India is one of the fastest growing markets for AI deployment in financial services, insurance, agriculture and public administration. It has no AI-specific statute. What it has instead is supervisory movement inside regulated sectors: a committee report and a draft guidance document at the central bank, reporting circulars from 2019 at the securities regulator, and a working group at the insurance regulator, all of which can be read at source. This guide sets out what is verifiable, what is not, and what a global operator should reasonably do about the difference.
Key takeaways
- No AI-specific Indian statute was found in this review. There is no Indian conformity assessment, no registration duty, no risk tier list and no AI-specific penalty regime.
- The Reserve Bank of India published the FREE-AI committee report on 13 August 2025, recording 26 actionable recommendations under six strategic pillars. A committee report binds nobody.
- On 24 June 2026 the Reserve Bank released the draft Guidance on Regulatory Principles for Model Risk Management, 2026 for comment by 24 July 2026, covering eleven categories of regulated entity. It was still a draft at the date of this review.
- SEBI's AI instruments are three reporting circulars from 2019 and one cybersecurity advisory of 5 May 2026. IRDAI has no AI circular and constituted a working group on AI governance on 17 June 2026.
- An operator built to the EU AI Act standard exceeds what Indian law currently demands. The residual Indian exposure is supervisory rather than statutory, and it sits in banking, securities and insurance.
What is actually in force
India has no AI-specific statute. Nothing in this review located an enacted Indian law that regulates artificial intelligence as such, and the posture of the three financial regulators points the same way. As at August 2026 the Reserve Bank of India has a committee report and a draft guidance document open to comment. The Securities and Exchange Board of India has reporting circulars dating from 2019 and one cybersecurity advisory. The Insurance Regulatory and Development Authority of India has constituted a working group. Regulators constitute working groups and consult on drafts when a framework does not yet exist.
That shapes how an operator should plan. There is no Indian conformity assessment procedure for AI systems, no centralised registration duty, no statutory risk tier list and no AI-specific penalty regime to comply with. What exists is supervisory expectation inside regulated sectors, and it is being written now rather than in some indefinite future. The three sections that follow set out what each regulator has actually published, with the status of each document stated plainly, because status is the part most often reported wrongly.
Reserve Bank of India: a committee report and a draft
On 13 August 2025 the Reserve Bank published the report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector. The accompanying press release records 26 actionable recommendations organised under six strategic pillars. A committee report is not a circular and imposes nothing on a regulated entity, but it is the clearest available statement of where the supervisor intends to go.
On 24 June 2026 the Reserve Bank released the draft Guidance on Regulatory Principles for Model Risk Management, 2026 for public comment, with comments invited until 24 July 2026. The draft covers eleven categories of regulated entity: commercial banks, small finance banks, payments banks, local area banks, regional rural banks, urban co-operative banks, rural co-operative banks, all India financial institutions, non-banking financial companies, asset reconstruction companies and credit information companies.
The substance of the draft is where an operator should look, because it indicates what the supervisor will expect once a final text issues. It requires a regulated entity to "define the explainability and transparency thresholds for all AI models" and to apply higher thresholds to models relied on for material decision-making. Models, including third party models, are to be subject to independent validation by the regulated entity, before and after deployment and periodically thereafter, with records and logs of changes, versioning and approvals sufficient to give traceability, reproducibility and auditability. On fairness, the draft states that the entity "should identify the risk of bias, and discriminatory outputs, specifically in use cases such as unfair treatment of certain customer groups" and should "conduct fairness assessment and implement appropriate mitigants, including recalibration or redesign". It states plainly that "An RE should not use any model that harms consumer."
Speaking at the FIBAC 2026 conference on 11 August 2026, Governor Sanjay Malhotra described the Reserve Bank's approach as one "articulated through the FREE-AI Committee's recommendations and draft guidelines on Model Risk Management". The word draft is the operative one. At the date of this review the model risk package was not in force, and an operator that reads the draft as a live obligation is reading it wrongly, just as an operator that ignores it until notification is planning badly.
Securities and Exchange Board of India: reporting, not governance
SEBI's register of circulars contains three instruments on artificial intelligence, all issued in 2019 and all of them reporting requirements. Circular SEBI/HO/MIRSD/DOS2/CIR/P/2019/10 of 4 January 2019 applies to market intermediaries. A circular of 31 January 2019 applies to market infrastructure institutions. A circular of 9 May 2019 applies to mutual funds. Their subject in each case is the reporting to SEBI of AI and machine learning applications and systems offered or used by the regulated entity.
The only recent AI item in the register is an advisory of 5 May 2026 on emerging advanced artificial intelligence tools for vulnerability detection. Its concern is cybersecurity exposure rather than the governance of AI used in advice, research or trading. A search of SEBI's regulations register returned no regulation whose title concerns artificial intelligence.
The practical reading for a SEBI-regulated entity is therefore narrower than is often assumed. The Indian securities market position on AI is a disclosure and reporting duty of some vintage, not a governance code with explainability, human oversight or labelling obligations attached.
Insurance Regulatory and Development Authority of India: a working group
IRDAI's document register lists one item on artificial intelligence in the current period, a Working Group on Artificial Intelligence (AI) Governance in the Insurance Sector, dated 17 June 2026. The constituting document is published as a PDF that could not be parsed for this review, so its terms of reference, membership and reporting deadline are not reproduced here.
No circular in the Authority's circulars register concerns artificial intelligence, machine learning, underwriting algorithms or claims automation. Insurers operating in India remain subject to the Authority's general conduct, product filing and outsourcing requirements as those apply to any system used in the business, and to whatever the working group ultimately proposes. An insurer planning an AI underwriting or claims deployment in India should treat the working group as the signal to prepare documentation now, and should not assume that a specific validation or human review duty already exists.
What this review could not verify
The Ministry of Electronics and Information Technology administers India's information technology law and its data protection statute, and it is the body that would publish any national AI framework. Its site returned 403 to every automated request made for this review, as did indiacode.nic.in, legislative.gov.in, pib.gov.in and india.gov.in. The Gazette of India at egazette.gov.in presented a certificate chain that could not be verified. The IndiaAI portal at indiaai.gov.in responded but its pages could not be retrieved in readable form.
The consequence is stated openly rather than papered over with confident summary. This guide does not reproduce section numbers, penalty amounts, designation criteria or commencement dates for the Digital Personal Data Protection Act 2023 or its rules, and it does not state the outlay, pillar count or safety institute mandate of the IndiaAI Mission, because none of that could be read at the administering body's own domain on 17 August 2026. An operator whose systems process personal data of people in India should obtain the current texts from the ministry directly and take Indian counsel on them, rather than relying on any secondary summary, this one included.
How India compares with the EU AI Act
The EU AI Act is Regulation (EU) 2024/1689, published in the Official Journal of the European Union on 12 July 2024. It did not enter into application in August 2024. Its obligations phase in, and the phasing was changed by the Digital Omnibus, which entered into force on 27 July 2026 as Regulation (EU) 2026/1744. The high-risk obligations attaching to the Annex III use cases now apply from 2 December 2027, and those attaching to Annex I product categories from 2 August 2028. The prohibitions in Article 5, the transparency duties in Article 50, the obligations on general purpose AI models and the AI literacy duty in Article 4 were not deferred and have applied since 2 August 2026. For a detailed analysis of what the EU AI Act requires of operators, see the EU AI Act operator obligations guide on agentliability.eu.
The penalty regime is set by Article 99. Breach of the prohibited practices in Article 5 carries up to EUR 35 million or 7 per cent of worldwide annual turnover, whichever is higher. Breach of other operator obligations carries up to EUR 15 million or 3 per cent. Supplying incorrect, incomplete or misleading information carries up to EUR 7.5 million or 1 per cent. The lower figure applies to SMEs and start-ups. These penalties are enforced by national market surveillance authorities, not by the AI Office, which holds the separate general purpose AI regime under Article 101 with a ceiling of EUR 15 million or 3 per cent.
Set against that, India has no equivalent instrument. There is no Indian Annex III, no conformity assessment, no registration and no AI-specific penalty. The comparison is therefore not between two regimes of differing strictness. It is between a regime and a set of supervisory expectations that are still being drafted. For a comparison of the US, EU and UK approaches, see the US, EU, and UK comparison on this site. The Asia-Pacific AI governance landscape places India in its regional context.
One international reference point is worth naming because it is genuinely voluntary and widely used as documentation scaffolding. The NIST AI Risk Management Framework 1.0 was released on 26 January 2023 and is, in NIST's own words, "intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems". It creates no obligation anywhere, in India or elsewhere, but it gives an operator a defensible structure for the evidence a supervisor will eventually ask for.
What operators should do now
The absence of an AI statute does not make India a low-governance market. It makes the exposure supervisory rather than statutory, which is harder to plan against, not easier. Four priorities follow from what can be verified.
First, work out which regulator supervises you in India, if any. Banking and credit activity sits with the Reserve Bank, capital markets activity with SEBI, insurance with IRDAI. If none of the three supervises you, no Indian AI-specific obligation was identified in this review that applies to your deployment, and your Indian exposure runs through data protection law and general law instead.
Second, if the Reserve Bank supervises you, read the draft Guidance on Regulatory Principles for Model Risk Management, 2026 and build to it now. Model inventory, explainability and transparency thresholds set by materiality, independent validation before and after deployment, change and version logs that give traceability and reproducibility, and a documented fairness assessment for models that could treat customer groups unequally. Comment closed on 24 July 2026, so the shape of the final text is largely set.
Third, if you are SEBI-regulated, confirm that your reporting under the 2019 AI and machine learning circulars is actually being filed for the systems you use today. That is a real and current duty, and it is more likely to be quietly out of date than any governance duty, because the systems in scope have changed considerably since 2019.
Fourth, if you are an insurer, treat the working group constituted on 17 June 2026 as the notice period it is. An insurer that can already show model documentation, validation evidence and a human oversight arrangement for AI used in underwriting or claims will be in a different position from one starting when a circular lands. Nothing requires that today, which is precisely why the work is cheap to do now.
Across all four, the EU AI Act remains the practical ceiling. An operator built to it will exceed what Indian law demands and will have most of the evidence an Indian supervisor is likely to ask for. What EU compliance does not do is discharge Indian data protection obligations, which are administered by a different ministry, sit outside the scope of this review, and should be taken to Indian counsel on the current text.
Frequently asked questions
Does India have a comprehensive AI law in 2026?
No AI-specific Indian statute was found in this review, and the position of the financial regulators points the same way. As at August 2026 the Reserve Bank of India has a committee report and a draft guidance document, SEBI has reporting circulars dating from 2019 and one cybersecurity advisory, and IRDAI has constituted a working group. Regulators constitute working groups and consult on drafts when a framework does not yet exist. There is no Indian conformity assessment, no registration duty, no risk tier list and no AI-specific penalty regime.
What does the Reserve Bank of India require of AI models?
Nothing yet, in binding form. On 13 August 2025 the Reserve Bank published the report of the FREE-AI committee, recording 26 actionable recommendations under six strategic pillars. On 24 June 2026 it released the draft Guidance on Regulatory Principles for Model Risk Management, 2026 for comment by 24 July 2026, covering eleven categories of regulated entity. The draft requires explainability and transparency thresholds for all AI models, independent validation of models including third party models before and after deployment, identification of bias and discriminatory output risk with a fairness assessment, and it states that a regulated entity should not use any model that harms consumers.
What has SEBI issued on artificial intelligence?
Three reporting circulars, all from 2019: circular SEBI/HO/MIRSD/DOS2/CIR/P/2019/10 of 4 January 2019 for market intermediaries, a circular of 31 January 2019 for market infrastructure institutions, and a circular of 9 May 2019 for mutual funds. Their subject is the reporting to SEBI of AI and machine learning systems offered or used by the regulated entity. The only recent AI item is an advisory of 5 May 2026 on AI tools for vulnerability detection, which concerns cybersecurity. No SEBI regulation with AI in its title was found.
Does IRDAI regulate AI in insurance underwriting or claims?
Not by circular. IRDAI's document register lists a Working Group on Artificial Intelligence (AI) Governance in the Insurance Sector dated 17 June 2026. No circular in the Authority's circulars register concerns artificial intelligence, machine learning, underwriting algorithms or claims automation. Insurers remain subject to the Authority's general conduct, product filing and outsourcing requirements as those apply to any system, and to whatever the working group proposes.
How does India's position compare with the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024, and its phasing was changed by the Digital Omnibus, which entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Annex III high-risk obligations now apply from 2 December 2027 and Annex I from 2 August 2028, while Article 5, Article 50, the general purpose AI obligations and the Article 4 AI literacy duty have applied since 2 August 2026. India has no equivalent instrument, so an operator built to the EU standard exceeds what Indian law demands. The residual Indian exposure is supervisory and sits in banking, securities and insurance.
References
- Reserve Bank of India, press release, Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector, 13 August 2025. rbi.org.in
- Reserve Bank of India, press release, RBI issues draft Guidance on Regulatory Principles for Model Risk Management, 24 June 2026. rbi.org.in
- Reserve Bank of India, draft Guidance on Regulatory Principles for Model Risk Management, 2026. rbi.org.in
- Reserve Bank of India, Winning in the AI Era: The New Playbook for Indian Banks, inaugural address by Governor Sanjay Malhotra at FIBAC 2026, 11 August 2026. rbi.org.in
- Securities and Exchange Board of India, circular SEBI/HO/MIRSD/DOS2/CIR/P/2019/10, Reporting for Artificial Intelligence (AI) and Machine Learning (ML) applications and systems offered and used by market intermediaries, 4 January 2019. sebi.gov.in
- Securities and Exchange Board of India, circulars register, AI and ML reporting circulars of 31 January 2019 and 9 May 2019, and Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection, 5 May 2026. sebi.gov.in
- Insurance Regulatory and Development Authority of India, Working Group on Artificial Intelligence (AI) Governance in the Insurance Sector, 17 June 2026. irdai.gov.in
- National Institute of Standards and Technology, AI Risk Management Framework 1.0, released 26 January 2023, intended for voluntary use. nist.gov
- Regulation (EU) 2024/1689 (EU AI Act), Official Journal of the European Union, 12 July 2024, as amended by Regulation (EU) 2026/1744 (Digital Omnibus), in force 27 July 2026.
- Not read at source for this review: meity.gov.in, indiacode.nic.in, legislative.gov.in, pib.gov.in and india.gov.in returned 403 to automated requests; egazette.gov.in presented an unverifiable certificate chain; indiaai.gov.in could not be retrieved in readable form. No claim in this guide rests on them.