Skip to content
August 11, 2026
Search
humaineetiblog AI engineered for your business
Share
AI 7 min read

The RBI FREE-AI framework, explained for engineering teams

The RBI's FREE-AI report sets out seven sutras, six pillars and 26 recommendations for AI in Indian finance. What BFSI engineering teams must operationalise: explainability, drift monitoring and grievance redressal.

On 13 August 2025 the Reserve Bank of India published the report of its committee on the Framework for Responsible and Ethical Enablement of Artificial Intelligence — FREE-AI. The committee had been constituted in December 2024 with four objectives: assess AI adoption in Indian financial services, review supervisory approaches, identify AI-related risks, and recommend a framework for responsible adoption.

The report is recommendatory, and that framing has led some institutions to file it for later. We think that reading is a mistake, for a reason the report itself supplies: it explicitly anticipates that the RBI may convert recommendations into binding requirements through Master Directions, circulars or other supervisory instruments. Where that happens, enforcement follows under existing statutory powers — the Banking Regulation Act, the Payment and Settlement Systems Act, and related statutes.

Institutions that build to the framework now will not be retrofitting under deadline later.

How much AI is actually deployed

The committee ran two surveys to establish a baseline. The finding worth carrying into any board conversation: roughly 20.8% of surveyed entities reported deploying AI systems, concentrated in customer support, sales, credit underwriting and cybersecurity.

Two of those four — credit underwriting and cybersecurity — are consequential decision domains. That is precisely why the framework leans as hard as it does on explainability and human oversight.

The structure: seven sutras, six pillars, 26 recommendations

FREE-AI is organised around seven guiding principles — the committee calls them sutras — and six strategic pillars, with 26 actionable recommendations distributed across them.

The sutras include trust as the foundation (AI systems should be reliable, transparent and inspire public confidence); people first (AI supports human decision-making but defers to human judgement, prioritising welfare, dignity and inclusion); innovation over restraint (encourage responsible innovation rather than reflexive restriction); fairness and equity (outcomes should be non-discriminatory); and accountability resting with the entities deploying AI, with clearly defined responsibility for AI decisions and their impacts.

The six pillars are Infrastructure, Policy, Capacity, Governance, Protection and Assurance. The first three are broadly enabling — indigenous models, data infrastructure integrated with AI Kosh, talent development, board-approved AI strategy. The last three are where engineering teams live.

The accountability sutra is where the most common architectural assumption breaks. Responsibility sits with the regulated entity. “The model provider’s system produced that output” is not a defence.

What this implies for how you build

Explainability has to be designed in, not reported on

The framework expects models to be explainable, with interpretation tooling such as SHAP or LIME applied where appropriate. For credit underwriting, the ability to reconstruct why a specific applicant received a specific outcome is an architectural requirement.

Systems that log only inputs and outputs cannot satisfy this after the fact. If the feature values, model version and decision path are not captured at inference time, they are not recoverable later — and a reconstruction produced by re-running today’s model against yesterday’s data is not evidence of what actually happened.

Consumers must know when they are dealing with AI

Disclosure obligations extend to chatbots, robo-advisory and automated underwriting. Alongside disclosure sits grievance redressal — a route for a customer to contest an AI-influenced decision and reach a human being.

That route has to exist operationally, with staffing, turnaround times and escalation paths, not only in a policy document. The RBI’s digital lending rules already require auditable AI credit assessments with human oversight and robust grievance redressal for AI-driven decisions, so this is a continuation rather than a departure.

Drift monitoring: the requirement most often missing

The framework asks institutions to extend IT and cybersecurity policies to cover AI-specific risks, bring AI into incident reporting, and monitor for model drift.

Drift is worth singling out because it is the control we most often find absent. A model that was accurate and fair at deployment can degrade quietly as the population it serves changes. Nothing errors. No alert fires. Detecting it requires continuous measurement against a documented baseline, disaggregated across the segments you care about — because aggregate accuracy can hold steady while performance for a particular group collapses.

Impact assessment before launch

New AI use cases are expected to undergo impact assessment prior to deployment. Institutions running mature model risk management have a foundation to extend. Those relying on general project governance will need something more specific, particularly for generative systems where the output space is not enumerable in advance.

Where FREE-AI sits in the wider regulatory stack

FREE-AI does not stand alone, and treating it in isolation produces duplicated effort.

  • DPDP Act and Rules — the horizontal personal-data layer. Rules notified November 2025, full enforcement expected May 2027, with penalties up to ₹250 crore. Notably, using AI for sizeable decision-making or profiling is among the indicative criteria for Significant Data Fiduciary status.
  • SEBI — Regulation 16C via the Intermediaries (Amendment) Regulations of February 2025, plus a June 2025 consultation paper on responsible AI/ML in securities markets proposing principles for governance, data privacy and cybersecurity, with a tiered approach by risk.
  • NITI Aayog — the national Responsible AI principles supplying the shared vocabulary.
  • Global alignment — the committee situates its recommendations against ISO/IEC AI standards and OECD analyses, favouring interoperability with international practice on documentation, model testing, explainability and fairness assessment.

The consistent direction across all of them: human oversight of consequential decisions, transparency about AI involvement, accountability with the deploying entity, fairness across populations, and security of personal data.

A pragmatic sequence

  1. Inventory every AI and ML system in production, including models embedded inside vendor products. Most institutions find more than the register shows.
  2. Classify by consequence to the customer. A fraud model that freezes accounts warrants different treatment from a document classifier.
  3. For high-consequence systems, verify you can reconstruct an individual decision from captured evidence — not by re-running the model.
  4. Confirm the human review path exists, is staffed, and is actually used rather than rubber-stamped.
  5. Establish drift monitoring against a documented baseline, disaggregated by segment.
  6. Fold AI incidents into the existing incident-reporting process rather than building a parallel one.
  7. Put AI use cases through impact assessment before launch, with generative systems getting explicit attention to output-space risk.

The institutions handling this well are not bolting compliance onto finished systems. They treat auditability, explainability and human oversight as design constraints — which, usefully, also produces systems that fail less often.

Frequently asked questions

Is the RBI FREE-AI framework mandatory?

Not currently. The report is recommendatory, but it explicitly anticipates that the RBI may convert particular recommendations into binding requirements through Master Directions, circulars or other supervisory instruments, enforceable under existing statutory powers.

What are the seven sutras of FREE-AI?

They are guiding principles covering trust as the foundation, a people-first stance in which AI defers to human judgement, innovation over restraint, fairness and equity in outcomes, and accountability resting with the deploying entity, alongside related principles on transparency and sustainability of AI adoption in finance.

What are the six pillars?

Infrastructure, Policy, Capacity, Governance, Protection and Assurance. Together they carry 26 actionable recommendations, spanning innovation sandboxes and indigenous financial models through to governance, audit and incident reporting.

How does FREE-AI relate to the DPDP Act?

They operate at different layers. DPDP governs personal data processing across all sectors with statutory force and a May 2027 enforcement horizon. FREE-AI is sector-specific guidance for financial services covering AI governance more broadly. Financial institutions are subject to both.

This article summarises publicly available material on the FREE-AI committee report for general information. It is not legal or compliance advice; institutions should consult the primary RBI publications and their own advisors.

Leave a Reply

Your email address will not be published. Required fields are marked *