News and developments
RBI’S FREE-AI FRAMEWORK: NAVIGATING THE LEGAL AND REGULATORY LANDSCAPE
Overview
On August 13, 2025, the Reserve Bank of India (“RBI”) released the much-anticipated committee report on Framework for Responsible and Ethical Enablement of Artificial Intelligence (“FREE-AI”) in the financial sector. This comprehensive framework, developed by a committee chaired by Dr. Pushpak Bhattacharyya of IIT Bombay, marks a significant milestone in India’s approach to AI governance in financial services.
This article seeks to unpack the FREE-AI framework in a manner accessible to legal professionals, policymakers, industry professionals and lay readers alike. It explains the core principles and regulatory vision behind the framework, situates it within India’s broader legal landscape, and evaluates its potential impact on financial institutions, regulators, and consumers. Further, it examines whether the framework adequately addresses the pressing challenges of accountability, consumer protection, and liability in AI-driven decision-making, while highlighting areas where additional legal clarity or regulatory alignment may be required.
The Genesis and Necessity
The FREE-AI framework emerges at a critical juncture. As AI rapidly transforms financial services, from customer interactions to credit assessments and fraud detection, it brings both unprecedented opportunities and novel risks. The committee, constituted following the RBI’s Statement on Developmental and Regulatory Policies dated December 6, 2024, was tasked with developing guardrails that would enable innovation while protecting stakeholders. Unlike many reactive regulatory approaches globally, the RBI’s initiative is notably proactive, seeking to establish principles before widespread problems emerge.
Regulatory Context and Authority
The FREE-AI Framework has been released pursuant to RBI’s powers under the Reserve Bank of India Act, 1934 and the Banking Regulation Act, 1949. It reflects the regulator’s intent to bring AI adoption under its supervisory ambit in much the same way as IT governance, outsourcing, and digital lending frameworks were previously regulated.
While the framework itself is not yet a binding regulation, it is evident that several of its provisions are intended to be incorporated into Master Directions, which would make compliance mandatory for regulated entities (“REs”).
Scope of Application
The FREE-AI framework is designed to apply across the spectrum of REs under the RBI’s jurisdiction. This includes Scheduled Commercial Banks (SCBs), Non-Banking Financial Companies (“NBFCs”), Payment System Operators (PSOs), and FinTech entities engaged in providing financial services under RBI’s regulatory ambit. In essence, any institution operating under RBI’s oversight that deploys AI whether for customer interaction, credit assessment, risk monitoring, or operational support falls within the framework’s purview.
Interestingly, the framework also contemplates an indirect extraterritorial reach. While offshore technology providers and AI developers are not directly regulated by RBI, they will inevitably be drawn into the compliance net. This is because Indian financial institutions are expected to “flow down” RBI obligations through their contractual arrangements with third-party vendors and service providers. In practical terms, foreign AI suppliers will need to demonstrate compliance with the framework’s requirements such as explainability, fairness, and incident reporting if they wish to continue providing AI solutions to Indian financial institutions.
Key Compliance Requirements
The FREE-AI framework translates its guiding principles into six major compliance touchpoints for REs. These are not mere technical recommendations but governance mandates that elevate AI oversight to the same level as credit risk or cyber risk management.
Yet, as with any first-of-its-kind initiative, questions remain about its enforceability and practical impact.
Gaps and Challenges
While the FREE-AI framework is undoubtedly progressive, several legal and regulatory uncertainties remain that could shape its effectiveness in practice.
Final Reflections
The FREE-AI framework is more than just a policy document. It is a signal of intent. By setting ethical and governance guardrails at this early stage, the RBI is positioning India’s financial sector to embrace technological innovation without losing sight of accountability and consumer trust. Its message is clear: AI in finance is no longer a side experiment but a matter of regulatory concern at the highest level.
That said, several questions remain. Until incorporated into binding directions, the framework risks uneven adoption. Further, the liability among institutions, vendors, and developers is yet to be clarified and overlaps with existing data and consumer protection laws could complicate compliance. The path forward will require careful coordination among regulators and alignment with global practices. In this sense, FREE-AI should be viewed as the beginning or a foundation upon which India’s broader AI regulatory architecture will be built.
Co-authored by Vara Gaur, Partner ([email protected]) and Sakina Kapadia, Senior Associate ([email protected]).