There is a question I now ask early in any conversation with an Indian bank or NBFC that is deploying agents, and it separates the room faster than anything else I have tried. It is not what are you building. It is: what is the current status of the model risk guidance you will be examined against, and what date is on it?

The honest answer, on 19 August 2026, is that there isn't one. There is a draft, issued on 24 June, whose comment window closed on 24 July. There is no final text — I checked the Reserve Bank's own notifications list on 18 August rather than assuming it, because a claim about an absence is worthless unless somebody went and looked. There is a Governor's address from 11 August telling the industry to accelerate. And there is a trade-press report from 18 August that a broader AI framework is under deliberation, at discussion stage, with nobody named.

That configuration is unusual, and it is the reason this piece exists. In North America the equivalent supervisor has deliberately stepped back and left a silence. In the Emirates there is one enumerated control list, scoped narrowly, sitting under an enormous ambition with no framework of its own. India is the third case and the most interesting one for anybody actually building: the text is being written, right now, in public, and the people writing it are reading what the industry does while they write.

Precision about status matters more here than anywhere else in this series, because the temptation is to compress five different kinds of document into one sentence about what RBI wants. They are not one thing. Here they are separately.

August 2025 — a committee recommends. The FREE-AI committee reported, recommending a framework for responsible and ethical AI in the financial sector. A committee report is an input to policy, not policy. Its significance here is chronological: it establishes that the current drafting is roughly a year downstream of a public recommendation rather than a sudden response to something, which tells you something about the pace to expect from what follows.

24 June 2026 — a draft you can actually read. The Reserve Bank issued its draft Guidance on Regulatory Principles for Model Risk Management. This is the one document in the chain with a text an institution can build against. Its addressed population is broad — commercial banks, small finance banks, payments banks, regional rural banks, urban and rural cooperative banks, non-banking financial companies across all layers, all-India financial institutions and asset reconstruction companies — which is worth noticing on its own, because a mid-sized NBFC running a scoring model does not usually expect to be inside the same instrument as a large commercial bank. And its proposals are structural rather than aspirational: a board-approved model risk management framework, risk-based tiering across an enterprise model inventory, model override and kill-switch capability, and accountability for third-party models.

24 July 2026 — the window closes. Comments were invited until 24 July, through the Reserve Bank's public feedback channel. That date matters for a reason people underrate: it is the moment the drafting moves out of public view. Between the close of a consultation and the issue of a final text, the only information anybody outside has about the direction of travel is what supervisors say in speeches — which is why the next item is not a piece of colour.

11 August 2026 — the Governor sets the posture. Governor Sanjay Malhotra gave the inaugural address at FIBAC 2026 in Mumbai, titled "Winning in the AI Era: The New Playbook for Indian Banks". The instruction was to accelerate: technology, infrastructure, upskilling. The warnings were specific: biased and opaque decisions; data-privacy and cyber threats; and concentration risk arising from dependence on a small number of models or vendors, which he framed as capable of leaving the banking system exposed to errors. I have verified the address on the Reserve Bank's own speeches listing. It is not an instrument. It is the clearest available statement of the posture the instrument is being drafted under, delivered a fortnight after the consultation closed.

18 August 2026 — a report of a deliberation. Trade press reported that the Reserve Bank is considering a dedicated AI framework spanning lending, customer service, fraud and compliance, explicitly at discussion stage. I am going to hold this at arm's length for the whole piece, and say why once: there are no named officials, nothing has been issued, and a report that a regulator is thinking about something is the weakest category of evidence in this entire series. It belongs in the chain because a reader deciding where to spend the next two quarters should know it exists. It does not belong in a board paper as a forecast.

FIGURE 1 · THE CHAIN, IN ORDER Nothing in the chain is final. That is the condition, not a complaint. Aug 2025 RECOMMENDATION The FREE-AI committee reports a framework recommended for responsible and ethical AI in the financial sector 24 Jun 2026 DRAFT · THE ONE TEXT YOU CAN ACTUALLY READ Draft Guidance on Regulatory Principles for Model Risk Management banks · small finance, payments and regional rural banks · cooperative banks · NBFCs, all layers all-India financial institutions · asset reconstruction companies board-approved MRM framework · risk-based tiering over an enterprise inventory model override / kill-switch · third-party accountability 24 Jul 2026 CONSULTATION CLOSED Comment window closes — and the drafting moves out of public view 11 Aug 2026 SUPERVISORY STATEMENT · GOVERNOR, FIBAC 2026 “Winning in the AI Era: The New Playbook for Indian Banks” accelerate adoption — and own three named risks: biased and opaque decisions · cyber threats · concentration on a few models or vendors verified on the central bank’s own speeches listing 18 Aug 2026 PRESS-SOURCED · DISCUSSION STAGE Trade press reports a comprehensive AI framework under deliberation for banks and NBFCs · no named officials · nothing issued · treated as a report, not an instrument 18 Aug 2026 VERIFIED NEGATIVE No final model risk guidance in RBI’s notifications — checked, not assumed A recommendation, a draft, a closed consultation, a speech and a report of a deliberation. No final text — which is exactly when what you build starts to matter.

Read the six labels together and the shape is clear. One readable draft. One closed consultation. One speech. One press report. One verified absence. The only text in the set that an institution can hold and build to is the draft — and a draft is exactly the artefact most compliance functions are trained to wait out.

The warning that is actually an architecture claim

Of the three risks the Governor named, two are familiar enough that most boards already have a paragraph about them. Bias and opacity have been on Indian bank agendas since well before this cycle. Cyber threat has its own supervisory machinery. The third is the one almost nobody in my conversations is treating as a design problem, and it is the one I would put first.

Concentration risk, said about models and vendors, is not a procurement complaint. It is a claim about correlation. If the same model family, or the same vendor platform, stands behind credit decisioning and collections and onboarding and fraud monitoring and grievance handling and the sampling your own control testing relies on, then those are not six systems. They are one dependency wearing six hats, and a single behavioural change in it — a version upgrade, a licensing change, a provider outage, a quiet retraining — moves all six at once.

The part that makes it genuinely dangerous rather than merely inconvenient is the last item in that list. When the control function's own tooling shares the dependency with the thing it is controlling, the correlated failure is also invisible to the mechanism that would detect it. That is not a hypothetical property of any particular Indian institution — I have no data on how concentrated anybody's estate actually is, and I am not going to invent any. It is a structural property of the architecture the market is currently selling, in every jurisdiction, and the Governor named it from a public stage a fortnight after his own consultation closed.

FIGURE 2 · WHAT CONCENTRATION MEANS Concentration risk is not a procurement complaint. It is a correlation. ONE DEPENDENCY a single model family, or a single vendor platform Credit decisioning Collections and recovery Onboarding and KYC Fraud and transaction monitoring Customer service and grievance handling Internal control testing One behavioural change, outage, licence change or version upgrade moves all six at once — and none of the six detects it independently. THE FOUR ARTEFACTS THAT ANSWER IT An inventory that names the dependency, not just the model model, version, vendor, and every workflow standing on it — including inside bought products A substitution test, per workflow what actually happens when that dependency is withdrawn — run, not asserted A fallback path with an owner a named person, an activation threshold, and a degraded mode somebody has agreed to operate Evidence of an exercised exit dated, with a result — an exit clause in a contract is a sentence, not a control Each one produces an artefact a supervisor can be walked through. None of them waits on a final instrument, and none of them is a purchase. The Governor named the risk. None of the four answers to it waits on a final instrument.

The useful thing about a structural risk is that the answer to it is also structural, which means it can be built before anybody requires it. Four artefacts cover the ground, and none of them is a purchase.

  1. An inventory that records the dependency, not just the model. Most model inventories list models. This one has to list the model, the version, the vendor behind it, and every workflow standing on it — including the models inside products you bought, which is the part that takes the time, because the vendor's answer to what is under the hood is frequently the first honest conversation of the engagement.
  2. A substitution test, per workflow. Not an assertion that an alternative exists. A run: withdraw the dependency, see what the workflow does, write down the result. The gap between organisations that have done this and organisations that believe they could is, in my experience, the whole finding.
  3. A fallback path with a named owner and an activation threshold. Somebody has to be accountable for deciding when the degraded mode starts, and somebody has to have agreed to operate it. A fallback nobody owns is a diagram.
  4. Evidence of an exercised exit, with a date on it. An exit clause in a contract is a sentence. An exit that has been exercised, even at small scale, even in a test environment, is a control — and it is the only one of the four that a supervisor cannot be talked out of.

What an unfinalised draft is worth

The instinct in most compliance functions when a draft is out is to wait. The reasoning is sound on its own terms: drafts change, effort spent building to a superseded version is wasted, and there is always a queue of obligations that are already final. I have watched that reasoning applied to this draft in several conversations, and I think it is wrong here for two specific reasons rather than as a matter of general enthusiasm.

The first is that the four proposals in the draft are the ones that do not usually change. Consultations move thresholds, timelines, scope boundaries, definitions and reporting formats. They rarely delete the requirement to have a board-approved framework, or the requirement to know what models you are running, or the requirement to be able to stop one. Those four items appear, in some form, in the current Emirati guidance note, in the withdrawn American inventory schema, and in the Indian draft — three supervisors who did not coordinate arriving at the same short list. If you build the four, the risk that the final text renders your work useless is materially lower than the risk that you are still starting when it lands.

The second reason is the one that matters commercially, and it is the same argument I have made about North America from the other direction. A final instrument, when it comes, is drafted after a consultation, and consultations are answered by firms describing what they already do. The institutions that had a working model inventory and a demonstrated override when the comment window was open are the institutions whose practice is in the pile the drafters are reading. That is not a compliance position. It is an influence position, and it is available for a bounded period, entirely on the merits of having built something.

There is a third, smaller point that only applies in India, and I want to state it carefully because it cuts against a habit. The addressed population of the draft is unusually wide. An NBFC in a lower layer, or a cooperative bank, reading that list and concluding that a document aimed at commercial banks does not concern it, is reading the list wrong. The tiering the draft proposes is risk-based, which is a mechanism for scaling obligations down, not a mechanism for exclusion — and an institution that has never assembled a model inventory will find that tiering requires one before it can do anything else.

The capability centre problem, which is a two-regulator problem

A large share of the agentic work actually being written in India is not being written for an Indian regulated entity. It is being written in a global capability centre in Bengaluru, Hyderabad, Pune or Chennai, for a parent bank or insurer supervised in New York, London or Frankfurt. The people building it sit under one supervisory regime; the system they are building will be examined under another.

The standard failure I see is that the centre governs to whichever regime is louder in the room, which is usually the parent's, and then discovers that the Indian obligations attached to where the work physically happens — the data protection duties, the operational resilience expectations, the third-party arrangements — were nobody's job. The mirror failure also exists: a centre that has internalised RBI's expectations and is surprised when the parent's model risk function arrives with a completely different vocabulary and a different definition of validation.

The practical resolution is unglamorous and it is the same one I would give anywhere: build the union, not the intersection. The four artefacts above are legible to both supervisors, because both supervisors are asking versions of the same five questions — what is running, who authorised it, can you stop it, can a stranger reconstruct it, and how do you govern the parts the vendor will not show you. A capability centre that can answer those five in a form the parent's model risk function and an Indian examiner would both accept has solved the problem once. One that has two governance stories has solved it zero times, and will discover which one when the first incident crosses the boundary.

The data protection clock, held at exactly its real weight

One watch item belongs in this piece, and it belongs framed precisely rather than dramatically, because the drama is where advisers in this market lose their credibility.

In January 2026 the ministry proposed compressing the compliance timelines for significant data fiduciaries under the data protection Rules — pulling obligations forward from the existing 2027 deadline. As of 19 August 2026 I have found no notification giving that proposal effect. It remains a proposal. Anybody telling an Indian board that the deadline has moved is telling them something I cannot verify, and the reputational cost of getting that wrong in a boardroom is higher than any deal it wins.

What is not a proposal is the underlying obligation, which is already in the notified Rules: a significant data fiduciary must, among other duties, verify that the algorithmic, machine-learning and AI systems it deploys do not pose a risk to the rights of Data Principals. Read that as an engineering requirement rather than a compliance sentence and it is a demand for a capability — the ability to take a system, evaluate it against a rights-based standard, and produce evidence of the evaluation — that most estates do not currently have and cannot assemble quickly. The date on which that capability is required is disputed. The requirement itself is not, and it is the capability, not the date, that takes two quarters to build.

FIGURE 3 · THREE TRACKS, THREE STATUSES Three tracks. Three different kinds of not-yet. TRACK 1 · PRUDENTIAL · STATUS: DRAFT, CONSULTATION CLOSED 24 JUL 2026, NO FINAL TEXT Draft Guidance on Regulatory Principles for Model Risk Management Would require: a board-approved MRM framework · risk-based tiering over an enterprise model inventory model override and kill-switch capability · accountability for third-party models What you can do now: read it and build to it. It is a published text. Confidence: high — the draft is published and the absence of a final was verified, not assumed. TRACK 2 · COMPREHENSIVE AI FRAMEWORK · STATUS: DELIBERATION, PRESS-REPORTED 18 AUG 2026 A dedicated AI framework for banks and NBFCs Reported candidate areas — reported, not required: customer data used for training · localisation third-party AI platforms · model override · regulatory reporting What you can do now: read it as direction. Nothing has been issued. Confidence: medium — trade press, no named officials, explicitly at discussion stage. TRACK 3 · DATA PROTECTION · STATUS: PROPOSED JAN 2026, UN-NOTIFIED AS OF 19 AUG 2026 Proposal to compress significant-data-fiduciary timelines Underlying duty, already in the notified Rules: verify that algorithmic, ML and AI systems do not pose risks to Data Principals’ rights · annual assessments and audits What you can do now: treat the date as risk, the duty as settled. Build the verification. Confidence: medium-low on the acceleration · high on the underlying obligations. One readable draft, one reported deliberation, one un-notified proposal — assert them as three different things.

That is the whole picture: three tracks, three different kinds of not-yet. A published draft with a closed consultation. A press-reported deliberation. An un-notified proposal sitting on top of a settled duty. Treating them as one wall of incoming regulation is how a board ends up doing nothing, because nothing on the wall has a date it believes.

The objections, at full strength

Building to an unfinalised draft is building to a moving target. The strongest version of this is not laziness, it is opportunity cost: a compliance function with finite capacity that spends two quarters on a draft that gets substantially rewritten has taken that capacity from obligations that were already binding, and there is no prize for having been early to a version that no longer exists. I take the objection fully, and my answer is narrow rather than sweeping. I would not build to the draft's thresholds, its tiering bands, its reporting formats or its timelines — all of those are exactly what consultations change, and building to them is the wasted work the objection describes. I would build the four structural items, because those are the items that survive redrafting, appear in three unconnected supervisors' texts, and are useful to the institution whether or not anybody ever asks. If the final guidance deletes all four, I was wrong and the two quarters were spent on good engineering anyway.

A speech is not an instrument, and reading supervisory intent into one is a well-known way to be wrong. Also true, and I would go further than most people making this objection do: a Governor's address at an industry conference is written to be quotable, is subject to the ordinary pressures of an audience of bankers, and has no enforcement consequence whatsoever. Nobody has ever been examined against a speech. What the speech is good for is narrower and, I think, real: it is the only public signal available about the posture of a drafting process that has gone behind closed doors, and the concentration item in it is a substantive risk claim rather than an exhortation. Treat the address as evidence of what the drafters are thinking about, which is what it is, rather than as a preview of text, which it is not.

The report of a comprehensive framework may describe nothing at all. This is the objection I agree with most, and it is why the report is quarantined throughout this piece. Trade press with no named officials reporting that a regulator is deliberating is a category of claim that is right often enough to publish and wrong often enough that it must never carry an argument. Regulators deliberate many things that never issue. If the report is empty, this piece loses one of six links in its chain and nothing else — the draft is still published, the consultation still closed, the final text is still absent, and the Governor still gave the address. I have built the argument so that the weakest link can be removed without the structure moving, which is the only responsible way to use a source of that grade.

The influence argument flatters the reader, and flattery is a sales technique. The sharpest objection, and it is aimed at me rather than at India. The claim that early builders become the reference the final text is written against is attractive precisely because it converts compliance spend into strategic positioning, which is what every adviser in this market wants to be able to say. So here is the honest limit. I cannot demonstrate that any particular Indian institution's practice has shaped any particular supervisory text; consultation responses and their influence are not published in a form that would let anybody prove it. What I can say is the mechanism: final guidance follows consultation, consultation responses describe existing practice, and practice that does not exist cannot be described. Whether that mechanism confers as much advantage as the framing implies is a judgement, and the reader should discount it as one.

What would falsify this reading

Four things, named now rather than conceded slowly.

  1. The final guidance arrives promptly and looks nothing like the draft. If the Reserve Bank issues a final text in the next quarter that drops the enterprise inventory, the tiering, the override requirement or third-party accountability, then the four structural items I have argued are stable were not stable, and the specific build advice in this piece was wrong. I would say so in print, because the alternative is quietly reinterpreting the argument until the outcome fits.
  2. The window closes far faster than the chain suggests. This piece treats the interval as long enough to matter. If the final guidance and a comprehensive AI framework both land inside a few months, the interval was short, the first-mover argument shrinks to nearly nothing, and the correct advice was simply to wait and comply well.
  3. The concentration warning turns out to be rhetorical. If the final text contains no requirement touching vendor or model dependency — no inventory field for it, no substitutability expectation, no third-party accountability with teeth — then the Governor's third risk was an observation rather than a signal, and the four artefacts I have built on it are good practice with no supervisory hook.
  4. The capability-centre framing proves to be my own projection. I argue that centres are governed to one regime and examined against two. That is drawn from what I see in engagements, not from any published study, and I have not found one. If somebody surveys Indian capability centres and finds that dual governance is routine and well handled, that section is describing a problem that has already been solved and should be deleted rather than defended.

None of the four is remote, and the first two in particular could resolve within the life of a single build cycle. What survives all four is the instruction underneath, which does not depend on any of them being false: know what is running, know who authorised it, be able to stop one thing without stopping everything, and be able to hand a stranger the reconstruction. Those are the questions three supervisors on three continents are converging on, and none of them requires a final text to start.

The particular gift of the Indian situation is that you can read the draft. In North America there is nothing to read and no consultation open. Here there is a published text, a closed comment window, a stated supervisory posture and an interval — and an institution that uses the interval is not waiting for the rules. It is one of the things the rules will be tested against.

If you are inside an Indian bank, an NBFC or a capability centre and the model inventory does not yet name the vendor behind each model, that is the conversation I have most weeks. Compare notes with me.

Confidence, stated in one place. The draft Guidance on Regulatory Principles for Model Risk Management (24 June 2026) and the closure of its comment window (24 July 2026) are published facts; its addressed population and its four structural proposals are as described in the published draft and the consultation coverage cited below. The absence of a final text was verified against the Reserve Bank's own notifications list on 18 August 2026 rather than inferred, and expires the moment a final text issues. The Governor's FIBAC 2026 address of 11 August 2026 is verified on the central bank's own speeches listing. The report that a comprehensive AI framework is under deliberation is trade press with no named officials, at discussion stage, and is attributed as press-sourced at every mention; no part of the argument depends on it. The January 2026 proposal to compress significant-data-fiduciary timelines remains un-notified as of the date on this piece and is framed strictly as timeline risk, never as a date. No Indian instrument beyond this set is cited, no figure is asserted about any institution's actual model concentration, and nothing here describes client work.