“I think the Reserve Bank of India’s Innovation Hub is doing a great job on that [cybercrime & fraud]. And they are coming up with a digital payments intelligence platform… which would be looking at all of these signals and doing a risk-based analysis and doing a kind of continuous KYC,” claimed Brijesh Singh, Principal Secretary, Directorate of Information & Public Relations, Government of Maharashtra, on a panel on agentic AI and cybersecurity at the Global Fintech 2026.
To challenge the risk of ‘good accounts’ turning mule accounts later:
“Because I was talking to bankers yesterday, and they said that, you know, in terms of mule accounts, good accounts turn into mules after some time. So all the KYC is correct. Everything is correct. It’s a genuine customer. Three months later, this guy is becoming a mule. So we are facing a challenge, and it’s upon us as regulators and as protectors and defenders to create a trustworthy system in which technology and policies both are important.” — Brijesh Singh, Directorate of Information & Public Relations, Government of Maharashtra.

Lack of provenance is creating a law enforcement problem: “So, for a digital evidence system to establish provenance, you would require having policies which would be enforced by everybody. For example, there is a piece of evidence in which, let’s say, there is some cryptographic signature. But the moment you are sending it on WhatsApp or on social media, that guy is again compressing it, changing the codec, removing metadata, stripping everything. How do I use it as evidence? Because tomorrow, the moot question would be whether this is AI-generated, machine-generated, or not. And increasingly, it is getting difficult because the gangs are learning signals,” said Singh.
“Social engineering has become very, very easy, while proving evidence with provenance in courts is becoming very difficult,” he further said. He also said that scammers are “learning signals each day and becoming closer to original.” “So, earlier, let’s say you used to say that there is jitter or, let’s say, eye blink rate or microexpressions. All of this is being fed back, and the models are becoming better and better and better at runtime,” he added.
“This has created another problem for law enforcement, which is called the liar’s dividend, where anyone can claim that a genuine video is AI-generated, because there is no provenance,” Singh said.
Deepfakes can bypass KYC in real time: “A friend of mine showed me a technology demo. He said, ‘Give me a WhatsApp video call,’ so I did, and he said, ‘Tell me whom you want to talk to.’ And he could become anybody,” Singh said, describing a demo in which the caller impersonated multiple people, including a Bollywood actor, on a live video call. “In real time today, you can have video deepfakes which can bypass KYC. Even for liveness detection, if you ask someone to wave their hand or raise a finger, the video stream being fed into the authentication framework can bypass it.”
“There are 4-5 billion-parameter models which you can run on your phone. The cost and time required to carry out an attack has come down.” – Brijesh Singh
“[Cyber] security should be like a public infrastructure,” Singh said, rather than something every organisation protects only within its own perimeter, since fraud networks operate “across telecom, apps, and social media platforms” and cannot be fought the way a single institution defends its own perimeter.
The accountability question for AI agentic actions: On the limits of full automation, Thapar said, “If you leave it to the agent to do something, and it does something not in line with the regulations or the law of the land, who do you hold accountable? Would you hold the developer? Would you hold the organisation? Would you hold the individual? That still has to evolve.”
Certainty around AI-generated content and actions: Mithilesh Singh, Managing Director, Protiviti, said, “Any system tagged to AI has to be 100% accurate, all the time. And you can’t just say this was done by AI or a model; some human has to be accountable for its execution,” he said.
Attackers are chaining vulnerabilities; the need to act faster: Rajesh Thapar, CISO, NSE India, said the scale of modern attacks has outpaced human response capacity. “How will you be able to handle it when your events per second is going into six digits?” he asked, adding that “exploits are built on the fly” today, and attackers are “chaining vulnerabilities” rather than targeting a single exposure.
You should be able to reverse agentic actions and keep all logs: “You should have a permissible agent. You know what agent has been deployed, for what objective, and what work it is delivering. At any moment, you should be able to pause it and, if possible, reverse the actions it has performed. The UK’s and the European Union’s AI regulations also talk about this. You should have logs for everything.”
Mithilesh Singh also said, “Anthropic released an AI misuse report today. North Korean military officers are posing as IT professionals to get into corporates and act as an insider threat, sending money back to North Korea, and they are doing this with agentic AI, from preparing for interviews to solving the actual assignments.”
PM Modi’s Mann ki Baat reduced digital arrests by 67% but shifted the focus: “You saw there was a spate of digital arrest cases, and none other than Prime Minister Modi himself spoke about this in Mann Ki Baat. Once he spoke, there was a huge spate of awareness campaigns about digital arrest, and actually, digital arrests have fallen by 67%,” claimed Brijesh Singh.
Also Read:














Leave a Reply