BREAKING
Technology

RBI seeks to mandate an emergency “kill switch” for AI in all banks and human oversight for all decisions

As AI tools gain popularity, concerns have arisen regarding their usage and the potential risks involved. This is particularly relevant for AI models employed by banks and other financial institutions that handle sensitive financial data and information. The Reserve Bank of India now plans to issue new guidelines requiring all banks to implement an emergency kill switch capable of shutting down any AI model used in their systems.

On Wednesday, the RBI released draft guidelines proposing a comprehensive framework for banks and other regulated entities using AI. If approved, this measure would require such entities to have the capability to instantly override, suspend, or deactivate any such system—including through an emergency kill switch. In other words, a bank must be able to shut down all the AI systems it uses, essentially at the flip of a switch.

The RBI noted that banks must establish override, suspension, and deactivation mechanisms to ensure that no AI model operates without the possibility of immediate shutdown should it produce harmful or erroneous results.

This move comes at a time when Anthropic’s “Claude Mythos” AI model has raised cybersecurity concerns, particularly for financial institutions.

Human oversight and AI risk classification

But that is not all. The draft guidelines also stipulate that all AI-driven decision-making must remain subject to human oversight. In other words, even when AI is tasked with performing functions, a person must oversee any decision made.

The proposed framework would apply to all models used by regulated entities, ranging from simple spreadsheet-based calculators to complex, cutting-edge AI systems.

Furthermore, the bank will be fully accountable for the outcomes of any model it uses, regardless of whether the model was developed in-house or acquired from a third party. The RBI has directed banks to conduct due diligence prior to using such models. The Reserve Bank of India has proposed a risk-based tiered classification structure, under which entities must categorize models according to their risk level and implement proportionate oversight, validation, and control measures.

The guidelines stipulate that if the assessed risk exceeds the bank’s risk appetite, the organization must take immediate action—such as implementing enhanced controls, usage restrictions, or corrective measures, or withdrawing the model—and report the matter to the board’s risk management committee.

A model’s risk level must be reviewed at least annually; additionally, high-risk models require approval from the board’s Risk Management Committee prior to implementation, rather than being authorised solely by the technology or risk teams.

Model Risk Management Framework for All AI Models

For the first time, the RBI (Reserve Bank of India) has placed AI and model governance directly under the responsibility of the board of directors. Every regulated entity must have a board-approved model risk management framework covering all models, whether developed in-house, acquired from vendors, or created through a combination of both methods.

The RBI stated: “Given the significant expansion in model usage and their increasing deployment by regulated entities—including those based on artificial intelligence and machine learning—across various business and decision-making processes, deficiencies in their governance, oversight, risk management, and controls could expose these entities to financial, operational, compliance, and reputational risks.”

It further added: “If not managed effectively, these risks can lead to inaccurate outcomes, erroneous decisions, financial losses, operational disruptions, regulatory non-compliance, and other adverse consequences for the entities, consumers, and the financial system.”

The central bank also highlighted supply chain risks stemming from over-reliance on a limited number of AI model vendors, noting that banks must actively manage this risk. Additionally, it indicated that banks must ensure the deployment of AI models does not introduce vulnerabilities into the models themselves.

Regarding customer-facing systems, the RBI mandated that banks inform customers when they are interacting with an AI system and offer them the option to switch to human interaction at any time.

The draft also warned against automation bias—the risk of employees placing excessive trust in AI-generated outputs without applying their own judgment. For generative AI models interacting with customers or external users, the RBI indicated that additional cybersecurity controls must be implemented.

The RBI has invited comments on the draft guidelines by July 24.