Regulation

Agentic AI in India: who answers when the agent acts

India has no AI statute — three instruments, three different legal forces, and only one enforceable against you today: SEBI’s, in force since February 2025.

In short
India has no AI statute. SEBI’s three amendments of 6 February 2025 are the only binding Indian AI rule: a regulated entity is solely responsible for the output of AI tools, including tools bought from a third party, at any scale of adoption. The RBI’s FREE-AI report and MeitY’s guidelines are recommendations, not obligations.

The question a board actually asks

The question that comes back from a board is never about model architecture. It is this: if an agent we deployed takes an action nobody authorised, who answers for it?

In India the answer is already written down, and it is more settled than the volume of commentary suggests. There is no Indian AI statute and no Indian AI regulator. What exists is three instruments issued in the space of fifteen months, and the single most common error is reading them as though they carried the same weight. They do not. One is a binding regulation enforceable today. One is a committee’s report. One says of itself that it is voluntary.

Three instruments, three different legal forces

InstrumentDateLegal forceWho it reaches
SEBI’s three amendment regulations6 February 2025Binding. Enforceable, with no transition periodSEBI-regulated entities, exchanges, clearing corporations, depositories
RBI FREE-AI committee report13 August 2025Recommendations to the RBINobody, until adopted by a Direction or circular
MeitY India AI Governance Guidelines5 November 2025Voluntary, and expressly soSector-agnostic guidance for developers, deployers and regulators
Indian AI governance instruments as at 20 August 2026.

The practical consequence is worth stating plainly. A SEBI-regulated entity that deploys an agent is inside a binding obligation and has been since February 2025. A bank or an NBFC doing the same thing is not — it is inside a set of recommendations that the RBI has not yet turned into a Direction. Any advice that treats those two positions as equivalent is wrong about one of them.

The one that binds: SEBI, February 2025

SEBI did not issue an AI circular. It amended three sets of regulations on the same day, inserting the same obligation into each — which is why commentary keeps referring to “SEBI’s AI regulation” in the singular and why the scope is so often described wrongly.

AmendmentReferenceInsertsBinds
IntermediariesSEBI/LAD-NRO/GN/2025/226Chapter IIIB, regulation 16CAny person regulated by the Board
Stock exchanges and clearing corporationsSEBI/LAD-NRO/GN/2025/227Regulation 39B, Chapter VIRecognised stock exchanges and clearing corporations
Depositories and participantsSEBI/LAD-NRO/GN/2025/225Regulation 82AA, Chapter VIIDepositories — not participants
Three notifications, all dated 6 February 2025, all published in the Gazette on 10 February 2025.

The operative words of regulation 16C are worth reading closely, because each clause closes a defence that a regulated entity might otherwise reach for. A person regulated by the Board who uses AI and machine learning tools, the regulation says, either designed by it or procured from third-party technology service providers, irrespective of the scale and scenario of adoption, is solely responsible for three things: the privacy, security and integrity of investor and stakeholder data throughout the processes involved; the output arising from the usage of those tools; and compliance with applicable laws in force.

So: buying the tool does not move the responsibility to the vendor. Using it at small scale does not exempt it. Using it internally rather than in a client-facing product does not exempt it either — the explanation to the regulation reaches tools used to carry out the entity’s activities including compliance requirements, not only those portrayed as part of a product offered to the public. And sub-regulation (2) is not decorative: SEBI may take such action as it deems fit, including action under Chapter V.

When the output of a tool is an action

Regulation 16C was drafted in a world of models that produce recommendations. It makes the regulated entity responsible for “the output arising from the usage of such tools and techniques it relies upon or deals with”. For a scoring model or an advisory engine, the output is a number or a suggestion, and a human decides what to do with it.

An agent collapses that gap. Its output is the action — the ticket closed, the record amended, the credential rotated, the payment released, the API called. Nothing in the regulation carves that out, and nothing in it requires that a human sat between the model and the consequence. The wording is broad enough to have arrived early, and a regulated entity that deploys agents today is relying on a provision written before the deployment pattern existed and drafted widely enough to cover it.

This is the part worth putting in front of a board. There is no materiality threshold in regulation 16C, no transition period, and no allocation of the responsibility anywhere other than the regulated entity. The word is solely.

What the RBI’s FREE-AI report is, and is not

The RBI constituted a committee in December 2024 to recommend a framework for AI in the financial sector, and published its report — the Framework for Responsible and Ethical Enablement of Artificial Intelligence — on 13 August 2025. It sets out seven guiding principles, six pillars covering infrastructure, policy, capacity, governance, protection and assurance, and 26 recommendations. It proposes board-approved AI policies, an inventory of AI systems, independent model validation, and proportionate treatment so that low-risk uses attract lighter obligations than high-risk ones.

It is a good document. It is not a Direction. A committee report becomes an obligation when the RBI issues an instrument adopting it, and as at 20 August 2026 none had been issued. Banks and NBFCs describing themselves as “FREE-AI compliant” are describing voluntary alignment with a recommendation, which is a reasonable thing to do and a different thing from compliance.

What MeitY’s guidelines actually say about agents

The India AI Governance Guidelines, issued on 5 November 2025, are sector-agnostic and built on seven sutras: Trust is the Foundation, People First, Innovation over Restraint, Fairness & Equity, Accountability, Understandable by Design, and Safety, Resilience & Sustainability. They recommend no new AI law, proposing instead that the IT Act be amended to clarify how AI systems are classified and how liability is imposed.

Their status is stated in the document itself: voluntary frameworks are described as lacking legal enforceability or punitive action. That is the sentence to keep in view when a vendor presents these guidelines as a compliance requirement.

Where they are genuinely useful is that they engage with agents directly, which the binding instrument does not. The glossary defines agentic AI as a highly autonomous system that senses and responds to its environment and takes actions to achieve its goals. The report notes that highly autonomous agents are demonstrating self-directed action and multi-agent collaboration, and flags autonomous AI-to-AI coordination and disruptive loss of control as risks that current governance approaches may not handle. Its answer is monitoring standards, audit trails and reporting protocols.

On liability it proposes a graded system in which responsibility is proportional to the function performed, the risk of harm anticipated, and the due diligence undertaken. Note the direction of travel against SEBI: MeitY proposes to distribute responsibility across the value chain, where SEBI has already placed it entirely on the regulated entity. For a SEBI-regulated firm, the binding instrument is the stricter one.

The kill switch is still a draft

SEBI published a consultation paper on guidelines for the responsible usage of AI/ML in Indian securities markets on 20 June 2025. It proposes a tiered regime — lighter obligations where AI is used internally for compliance, surveillance or cyber security, stricter where it touches clients directly — along with model audit trails, data governance standards, human oversight, and a kill-switch mechanism.

That kill-switch proposal has since been reported in places as though SEBI had imposed one. It has not. The consultation paper remains a draft, and the binding position is still regulation 16C and its two siblings. MeitY’s guidelines make a related recommendation from the other direction: where direct human oversight is ineffective because of the speed at which a system operates, safeguards such as circuit breakers, automated checks or system-level constraints should be considered.

The gap between the two is where a sensible programme sits. Nothing requires a kill switch today. Both regulators have signalled that something like one is coming, and an entity that is already solely responsible for what its agents do has its own reason not to wait.

What to put in place now

None of this needs a new function. It needs five things that a regulated entity can evidence to a supervisor, and that a board can be shown.

  1. An inventory of deployed agents. What is running, what it can reach, what credentials it holds, and what it is permitted to change without a human. FREE-AI recommends an AI inventory; regulation 16C makes you responsible for output you cannot enumerate.
  2. A named human owner for each one. Not a team and not a vendor. Sole responsibility is easier to discharge when it has been allocated internally to a person who can be asked what the agent did last week.
  3. Kill-switch authority, exercised at least once. Someone must be able to stop an agent without a change-management queue, and must have done it in a test. An untested stop is a plan, not a control.
  4. An audit trail that survives the agent. Actions taken, inputs relied on, and the human decision that authorised the deployment — retained on the entity’s own systems rather than in a vendor console you may lose access to.
  5. Contract terms that reflect where the liability actually sits. Since procurement does not move responsibility under regulation 16C, the contract is the only place to recover it. Ask what data the vendor’s models touch, what autonomy their agents have inside your environment, and what they will indemnify.

What an external rating tells you here, and what it does not

A security rating observes internet-facing infrastructure from outside — certificates, exposed services, patching cadence, botnet traffic. It cannot see inside a supplier’s network, so it cannot tell you whether they have deployed agents, what those agents can reach, or who can stop one. Anyone claiming otherwise is overselling.

What it does show is the surface those agents would be reached through, and it shows it continuously rather than at the moment a questionnaire was answered. That is a real input to the second and fifth items above, and it is not a substitute for asking the question directly. What agentic AI does to your attack surface takes the same subject from the third-party side.

Regulation 16C, regulation 39B and regulation 82AA were read from the Gazette of India notifications attached to each SEBI page, Part III Section 4, published 10 February 2025. The FREE-AI report and the India AI Governance Guidelines were read from the RBI’s and MeitY’s own published PDFs. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

Is there a law governing artificial intelligence in India?
No. India has no AI statute and no general AI regulator. The binding obligations come from sector regulators using existing powers — SEBI amended three sets of regulations on 6 February 2025 to make regulated entities responsible for AI outputs. MeitY’s India AI Governance Guidelines of 5 November 2025 are expressly voluntary, and recommend amending the IT Act rather than passing an AI law.
What does SEBI’s regulation 16C require?
That any person regulated by SEBI using AI or machine learning tools — whether built in-house or procured from third-party technology service providers, and irrespective of the scale and scenario of adoption — is solely responsible for the privacy, security and integrity of investor and stakeholder data, for the output arising from those tools, and for compliance with applicable laws. SEBI may act on a breach under Chapter V.
When did SEBI’s AI provisions come into force?
10 February 2025, the date of gazette publication, for all three instruments. The depositories amendment is widely reported as commencing on 1 April 2025, but the proviso to its regulation 2 puts the AI clause into force on gazette publication instead; 1 April 2025 is the commencement of the fee provisions carried by the same notification.
Is the RBI’s FREE-AI framework binding on banks and NBFCs?
No. FREE-AI is the report of a committee constituted by the RBI in December 2024 and published on 13 August 2025. It contains 26 recommendations across six pillars. Recommendations become obligations only when the RBI issues a Direction or circular adopting them, and none had been issued as at 20 August 2026.
Does any Indian regulator require a kill switch for AI systems?
Not yet. A kill-switch requirement appears in SEBI’s consultation paper of 20 June 2025 on guidelines for the responsible usage of AI/ML, which remains a draft. MeitY’s guidelines recommend that where direct human oversight is ineffective, safeguards such as circuit breakers, automated checks or system-level constraints should be considered — a recommendation, not a rule.
Does a security rating show whether a vendor is running AI agents?
No. An external rating observes internet-facing infrastructure — certificates, exposed services, patching, botnet traffic. It cannot see what runs inside a supplier’s network, so it cannot tell you whether they have deployed agents, what those agents can reach, or who holds the authority to stop one. It shows the surface those agents could be reached through, which is a different question.

See where you actually stand.

Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating Read the FAQ