Preeti Chhabria

In the first part of this series, we looked at the first two chapters of RBI’s FREE-AI Committee report that dealt with the opportunities and risks of AI in financial services.

Chapter 3 of the report examines global regulatory approaches, India’s existing policy landscape, and the current state of AI adoption across the financial sector. Its central message is that AI adoption is accelerating, but governance has not kept pace.

Here are the links to the next parts: Part 3.

There Is No Single Global Playbook

Countries are regulating AI differently, depending on their priorities.

The EU has adopted a comprehensive, risk-based AI Act that applies across sectors and classifies AI systems according to the level of risk they pose. AI Systems are classified into risk categories – “unacceptable’, ‘high risk’, ‘low risk’ – stricter rules apply only to riskier uses. China has taken a more targeted approach, issuing separate regulations for areas such as generative AI, recommendation algorithms and deepfakes. Meanwhile, countries like the US, the UK and Singapore have preferred flexible, principle-based frameworks that allow sectoral regulators to issue guidance while encouraging innovation.

Alongside regulation, governments are also creating institutional mechanisms to evaluate AI systems. AI Safety Institutes in countries such as the UK and Singapore test model capabilities, while AI sandboxes allow firms to experiment with new applications under regulatory supervision.

The committee argues that regulation should draw on the best practices globally, but reflect domestic priorities.

India’s Approach: Innovation First, Regulation Second

The report highlights several ongoing policy initiatives, including NITI Aayog’s Responsible AI principles, the IndiaAI Mission (AI Safety Institute), and SEBI’s consultation paper on responsible AI use in securities markets. However, the committee also identifies important gaps within the RBI’s own regulatory framework.

Take existing outsourcing guidelines. They do not address AI-specific risks when third-party vendors deploy AI models. Cybersecurity regulations predate threats such as data poisoning and adversarial attacks. Digital lending guidelines require credit decisions to be auditable but do not explicitly address AI-specific risks.

Rather than recommending an entirely new regulatory architecture, the committee proposes a consolidated AI guidance framework that builds on existing regulations while addressing these incremental gaps.

The Reality on the Ground

The most interesting part of the chapter is the RBI’s survey of the financial sector. The RBI surveyed several banks, NBFCs, FinTechs and technology providers to understand how AI is actually being used.

The findings suggest that AI adoption remains at an early stage. Only 20.8% of surveyed institutions reported either deploying or developing AI systems. Adoption is concentrated among large commercial banks and leading NBFCs, while smaller financial institutions, including many urban cooperative banks and asset reconstruction companies, have little or no AI deployment.

Even among adopters, the technology remains relatively simple. Financial Institutions overwhelmingly prefer rule-based systems and conventional machine learning models because they are easier to implement, explain and integrate with legacy systems. Current deployments are also concentrated in relatively low-risk functions such as customer support, credit underwriting, sales and marketing, and cybersecurity.

While 67% of surveyed institutions are exploring generative AI, most experiments relate to internal productivity tools rather than customer-facing applications. Concerns around hallucinations, being biased, explainability, privacy and regulatory uncertainty continue to limit wider deployment.

Governance Is the Bigger Challenge

The report suggests that the biggest obstacle is not technology—it is governance.
Many financial institutions lack basic oversight mechanisms. Board-approved AI policies remain uncommon, explainability tools are rarely used, AI-specific incident management is still evolving, and continuous monitoring of model performance is limited (for eg. Keep logs of what the AI did, or monitor it after launch). This creates a disconnect between technical adoption and institutional readiness.

At the same time, firms face practical constraints such as shortages of AI talent, implementation costs and poor data quality. These challenges are particularly acute for smaller financial institutions. A large majority of surveyed financial institutions want clearer regulatory guidance from the RBI on critical issues on usage of AI across financial institutions such as data privacy, algorithmic transparency, bias mitigation, use of external LLMs, cross-border data flow, etc, which they believe would enable long-term investment.

Looking Ahead

If Chapter 3 explains why existing regulatory frameworks need to evolve, Chapter 4 answers the more important question: what should that framework actually look like?

The committee responds by proposing the FREE-AI Framework—built around seven guiding principles and 26 recommendations covering governance, innovation, consumer protection, cybersecurity and institutional capacity. It is here that the report moves from identifying problems to offering a roadmap for responsible AI adoption in India’s financial sector.

I will share about it in the next part of this series.

Acknowledgement

The report has been prepared by a multidisciplinary committee chaired by Dr Pushpak Bhattacharyya (IIT Bombay), with members from NITI Aayog, IIT Madras, the Ministry of Electronics and IT, Trilegal, HDFC Bank, Microsoft India, and the Reserve Bank of India. The composition reflects the intersection of academia, policy, law, and industry required to address the complexities of AI in finance.

Follow me on LinkedIn for more information and subscribe for updates on compliance, NBFCs, BFSI, etc.