13 August 2025, and what it meant.
The Reserve Bank of India released the Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector on 13 August 2025. The release was announced under press release reference 2025-2026/902. The release closed an arc that started eight months earlier, when the RBI's Statement on Developmental and Regulatory Policies dated 6 December 2024 announced the constitution of a committee to study AI adoption in Indian financial services and recommend a governance framework. The committee was formally constituted on 26 December 2024 under press release 2024-2025/1779.
The publication moment matters in three ways at once. First, it is the RBI's first sector-wide AI framework document, and it arrives into a domestic policy field the report itself maps at §3.2.2: the NITI Aayog National Strategy for Artificial Intelligence and its Principles for Responsible AI, the IndiaAI Mission, and — in the financial sector — a SEBI consultation paper released in 2025 on guidelines for the responsible usage of AI/ML in Indian securities markets. What none of those did was speak to the cross-cutting use-cases banks and NBFCs were already running. FREE-AI names those together and describes a single governance model over them.
Second, FREE-AI lands on top of enabling rails that were already laid. The Digital Personal Data Protection Act 2023 received presidential assent on 11 August 2023; the DPDP Rules followed in 2025. The IndiaAI Mission — the report's name for it at §3.2.2, not "Bharat AI Mission" — was "backed by ₹10,372 crore in the 2024 Union Budget" and launched to develop capabilities, boost research and democratise access to compute infrastructure. The AI Kosh India Datasets Platform sits under that mission; Recommendation 1 proposes integrating the financial-sector data infrastructure with it. We put no launch date on AI Kosh here, because we have not confirmed one against a primary source. The framework reads as the financial-sector layer over these rails, not as a standalone instrument.
Third, and against the grain of how the report is usually summarised, the framework is published into a sector where AI adoption is low and unevenly distributed. Only 20.80% of the 612 entities the Department of Supervision surveyed were using or developing AI systems at all (§3.3.2). The report is not a study of AI at scale in Indian finance. It is a study of why adoption stalled below the largest institutions, written with two surveys behind it, which is why innovation enablement carries equal billing with risk mitigation throughout.
Just under a year on, FREE-AI sits where committee reports usually sit: cited in industry commentary, not codified into binding direction. The gap between recommendation and direction is the operative gap regulated entities now manage.
The chair, the mandate, the surveys.
The roster is at §1.3.1 of the report, and it runs eight names. Dr Pushpak Bhattacharyya, Professor, Department of Computer Science and Engineering, IIT Bombay, as Chairperson. Ms Debjani Ghosh, Distinguished Fellow, NITI Aayog, Independent Director at the Reserve Bank Innovation Hub and former President of NASSCOM. Dr Balaraman Ravindran, Professor and Head, Wadhwani School of Data Science and AI, IIT Madras. Shri Abhishek Singh, Additional Secretary, Ministry of Electronics and Information Technology. Shri Rahul Matthan, Partner, Trilegal. Shri Anjani Rathor, Group Head and Chief Digital Experience Officer, HDFC Bank Ltd. Shri Sree Hari Nagaralu, Head of Security AI Research, Microsoft India (R&D). Shri Suvendu Pati, CGM, FinTech Department, Reserve Bank of India, as Member Secretary. Academia, government, law, banking and technology, with the secretariat inside the RBI's own FinTech Department.
The mandate is five items, not four, and the fifth is a catch-all: assess adoption, review regulatory and supervisory approaches, identify risks and recommend an evaluation-mitigation-monitoring framework, recommend a governance framework, and any other matter related to AI in the Indian financial sector. The report's own structure does not mirror them. Per §1.6.1 the remainder of the report runs three chapters after the introduction: Chapter 2 on the current state of AI adoption and its risks, Chapter 3 on the policy environment and the survey findings, Chapter 4 on the FREE-AI framework itself. The Sutras, the pillars and the twenty-six recommendations all sit in Chapter 4. Methodology is a four-pronged approach at §1.5.1 — stakeholder engagement, surveys and interactions, review of global developments, and analysis of the extant regulatory guidelines — and that is the "four" the mandate is often confused with.
Two surveys sit under the framework, and §3.3.1 gives their shape precisely. The Department of Supervision administered a brief objective survey among 612 supervised entities during February–May 2025 — banks, NBFCs, Asset Reconstruction Companies and All India Financial Institutions, representing close to 90% of the asset size — covering AI usage, technical infrastructure and governance. The FinTech Department ran an in-depth survey of 76 entities during January–May 2025 among select banks and NBFCs representing over 90% of the asset size, extended to select FinTechs and technology companies, then interviewed the CTOs or CDOs of 55 of those 76. Terms of reference item iii names the perimeter the surveys were drawn from: banks, NBFCs, FinTechs and PSOs.
The finding that shaped the framework is the adoption number, and it is low. Per §3.3.2, only 20.80% — 127 of 612 surveyed entities — were either using or developing AI systems. §3.3.3 puts the reason in the tail: no AI usage at all was reported by Tier 1 urban cooperative banks, adoption among Tier 2 and Tier 3 UCBs stayed below 10%, only 27% of the 171 surveyed NBFCs used AI in any manner, and no adoption was observed among Asset Reconstruction Companies. Where larger banks had adopted, it was "largely in the form of simpler rule-based models or early-stage exploration of advanced models". This is not a framework written for a sector saturated with AI. It is written for a sector where adoption is concentrated in the largest institutions and the committee treated the divide itself as the problem.
The FinTech Department, Central Office, provided the secretarial support to the Committee. The two surveys were administered by the Department of Supervision and the FinTech Department, so supervisor-side input is on the record as survey design rather than as drafting consultation — and the framework's tolerant supervisory stance for first-time errors, its emphasis on board-approved policy, and its treatment of the AI inventory as the practical model registry all read that way.
The seven Sutras, verbatim.
The seven Sutras are the framework's principles spine. They are the values the framework reads downstream recommendations against. Each Sutra is short, declarative, and written in the tone of a charter rather than a regulation. The list is not aspirational; the framework binds each Sutra to operational recommendations under the six pillars.
Five of the seven Sutras have a direct correspondent in the Warrant evidence schema, and two do not. We state both, because a mapping that claims a field for every principle is the kind of claim an examiner disproves in one request. Trust corresponds to the package being checkable without contacting Warrant, with trace_metadata.regulations_corpus_sha256 pinning the exact corpus version the obligations were read from and trace_metadata.signature_b64 carrying the signature over the package bytes. People First corresponds to authorizations[].human_oversight_appropriate. Accountability corresponds to actions[].actor together with authorizations[].justification — there is no named-officer field in the schema, and the actor string is what the trace supplied. Understandable by Design corresponds to authorizations[].justification and the per-obligation evidence string; there is no alternatives-considered field in the schema, and the actions[] object is closed to additional properties, so one cannot be added by a caller. Safety, Resilience and Sustainability corresponds to classification.risk_tier and classification.risk_tier_justification.
The two without a field are worth naming. Innovation over Restraint is a supervisory posture, not a per-decision artefact, and nothing in an evidence package speaks to it. Fairness and Equity has no dedicated field: the schema carries no cohort-level or bias-test result, and fairness reaches the package only as an obligation row — Warrant's corpus lists bias_testing among the eight FREE-AI obligations, so it appears as an obligations.<action_id>[] entry with a compliance status of satisfied, gap, uncertain or unvalidated and an evidence string, not as a measurement. A correspondence is not a satisfaction: a field exists to carry the answer, and whether the answer is adequate is the examiner's question, not the schema's.
The six pillars, twenty-six recommendations.
The six pillars sit in two halves. Three pillars enable innovation: Infrastructure (the rails on which AI is built), Policy (the rules governing its use), Capacity (the people who build and run it). Three pillars mitigate risk: Governance (board-level oversight), Protection (consumer and cyber safeguards), Assurance (audit and monitoring). The architecture is deliberate. Innovation enablement and risk mitigation are presented as complementary forces rather than tradeoffs to be balanced.
The twenty-six recommendations distribute evenly by count — five, four, four, four, five, four — but not by addressee, and the addressee is what matters to a regulated entity. Each recommendation carries its own action-and-timeline tag in the report, and Warrant's corpus records the tally: thirteen of the twenty-six are innovation-enablement measures addressed to the RBI, government, regulators or industry bodies rather than risk controls on regulated entities. The Infrastructure and Policy pillars are almost entirely of that kind — data infrastructure, sandbox, funding, indigenous models, DPI integration, the Standing Committee, the consolidated guidance. The operational load on an RE sits in Governance, Protection and Assurance: the board-approved AI policy (Rec 14), data lifecycle governance (Rec 15), product approval (Rec 17), consumer protection (Rec 18), cybersecurity (Rec 19), red teaming (Rec 20), business continuity (Rec 21), the AI inventory (Rec 23) and the audit framework (Rec 24).
The Master Direction expansions deserve separate emphasis, and they are the single most misreported part of this report. They are not recommendations. They sit in Annexure IV, "AI Specific Enhancements in RBI Master Directions", as suggestions against seven named existing instruments. The vendor-accountability path runs through item 1, the RBI Guidelines on Outsourcing of Financial Services, where the suggestion is that "specific clauses addressing AI specific risks, including algorithmic bias, may be incorporated as applicable into the Outsourcing Agreement", alongside a clause obliging disclosure of AI use by third-party vendors and their subcontractors. The Master Direction on Outsourcing of Information Technology Services (2023) is item 7, and its suggestions are narrower: that service providers disclose use of AI in service delivery under para 16 of Chapter V, and that AI-specific risk assessments be added under Chapter IV. The Indian regulated entity remains the accountable party, and the contract with the vendor is where the accountability terms would land. Annexure IV is where the largest contractual rework sits if the RBI adopts it — and an annexure suggestion is a weaker instrument than a recommendation, which is itself weaker than a direction.
What changed between August 2025 and July 2026.
Just under a year sits between FREE-AI's publication and the state of play recorded here. Three observations frame the supervisory cycle implication.
First, as at 31 July 2026 the RBI has issued no instrument adopting these recommendations, and no public RBI enforcement action has cited FREE-AI as a binding obligation. The framework remains advisory. There is no adoption instrument, no direction and no compliance date, and the report's release date of 13 August 2025 is a publication date rather than a commencement date. Codification into Master Directions or circulars is the path through which any of it would become binding.
Second, the framework reads onto existing binding directions even without codification, and Annexure IV is the map of where. It names the seven instruments the committee thought could absorb AI-specific enhancements: the Guidelines on Outsourcing of Financial Services, the Cyber Security Framework in Banks (2016), the Guidelines on Digital Lending dated 2 September 2022, the Master Circular on Customer Service in Banks (2015), the Master Direction on Fraud Risk Management (2024), the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (2023), and the Master Direction on Outsourcing of Information Technology Services (2023). The annexure's middle column is the committee's own account of what those instruments already cover implicitly — accountability for outsourced activities, incident reporting and response mechanisms, board-level oversight of customer service, broad IT governance — and its right-hand column is what it would add to each. The AI inventory at Rec 23 needs no new inspection power to be read: the recommendation itself says the inventory must be made available for supervisory inspections and audits. The framework's operational footprint is larger than its formal status suggests, because much of what it asks for is already implicit in directions the regulated entity already obeys.
Third, the report's RE-facing recommendations are written in binding-sounding modality even though nothing binds. "REs must establish robust data governance frameworks" at Rec 15; "REs must identify potential security risks" at Rec 19; "REs must augment their existing BCP frameworks" at Rec 21. That drafting is why the framework gets summarised as though it were a direction. It is not one, and the modality creates no legal duty. We make no claim here about what examiners have asked in supervisory cycles since publication — we have not surveyed inspection outcomes, and an unsourced assertion about supervisory behaviour is not one this page will make.
The tolerant supervisory stance is Rec 8, the AI Liability Framework, and its conditions are explicit in the text. Graded liability, an accommodative supervisory approach where the RE "has followed appropriate safety mechanisms such as incident reporting, audits, red teaming, etc.", and the stance "limited to first time / one-off aberrations and denied in the event of repeated breaches, gross negligence, or failure to remediate identified issues". Rec 8 also preserves the customer's position: "REs must continue to remain liable for any loss suffered by customers". The leniency is conditional on the safeguards existing and the reporting happening. It is not a substitute for either.
FREE-AI's practical use is as a forward read on what binding direction would likely contain. An entity that builds to the recommendations before codification has the work already done if and when direction issues. That is a planning judgement about cost and timing, not a legal position, and nothing in the report confers a safe harbour.
The cross-regulator perimeter.
India's financial-sector regulatory architecture is plural. The RBI is one of several authorities. The Securities and Exchange Board of India (SEBI) regulates the securities market and asset management. The Insurance Regulatory and Development Authority of India (IRDAI) regulates insurance. The International Financial Services Centres Authority (IFSCA) regulates the GIFT City IFSC. The Pension Fund Regulatory and Development Authority (PFRDA) regulates pension funds. The Ministry of Electronics and Information Technology (MeitY) administers the DPDP Act 2023 and the IndiaAI Mission.
FREE-AI's operative perimeter is RBI-regulated entities: scheduled commercial banks, urban cooperative banks, NBFCs, payment system operators, and entities under the Payment and Settlement Systems Act, 2007. Terms of reference item iii names them as "banks, NBFCs, FinTechs, PSOs, etc.". The framework binds nobody, so the question of whether it binds SEBI-, IRDAI-, IFSCA- or PFRDA-regulated entities does not arise — but the report does address other financial-sector regulators in places, and that is now checkable rather than assumed. Rec 2 says of the innovation sandbox that "Other FSRs should also collaborate to contribute to and benefit from this initiative", and tags the recommendation to "Regulators, RBI, MeitY, FSRs". Rec 22 addresses its incident-reporting duty to "financial sector regulators" generally, not to the RBI alone. What the report does not contain is a coordination mechanism between regulators.
In practice, three overlap patterns matter. Where an entity holds licences across multiple authorities (a banking-cum-insurance distributor; a wealth platform that lends and recommends mutual funds; a neo-broker that holds payment-system authorisation), each regulator's framework applies inside its own perimeter. The AI agent that issues a credit decision under bank licence reads against FREE-AI; the same agent recommending a mutual fund reads against SEBI's AI guidance; the same agent quoting an insurance product reads against IRDAI's posture. The agent does not split; the supervision does.
The IFSCA case is the cleanest. The GIFT City IFSC is regulated under the IFSCA Act 2019, and an entity inside IFSCA jurisdiction obeys IFSCA direction and reads RBI guidance as informational; the entity outside IFSCA but transacting with one obeys its principal supervisor's direction. We make no claim here about IFSCA's own AI sandbox activity, or about IRDAI's InsurTech drafting — neither is verified against those regulators' own instruments, and an unverified one does not go on this page.
The MeitY interface is different. The DPDP Act 2023 is a statutory regime that will bind all entities, including all financial-sector entities, processing the personal data of Indian data principals — its principal obligations commencing 14 May 2027 per Warrant's corpus, so it is enacted but not yet operative on either party. The DPDP Board sits under MeitY. FREE-AI's Rec 15 is the recommendation that carries the cross-reference: the framework defers to the DPDP regime on personal-data questions and overlays AI-governance expectations on top.
What FREE-AI says about when.
FREE-AI does not specify binding adoption deadlines. It is a committee report, not a regulation. The framework is presented as a direction of travel rather than a calendar.
The framework does recommend review cadences, and there are exactly three dated ones. The AI inventory under Rec 23 is to be "updated at least half yearly". The audit framework under Rec 24(c) is to be "reviewed and updated at least biennially" — once every two years. Rec 6 asks regulators to "periodically undertake an assessment of existing policies and legal frameworks" without fixing an interval. There is no recommendation directing a biannual review of the framework itself.
The implementation calendar is therefore the regulator's calendar, not the regulated entity's. The RBI will, on the framework's logic, codify recommendations into Master Directions or circulars on its own timetable. The regulated entity's optimal posture is forward-leaning: adopt the framework's recommendations under principles-based interpretation now, treating the as-yet-uncodified recommendations as the most likely shape of forthcoming direction.
The material that reads most directly into existing binding directions is Annexure IV, because it is drafted against named instruments and paragraph numbers — para 5 of the Cyber Security Framework's Cyber Security Policy, para 5 "Disclosures to borrowers" and para 9 of the Digital Lending guidelines, paras 8 and 16 of the Customer Service master circular, Chapter III of the Fraud Risk Management direction, para 19 of the IT Governance direction, Chapters IV and V of the IT Services Outsourcing direction. An entity tracking the gap between framework and direction watches those seven instruments, not a block of recommendation numbers. Amending an existing direction is a smaller act than issuing a new one, which is what makes Annexure IV the cheapest thing on this list for the RBI to do first.
Two items have their own tracks. The AI Innovation Sandbox at Rec 2 would be established by regulators — the recommendation is tagged "Regulators, RBI, MeitY, FSRs, Short term" — and we make no claim about cohort calendars, because no FREE-AI sandbox is on record as operating. The AI Standing Committee at Rec 9 is proposed for an initial five years with a review mechanism and a sunset clause; on whether it has since been constituted we have no verified answer, having not surveyed RBI announcements after publication, so treat that as open rather than answered either way.
The FREE-AI field map.
The mapping below is keyed to the report's own recommendation numbers, checked one by one against the report text the RBI serves rather than against commentary. Two things about it need saying before the table.
First, Warrant's regulations corpus maps FREE-AI mostly by theme rather than per numbered recommendation. It carries eight named obligations for this regime — audit_trail_reconstructable, bias_testing, explainability_for_high_impact_decisions, human_oversight_high_risk, third_party_ai_governance, board_level_ai_policy, ai_inventory_at_regulated_entity, consumer_recourse_for_ai_decisions — carried by twenty-six sub-clause entries with ids running rbi_free_ai.rec_1 to rbi_free_ai.rec_26. Those ids are storage keys, not recommendation numbers. Reading the digit in an id as a Recommendation number produces a wrong citation. Twenty-one of the twenty-six say so on their face: "thematic reading of the report; NOT attributable to a single numbered Recommendation". The remaining five carry an express per-Recommendation attribution, and in four of those five the digit in the id is not the Recommendation named — rec_1 names Recommendation 14, rec_2 names Recommendation 23, rec_17 names Recommendation 24, rec_23 names Recommendation 10. One coincides: rec_22 names Recommendation 22. That single agreement is a coincidence of numbering, not a rule anyone can extend. Where a sub-clause names a Recommendation, a row citing that sub-clause inherits the number; for the other twenty-one there is no recommendation number to cite at all.
Second, most FREE-AI expectations have no dedicated schema field, and the table says so where that is the case. obligations is an object keyed by action_id, and each key holds an array of rows: an id that is a corpus sub-clause id echoed back verbatim, a compliance status of satisfied, gap, uncertain or unvalidated, a confidence number and an evidence string. The regime name and the obligation name are not written onto the row — they are read out of the corpus from that id, which is why the id has to be exact. That is the artefact an examiner reads. Naming a bespoke field per recommendation would be a claim the schema does not support.
| FREE-AI clause | What evidence must show | Warrant evidence field |
|---|---|---|
| Sutra 1 · Trust | Record checkable without trusting the issuer | trace_metadata.signature_b64 over the package bytes; trace_metadata.regulations_corpus_sha256 pins the corpus version read |
| Sutra 2 · People First | Human oversight appropriate to the decision | authorizations[].human_oversight_appropriate |
| Sutra 5 · Accountability | Named accountable actor per action | actions[].actor + authorizations[].justification. No named-officer field; the actor is what the trace supplied |
| Sutra 6 · Understandable | Per-decision rationale | authorizations[].justification. No alternatives-considered field, and actions[] is closed to added properties |
| Sutra 7 · Safety, Resilience | Risk tier assessed and reasoned, not asserted | classification.risk_tier + classification.risk_tier_justification |
| Sutra 4 · Fairness | Bias testing performed and recorded | No field. Reaches the package only as an obligations.<action_id>[] row whose id is an rbi_free_ai sub-clause under the corpus obligation bias_testing, with a compliance status — not as a measurement |
| Rec 14 · Board-approved AI policy | Policy exists and governs the decision | No policy-version field. obligations.<action_id>[] id rbi_free_ai.rec_1, the corpus sub-clause for Recommendation 14, under the obligation board_level_ai_policy |
| Rec 23 · AI inventory | Model enumerated in the entity inventory | No inventory-id field. obligations.<action_id>[] id rbi_free_ai.rec_2, the corpus sub-clause for Recommendation 23, under the obligation ai_inventory_at_regulated_entity |
| Rec 22 · Incident reporting | Reconstructable trail behind the decision | No incident-record field. obligations.<action_id>[] id rbi_free_ai.rec_22, under the obligation audit_trail_reconstructable. Note the duty to establish the reporting framework runs to regulators; Rec 22 is tagged to REs and regulators both |
| Rec 15 · Data lifecycle / DPDP | Lawful basis under the DPDP Act | No lawful-basis field. DPDP is a separate regime row: coverage_by_regime["dpdp_2023"], with its own obligations.<action_id>[] entries |
| Rec 24 · Audit framework | Audit trail an internal or third-party auditor can follow | No eval-result field. obligations.<action_id>[] id rbi_free_ai.rec_17, the corpus sub-clause for Recommendation 24, under the obligation audit_trail_reconstructable |
| Annexure IV · Outsourcing | Vendor accountability chain, incl. algorithmic bias clauses | No provenance field. obligations.<action_id>[] carries an rbi_free_ai sub-clause id under the obligation third_party_ai_governance |
Read that specimen for the shape of the record, and read the two paragraphs above for the citations. Its own header records it as generated at 2026-05-06 12:32:22 UTC, against a corpus revision that still attached bare Recommendation numbers to the FREE-AI sub-clauses. Its FREE-AI rows therefore print "Recommendation 14 (Auditability)", "Recommendation 11 (Explainability)", "Recommendation 7 (Bias Mitigation)" and "Recommendation 18 (Human Oversight for High-Risk AI Decisions)" — numbers the report gives to the board-approved AI policy, capacity building for regulators and supervisors, AI-based affirmative action and consumer protection, and which the corpus has since withdrawn. Its DPDP purpose-limitation row prints section 5(1)(a); the corpus carries that obligation at section 6(1). A package generated against the current corpus carries the sub-clause ids set out in the table above.
FREE-AI and the DPDP Act, in parallel.
The Digital Personal Data Protection Act 2023 is India's privacy statute, and its timing needs stating precisely because it changes what a regulated entity has to do today. It received presidential assent on 11 August 2023 as Act No. 22 of 2023. Its substantive obligations do not commence on assent: they phase in under the DPDP Rules 2025, and Warrant's corpus records the main duties as applying from 14 May 2027. So on the date this entry was published, DPDP was enacted but its principal obligations were not yet in force, while FREE-AI was published but never binding. Two regimes, two different reasons an entity cannot be penalised under them yet, and neither reason is a reason to build the record later.
The DPDP Act attaches at the personal-data layer, and the section numbers matter. Section 4(1) sets the lawful bases: personal data may be processed only for a lawful purpose, either one for which the data principal has given consent, or one of certain legitimate uses. Section 6(1) then sets the standard of consent — "free, specific, informed, unconditional and unambiguous with a clear affirmative action" — which is a standard, not a lawful basis in itself. Section 7 lists the legitimate uses, and they are narrower than they are usually described: voluntary provision by the data principal, State subsidies and services, performance of a State function, compliance with a legal obligation, compliance with a court order, medical emergency, health services during an epidemic, safety during a disaster, and employment purposes. There is no general "public interest" head. Section 8(5) carries the duty to take reasonable security safeguards to prevent a breach, and section 8(6) — not section 9 — is breach intimation to the Board and to each affected data principal, in the form and manner prescribed; the Act fixes no hour-count, the Rules do. Section 9 is processing of the personal data of children. Section 10 is the additional obligations of a Significant Data Fiduciary, and s.10(2) is where the data protection officer, the independent data auditor, and at s.10(2)(c) the periodic Data Protection Impact Assessment and periodic audit sit — not sections 33 to 37, which are the penalty and Board provisions.
Data-principal rights are four separate sections, not one. Section 11 is the right to access information about personal data — a summary of the data processed and the processing activities, the identities of other fiduciaries and processors it was shared with. Section 12 is correction, completion, updating and erasure. Section 13 is grievance redressal, which a data principal must exhaust before approaching the Board. Section 14 is nomination. The Act confers no right to data portability; that is a GDPR Article 20 right and must not be read into DPDP.
FREE-AI attaches at the AI-governance layer. Recommendation 15 is the one that carries the DPDP cross-reference, requiring data governance frameworks that "ensure compliance with the applicable legislations, such as the DPDP Act, throughout the data life cycle"; the framework does not duplicate the DPDP regime, it defers to it. The framework's other recommendations — the board-approved AI policy at Rec 14, the AI inventory at Rec 23, incident reporting at Rec 22, audit at Rec 24 — overlay AI-governance expectations on top of the personal-data foundation.
The two regimes meet at the per-decision evidence layer. The lawful-basis question under DPDP and the model-decision rationale FREE-AI asks for run off the same trace. One package carries both readings: DPDP sub-clause ids and FREE-AI sub-clause ids sit side by side in the obligations rows for the same action, and coverage_by_regime records separately whether each regime was evaluated at all. Neither reading discharges a duty. FREE-AI imposes none; DPDP's substantive obligations do not commence until 14 May 2027; and a satisfied status is the pipeline's judgement on what the trace contained, not a regulator's.
Cross-border transfer becomes operative when a regulated entity sends personal data to a foreign-headquartered AI provider for inference. Section 16(1) reads: "The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." The mechanism is a negative list, not an adequacy regime — absent a notification, transfer is permitted, subject to the Act's other duties, and s.16(2) preserves any Indian law imposing a higher restriction. An Indian regulated entity using a foreign foundation model on personal data therefore carries the DPDP duties on that flow, and the Annexure IV outsourcing expectations sit alongside them if the RBI adopts them. For European analog reading on cross-border AI evidence, see /blog/eu-ai-act-article-12.
The Data Protection Board and the AI Standing Committee proposed at Rec 9 are separate bodies with different powers. The Board determines breaches on inquiry and imposes penalties tiered by the Schedule under s.33(1), with a ceiling of ₹250 crore for breach of the s.8(5) security-safeguards duty, ₹200 crore for s.8(6) breach intimation and for s.9 children's data, and ₹150 crore for the s.10 Significant Data Fiduciary duties; there is no per-instance multiplier in the Act, and s.33(2) directs the Board to weigh the nature, gravity, duration and repetitiveness of the breach. The Standing Committee, if constituted, would advise the RBI — the recommendation gives it a five-year initial term and a sunset clause — and would carry no enforcement power. Personal-data questions are answered at the Board; AI-governance questions are answered by the RBI, and only through instruments the RBI has actually issued.
Questions a CCO and an RBI examiner ask first.
Read the source directly.
- FREE-AI Committee Report PDF · rbidocs.rbi.org.in · 13 August 2025
- FREE-AI report · RBI publication page · the text this page was checked against
- RBI Press Release 2024-2025/1779 · committee setup · 26 December 2024
- RBI Press Release 2025-2026/902 · report released · 13 August 2025
- RBI Master Directions index · the codification target
- Digital Personal Data Protection Act 2023 · MeitY canonical text
- IndiaAI Mission · AI Kosh and the data infrastructure rail
- India regime surface · per-regime field map across SEBI, RBI FREE-AI and the DPDP Act
Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. References to FREE-AI reflect the Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector dated 13 August 2025; the framework remains advisory pending RBI codification into Master Directions or circulars.
Provenance of every citation on this page. Each recommendation number, section reference and quoted passage was checked against the report text served at the RBI publication page for the report, retrieved 7 August 2026 at 197,518 characters; a perturbed publication identifier on the same host returned a page carrying no FREE-AI content at all, which is the control that makes the retrieval provable rather than merely successful. The two press-release numbers were read off the releases themselves: 2024-2025/1779 at prid=59377 for the committee's constitution on 26 December 2024, and 2025-2026/902 at prid=61018 for the report's release on 13 August 2025, the latter recording only that the committee "has since submitted its report and the same is being placed on the RBI website". DPDP references were checked against the MeitY canonical PDF. One caution on probing this material yourself: rbidocs.rbi.org.in serves a JavaScript bot interstitial to a plain request and returns HTTP 200 to a fabricated filename as readily as to the real one, so a status code on that host proves nothing about whether a document exists.