India - Responsible AI Framework
FREE‑AI Framework — Framework for Responsible and Ethical Enablement of Artificial Intelligence (RBI FREE‑AI Committee Report)
India
RAI-IN-NA-FREEAXX-2025RBI's 2025 FREE‑AI report sets principles and 26 recommendations to enable responsible AI across India’s financial sector.
Summary
Read full text ↗Plain English
Overview
The Reserve Bank of India (RBI) published the FREE-AI Committee Report — "Framework for Responsible and Ethical Enablement of Artificial Intelligence" — on 13 August 2025. The report is the output of an eight-member expert committee (constituted by RBI in December 2024) chaired by Dr. Pushpak Bhattacharyya (IIT Bombay). The Committee’s mandate was to assess AI adoption in financial services, review global regulatory approaches, identify AI risks for regulated entities (REs) and recommend a practical governance, evaluation, mitigation and monitoring framework tailored to India’s financial sector. The report is advisory: it lays out principles, structured recommendations and operational artifacts (annexures such as a suggested Board policy outline and an indicative AI incident reporting form) intended to guide RBI policy and empower supervised entities to adopt AI responsibly.
Definitions
The published report does not provide a single consolidated glossary within the material summarised here. Relevant terms used in the report and in this summary include: "Regulated Entities (REs)" — scheduled commercial banks, cooperative banks, NBFCs, payment system operators, fintechs and other firms subject to RBI supervision; "AI/ML" — artificial intelligence and machine learning including Generative AI and large language models (LLMs); "7 Sutras" — the seven guiding principles set out by the Committee; and "Pillars" — the six strategic categories (Infrastructure, Policy, Capacity, Governance, Protection, Assurance) under which 26 recommendations are grouped. Where the original report or annexures defines additional operational terms (for example, Model Context Protocols (MCP), incident taxonomy, or annex-specific templates), those definitions are found in the report annexures (see Sources and Full Text link).
Governance and Institutional Framework
The FREE-AI Committee was constituted by the RBI (press release dated 2024-12-26) with an expert membership and a remit to recommend a proportionate framework for the financial sector. The report proposes a governance posture that combines board-level responsibility with structured lifecycle governance inside regulated entities: board-approved AI policies (illustrative outline at Annex V), formal model approval and change-control processes, independent model validation and periodic audits, vendor and third-party management safeguards, and a standing multi-stakeholder committee for ongoing oversight and calibration. Although the report itself is advisory, its recommendations are expressly designed so that RBI may convert them into supervisory expectations, Master Directions, circulars or other binding instruments for regulated entities; implementation would therefore flow through RBI instruments and inter-regulatory coordination where relevant.
Key Focus Areas
- Seven guiding principles ("7 Sutras"): Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; Safety, Resilience and Sustainability. These sutras provide normative guidance for policy and operational decisions across the AI lifecycle.
- Six strategic pillars framing the 26 recommendations: Infrastructure; Policy; Capacity (innovation enablement); Governance; Protection; Assurance. Recommendations are grouped under these pillars to balance innovation and prudential safeguards.
- Infrastructure & Innovation: creation of shared digital infrastructure (compute and curated data access), build an "AI Innovation Sandbox" (GenAI-enabled testing environments), and incentivise indigenous, financial-sector specific AI model development (including proposals for a fund to support home-grown models).
- Policy and regulatory design: an enabling, proportionate approach — "regulatory-lite" posture for low-risk uses, explicit guidance for high-risk applications, and suggested AI-specific enhancements for RBI Master Directions (Annex IV).
- Capacity building: sector-wide capacity development including board and senior management training, creation of model governance expertise within REs, and knowledge-sharing across the ecosystem.
- Operational governance: mandate for board-approved AI policies, structured AI lifecycle governance (model approval, testing, deployment, change control), and specified vendor/third-party contractual safeguards where models or services are externally sourced.
- Protection and consumer safeguards: expand product approval and consumer protection processes to handle AI-enabled features, ensure disclosure to customers when AI materially affects outcomes, and align data handling with the Digital Personal Data Protection Act, 2023 (DPDP Act).
- Assurance and oversight: enhanced model-assurance mechanisms (independent model validation, periodic audits, logging and record retention), an AI incident reporting mechanism (Annex VI indicative incident reporting form), and a proposal for a multi-stakeholder standing committee to provide continuing oversight.
- Technical controls and artefacts: reproducible model development pipelines, Model Context Protocols (MCP), comprehensive documentation (inputs, outputs, pre/post processing), stress testing and scenario analysis, dataset and log retention for auditability, and privacy-enhancing/security controls for model and data confidentiality.
Implementation Framework
The Committee provides 26 actionable recommendations grouped under the six pillars and includes operational annexures intended to reduce implementation friction for supervised entities and supervisors alike. Key implementation mechanisms recommended include: shared infrastructure and curated datasets to lower barriers for innovation while managing concentration risk; an AI Innovation Sandbox to enable testing of generative and other advanced models in controlled environments; incentives and a proposed fund to encourage indigenous model development for financial-sector needs; suggested text and enhancements for RBI Master Directions (Annex IV); illustrative Board policy outline (Annex V); and an indicative AI incident reporting form and protocol (Annex VI). The report emphasises proportionate regulation — lighter touch for low-risk use-cases, stricter requirements and supervisory involvement for high-risk AI applications. Operationalising the recommendations is expected to proceed via RBI consultations, circulars, supervisory guidance, updates to Master Directions and sandbox rules, and through coordination with other regulators and national digital public infrastructure (DPI) initiatives.
Monitoring and Evaluation
The report recommends robust assurance, monitoring and incident management processes. Proposed measures include independent model validation and periodic audits, logging and record retention to enable auditability, an AI incident reporting mechanism (illustrative form at Annex VI) and stress testing/scenario analysis for systemic and operational resilience risks. It also recommends setting up a multi-stakeholder standing committee to continue oversight, provide calibration between industry practices and supervisory expectations, and to coordinate across regulators where cross-sector issues arise. The Committee further suggests that supervisory tools and audit frameworks be updated to incorporate AI considerations, enabling RBI to assess compliance and resilience during on-site/off-site supervision and model reviews.
Penalties, Liability, and Appeals
The FREE-AI report is advisory and does not itself establish penalties. However, it explicitly anticipates that RBI may convert recommendations into mandatory requirements via Master Directions, circulars or other binding supervisory instruments. Where RBI elects to make particular requirements mandatory, enforcement and penalties would be applied under existing statutory powers and instruments available to RBI (for example under the Banking Regulation Act, Payment and Settlement Systems Act and related statutes). The report recommends strengthening incident reporting and assurance so that RBI can act promptly when AI-related incidents implicate consumer protection, operational resilience or systemic risks; legal liability, penalties and appeal mechanisms would therefore follow the statutory and administrative processes applicable to the underlying mandatory instrument once issued.
Relationship to Other Instruments
The Committee situates the framework within India's broader regulatory and legal environment. It expressly references the Digital Personal Data Protection Act, 2023 (DPDP Act) as the national data protection statute to which AI data practices must conform. The report also contemplates inter‑regulatory coordination with other financial regulators (for example SEBI and IRDAI) and alignment with national digital public infrastructure such as UPI and initiatives like IndiaAI. Many recommendations have cross-sector relevance and the Committee recommends coordination mechanisms so that RBI, other regulators and national DPI custodians can align expectations, supervisory approaches and sandbox/testbed arrangements.
International Alignment
The Committee assesses global approaches to AI governance and aligns many recommendations with established international technical and standards frameworks. The report references ISO/IEC AI standards and OECD analyses as part of the background and recommends that technical controls be consistent with international best practices: documentation standards, model testing and stress testing, explainability and fairness assessments, privacy-enhancing technologies, and security controls for model confidentiality. The Committee's approach emphasises interoperability with international standards to facilitate cross-border model development, validation studies and supervisory cooperation where relevant.
Implementation Timeline
| Date | Event |
|---|---|
| 2024-12-06 | RBI announced in its Monetary Policy Statement / Statement on Developmental & Regulatory Policies its intent to set up a committee to develop a framework for responsible and ethical enablement of AI in the financial sector. |
| 2024-12-26 | RBI press release formally constituted the FREE-AI Committee and published its Terms of Reference (Press Release: 2024-2025/1779). |
| 2025-06-20 | SEBI published a consultation paper on Guidelines for Responsible Usage of AI/ML in Indian Securities Markets (relevant inter-regulatory development; public comment period). |
| 2025-08-13 | RBI published the FREE-AI Committee Report — "Framework for Responsible and Ethical Enablement of Artificial Intelligence" (committee report containing 7 Sutras and 26 recommendations). |
Compliance Checklist
| Requirement | Description |
|---|---|
| Board-approved AI policy | Prepare or update a Board-approved AI policy using the illustrative outline provided (Annex V) covering governance, risk appetite, accountability and oversight. |
| Model governance and assurance | Implement structured lifecycle governance: model approval, testing, deployment, change control, independent validation and periodic audits, and maintain comprehensive documentation (MCPs, inputs/outputs, pre/post processing). |
| Data protection & privacy alignment | Align AI data practices with the Digital Personal Data Protection Act, 2023 (DPDP Act) and use privacy-enhancing technologies; ensure lawful bases and disclosures where AI materially affects consumers. |
| Incident reporting & contingency planning | Establish incident detection, escalation and reporting processes consistent with the illustrative incident reporting form (Annex VI), and maintain fallback/contingency arrangements. |
| Third-party/vendor management | Adopt contractual safeguards and oversight for externally sourced models/services, including SLAs, audit rights and security/confidentiality provisions. |
| Capacity building | Invest in board and senior management training, create model governance expertise internally, and engage in sector-level knowledge sharing and sandbox participation. |
Sources and References
| Source | URL |
|---|---|
| FREE-AI Committee Report — RBI publication details (13 Aug 2025) | https://rbi.org.in/Scripts/PublicationReportDetails.aspx?ID=1306&UrlPage= |
| FREE-AI Committee Report — full PDF (RBI / rbidocs) (13 Aug 2025) | https://rbidocs.rbi.org.in/rdocs/content/pdfs/FREEAIR13082025_ANVI.pdf |
| Reserve Bank of India — Press Release: Framework for Responsible and Ethical Enablement (FREE) of Artificial Intelligence in the Financial Sector — Setting up of a committee (26 Dec 2024) | https://www.rbi.org.in/scripts/FS_PressRelease.aspx?prid=59377 |
| Digital Personal Data Protection Act, 2023 — Act text (Ministry of Electronics & Information Technology / MeitY) | https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf |
| SEBI — Consultation Paper: Guidelines for Responsible Usage of AI/ML in Indian Securities Markets (20 Jun 2025) | https://www.sebi.gov.in/sebiweb/home/HomeAction.do?doListing=yes&sid=4&smid=36%2F1000&ssid=38 |
| IndiaAI — Commentary: RBI’s Framework for Responsible and Ethical Enablement (IndiaAI portal) | https://indiaai.gov.in/article/rbi-s-framework-for-responsible-and-ethical-enablement-towards-ethical-ai-in-finance |
The Reserve Bank of India’s (RBI) FREE-AI report provides a comprehensive framework to guide financial institutions in India on the responsible and ethical use of Artificial Intelligence (AI). This framework applies to all entities regulated by the RBI, including scheduled commercial banks, cooperative banks, non-banking financial companies (NBFCs), payment system operators, and fintechs.
Published on August 13, 2025, the report outlines seven guiding principles, known as "Sutras," and 26 recommendations across six strategic pillars. The most important obligations for regulated entities include: - Establishing a board-approved AI policy and implementing structured governance throughout the AI lifecycle, covering everything from model approval and testing to deployment and change control, with independent validation and periodic audits. - Ensuring all AI data practices strictly comply with India's Digital Personal Data Protection Act, 2023. - Developing robust mechanisms for detecting, escalating, and reporting AI-related incidents, along with maintaining clear contingency plans. - Implementing strong contractual safeguards and oversight when sourcing AI models or services from third-party vendors.
While the FREE-AI report itself is currently advisory and does not immediately impose penalties, it is explicitly designed for the RBI to convert its recommendations into mandatory requirements through future Master Directions, circulars, or other binding instruments. Once these requirements become mandatory, non-compliance would be subject to the RBI's existing statutory enforcement powers and penalties.
A crucial practical takeaway for regulated entities is to begin preparing now, even before specific rules are made binding. The framework advocates for a "proportionate" regulatory approach, meaning lighter oversight for low-risk AI applications but stricter requirements and supervisory involvement for high-risk uses. This necessitates a careful assessment of all AI deployments. The RBI also plans to create an "AI Innovation Sandbox" to facilitate safe testing of advanced AI models, offering a valuable resource for development.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under India - Responsible AI Framework. Not legal advice — verify against the official text before relying on it.
- #1CriticalCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“Align AI data practices with the Digital Personal Data Protection Act, 2023 (DPDP Act).”
- #2ImportantCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“Prepare or update a Board-approved AI policy using the illustrative outline provided (Annex V) covering governance, risk appetite, accountability and oversight.”
- #3ImportantCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“Implement structured lifecycle governance: model approval, testing, deployment, change control, independent validation and periodic audits.”
- #4ImportantCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“maintain comprehensive documentation (MCPs, inputs/outputs, pre/post processing).”
- #5ImportantCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“ensure lawful bases and disclosures where AI materially affects consumers.”
- #6ImportantCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“Establish incident detection, escalation and reporting processes consistent with the illustrative incident reporting form (Annex VI).”
- #7ImportantCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“maintain fallback/contingency arrangements.”
- #8ImportantCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“Adopt contractual safeguards and oversight for externally sourced models/services, including SLAs, audit rights and security/confidentiality provisions.”
- #9RecommendedCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“Invest in board and senior management training, create model governance expertise internally.”
- #10RecommendedCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“create model governance expertise internally.”
- #11RecommendedCompliance Checklist
Applies to: Regulated Entities in India's financial sector.
“engage in sector-level knowledge sharing and sandbox participation.”
Related Regulations
India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation
India94% similar
Artificial Intelligence (Ethics & Accountability) Bill, 2025
India91% similar
India AI Regulation Overview
India90% similar
Report of the Committee on Platforms and Data on Artificial Intelligence (MeitY report)
India90% similar
National Strategy for Artificial Intelligence (#AIforAll) - NITI Aayog
India89% similar
© Regulations.AI — created on 06-Jan-2026