The seven sutras
The principles the committee wants every AI decision in finance to respect 24.
1 · Trust is the foundation
AI in finance only works if customers and the system can rely on it.
2 · People first
Human welfare and customer interests come before automation for its own sake.
3 · Innovation over restraint
The default is to enable responsible AI, not to block it.
4 · Fairness and equity
Outcomes must not discriminate, and must widen access rather than narrow it.
5 · Accountability
A regulated entity owns the outcomes of its AI, whoever built the model.
6 · Understandable by design
Explainability is designed in from the start, not added afterwards.
7 · Safety, resilience and sustainability
AI must be secure, able to fail safely, and sustainable to run.
The six pillars
The 26 recommendations sit under six pillars: three that enable innovation and three that manage risk 15.
Innovation enablement
Infrastructure: shared financial-sector data and compute as digital public infrastructure, an AI innovation sandbox, and indigenous, India-specific models developed as public goods 6.
Policy: board-approved AI policies, and adaptive supervision, including a tolerant stance on first-time errors in low-risk, inclusion-oriented uses where safeguards exist 7.
Capacity: training boards, senior management, risk, compliance and audit teams to understand and oversee AI.
Risk mitigation
Governance: clear ownership, an inventory of AI systems, model risk management extended to AI, and third-party AI treated as the entity's own responsibility.
Protection: consumer disclosure when customers interact with AI, grievance and recourse routes, data-lifecycle governance and AI-aware cybersecurity 4.
Assurance: audits and impact assessments of AI systems, incident reporting, red-teaming scaled to risk, and tested fallback plans for AI-dependent processes.
What the report says about agents
The committee noted that most regulated entities were still at the pilot stage with generative AI, largely internal chatbots, and flagged the use of external models as a concern 8. It also discussed the move from task automation to decision automation through agent protocols, and treated that as an emerging risk area 6.
Read together with the draft model-risk guidance, the direction is clear: an AI agent that takes decisions in a regulated process will be expected to have an owner, an inventory entry, validation evidence, an override, and a human a customer can reach.
The checklist: twelve things to do now
Practical steps that line up with FREE-AI and the draft model-risk guidance. None of them is wasted if the final rules change.
1 · Write a board-approved AI policy
Permitted uses, risk appetite, where a human must decide, and who owns what.
2 · Build an AI inventory
Every model and agent: owner, purpose, data used, vendor, version, risk tier, validation evidence.
3 · Tier your use cases by risk
Credit, fraud and AML decisions carry more scrutiny than an internal summariser. Controls should follow the tier.
4 · Extend model risk management to AI
Validation before use, monitoring after, and change control for prompts and configurations as well as weights.
5 · Own your vendors' models
Third-party AI does not move accountability. Contract for evidence, audit rights and exit.
6 · Put a named human on consequential decisions
An approver who sees the context, with an escalation path and a clock.
7 · Tell customers when it is AI
Plain-language disclosure, and a route to a person and to redress.
8 · Govern the data
Mask customer data before it reaches models; know where it is stored, for how long, and why.
9 · Secure the AI itself
Defend against prompt injection and data exfiltration, and red-team high-risk systems.
10 · Build the override and the fallback
A way to stop or bypass an AI system quickly, and a tested process that runs without it.
11 · Report AI incidents
Define what counts as an AI incident, and route it into your existing incident process.
12 · Keep evidence an auditor can check
Records of what each system saw, decided and who approved, that the operating team cannot quietly edit.
Where AgentAnywhere fits
Several items on that list are what our platform is built to produce. The registry and Model Hub keep models and agents inventoried with owners, lineage and approvals. Veil masks customer data before any model sees it. Kavach sits in front of model calls to detect prompt injection and jailbreaks. Consequential steps wait for a named approver, every call writes a signed Trust Receipt, and Custodian keeps compliance evidence current. Our BFSI model family, Kuber, is in private preview.
Our alignment to the RBI's FREE-AI framework is designed to support your own assessment, not to replace it. ShepHertz operates a control environment certified for SOC 2 and ISO 27001 and independently assessed for HIPAA and GDPR.
To walk one AI use case through the checklist with us, book a session with our compliance team.
What this guide is not
It is a plain-language reading of a committee report and a draft consultation, not legal or regulatory advice, and not the text of any binding direction. The full list of 26 recommendations, with owners and timelines, is in the RBI's report; read it with your compliance team, and watch for final directions.
Frequently asked questions
What is the RBI FREE-AI framework?
FREE-AI, the Framework for Responsible and Ethical Enablement of Artificial Intelligence, is a report by a Reserve Bank of India committee chaired by Prof. Pushpak Bhattacharyya, released on 13 August 2025. It sets seven guiding sutras and 26 recommendations across six pillars for the responsible use of AI by banks, NBFCs and other regulated entities.
Is RBI FREE-AI mandatory for banks?
FREE-AI itself is a committee report with recommendations, not binding directions. Its ideas are being carried into regulation: in June 2026 the RBI issued draft guidance on model risk management that covers AI and machine-learning models and cites FREE-AI. That guidance was a draft for consultation, so banks should track the final directions.
What are the seven sutras of FREE-AI?
Trust is the foundation; people first; innovation over restraint; fairness and equity; accountability; understandable by design; and safety, resilience and sustainability.
What are the six pillars of FREE-AI?
Three innovation-enablement pillars (infrastructure, policy and capacity) and three risk-mitigation pillars (governance, protection and assurance), under which the 26 recommendations are organised.
Does using a third-party AI vendor reduce a bank's responsibility?
No. FREE-AI and the 2026 draft model-risk guidance both treat the regulated entity as accountable for AI outcomes, including models supplied by vendors. Banks should contract for evidence, audit rights and exit, and keep vendor models in their own AI inventory.
Sources
Accessed September 2026. The primary document is the RBI committee report; secondary summaries are used where they are consistent with each other.
- 1KPMG India — RBI FREE-AI committee report.
- 2Lexology — RBI's FREE-AI framework.
- 3CorpLawUpdates — RBI draft guidance on model risk management, 2026.
- 4Scrut — RBI's framework for responsible and ethical enablement of AI.
- 5Law.asia — RBI AI framework.
- 6Medianama — RBI committee on sector-specific AI models.
- 7AuthBridge — RBI's FREE-AI framework: key highlights.
- 8Dvara Research — Summary of the RBI FREE-AI committee report.
- 9Reserve Bank of India — FREE-AI committee report (PDF).
Written by
AgentAnywhere Research
The team that builds the platform and the models
AgentAnywhere Research writes about the platform, the model families and the trust layer we build and run in India. Where a figure is ours, it says what it covers; where something is a demonstration or in preview, it says so.