Artificial intelligence is no longer just an experimental tool for Indian banking; it is fundamentally rewriting the economics of credit delivery.
Speaking at the FIBAC 2026 conference in Mumbai, Reserve Bank of India (RBI) Governor Sanjay Malhotra made a definitive statement: AI will define the 2020s banking landscape just as liberalization did in the 1990s and digitalization in the 2010s.
Banks now face a critical choice to either deliberately architect their AI transition or let the technology dictate their future by default.
The potential upside is massive. Traditional underwriting struggles with new-to-credit borrowers, gig workers, and micro-enterprises lacking formal financial histories.
AI flips this script by analyzing alternative cash flows, GST filings, and digital footprints, drastically expanding the “bankable” demographic while slashing the marginal cost of loan origination.
Furthermore, AI-powered predictive models and voice interfaces in regional languages can dismantle barriers to financial inclusion.
When layered atop India’s robust digital public infrastructure including UPI, DigiLocker, ONDC, and [Aadhaar Redacted] AI has the potential to make financial judgment as instant and granular as digital transactions are today.
It also equips institutions to combat digital fraud that now moves at the speed of an API call, shifting security from rules-based reactive measures to real-time anomaly detection.
Navigating the Seven Critical Risks of Algorithmic Banking
Despite the immense potential, the RBI Governor outlined seven systemic risks that require immediate board-level attention. Leading the charge is the “black box” dilemma.
When generative AI or advanced machine learning models reject a loan application, the rationale must be clearly explainable to both the consumer and the regulator. Opacity is a regulatory liability.
Closely tied to this is the threat of algorithmic bias. AI systems trained on historical data can inadvertently weaponize past prejudices, redlining specific demographics, occupations, or geographies.
Fairness cannot be an afterthought; it must be engineered into the architecture from day one rather than treated as a compliance checklist.
Malhotra also warned against concentration and herding behaviors. If multiple financial institutions rely on identical third-party AI models, a single vulnerability could trigger a system-wide crisis. This herd mentality extends to algorithmic trading, where uniform AI responses to market stress could amplify volatility.
Banks must also navigate the treacherous waters of vendor dependency. Outsourcing AI capabilities requires stringent accountability frameworks, audit rights, and viable exit strategies if a model needs to be pulled.
Compounding these operational threats are severe data privacy and cybersecurity risks. AI feeds on massive data lakes, making robust privacy standards where the Digital Personal Data Protection Act serves as a baseline, not a ceiling mandatory.
Meanwhile, institutions must harden their defenses against novel cyber threats like model manipulation and data poisoning designed to blind AI fraud detectors.
Above all, Malhotra issued a stark warning against the erosion of human accountability. The phrase “the model decided” will never serve as a valid defense to an auditor, a customer, or the central bank.
The Blueprint for Explainable AI and Robust Governance
The central bank is not slamming the brakes on innovation, but it is demanding a structural overhaul of how banks deploy these technologies.
The RBI expects lenders to treat AI governance as an immediate operational necessity.
Institutions are now tasked with maintaining a comprehensive inventory of all active AI systems, including those embedded discreetly within third-party vendor products.
These deployments must operate under board-approved frameworks that explicitly map out accountability for algorithmic outcomes.
Before any system goes live especially in high-stakes areas like lending and fraud detection it must undergo rigorous red-teaming and stress testing, followed by continuous post-deployment auditing.
The RBI favors a principles-based, proportionate regulatory approach rather than imposing rigid, one-size-fits-all mandates.
A massive commercial bank running proprietary neural networks will naturally face different regulatory scrutiny than a regional lender using off-the-shelf software.
The regulator plans to collaborate closely with the industry through its regulatory sandbox, fostering safe environments to test edge cases while developing common security utilities like MuleHunter and the proposed Digital Payments Intelligence Platform.
The edge in this new era belongs to the institutions that deeply understand the mechanics of their algorithms, firmly maintain a human in the loop for high-risk decisions, and aggressively protect consumer trust.
Rapid deployment without governance will only invite systemic risk.
Source: Official Financial Express, "AI: A New Way of Running a Bank: RBI Governor Sanjay Malhotra Outlines Governance Roadmap, Flags 7 AI Risks"




