There is no single RBI regulation governing artificial intelligence. What exists is a committee report with recommendations, several existing master directions that partly apply, and a signalled intention to do more. For institutions deciding what to build, that ambiguity is itself the planning problem.
Where Things Stand
| Instrument | Status |
|---|---|
| FREE-AI committee report | Released 13 August 2025 — recommendations, not binding |
| Existing master directions | Binding, and apply to AI indirectly through cybersecurity, outsourcing, digital lending and IT governance |
| Comprehensive AI guidelines | Under consideration as of August 2026 |
The practical position: institutions are already subject to obligations that reach AI through existing directions, while a dedicated framework is being weighed.
What Already Binds You
This is frequently missed. Several existing master directions apply to AI systems without mentioning AI:
| Direction area | How it reaches AI |
|---|---|
| Outsourcing of IT services | A vendor AI model is outsourced IT — due diligence and accountability apply |
| IT governance | Covers systems making or supporting decisions |
| Cybersecurity | Applies to AI systems as to any other technology |
| Digital lending | Governs automated credit decisioning and disclosure |
| Customer service | Applies to AI-driven customer interaction |
| Fraud risk management | Covers detection systems including model-based ones |
An institution treating AI as unregulated because no AI-specific rule exists has misread the position. The outsourcing direction in particular already places obligations on any firm using a vendor’s credit model.
The FREE-AI report proposes expanding seven existing master directions to address AI explicitly — the same instruments listed above. The logic is that extending familiar directions is faster and less disruptive than a parallel regime.
What Comprehensive Guidelines Would Likely Cover
Based on the FREE-AI recommendations and reported direction of travel, likely areas:
- Governance — board-approved AI policy, named accountability, committee oversight
- Model risk — inventory, independent validation, ongoing monitoring
- Data — quality, provenance, protection, purpose limitation
- Human oversight — where a person must remain in the decision
- Transparency — disclosing to customers where AI affects them
- Fairness — testing for and addressing discriminatory outcomes
- Third-party risk — vendor due diligence and contractual requirements
- Incident handling — what happens when a model fails
None of this would be surprising to an institution that has read the FREE-AI report. That is deliberate — the report functions as advance notice of direction.
What to Build Now
Regardless of whether formal guidelines arrive, these are defensible and largely required by existing directions:
| Priority | Action |
|---|---|
| First | Build a complete model inventory, including vendor and embedded models |
| First | Tier models by customer impact |
| Second | Independent validation for high-impact models |
| Second | Monitoring that would actually detect drift |
| Second | Reason codes for adverse customer decisions |
| Third | Board-approved AI policy |
| Third | Vendor contract review — disclosure and change notification rights |
| Third | Fairness testing on outcomes |
The inventory comes first because nothing else is possible without it. An institution that cannot list its models cannot validate, monitor or govern them, and cannot answer a supervisor who asks.
Where Institutions Are Typically Behind
- Shadow models. Spreadsheets with embedded logic, vendor features switched on without review, team-built scripts. They make decisions and appear nowhere.
- Vendor contracts. Most predate AI concerns and lack disclosure rights, change notification and audit access.
- Monitoring. Frequently limited to uptime rather than model performance.
- Fairness testing. Often absent, sometimes because the institution does not collect the attributes needed to test.
- Oversight capability. Boards asked to govern models few members can evaluate.
The second is the most actionable. Contract renewal is a natural point to insert change notification and disclosure clauses, and it costs little compared with retrofitting governance later.
Cross-Regulator Direction
The FREE-AI report envisages coordination among RBI, SEBI, IRDAI and PFRDA to harmonise AI oversight. For institutions spanning products — a bank distributing insurance and mutual funds — this matters, since a single model may touch multiple regulatory perimeters.
Key Takeaways
- No single AI regulation exists — but existing directions already reach AI
- Outsourcing, IT governance, cybersecurity and digital lending directions apply today
- FREE-AI proposes expanding seven existing master directions
- Comprehensive guidelines are under consideration as of August 2026
- Build the model inventory first — nothing else works without it
- Tier by customer impact, not technical complexity
- Vendor contracts are the common weak point — fix at renewal
- The FREE-AI report functions as advance notice of direction
Frequently Asked Questions (FAQ)
Q: Are there RBI regulations on AI for banks?
There is no single dedicated AI regulation. The FREE-AI committee report of August 2025 contains recommendations rather than binding rules, but several existing master directions — outsourcing, IT governance, cybersecurity, digital lending — already apply to AI systems. As of August 2026 RBI is weighing comprehensive guidelines.
Q: Is AI currently unregulated in Indian banking?
No. Treating AI as unregulated because no AI-specific rule exists misreads the position. The outsourcing direction already places obligations on institutions using vendor models, and the digital lending direction governs automated credit decisioning.
Q: What would comprehensive AI guidelines likely cover?
Based on the FREE-AI recommendations, likely areas include governance and board accountability, model inventory and validation, data quality and protection, human oversight, customer disclosure, fairness testing, third-party risk and incident handling.
Q: What should an NBFC do first?
Build a complete model inventory including vendor and embedded models, then tier them by customer impact. Nothing else is possible without knowing what models exist — an institution that cannot list its models cannot validate, monitor or govern them.
Q: Do these expectations apply to models bought from vendors?
Yes. Accountability stays with the regulated entity regardless of who built the model, which is why institutions are expected to validate third-party models rather than relying on vendor assurance. Contractual disclosure and change notification rights are the practical mechanism.
Q: Where are institutions typically weakest?
Shadow models that appear in no register, vendor contracts predating AI concerns and lacking disclosure rights, monitoring limited to uptime rather than model performance, absent fairness testing, and boards asked to oversee models they cannot technically evaluate.
Q: Will SEBI and IRDAI issue their own AI rules?
The FREE-AI report envisages coordination among RBI, SEBI, IRDAI and PFRDA to harmonise oversight. Each regulator’s position continues to develop, so institutions spanning products should check each relevant regulator directly.
Related Reading: