AI in Finance

India's Central Bank Just Redrew the Rules of the AI Banking Race

RBI Governor Sanjay Malhotra told bankers in Mumbai that the winners of the AI era will be those who understand what they deploy, not those who move fastest. Here is why his warning about model concentration matters for global markets.

On a stage in Mumbai this week, the head of one of the world's most closely watched central banks delivered a message that cut against the prevailing mood in banking. Speed, he argued, is not the prize. Understanding is.

Speaking at the FIBAC 2026 conference on 11 August, Reserve Bank of India Governor Sanjay Malhotra told an audience of senior bankers that the institutions destined to lead the artificial-intelligence era would not be the fastest or most enthusiastic adopters, but those that "adopt it with full understanding of what they are deploying" (Business Standard). It was an unusual note to strike at a moment when banks are racing to embed AI into everything from credit decisions to fraud monitoring, and it deserves the attention of anyone with capital exposed to the financial system.

What Malhotra Actually Said#

The Governor's remarks carried two messages that sit in deliberate tension. The first was a push. Indian lenders, he said, cannot afford to sit on the sidelines and must accelerate their spending on AI technology, infrastructure and staff training (Business Standard). The RBI, he added, "sees AI as a capability to be responsibly harnessed and not merely as a risk to be contained" (ANI).

The second was a warning. Wider use of AI, Malhotra cautioned, brings risks that include biased or opaque decisions, threats to data privacy, and cyber-security exposure. Most pointedly, he flagged that "dependence on a small number of models or technology vendors could potentially leave the banking system exposed to errors," urging banks to be on guard when relying on outside suppliers (Business Standard). Deployed carelessly, he said, AI "can also entrench new forms of exclusion and instability at a pace regulators and banks may struggle to keep up with" (ANI).

The framing matters because it comes from a regulator with authority over a banking system serving more than a billion people, and because it lands the same week that the Financial Stability Board, the body that coordinates financial regulation for the G20, has been pressing the same concern about concentration onto the global agenda.

The Concepts Behind the Headline#

To see why this is more than a routine speech, a few ideas need unpacking.

Start with the India-specific backdrop. Malhotra grounded his optimism in what officials call the "India Stack", a layered set of public digital utilities including Aadhaar (a biometric identity system), the Unified Payments Interface or UPI (real-time retail payments), DigiLocker, the Open Network for Digital Commerce, the Account Aggregator consent framework and the Unified Lending Interface. AI built on this foundation, he argued, could "do for financial judgment what UPI did for financial transactions: make it instant, granular, and available to the last mile" (ANI).

The mechanism he has in mind is alternative-data underwriting. Traditional lending leans on credit histories that many borrowers (gig workers, small firms without formal accounts, first-time borrowers) simply do not have. Machine-learning models can instead read cash-flow patterns, goods-and-services-tax filings, utility payments and digital footprints to judge creditworthiness, potentially widening the pool of people a bank will lend to (ANI). The same predictive tooling can flag borrowers drifting towards default early enough for a bank to offer counselling rather than pursue recovery.

Now the risk concept. When Malhotra warns about "dependence on a small number of models or technology vendors," he is pointing at what economists call concentration or third-party risk, and its close cousin, model monoculture. If most banks buy inference from the same handful of cloud providers, run the same foundation models and train on overlapping data, their systems can fail in the same way at the same time. Individually rational choices, each bank picking the best available model, can produce a collectively fragile system. That is the thread connecting a speech in Mumbai to a debate playing out in Basel.

Why Markets Should Care#

The immediate market read is straightforward: India's regulator wants faster adoption, which is supportive for the technology vendors, cloud operators and domestic fintechs positioned to supply it. Malhotra reassured the audience that Indian banks are "well positioned," citing robust credit growth, low bad loans and healthy liquidity (Business Standard).

The deeper implications run across asset classes. In equities, the divide is sharpening between institutions that can demonstrate measurable returns on AI investment and those still trading on narrative, a distinction global markets are already pricing after this earnings season (Boston Institute of Analytics). In credit and fixed income, the expansion of algorithmic underwriting reshapes how loss curves are modelled; a lending book approved by an opaque model is harder to stress-test than one built on documented income. For banking-sector risk premia, a supervisor publicly naming vendor concentration signals that operational-resilience requirements, and their compliance costs, are heading only one way.

The scale of the spending underlines the stakes. JPMorgan's 2026 technology budget runs to roughly $20bn and Goldman Sachs has earmarked around $6bn, with large shares directed at AI (Bloomberg via Business Standard reporting). NVIDIA's 2026 industry survey found 61% of financial firms using or assessing generative AI and 42% doing the same with agentic AI, the more autonomous systems that can take actions rather than merely draft text (reported figures). This is not a pilot phase; it is a build-out, and regulators are recalibrating in real time.

A Technical Look at Model Monoculture#

For quantitative readers, the concentration concern is worth stating precisely. The classic argument for diversification assumes that institutions' decisions are imperfectly correlated: when one lender tightens, another may not. Shared AI infrastructure erodes that assumption. If a large fraction of the market prices risk using similar models trained on similar data, their outputs become correlated by construction, and correlation is the enemy of systemic resilience.

The Financial Stability Board has formalised this. In its 2024 assessment it warned that reliance on a few cloud, hardware and foundation-model providers could push institutions towards correlated behaviour and amplify herding and procyclicality in a downturn (FSB, November 2024). Widespread use of common models and data, it noted, could increase correlations in trading, lending and pricing, magnifying market stress and liquidity crunches (FSB monitoring report, October 2025). On 10 June 2026 the FSB followed up with a set of sound practices for responsible AI adoption, aimed squarely at governance and operational oversight (FSB, June 2026).

Two mechanisms drive the danger. The first is procyclicality: models trained on recent benign conditions may simultaneously downgrade the same borrowers when conditions turn, deepening a credit crunch precisely when forbearance is needed. The second is model opacity: the difficulty of explaining why a complex model reached a decision, which frustrates the independent validation that bank supervisors have required since the post-crisis era. This is why India's response is not a rulebook of prohibitions but a principles-based framework, resting on the recommendations of the RBI's FREE-AI Committee and draft guidelines on model risk management (ANI).

Strengths, Limits and the Uncomfortable Questions#

The RBI's stance has clear merits. Treating AI as a capability to be harnessed rather than a hazard to be quarantined keeps India commercially competitive and acknowledges the genuine inclusion gains from alternative-data lending. A proportionate, principles-based approach is also more durable than prescriptive rules that a fast-moving technology would render obsolete within a year.

The limitations are equally real. Principles are only as good as their enforcement, and "understand what you deploy" is far easier to say than to supervise across hundreds of regulated entities of wildly varying sophistication. The RBI's own FREE-AI survey found only 20.8% of surveyed entities currently deploying AI, even as 67% expressed interest. That gap implies a wave of adoption arriving faster than governance capacity can be built (Dvara Research summary). Alternative-data models also carry a fairness paradox: the same signals that extend credit to the underserved can encode proxies for caste, geography or gender, quietly reproducing the exclusion they were meant to cure. That is the "new form of exclusion" Malhotra warned about, and it is difficult to detect without the very transparency that complex models resist.

There is also a competing view worth airing. Some technologists argue that convergence on a few high-quality foundation models raises the average standard of risk assessment and that fragmentation into many weaker in-house models would be worse for both consumers and stability. The concentration critique, on this reading, mistakes standardisation for fragility. The honest answer is that the empirical evidence is thin in both directions; correlated AI-driven stress has not yet been tested by a genuine downturn, which is exactly why supervisors are moving pre-emptively rather than waiting for the natural experiment.

Where This Sits in the Arc of Financial Regulation#

Placed against recent history, Malhotra's intervention looks less like a single event and more like a marker of a structural shift. India's Finance Minister Nirmala Sitharaman warned in April of unprecedented AI-related risks to banks and called for pre-emptive safeguards (Business Standard). Globally, the picture is uneven. In the United States, the Federal Reserve's revised model-risk guidance, SR 26-2, explicitly left generative and agentic AI outside its scope, describing them as too novel and fast-moving to cover, a candid admission of a regulatory gap (reported detail). In the European Union, the AI Act entered its enforcement era on 2 August 2026, though the high-risk obligations covering credit scoring were pushed back to December 2027 under the Digital Omnibus regulation, a concession to industry (enforcement analysis).

The comparison suggests this is neither a purely cyclical story nor an incremental tweak. It is a structural change in how supervisors think about technology risk. For two decades, the governing question was whether a bank's own models were sound. The emerging question is whether the models the entire system shares are sound together. That reframing, from institutional to systemic model risk, is the real shift, and India, by pairing an explicit growth mandate with an explicit concentration warning, has articulated it more crisply than most.

Key Takeaways#

  1. The RBI is pushing Indian banks to accelerate AI adoption while insisting that comprehension, not speed, defines the eventual winners (Business Standard).
  2. The sharpest new concern is concentration risk: dependence on a few models and vendors can turn individually sensible choices into collective fragility (FSB, November 2024).
  3. Alternative-data underwriting offers real financial-inclusion gains but can encode fresh forms of bias if left opaque (ANI).
  4. India's principles-based FREE-AI framework contrasts with a fragmented global picture, where the Fed has left agentic AI unregulated and the EU has delayed its high-risk credit-scoring rules (Dvara Research; Gibson Dunn).
  5. The regulatory question has shifted from "is your model sound?" to "are our shared models sound together?", a move from institutional to systemic model risk.

Frequently Asked Questions#

What is the FREE-AI framework? FREE-AI stands for the Framework for Responsible and Ethical Enablement of Artificial Intelligence. Published by the RBI on 13 August 2025, it is built around seven guiding principles ("sutras"), six pillars and 26 recommendations for how India's financial sector should adopt AI (KPMG).

What is model concentration or monoculture risk? It is the danger that many institutions relying on the same AI models, data and infrastructure will make similar decisions and fail in similar ways simultaneously, amplifying market stress rather than diversifying it away (FSB).

Is agentic AI regulated in banking yet? Largely not. The US Federal Reserve's revised model-risk guidance explicitly excluded generative and agentic AI as too novel to cover, leaving a supervisory gap that other frameworks are only beginning to address (reported detail).

How can AI improve financial inclusion? By using alternative data such as cash flows, tax filings, utility payments and digital footprints, models can assess borrowers who lack conventional credit histories, potentially extending formal credit to gig workers and small businesses (ANI).

Why would faster AI adoption create instability? Because shared models can behave procyclically, downgrading the same borrowers at the same time in a downturn, and because heavy reliance on a few vendors concentrates operational and cyber risk across the system (FSB, November 2024).

Does this apply outside India? Yes. The concentration and herding concerns are global, flagged by the Financial Stability Board for the G20, even as national approaches to enforcement diverge (FSB, June 2026).

Is any of this investment advice? No. This article describes regulatory developments and market interpretation. It contains no recommendation to buy, sell or hold any asset, and forward-looking statements are estimates rather than certainties.

References#

Disclaimer: This article is for information only and does not constitute investment, legal or financial advice. Verified facts are attributed to primary sources; market interpretation and forward-looking statements are the author's analysis and should be treated as estimates, not certainties.