SEBI — Cybersecurity Framework, Regulation 16C, and the AI Consultation
Two binding instruments and one proposal. CSCRF 2024 and Regulation 16C (in force 10 February 2025) already apply to SEBI-regulated entities. The AI-in-markets consultation paper of 20 June 2025 is a proposal only.
CSCRF 2024 — binding today
If SEBI regulates you, CSCRF already applies. That covers brokers, depositories, mutual funds, portfolio managers, investment advisers, and market infrastructure institutions.
CSCRF is SEBI's Cybersecurity and Cyber Resilience Framework, issued in 2024. It is binding now, not a proposal. The rules are tiered by size, so how much you must do depends on how big you are.
- A documented information security policy.
- Every quarter, check your systems for weaknesses and then try to break in yourself. This is called VA/PT — vulnerability assessment and penetration testing.
- A Security Operations Centre — a team that watches your systems for attacks around the clock.
- Quarterly cyber incident reporting.
CSCRF has changed six times since it was issued
Most write-ups cite the original circular of 20 August 2024. That is not the whole rule.
SEBI has amended or clarified it six times: in December 2024, March 2025, April 2025, June 2025, August 2025, and again in May 2026 with an advisory on AI tools.
Two of those changes matter most. The April 2025 circular revised how entities are put into categories, and your category decides what standard you are held to. And the deadline moved twice before landing on 31 August 2025. That date has passed, and SEBI has not extended it again.
So implementation is no longer the live obligation. The recurring cyber-audit cycle is. For 2025-26, half-yearly audit reports and action-taken reports were due by 31 March 2026, with the next cycle by 30 June 2026.
Regulation 16C — the binding AI rule
There is also a separate AI rule, and it is already law.
SEBI added it through the SEBI (Intermediaries) (Amendment) Regulations, 2025. SEBI notified these on 6 February 2025, under Section 30 of the SEBI Act, 1992. The rule took effect when the Official Gazette published it on 10 February 2025. That second date is the one that matters.
The rule sits in a new Chapter IIIB of the SEBI (Intermediaries) Regulations, 2008. The chapter is titled "Usage of Artificial Intelligence". Within it, Regulation 16C is headed "Responsibility for the use of artificial intelligence".
If you use an AI tool, you own what it does. Regulation 16C makes this simple: a SEBI-regulated firm is solely responsible for any AI or machine-learning tool it uses. It does not matter whether you built the tool or bought it. It does not matter how small the use is.
You are responsible for three things: keeping client and stakeholder data private and secure, including data you hold on someone else's behalf; whatever the tool outputs; and staying compliant with the law. SEBI can act against you if any of that fails.
Buying the tool from a vendor does not move the liability to the vendor.
SEBI enforces this under Chapter V of the Intermediaries Regulations.
The same AI rule reached two other groups in the same package, approved at SEBI's 208th Board meeting.
Recognised stock exchanges and clearing corporations came under it on 10 February 2025. The instrument was the Securities Contracts (Regulation) (Stock Exchanges and Clearing Corporations) (Amendment) Regulations, 2025.
Depositories and participants followed on 1 April 2025. The instrument was the SEBI (Depositories and Participants) (Amendment) Regulations, 2025.
Commencement date confirmed against the SEBI page. The operative text of Regulation 16C has not yet been read in full. A consolidated compilation dated April 2026 attributes Chapter IIIB to an (Intermediaries) (Amendment) Regulations, 2026. The notification number is SEBI/LAD-NRO/GN/2025/226, dated 2025. We have not resolved this and cite 2025.
AI-in-markets consultation — the proposed layer, not yet binding
SEBI is also thinking about going further, but it has not done so yet.
SEBI put out a consultation paper on AI in securities markets on 20 June 2025. It took comments until 11 July 2025. Nothing has been finalised, so it creates no duty today. Here is what it proposes:
- Model documentation.
- Model validation.
- Drift monitoring.
- Human oversight.
- Explainability for AI-driven investment tools.
Again, this is a proposal, not a rule. It asks nothing of you today. Consultation-to-binding-rule status: .
SEBI has also written about AI as a security risk
On 5 May 2026 SEBI issued an advisory on advanced AI tools for finding security weaknesses.
This is a different subject from Regulation 16C. That rule is about you being answerable for AI you use in your business. This advisory is about AI being used to find holes in systems — by attackers looking for a way in, and by defenders looking before they do.
It sits alongside CERT-In's advisory of 26 April 2026 on frontier AI and cyber risk. Both regulators reached the same conclusion within ten days of each other.
We have logged the SEBI circular but not yet read what it requires.
Read the CERT-In breach-response and cyber duties guide →
So: you owe CSCRF work now. Regulation 16C makes you answerable for any AI tool you use, now. The consultation paper only warns you about what may come next.
For what you specifically have to report, check with your lawyer and read the SEBI circular linked below.
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024. The original circular has been amended or clarified six times: December 2024, March 2025, April 2025, June 2025, August 2025, and May 2026 (advisory on AI tools). Only the original circular has been retrieved; the six later instruments are cited by date only and have not been opened.
Status unverified — no status check recorded
Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026, 5 May 2026. Circular page verified. Contents of the advisory PDF not yet read.
Am I a Data Fiduciary?
Sector rules sit on top of DPDP, not instead of it. Run the self-check to confirm your baseline DPDP status first.
Run it now