In recent days, a story tailor-made for a cinematic headline has raced across the internet. A new artificial intelligence model was said to have been handed a 1941 German military telegram, worked inside a virtual room and, in about ten hours, cracked a message that had supposedly resisted decryption since the Second World War. The conclusion attached to the story was even more dramatic: if a commercial machine could succeed where the finest minds had failed, the age of secrecy was over.
The accurate version is different. The original report concerned a German radio message from November 1918, encoded using the ADFGVX cipher, not a 1941 Enigma telegram. The model did not smash modern encryption through brute force. It identified a possible keyword in historical material, applied the decryption method and assembled a text that was then checked against independent British naval logs. The result matched the arrival of HMS Canterbury at Sevastopol and the movements of an Allied squadron.
Some will see that correction as taking the air out of the story. That would be a mistake. The real event is less Bollywood but far more relevant to national security. AI did not defeat the mathematics. It defeated friction: the hours required to read old documents, the difficulty of connecting clues scattered across different sources, the effort of writing code, and the human fatigue that sets in after hundreds of failed hypotheses.
That is the change intelligence services, banks, and critical infrastructure operators must understand. For years, an attacker’s strength was measured by the number of cryptographers, developers, and computing hours at its disposal. AI agents are rapidly reducing the cost of that work. An organisation can deploy dozens of agents simultaneously to read documentation, write tools, test configurations, compare versions, and keep working without rest. A capability once reserved for major powers may now be within reach of a criminal syndicate, a small intelligence service, or a private company.
It is important not to turn this into groundless fear. A language model has not made AES-256 easy to crack, nor has it proved that every RSA key can be broken overnight. The line “there is no code that cannot be broken” sounds impressive, but it is not true. Properly implemented modern encryption still rests on extremely difficult mathematical problems. Yet systems are almost never breached at their strongest mathematical core. They are breached at the edges.
At those edges sit an unpatched legacy server, an abandoned software library, a key stored in a file, a weak random number generator, an expired certificate, a reused password, an unencrypted backup, an employee fooled by social engineering or an outside vendor granted excessive access. AI does not need to prove a new theorem. It only needs to find the weakest link quickly and test thousands of variations against it.
This is where the immediate challenge for India lies. The country has built, at unprecedented scale, digital public infrastructure connecting identity, payments, documents, and services. UPI processes billions of transactions, Aadhaar underpins countless interactions with the state, and DigiLocker has brought official records online. Alongside them sit systems used by banks, railways, ports, hospitals, energy companies, and local authorities, built in different eras by different suppliers. India’s advantage is scale. So is its exposure.
When a human attacker must examine each system individually, minor vulnerabilities are sometimes not worth the effort. When an autonomous agent can scan, learn, and adapt, even a small flaw in a district system can become a worthwhile entry point. The flaw is not new; the cost of finding and exploiting it has collapsed. This is the new economics of attack.
There is an opposite danger as well. A model can produce a decryption that sounds plausible even when it is wrong. In intelligence work, a convincing text that fits an analyst’s expectations can be more dangerous than an unreadable one. The historical achievement therefore lay not only in finding the key but also in verifying the result against independent logs. India must demand the same discipline from every AI tool used in intelligence analysis or cyber investigation. A plausible answer is not evidence, and a model’s confidence is no substitute for verification.
The first step should be a national cryptographic inventory. Not a general list of products, but a detailed record of the algorithms, libraries, keys, certificates, and protocols operating across every critical system. It must cover government departments, security agencies, banks, telecommunications companies, energy infrastructure, health systems, and their supply chains. India cannot protect encryption if no one knows where it is deployed or when it should be retired.
The second step is to mandate cryptographic agility. A new system must allow an algorithm, library, or key to be replaced without dismantling the entire product or waiting years for a single vendor. That requirement should be written into government tenders, defence procurement and financial infrastructure regulation. Encryption that cannot be upgraded quickly is technical debt with strategic consequences.
The third step is to begin an orderly transition to quantum-resistant encryption now. AI and quantum computing are different threats. AI accelerates the search for existing errors and weaknesses, while a sufficiently powerful quantum computer may one day undermine some of the public key algorithms on which the internet relies. The first post-quantum cryptography standards already exist, but a national migration is not a weekend software update. It requires years of testing, phased integration, and backward compatibility.
India has already invested in research infrastructure through the National Quantum Mission. It must now connect that research to systems in the field. Banks, telecom companies, and government bodies should test hybrid solutions that combine existing protections with post-quantum algorithms. Yet even a quantum-resistant algorithm will fail if its key is left exposed or the implementation contains a flaw. There is no substitute for sound key management, separation of privileges, and vendor oversight.
The fourth step is to turn those same AI agents towards defence. Testing teams should deploy them against legacy code, configuration repositories, authentication systems, and backups inside controlled environments and under human supervision. The purpose is not to stage an impressive conference demonstration but to find hard-coded keys, weak encryption, excessive permissions, and anomalous usage patterns before an adversary does. India can build a defensive ecosystem in which CERT-In, financial regulators, security agencies, IITs, and start-ups share methods and findings without exposing sensitive information.
India must also address data that has already been collected. Adversaries do not have to decrypt protected traffic in real time. They can store it and wait for a better tool, a stolen key, or a future quantum computer. Every class of information should therefore have a defined secrecy lifetime; unnecessary data should be deleted; and valuable long-term archives should be re-encrypted. A military secret, biometric record, or medical file does not become less sensitive on the day it crosses a network.
This contest is not purely defensive. The same tools can help India identify weak communications used by an adversary, reveal patterns inside enormous volumes of traffic, and test whether a message is genuine or part of a deception operation. But a short-lived offensive advantage is no excuse for complacency. Every capability India develops will, sooner or later, be available to rival states and hostile organisations. India will retain the lead only if its defences evolve faster than new vulnerabilities are exposed.
The lesson of Bletchley Park was not that machines replace people. The advantage emerged when mathematicians, linguists, engineers, radio operators, and intelligence officers worked as one system. India needs its own version for the AI age: a national cryptographic resilience framework connecting government, the armed forces, academia, and industry, and measuring preparedness by the time required to detect and replace a weakness, not by the number of presentations and committees.
The story of the historical cipher is not an obituary for encryption. It is a warning against passive secrecy: the assumption that what was difficult yesterday will remain difficult tomorrow. In a world of autonomous agents, every forgotten clue, every old file, and every lazy design decision can become part of a fast, inexpensive attack. India must lead this shift, take control of the key, and turn these capabilities to its advantage, especially because its rivals are already using them.
