The Reserve Bank of India closed comments on its first AI in lending rulebook on July 24 and spent August at a banking conference making the same point: the algorithm gets the call, the bank gets the liability.
The Reserve Bank of India closed public comments on its first dedicated rulebook for AI/ML models in credit decisions on July 24, 2026. On August 11, 2026, Governor Sanjay Malhotra used the country's main banking conference to tell lenders the bank owns the decision even when the model says yes.
Malhotra told the FIBAC audience that artificial intelligence could "close existing gaps in financial inclusion faster than any preceding technological innovation" (New Indian Express, Aug 11 2026). The RBI press release prid=63006 and the draft guidance together set the first regulatory floor in India for AI/ML models in credit underwriting, customer interaction, and other business processes.
The guidance applies to every regulated lender RBI oversees: commercial banks, small finance banks, payments banks, local area banks, regional rural banks, urban and rural cooperative banks, all-India financial institutions, non-banking financial companies (NBFCs), asset reconstruction companies, and credit information companies. The draft runs alongside RBI's August 2025 report from the Committee on FREE-AI, which set the wider AI risk agenda. Where the June draft differs is that it lands in the specific business of saying yes to a borrower.
Credit-underwriting models must be explainable. Lenders must build human-in-the-loop or human-on-the-loop arrangements into the decision flow. A kill switch is mandatory: a documented mechanism for a human officer to override the model. The board has to approve a Model Risk Management Framework. Outsourcing the model to a vendor does not outsource the risk, which the draft text says in those terms.
The draft widens the lane for AI and narrows the lane for vendor escape. Malhotra made the same point at FIBAC: "ultimate responsibility has to lie with the bank, and not with the vendor or the algorithm" (New Indian Express). He used the UPI analogy: the public rails underneath the decision do not move the liability to the rails.
The borrower the Governor has in mind is the one the file-based system shuts out: a small merchant whose paper trail is GST filings, UPI flows, and account-aggregator data; a first-time borrower whose only financial record is on the public rails; a gig worker, a kirana shop owner, a small-business borrower who has never had a salaried credit file.
The substrate, in Malhotra's telling, is the digital public infrastructure India built over the last decade. Aadhaar for identity. UPI for payments. DigiLocker for documents. The account aggregator framework for consented data sharing. The unified lending interface, which lets a lender query that data through a single API. With those rails, the argument goes, an AI underwriting model has more to work with than a human reviewer pulling a file.
Wire coverage called the proposal an instruction to let AI overrule human loan officers. The draft and the speech instead ask lenders to let AI approve borrowers the human system already declined, with the kill switch, explainability, and a board-approved framework installed first.
Two things will tell whether the regime works. The first is what "explainability" means in practice. A rule that requires an explainable model can be honored by a two-page feature-importance chart in a risk report. It can also be honored by an intelligible reason code on every decline, in plain language, that a borrower can read and dispute. The draft requires the former. The supervisor's job is to deliver the latter.
The second is how often the kill switch is used. A documented override is not the same as a used override. India's regulated lender universe is wide: NBFCs alongside the bank system, urban cooperative banks, payments banks, all of them now covered by the same draft. If AI-led approvals scale at the volume the Governor is betting on, the share of decisions that never reach a human reviewer will be the variable worth watching. Specialist NBFC analysis has flagged the same gap: the rules are sound, but supervisory follow-through, not the rule text, decides whether new-to-credit borrowers are reached or whether the AI simply re-rates the existing pool at lower cost.
The next milestone is the final guidance, expected to land in the second half of 2026. The version that issues will tell whether the kill switch the draft mandates is a real lever, with overrides used and reviewed, or a checkbox on a model-risk form.