Tool 7

Which Indian AI rules bind a bank or NBFC

India has no AI statute. This separates what binds you from the report, the voluntary guidelines and the draft that are cited as though they did.

In short
India has no AI statute and no AI regulator. Two instruments bind: SEBI’s amendments of 6 February 2025, making a regulated entity solely responsible for the output of AI tools including those bought in, and IFSCA’s frontier AI circular of 4 June 2026, drafted mostly as “shall”. The RBI’s FREE-AI document is a committee report, MeitY’s guidelines are voluntary, and SEBI’s kill switch is a draft.

What binds you

This is the profile where the honest answer is zero, and where the web is least reliable. No AI-specific instrument binds an RBI regulated entity today. Two things that do are technology-neutral and easy to overlook precisely because they are not about AI.

The entity you are asking about

India has no AI statute and no AI regulator, so the question is never only whether a document reaches you. It is what kind of document it is.

0 AI-specific rulesBank, NBFC or other RBI regulated entity

A commercial bank, small finance bank, payments bank, urban co-operative bank, NBFC, AIFI or credit information company.

No AI-specific instrument binds you. That is the answer, and it is not the same as nothing applying — the 2026 cyber Directions bind whatever technology you deploy, and the RBI’s FREE-AI document is a committee report rather than an RBI framework.

Nothing on this list is an AI rule that binds you. That is the finding, not a gap in it. What does bind you today is technology-neutral: the incident reporting duty, your sector regulator’s cyber instrument, and — from 13 May 2027 — the DPDP obligations wherever a model touches personal data.

Every Indian AI-facing instrument reaching Bank, NBFC or other RBI regulated entity, heaviest force first
InstrumentForceFrom
CERT-In Directions, 2022
No. 20(3)/2022-CERT-In
Binding27 June 2022
Digital Personal Data Protection Rules, 2025
G.S.R. 846(E)
Binding13 May 2027
MeitY India AI Governance GuidelinesVoluntary5 November 2025
RBI FREE-AI committee reportA report to a regulator13 August 2025

What each one asks for, and what it can do to you

  • CERT-In Directions, 2022binding. A cyber incident reported to CERT-In within six hours of noticing it. The Directions are technology-neutral, so an incident caused by or involving an AI system is reportable on exactly the same terms as any other.
    Enforceable against you today. A breach is actionable by the regulator under its own powers. Not an AI instrument, and included because it is the one obligation on this page that is certain to apply to an AI incident today. An organisation waiting for AI-specific reporting rules already has reporting rules.
  • Digital Personal Data Protection Rules, 2025binding. Where an AI system processes digital personal data, the Data Fiduciary obligations — notice, security safeguards, breach intimation, retention limits and Data Principal rights — reach that processing like any other. They commence on 13 May 2027.
    Enforceable against you today. A breach is actionable by the regulator under its own powers. The date matters more here than elsewhere, because model training on personal data is the use most often described as already regulated in India. It is not yet: rules 3 and 5 to 16 commence eighteen months after publication.
  • MeitY India AI Governance Guidelinesvoluntary. A set of governance recommendations for AI development and deployment in India, addressed to industry and to government.
    Not enforceable. The document says so of itself, and adopting it is a choice rather than compliance. The Guidelines say of themselves that voluntary frameworks lack legal enforceability or punitive action, and they recommend amending the Information Technology Act rather than passing an AI law. They are the document most often cited as evidence that India “has AI governance rules”.
  • RBI FREE-AI committee reporta report to a regulator. A framework for the responsible and ethical enablement of artificial intelligence, recommended to the Reserve Bank by the committee that wrote it.
    A committee reporting to a regulator, not the regulator instructing you. It may become policy and has not. A committee reporting to the RBI is not the RBI instructing a regulated entity. FREE-AI is routinely written up as “the RBI’s AI framework”, which reverses the direction of the document. Nothing in it is enforceable against a bank today.

Indicative, and not legal advice. Every binding instrument here was read from the issuing regulator’s own notification; the non-binding documents are linked to their publishers. Whether an instrument reaches your organisation is a determination for your legal team.

Take this away as a print-ready AI obligations brief

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Five documents, five different forces

India has no AI statute and no AI regulator, so the question is never only whether a document reaches you. A committee report, a voluntary framework and a consultation paper all read like rules and none of them is one.

ForceWhat it means
BindingEnforceable against you today. A breach is actionable by the regulator under its own powers.
Advisory, largely drafted as “shall”Issued as a circular, in force, and expressly diluting no other obligation — but titled an advisory, and encouraging compliance on its covering page. Read the annexure rather than the label: what is drafted with “shall” is what a supervisor will ask about.
VoluntaryNot enforceable. The document says so of itself, and adopting it is a choice rather than compliance.
A report to a regulatorA committee reporting to a regulator, not the regulator instructing you. It may become policy and has not.
DraftA consultation paper. Nothing in it binds anyone, and the proposals in it may change or be dropped.
The forms an Indian AI-facing document takes, and what each one can do to you.

Every binding instrument here was read from the issuing regulator’s own notification. Indicative, and not legal advice.

Every instrument cited here was verified against the issuing regulator's own notification on .

Other worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

Is there a law regulating artificial intelligence in India?
No. India has no AI statute and no AI regulator. The binding obligations come from sector regulators using existing powers: SEBI amended three sets of regulations on 6 February 2025, and IFSCA issued a frontier AI circular for GIFT City entities on 4 June 2026. MeitY’s India AI Governance Guidelines of 5 November 2025 are expressly voluntary and recommend amending the Information Technology Act rather than passing an AI law.
Does the RBI have an AI framework banks must follow?
No. The FREE-AI document of 13 August 2025 is a committee’s report to the Reserve Bank, not the Reserve Bank instructing a regulated entity, and nothing in it is enforceable against a bank today. It is routinely written up as “the RBI’s AI framework”, which reverses the direction of the document. What does bind an RBI regulated entity is the cybersecurity Directions of 31 July 2026, which apply to the systems it runs whether or not a model is inside them.
When did SEBI’s AI rule for depositories commence?
10 February 2025, on publication in the Official Gazette. The Depositories and Participants amendment is widely reported as commencing on 1 April 2025, but its own regulation 2 carries a proviso putting the amendment in regulation 3(IV) into force on gazette publication instead — and regulation 3(IV) is the AI clause. The 1 April date is true of the fee clauses the same amendment carries and false of the clause it is cited for.
Has SEBI required a kill switch for AI systems?
No. The kill switch appears in SEBI’s consultation paper on guidelines for the responsible usage of AI and machine learning, issued for comment on 20 June 2025. It is a draft proposal. SEBI’s final guidelines were confirmed still unissued on 3 September 2026, checked against SEBI’s own circular and regulation listings rather than against commentary.
What does the IFSCA frontier AI advisory require?
Despite its title, most of its annexure is drafted with “shall”: frontier AI carried as a named scenario in the cyber risk assessment and put before the Board, a Software Bill of Materials covering open-source components, an inventory of APIs and the applications consuming them with rate-limiting and a whitelist, critical service providers required to furnish evidence of frontier-AI preparedness, monitoring tuned for attack sequences faster than a human could run, and human oversight plus security testing of AI-generated code before production.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools