THE POLICY EDGE
Policy Bites

11 August 2026

RBI Governor Sets Governance Priorities for Banks Using AI

Banks should maintain inventories of AI systems, make boards accountable for their use and preserve human oversight over decisions affecting customers, RBI Governor Sanjay Malhotra said at FIBAC 2026

Listen to the article
Policy Bites image

Key Details

The RBI Governor’s address is a policy signal rather than a new regulatory direction. It explains how the RBI expects banks to approach AI while its draft Model Risk Management guidelines and the recommendations of the FREE-AI Committee shape the emerging framework.

Banks were asked to treat five areas as immediate priorities:

  1. Maintain a complete inventory of AI systems, including tools embedded in vendor products.

  2. Adopt board-approved AI governance policies with clear accountability for outcomes.

  3. Explain AI-driven decisions that materially affect customers, particularly in lending and fraud cases.

  4. Red-team and stress-test systems before deployment and periodically thereafter.

  5. Preserve human oversight wherever errors could harm customers or financial stability.


RBI Sees AI as a Banking Capability, Not Just a Technology Project

The Governor presents AI as a change in how banks assess risk, serve customers, price capital and manage operations — not simply another technology investment. AI governance should therefore form part of a bank’s business and risk strategy.

Potential applications include alternative-data credit assessment, fraud detection, compliance, liquidity forecasting and customer service. Voice-based interfaces in Indian languages could widen access, while early-warning models could identify borrowers approaching financial stress.

RBI nevertheless leaves the pace and choice of adoption to individual banks, based on their customers, risk appetite and capacity to govern the technology.


Accountability Cannot Be Transferred to an Algorithm

AI embedded in lending, fraud detection or market decisions creates risks around explainability, bias and concentration. Customers may not understand why credit was refused or a transaction blocked, while dependence on common models or vendors could turn an institutional weakness into a system-wide vulnerability.

The central principle is that responsibility remains with the bank. “The model decided” cannot substitute for an explanation to a customer, auditor or regulator.

Banks therefore need to:

  • identify where AI is used;

  • explain material decisions;

  • retain human intervention and override;

  • audit models and external providers; and

  • maintain the ability to replace vendors or models without disrupting critical services.


Outsourcing AI Does Not Outsource Responsibility

Smaller banks may rely on external AI providers rather than develop models themselves. RBI accepts this approach but expects contracts to provide audit rights, explainability and credible exit arrangements.

Banks must also address data governance and cybersecurity. Compliance with the Digital Personal Data Protection Act is described as a minimum safeguard, while AI systems must be protected against data poisoning, model manipulation and adversarial inputs designed to defeat controls.


Regulation Will Be Principles-Based and Proportionate

The RBI intends to avoid a single rigid framework for every institution. A large bank operating proprietary models and a smaller bank using an off-the-shelf vendor product may present different levels of risk and require different controls.

Its approach will instead be:

  • principles-based, focusing on accountability and outcomes;

  • proportionate to the size and complexity of the institution and its AI use;

  • consultative, allowing regulation to evolve with evidence and technology; and

  • supervisory, with attention to how systems operate in practice.

The RBI will continue to provide a regulatory sandbox for testing new applications and support shared fraud-detection infrastructure such as MuleHunter and the proposed Digital Payments Intelligence Platform.


What Is AI Red-Teaming?

Red-teaming involves deliberately testing an AI system for weaknesses before it causes harm. Specialist teams simulate misuse, biased outcomes, misleading inputs, cyberattacks and unexpected operating conditions to see whether the model fails or can be manipulated. For banks, this could include testing whether an AI system incorrectly rejects borrowers, misses fraudulent transactions or reveals customer information.


Policy Relevance

  • Board accountability becomes central: AI adoption is moving from the technology department to the institution’s governance and risk framework.

  • Explainability becomes a customer-protection issue: Banks may need to provide intelligible reasons for automated lending and fraud decisions.

  • Third-party risk extends to models: Outsourcing AI does not outsource regulatory responsibility.

  • Common dependencies create systemic exposure: Heavy reliance on a few vendors or foundation models could transmit errors across institutions.

  • Financial inclusion depends on model design: Alternative data may widen access to credit, but biased or poorly tested models could reproduce existing exclusion.

  • Supervision will look beyond formal policies: Inventories, testing records, override mechanisms and actual customer outcomes are likely to become important evidence of responsible deployment.


Relevant Question for Policy Stakeholders: How should banks demonstrate that AI-based lending and fraud decisions are explainable, contestable and free from unfair bias without losing the speed and efficiency the technology offers?



Follow the Full Address Here: Winning in the AI Era: The New Playbook for Indian Banks

Rethinking Public Policy Through Insight | Inquiry | Impact

Opinion • Grassroots Voices • Policymakers Perspectives • Expert Analysis • Policy Briefs