The Reserve Bank of India (RBI) wants Indian banks to use artificial intelligence to approve loans that human assessors would traditionally reject. Speaking at the FIBAC 2026 conference in Mumbai, Governor Sanjay Malhotra laid out a detailed roadmap covering expected use cases, the risks to be managed and the governance standards lenders must meet.
🔑 Key takeaways
- The RBI is asking Indian banks to adopt AI across lending and operations
- Models can use cash flows, GST filings, utility payments and digital footprints to assess borrowers
- Seven risks are flagged: opacity, bias, concentration, third-party dependence, privacy, cyber, judgment erosion
- Banks must inventory every AI system and retain effective human oversight
- The regulator will follow a principles-based, proportionate approach rather than rigid rules
AI as a new paradigm for Indian credit
Addressing senior executives of the Indian banking sector, Sanjay Malhotra described artificial intelligence as a « new way of running a bank », a shift comparable to the liberalisation of the 1990s or the digitalisation of the 2010s. He urged lenders to deliberately shape their AI journey rather than let the technology shape them by default.
« Artificial intelligence is not a single technology to be procured, nor a project to be completed. It is a new way of doing business, of running a bank. »
Sanjay Malhotra, Governor of the Reserve Bank of India
For Malhotra, AI should be treated as « a capability to be responsibly harnessed, not merely as a risk to be managed ». That deliberately proactive stance stands in contrast with the defensive posture usually adopted by central banks towards emerging technology.

Expanding the pool of bankable borrowers
For the governor, the central prize is access to credit. Conventional scoring models struggle to assess new-to-credit consumers, gig economy workers and very small businesses lacking formal books. AI can instead exploit alternative data: cash flows, GST filings, utility payments and digital footprints.
| Data source | Scoring use case | Target population |
|---|---|---|
| Bank cash flows | Real-time solvency assessment | Self-employed workers |
| GST filings | Revenue verification | SMBs and micro businesses |
| Utility payments | Household financial stability | Unbanked households |
| Digital footprints | Behavioural credit models | First-time borrowers |
This approach could « significantly expand the pool of borrowers considered bankable » while reducing the marginal cost of underwriting, Malhotra argued. AI-driven credit risk models would also help lenders detect emerging stress earlier, well before it shows up in traditional financial statements.
Voice interfaces for financial inclusion
The governor also highlighted inclusion gains from voice-based interfaces in Indian languages, which could break down linguistic barriers for rural or low-literacy customers. Combined with predictive models, these tools could identify at-risk borrowers early enough for lenders to offer support rather than triggering recovery action.
India enjoys a structural advantage thanks to its digital public infrastructure. Malhotra pointed to Aadhaar (digital ID), UPI (instant payments), DigiLocker, ONDC, the Account Aggregator framework and the Unified Lending Interface (ULI) as platforms capable of supporting further innovation.
« AI, layered on top of this stack, has the potential to do for financial judgment what UPI did for financial transactions: make it instant, granular, and available to the last mile. »
Sanjay Malhotra, Governor of the Reserve Bank of India
Fraud fighting and operational gains
Beyond lending, AI is expected to sharpen fraud detection. « Fraud today moves at the speed of an API call », Malhotra warned, noting that static rules-based systems struggle to keep pace with criminals who constantly rotate their methods. Machine learning models can learn continuously from transaction patterns and flag anomalies in real time, potentially intercepting fraudulent transactions before losses crystallise.
Internally, AI could automate document processing, reconciliation, internal audit sampling and regulatory reporting. AI-assisted relationship managers could identify suitable products and risk alerts faster, allowing each employee to serve more customers. Banks would free up skilled staff to focus on tasks that genuinely require human judgement.
Seven risks flagged by the RBI
The governor’s support for AI comes with a clear warning on the risks that must be contained. He listed seven, which will shape the regulator’s supervisory doctrine.
| Risk | Concrete manifestation | Expected response |
|---|---|---|
| Black box | Lending decisions that cannot be justified | Mandatory explainability |
| Bias and exclusion | Discrimination reproduced by models | Fairness built in by design |
| Concentration | Same vendor equals systemic risk | Model diversification |
| Third-party dependence | Vendor lock-in, no audit rights | AI-specific contractual clauses |
| Data privacy | Massive data collection footprints | Beyond-statutory safeguards |
| Cybersecurity | Data poisoning, model manipulation | Regular adversarial testing |
| Judgment erosion | Responsibility shifted to the model | Human oversight maintained |
On this last point, Malhotra delivered what is likely to become the most quoted line of his speech. On bias and exclusion, he stressed that fairness must be embedded from the start, not bolted on as a compliance afterthought. On concentration, he warned of herd behaviour: if several banks rely on the same AI trading models, they could react identically during market stress, amplifying volatility.
Governance and human accountability
The RBI wants banks to treat AI governance as an immediate priority. Every lender must maintain a complete inventory of its AI systems, including AI embedded in vendor products. A board-approved AI governance policy must fix clear accountability for outcomes.
« ‘The model decided’ can never be an acceptable answer to a customer, an auditor, or the Reserve Bank. »
Sanjay Malhotra, Governor of the Reserve Bank of India
Banks must also red-team and stress-test models before deployment, then on a recurring basis in production. Human oversight must remain in place wherever an AI error could cause material harm to customers or to financial stability.
The Digital Personal Data Protection Act represents « the floor, not the ceiling, of what customers should expect from their bank », the governor warned. Outsourcing contracts will need to grant AI-specific audit rights, the ability to demand explanations from vendors and a credible exit plan should a model or supplier fail.
Principles-based and proportionate regulation
Malhotra announced a deliberately flexible regulatory stance: guiding principles rather than rigid rules, and proportionality calibrated to each institution’s risk profile. A large bank running proprietary models does not face the same constraints as a small lender using an off-the-shelf product from a software vendor.
The RBI will continue to operate its regulatory sandbox to test innovative use cases and plans to facilitate common utilities, including MuleHunter and the proposed Digital Payments Intelligence Platform, to strengthen fraud detection at the system level.
Research by Elisabeth Paulson at Harvard Business School, published in PNAS Nexus in December 2024, offers useful context on public attitudes towards algorithmic lending. Across 9,000 participants, respondents chose a human decision-maker in a hypothetical loan scenario by a 4.3-percentage-point margin. Participants cared most about reducing collective risk; fairness across racial groups was systematically the least important factor. If algorithms can demonstrate clear superiority in accuracy, « people will likely prefer them », Paulson concluded.
Conclusion: it won’t be the banks that deploy the most AI that win
Malhotra’s message was twofold. India enjoys exceptional assets to make AI a lever for financial inclusion and banking modernisation. But the RBI will not countenance hasty adoption that sacrifices explainability, accountability or customer trust on the altar of performance.
The bullish scenario sees Indian banks combining UPI, ULI and AI models to dramatically lower the cost of lending to SMBs and underbanked households, securing a durable competitive edge in emerging markets. The bearish scenario is a systemic incident, a large-scale bias event or a compromised single-vendor dependency, that shakes confidence in the entire sector. Governance, more than the technology itself, is the real differentiating factor.
Sources
- Financial Express
- The Banker
- Yahoo Finance
- Bloomberg
- Harvard Business School – Working Knowledge
- The Register
This article is published for informational and educational purposes. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

