Regulation10 min read

What the RBI actually asks of your AI, in plain English.

FREE-AI is the most detailed statement yet of how India's banking regulator thinks about AI. It is a committee report, not a rulebook, but its ideas are already turning into draft rules. Here is what it says, and what a bank or NBFC should do about it now.

AgentAnywhere Research

Animated diagram of the RBI FREE-AI framework: seven sutra blocks form a foundation (trust, people first, innovation over restraint, fairness and equity, accountability, understandable by design, safety, resilience and sustainability); above them six pillars rise, three labelled innovation enablement (infrastructure, policy, capacity) and three labelled risk mitigation (governance, protection, assurance), supporting a banner for the recommendations.
FIG.57FREE-AI in one picture: seven sutras as the foundation, six pillars on top (three that enable innovation, three that manage risk), and the recommendations that turn them into work.

The seven sutras

The principles the committee wants every AI decision in finance to respect 24.

  • 1 · Trust is the foundation

    AI in finance only works if customers and the system can rely on it.

  • 2 · People first

    Human welfare and customer interests come before automation for its own sake.

  • 3 · Innovation over restraint

    The default is to enable responsible AI, not to block it.

  • 4 · Fairness and equity

    Outcomes must not discriminate, and must widen access rather than narrow it.

  • 5 · Accountability

    A regulated entity owns the outcomes of its AI, whoever built the model.

  • 6 · Understandable by design

    Explainability is designed in from the start, not added afterwards.

  • 7 · Safety, resilience and sustainability

    AI must be secure, able to fail safely, and sustainable to run.

The six pillars

The 26 recommendations sit under six pillars: three that enable innovation and three that manage risk 15.

Innovation enablement

Infrastructure: shared financial-sector data and compute as digital public infrastructure, an AI innovation sandbox, and indigenous, India-specific models developed as public goods 6.

Policy: board-approved AI policies, and adaptive supervision, including a tolerant stance on first-time errors in low-risk, inclusion-oriented uses where safeguards exist 7.

Capacity: training boards, senior management, risk, compliance and audit teams to understand and oversee AI.

Risk mitigation

Governance: clear ownership, an inventory of AI systems, model risk management extended to AI, and third-party AI treated as the entity's own responsibility.

Protection: consumer disclosure when customers interact with AI, grievance and recourse routes, data-lifecycle governance and AI-aware cybersecurity 4.

Assurance: audits and impact assessments of AI systems, incident reporting, red-teaming scaled to risk, and tested fallback plans for AI-dependent processes.

What the report says about agents

The committee noted that most regulated entities were still at the pilot stage with generative AI, largely internal chatbots, and flagged the use of external models as a concern 8. It also discussed the move from task automation to decision automation through agent protocols, and treated that as an emerging risk area 6.

Read together with the draft model-risk guidance, the direction is clear: an AI agent that takes decisions in a regulated process will be expected to have an owner, an inventory entry, validation evidence, an override, and a human a customer can reach.

The checklist: twelve things to do now

Practical steps that line up with FREE-AI and the draft model-risk guidance. None of them is wasted if the final rules change.

  • 1 · Write a board-approved AI policy

    Permitted uses, risk appetite, where a human must decide, and who owns what.

  • 2 · Build an AI inventory

    Every model and agent: owner, purpose, data used, vendor, version, risk tier, validation evidence.

  • 3 · Tier your use cases by risk

    Credit, fraud and AML decisions carry more scrutiny than an internal summariser. Controls should follow the tier.

  • 4 · Extend model risk management to AI

    Validation before use, monitoring after, and change control for prompts and configurations as well as weights.

  • 5 · Own your vendors' models

    Third-party AI does not move accountability. Contract for evidence, audit rights and exit.

  • 6 · Put a named human on consequential decisions

    An approver who sees the context, with an escalation path and a clock.

  • 7 · Tell customers when it is AI

    Plain-language disclosure, and a route to a person and to redress.

  • 8 · Govern the data

    Mask customer data before it reaches models; know where it is stored, for how long, and why.

  • 9 · Secure the AI itself

    Defend against prompt injection and data exfiltration, and red-team high-risk systems.

  • 10 · Build the override and the fallback

    A way to stop or bypass an AI system quickly, and a tested process that runs without it.

  • 11 · Report AI incidents

    Define what counts as an AI incident, and route it into your existing incident process.

  • 12 · Keep evidence an auditor can check

    Records of what each system saw, decided and who approved, that the operating team cannot quietly edit.

Where AgentAnywhere fits

Several items on that list are what our platform is built to produce. The registry and Model Hub keep models and agents inventoried with owners, lineage and approvals. Veil masks customer data before any model sees it. Kavach sits in front of model calls to detect prompt injection and jailbreaks. Consequential steps wait for a named approver, every call writes a signed Trust Receipt, and Custodian keeps compliance evidence current. Our BFSI model family, Kuber, is in private preview.

Our alignment to the RBI's FREE-AI framework is designed to support your own assessment, not to replace it. ShepHertz operates a control environment certified for SOC 2 and ISO 27001 and independently assessed for HIPAA and GDPR.

To walk one AI use case through the checklist with us, book a session with our compliance team.

What this guide is not

It is a plain-language reading of a committee report and a draft consultation, not legal or regulatory advice, and not the text of any binding direction. The full list of 26 recommendations, with owners and timelines, is in the RBI's report; read it with your compliance team, and watch for final directions.

Frequently asked questions

What is the RBI FREE-AI framework?

FREE-AI, the Framework for Responsible and Ethical Enablement of Artificial Intelligence, is a report by a Reserve Bank of India committee chaired by Prof. Pushpak Bhattacharyya, released on 13 August 2025. It sets seven guiding sutras and 26 recommendations across six pillars for the responsible use of AI by banks, NBFCs and other regulated entities.

Is RBI FREE-AI mandatory for banks?

FREE-AI itself is a committee report with recommendations, not binding directions. Its ideas are being carried into regulation: in June 2026 the RBI issued draft guidance on model risk management that covers AI and machine-learning models and cites FREE-AI. That guidance was a draft for consultation, so banks should track the final directions.

What are the seven sutras of FREE-AI?

Trust is the foundation; people first; innovation over restraint; fairness and equity; accountability; understandable by design; and safety, resilience and sustainability.

What are the six pillars of FREE-AI?

Three innovation-enablement pillars (infrastructure, policy and capacity) and three risk-mitigation pillars (governance, protection and assurance), under which the 26 recommendations are organised.

Does using a third-party AI vendor reduce a bank's responsibility?

No. FREE-AI and the 2026 draft model-risk guidance both treat the regulated entity as accountable for AI outcomes, including models supplied by vendors. Banks should contract for evidence, audit rights and exit, and keep vendor models in their own AI inventory.

Sources

Accessed September 2026. The primary document is the RBI committee report; secondary summaries are used where they are consistent with each other.

  1. 1KPMG India — RBI FREE-AI committee report.
  2. 2Lexology — RBI's FREE-AI framework.
  3. 3CorpLawUpdates — RBI draft guidance on model risk management, 2026.
  4. 4Scrut — RBI's framework for responsible and ethical enablement of AI.
  5. 5Law.asia — RBI AI framework.
  6. 6Medianama — RBI committee on sector-specific AI models.
  7. 7AuthBridge — RBI's FREE-AI framework: key highlights.
  8. 8Dvara Research — Summary of the RBI FREE-AI committee report.
  9. 9Reserve Bank of India — FREE-AI committee report (PDF).
TopicsRBI FREE-AI frameworkFREE-AI seven sutrasRBI AI guidelines for banksRBI model risk management AI 2026AI governance BFSI IndiaAI compliance NBFC

Written by

AgentAnywhere Research

The team that builds the platform and the models

AgentAnywhere Research writes about the platform, the model families and the trust layer we build and run in India. Where a figure is ours, it says what it covers; where something is a demonstration or in preview, it says so.

All articles →