The Regulator’s Guardrails
The Reserve Bank of India (RBI) is making it clear that while AI is a powerful tool for progress, it will not be adopted at the cost of financial stability. Speaking at the recent FIBAC 2026 conference, RBI Governor Sanjay Malhotra emphasised that AI is a capability
to be “responsibly harnessed, not merely as a risk to be contained.” The central bank's stance is not about stifling innovation but about building a strong foundation of governance before scaling up. The Governor warned that carelessly deployed AI could create new forms of financial exclusion and instability faster than regulators can manage. The core message from the RBI is one of ultimate accountability. “The model decided” will never be an acceptable excuse for a negative outcome, be it a rejected loan or a fraud case. To ensure this, the RBI has urged all banks to establish board-approved AI governance policies, maintain a complete inventory of every AI system in use, and ensure meaningful human oversight is preserved wherever AI can cause material harm.
The Banker’s Playbook
State Bank of India (SBI), the country's largest lender, is translating the RBI's principles into a clear business strategy. While early AI adoption in banking has focused on retail customers, SBI Chairman C.S. Setty stated that the technology's real test lies in what it can accomplish for the broader economy. The bank’s vision is to push AI into more complex areas like agricultural finance and lending to micro, small, and medium enterprises (MSMEs). This involves using alternative data sources like satellite imagery and digital records to assess creditworthiness for those without a formal financial history. However, Setty also echoed the RBI's cautious tone, highlighting that a wider AI footprint brings new risks, especially from sophisticated cyber threats. For SBI, the mantra is to strengthen defences concurrently with AI expansion. The bank's leadership believes the success of AI will be measured not by technological sophistication, but by its real-world economic impact, such as helping a small business get timely credit or making the financial system more resilient.
The Risks of Moving Too Fast
Why are these institutions so focused on a measured approach? The risks associated with AI in finance are substantial. One of the primary concerns is algorithmic bias. AI models trained on historical data could inadvertently perpetuate and even amplify existing biases against certain communities or geographies, leading to discriminatory lending practices. Another major risk is the “black box” problem, where even the developers cannot fully explain how a complex AI model arrived at a particular decision. This lack of transparency is unacceptable in a sector built on trust and regulatory accountability. The RBI also warns of concentration risk, where many banks relying on the same few AI vendors or models could lead to a system-wide failure if a vulnerability is found. Finally, the Governor has repeatedly flagged the erosion of human judgment and accountability as a primary danger, stressing that responsibility always rests with the bank, not its algorithm.
Building a Framework for Trust
This focus on responsible adoption is not just talk. The RBI has been developing a formal structure for AI governance. An RBI committee report from last year proposed the FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) framework, built on principles like fairness, accountability, and transparency. More recent draft guidelines have proposed concrete measures, including a mandate for banks to have a 'kill switch' to override or deactivate any AI model that behaves erratically. These rules would also require explicit disclosure when a customer is interacting with an AI, and the option to switch to a human representative. The strategy is not to prevent AI-driven fraud, but to fight it with more advanced AI. The Governor has stated that only AI and machine learning models can keep pace with modern, high-speed fraud, making responsible AI adoption a necessity for security.














