3 Sources
[1]
RBI mandates kill switch for AI models at banks, introduces comprehensive model risk framework
The Reserve Bank of India is implementing stringent rules for banks and financial entities using Artificial Intelligence. A new draft framework mandates 'kill switches' for AI models, ensuring immediate shutdown if errors occur. Banks must also ensure human oversight, disclose AI use to customers,
[2]
Lowdown: RBI wants banks to add sill Switches, human oversight for AI models - MEDIANAMA
Banks and other regulated entities (REs) may soon have to ensure every artificial intelligence (AI) system they deploy can be overridden, suspended or deactivated through "kill-switch arrangements", under the Reserve Bank of India's (RBI) draft Guidance on Regulatory Principles for Model Risk
[3]
RBI proposes guidelines for banks to manage AI risks
MUMBAI, June 24 (Reuters) - India's central bank has proposed rules requiring banks to strengthen oversight of risks tied to AI and machine-learning models, mandating board-approved policies, stronger controls and model inventories. The Reserve Bank of India said banks must put in place a
Share
Copy Link
The Reserve Bank of India has released draft guidelines requiring banks and financial institutions to install kill switches for all AI systems, ensuring immediate shutdown capabilities. The comprehensive framework introduces board-level accountability, mandatory human oversight, and strict controls on third-party AI vendors, with public consultation open until July 24, 2026.
The Reserve Bank of India has released a sweeping draft framework that will fundamentally reshape how banks and financial institutions deploy and manage artificial intelligence systems. The draft Guidance on Regulatory Principles for Model Risk Management, 2026, released for public consultation on Wednesday, mandates that all regulated entities must have the ability to instantly override, suspend or deactivate any AI model through kill switch arrangements
1
. This requirement ensures that no AI system can operate without the capability to be immediately shut down if it produces harmful or erroneous outputs. Stakeholders have until July 24, 2026, to submit comments on the proposed RBI AI guidelines2
.
Source: ET
The RBI draft framework for AI establishes stringent requirements for human oversight for AI across all automated decision-making systems. Regulated entities must implement human-in-command mechanisms, including human-in-the-loop or human-on-the-loop oversight arrangements
2
. The framework specifically addresses automation bias—the tendency of bank employees to over-rely on AI outputs without applying independent judgment. Personnel responsible for overseeing AI systems must possess sufficient expertise to effectively challenge, override, or escalate concerns in model outputs where required. For customer-facing AI systems, banks must disclose to customers that they are interacting with an AI system and provide them with the option to switch to a human at any point1
. The Reserve Bank of India has also mandated periodic human review of model outputs and AI-driven decisions to identify anomalies, with regular reviews of human interventions, overrides, incidents and near misses.For the first time, AI governance in banking is being placed squarely at the board level. Every regulated entity must establish a board-approved model risk management framework covering all models—whether built internally, sourced from vendors, or a combination
1
. The board is responsible for approving the entity's risk appetite for model risk and setting policies for risk classification. The framework introduces a risk-based tiering structure requiring regulated entities to classify all models—from simple spreadsheet-based calculators to complex frontier AI systems—by their risk level, and apply proportionate oversight accordingly1
. High-risk models require approval from the Risk Management Committee of the Board before deployment and cannot be cleared by technology or risk teams alone. The risk tier of a model must be reviewed at least annually, with AI models assessed based on the extent of reliance and level of autonomy placed on model outputs for decision-making2
.Related Stories
The draft guidelines take a particularly firm stance on third-party AI vendors and externally sourced AI models in financial sector. A regulated entity remains fully accountable for the outcomes of any model it uses, regardless of whether it built the model itself or acquired it from outside
1
. The RBI has specifically flagged supply chain risk—the risk arising from over-dependence on a limited number of AI model providers—as a concern that banks must actively manage. This represents a pointed reference to the growing concentration of AI capabilities in a handful of global technology companies. For material third-party AI models, datasets and dependencies, regulated entities should consider risks arising from dependence on a limited number of providers, limitations in independently validating models, and behavioral changes resulting from provider-driven updates2
. Banks must ensure all models, including third-party models, are subject to independent validation3
.The RBI has introduced specific requirements for model explainability that go beyond conventional model validation. Banks must define explainability thresholds for all AI models—the ability to explain, in understandable terms, why a model produced a particular output
1
. Models relied upon for material decision-making or having significant impact on customers or operations should meet higher explainability standards2
. For generative AI models that interface with customers or external users, additional cybersecurity controls must be implemented3
. The guidelines apply to commercial banks, small finance banks, payments banks, local area banks, co-operative banks, regional rural banks, NBFCs, all-India financial institutions, asset reconstruction companies and credit information companies2
. If risks are found to be excessive, lenders should take timely corrective steps, including enhanced controls, restrictions on use, remediation or decommissioning of the model, and submit a report to the board's risk management committee3
.Summarized by
Navi
[1]
[2]
[3]
14 Aug 2025•Policy and Regulation

12 Aug 2026•Policy and Regulation

08 Oct 2025•Policy and Regulation

1
Technology

2
Science and Research

3
Technology
