AI
RBI AI Kill Switch Draft Leaves Banks Owning Vendor Models
RBI’s AI kill switch is one paragraph. The June draft would make banks own every vendor model they cannot inspect, and the circular still has not landed.
The Reserve Bank of India wants every bank AI system to have a kill switch, and it wants the bank, not the vendor, to own the outcome. That pairing is the June draft, not a finished circular.
The document is the draft Guidance on Regulatory Principles for Model Risk Management, 2026, released on June 24 as press release 2026-2027/528. Comments closed on July 24. On September 12 the same item still sat on the Reserve Bank’s draft-notifications list.
The Kill Switch in Paragraph 60
The off-button is real, and it is narrow. It lives in the AI chapter, as paragraph 60, among 64 numbered paragraphs across six chapters. It is not a separate AI law, and it is not in force.
Paragraph 60 asks each regulated entity to keep humans in command of AI models, including automated decisions. The risk tools listed with that duty are human-in-the-loop or human-on-the-loop arrangements, override, suspension or deactivation mechanisms including kill-switch arrangements, and periodic human review of outputs to catch anomalies.
An RE should establish robust human oversight for AI models including use cases involving automated decision-making by models. It should establish appropriate risk mitigants which inter-alia include: (i) Human-in-command arrangements (e.g., human-in-the-loop / human-on-the-loop / other human oversight mechanisms); (ii) override, suspension, or deactivation mechanisms, including kill-switch arrangements; and, (iii) periodic review of model outputs and model-driven decisions by humans to identify anomalies.
Reserve Bank of India, draft Guidance on Regulatory Principles for Model Risk Management, 2026, paragraph 60
Paragraph 61 adds automation bias, over-reliance on model outputs, and decision fatigue. Staff who oversee the models must be able to challenge, override or escalate what the system produces. A switch that has never been tested, with no named owner, no trigger, and no fallback, is a line in a policy, not a control.
That is the piece that travelled as the kill-switch headline from June. The rest of the draft is about who is on the hook when the model cannot be opened.
Banks Cannot Kill Models They Do Not Run
Paragraph 8 is the spine. A regulated entity is accountable for the outcomes of all models it uses, whether built inside, bought in, or mixed. Paragraph 45 repeats the same rule for third-party models at any stage of the lifecycle. Vendor certificates do not count as the bank’s own check.
A bank cannot switch off a model it does not operate. Frontier systems from a handful of global providers sit behind APIs, update on the provider’s clock, and often will not hand over weights, training data or a full design file. Paragraph 51 already names that case: if the third-party provider does not disclose adequate information, the lender should identify the risks and put mitigants in place, “such as limiting the usage.”
Paragraph 53 goes further for material third-party AI, datasets and dependencies. Lenders should weigh extra risk from dependence on a limited number of model providers, including supply chain risk, limits on independent validation, and behaviour changes from provider-driven updates. Paragraph 49 brings foundational and frontier AI models into that net and asks for extra controls matched to customer, business and financial impact.
THE DUTIES THE DRAFT SPLITS
| Duty | Who carries it |
|---|---|
| Outcomes of every model in use | The bank or NBFC, even when a vendor built it |
| Independent validation | The regulated entity; vendor assurance is not a substitute |
| Kill-switch, override and suspension | The regulated entity must be able to stop the model |
| Minimum technical documents and audit access | Must be written into the vendor contract |
| Vendor will not open the model | Identify the gap and limit use or add other mitigants |
| Retired models | Stay on the inventory for at least ten years |
That split is why procurement, not the red button, is the part that will move first. A contract that cannot deliver documentation, audit rights, continuity and a clean exit is a model the risk committee may never clear. A model the vendor will not open is, under paragraph 51, a model the bank should use less.
How a 2002 Credit Note Grew Into Frontier AI Rules
The June text is a rewrite of an old credit chapter, not a sudden AI panic. Paragraph 64 says that once the guidance is final, it would supersede Chapter 3 on Credit Risk Models in the Guidance Note on Credit Risk Management dated October 12, 2002. The Reserve Bank had already floated a credit-only model-risk draft on August 5, 2024. This one covers every model that materially affects a business decision, including a spreadsheet that sets a lending rate.
The AI overlay has a named parent. In December 2024 the Reserve Bank formed the Committee on the Framework for Responsible and Ethical Enablement of Artificial Intelligence. On August 13, 2025 it published the FREE-AI committee report, built on 7 sutras, 6 pillars and 26 recommendations. Sutra 2, People First, says AI should augment human decision-making but defer to human judgment, and that humans should be able to override AI. Paragraph 60 is that sutra written as an operating rule.
The June press release, signed by Chief General Manager Brij Raj, cites both the 2024 credit draft and the FREE-AI report as the path into this document. It also points at Utkarsh 2029: further requirements for AI models, if any, may be issued later. The kill switch is a floor, not the last word.
THE PATH INTO THE JUNE DRAFT
- October 12, 2002: Chapter 3 of the credit-risk guidance note covers credit models only.
- August 5, 2024: A draft on regulatory principles for model risks in credit goes out for comment.
- December 2024: The FREE-AI committee is formed.
- August 13, 2025: The FREE-AI report sets 7 sutras, including People First and a human override.
- June 24, 2026: The all-models draft, including AI and third-party systems, is released as press release 2026-2027/528.
- July 24, 2026: Public comments close.
- September 12, 2026: The draft is still listed among open draft notifications.
Anthropic’s Mythos model sat in the background of that June week. In April, Finance Minister Nirmala Sitharaman described Mythos as a new challenge for the financial system. The model is built to find software flaws, which is why supervisors treated it as a cyber problem as well as an AI problem. The draft itself never names Mythos. It names frontier models, supply-chain concentration, and the right to shut a system down.
Eleven Kinds of Lender, One Inventory
The press release lists 11 kinds of regulated entity, not just private and public commercial banks. Foreign banks are inside the commercial-bank bucket under the Banking Regulation Act, 1949. Small finance banks, payments banks, local area banks, regional rural banks, urban and rural co-operative banks, all four NBFC layers, the all-India financial institutions, asset reconstruction companies and credit information companies are in the same frame.
The five all-India institutions named in the draft are EXIM Bank, NABARD, NaBFID, NHB and SIDBI. NBFCs are covered in Base, Middle, Upper and Top layers. That is the part that will hurt shops that never staffed a model-validation team. A base-layer NBFC with a vendor scorecard, a co-operative bank with a pricing spreadsheet, and a credit information company with a scoring engine are all asked to keep a living inventory and a board-approved Model Risk Management Framework.
The definition of a model is the trap. It is any system, inside or bought, that takes data, applies statistical, mathematical, economic, financial or AI and ML techniques, and produces an output used for business or decision-making. Algorithms, analytics, interfaces, applications, decision-based rules and other computational tools count if they have a material impact, even if the lender never labelled them as models. The draft’s own illustration is a spreadsheet-based loan pricing calculator that sets lending rates, margins or credit terms.
Unlisted active models are not a grey area. If it is in use and it moves a decision, it belongs on the inventory. High-risk models need the Risk Management Committee of the Board to review validation reports before deployment. Model-risk tiering reports come back to that committee at least once a year. Third-party models and AI models sit under that committee’s watch even when they are not in the top risk tier.
What Vendors Want Changed in the Final Text
Nasscom filed from the other side of the contract. Ayush Raj, an associate in public policy, wrote that the IT industry may be functioning as third parties under this guidance, and that the final text should make the paperwork livable. The file on the post is dated July 23, 2026, the day before comments closed.
Nasscom’s comments on audit rights ask the Reserve Bank to define what “comprehensive documentation” means, to give a picture of minimum and enhanced technical files for AI models, and to recognise independent certifications so that every audit is not a full dump of a vendor’s internals. They also want more mitigants than “limit the usage” when a provider will not open a model, and they want complexity tools such as regularisation treated as examples, not as a default method.
WHAT NASCOM ASKED THE RESERVE BANK TO CLARIFY
- Inventory contents: What belongs in the model register, including retired models, so firms keep the same records.
- Technical files: Illustrative minimum and enhanced documentation for third-party and AI models, kept in proportion to risk.
- Audit rights: A defined scope for contract audits, with room for independent certifications instead of an open vault.
- Closed models: A wider set of mitigants than cutting use when the provider will not disclose enough.
- Complexity tools: A range of methods for hard models, so one technique is not read as the required one.
Those asks map onto paragraphs 47 and 48. Before buying or using a third-party model, the lender should diligence the provider’s credibility, the model’s method and limits, and the quality of the data. Contracts should give access to minimum technical documentation that yields a reasonable understanding of design, configuration, assumptions and, in the surrounding clauses, audit rights, continuity and exit. Nasscom is not arguing against accountability. It is arguing that a bank cannot validate a black box, and a vendor will not sign a contract that treats every model as an open-source dump.
That deadlock is a fair reading of why the June model-risk draft has not yet come back as a circular. The Reserve Bank has issued other drafts since June, including data-governance guidance on July 15. Model risk is the one that still sits.
A Human on Every Decision, a File for Ten Years
Customer-facing systems get their own list. If a model, including a generative one, talks to customers or outside users, the lender should add cyber controls against prompt injection, adversarial inputs, persistent sessions and odd usage. It should tell the person they are dealing with an AI or ML system, explain the limits, and offer a switch to a human whenever they ask. Red-teaming, or an equivalent challenge process, is called out for customer and generative use.
Explainability is a threshold, not a slogan. Models used for material decisions, or with a large effect on customers or operations, need a higher bar. Where full explainability is not possible, the draft wants extra validation, more frequent monitoring, usage limits and other compensating controls. Hallucinations, bias, overfitting, spurious correlations, wild output swings, and data or concept drift each get their own control language. Independent validation applies before and after deployment, after changes, on triggers, and on a cycle set in the framework, and it applies to third-party models the same way.
Paragraph 23 is the long tail. Decommissioned models stay on the inventory for at least ten years from the date they are retired or the date they stop serving as a backup or benchmark, whichever is later, or longer if law requires it. A chatbot the bank kills in 2027 is still a file in 2037. That is a records problem as much as a safety problem, and it is one more reason a vendor model without an exportable archive is hard to buy.
WHAT WE KNOW
- The text: The June 24 draft would put a kill switch, human command and full third-party liability on every model that moves a decision.
- The clock: Comments closed on July 24, 2026, through Connect 2 Regulate or to the Operational Risk Group in Mumbai.
- The status: On September 12, 2026, the item was still listed as a draft notification.
WHAT IS UNCONFIRMED
- Timing: No public date for a final circular.
- The button: Whether paragraph 60’s kill-switch language survives industry comments in that form.
- The contracts: Whether audit rights, documentation minima and closed-model mitigants are rewritten for vendors.
Until that circular lands, the draft already names the move for a model the bank cannot open: limit the usage. A kill switch is only as real as the system it is wired to.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
