RBI Weighs Comprehensive AI Rules for Banks

The Reserve Bank of India (RBI) is considering a comprehensive regulatory framework governing the use of artificial intelligence (AI) by banks and non-banking financial companies (NBFCs) as financial institutions rapidly expand the technology across lending, customer service, fraud detection, compliance and other business functions.

The proposed approach would represent a shift from RBI’s existing issue-specific requirements towards a broader set of AI governance standards applicable to regulated entities. According to the report, discussions are underway within the central bank on whether dedicated AI guidelines are required and, if introduced, what areas they should cover. No comprehensive AI guidelines have yet been formally issued by RBI, and the deliberations remain at a discussion stage.

The initiative assumes significance as banks and NBFCs increasingly rely on AI and sophisticated analytical models for business decisions. RBI has already expressed concerns about the additional risks created when financial institutions depend heavily on models, including internally developed systems as well as those supplied by third parties.

One important regulatory development preceding these discussions is RBI’s draft framework on model risk management, released in June 2026. The draft envisages stronger governance of models used by regulated entities and stresses human oversight, particularly where AI models influence important decisions. It also envisages mechanisms that would allow institutions to override, suspend or deactivate models, including appropriate “kill-switch” arrangements.

The broader AI framework being considered could address critical issues such as the use of customer data for training AI models, data storage and localisation, third-party AI platforms, model safeguards, decision-making controls and regulatory reporting. These areas are particularly important where AI outputs can directly affect customers or regulatory compliance.

For example, an AI model used for credit decisions could potentially generate incorrect or biased recommendations if its underlying data, design or validation process is inadequate. Similarly, errors or “hallucinations” in AI systems used for regulatory reporting or compliance could expose institutions to consumer, operational and regulatory risks. The emerging framework is therefore expected to place considerable emphasis on governance, accountability and appropriate controls around high-impact AI applications.

The regulatory discussions also build upon recommendations made by RBI’s Committee on Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI). The committee submitted its report in August 2025, recommending measures including financial sector-specific AI models and an AI policy framework to guide responsible adoption of the technology.

Cybersecurity is another major concern. According to an RBI survey cited in its June Financial Stability Report, AI-enabled cyber threats were identified by major banks and NBFCs as the biggest cyber risk facing their businesses over the following 12 months.

RBI has already permitted AI in specific banking applications. For instance, its KYC framework allows appropriate AI technology to strengthen Video-based Customer Identification Process (V-CIP) systems, including areas such as face liveness, spoof detection and face matching, while keeping ultimate responsibility for customer identification with the regulated entity.

A comprehensive AI framework could therefore become an important next stage in India’s banking regulation, attempting to balance technological innovation with model risk management, cybersecurity, customer protection, data governance and human accountability as AI becomes more deeply embedded in financial services.

Want to deepen your expertise beyond today’s news?

Popular from web