Back to Insights
DispatchInsights

Deploying AI Agents Under RBI Guidelines: Governance Requirements for Indian Banks and NBFCs

Explore how Indian banks and NBFCs can deploy AI agents responsibly while aligning with RBI expectations around governance, risk management, data security, accountability, and human oversight. This guide covers practical considerations for designing, monitoring, and governing AI agents across financial workflows without compromising compliance, transparency, or operational controls.

Vaibhav Singh·25 September 2026·4 min read
Deploying AI Agents Under RBI Guidelines: Governance Requirements for Indian Banks and NBFCs

Indian banks and NBFCs are increasingly exploring AI for credit, fraud detection, customer service, compliance, operations, and risk management. But deploying AI in financial services is not the same as deploying it in an ordinary enterprise workflow, these institutions handle sensitive data and make decisions that materially affect customers, which creates a hard need for governance.

When people talk about RBI guidelines for AI in banking, it's important to separate existing binding requirements from the RBI's evolving AI policy direction. The RBI's FREE-AI Committee Report, dated August 13, 2025, proposed a framework for responsible and ethical AI in the financial sector, containing seven guiding principles and 26 recommendations. It shouldn't be described as a standalone blanket "AI Act" for banks and NBFCs. Instead, institutions should read the FREE-AI framework alongside applicable existing regulatory, cybersecurity, data, outsourcing, consumer-protection, and model-risk requirements, the practical governance layer beneath every use case in the agentic AI in finance cluster.

The FREE-AI framework, and why governance matters

The RBI constituted the FREE-AI Committee to recommend a framework for responsible and ethical AI adoption. The report identifies seven guiding principles, trust is the foundation, people first, innovation over restraint, fairness and equity, accountability, understandable by design, and safety, resilience and sustainability, then translates them into six strategic pillars covering innovation enablement and risk mitigation. These give banks and NBFCs a solid foundation for AI governance programmes.

Governance matters because AI touches credit underwriting, fraud detection, customer service, AML monitoring, KYC, collections, financial reporting, risk management, and internal operations, while introducing risks around bias, explainability, data quality, cybersecurity, model risk, operational resilience, third-party dependency, and customer protection, all of which the FREE-AI report discusses. And governance should begin at the board level, not as an IT project: a bank or NBFC should establish clear ownership for AI strategy, risk, compliance, data, cybersecurity, model validation, and business ownership, with the report recommending a board-approved AI policy for regulated entities. The structure should answer who owns the system, who approves it, who validates it, who can stop it, and who is accountable when it produces an incorrect result.

Classify by risk, manage model risk, govern data, and oversee agents

Not every application needs the same governance. A simple classification: low risk (internal summarisation, meeting assistance, document search), medium risk (customer-service assistance, operational recommendations, workflow prioritisation), and high risk (credit decisions, financial transactions, regulatory reporting, fraud decisions, sensitive customer decisions), with Applore's agent governance framework similarly recommending stronger controls where errors could affect financial decisions, regulatory reporting, or sensitive information. Treat AI systems as models that can fail through inaccurate or incomplete data, drift, biased training data, wrong implementation, changing behaviour, or unusual conditions, and remember the RBI's emphasis on robust models, periodic testing, and model risk, so governance continues after deployment. On explainability, a bank should be able to explain what the system does, what data it uses, its limitations, its controls, who approved it, how it's monitored, and when it changed, documented across the full lifecycle. On data, governance should cover lineage, access permissions, retention, quality, consent where applicable, minimisation, third-party access, and security, and an agent should never get broad database access just because it needs information; least privilege belongs in the architecture.

Agentic AI adds a layer: a traditional model produces a prediction, but an agent can retrieve information, call APIs, update records, send communications, initiate workflows, and make recommendations, so you govern not only the model but its tools and permissions, with scoped permissions, structured outputs, validation, audit trails, and human escalation. Human oversight should scale with risk, low-risk tasks the agent executes automatically, moderate-risk the agent prepares and an employee approves, high-risk the agent analyses evidence and an authorised professional decides. Prepare for AI incidents too (incorrect outputs, privacy leakage, unauthorised action, prompt injection, data poisoning, unexpected behaviour, outages); the FREE-AI report even includes an indicative AI incident reporting form among its annexures. And manage third-party providers, cloud, foundation-model providers, AI platforms, vendors, by understanding where data is processed, who can access it, how models are updated, what happens during an outage, what contractual controls exist, and whether audit information is available.

A practical governance checklist, and the road ahead

Before production, an institution should be able to answer: on governance, is there a defined business owner, documented AI governance, and an established risk classification; on data, what does the system access, is access restricted, is quality monitored; on the model, has it been validated, are limitations documented, is ongoing monitoring in place; on security, are permissions scoped, are AI-specific attacks considered, is sensitive data protected; on human oversight, which decisions require approval and what triggers escalation; on auditability, are actions logged and can outputs be traced to source; and on incident management, is there a rollback mechanism and an incident-response process.

AI adoption in Indian finance will keep expanding across customer-facing and internal workflows, so the question moves from "can we use AI?" to "can we govern AI at the scale we want to deploy it?" The FREE-AI framework is a major reference point, while institutions still assess the full set of regulations and controls per use case. Handle the phrase "RBI guidelines for AI in banking" carefully: the environment is evolving, and the 2025 FREE-AI report provides a significant framework built on trust, accountability, fairness, explainability, and safety, plus recommendations on governance, cybersecurity, audits, and capability. The practical objective is clear: build AI systems that can be understood, controlled, monitored, and audited. The strongest programme isn't the one with the most autonomous agents; it's the one where the organisation knows exactly what the AI can and can't do, who's accountable, and what happens when it's wrong.

Written by
Vaibhav Singh
CEO, Applore Technologies
Sign-off

Bring us the work that needs the reading list to be true