RBI’s AI Draft Sends A Clear Message: Banks Cannot Blame The Algorithm

Experts say banks remain liable despite AI-assisted decision-making.
When a bank rejects a loan application, flags a transaction as suspicious or assigns a customer a risk score, artificial intelligence is no longer a distant possibility. It is increasingly part of the decision-making process. This makes the legal question unavoidable, what if AI gets it wrong? Who is responsible?
The Reserve Bank of India’s draft Guidance on Regulatory Principles for Model Risk Management, 2026, released for public consultation on June 24, appears to answer this question. Banks and non-banking financial companies may use AI, machine learning and third-party technology systems, but they cannot transfer accountability to the algorithm or the vendor.
Once finalised, the draft will replace the RBI’s 2002 guidance on credit risk models. Its significance lies not merely in updating an old framework, but in recognising that AI is now embedded in core financial functions.
The RBI has not chosen to create a separate liability regime for AI. Instead, it has folded AI into a broader model risk management framework. It appears to suggest that the regulator does not see AI as an independent legal actor, but as a tool deployed by regulated entities, which must remain answerable for its consequences.
Gowree Gokhale, Advocate & Solicitor and independent legal counsel, captures this point sharply. She says the RBI has consciously retained the regulated entity as the primary point of accountability because lending decisions ultimately remain business and regulatory decisions that cannot be attributed solely to an algorithm.
“The adoption of AI should not become a mechanism to dilute existing obligations relating to consumer protection, fair lending, transparency and accountability. AI may assist decision-making, but it cannot become the legal decision-maker,” she says.
This is the core of the draft. AI may support a decision, but it cannot become the entity responsible for it.
Supratim Chakraborty, Partner at Khaitan & Co., views this as a deliberate regulatory choice rather than an omission. According to him, the RBI has consciously integrated AI into a technology-neutral model risk management framework instead of creating a separate AI-specific liability regime.
That approach attempts to balance innovation with consumer protection. Financial institutions should not be discouraged from using technology, but customers should not be left remediless when technology produces harmful outcomes.
Dr. Ajai Garg, Head, Digital Tech & AI, Anand and Anand, also sees the draft as a major step towards responsible AI use in financial services. According to him, the framework “does not dissuade banks and NBFCs from using technology,” which is increasingly important for efficient credit disbursal, fraud detection and client services. Instead, it introduces a broader model risk management discipline where AI systems must be “explainable, auditable, controllable, and subject to human oversight.”
This is where the draft could reshape the banking ecosystem. Banks, fintech vendors, software providers and customers will now operate in a more accountable AI environment. As Garg notes, the sector may move from AI experimentation to “governed AI deployment,” where innovation must function within board-approved risk frameworks, customer protection standards and operational resilience mechanisms. The draft’s strongest message appears to be that responsibility cannot be outsourced.
For a customer wrongly denied credit or affected by an inaccurate risk score, the relevant question should not be whether the error came from bad data, a defective model, a vendor system or a flawed internal process. The bank or NBFC deploying the system must remain the first point of accountability.
Gokhale’s view supports this distinction. Regulated entities may later pursue contractual remedies against AI vendors where defects in technology or inaccurate outputs contribute to the harm, but customers and regulators should not have to navigate the complexities of the AI supply chain.
Ravi Goyal, Partner at Scriboard, says the draft reinforces this position by expressly requiring human oversight over AI-driven decisions and grievance redressal mechanisms for consumer-facing AI systems.
According to him, the RBI’s emphasis on due diligence, human supervision and customer grievance mechanisms demonstrates that AI remains a technological tool deployed by regulated entities, which must continue to answer for its outcomes irrespective of whether the model was developed internally or procured from a third party.
That is crucial. Commercial contracts between banks and vendors may contain indemnities, warranties and audit rights, but such arrangements cannot dilute regulatory obligations owed to customers or the RBI.
At the same time, the draft does not answer every question. Modern AI systems often involve several actors, including model developers, cloud providers, data suppliers, fintech partners and deployment teams. In such layered ecosystems, determining who caused the error may become difficult.
Chakraborty’s suggestion for further guidance on responsibility allocation across multi-party AI ecosystems and third-party deployment models is therefore important. Without such clarity, regulated entities may remain accountable externally, while disputes over internal allocation of responsibility become increasingly complex.
Garg raises an even larger concern. While he welcomes the guidelines as a step towards responsible AI adoption, he argues that legal accountability in critical sectors such as finance, healthcare and education should eventually be defined through law rather than guidelines. In his view, this would empower judicial systems to create a clearer accountability matrix for AI adoption instead of leaving responsibility to interpretation.
That may be the next stage of India’s AI governance debate. For now, however, the RBI’s direction is unmistakable. AI can help banks make faster, more efficient and more sophisticated decisions. But when those decisions affect access to credit, financial reputation or customer rights, there must always be a human institution that can be questioned, audited and held responsible. The algorithm may assist the bank but it cannot become the bank’s excuse.
