credit-risk modelling;
personalized product recommendations;
customer-service assistants;
compliance and surveillance;
portfolio and risk analytics;
software-development assistance; and
multi-step AI agents capable of coordinating complex workflows.
Agentic AI represents a particularly important emerging area. Instead of merely generating a response, an AI agent can potentially plan a sequence of actions, interact with multiple systems and execute parts of a business process.
However, fully autonomous deployment in high-risk areas such as lending, payments or investment decision-making raises significantly greater governance concerns. Consequently, human oversight and control are likely to remain particularly important where AI affects customers or material financial decisions.
2. AI-Powered Fraud Detection
Fraud detection is one of the clearest financial-sector applications of machine learning.
Traditional fraud systems rely heavily on predefined rules such as transaction limits, unusual locations or known suspicious patterns. Machine-learning systems can supplement these controls by analysing large volumes of transactions and identifying combinations of behaviour that conventional rules may overlook.
NPCI-hosted research on conversational payments notes the use of machine-learning algorithms by financial service providers to analyse transaction behaviour and identify potentially fraudulent activity.
The RBI ecosystem is also experimenting directly with AI-based fraud controls.
A notable example is MuleHunter.AI, an AI/ML-based system developed by the Reserve Bank Innovation Hub (RBIH), an RBI subsidiary, to improve identification of suspected mule bank accounts.
RBI reported that pilots involving two large public-sector banks produced encouraging results and encouraged other banks to collaborate with RBIH.
This is an important signal: regulators are not merely evaluating AI from a compliance perspective; they are also exploring how AI can strengthen financial-system resilience.
RBI's FREE-AI Framework
In December 2024, RBI constituted an external committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence, commonly known as FREE-AI.
The committee's report was published in August 2025. RBI's official reports listing identifies the document as the "FREE-AI Committee Report – Framework for Responsible and Ethical Enablement of Artificial Intelligence."
An important distinction is necessary.
FREE-AI is a committee framework containing recommendations; it should not be treated as though every recommendation is already a binding RBI Master Direction.
Nevertheless, the report provides an important indication of RBI's policy direction and has become an important reference point for responsible AI governance in Indian financial services.
The framework contains seven guiding Sutras and 26 recommendations organised under six strategic pillars.
The Seven Sutras of FREE-AI
Sutra | Governance Meaning |
|---|
Trust is the Foundation | AI adoption should preserve confidence in financial institutions and their decision-making systems. |
People First | AI should augment human capabilities while protecting customer interests and maintaining appropriate human oversight. |
Innovation over Restraint | Regulation should enable responsible experimentation rather than unnecessarily prevent technological innovation. |
Fairness and Equity | AI outcomes should be monitored for discrimination, bias and unequal treatment. |
Accountability | Responsibility ultimately remains with the institution deploying or using the AI system. |
Understandable by Design | AI systems should provide sufficient transparency and explainability for their intended use and risk level. |
Safety, Resilience and Sustainability | AI systems should remain secure and resilient against operational, infrastructural and cyber risks while considering sustainability. |
These are the official seven Sutras described by the FREE-AI Committee.
The report then converts these principles into six strategic pillars.
Innovation Enablement
Infrastructure
Policy
Capacity
Risk Mitigation
Governance
Protection
Assurance
Among other measures, the committee recommends stronger AI governance, institutional capacity building, AI-specific consumer protections, cybersecurity safeguards, appropriate model controls, incident reporting and clearer accountability across the AI lifecycle.
The Bigger 2026 Development: RBI's Model Risk Management Proposal
FREE-AI provides the policy vision, but another RBI development may ultimately have a more direct operational impact on banks and NBFCs.
On 24 June 2026, RBI released its draft Guidance on Regulatory Principles for Model Risk Management for public consultation.
The proposed guidance applies broadly across RBI-regulated institutions, including commercial banks, small finance banks, payments banks, regional rural banks, co-operative banks, All India Financial Institutions, NBFCs, Asset Reconstruction Companies and Credit Information Companies.
Crucially, the guidance applies not only to traditional financial models but also to:
RBI invited comments until 24 July 2026. As of August 2026, RBI continues to identify the instrument as draft guidance rather than a final direction.
What the Draft Model Risk Framework Could Mean
The proposal moves AI governance beyond broad ethical principles and towards formal model lifecycle management.
Key themes include:
Board-Level Model Governance
Regulated entities would establish a comprehensive Model Risk Management Framework (MRMF) aligned with the nature, size and complexity of their model usage.
This elevates model risk from a technical issue into an enterprise governance responsibility.
Enterprise Model Inventory
Financial institutions would need structured visibility over the models being used across the organisation.
For AI governance, such an inventory can capture information including:
This should be described as an AI or model inventory, not "AI Kosh."
AI Kosh is associated with the broader IndiaAI Mission and should not be confused with an institution's internal model-risk register.
Independent Model Validation
Development teams should not be the sole judges of whether their models are safe to deploy.
Independent validation is therefore central to the proposed framework.
Depending on the model, this could involve testing:
Continuous Monitoring
Validation does not end when a model reaches production.
Financial behaviour changes. Customer populations change. Fraud patterns evolve. Data pipelines change.
An AI model that performed well during development can therefore deteriorate over time.
Institutions need mechanisms for detecting:
Human Oversight
Human oversight becomes particularly important where AI systems participate in automated decision-making.
RBI's 2026 draft specifically proposes human oversight for AI models involved in automated decisions.
The objective is not necessarily to require a person to manually approve every AI output. Instead, institutions should retain meaningful mechanisms to review, challenge, override or stop consequential AI decisions where appropriate.
Third-Party AI Does Not Transfer Accountability
Banks increasingly consume AI through vendors, APIs, cloud platforms, fintech partnerships and externally developed models.
But outsourcing the model does not eliminate model risk.
RBI's proposed framework applies to third-party models as well as internally developed ones and emphasises due diligence, validation and governance of externally sourced models.
This will make AI vendor governance increasingly important.
Institutions may need to understand issues such as:
training-data limitations;
model architecture and intended use;
performance benchmarks;
change-management procedures;
cybersecurity controls;
auditability;
explainability;
subcontractors;
data-processing arrangements; and
contractual rights to obtain sufficient information for validation.
DPDP and AI: The Privacy Layer
Alongside RBI's emerging AI and model-risk architecture sits India's Digital Personal Data Protection Act, 2023.
The Digital Personal Data Protection Rules, 2025 were notified in November 2025. However, implementation is phased rather than immediate.
This distinction is important when discussing compliance in 2026.
Under the government's commencement notification, several institutional provisions became effective first, while many of the Act's substantive provisions dealing with processing, consent, Data Fiduciary obligations and Data Principal rights are scheduled to commence 18 months after publication of the notification.
Therefore, it would be inaccurate to describe the entire DPDP regime as already fully operational in August 2026.
Financial institutions should nevertheless be preparing their technology and governance environments for these requirements.
Purpose-Specific Consent
Section 6 of the DPDP Act provides that where processing relies on consent, the consent must be:
free, specific, informed, unconditional and unambiguous, involving clear affirmative action.
Consent must also relate to a specified purpose and be limited to personal data necessary for that purpose.
This has major implications for AI systems.
Banks should be cautious about assuming that data collected for one purpose can automatically be reused for unrelated AI applications.
For example, customer information collected for a specific operational requirement should not automatically become unrestricted training data for marketing, cross-selling or behavioural modelling.
Whether additional consent is required will depend on the purpose of processing and the applicable lawful basis.
Consent Withdrawal and AI
The DPDP Act also gives individuals the ability to withdraw consent where consent forms the basis of processing.
Following withdrawal, the Data Fiduciary must cease the relevant processing within a reasonable time unless continued processing is required or authorised under the DPDP framework or another applicable Indian law.
For AI systems, this can create difficult engineering questions.
Organisations may need mechanisms for:
removing personal data from future training datasets;
preventing further inference using restricted information;
tracking data lineage;
controlling retraining pipelines; and
determining whether model retraining or techniques such as machine unlearning are appropriate.
However, an important distinction should be maintained:
The DPDP Act does not expressly mandate "machine unlearning" from trained model parameters.
Machine unlearning is better understood as a potential technical response to particular data-governance problems rather than a statutory requirement explicitly imposed by the Act.
Dark Patterns: A Separate but Related Compliance Risk
Manipulative interfaces are another important concern for digital financial services.
Examples include:
making consent rejection unnecessarily difficult;
hiding opt-out mechanisms;
creating misleading urgency;
using confusing button designs; or
steering users towards choices they may not otherwise make.
India already regulates this issue through the Guidelines for Prevention and Regulation of Dark Patterns, 2023, issued by the Central Consumer Protection Authority under the consumer-protection framework. The guidelines apply to platforms, advertisers and sellers and prohibit specified dark-pattern practices.
Dark-pattern regulation should therefore not be described as originating from the DPDP Act.
Nevertheless, the two regimes can intersect.
A consent flow that manipulates a user may create consumer-protection issues while also undermining the quality of consent expected under privacy law.
As a result, UI/UX design is increasingly becoming part of financial-services compliance rather than merely a product-design concern.
An AI Governance Roadmap for Banks and NBFCs
The regulatory direction suggests that financial institutions should begin treating AI governance as part of enterprise risk management.
A practical framework can be built around several capabilities.
1. Maintain an Enterprise AI and Model Inventory
Every material AI system should have an identifiable:
owner;
business purpose;
risk classification;
data source;
validation status;
vendor dependency; and
lifecycle status.
Unknown AI is ungovernable AI.
2. Introduce Risk-Based Classification
A chatbot summarising internal documentation does not necessarily require the same controls as an AI model determining whether a customer receives credit.
Institutions should therefore classify AI systems according to potential consequences.
Higher-risk use cases may require:
3. Build Data Lineage into AI Platforms
Banks should be able to answer:
Where did the data come from?
Why was it collected?
Which models consume it?
Which downstream decisions depend on it?
What happens when that data changes or must no longer be processed?
Without lineage, privacy compliance and model governance become significantly harder.
4. Establish Independent Validation
Model creators, business owners and model validators should have clearly separated responsibilities.
Validation should challenge assumptions rather than merely reproduce development results.
5. Monitor Models After Deployment
Production monitoring should include both technical and business metrics.
Depending on the use case, institutions may monitor:
6. Strengthen Third-Party AI Governance
AI procurement should involve more than technology and commercial teams.
Risk, cybersecurity, legal, privacy, compliance and model-validation functions may also need to participate, particularly for systems that affect customers or material financial decisions.
7. Create AI Incident-Management Procedures
Institutions should determine in advance what happens if an AI system:
produces discriminatory outcomes;
exposes confidential information;
suffers a cyberattack;
generates materially incorrect decisions;
behaves unexpectedly after an update; or
experiences severe model drift.
Escalation, containment, investigation, remediation and governance reporting should be defined before such incidents occur.
From Responsible AI Principles to Model Governance
India's approach to AI in financial services is evolving rapidly, but it is important to distinguish between what is already law, what RBI has recommended and what remains under regulatory consultation.
The FREE-AI Committee Report of August 2025 establishes the policy philosophy: encourage innovation while protecting trust, fairness, accountability, explainability and resilience.
The DPDP Act and Rules establish India's emerging statutory framework for the processing of personal data, although many important provisions remain on a phased implementation timetable.
RBI's June 2026 draft Model Risk Management guidance takes another significant step by translating many of these principles into a proposed governance structure covering model inventories, validation, monitoring, third-party models, AI/ML risks and human oversight.
The direction is therefore becoming clearer.
The question for banks and NBFCs is no longer simply:
"Can AI improve this process?"
Increasingly, institutions must also ask:
"Can we explain it, validate it, monitor it, govern its data, control its vendors, protect the customer and remain accountable when it fails?"
That shift—from AI adoption to AI lifecycle governance—is likely to define the next stage of artificial intelligence in Indian banking.
For financial institutions, responsible AI is therefore not merely an ethical aspiration. It is becoming an integral part of model risk management, privacy engineering, cybersecurity, consumer protection and corporate governance.