India’s central bank did something unusual with AI regulation: rather than waiting for problems and then restricting, it commissioned a framework designed to enable adoption while managing risk. The result is one of the more considered pieces of financial AI policy anywhere, and it has received almost no coverage outside legal and consulting circles.
What FREE-AI Is
FREE-AI stands for Framework for Responsible and Ethical Enablement of Artificial Intelligence. It is the report of a committee constituted by the Reserve Bank of India to recommend how AI should be governed in the Indian financial sector.
| Item | Detail |
|---|---|
| Announced | 6 December 2024, via the Statement on Developmental and Regulatory Policies |
| Committee constituted | 26 December 2024 |
| Chair | Professor Pushpak Bhattacharyya, IIT Bombay |
| Report released | 13 August 2025 |
| Consultation | Over 100 stakeholders — banks, fintechs, academics, technology firms |
| Output | 7 Sutras and 26 recommendations across 6 strategic pillars |
The word “enablement” in the title is deliberate. The framing throughout is that AI adoption should be encouraged, with guardrails, rather than constrained by default.
The Seven Sutras
The committee distilled its principles into seven foundational themes:
| Principle | What it means in practice |
|---|---|
| Trust | Public confidence is the precondition for adoption, not a by-product |
| Transparency | Disclosure about where and how AI is used |
| Accountability | Responsibility for outcomes stays with the regulated entity |
| Fairness | Models must not produce discriminatory outcomes |
| Inclusivity | AI should widen access, including through multilingual and multimodal tools |
| Explainability | Decisions affecting customers must be capable of being explained |
| Sustainability | Resource and environmental considerations in AI deployment |
Two of these carry particular operational weight. Accountability means a bank cannot deflect responsibility to a vendor whose model it deployed — institutions are expected to validate third-party models as rigorously as their own, with contractual disclosure requirements. Explainability makes explainable AI a compliance requirement rather than a technical preference.
The Two-Pronged Regulatory Approach
Rather than proposing a single new AI regulation, the report recommends working on two tracks simultaneously:
Track one — amend existing regulations. Annexure IV of the report suggests expanding seven existing RBI master directions to bring AI within their scope. Those master directions cover cybersecurity, digital lending, customer service, fraud detection, IT governance and outsourcing of IT services.
The logic is practical: institutions already comply with these directions. Extending them to address AI is faster and less disruptive than building a parallel regime.
Track two — a new principles-based framework. A dedicated set of principles for developing AI-specific regulation over time, allowing the approach to adapt as the technology moves.
Who It Applies To
Scope is deliberately broad:
- All RBI-regulated entities — banks, NBFCs, payment system operators and others
- Their AI supply chain — fintech partners, data analytics firms, RegTech providers, cloud platforms and AI vendors that design or operate models used by regulated entities
That second category is the significant one. A vendor selling a credit model to an NBFC is inside the framework’s reach through the institution’s obligations, even though the vendor is not itself regulated by the RBI.
The framework also spans the full AI lifecycle — design, development, deployment, monitoring and retirement — rather than applying only at the point of use.
Cross-Regulator Coordination
The report envisages coordination among India’s financial regulators — RBI, SEBI, IRDAI and PFRDA — to harmonise AI oversight and share risk intelligence, avoiding a fragmented position where the same model faces different expectations depending on which product it touches.
It also proposes a National Repository of Audited AI Models, intended to build shared assurance infrastructure rather than requiring every institution to validate common models independently.
What Institutions Are Expected to Build
| Element | Purpose |
|---|---|
| Board-approved AI policy | Governance from the top rather than a technology-team decision |
| Model inventory | A register of every AI model in use, including vendor models |
| Validation processes | Independent testing before deployment |
| Ongoing monitoring | Detecting drift and degradation in production |
| Disclosure standards | Telling customers where AI affects them |
| Internal audit coverage | Assurance over the AI estate |
| Capacity building | Skills to oversee models the institution deploys |
Commentary following the report suggested this represents significant investment and operational change for many institutions, particularly smaller NBFCs that have adopted vendor AI without corresponding governance.
Where Things Stand
The FREE-AI report is a committee report with recommendations, not itself binding regulation. As of August 2026, the RBI is reported to be considering whether to issue comprehensive AI guidelines for banks and NBFCs covering governance, model risk, data safeguards and human oversight — which would represent a shift from issue-specific requirements to a broader standard.
Separately, the RBI’s Financial Stability Report noted that major banks and NBFCs identified AI-enabled cyber threats as the single biggest cyber risk facing them over the following twelve months — a finding that has sharpened attention on the security dimension. See AI Fraud Detection in Banking.
Why This Matters Beyond Compliance
For a retail customer, the framework’s practical effect is that decisions affecting you should become explainable and contestable — an institution using a model to decline your loan is expected to be able to say why.
For anyone working in or building for BFSI, it sets the direction of travel. Model inventories, validation evidence and audit trails are moving from good practice to expected practice, and vendor contracts are expected to carry disclosure obligations they historically did not.
Key Takeaways
- FREE-AI = Framework for Responsible and Ethical Enablement of Artificial Intelligence
- Committee chaired by Prof. Pushpak Bhattacharyya, IIT Bombay; report released 13 August 2025
- 7 Sutras, 26 recommendations, 6 strategic pillars, from 100+ stakeholder consultation
- Two-pronged: amend 7 existing master directions plus a new principles-based framework
- Applies to regulated entities and their AI vendors and cloud providers
- Accountability stays with the institution, including for third-party models
- Proposes cross-regulator coordination and a National Repository of Audited AI Models
- It is a recommendation report, not binding regulation — RBI is weighing formal guidelines
Frequently Asked Questions (FAQ)
Q: What is the RBI FREE-AI framework?
FREE-AI stands for Framework for Responsible and Ethical Enablement of Artificial Intelligence. It is the report of an RBI-constituted committee recommending how AI should be governed in India’s financial sector, released on 13 August 2025 with seven principles and 26 recommendations across six pillars.
Q: Who chaired the FREE-AI committee?
Professor Pushpak Bhattacharyya of IIT Bombay. The committee was announced in the RBI’s Statement on Developmental and Regulatory Policies on 6 December 2024 and constituted later that month.
Q: Is FREE-AI legally binding on banks?
Not in itself — it is a committee report containing recommendations. As of August 2026 the RBI is reported to be considering comprehensive AI guidelines for banks and NBFCs, which would be binding. Verify the current position on rbi.org.in.
Q: What are the seven Sutras of FREE-AI?
The committee distilled its principles into seven foundational themes covering trust, transparency, accountability, fairness, inclusivity, explainability and sustainability. Accountability and explainability carry the most direct operational consequences for institutions.
Q: Does FREE-AI apply to fintech companies and AI vendors?
Its reach extends to them through the regulated entity’s obligations. Fintech partners, analytics firms, RegTech providers, cloud platforms and AI vendors whose models are used by regulated entities fall within scope, and institutions are expected to validate vendor models as rigorously as their own.
Q: What is the National Repository of Audited AI Models?
A proposal in the report for shared assurance infrastructure, so that commonly used models can be independently audited once rather than every institution validating them separately. It is a recommendation rather than an existing facility.
Q: How does FREE-AI affect me as a bank customer?
Its practical intent is that decisions affecting you become explainable and contestable. An institution using a model to decline a loan or flag a transaction should be able to explain the basis, and should disclose where AI is being used.
Q: Do SEBI and IRDAI have similar AI frameworks?
The FREE-AI report envisages coordination among RBI, SEBI, IRDAI and PFRDA to harmonise oversight and avoid fragmentation. Each regulator’s own position continues to develop, so check the relevant regulator directly for products outside RBI’s remit.
Related Reading: