Which Indian AI rules bind a bank or NBFC
India has no AI statute. This separates what binds you from the report, the voluntary guidelines and the draft that are cited as though they did.
What binds you
This is the profile where the honest answer is zero, and where the web is least reliable. No AI-specific instrument binds an RBI regulated entity today. Two things that do are technology-neutral and easy to overlook precisely because they are not about AI.
A commercial bank, small finance bank, payments bank, urban co-operative bank, NBFC, AIFI or credit information company.
No AI-specific instrument binds you. That is the answer, and it is not the same as nothing applying — the 2026 cyber Directions bind whatever technology you deploy, and the RBI’s FREE-AI document is a committee report rather than an RBI framework.
Nothing on this list is an AI rule that binds you. That is the finding, not a gap in it. What does bind you today is technology-neutral: the incident reporting duty, your sector regulator’s cyber instrument, and — from 13 May 2027 — the DPDP obligations wherever a model touches personal data.
| Instrument | Force | From |
|---|---|---|
| CERT-In Directions, 2022 No. 20(3)/2022-CERT-In | Binding | 27 June 2022 |
| Digital Personal Data Protection Rules, 2025 G.S.R. 846(E) | Binding | 13 May 2027 |
| MeitY India AI Governance Guidelines | Voluntary | 5 November 2025 |
| RBI FREE-AI committee report | A report to a regulator | 13 August 2025 |
What each one asks for, and what it can do to you
- CERT-In Directions, 2022 — binding. A cyber incident reported to CERT-In within six hours of noticing it. The Directions are technology-neutral, so an incident caused by or involving an AI system is reportable on exactly the same terms as any other.
Enforceable against you today. A breach is actionable by the regulator under its own powers. Not an AI instrument, and included because it is the one obligation on this page that is certain to apply to an AI incident today. An organisation waiting for AI-specific reporting rules already has reporting rules. - Digital Personal Data Protection Rules, 2025 — binding. Where an AI system processes digital personal data, the Data Fiduciary obligations — notice, security safeguards, breach intimation, retention limits and Data Principal rights — reach that processing like any other. They commence on 13 May 2027.
Enforceable against you today. A breach is actionable by the regulator under its own powers. The date matters more here than elsewhere, because model training on personal data is the use most often described as already regulated in India. It is not yet: rules 3 and 5 to 16 commence eighteen months after publication. - MeitY India AI Governance Guidelines — voluntary. A set of governance recommendations for AI development and deployment in India, addressed to industry and to government.
Not enforceable. The document says so of itself, and adopting it is a choice rather than compliance. The Guidelines say of themselves that voluntary frameworks lack legal enforceability or punitive action, and they recommend amending the Information Technology Act rather than passing an AI law. They are the document most often cited as evidence that India “has AI governance rules”. - RBI FREE-AI committee report — a report to a regulator. A framework for the responsible and ethical enablement of artificial intelligence, recommended to the Reserve Bank by the committee that wrote it.
A committee reporting to a regulator, not the regulator instructing you. It may become policy and has not. A committee reporting to the RBI is not the RBI instructing a regulated entity. FREE-AI is routinely written up as “the RBI’s AI framework”, which reverses the direction of the document. Nothing in it is enforceable against a bank today.
Indicative, and not legal advice. Every binding instrument here was read from the issuing regulator’s own notification; the non-binding documents are linked to their publishers. Whether an instrument reaches your organisation is a determination for your legal team.
Take this away as a print-ready AI obligations brief
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Five documents, five different forces
India has no AI statute and no AI regulator, so the question is never only whether a document reaches you. A committee report, a voluntary framework and a consultation paper all read like rules and none of them is one.
| Force | What it means |
|---|---|
| Binding | Enforceable against you today. A breach is actionable by the regulator under its own powers. |
| Advisory, largely drafted as “shall” | Issued as a circular, in force, and expressly diluting no other obligation — but titled an advisory, and encouraging compliance on its covering page. Read the annexure rather than the label: what is drafted with “shall” is what a supervisor will ask about. |
| Voluntary | Not enforceable. The document says so of itself, and adopting it is a choice rather than compliance. |
| A report to a regulator | A committee reporting to a regulator, not the regulator instructing you. It may become policy and has not. |
| Draft | A consultation paper. Nothing in it binds anyone, and the proposals in it may change or be dropped. |
Every binding instrument here was read from the issuing regulator’s own notification. Indicative, and not legal advice.
Every instrument cited here was verified against the issuing regulator's own notification on .Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- Is there a law regulating artificial intelligence in India?
- No. India has no AI statute and no AI regulator. The binding obligations come from sector regulators using existing powers: SEBI amended three sets of regulations on 6 February 2025, and IFSCA issued a frontier AI circular for GIFT City entities on 4 June 2026. MeitY’s India AI Governance Guidelines of 5 November 2025 are expressly voluntary and recommend amending the Information Technology Act rather than passing an AI law.
- Does the RBI have an AI framework banks must follow?
- No. The FREE-AI document of 13 August 2025 is a committee’s report to the Reserve Bank, not the Reserve Bank instructing a regulated entity, and nothing in it is enforceable against a bank today. It is routinely written up as “the RBI’s AI framework”, which reverses the direction of the document. What does bind an RBI regulated entity is the cybersecurity Directions of 31 July 2026, which apply to the systems it runs whether or not a model is inside them.
- When did SEBI’s AI rule for depositories commence?
- 10 February 2025, on publication in the Official Gazette. The Depositories and Participants amendment is widely reported as commencing on 1 April 2025, but its own regulation 2 carries a proviso putting the amendment in regulation 3(IV) into force on gazette publication instead — and regulation 3(IV) is the AI clause. The 1 April date is true of the fee clauses the same amendment carries and false of the clause it is cited for.
- Has SEBI required a kill switch for AI systems?
- No. The kill switch appears in SEBI’s consultation paper on guidelines for the responsible usage of AI and machine learning, issued for comment on 20 June 2025. It is a draft proposal. SEBI’s final guidelines were confirmed still unissued on 3 September 2026, checked against SEBI’s own circular and regulation listings rather than against commentary.
- What does the IFSCA frontier AI advisory require?
- Despite its title, most of its annexure is drafted with “shall”: frontier AI carried as a named scenario in the cyber risk assessment and put before the Board, a Software Bill of Materials covering open-source components, an inventory of APIs and the applications consuming them with rate-limiting and a whitelist, critical service providers required to furnish evidence of frontier-AI preparedness, monitoring tuned for attack sequences faster than a human could run, and human oversight plus security testing of AI-generated code before production.