# RBI FREE-AI framework: Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) Committee Report

Source: https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025
Last updated: Oct 5, 2026

The FREE-AI report, released by the Reserve Bank of India on 13 August 2025, is the report of the committee chaired by Dr. Pushpak Bhattacharyya of IIT Bombay on a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the financial sector. It sets out 7 Sutras (principles) and 26 recommendations under six pillars: Infrastructure, Policy and Capacity to enable innovation, and Governance, Protection and Assurance to mitigate risk. For regulated entities the most concrete recommendations are a board-approved AI policy (14), AI-specific product approval (17), consumer protection and AI disclosure (18, 25), an AI incident reporting framework (22), a semi-annually updated AI inventory (23) and a risk-based AI audit framework (24). The report recommends that the RBI consider issuing consolidated AI guidance, but it is not binding; as of 5 October 2026 no RBI directions adopting it were found on rbi.org.in.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) |
| Type | Report |
| Status | Final |
| Published | Aug 13, 2025 |
| Applies to | India's financial sector. The report is addressed to regulators (including the RBI and other financial sector regulators), regulated entities (REs) such as banks and NBFCs, industry bodies and government. It is a committee report of recommendations; it is not itself an RBI direction, and each recommendation names the party that should act (REs, regulators, industry or government). |
| Official text | https://www.rbi.org.in/Scripts/PublicationReportDetails.aspx?ID=1306 |

## Key points

- Seven Sutras: Trust is the Foundation; People First; Innovation over Restraint; Fairness and Equity; Accountability; Understandable by Design; and Safety, Resilience and Sustainability.
- Six pillars and 26 recommendations: Infrastructure (1 to 5), Policy (6 to 9) and Capacity (10 to 13) for innovation enablement; Governance (14 to 17), Protection (18 to 22) and Assurance (23 to 26) for risk mitigation.
- Recommendation 14: REs should establish a board-approved AI policy covering governance structure, accountability, risk appetite, operational safeguards, auditability, consumer protection measures, AI disclosures, model life cycle framework and liability framework; Annexure V gives a suggested outline.
- Recommendation 16: robust model governance across the AI lifecycle (design, development, deployment, decommissioning), documentation, validation and drift monitoring, and strong governance with human oversight before deploying autonomous AI systems, especially for medium and high-risk uses.
- Recommendations 17 and 18: bring all AI-enabled products into the product approval framework with AI-specific risk evaluation, and set up a board-approved consumer protection framework on transparency, fairness and accessible recourse, with consumer awareness efforts.
- Recommendation 22: financial sector regulators should establish a dedicated AI incident reporting framework for REs and FinTechs with a tolerant, good-faith approach to encourage timely disclosure; Annexure VI is an indicative incident reporting form.
- Recommendations 23 and 24: a comprehensive internal AI inventory updated at least half yearly and available for supervisory inspection, and a risk-based AI audit framework with internal audits, third-party audits for high-risk or complex use cases and review at least biennially.
- Recommendation 8: a graded liability framework in which REs remain liable for customer losses but supervisors take an accommodative stance for first-time or one-off aberrations where safety mechanisms such as incident reporting, audits and red teaming were followed, denied for repeated breaches, gross negligence or failure to remediate.

## What changed for banks

The report is the RBI's published framework on AI in the financial sector and the reference point cited in its later work, including the June 2026 draft Guidance on Regulatory Principles for Model Risk Management. It moved Indian AI policy for banks from general technology and outsourcing rules to a structured set of expectations on board policy, inventory, audit and incident reporting, while leaving adoption as binding rules to future RBI action.

## Use cases it governs

- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Customer-facing chatbots](https://www.bankingnewsai.com/ai-regulation/by-use-case#customer-chatbots)
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy)

## What does the RBI's FREE-AI framework recommend that banks do?

The FREE-AI Committee report of 13 August 2025 recommends that regulated entities adopt a board-approved AI policy, bring AI-enabled products under product approval with AI-specific risk evaluation, run lifecycle model governance with human oversight of autonomous systems, set up a consumer protection framework, strengthen cybersecurity and red teaming, extend business continuity plans to AI failures, keep an AI inventory updated at least half yearly, and run risk-based AI audits with third-party audits for high-risk uses. It also asks regulators to build an AI incident reporting framework, a graded liability approach and an AI disclosure framework. The recommendations are not binding RBI directions; Recommendation 6 says the RBI may consider issuing consolidated AI guidance, and the RBI's June 2026 draft model risk guidance partly takes this forward.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Recommendation 14 — Board-approved AI policy | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | REs should establish a board-approved AI policy covering governance, accountability, risk appetite, safeguards, auditability, consumer protection, disclosures, model lifecycle and liability. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 16 — AI system governance framework | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Govern the whole AI model lifecycle, with documentation, validation and drift monitoring, and human oversight before deploying autonomous AI, especially for medium and high-risk uses. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 17 — Product approval process | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Bring all AI-enabled products and solutions into the institutional product approval framework, with AI-specific risk evaluations. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 18 — Consumer protection | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Establish a board-approved consumer protection framework prioritising transparency, fairness and accessible recourse, and invest in consumer awareness on safe AI use. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 20 — Red teaming | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Run structured red teaming across the AI lifecycle, proportionate to risk, with trigger-based red teaming for evolving threats. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 21 — Business continuity for AI systems | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Extend BCP frameworks to AI model degradation, with fallback mechanisms tested through BCP drills. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 22 — AI incident reporting | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Regulators should establish an AI incident reporting framework for REs and FinTechs with a tolerant, good-faith approach to timely disclosure. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 23 — AI inventory | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Maintain an internal AI inventory of models, use cases, target groups, dependencies, risks and grievances, updated at least half yearly and available for supervisory inspection. | Recommended; short term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 24 — AI audit framework | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Implement a risk-based AI audit framework with internal audits, independent third-party audits for high-risk or complex uses, and review at least biennially. | Recommended; medium term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |
| Recommendation 25 — AI disclosures | [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Include AI-related disclosures in annual reports and websites; regulators should specify an AI disclosure framework. | Recommended; short term | [RBI FREE-AI framework](https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025) |

FREE-AI is an enabling-and-safeguards framework. Its innovation pillars call for shared data infrastructure, an AI Innovation Sandbox, indigenous financial-sector AI models, a sector-wide AI policy framework anchored in the Sutras and an AI Standing Committee under the RBI; its risk pillars place most duties on regulated entities. The timeline column of the report labels each recommendation short term or medium term and names who should act.

The report's Annexure IV lists AI-specific clarifications and enhancements in select RBI Master Directions, showing where existing rules already reach AI. The RBI's June 2026 draft Guidance on Regulatory Principles for Model Risk Management, which covers AI/ML and third-party models, is the nearest follow-through, and the RBI's Utkarsh 2029 strategy lists a framework on the use of AI in the financial sector among its deliverables.

### What this means in practice

- Draft a board-approved AI policy using the outline in Annexure V, covering the elements Recommendation 14 lists, even though adoption is not yet mandatory.
- Build an AI inventory (models, use cases, dependencies, risk tier, grievances) refreshed at least half yearly and ready for supervisory inspection.
- Add AI-specific risk evaluation to the product approval process and extend business continuity and red-teaming programmes to AI systems.
- Prepare an AI incident log and escalation process aligned with the indicative form in Annexure VI.
- Track the RBI's final model risk guidance, which would turn parts of this into binding expectations.

## FAQ

### What is the RBI FREE-AI framework?

FREE-AI is the Framework for Responsible and Ethical Enablement of Artificial Intelligence in the financial sector, the report of a committee set up by the RBI on 26 December 2024 and released on 13 August 2025. It contains 7 Sutras and 26 recommendations under six pillars: Infrastructure, Policy, Capacity, Governance, Protection and Assurance.

### Is the RBI FREE-AI framework binding on banks?

No. It is a committee report of recommendations addressed to regulators, regulated entities, industry and government. Recommendation 6 says the RBI may consider issuing consolidated AI guidance; as of 5 October 2026 the RBI had published a draft Guidance on Regulatory Principles for Model Risk Management that covers AI/ML, but no direction adopting the report as a whole.

### What does FREE-AI recommend that banks do?

Among its recommendations for regulated entities: adopt a board-approved AI policy, bring AI products into the product approval process, build a consumer protection framework and disclosures, strengthen cybersecurity and red teaming, plan business continuity for AI failures, report AI incidents, keep a semi-annually updated AI inventory and run risk-based AI audits.

### How does FREE-AI compare with the EU AI Act or SS1/23?

The EU AI Act is binding regulation that classifies AI systems by risk. FREE-AI is a set of recommendations rooted in 7 Sutras that favours innovation alongside risk controls, and proposes graded liability for good-faith aberrations. PRA SS1/23 sets model risk supervisory expectations for UK banks; the RBI's closer analogue is the June 2026 draft model risk guidance.

## Related documents

- [RBI draft Guidance on Regulatory Principles for Model Risk Management](https://www.bankingnewsai.com/ai-regulation/documents/rbi-model-risk-management-guidance-2026) — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) (Jun 24, 2026)
- [RBI draft circular on Regulatory Principles for Management of Model Risks in Credit](https://www.bankingnewsai.com/ai-regulation/documents/rbi-model-risks-credit-circular-2024) — Regulatory Principles for Management of Model Risks in Credit (draft circular for comments) (Aug 5, 2024)
- [SB 947](https://www.bankingnewsai.com/ai-regulation/documents/ca-sb-947-2026) — Employment: Automated Decision Systems (No Robo Bosses Act) (Sep 30, 2026)
- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [AB 1609](https://www.bankingnewsai.com/ai-regulation/documents/ca-ab-1609-2026) — Customer Service Chatbots (Right to Human Customer Service Act) (Sep 28, 2026)
- [Atkins remarks at Investor Advisory Committee (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/sec-atkins-iac-ai-disclosure-remarks-2026-09) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information Ecosystem (Sep 10, 2026)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [FSB Chair's letter to G20 (Aug 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-chair-letter-g20-august-2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models (Aug 31, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.rbi.org.in/Scripts/PublicationReportDetails.aspx?ID=1306) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/rbi-free-ai-framework-2025
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
