The Reserve Bank of India (RBI) has asked banks to make AI governance an immediate priority, calling for complete inventories of AI systems, board-approved governance frameworks, explainable AI decisions, regular stress testing and meaningful human oversight as the technology becomes increasingly embedded in banking.
RBI Governor Sanjay Malhotra said banks should treat these measures as immediate priorities rather than distant compliance requirements as they accelerate the adoption of artificial intelligence across lending, customer service, fraud detection and operations.
Addressing the FIBAC 2026 Conference in Mumbai, Malhotra said the RBI’s approach to AI would seek to balance innovation with safety, with the regulator favouring a principles-based and proportionate framework rather than a rigid, prescriptive approach.
Five priorities for banks
The Governor said every institution should maintain a complete inventory of every AI system in use, including AI capabilities embedded in products supplied by vendors. This, he said, would ensure that neither banks nor regulators are caught unaware by systems operating within an institution.
Banks should also establish board-approved AI governance policies, with accountability extending to outcomes rather than merely technology procurement.
Another priority is the ability to explain AI-driven decisions that materially affect customers, particularly decisions involving lending and fraud outcomes.
The RBI also expects banks to red-team and stress-test AI systems before deployment and periodically thereafter, in line with the way other material risks are assessed.
Finally, banks should preserve meaningful human oversight wherever an AI error could cause material harm to a customer or threaten financial stability.
“These are immediate priorities rather than distant compliances,” Malhotra said, emphasising that responsibility for decisions cannot be transferred to algorithms.
AI could widen the banking frontier
The RBI Governor said the central bank views AI as a capability to be responsibly harnessed rather than simply a risk to be contained.
For Indian banking, one of the biggest opportunities lies in expanding access to credit. Traditional underwriting often depends on established financial histories, leaving new-to-credit borrowers, gig workers and small businesses with limited formal records at a disadvantage.
AI models can potentially use alternative information such as cash flows, GST filings, utility payments and digital footprints to assess creditworthiness and expand the pool of borrowers that banks can serve.
AI-enhanced credit-risk models, liquidity forecasting and scenario analysis could also help banks identify emerging stress earlier than traditional financial statements allow.
The technology can improve customer service as well. AI-assisted relationship managers could identify appropriate products and risk signals, while AI-powered grievance redressal and personalised financial guidance could improve the customer experience.
For a country as diverse as India, the Governor sees particular potential in financial inclusion. Voice-based interfaces in Indian languages could reduce language barriers, while predictive models could identify borrowers at risk of default early enough for banks to offer counselling rather than rely only on recovery measures.
Efficiency and fraud detection
AI could also help banks lower operating and intermediation costs by automating document processing, reconciliation, internal-audit sampling, transaction reporting and regulatory-return preparation.
This could free skilled employees to focus on areas requiring human judgment while reducing the operational risk associated with manual errors.
Fraud detection represents another major opportunity. Malhotra pointed out that fraud can move at the speed of an API call, while traditional rules-based systems can struggle to keep pace with constantly adapting fraud patterns.
Machine-learning models can continuously learn from transaction behaviour and identify anomalies in real time, potentially allowing banks to detect and stop fraud before losses crystallise.
Seven risks banks cannot ignore
The opportunities, however, come with significant risks.
The first is the “black box” problem. Advanced AI models may not readily explain their reasoning, making it difficult for customers, auditors, boards and regulators to understand why a particular decision was taken.
The second is bias and exclusion. Models trained on historical lending data can reproduce existing biases against particular geographies, occupations or communities. The Governor said fairness in AI-driven finance must be treated as a design requirement rather than a compliance checkbox.
The RBI is also concerned about concentration and herding. If multiple banks rely on the same foundation models or technology vendors, a common error or vulnerability could become a systemic risk. Similar AI-driven trading strategies could also amplify volatility during stressed market conditions.
Third-party dependence is another concern, particularly for smaller banks that are likely to rely on external technology providers. Vendor contracts, the Governor said, should include AI-specific accountability, including audit and explanation rights and a credible exit plan.
Data privacy and security present additional challenges as AI systems require large volumes of information. Banks must guard against excessive data collection, prolonged retention or using customer information beyond the purposes for which consent was provided.
AI systems themselves could become cyber targets through data poisoning, model manipulation and adversarial attacks designed to deceive systems such as automated fraud detectors.
The most fundamental risk, however, is the erosion of human judgment and accountability.
Malhotra made it clear that responsibility for a bank’s decisions remains with the bank, not its algorithm. “The model decided” cannot be an acceptable answer to a customer, auditor or the RBI.
RBI promises agile regulation
The RBI’s approach, based on the recommendations of its FREE-AI Committee and draft guidelines on Model Risk Management, is built around the principle that innovation and safety are complementary rather than competing objectives.
The regulatory framework will be principles-based and proportionate, recognising that AI risks can differ significantly between a large bank operating proprietary models and a smaller institution using an off-the-shelf vendor solution.
The RBI also plans to engage with the industry as AI capabilities evolve, while continuing to support its regulatory sandbox for testing innovative use cases.
Malhotra said the central bank would also facilitate common utilities such as MuleHunter and the proposed Digital Payments Intelligence Platform to strengthen fraud detection and protect the financial system.
For Indian banks, the message is clear: AI adoption is no longer simply a technology decision. It is becoming a board-level business, risk and governance priority, with the benefits of speed, inclusion and efficiency depending ultimately on how responsibly the technology is deployed.
