With frontier AI models’ advancing capabilities in finding cybersecurity loopholes, the focus has now turned to human-led real time monitoring and judgement as India launched a unique hackathon event CYBER KUSHTI 2026 (literally, cyber-wrestling) to “test and recognize human judgment in cybersecurity assessment.
Of late, the frontier AI models like Claude Mythos, Claude Fable, GPT 5.6 have consistently shown enhanced cybersecurity capabilities with models drastically reducing time to find exploits compared to human coders.
The enhanced cybersecurity capabilities of AI models have rung alarm bells in policy corridors from Washington D.C. to 10 Downing Street to New Delhi as governments have asked banks and institutions to enhance cybersecurity.
In that light, the National Institute of Electronics and Information Technology (NIELIT), under the Ministry of Electronics and Information Technology (MeitY), launched CYBER KUSHTI 2026, a national-level cybersecurity and AI hackathon is designed to test how well participants can assess, prioritize and defend security decisions rather than simply identify vulnerabilities.
“The most difficult part of security work has shifted. For a generation, the scarce skill was finding the problem. Today, machines generate findings faster than any team can read them. What they cannot yet do reliably is tell us which findings are real, which matter most, and what must be fixed first. That judgment is now the skill our institutions must build, and it is the only thing this competition measures,” said Professor M. M. Tripathi, Director General, NIELIT.
The competition is being conducted with the Information Sharing and Analysis Center (ISAC Foundation) under the National Security Database (NSD), with CERT-In as the Knowledge Partner. Registration is open until September 10 and is free for teams of three comprising students and independent researchers.
CYBER KUSHTI will give every team the same deliberately imperfect security assessment package, containing AI-generated findings, static analysis results, dependency and secrets scans, architecture documents, source code and application logs. Some findings will be false or duplicated, while genuine vulnerabilities may be missing.
Participants must separate signals from noise, identify what is real and decide which issues require immediate attention. They will also be rewarded for correctly rejecting false findings, highlighting the growing importance of human oversight in AI-assisted security.
The hackathon will have three rounds: Akhada on September 15, Dangal on September 24 and the final Kesari on October 9 at the Dr. Ambedkar International Centre in New Delhi. Ten teams will reach the final.
Why Has Focus Shifted on Human-in-the-Loop in Cybersecurity?
In February 2026, Anthropic AI, the creators of Claude family of AI models, announced that Claude Opus 4.6 found and helped validate more than 500 high-severity vulnerabilities in open-source software and found meaningful zero-days in well-tested codebases without specialized scaffolding.
This was the first time the world heard about advanced capability of AI models in cybersecurity assessment.
Then with the restricted launch of Claude Mythos preview, researchers found out that the model can reportedly produce a proof-of-concept exploit for a Windows Kernel vulnerability in just 31 minutes after disclosure.
Then a 2026 ExploitGym benchmark tested AI agents on 898 real-world vulnerabilities and found a median success of 50-70% in finding vulnerabilities.
Recent incidents of OpenAI and Anthropic’s AI agents autonomously hacking third party organizations have further testified to the capabilities of frontier AI.
Also Read: METR Report Says Frontier AI Agents Can Go Rogue Without Human Supervision






