ENTRY № 17 · STATUTORY READING · RBI FREE-AI
PUBLISHED 2026-05-09 · ~13-MIN READ · WARRANT COMPLIANCE

RBI FREE-AI, line by line.

The Reserve Bank of India's Committee on a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector was chaired by Dr Pushpak Bhattacharyya of IIT Bombay. The Reserve Bank released its report on 13 August 2025. Seven Sutras. Six pillars. Twenty-six recommendations. Advisory in form, unadopted as at 31 July 2026, and the most detailed account yet of what a Reserve Bank committee holds AI governance inside a regulated entity should look like.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to the specific obligations the corpus carries for the regimes in scope — for an Indian regulated entity, RBI FREE-AI and the DPDP Act 2023 — independently verifiable without contacting Warrant.

REPORT
13 August 2025· 7 Sutras · 6 pillars · 26 recs
Committee constituted under the RBI Statement on Developmental and Regulatory Policies dated 6 December 2024. Chaired by Dr Pushpak Bhattacharyya of IIT Bombay. Eight members across academia, government, banking, and technology.
AUTHORITY
RBI · advisory· no adoption instrument
Non-binding as published, and still non-binding: as at 31 July 2026 the RBI had issued no instrument adopting these recommendations. Annexure IV suggests AI-specific enhancements to seven existing Master Directions and circulars — outsourcing of financial services, cyber security, digital lending, customer service, fraud risk management, IT governance, IT services outsourcing.
ALIGNMENT
DPDP Act 2023· cross-references
Recommendation 15 carries the DPDP cross-reference. DPDP itself is on a later clock — assent 11 August 2023, main duties from 14 May 2027 under the DPDP Rules 2025. The report addresses other financial-sector regulators in places (Rec 2 invites other FSRs to collaborate on the sandbox; Rec 22 addresses financial sector regulators generally) but contains no inter-regulator coordination mechanism.
01 · THE PUBLICATION MOMENT

13 August 2025, and what it meant.

The Reserve Bank of India released the Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector on 13 August 2025. The release was announced under press release reference 2025-2026/902. The release closed an arc that started eight months earlier, when the RBI's Statement on Developmental and Regulatory Policies dated 6 December 2024 announced the constitution of a committee to study AI adoption in Indian financial services and recommend a governance framework. The committee was formally constituted on 26 December 2024 under press release 2024-2025/1779.

The publication moment matters in three ways at once. First, it is the RBI's first sector-wide AI framework document, and it arrives into a domestic policy field the report itself maps at §3.2.2: the NITI Aayog National Strategy for Artificial Intelligence and its Principles for Responsible AI, the IndiaAI Mission, and — in the financial sector — a SEBI consultation paper released in 2025 on guidelines for the responsible usage of AI/ML in Indian securities markets. What none of those did was speak to the cross-cutting use-cases banks and NBFCs were already running. FREE-AI names those together and describes a single governance model over them.

Second, FREE-AI lands on top of enabling rails that were already laid. The Digital Personal Data Protection Act 2023 received presidential assent on 11 August 2023; the DPDP Rules followed in 2025. The IndiaAI Mission — the report's name for it at §3.2.2, not "Bharat AI Mission" — was "backed by ₹10,372 crore in the 2024 Union Budget" and launched to develop capabilities, boost research and democratise access to compute infrastructure. The AI Kosh India Datasets Platform sits under that mission; Recommendation 1 proposes integrating the financial-sector data infrastructure with it. We put no launch date on AI Kosh here, because we have not confirmed one against a primary source. The framework reads as the financial-sector layer over these rails, not as a standalone instrument.

Third, and against the grain of how the report is usually summarised, the framework is published into a sector where AI adoption is low and unevenly distributed. Only 20.80% of the 612 entities the Department of Supervision surveyed were using or developing AI systems at all (§3.3.2). The report is not a study of AI at scale in Indian finance. It is a study of why adoption stalled below the largest institutions, written with two surveys behind it, which is why innovation enablement carries equal billing with risk mitigation throughout.

Just under a year on, FREE-AI sits where committee reports usually sit: cited in industry commentary, not codified into binding direction. The gap between recommendation and direction is the operative gap regulated entities now manage.

Using the Sutras as guidance, the Committee recommends an approach that fosters innovation and mitigates risks, treating these two seemingly competing objectives as complementary forces that must be pursued in tandem. FREE-AI Report · executive summary · 13 August 2025
02 · THE COMMITTEE + THE MANDATE

The chair, the mandate, the surveys.

i. To assess the current level of adoption of AI in financial services globally and in India. ii. To review regulatory and supervisory approaches on AI with a focus on the financial sector globally. iii. To identify potential risks associated with AI, if any, and recommend an evaluation, mitigation and monitoring framework and consequent compliance requirements for financial institutions, including banks, NBFCs, FinTechs, PSOs, etc. iv. To recommend a framework including governance aspects for responsible, ethical adoption of AI models/ applications in the Indian financial sector. v. Any other matter related to AI in the Indian financial sector. FREE-AI Report §1.4.1 · terms of reference · 13 August 2025

The roster is at §1.3.1 of the report, and it runs eight names. Dr Pushpak Bhattacharyya, Professor, Department of Computer Science and Engineering, IIT Bombay, as Chairperson. Ms Debjani Ghosh, Distinguished Fellow, NITI Aayog, Independent Director at the Reserve Bank Innovation Hub and former President of NASSCOM. Dr Balaraman Ravindran, Professor and Head, Wadhwani School of Data Science and AI, IIT Madras. Shri Abhishek Singh, Additional Secretary, Ministry of Electronics and Information Technology. Shri Rahul Matthan, Partner, Trilegal. Shri Anjani Rathor, Group Head and Chief Digital Experience Officer, HDFC Bank Ltd. Shri Sree Hari Nagaralu, Head of Security AI Research, Microsoft India (R&D). Shri Suvendu Pati, CGM, FinTech Department, Reserve Bank of India, as Member Secretary. Academia, government, law, banking and technology, with the secretariat inside the RBI's own FinTech Department.

The mandate is five items, not four, and the fifth is a catch-all: assess adoption, review regulatory and supervisory approaches, identify risks and recommend an evaluation-mitigation-monitoring framework, recommend a governance framework, and any other matter related to AI in the Indian financial sector. The report's own structure does not mirror them. Per §1.6.1 the remainder of the report runs three chapters after the introduction: Chapter 2 on the current state of AI adoption and its risks, Chapter 3 on the policy environment and the survey findings, Chapter 4 on the FREE-AI framework itself. The Sutras, the pillars and the twenty-six recommendations all sit in Chapter 4. Methodology is a four-pronged approach at §1.5.1 — stakeholder engagement, surveys and interactions, review of global developments, and analysis of the extant regulatory guidelines — and that is the "four" the mandate is often confused with.

Two surveys sit under the framework, and §3.3.1 gives their shape precisely. The Department of Supervision administered a brief objective survey among 612 supervised entities during February–May 2025 — banks, NBFCs, Asset Reconstruction Companies and All India Financial Institutions, representing close to 90% of the asset size — covering AI usage, technical infrastructure and governance. The FinTech Department ran an in-depth survey of 76 entities during January–May 2025 among select banks and NBFCs representing over 90% of the asset size, extended to select FinTechs and technology companies, then interviewed the CTOs or CDOs of 55 of those 76. Terms of reference item iii names the perimeter the surveys were drawn from: banks, NBFCs, FinTechs and PSOs.

The finding that shaped the framework is the adoption number, and it is low. Per §3.3.2, only 20.80% — 127 of 612 surveyed entities — were either using or developing AI systems. §3.3.3 puts the reason in the tail: no AI usage at all was reported by Tier 1 urban cooperative banks, adoption among Tier 2 and Tier 3 UCBs stayed below 10%, only 27% of the 171 surveyed NBFCs used AI in any manner, and no adoption was observed among Asset Reconstruction Companies. Where larger banks had adopted, it was "largely in the form of simpler rule-based models or early-stage exploration of advanced models". This is not a framework written for a sector saturated with AI. It is written for a sector where adoption is concentrated in the largest institutions and the committee treated the divide itself as the problem.

The FinTech Department, Central Office, provided the secretarial support to the Committee. The two surveys were administered by the Department of Supervision and the FinTech Department, so supervisor-side input is on the record as survey design rather than as drafting consultation — and the framework's tolerant supervisory stance for first-time errors, its emphasis on board-approved policy, and its treatment of the AI inventory as the practical model registry all read that way.

03 · THE 7 SUTRAS

The seven Sutras, verbatim.

The Committee believes that the way ahead must be anchored in a principle-based framework. To this end, the Committee has formulated 7 Sutras - a set of foundational principles that will guide the development, deployment, and governance of AI in the financial sector. FREE-AI Report §4.3.1 · the seven Sutras · 13 August 2025

The seven Sutras are the framework's principles spine. They are the values the framework reads downstream recommendations against. Each Sutra is short, declarative, and written in the tone of a charter rather than a regulation. The list is not aspirational; the framework binds each Sutra to operational recommendations under the six pillars.

Sutra 1
Trust is the Foundation. READING · Public trust in AI systems and in the regulated entities deploying them is the prerequisite, not a downstream metric. Confidence in outcomes and processes is built before scale, not earned after.
Sutra 2
People First. READING · Disclosure of AI usage to the affected party. The individual retains final authority to override an AI decision. Human oversight and consumer interests are paramount; AI augments, never displaces, the named accountable human.
Sutra 3
Innovation over Restraint. READING · Responsible, socially useful innovation takes priority over cautionary restraint. The framework treats innovation enablement and risk mitigation as complementary, not opposed. The supervisor does not reach for prohibition where calibrated supervision is available.
Sutra 4
Fairness and Equity. READING · AI systems are designed and tested to promote fairness, equity, and inclusion. Systemic bias is treated as a measurable property of the deployed system, not a residual to be apologised for after harm has occurred.
Sutra 5
Accountability. READING · Entities deploying AI systems are accountable for the decisions of those systems regardless of the level of autonomy. Responsibility sits with identifiable decision-makers; it does not diffuse into algorithms or vendor stacks.
Sutra 6
Understandable by Design. READING · Decisions are explainable; the design choice is upstream, not bolted on. Black-box outputs in customer-facing decisions are inconsistent with this Sutra on the framework's plain reading.
Sutra 7
Safety, Resilience and Sustainability. READING · Stress-tested for shocks, viable across the system's operational lifetime, and engineered for graceful degradation. Operational risk and model risk are treated as overlapping, not separable.
"At the heart of the FREE-AI framework are the 7 Sutras, the foundational principles which are the living spirit of the framework. […] The recommendations have been carefully crafted to embody and advance the Sutras."FREE-AI Report §4.5.1 · conclusion

Five of the seven Sutras have a direct correspondent in the Warrant evidence schema, and two do not. We state both, because a mapping that claims a field for every principle is the kind of claim an examiner disproves in one request. Trust corresponds to the package being checkable without contacting Warrant, with trace_metadata.regulations_corpus_sha256 pinning the exact corpus version the obligations were read from and trace_metadata.signature_b64 carrying the signature over the package bytes. People First corresponds to authorizations[].human_oversight_appropriate. Accountability corresponds to actions[].actor together with authorizations[].justification — there is no named-officer field in the schema, and the actor string is what the trace supplied. Understandable by Design corresponds to authorizations[].justification and the per-obligation evidence string; there is no alternatives-considered field in the schema, and the actions[] object is closed to additional properties, so one cannot be added by a caller. Safety, Resilience and Sustainability corresponds to classification.risk_tier and classification.risk_tier_justification.

The two without a field are worth naming. Innovation over Restraint is a supervisory posture, not a per-decision artefact, and nothing in an evidence package speaks to it. Fairness and Equity has no dedicated field: the schema carries no cohort-level or bias-test result, and fairness reaches the package only as an obligation row — Warrant's corpus lists bias_testing among the eight FREE-AI obligations, so it appears as an obligations.<action_id>[] entry with a compliance status of satisfied, gap, uncertain or unvalidated and an evidence string, not as a measurement. A correspondence is not a satisfaction: a field exists to carry the answer, and whether the answer is adequate is the examiner's question, not the schema's.

04 · THE 6 PILLARS

The six pillars, twenty-six recommendations.

This is achieved through a unified vision spread across 6 strategic Pillars that address the dimensions of innovation enablement as well as risk mitigation. Under innovation enablement, the focus is on Infrastructure, Policy and Capacity and for risk mitigation, the focus is on Governance, Protection and Assurance. Under these six pillars, the report outlines 26 Recommendations for AI adoption in the financial sector. FREE-AI Report · executive summary · 13 August 2025

The six pillars sit in two halves. Three pillars enable innovation: Infrastructure (the rails on which AI is built), Policy (the rules governing its use), Capacity (the people who build and run it). Three pillars mitigate risk: Governance (board-level oversight), Protection (consumer and cyber safeguards), Assurance (audit and monitoring). The architecture is deliberate. Innovation enablement and risk mitigation are presented as complementary forces rather than tradeoffs to be balanced.

Pillar 1
Infrastructure. READING · The shared rails, Recommendations 1 to 5. Rec 1 establishes a high-quality financial-sector data infrastructure as digital public infrastructure, which "may be integrated with the AI Kosh – India Datasets Platform, established under the IndiaAI Mission". Rec 2 establishes an AI Innovation Sandbox for REs, FinTechs and other innovators, with other financial-sector regulators invited to collaborate. Rec 3 is Incentives and Funding Support for smaller entities. Rec 4 is indigenous financial-sector-specific AI models, "offered as a public good". Rec 5 integrates AI with India's Digital Public Infrastructure. Every one of the five is addressed to regulators, government or industry — none is a control on a regulated entity.
Pillar 2
Policy. READING · The regulatory clarity layer, Recommendations 6 to 9. Rec 6 asks regulators to "periodically undertake an assessment of existing policies and legal frameworks", to develop a comprehensive AI policy framework anchored in the seven Sutras, and adds that "the RBI may consider issuing consolidated AI Guidance to serve as a single point of reference". Rec 7 enables AI-based affirmative action by "lowering compliance expectations as far as is possible, without compromising basic safeguards". Rec 8 is the AI Liability Framework — the graded-liability recommendation read in section 05 below. Rec 9 is the AI Institutional Framework: a permanent multi-stakeholder AI Standing Committee under the RBI, proposed for an initial five years with a built-in review mechanism and a sunset clause.
Pillar 3
Capacity. READING · The people layer, Recommendations 10 to 13. Rec 10 is capacity building within REs; Rec 11 is capacity building for regulators and supervisors; Rec 12 is a framework for sharing best practices; Rec 13 asks regulators to recognise and reward responsible AI innovation. The pillar reads against the supply-side constraint the surveys measured — adoption below 10% among Tier 2 and Tier 3 urban cooperative banks — so that smaller entities are not foreclosed from AI deployment by skill gaps alone.
Pillar 4
Governance. READING · The board pillar, Recommendations 14 to 17. Rec 14 is the board-approved AI policy, covering "governance structure, accountability, risk appetite, operational safeguards, auditability, consumer protection measures, AI disclosures, model life cycle framework, and liability framework", with industry bodies asked to give smaller entities an indicative template. Rec 15 is data lifecycle governance — controls for collection, access, usage, retention and deletion, and the recommendation that carries the DPDP cross-reference. Rec 16 is the AI system governance framework. Rec 17 puts AI-specific risk evaluation inside the institutional product approval process. This pillar, not the Protection pillar, is where the board-level obligations sit.
Pillar 5
Protection. READING · The consumer + cyber pillar, Recommendations 18 to 22. Rec 18 is consumer protection: a board-approved framework prioritising "transparency, fairness, and accessible recourse mechanisms", plus ongoing education campaigns on safe AI usage — consumer education is the second sentence of Rec 18, not a recommendation of its own. Rec 19 is cybersecurity measures. Rec 20 is structured red teaming across the AI lifecycle, proportionate to assessed risk, with trigger-based red teaming for evolving threats. Rec 21 augments business-continuity frameworks for AI model performance degradation, with tested fallback workflows. Rec 22 is the AI incident reporting and sectoral risk intelligence framework. The expansions of existing RBI Master Directions are not recommendations at all — they sit in Annexure IV, read below.
Pillar 6
Assurance. READING · The audit pillar, Recommendations 23 to 26. Rec 23 is the AI inventory within REs plus a sector-wide repository at the regulator. Rec 24 is the AI audit framework, and it has three limbs: (a) internal audits proportionate to risk, (b) independent third-party audits "For high risk or complex AI use cases", (c) periodic review — the audit framework "should be reviewed and updated at least biennially", every two years, not twice a year. Rec 25 is disclosures by REs. Rec 26 is the AI Compliance Toolkit, to be developed and maintained by a recognised SRO or industry body.

The twenty-six recommendations distribute evenly by count — five, four, four, four, five, four — but not by addressee, and the addressee is what matters to a regulated entity. Each recommendation carries its own action-and-timeline tag in the report, and Warrant's corpus records the tally: thirteen of the twenty-six are innovation-enablement measures addressed to the RBI, government, regulators or industry bodies rather than risk controls on regulated entities. The Infrastructure and Policy pillars are almost entirely of that kind — data infrastructure, sandbox, funding, indigenous models, DPI integration, the Standing Committee, the consolidated guidance. The operational load on an RE sits in Governance, Protection and Assurance: the board-approved AI policy (Rec 14), data lifecycle governance (Rec 15), product approval (Rec 17), consumer protection (Rec 18), cybersecurity (Rec 19), red teaming (Rec 20), business continuity (Rec 21), the AI inventory (Rec 23) and the audit framework (Rec 24).

The Master Direction expansions deserve separate emphasis, and they are the single most misreported part of this report. They are not recommendations. They sit in Annexure IV, "AI Specific Enhancements in RBI Master Directions", as suggestions against seven named existing instruments. The vendor-accountability path runs through item 1, the RBI Guidelines on Outsourcing of Financial Services, where the suggestion is that "specific clauses addressing AI specific risks, including algorithmic bias, may be incorporated as applicable into the Outsourcing Agreement", alongside a clause obliging disclosure of AI use by third-party vendors and their subcontractors. The Master Direction on Outsourcing of Information Technology Services (2023) is item 7, and its suggestions are narrower: that service providers disclose use of AI in service delivery under para 16 of Chapter V, and that AI-specific risk assessments be added under Chapter IV. The Indian regulated entity remains the accountable party, and the contract with the vendor is where the accountability terms would land. Annexure IV is where the largest contractual rework sits if the RBI adopts it — and an annexure suggestion is a weaker instrument than a recommendation, which is itself weaker than a direction.

05 · THE SUPERVISORY CYCLE IMPLICATION

What changed between August 2025 and July 2026.

Just under a year sits between FREE-AI's publication and the state of play recorded here. Three observations frame the supervisory cycle implication.

First, as at 31 July 2026 the RBI has issued no instrument adopting these recommendations, and no public RBI enforcement action has cited FREE-AI as a binding obligation. The framework remains advisory. There is no adoption instrument, no direction and no compliance date, and the report's release date of 13 August 2025 is a publication date rather than a commencement date. Codification into Master Directions or circulars is the path through which any of it would become binding.

Second, the framework reads onto existing binding directions even without codification, and Annexure IV is the map of where. It names the seven instruments the committee thought could absorb AI-specific enhancements: the Guidelines on Outsourcing of Financial Services, the Cyber Security Framework in Banks (2016), the Guidelines on Digital Lending dated 2 September 2022, the Master Circular on Customer Service in Banks (2015), the Master Direction on Fraud Risk Management (2024), the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (2023), and the Master Direction on Outsourcing of Information Technology Services (2023). The annexure's middle column is the committee's own account of what those instruments already cover implicitly — accountability for outsourced activities, incident reporting and response mechanisms, board-level oversight of customer service, broad IT governance — and its right-hand column is what it would add to each. The AI inventory at Rec 23 needs no new inspection power to be read: the recommendation itself says the inventory must be made available for supervisory inspections and audits. The framework's operational footprint is larger than its formal status suggests, because much of what it asks for is already implicit in directions the regulated entity already obeys.

Third, the report's RE-facing recommendations are written in binding-sounding modality even though nothing binds. "REs must establish robust data governance frameworks" at Rec 15; "REs must identify potential security risks" at Rec 19; "REs must augment their existing BCP frameworks" at Rec 21. That drafting is why the framework gets summarised as though it were a direction. It is not one, and the modality creates no legal duty. We make no claim here about what examiners have asked in supervisory cycles since publication — we have not surveyed inspection outcomes, and an unsourced assertion about supervisory behaviour is not one this page will make.

The tolerant supervisory stance is Rec 8, the AI Liability Framework, and its conditions are explicit in the text. Graded liability, an accommodative supervisory approach where the RE "has followed appropriate safety mechanisms such as incident reporting, audits, red teaming, etc.", and the stance "limited to first time / one-off aberrations and denied in the event of repeated breaches, gross negligence, or failure to remediate identified issues". Rec 8 also preserves the customer's position: "REs must continue to remain liable for any loss suffered by customers". The leniency is conditional on the safeguards existing and the reporting happening. It is not a substitute for either.

Financial sector regulators should establish a dedicated AI incident reporting framework for REs and FinTechs and encourage timely detection and reporting of AI-related incidents. The framework should adopt a tolerant, good-faith approach to encourage timely disclosure. FREE-AI Report · Recommendation 22 · AI Incident Reporting and Sectoral Risk Intelligence Framework

FREE-AI's practical use is as a forward read on what binding direction would likely contain. An entity that builds to the recommendations before codification has the work already done if and when direction issues. That is a planning judgement about cost and timing, not a legal position, and nothing in the report confers a safe harbour.

06 · SEBI · IRDAI · IFSCA

The cross-regulator perimeter.

India's financial-sector regulatory architecture is plural. The RBI is one of several authorities. The Securities and Exchange Board of India (SEBI) regulates the securities market and asset management. The Insurance Regulatory and Development Authority of India (IRDAI) regulates insurance. The International Financial Services Centres Authority (IFSCA) regulates the GIFT City IFSC. The Pension Fund Regulatory and Development Authority (PFRDA) regulates pension funds. The Ministry of Electronics and Information Technology (MeitY) administers the DPDP Act 2023 and the IndiaAI Mission.

FREE-AI's operative perimeter is RBI-regulated entities: scheduled commercial banks, urban cooperative banks, NBFCs, payment system operators, and entities under the Payment and Settlement Systems Act, 2007. Terms of reference item iii names them as "banks, NBFCs, FinTechs, PSOs, etc.". The framework binds nobody, so the question of whether it binds SEBI-, IRDAI-, IFSCA- or PFRDA-regulated entities does not arise — but the report does address other financial-sector regulators in places, and that is now checkable rather than assumed. Rec 2 says of the innovation sandbox that "Other FSRs should also collaborate to contribute to and benefit from this initiative", and tags the recommendation to "Regulators, RBI, MeitY, FSRs". Rec 22 addresses its incident-reporting duty to "financial sector regulators" generally, not to the RBI alone. What the report does not contain is a coordination mechanism between regulators.

In practice, three overlap patterns matter. Where an entity holds licences across multiple authorities (a banking-cum-insurance distributor; a wealth platform that lends and recommends mutual funds; a neo-broker that holds payment-system authorisation), each regulator's framework applies inside its own perimeter. The AI agent that issues a credit decision under bank licence reads against FREE-AI; the same agent recommending a mutual fund reads against SEBI's AI guidance; the same agent quoting an insurance product reads against IRDAI's posture. The agent does not split; the supervision does.

The IFSCA case is the cleanest. The GIFT City IFSC is regulated under the IFSCA Act 2019, and an entity inside IFSCA jurisdiction obeys IFSCA direction and reads RBI guidance as informational; the entity outside IFSCA but transacting with one obeys its principal supervisor's direction. We make no claim here about IFSCA's own AI sandbox activity, or about IRDAI's InsurTech drafting — neither is verified against those regulators' own instruments, and an unverified one does not go on this page.

The MeitY interface is different. The DPDP Act 2023 is a statutory regime that will bind all entities, including all financial-sector entities, processing the personal data of Indian data principals — its principal obligations commencing 14 May 2027 per Warrant's corpus, so it is enacted but not yet operative on either party. The DPDP Board sits under MeitY. FREE-AI's Rec 15 is the recommendation that carries the cross-reference: the framework defers to the DPDP regime on personal-data questions and overlays AI-governance expectations on top.

The Digital Personal Data Protection (DPDP) Act provides overarching principles for data protection and privacy and REs are obligated to adhere to DPDP Act provisions and operationalise responsible data management. […] REs must establish robust data governance frameworks, including internal controls and policies for data collection, access, usage, retention, and deletion for AI systems. These frameworks should ensure compliance with the applicable legislations, such as the DPDP Act, throughout the data life cycle. FREE-AI Report ¶4.4.47 and Recommendation 15 · Data Lifecycle Governance
07 · IMPLEMENTATION CALENDAR

What FREE-AI says about when.

FREE-AI does not specify binding adoption deadlines. It is a committee report, not a regulation. The framework is presented as a direction of travel rather than a calendar.

The framework does recommend review cadences, and there are exactly three dated ones. The AI inventory under Rec 23 is to be "updated at least half yearly". The audit framework under Rec 24(c) is to be "reviewed and updated at least biennially" — once every two years. Rec 6 asks regulators to "periodically undertake an assessment of existing policies and legal frameworks" without fixing an interval. There is no recommendation directing a biannual review of the framework itself.

The implementation calendar is therefore the regulator's calendar, not the regulated entity's. The RBI will, on the framework's logic, codify recommendations into Master Directions or circulars on its own timetable. The regulated entity's optimal posture is forward-leaning: adopt the framework's recommendations under principles-based interpretation now, treating the as-yet-uncodified recommendations as the most likely shape of forthcoming direction.

The material that reads most directly into existing binding directions is Annexure IV, because it is drafted against named instruments and paragraph numbers — para 5 of the Cyber Security Framework's Cyber Security Policy, para 5 "Disclosures to borrowers" and para 9 of the Digital Lending guidelines, paras 8 and 16 of the Customer Service master circular, Chapter III of the Fraud Risk Management direction, para 19 of the IT Governance direction, Chapters IV and V of the IT Services Outsourcing direction. An entity tracking the gap between framework and direction watches those seven instruments, not a block of recommendation numbers. Amending an existing direction is a smaller act than issuing a new one, which is what makes Annexure IV the cheapest thing on this list for the RBI to do first.

Two items have their own tracks. The AI Innovation Sandbox at Rec 2 would be established by regulators — the recommendation is tagged "Regulators, RBI, MeitY, FSRs, Short term" — and we make no claim about cohort calendars, because no FREE-AI sandbox is on record as operating. The AI Standing Committee at Rec 9 is proposed for an initial five years with a review mechanism and a sunset clause; on whether it has since been constituted we have no verified answer, having not surveyed RBI announcements after publication, so treat that as open rather than answered either way.

08 · WHERE WARRANT MAPS RBI FREE-AI

The FREE-AI field map.

The mapping below is keyed to the report's own recommendation numbers, checked one by one against the report text the RBI serves rather than against commentary. Two things about it need saying before the table.

First, Warrant's regulations corpus maps FREE-AI mostly by theme rather than per numbered recommendation. It carries eight named obligations for this regime — audit_trail_reconstructable, bias_testing, explainability_for_high_impact_decisions, human_oversight_high_risk, third_party_ai_governance, board_level_ai_policy, ai_inventory_at_regulated_entity, consumer_recourse_for_ai_decisions — carried by twenty-six sub-clause entries with ids running rbi_free_ai.rec_1 to rbi_free_ai.rec_26. Those ids are storage keys, not recommendation numbers. Reading the digit in an id as a Recommendation number produces a wrong citation. Twenty-one of the twenty-six say so on their face: "thematic reading of the report; NOT attributable to a single numbered Recommendation". The remaining five carry an express per-Recommendation attribution, and in four of those five the digit in the id is not the Recommendation named — rec_1 names Recommendation 14, rec_2 names Recommendation 23, rec_17 names Recommendation 24, rec_23 names Recommendation 10. One coincides: rec_22 names Recommendation 22. That single agreement is a coincidence of numbering, not a rule anyone can extend. Where a sub-clause names a Recommendation, a row citing that sub-clause inherits the number; for the other twenty-one there is no recommendation number to cite at all.

Second, most FREE-AI expectations have no dedicated schema field, and the table says so where that is the case. obligations is an object keyed by action_id, and each key holds an array of rows: an id that is a corpus sub-clause id echoed back verbatim, a compliance status of satisfied, gap, uncertain or unvalidated, a confidence number and an evidence string. The regime name and the obligation name are not written onto the row — they are read out of the corpus from that id, which is why the id has to be exact. That is the artefact an examiner reads. Naming a bespoke field per recommendation would be a claim the schema does not support.

FREE-AI clause What evidence must show Warrant evidence field
Sutra 1 · Trust Record checkable without trusting the issuer trace_metadata.signature_b64 over the package bytes; trace_metadata.regulations_corpus_sha256 pins the corpus version read
Sutra 2 · People First Human oversight appropriate to the decision authorizations[].human_oversight_appropriate
Sutra 5 · Accountability Named accountable actor per action actions[].actor + authorizations[].justification. No named-officer field; the actor is what the trace supplied
Sutra 6 · Understandable Per-decision rationale authorizations[].justification. No alternatives-considered field, and actions[] is closed to added properties
Sutra 7 · Safety, Resilience Risk tier assessed and reasoned, not asserted classification.risk_tier + classification.risk_tier_justification
Sutra 4 · Fairness Bias testing performed and recorded No field. Reaches the package only as an obligations.<action_id>[] row whose id is an rbi_free_ai sub-clause under the corpus obligation bias_testing, with a compliance status — not as a measurement
Rec 14 · Board-approved AI policy Policy exists and governs the decision No policy-version field. obligations.<action_id>[] id rbi_free_ai.rec_1, the corpus sub-clause for Recommendation 14, under the obligation board_level_ai_policy
Rec 23 · AI inventory Model enumerated in the entity inventory No inventory-id field. obligations.<action_id>[] id rbi_free_ai.rec_2, the corpus sub-clause for Recommendation 23, under the obligation ai_inventory_at_regulated_entity
Rec 22 · Incident reporting Reconstructable trail behind the decision No incident-record field. obligations.<action_id>[] id rbi_free_ai.rec_22, under the obligation audit_trail_reconstructable. Note the duty to establish the reporting framework runs to regulators; Rec 22 is tagged to REs and regulators both
Rec 15 · Data lifecycle / DPDP Lawful basis under the DPDP Act No lawful-basis field. DPDP is a separate regime row: coverage_by_regime["dpdp_2023"], with its own obligations.<action_id>[] entries
Rec 24 · Audit framework Audit trail an internal or third-party auditor can follow No eval-result field. obligations.<action_id>[] id rbi_free_ai.rec_17, the corpus sub-clause for Recommendation 24, under the obligation audit_trail_reconstructable
Annexure IV · Outsourcing Vendor accountability chain, incl. algorithmic bias clauses No provenance field. obligations.<action_id>[] carries an rbi_free_ai sub-clause id under the obligation third_party_ai_governance
Sutra 1
Trust · a record checkable without trusting the issuer. FIELD · trace_metadata.package_id, trace_metadata.timestamp and trace_metadata.signature_b64 carry the identity, time and signature of the package; trace_metadata.regulations_corpus_sha256 pins the exact corpus revision the obligations were read from, so a reader can tell whether the regime text has moved since. A third party checks the package on their own. There is no field attesting an officer's role; the schema carries none.
Sutra 5
Accountability · the actor behind each action. FIELD · actions[].actor names who acted, and authorizations[].justification records why the action was judged authorised, alongside within_purpose, preconditions_met and reversible. Accountability does not diffuse into the agent. But the actor string is whatever the submitted trace supplied, and no field binds it to a regulated officer role, so an entity relying on this for Sutra 5 is relying on its own trace discipline.
Rec 23
AI inventory · maintained at the entity, read on inspection. NO FIELD · Rec 23 requires an inventory of "all models, use cases, target groups, dependencies, risks and grievances", updated at least half yearly and made available for supervisory inspections and audits, plus a sector-wide repository at the regulator with entity details anonymised. The inventory lives at the entity. An evidence package carries the obligation as an obligations.<action_id>[] row with id rbi_free_ai.rec_2 — the corpus sub-clause for Recommendation 23, under the obligation ai_inventory_at_regulated_entity — and a compliance status; it does not carry an inventory identifier, and no per-decision field links a package to a model card.
Rec 22
Incident reporting · a tolerant, good-faith regime. NO FIELD · Rec 22's operative duty runs to regulators — "financial sector regulators should establish a dedicated AI incident reporting framework" — and no such framework exists as at 31 July 2026, so there is nothing to report into. The report also notes that reporting an incident "should not, by itself, trigger penal action if timely corrective measures have been taken and disclosure is complete", and that compensation must be provided where a customer has been adversely impacted. What a package carries is the reconstructable trail: an obligations.<action_id>[] row with id rbi_free_ai.rec_22, under the obligation audit_trail_reconstructable. The leniency at Rec 8 is conditional on safeguards including incident reporting; absence of the safeguards is what removes it.
Rec 15
Data lifecycle governance · the DPDP cross-reference. NO FIELD · Rec 15 requires controls for "data collection, access, usage, retention, and deletion for AI systems" and compliance with applicable legislation "such as the DPDP Act, throughout the data life cycle". Warrant treats DPDP as its own regime rather than as a FREE-AI field: it appears under coverage_by_regime["dpdp_2023"] with its own sub-clause rows, grouped under five corpus obligations — lawful_basis_recorded, purpose_limitation, data_principal_rights_honored, breach_intimation_to_board, processor_agreements_documented. No field records a DPDP section number per decision.
W
Sample Indian evidence package · automated credit underwriting agentSPECIMEN GENERATED 6 MAY 2026 · INDEPENDENTLY VERIFIABLE WITHOUT CONTACTING WARRANT
→ /samples/india-fintech.pdf

Read that specimen for the shape of the record, and read the two paragraphs above for the citations. Its own header records it as generated at 2026-05-06 12:32:22 UTC, against a corpus revision that still attached bare Recommendation numbers to the FREE-AI sub-clauses. Its FREE-AI rows therefore print "Recommendation 14 (Auditability)", "Recommendation 11 (Explainability)", "Recommendation 7 (Bias Mitigation)" and "Recommendation 18 (Human Oversight for High-Risk AI Decisions)" — numbers the report gives to the board-approved AI policy, capacity building for regulators and supervisors, AI-based affirmative action and consumer protection, and which the corpus has since withdrawn. Its DPDP purpose-limitation row prints section 5(1)(a); the corpus carries that obligation at section 6(1). A package generated against the current corpus carries the sub-clause ids set out in the table above.

09 · DPDP ACT 2023

FREE-AI and the DPDP Act, in parallel.

The Digital Personal Data Protection Act 2023 is India's privacy statute, and its timing needs stating precisely because it changes what a regulated entity has to do today. It received presidential assent on 11 August 2023 as Act No. 22 of 2023. Its substantive obligations do not commence on assent: they phase in under the DPDP Rules 2025, and Warrant's corpus records the main duties as applying from 14 May 2027. So on the date this entry was published, DPDP was enacted but its principal obligations were not yet in force, while FREE-AI was published but never binding. Two regimes, two different reasons an entity cannot be penalised under them yet, and neither reason is a reason to build the record later.

The DPDP Act attaches at the personal-data layer, and the section numbers matter. Section 4(1) sets the lawful bases: personal data may be processed only for a lawful purpose, either one for which the data principal has given consent, or one of certain legitimate uses. Section 6(1) then sets the standard of consent — "free, specific, informed, unconditional and unambiguous with a clear affirmative action" — which is a standard, not a lawful basis in itself. Section 7 lists the legitimate uses, and they are narrower than they are usually described: voluntary provision by the data principal, State subsidies and services, performance of a State function, compliance with a legal obligation, compliance with a court order, medical emergency, health services during an epidemic, safety during a disaster, and employment purposes. There is no general "public interest" head. Section 8(5) carries the duty to take reasonable security safeguards to prevent a breach, and section 8(6) — not section 9 — is breach intimation to the Board and to each affected data principal, in the form and manner prescribed; the Act fixes no hour-count, the Rules do. Section 9 is processing of the personal data of children. Section 10 is the additional obligations of a Significant Data Fiduciary, and s.10(2) is where the data protection officer, the independent data auditor, and at s.10(2)(c) the periodic Data Protection Impact Assessment and periodic audit sit — not sections 33 to 37, which are the penalty and Board provisions.

Data-principal rights are four separate sections, not one. Section 11 is the right to access information about personal data — a summary of the data processed and the processing activities, the identities of other fiduciaries and processors it was shared with. Section 12 is correction, completion, updating and erasure. Section 13 is grievance redressal, which a data principal must exhaust before approaching the Board. Section 14 is nomination. The Act confers no right to data portability; that is a GDPR Article 20 right and must not be read into DPDP.

FREE-AI attaches at the AI-governance layer. Recommendation 15 is the one that carries the DPDP cross-reference, requiring data governance frameworks that "ensure compliance with the applicable legislations, such as the DPDP Act, throughout the data life cycle"; the framework does not duplicate the DPDP regime, it defers to it. The framework's other recommendations — the board-approved AI policy at Rec 14, the AI inventory at Rec 23, incident reporting at Rec 22, audit at Rec 24 — overlay AI-governance expectations on top of the personal-data foundation.

The two regimes meet at the per-decision evidence layer. The lawful-basis question under DPDP and the model-decision rationale FREE-AI asks for run off the same trace. One package carries both readings: DPDP sub-clause ids and FREE-AI sub-clause ids sit side by side in the obligations rows for the same action, and coverage_by_regime records separately whether each regime was evaluated at all. Neither reading discharges a duty. FREE-AI imposes none; DPDP's substantive obligations do not commence until 14 May 2027; and a satisfied status is the pipeline's judgement on what the trace contained, not a regulator's.

Cross-border transfer becomes operative when a regulated entity sends personal data to a foreign-headquartered AI provider for inference. Section 16(1) reads: "The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." The mechanism is a negative list, not an adequacy regime — absent a notification, transfer is permitted, subject to the Act's other duties, and s.16(2) preserves any Indian law imposing a higher restriction. An Indian regulated entity using a foreign foundation model on personal data therefore carries the DPDP duties on that flow, and the Annexure IV outsourcing expectations sit alongside them if the RBI adopts them. For European analog reading on cross-border AI evidence, see /blog/eu-ai-act-article-12.

The Data Protection Board and the AI Standing Committee proposed at Rec 9 are separate bodies with different powers. The Board determines breaches on inquiry and imposes penalties tiered by the Schedule under s.33(1), with a ceiling of ₹250 crore for breach of the s.8(5) security-safeguards duty, ₹200 crore for s.8(6) breach intimation and for s.9 children's data, and ₹150 crore for the s.10 Significant Data Fiduciary duties; there is no per-instance multiplier in the Act, and s.33(2) directs the Board to weigh the nature, gravity, duration and repetitiveness of the breach. The Standing Committee, if constituted, would advise the RBI — the recommendation gives it a five-year initial term and a sunset clause — and would carry no enforcement power. Personal-data questions are answered at the Board; AI-governance questions are answered by the RBI, and only through instruments the RBI has actually issued.

10 · THE FAQ + THE SOURCE

Questions a CCO and an RBI examiner ask first.

Is RBI FREE-AI binding?

Not as published. FREE-AI is a committee report. The Committee was announced in the RBI Statement on Developmental and Regulatory Policies dated 6 December 2024, constituted on 26 December 2024 under press release 2024-2025/1779, and its report was released on 13 August 2025 under press release 2025-2026/902. There is no adoption instrument, no direction and no compliance date; the 13 August 2025 date is a publication date, not a commencement date. As at 31 July 2026 the RBI had issued no instrument adopting these recommendations. The report's Annexure IV suggests AI-specific enhancements to seven existing RBI Master Directions and circulars, which is the cheapest codification path open to the RBI. Until something is issued, the recommendations create no legal duty — several RE-facing recommendations are drafted in binding-sounding modality (Rec 15 says REs must establish robust data governance frameworks) but that modality binds nobody.

Does FREE-AI apply to non-bank fintechs?

FREE-AI's terms of reference cover the Indian financial sector. Banks, NBFCs, payment system operators, and other entities regulated by the RBI fall within scope. Non-bank fintechs operating under a regulated partner (BaaS, sponsor-bank arrangements, payment aggregator licensing) inherit the framework through the regulated principal. Where a fintech operates outside RBI licensing entirely, FREE-AI does not bind directly — and it binds nobody in any case — but a partner bank's or NBFC's AI policy reads through to the fintech's models on the third-party outsourcing leg. That leg is not a recommendation. It is Annexure IV item 1, which suggests that clauses addressing AI-specific risks including algorithmic bias may be incorporated as applicable into the Outsourcing Agreement under the RBI Guidelines on Outsourcing of Financial Services, alongside a clause obliging disclosure of AI use by third-party vendors and their subcontractors.

How does FREE-AI relate to the DPDP Act?

The Digital Personal Data Protection Act 2023 is enacted statute; FREE-AI is committee guidance that binds nobody. They run in parallel, but on different clocks: DPDP received assent on 11 August 2023 while its substantive obligations phase in under the DPDP Rules 2025, with the main duties applying from 14 May 2027 per Warrant's corpus. DPDP attaches to the personal-data leg of any AI-driven decision — lawful basis under s.4(1), the consent standard at s.6(1), purpose limitation, security safeguards at s.8(5), breach intimation at s.8(6), and data-principal rights at ss.11 to 14. FREE-AI attaches to the model-governance leg: the board-approved AI policy at Rec 14, data lifecycle governance at Rec 15, incident reporting at Rec 22, the AI inventory at Rec 23, audit at Rec 24. Rec 15 is the recommendation carrying the DPDP cross-reference, requiring data governance frameworks that ensure compliance with applicable legislation such as the DPDP Act throughout the data life cycle.

What is the difference between FREE-AI and SEBI's AI guidance?

FREE-AI is RBI's framework for the banking, NBFC, and payment-system perimeter. SEBI's AI work runs in parallel for the securities market. The FREE-AI report itself records at §3.2.2 that SEBI released a consultation paper in 2025 on guidelines for the responsible usage of AI/ML in Indian securities markets. Separately, Warrant's corpus carries the SEBI Retail Algorithmic Trading Framework as the Safer Participation circular of February 2025, whose glide path was reset by circular SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/132 of 30 September 2025 and became fully applicable to all stock brokers on 1 April 2026. No other SEBI artefact is named here. Where an AI agent crosses both perimeters (a wealth platform that lends and recommends mutual funds; a neo-broker that holds a payment-system licence) both frameworks attach. The Sutras and pillars under FREE-AI overlap conceptually with SEBI's principles-based guidance but are not identical text. Counsel reading both should treat each AI use-case as in scope for the supervisor whose perimeter it sits inside. One record built to the higher bar can be read by either supervisor, which is not the same as discharging a duty to either.

Has the RBI cited FREE-AI in any enforcement action since publication?

No. As at 31 July 2026 the RBI had issued no instrument adopting these recommendations, and no public RBI enforcement action has cited FREE-AI as a binding obligation. The framework remains advisory. The RBI press release of 13 August 2025 says only that the committee has submitted its report and that it is being placed on the RBI website — it does not adopt the report. Several recommendations do read onto instruments that already bind. Annexure IV names both the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (2023) and the Cyber Security Framework in Banks (2016), and records in its own middle column what the committee thought each already covers implicitly — broad IT governance and oversight of information systems in the first, incident reporting and response mechanisms in the second. What the annexure adds against them is drafted as a suggestion, not a duty. Regulated entities should track the gap between recommendation and direction, since that gap is where the next round of circulars would land.

Does FREE-AI require model registration?

Recommendation 23 asks regulated entities to maintain a comprehensive internal AI inventory covering all models, use cases, target groups, dependencies, risks and grievances, updated at least half yearly, made available for supervisory inspections and audits. That is the operational analogue of model registration, and it is a recommendation, not a requirement. Rec 23 also asks regulators to establish a sector-wide AI repository tracking adoption trends, concentration risks and systemic vulnerabilities, with entity details anonymised — so there is a proposed central repository, but it is anonymised and sits at the regulator, not a registry each entity files into. Recommendation 25 separately asks for AI-related disclosures in REs annual reports and websites, which is the public-facing leg of the same accountability principle.

What does Understandable by Design mean for an LLM-driven decision?

Understandable by Design is the sixth Sutra. The principle is that AI systems should be designed and operated such that their decisions can be examined, challenged, and explained to the affected party. For a deterministic linear model, the explanation is the coefficients and the input values. For an LLM-driven decision, the explanation is the chain of tool calls, retrievals, and reasoning steps that produced the output, plus the rationale for the chosen action. In a Warrant evidence package that rationale is authorizations[].justification, recorded per action alongside within_purpose, preconditions_met, human_oversight_appropriate and reversible. There is no alternatives-considered field in the schema, and the actions[] object is closed to additional properties, so a caller cannot add one. Black-box LLM output with no reconstructable trail does not satisfy this Sutra on the framework's plain reading.

How does FREE-AI handle foreign-headquartered AI providers?

The vendor path is Annexure IV, not a recommendation — Recommendation 18 is consumer protection. Annexure IV item 1 suggests that clauses addressing AI-specific risks including algorithmic bias may be incorporated as applicable into the Outsourcing Agreement under the RBI Guidelines on Outsourcing of Financial Services. Item 7 addresses the Master Direction on Outsourcing of Information Technology Services (2023) and suggests that service providers disclose use of AI in service delivery under para 16 of Chapter V, and that AI-specific risk assessments be added under Chapter IV. Foreign-headquartered foundation-model providers supplying AI services to Indian regulated entities sit on that outsourcing leg. The regulated entity remains the accountable party on the report's own logic at Rec 8, which recommends graded liability while stating that REs must continue to remain liable for any loss suffered by customers, and would have to hold the vendor to the same Sutra-aligned standard it is held to. Vendor model cards and system cards address part of the development-side question but do not displace the Indian regulated entity's accountability. The DPDP Act 2023 cross-border transfer rules attach in parallel where personal data flows to the vendor.

Read the source directly.

Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. References to FREE-AI reflect the Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector dated 13 August 2025; the framework remains advisory pending RBI codification into Master Directions or circulars.

Provenance of every citation on this page. Each recommendation number, section reference and quoted passage was checked against the report text served at the RBI publication page for the report, retrieved 7 August 2026 at 197,518 characters; a perturbed publication identifier on the same host returned a page carrying no FREE-AI content at all, which is the control that makes the retrieval provable rather than merely successful. The two press-release numbers were read off the releases themselves: 2024-2025/1779 at prid=59377 for the committee's constitution on 26 December 2024, and 2025-2026/902 at prid=61018 for the report's release on 13 August 2025, the latter recording only that the committee "has since submitted its report and the same is being placed on the RBI website". DPDP references were checked against the MeitY canonical PDF. One caution on probing this material yourself: rbidocs.rbi.org.in serves a JavaScript bot interstitial to a plain request and returns HTTP 200 to a fabricated filename as readily as to the real one, so a status code on that host proves nothing about whether a document exists.