the following practices:

  • Maintain an inventory of AI systems and agents.
  • Limit AI access to only necessary systems.
  • Use multi-factor authentication.
  • Protect privileged accounts.
  • Monitor important AI activities.
  • Patch critical vulnerabilities quickly.
  • Verify unusual payment requests.
  • Review important AI vendors.
  • Protect confidential and personal data.
  • Maintain secure backups.
  • Train employees regularly.
  • Conduct AI-focused cyber drills.
  • Maintain clear incident-response plans.
  • Preserve logs and other digital evidence.
  • Review legal and regulatory reporting requirements.

A strong security programme should combine technology controls with legal, contractual, and governance measures.

2026 AI Cybercrime Considerations

AI Cybercrime is a particularly important issue in 2026 because AI systems are becoming more capable and more deeply integrated into business operations.

CERT-In’s April 2026 advisory highlighted advanced AI capabilities involving automated vulnerability discovery, reconnaissance, exploit development, and multi-stage attack activity.

In July 2026, the Government reported that CERT-In had conducted 10 cyber-security exercises on AI-driven cyber threats involving 1,470 participants from 345 government and private organisations. The Government also stated that CERT-In had expanded AI-enabled vulnerability assessment for public-facing digital assets and issued 2026 guidance concerning AI-accelerated vulnerability protection and response.

The Ministry of Home Affairs has also stated that the Government is strengthening mechanisms to address AI-enabled cybercrime through I4C, cyber-fraud mitigation, threat intelligence, and digital-identity protection.

Businesses should therefore focus on:

  • AI-enabled phishing and fraud.
  • AI-assisted vulnerability exploitation.
  • AI-agent access controls.
  • Digital identity protection.
  • Payment verification.
  • Third-party AI risk.
  • Data protection.
  • Incident reporting.
  • Evidence preservation.
  • Business continuity.
  • Employee awareness.

The legal framework will continue to develop as AI capabilities change. Companies should therefore review their security and legal controls regularly.

How Derecho Consulting Can Help

Derecho Consulting can help Indian businesses manage AI Cybercrime risks through AI-risk assessments, cybersecurity legal advisory, AI governance reviews, technology-contract reviews, vendor due diligence, incident-response planning, data-protection assessments, compliance reviews, and documentation support.

A proactive approach can help businesses:

  • Identify AI-related cyber risks.
  • Review AI-agent permissions.
  • Assess technology vendors.
  • Strengthen incident-response processes.
  • Review cybersecurity contracts.
  • Protect sensitive business information.
  • Improve compliance documentation.
  • Prepare for regulatory developments.
  • Establish stronger governance around AI use.

Derecho Consulting can also support periodic reviews as AI technologies and cyber threats continue to evolve.

Conclusion

Cybercrime Through AI Agents is creating new legal and operational challenges for Indian companies. AI can make some cyber activities faster, more targeted, and more scalable. CERT-In and the Ministry of Home Affairs have already highlighted the growing importance of AI-enabled cyber threats and cyber resilience.

Companies should not focus only on the technology used by attackers. They should also examine their own systems, access controls, payment processes, AI tools, vendor relationships, data protection, incident response, and evidence-management practices.

Clear AI governance can help companies understand who is responsible for important systems and what controls are required when AI interacts with business infrastructure.

By combining cybersecurity, legal controls, employee training, vendor management, incident response, and strong governance, Indian businesses can strengthen their resilience against emerging AI Cybercrime risks in 2026 and beyond.