top of page
Search

RBI Draft AI Rules Hold Banks and NBFCs Responsible for All AI-Driven Decisions

The Reserve Bank of India (RBI) has proposed a comprehensive framework to regulate the use of artificial intelligence (AI), machine learning (ML), and automated decision-making systems in the financial sector, making banks and non-banking financial companies (NBFCs) fully accountable for outcomes generated by such technologies.


In its draft Guidance on Regulatory Principles for Model Risk Management, 2026, the RBI has clarified that regulated entities cannot avoid responsibility for faulty decisions, customer harm, or regulatory violations by blaming third-party vendors or AI systems. The proposed rules apply irrespective of whether the models are developed internally or procured from external technology providers.


The draft requires all regulated entities to adopt a Board-approved Model Risk Management Framework covering the entire lifecycle of models, including development, validation, deployment, monitoring, modification, and retirement. The framework will apply to banks, NBFCs, co-operative banks, payment banks, asset reconstruction companies, and credit information companies.


Significantly, the RBI has expanded the definition of a “model” to include not only AI and machine learning tools but also algorithms, analytics systems, rule-based decision tools, applications, and spreadsheets that materially influence business decisions.


The proposed framework mandates independent validation and continuous monitoring of third-party models. Financial institutions must also assess risks such as AI hallucinations, biased outcomes, data drift, adversarial attacks, and cybersecurity vulnerabilities.


The RBI has further proposed mandatory human oversight mechanisms, including override controls and emergency “kill switches.” Public comments on the draft have been invited until July 24, 2026.

 
 
 

Recent Posts

See All

Comments


bottom of page