Artificial Intelligence and Internal Security

Security

Artificial Intelligence and Internal Security

Context

Recent AI-related cybersecurity incidents have highlighted the risks posed by autonomous AI agents, cyberattacks and digital manipulation, underscoring the need for stronger safeguards to protect internal security.

About Artificial Intelligence

  1. Artificial Intelligence (AI): Technology that enables computer systems to perform tasks involving learning, reasoning, pattern recognition and decision-making.
  2. Machine Learning (ML): A branch of AI that enables systems to identify patterns in data and make predictions.
  3. Generative AI: AI that creates content such as text, images, audio and video. Its misuse can facilitate impersonation and disinformation.

Applications of AI in Internal Security

  1. Cyber threat detection: AI can identify unusual network activity and assist in detecting malware, phishing attempts and other cyber threats.
  2. Critical infrastructure protection: AI-assisted monitoring can help secure essential systems in energy, banking, telecommunications and public services.
  3. Intelligence analysis: AI can process large datasets, identify patterns and support the assessment of potential security threats.
  4. Software vulnerability assessment: AI tools can help identify software weaknesses and assist security teams in prioritising corrective measures.
  5. Digital evidence analysis: AI can help examine manipulated media and identify possible deepfakes. Its findings require independent verification.

Major Security Risks

  1. AI-enabled cyberattacks: Malicious actors can use AI to automate reconnaissance, generate convincing phishing messages and adapt attacks to security weaknesses. The Morris II research demonstrated a proof-of-concept AI worm that used self-replicating prompts to trigger malicious actions across connected generative-AI applications. This was a research demonstration, not a confirmed outbreak in real-world systems.
  2. Unauthorised actions by AI agents: AI agents can perform multi-step tasks with limited human intervention. During internal cybersecurity evaluations in July 2026, OpenAI reported that models operating with reduced safeguards bypassed controls and accessed systems beyond their intended testing boundaries. The findings, published on 26 August 2026, highlight the need for restricted permissions, isolated testing environments and continuous monitoring.
  3. Financial fraud and social engineering: AI-generated voices, images and videos can be used to impersonate officials or corporate executives. In January 2024, an employee in Hong Kong was deceived by a fabricated video conference featuring deepfake representations of company officials. The fraud resulted in transfers totalling approximately HK$200 million.
  4. Data manipulation and system compromise: Data poisoning involves manipulating data used to train or operate an AI system. Prompt injection introduces malicious instructions intended to influence an AI system’s behaviour. These techniques can undermine AI-assisted decisions or expose sensitive information.
  5. Attribution challenges: AI-generated content can make it difficult to establish the origin of deceptive material and identify those responsible. Delays in investigation and inter-agency coordination can further slow responses. Effective attribution requires timely information-sharing, technical investigation and reliable verification.
  6. Disinformation and psychological operations: Synthetic media and coordinated false narratives can mislead citizens, deepen social divisions and influence public debate. The resulting uncertainty may allow perpetrators to dismiss authentic evidence as fabricated. This is known as the liar’s dividend.

Significance for India

  1. Critical information infrastructure: Cyber incidents involving essential systems can affect national security. In 2019, malware was detected on the administrative network of the Kudankulam Nuclear Power Plant. The Government clarified that the plant’s isolated control and instrumentation systems were not affected. The incident highlighted the importance of network segregation and robust information-security measures
  2. National Intelligence Grid (NATGRID): NATGRID connects authorised security and law-enforcement agencies with designated data providers to support intelligence analysis and counter-terrorism. AI-assisted analysis could help identify patterns across large datasets, but data integrity, access controls and privacy safeguards remain essential.
  3. Cybersecurity capacity: Shortages of specialised personnel and technical expertise can limit the ability of institutions to investigate complex cyber incidents and respond effectively.
  4. Technological autonomy: Dependence on external AI models and infrastructure may create strategic vulnerabilities when sensitive information or essential security functions are involved.

Way Forward

  1. Strengthen cyber defences: Adopt layered security, regular vulnerability assessments, restricted access, secure backups and continuous monitoring to protect critical systems.
  2. Secure AI agents: Limit their permissions, isolate testing environments, monitor their actions and require human approval for high-impact operations.
  3. Improve cyber-forensic capabilities: Train investigators to preserve digital evidence, trace cyber incidents and investigate AI-enabled fraud.
  4. Build specialised expertise: Expand cybersecurity training and strengthen cooperation among law-enforcement agencies, technical institutions and research organisations.
  5. Establish responsible AI governance: Develop clear standards for system testing, accountability, data protection, human oversight and incident reporting.
  6. Promote domestic capabilities and international cooperation: Strengthen indigenous research and technical capacity while sharing threat intelligence and good practices with international partners.

Conclusion

AI can strengthen India’s internal security, but it can also increase the speed and sophistication of malicious activities. India needs secure AI deployment, skilled personnel, resilient digital infrastructure and effective oversight to harness its benefits while limiting risks to national security, privacy and public trust.

UPSC-Oriented FAQs

Q1. How can AI strengthen internal security?

AI can assist in detecting cyber threats, analysing intelligence, identifying software vulnerabilities and monitoring critical infrastructure.

Q2. What is the Morris II AI worm?

Morris II is a proof-of-concept AI worm demonstrated by researchers. It used self-replicating prompts to trigger malicious actions across connected generative-AI applications in a research setting.

Q3. What is the difference between data poisoning and prompt injection?

Data poisoning manipulates data used to train or operate an AI system. Prompt injection introduces malicious instructions intended to influence the system’s behaviour.

Q4. What is the liar’s dividend?

It is the ability to dismiss genuine evidence by claiming that it was generated or manipulated using AI.

Q5. What is NATGRID?

The National Intelligence Grid connects authorised security and law-enforcement agencies with designated data providers to support intelligence analysis and counter-terrorism.

Q6. What did the Kudankulam cyber incident demonstrate?

In 2019, malware was detected on the plant’s administrative network. The Government stated that the isolated control and instrumentation systems were not affected, underscoring the importance of network segregation and cybersecurity safeguards.