REGULATOR · IN · FINTECH · 3 REGIMES
REVISED 2026-08-06 · SEBI · RBI FREE-AI · DPDP · STAGED COMMENCEMENT 2026–2027

India: SEBI + RBI + DPDP.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific regulatory obligation, independently verifiable without contacting Warrant. Three Indian regimes bear on AI agents in fintech, and they are in three different states. SEBI's algo-trading circular applies to all stock brokers from 1 April 2026 and is binding. The RBI's FREE-AI committee report is not binding: the Reserve Bank has adopted no instrument giving it force. The DPDP Act 2023 is enacted but its substantive obligations commence eighteen months from 13 November 2025. Warrant maps all three on a single trace, and labels each with the state it is actually in.

SEBI
2026-04-01
Retail Algorithmic Trading Framework, fully mandatory.
RBI · FREE-AI
7 sutras· 26 recs
Committee report released 13 Aug 2025. Not adopted, not binding.
DPDP CEILING
₹250 cr· s.8(5)
Highest Schedule entry. Substantive duties commence 14 May 2027.
01 · SEBI · RETAIL ALGORITHMIC TRADING FRAMEWORK

Retail algorithmic trading under glide path.

"The facility of algo trading shall be provided by the broker only after obtaining requisite permission of the stock exchange for each algo." Every algo order is tagged with a unique identifier provided by the Exchange "in order to establish audit trail". Algo providers "shall not be regulated by SEBI" but must be empanelled with Exchanges. SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/0000013 · 4 February 2025 · paras II(a), II(b), III(a)

SEBI's "Safer participation of retail investors in Algorithmic trading" circular (4 February 2025) governs "algo" orders, which paragraph 1 defines as "orders generated using automated execution logic". It is not AI/ML-scoped. The words "artificial intelligence", "machine learning" and "model" do not occur anywhere in it, and the permission that gates an algo comes from the stock exchange, not from SEBI. The glide path is set by a later circular, SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/132 of 30 September 2025: product application 31 October 2025, registration 30 November 2025, mock session 3 January 2026, and under paragraph 8 applicability to all stock brokers from 1 April 2026. Paragraph 5 adds a fifth dated consequence — brokers who miss the milestones "shall be barred from onboarding new retail clients for API based algo trading framework w.e.f. January 05, 2026".

para II(a)
Exchange permission for each algo, obtained by the broker before the facility is provided. WARRANT · regulated_entity, a root field of the submitted trace, names the broker. warrant-v1 has no field for an exchange permission reference, so the per-algo permission itself is not carried in the package.
para II(b)
Unique exchange-issued algo identifier on every algo order, to establish audit trail; Exchange approval for any modification to an approved algo. WARRANT · actions[*].action_id identifies each action inside the package, in a record independently verifiable without contacting Warrant. That identifier is Warrant's own: warrant-v1 has no field for the exchange-issued algo id and none for a model version.
para II(c)
Broker is solely responsible for investor grievances related to algo trading and for monitoring of APIs for prohibited activities. WARRANT · authorizations[*] carries the per-action assessment (within_purpose, preconditions_met, human_oversight_appropriate, reversible, justification). warrant-v1 has no field for an API-monitoring outcome, so the monitoring limb of this paragraph is not evidenced.
para V(a)(ii)
Black-box algos only: the algo provider registers as a Research Analyst and maintains a detailed research report for each algo. This is a duty on the provider, not on the broker. WARRANT · warrant-v1 has no field referencing a research report or model documentation. The obligation row carries compliance="gap" where nothing evidences it.
02 · RBI · FRAMEWORK FOR RESPONSIBLE AND ETHICAL ENABLEMENT OF AI

Seven sutras for AI in regulated entities.

The seven sutras are named in the report as: 1 Trust is the Foundation · 2 People First · 3 Innovation over Restraint · 4 Fairness and Equity · 5 Accountability · 6 Understandable by Design · 7 Safety, Resilience, and Sustainability. The report sets out "26 Recommendations" under "6 strategic Pillars" — Infrastructure, Policy and Capacity for innovation enablement, and Governance, Protection and Assurance for risk mitigation. RBI · Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector · 13 August 2025

The Reserve Bank placed the FREE-AI committee report on its website on 13 August 2025. It is not binding and it has not been adopted. The RBI press release of that date says only that the committee "has since submitted its report and the same is being placed on the RBI website" — there is no adoption instrument, no direction and no compliance date. Nor is the report uniformly addressed to firms: 13 of the 26 recommendations run to the RBI, Government, regulators or industry bodies rather than to regulated entities, and each carries its own addressee and horizon tag. There is no sutra called "Explainability"; explainability appears in the report as a sub-line under Sutra 6, Understandable by Design. For the sutra-by-sutra reading, see RBI FREE-AI, read against the AI agent.

Thematic reading · no numbered recommendation cited

thematic
Bias testing per high-impact decision class. WARRANT · warrant-v1 has no field referencing a bias-test record. authorizations[*].justification carries the per-action rationale; the obligation row carries compliance="gap" where the trace shows no test.
thematic
Explainability for high-impact decisions. WARRANT · authorizations[*].justification per action. That is Warrant's assessment of the action, not the agent's own words: a firm's reasoning travels in the free-form trace[*].outputs it submits — the sample traces put a rationale key there — and warrant-v1 does not re-emit it, so the agent's own rationale is not a package field.
thematic
Human oversight for high-risk decisions. WARRANT · authorizations[*].human_oversight_appropriate is Warrant's per-action assessment of whether human oversight was appropriate. It is not a record that a human was present or intervened, and warrant-v1 has no field that carries one: a human_review_recorded flag a firm puts in the free-form trace[*].outputs it submits is not re-emitted in the signed package.
thematic
Audit trail reconstructable. WARRANT · a record mapped to the obligation, independently verifiable without contacting Warrant (forever).

The four rows above are a thematic reading of the report, not pinpoints. Warrant does not attach a numbered Recommendation to them, because the numbers do not line up: the report's own Recommendation 14 is the board-approved AI policy, 22 is AI incident reporting (a duty on regulators, not on firms), 23 the AI inventory and 24 the AI audit framework. Citing "Recommendation 3" for bias testing would be an invented pinpoint.

03 · DPDP ACT 2023

Personal data, across both regimes.

"A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,— (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses." Consent "shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose." Digital Personal Data Protection Act 2023 · ss. 4(1), 6(1) · assent 11 August 2023

The DPDP Act layers across the SEBI and RBI regimes, but not yet. Its substantive obligations are not in force. The Act was brought into effect in tranches by G.S.R. 843(E) of 13 November 2025: ss. 1, 2, 18 to 26, 35 and 38 to 43 on publication, s. 6(9) and s. 27(1)(d) at twelve months, and "sections 3 to 5, sub-sections (1) to (8) and (10) of section 6, sections 7 to 10, sections 11 to 17, section 27 except clause (d)... sections 28 to 34, 36, 37" at eighteen months — 14 May 2027 on the conservative reading of that clock. Every section mapped below sits in that eighteen-month tranche. The ₹250 crore figure is the highest ceiling in the Schedule and attaches to one entry: breach of the s. 8(5) duty to take reasonable security safeguards. For the section-by-section reading, see the DPDP Act 2023, read against the AI agent.

7sutras
RBI FREE-AI
Trust is the Foundation, People First, Innovation over Restraint, Fairness and Equity, Accountability, Understandable by Design, Safety Resilience and Sustainability. 26 recommendations across six pillars.
2026-04-01
SEBI · ALL BROKERS
Applicable to all stock brokers under paragraph 8 of the circular of 30 September 2025, which set the glide path.
"Three regimes, one trace. Per-vertical depth no horizontal infrastructure player covers."Counsel · IN regulatory · review · 2026-04-30
04 · WHY THIS REGULATOR NOW

Which Indian regulators cover AI in fintech?

Three sectoral regimes bear on AI in Indian fintech, and only one of them is binding today. SEBI's algo circular of 4 February 2025 was deferred twice — its own paragraph 7(b) set 1 August 2025, a circular of 29 July 2025 moved that to 1 October 2025, and the circular of 30 September 2025 replaced it with the milestone glide path ending 1 April 2026. The RBI's FREE-AI report is a committee report the Reserve Bank has not adopted. The DPDP Act's substantive obligations commence at the eighteen-month mark from 13 November 2025, and the DPDP Rules 2025 (G.S.R. 846(E)) commence rules 3, 5 to 16, 22 and 23 on the same clock — the Draft Rules published in January 2025 were superseded by that notification. A cross-border firm running one AI agent sits inside one binding Indian regime today and two more that arrive on dated clocks.

What the record does and does not show. The RBI's own live instrument for AI/ML models at regulated entities is the draft "Guidance on Regulatory Principles for Model Risk Management, 2026", released 24 June 2026 with comments closed 24 July 2026 — still a draft, and Warrant does not cite drafts as binding. We do not read across from unrelated SEBI or RBI enforcement actions to predict how an algo-trading or AI documentation gap would be pursued: the instruments do not support that inference, so this page does not make it. The Data Protection Board of India is established under s. 18, and ss. 18 to 26 commenced on publication of G.S.R. 843(E), so the Board exists before the duties it will adjudicate do.

Where the leverage sits, on the text rather than on prediction. Under SEBI the gate is exchange permission per algo (para II(a)) plus the exchange-issued algo identifier on every order (para II(b)); an algo run without that permission is outside the framework regardless of how the strategy was built, and the circular reaches automated execution logic whether or not a model is involved. Under FREE-AI there is no gate, because there is no adopted instrument. Under DPDP the gate is the lawful basis in s. 4 and the purpose limit carried by consent in s. 6(1), from the commencement date forward.

05 · MAPPING · THREE REGIMES

Per-regime field map.

"Brokers shall be the principal while any algo provider or fintech/vendor... shall act as its agent, while using the API provided by the broker." "Exchanges shall continue to be responsible for supervising algorithmic trading while ensuring the following: putting in place a comprehensive Standard Operating Procedure (SOP) for testing of algos; surveillance on all algo orders and monitoring their behaviour at all times including simulation testing of all algos." SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/0000013 · 4 February 2025 · paras I(a), IV(a)(i)–(ii)

Three mini-mappings below. SEBI algo circular, RBI FREE-AI, DPDP Act 2023. Each row names the obligation, the instrument text it comes from, and what the warrant-v1 evidence package actually carries against it. The published schema, api/spec/warrant-v1-evidence.schema.json, sets additionalProperties: false at its root and on every action, so the field list is closed: a package carries no pre-approval reference, no model-documentation reference, no bias-test record, no sign-off, no consent reference, no cross-border flag, no vulnerability marker and no model version. The rows below name the fields that do exist and state plainly where there is none. Where a duty sits on the exchange rather than on the attesting firm, the row says so — a firm cannot discharge someone else's obligation, and an evidence package that implies otherwise is worse than one that leaves the gap visible.

5.1 · SEBI algo circular, 4 February 2025 · paragraph pinpoints

para I(a)
Broker is principal; the algo provider or vendor acts as its agent when using the broker's API. WARRANT · regulated_entity, a root field of the trace the firm sends, names the broker rather than the vendor whose logic produced the order. It is a field of the submitted trace, not one the package emits.
para II(a)
Exchange permission for each algo, obtained before the facility is provided. Permission runs from the exchange; algo providers "shall not be regulated by SEBI" (para III(a)). WARRANT · warrant-v1 has no field for an exchange permission reference; the obligation row carries compliance="gap" where nothing evidences the permission.
para II(b)
Unique exchange-issued algo identifier on every order, to establish audit trail; Exchange approval for any modification to an approved algo. WARRANT · actions[*].action_id identifies each action inside the package. warrant-v1 carries neither the exchange-issued algo id nor a model version, so the tag this paragraph requires is not in the record.
para II(c)
Broker is solely responsible for investor grievances related to algo trading and for monitoring of APIs for prohibited activities. WARRANT · authorizations[*] carries the per-action assessment (within_purpose, preconditions_met, human_oversight_appropriate, reversible, justification). warrant-v1 has no field for an API-monitoring outcome, so the monitoring limb of this paragraph is not evidenced.
para V(a)(ii)
Black-box algos only: the algo provider registers as a Research Analyst and maintains a detailed research report for each algo, and re-registers the algo as fresh on any change in logic. WARRANT · warrant-v1 has no field referencing model documentation. Provider-side duty; the record names it as such and the obligation row carries compliance="gap".
para IV(a)
Testing SOP, surveillance of all algo orders, and the kill switch per algo id are duties on the EXCHANGE, not on the attesting broker. WARRANT · recorded as an exchange-side obligation. Warrant does not represent it as discharged by the firm.

5.2 · RBI Framework for Responsible and Ethical Enablement of AI

Sutra 1
Trust is the Foundation · system reliability and resilience evidenced. WARRANT · a record mapped to the obligation, independently verifiable without contacting Warrant (forever).
Sutra 2
People First · vulnerable customer and accessibility considerations. WARRANT · authorizations[*] carries the per-action assessment. The submitted trace's inputs object is free-form and a firm can put a vulnerability marker in it, but warrant-v1 defines no vulnerability field and the package emits none.
Sutra 4
Fairness and Equity · bias testing per high-impact decision class. WARRANT · warrant-v1 has no field referencing a bias-test record. authorizations[*].justification carries the per-action rationale; the obligation row carries compliance="gap" where the trace shows no test.
Sutra 5
Accountability · clear owner of every AI-driven decision. WARRANT · regulated_entity, a root field of the submitted trace, names the firm, and authorizations[*].justification carries Warrant's per-decision assessment. No field in warrant-v1 names an accountable individual, so the clear-owner record the sutra asks for has no home in the package today.
Sutra 6
Understandable by Design · rationale for high-impact decisions. Explainability sits under this sutra; it is not a sutra of its own. WARRANT · authorizations[*].justification per action. That is Warrant's assessment of the action, not the agent's own words: a firm's reasoning travels in the free-form trace[*].outputs it submits — the sample traces put a rationale key there — and warrant-v1 does not re-emit it, so the agent's own rationale is not a package field.
Sutra 7
Safety, Resilience, and Sustainability · audit trail reconstructable on supervisor request. WARRANT · actions[*] (action_id, actor, action, subject) bound into a record independently verifiable without contacting Warrant. The submitted inputs, outputs and timestamps stay in the trace; the package carries those four action fields, the authorization row and the obligation rows.
not binding
Sutra 3, Innovation over Restraint, addresses the regulator rather than the firm, and no sutra carries legal force: the report has not been adopted by the Reserve Bank. WARRANT · FREE-AI rows are labelled non-binding in the record and are never presented as a statutory obligation.

5.3 · DPDP Act 2023

Every section below commences at the eighteen-month mark from 13 Nov 2025 · not operative as at 2026-08-06

§ 4(1)
Lawful purpose · consent, or certain legitimate uses. WARRANT · authorizations[*].within_purpose records the per-action purpose assessment. warrant-v1 has no consent-reference field, so a consent artefact is not evidenced in the package.
§ 5
Notice accompanying or preceding the request for consent. Notice is s. 5; consent itself is s. 6. WARRANT · warrant-v1 has no field referencing a consent notice and none carrying a data-principal identifier. The obligation row carries compliance="gap".
§ 6(1)
Purpose limitation · consent is "limited to such personal data as is necessary for such specified purpose". This is s. 6(1), not s. 8(1) — s. 8(1) is the Data Fiduciary's general compliance obligation. WARRANT · authorizations[*].within_purpose flags out-of-purpose access.
§ 8(6)
Breach intimation to the Board and each affected Data Principal, "in such form and manner as may be prescribed". The Act sets no hour count; Rule 7(2)(b) of the DPDP Rules 2025 supplies the seventy-two-hour clock to the Board. WARRANT · Incident-mode trace ingestion ships v0.5; today, breach-pattern traces produce a per-obligation evidence record, independently verifiable without contacting Warrant. CERT-In's six-hour direction under s. 70B(6) IT Act is already in force and runs separately.
§§ 11, 12
Right to a summary of personal data and processing activities is s. 11. Correction, completion, updating and erasure is s. 12 — a separate section. The Act confers no data-portability right. WARRANT · a right-of-access request submitted as a trace step is attested in the same shape, as actions[*] with its authorization and obligation rows. warrant-v1 has no data-principal identifier field, so the record is not addressable by data principal.
§ 16(1)
Cross-border transfer · the Central Government "may, by notification, restrict the transfer of personal data... to such country or territory outside India as may be so notified". Restriction by notification, not a general bar. WARRANT · authorizations[*].within_purpose carries the per-action purpose check and classification.jurisdictions records the jurisdictions the trace was classified against. warrant-v1 has no cross-border transfer field. The RBI payment-data residency circular of 6 April 2018 is in force and carries independently.
06 · FAQ

Questions a CCO and DPO ask first.

Does DPDP Act 2023 permit cross-border data flows for AI processing?

Section 16(1) provides that "the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified". The default is therefore open transfer, restricted only where a country is notified. Section 16 sits in the ss. 11 to 17 block that commences eighteen months from publication of G.S.R. 843(E) of 13 November 2025, so it is not yet operative. Sectoral obligations already in force are stricter and run independently: RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 of 6 April 2018 requires that "the entire data relating to payment systems" operated by system providers "are stored in a system only in India". As at G.S.R. 843(E), 13 November 2025.

When does SEBI's algo circular apply to my system?

The instrument is circular SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/0000013 of 4 February 2025, and it is not AI/ML-scoped. It governs "algo" orders — defined in paragraph 1 as "orders generated using automated execution logic" — routed to retail investors through broker APIs. The words "artificial intelligence", "machine learning" and "model" do not occur in it. The gating event is permission from the stock exchange, not from SEBI: algo trading "shall be provided by the broker only after obtaining requisite permission of the stock exchange for each algo" (para II(a)), and algo providers "shall not be regulated by SEBI" though they must be empanelled with Exchanges (para III(a)). Applicability to all stock brokers runs from 1 April 2026 under paragraph 8 of circular SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/132 of 30 September 2025. Documentation duties are narrower than a model-documentation regime: for black-box algos the provider must register as a Research Analyst and maintain a detailed research report for each algo (para V(a)(ii)). As at the circulars of 4 February 2025 and 30 September 2025.

How do RBI FREE-AI recommendations bind a regulated entity in practice?

They do not bind. FREE-AI is the report of a committee constituted by the Reserve Bank, placed on the RBI website on 13 August 2025; the press release of that date says only that the committee "has since submitted its report and the same is being placed on the RBI website". There is no adoption instrument, no direction and no compliance date. Nor is the report uniformly addressed to firms: 13 of the 26 recommendations run to the RBI, Government, regulators or industry bodies rather than to regulated entities, and each carries its own addressee and horizon tag. The seven sutras are Trust is the Foundation, People First, Innovation over Restraint, Fairness and Equity, Accountability, Understandable by Design, and Safety, Resilience and Sustainability — there is no sutra called "Explainability". The Reserve Bank's live instrument on AI/ML models at regulated entities is the draft "Guidance on Regulatory Principles for Model Risk Management, 2026" of 24 June 2026, which is also still a draft. As at the report of 13 August 2025.

How do i generate India evidence if my agent runs on a non-India LLM provider?

The location of the model vendor is not material under SEBI, RBI, or DPDP. What is material is whether the regulated entity (the SEBI-registered intermediary, the RBI-regulated entity, the data fiduciary) can produce per-decision evidence and whether personal data of Indian data principals is processed in compliance with DPDP. Warrant produces a per-obligation evidence record mapped to all three regimes from a single trace, independently verifiable without contacting Warrant.

What is the maximum financial penalty under DPDP Act 2023?

The Schedule to the Act, headed "See section 33 (1)", sets tiered ceilings. The highest reads "May extend to two hundred and fifty crore rupees" and attaches to one entry: breach of the obligation to take reasonable security safeguards under s. 8(5). Breach of the s. 8(6) intimation duty carries up to 200 crore, additional obligations for children under s. 9 up to 200 crore, Significant Data Fiduciary obligations under s. 10 up to 150 crore, and any other provision up to 50 crore. There is no per-instance multiplier in the Act; s. 33(2) directs the Board to weigh the nature, gravity and duration of the breach and its repetitive nature. The penalty provisions, ss. 28 to 34, commence at the eighteen-month mark and are not yet operative. The Data Protection Board of India is established under s. 18, and ss. 18 to 26 commenced on publication of G.S.R. 843(E). As at G.S.R. 843(E), 13 November 2025.

Is there a 72-hour breach notification under DPDP analogous to NYDFS § 500.17?

Not in the Act. Section 8(6) requires the Data Fiduciary to "give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed", and sets no hour count. The clock comes from the DPDP Rules 2025, notified 13 November 2025: Rule 7(1) requires intimation to each affected Data Principal "without delay"; Rule 7(2)(a) requires a description to the Board "without delay"; Rule 7(2)(b) requires detailed particulars to the Board "within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing". Both s. 8(6) and Rule 7 commence eighteen months from publication of the November 2025 gazette, so neither is operative yet. A sectoral obligation that is already in force is shorter: the CERT-In directions of 28 April 2022 under s. 70B(6) of the Information Technology Act require entities to "mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents". As at G.S.R. 843(E) and G.S.R. 846(E), 13 November 2025.

07 · READ THE SOURCE

Primary citations.

SEBI circular SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/0000013 of 4 February 2025 at sebi.gov.in. SEBI circular SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/132 of 30 September 2025, which sets the glide path and the 1 April 2026 date: extension of timeline. RBI press release of 13 August 2025 placing the FREE-AI committee report on the record: rbi.org.in, with the report itself at rbidocs.rbi.org.in. DPDP Act 2023 as enacted at meity.gov.in; the commencement notification G.S.R. 843(E) of 13 November 2025 at meity.gov.in; the DPDP Rules 2025, G.S.R. 846(E), at meity.gov.in. Every pinpoint on this page was read against these documents on 2026-08-06.

W
Sample India evidence package · RBI NBFC-MFI lending agent · CIBIL bureau reportINDEPENDENTLY VERIFIABLE · ID c30707ea704c6b6d
→ india-fintech.pdf
Verify a package → Open the demo All regulators