Over the past year, the Reserve Bank of India has given the financial sector a clear sense of how it expects artificial intelligence to be used.
It began in August 2025 with a framework called FREE-AI, which is short for the Framework for Responsible and Ethical Enablement of Artificial Intelligence. It then followed up, in June 2026, with a draft rule on model risk management. Read together, these two documents show where AI governance in Indian finance is heading, and what your institution will be expected to do about it. This post is a plain walk through both. It is written for the people who run risk, compliance and technology inside banks and NBFCs, and for the teams who build AI for them. One note up front: Neulaxy took part in the consultation on the June draft, and we will share what we suggested near the end. We will start with why AI matters so much to finance and what can go wrong with it, then look at where the sector actually stands today, before turning to the framework itself, the draft that follows it and what the two ask of you.
Why the sector wants in
It helps to be clear about why AI matters so much to finance in the first place, because the size of the opportunity is what makes getting the governance right worth the effort. The numbers are large. One widely cited estimate puts AI-related investment across banking, insurance, capital markets and payments at more than eight lakh crore rupees, close to ninety-seven billion dollars, by 2027. Generative AI is expected to grow especially fast, and in the Indian context one estimate suggests it could lift banking operations by up to forty-six percent.
Behind the headline numbers sit concrete uses. AI can widen access to credit by scoring people who have little formal credit history, using signals such as utility payments, mobile usage and GST filings, which brings first-time and thin-file borrowers into the system. Chatbots can answer routine questions at any hour, and voice-based banking in regional languages can reach people who are not comfortable with English or with text. Early-warning models can flag risk sooner, and AI-based fraud screening can cut losses. One large bank reported a clear drop in wrongly rejected payments after applying AI to the problem.
The report also points to ideas that fit India specifically. It makes the case for home-grown, finance-specific models, including smaller models tuned to a single job, and what it calls Trinity Models built around a language, a task and a domain together, for example Marathi with credit-risk questions for MSME finance. It sees promise in connecting AI with India's digital public infrastructure, such as Aadhaar, UPI and the Account Aggregator system, to make services not only digital but responsive. And it looks ahead to autonomous agents that can break a goal into steps and coordinate with other agents, shifting AI from automating tasks to taking decisions. The upside, in short, is real and broad.
The risks that come with it
Every one of those opportunities carries a matching risk, which is why the framework spends as much effort on caution as on encouragement. The report groups the risks, and it is worth walking through them, because they line up almost one for one against the benefits.
The first is model risk. AI models can be biased, through their training data or their design, and they are often opaque, which makes their decisions hard to explain or to audit. Generative models add the problem of hallucination, where a system produces confident but wrong output. The second is operational risk. Automating a process at scale removes human error, but it can also multiply a single fault across a huge number of transactions, and models can quietly degrade over time through drift if no one is watching. The third is third-party risk. Because most institutions rely on outside vendors and cloud providers for their AI, they inherit dependencies they cannot fully see, along with concentration risk when the whole sector leans on a small number of providers.
Then there is liability. When a decision is probabilistic and hard to explain, it is not always clear who is responsible when it goes wrong: the institution, the model developer or the data provider. There are risks to the wider system too. When many firms use similar models, they can move in the same direction at the same time, a herding effect that can amplify swings in the market. The report recalls the 2010 flash crash, when automated trading briefly wiped out close to a trillion dollars in market value, as a reminder of what untested automation can do under stress.
Cybersecurity cuts both ways. AI can strengthen defence, but it also opens new lines of attack: poisoning the data a model learns from, adversarial inputs and prompt injection that hide instructions inside an ordinary-looking request, and deepfakes that can fool a video KYC check. Alongside these sit familiar concerns about data privacy and the risk that AI quietly works against the interests of the very consumers it is meant to serve. And there is one risk that is easy to miss: the risk of not adopting AI at all, which can leave an institution exposed to sharper competitors and to the fraudsters who are already using it. The aim of the framework is not to remove these risks, which is impossible, but to make them manageable.
| What AI makes possible | The risk that shadows it |
|---|---|
| Credit for thin-file and new-to-credit borrowers | Algorithmic bias that can deepen exclusion |
| Round-the-clock generative AI customer service | Hallucination and answers that cannot be explained |
| Automation of high-volume processes | A single fault multiplied at scale and silent model drift |
| Reliance on external and foundation models | Third-party dependencies and concentration risk |
| Autonomous, goal-seeking agents | Unclear liability and the risk of AI-driven collusion |
| Many firms running similar models | Herding that can amplify stress across the market |
The benefits and the risks in the framework map almost one to one. Governance is what lets an institution capture the first column while holding down the second.
Where Indian finance actually stands today
So the opportunity is real, and so are the risks. The next question is where the sector actually stands today, and the Reserve Bank's surveys give a clear answer. As part of its work, it surveyed more than six hundred supervised entities, ran a deeper survey of seventy-six institutions and followed up with their technology leaders. The picture that came back was clear, and in places sobering.
AI adoption in Indian finance is still early and uneven. Larger public and private banks have started to explore it, mostly through basic rule-based systems and early-stage models. Among smaller institutions the picture thins out quickly. Many urban co-operative banks reported no use of AI at all, adoption among NBFCs was low, and asset reconstruction companies reported none. The reasons were practical rather than philosophical: limited in-house capacity, a weak business case at smaller scale and the cost of the infrastructure involved.
Six numbers from the surveys frame the situation well.
Adoption itself is still thin, with only about one in five supervised entities using or building AI, and none at all among some smaller categories. Yet interest in generative AI is strong, with two in three of the more advanced institutions exploring at least one use case, most of it still experimental and internal for now. The controls have not kept pace. Only about one in three had board-level oversight of AI, only about one in five watched their models for drift, and fewer still kept audit logs of what their systems decided. At the same time, close to eighty-five percent asked the regulator for a clear framework. The demand for rules, in other words, came from the industry itself.
The kind of AI in use tells a similar story. Most of it is still simple.
Simple rule-based models and moderately complex machine-learning models make up most of what is deployed, with only a small share using advanced models. Simpler models are preferred for understandable reasons: they are easier to build, they sit more comfortably with legacy systems, and they are easier to explain and control. That preference matters for governance, because the harder problems the framework and the draft focus on, such as explainability, drift and autonomy, arrive with the more advanced models that most firms have not adopted yet.
When asked what was holding AI back, respondents pointed to a familiar set of constraints.
A shortage of skills and talent led the list, followed by cost, data quality and the wish for regulatory clarity. This is worth holding on to, because it shapes what good policy looks like. A rule that assumes every institution can hire a specialist validation team will not land the same way at a large bank and at a small co-operative bank. We will return to this point when we look at the draft.
The surveys also found real gaps in how AI is governed. Data management was often fragmented, with few dedicated policies for the data used to train models. Tools for detecting bias or monitoring models were used sparingly. Most institutions did not track model drift or run real-time audits, and incident-response mechanisms were rare. Put simply, the appetite for AI is running ahead of the controls around it. Closing that gap is exactly what the FREE-AI framework sets out to do.
The first thing to understand about FREE-AI is the balance at its heart. A framework from a central bank can read like a long list of things you may not do. FREE-AI is not written that way. It sets out to encourage useful innovation and to manage the real risks of AI at the same time, and it treats these two goals as partners rather than opposites. That single choice shapes everything that follows.
Seven principles the RBI calls Sutras
FREE-AI rests on seven principles that the committee calls Sutras. The word sutra means a thread, and the idea is that these principles should run through the whole life of an AI system, from the moment it is designed to the day it is retired. The seven are: trust is the foundation, people first, innovation over restraint, fairness and equity, accountability, understandable by design, and safety, resilience and sustainability.
Most of these read as you would expect from a careful regulator. The one worth remembering is accountability. FREE-AI is direct about it: accountability cannot be handed over to the model or the algorithm. If an AI system gets something wrong, the institution that deployed it owns the outcome. You cannot point to a vendor or to a probabilistic output and treat the matter as closed. Everything else in the framework, from validation to audits to human oversight, exists to make that ownership real.
One framework, two halves
From these principles, FREE-AI builds a single structure with two sides. There are six pillars in all. Three of them are about enabling innovation, namely infrastructure, policy and capacity. The other three are about managing risk, namely governance, protection and assurance. Twenty-six recommendations sit across these pillars. The point of arranging them this way is to show that opening up AI and keeping it safe are meant to move together, not to work against each other.
The enabling side
The enabling half is easy to overlook, and it is more generous than people expect. Under infrastructure, FREE-AI proposes shared resources so that smaller players are not left behind. It suggests a well governed pool of financial-sector data, an AI innovation sandbox offered as a public facility where firms can build and test using shared compute and models, and finance-specific AI models released as public goods, so that a smaller NBFC does not have to force a general-purpose model to fit Indian rules.
Under policy and capacity, it goes further. It proposes dedicated funding to seed this ecosystem, and it suggests a measured approach to liability, where an institution that has followed the expected safeguards is not treated harshly for a genuine first-time mistake, although that patience does not extend to repeated failures or clear negligence. For a regulator, that is a notably supportive stance, and it is a good sign that the enabling half is meant sincerely.
A closer look: the generative AI sandbox
One idea inside the infrastructure pillar is worth pulling out on its own, because it speaks directly to the adoption gap the surveys found. It is a shared generative AI sandbox: a secure, controlled space where banks and fintechs can build, test and validate AI models before anything touches real customers or real data.
Inside a sandbox like this, teams work with synthetic or anonymised data and common model frameworks, on shared compute they would struggle to justify buying on their own. Around that sit the guardrails that make it safe to experiment: real-time monitoring for problems such as bias and hallucination, checks against rules such as AML and KYC, and explainability tools that show how a decision was reached. For a smaller institution without its own AI infrastructure, a facility like this is the difference between experimenting responsibly and not experimenting at all. It is the enabling half of the framework made concrete.
The risk side
The other three pillars are where the framework asks for discipline. Governance expects every regulated entity to put a board-approved AI policy in place, to sort AI use cases by their level of risk and to oversee models across their whole life. Protection is about the people on the other side of the technology. Customers should be told when they are dealing with AI and given the option to reach a human, and firms are expected to test their systems, guard against misuse and report incidents in an open, low-blame way so that the whole sector can learn.
Then comes assurance, which is where good intentions turn into evidence, and where a lot of our own work sits. Assurance asks for a complete inventory of the AI in use, because you cannot govern what you cannot see. It asks for independent audits, sized to the risk of each system, with outside audits expected on the highest-risk use cases. It asks that institutions disclose how they use and govern AI in their annual reports, in the same way they already report on cyber and climate risk. And it points to a shared toolkit that firms can use to check their work. In the framework's own words, assurance is the way trust is kept up over time.
From advice to a draft rule
For its first year, FREE-AI came with an honest caveat. It was advisory. It set out principles and recommendations meant to guide the Reserve Bank's future policy, rather than binding rules with immediate effect. In June 2026, that began to change. The RBI released, for public comment, a draft called the Guidance on Regulatory Principles for Model Risk Management, 2026. Once it is final, it will replace guidance that has been in place since 2002. This matters because India's model-risk rules had stayed broadly the same through the rise of modern AI, and this update brings AI clearly into scope. The draft gives a full chapter to models that use AI and machine learning, including large foundation models.
The heart of the draft is familiar model-risk discipline, now applied to AI. It asks for three lines of defence, with an independent validation function and an independent internal audit function. It asks that models be sorted by risk, with the highest-risk models approved by a committee of the board. It asks for an inventory so complete that no model is used unless it is on the list, and that records are kept for years after a model is retired. And it asks that every model be independently validated, both before and after it goes live, with the findings taken to the board committee within a set time.
Two parts of the draft matter most for anyone who relies on someone else's model. The first is that a third-party model must still be validated independently by the institution using it, whatever assurance the vendor has already given. In plain terms, you cannot simply inherit your supplier's sign-off. The second is that contracts are expected to give the institution, and its supervisor, the right to examine the model, either directly or through outside experts. The chapter on AI then reads like a practical checklist for the risks that generative systems bring.
| The draft asks you to control | What it means |
|---|---|
| Explainability | Set thresholds per model, with a higher bar for decisions that affect customers. |
| Hallucination | Design and system controls on generative outputs that feed into decisions. |
| Bias and fairness | Test for unfair outcomes and fix them by recalibrating or redesigning. |
| Robustness | Check behaviour under edge cases, unusual inputs and adversarial conditions. |
| Red teaming | Structured challenge, especially for customer-facing and generative models. |
| Prompt injection | Controls at the interface against injection and manipulated inputs. |
| Human oversight | Override, pause and stop controls over decisions the model makes on its own. |
| Drift and records | Watch for data and concept drift, and document for traceability and audit. |
Read alongside FREE-AI's assurance pillar, the direction is clear: principles in 2025, a draft rule in 2026, and, on the RBI's own signal, more to come.
Where the draft meets reality, and what we suggested
We welcomed the draft and shared our comments with the Reserve Bank through its public consultation. Our support is genuine. The lifecycle approach, the extension of independent validation to third-party and AI models, and the clear line that accountability cannot be passed to a vendor or an algorithm are all sensible and timely. Our comments were about making the rule easy to apply in practice, especially for smaller institutions and for the large models that many firms now depend on. Six points, in short.
| What the draft asks | Where it is hard to apply | What we suggested |
|---|---|---|
| Validation independent of building and using the model | A truly independent in-house team is not realistic for many smaller banks and NBFCs | Confirm that a capable external validator can meet the requirement, and allow shared validation services for smaller entities |
| One set of rules across many types of institution | There is no timeline or lighter path, so smaller entities cannot do everything at once | A phased schedule, with larger institutions and higher-risk models first, and a clear map of what is expected at each level |
| A broad definition of what counts as a model | It can sweep in even a spreadsheet once it affects a decision, which risks very large, unfocused inventories | Simple guidance on what is material, so effort goes where the real risk sits |
| The right to examine third-party and foundation models | Large global model providers rarely grant that level of access in practice | An independent assessment of widely used models that many institutions can rely on, alongside their own checks |
| Each institution sets its own explainability thresholds | Different firms setting different bars leads to uneven treatment of similar models | A shared reference for explainability levels, matched to how sensitive the use case is |
| Oversight staff who can properly challenge a model | People with these skills are in short supply across the sector | Recognised training and benchmarks for validators and boards, and easier access to independent validation |
Shared with the Reserve Bank through its public consultation. The comments support the draft and are aimed at making it easier to apply and more consistent in practice.
The common thread across all six is simple. The draft is right to insist that institutions cannot outsource accountability. For its backbone, independent validation, to be real rather than a box-ticking exercise, the market needs capable, independent validators that even smaller institutions can reach. That is not a complaint about the framework. It is the same logic, carried one step further.
What this means for you
If you run AI inside a regulated institution, the practical takeaway is straightforward. AI governance is moving from a slide in a strategy deck to something you will need to show, with evidence. Independent validation, of your own models and of the third-party and foundation models you rely on, is becoming an expectation rather than a nice-to-have. The institutions that are handling this well are not waiting for the final version to be published. They are building an inventory and ranking it by risk. They are setting up validation that is genuinely independent, whether in-house or brought in. They are testing their customer-facing and generative systems. They are adding human oversight and clear stop controls to anything that acts on its own. And they are keeping proper records as they go, so that when a supervisor or an auditor asks, the answer is a document rather than a scramble.
None of this is glamorous. It is inventories, validation reports, test findings and evidence packs. It is the quiet, load-bearing work that sits underneath AI a regulated institution can put its name behind. Both documents are worth reading in full, and they are short enough to be useful: the FREE-AI report and the model risk draft. In regulated finance, trust is not something you add at the end. It is the product.
The AI is already making decisions that matter. The question the Reserve Bank has now put to every regulated entity is whether someone can independently stand behind it. That is the work worth doing.
References
- Reserve Bank of India. Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector. August 2025. The survey statistics and India-specific figures in this article are drawn from this report.
- Reserve Bank of India. Draft Guidance on Regulatory Principles for Model Risk Management, 2026. Released for public consultation on 24 June 2026.
- World Economic Forum. Artificial Intelligence in Financial Services, 2025. Source of the global investment estimate cited in the FREE-AI report.
Disclaimer
The views expressed in this article are personal and do not necessarily reflect those of any organisation the author is associated with. This article is provided for general information only. It summarises and interprets publicly available documents, including the Reserve Bank of India's FREE-AI report and its draft guidance on model risk management, and it does not constitute legal, regulatory or professional advice. Readers should refer to the original documents and seek appropriate professional guidance before acting on anything discussed here.
Facing a similar challenge?
Let's talk about how applied AI can move the needle for your business.

Founder and CEO of Neulaxy, with over two decades building large-scale, security-critical technology across banking, telecom, education and healthcare. Now focused on practical, secure, production-grade AI.
More about Neulaxy →AI Governance & Assurance
Independent validation, bias and explainability testing, and audit-ready evidence for regulated AI.
Explore AI Governance & Assurance


