RBI's Governor Just Told Banks the DPDP Act Isn't Enough for AI. Read the Act and He's Right
RBI Governor Malhotra told FIBAC 2026 that DPDP Act compliance alone won't cover AI in banking. India's law has no right to contest automated decisions.
#RBI's Governor Just Told Banks the DPDP Act Isn't Enough for AI. Read the Act and He's Right
On 11 August 2026, at the opening session of FIBAC 2026 in Mumbai, Reserve Bank of India Governor Sanjay Malhotra told a room full of bank chairpersons something no Indian regulator had said quite so bluntly: complying with the Digital Personal Data Protection Act will not be sufficient for banks deploying artificial intelligence. He then listed seven categories of AI risk and handed boards a five-item checklist. The uncomfortable part for compliance teams is that he is legally correct — India's DPDP Act genuinely does not regulate algorithmic decision-making, and the country's most consequential AI-privacy rules are now arriving from a sectoral regulator rather than from the data protection law itself.
That distinction matters enormously for how Indian banks, NBFCs and fintechs should budget the next nine months. A DPDP Act gap-assessment programme, however well-run, will not produce the artefacts the RBI is now asking for.
#What Malhotra actually said
Speaking at the annual conference organised by FICCI and the Indian Banks' Association, Malhotra framed AI as the defining force of this decade — the equivalent of digitalisation in the 2000s and liberalisation in the 1990s — and pressed banks to treat it as a board-level strategy rather than a technology procurement line item. "The only question now before us is whether you shape the AI journey or you let it shape you by default," he said, according to reporting on the speech.
The warning came alongside the encouragement. Careless AI deployment in the financial sector, he cautioned, could create new forms of exclusion and instability "at a pace that regulators and banks may struggle to manage." And on privacy specifically, the message was that statutory minimums are the floor, not the ceiling: data privacy, fairness and governance must be built in as design requirements. "Fairness in AI is not a compliance checkbox. It is a design requirement," he said. On accountability he was unambiguous: "The ultimate responsibility has to lie with the bank and not with a vendor or with an algorithm."
The seven risk areas he set out were:
- Explainability — black-box models producing consequential decisions no one can reconstruct or audit
- Bias and exclusion — discrimination inherited from historical lending data, by geography, occupation or community
- Concentration and herding — many lenders running the same handful of models, so one modelling error becomes systemic contagion
- Third-party dependencies — outsourced models without outsourced accountability
- Data privacy — obligations extending beyond bare legal compliance
- Cyber and adversarial vulnerabilities — attackers using AI to probe and exploit banking defences
- Erosion of human accountability — institutional judgement quietly deferring to model output
His prescription for boards was concrete: maintain a complete inventory of every AI model in use; adopt a board-approved AI governance policy framed around outcomes rather than tooling; build the capability to explain any decision that materially affects a customer; red-team and stress-test AI systems; and preserve meaningful human oversight wherever failure could cause material harm. He also noted the economics — bank IT spending rose roughly 6.1 times between FY2015 and FY2026 while the sector's cost-to-income ratio barely moved, from 47.3% to 48.6% — arguing that AI pays off only when processes are redesigned around it, not when existing workflows are automated in place.
#The gap Malhotra was pointing at is real
Read the DPDP Act and its Rules end to end and you will find no provision on automated decision-making. There is no right to an explanation, no right to contest a decision made solely by a machine, and no obligation to offer human review of an algorithmic outcome. This is one of the sharpest divergences from the GDPR, where Article 22 lets individuals challenge purely automated decisions with legal or similarly significant effects. India's statute has no equivalent.
What the DPDP Act does do is regulate the personal data that flows into and out of an AI system. Consent must be free, specific, informed and unconditional, with an itemised notice. Purpose limitation binds processing to the purpose consented to. Data minimisation restricts collection to what is necessary. Section 8(5) requires reasonable security safeguards, and Rule 7 of the DPDP Rules 2025 sets the two-stage breach notification path — an initial alert without delay, followed by a detailed report to the Data Protection Board within 72 hours.
So a bank can build a credit model that is opaque, statistically biased against applicants from a particular district, and entirely unexplainable — and still be fully DPDP Act compliant, provided it collected the training data with valid consent and stored it securely. That is precisely the hole Malhotra was describing. Under the DPDP framework, an unfair model is not a privacy violation.
The one place the Act edges towards algorithmic accountability is the Significant Data Fiduciary regime. Under Section 10 and Rule 13 of the DPDP Rules 2025, an entity designated as an SDF must conduct an annual Data Protection Impact Assessment and independent audit, submit key findings to the Board, and — the operative language — exercise due diligence to verify that technical measures and algorithmic software deployed do not pose a risk to the rights of data principals. That is a genuine algorithmic due-diligence duty. But it applies only to entities the Central Government designates, and as of mid-2026 MeitY had not published an initial SDF list. For every bank not yet designated, Rule 13 is a duty in waiting.
#The RBI has been building this in parallel
Malhotra's speech was not an off-the-cuff intervention. It sits on top of two years of RBI work that has quietly become India's most detailed AI governance regime.
The FREE-AI Committee — Framework for Responsible and Ethical Enablement of Artificial Intelligence — was constituted in December 2024 and reported in August 2025 with 26 recommendations across six pillars: Infrastructure, Policy, Capacity, Governance, Protection and Assurance. Its accompanying survey of regulated entities found that only 20.8% were deploying AI at the time, with credit underwriting at 13.7% and customer support at 15.6% — but 67% expressed interest in exploring use cases. The regulator was writing rules for adoption it could see coming rather than adoption already in place.
Then came the operative document. On 24 June 2026 the RBI released its draft Guidance on Regulatory Principles for Model Risk Management, 2026, with public comments closing 24 July. Its scope is expansive: commercial banks, small finance banks, payments banks, regional rural banks, urban and rural cooperative banks, NBFCs across all layers, all-India financial institutions, asset reconstruction companies and credit information companies. It assigns model governance to the Board and the Risk Management Committee, mandates risk-based tiering of models, requires maintained model inventories, and — critically — states that a regulated entity cannot rely on a vendor's safety certification. Third-party AI must be independently validated by the institution carrying the risk.
Set the two documents side by side and the five items Malhotra gave boards on 11 August are simply the draft MRM guidance restated as a to-do list. This was a supervisory preview, not a philosophical musing. And note the direction of travel: the RBI is layering algorithmic accountability onto financial institutions through prudential regulation, while the DPDP Act's own AI provisions remain absent. MeitY's India AI Governance Guidelines, released in February 2026 around seven guiding principles, are explicitly principle-based and largely voluntary, and expressly defer binding obligations to existing law — the DPDP Act, the IT Act, consumer protection statutes, and sectoral regulators. In other words, the AI guidelines point at the DPDP Act, and the DPDP Act is silent on AI. The RBI is filling that vacuum for its own regulated universe.
#Why this lands hard on a compressed timeline
The DPDP Rules were notified on 13 November 2025 with a phased commencement. Phase one, covering the Data Protection Board and its procedures, is already live. The consent manager framework activates on 13 November 2026. Full substantive compliance — notice and consent operations, data principal rights, breach reporting, retention, SDF obligations — bites on 13 May 2027. MeitY floated a proposal at a stakeholder consultation on 23 January 2026 to compress that 18-month runway to 12 months, which would pull the deadline forward to November 2026. That proposal has not been confirmed by gazette notification, but no bank should be planning as though it definitely will not happen.
Against that calendar, the readiness data is poor. Survey work through 2026 found roughly 48% of organisations had begun gap assessments, more than 81% had not drafted or updated DPDP-aligned privacy policies, and 83% had not initiated system-level changes for consent logging. Consent logging is the foundational plumbing. Without it, neither a DPDP audit trail nor an RBI model-lineage inquiry can be answered — you cannot demonstrate which consent authorised the data that trained a given model version.
There is also the regulator-shaped hole. The Data Protection Board of India was constituted on 13 November 2025, but reporting in late July and early August 2026 has flagged that it still lacks a publicly announced full complement of appointed leadership, with MeitY having sought nominations for the chairperson and member posts through communications dated 6 May and 6 June 2026, assessed by a search-cum-selection committee chaired by the Cabinet Secretary. LiveLaw's assessment — "established in law, absent in fact" — captures the operational reality. That matters directly for consent managers: registration runs through the Board, and the November 2026 deadline is now under four months away.
The practical consequence is that for Indian banks and NBFCs in 2026, the DPDP enforcer with actual teeth on the ground is the RBI. Prudential supervision does not wait for a Board to be staffed. An RBI inspection can ask for your model inventory next quarter.
#What to do with this
For regulated financial entities, the honest reading is that you are running two overlapping programmes and most institutions have budgeted for one.
The DPDP programme delivers consent architecture, itemised notices, retention schedules, data principal rights workflows, processor contracts and 72-hour breach machinery. The RBI programme delivers a model inventory, a board-approved AI governance policy, model risk tiering, independent validation of vendor models, red-teaming evidence, explainability capability for customer-affecting decisions, and documented human oversight at material-harm points. They share infrastructure — consent metadata, data lineage, purpose tagging — and diverge sharply in artefacts.
The efficient move is to build the shared layer once. If every customer record carries the consent that authorised it and the purpose it was collected for, that single control simultaneously answers a DPDP purpose-limitation audit and an RBI question about what data a model was permitted to see. Institutions that treat these as two disconnected projects will build the same lineage twice and reconcile neither.
For everyone outside RBI's perimeter — SaaS companies, healthcare platforms, ed-tech, HR-tech, marketplaces — the lesson is different but not comfortable. Malhotra has just articulated a standard that will be quoted back at you. When the Data Protection Board is eventually staffed and begins adjudicating, "we met the letter of the DPDP Act" will be argued against a public record in which India's most senior financial regulator called that standard insufficient for AI. Sectoral supervisory expectations have a way of becoming general market practice, and then becoming what a reasonable data fiduciary is deemed to have known.
Three things are worth doing this quarter regardless of sector. Inventory every model or automated system that touches personal data and can affect a person's access to a service, price, or eligibility. For each one, write down what data it uses and what consent authorised that use — if you cannot, you have a DPDP problem before you have an AI problem. And decide now who at your organisation can explain a decision to a customer who asks, because that capability is built, not declared.
If you are mapping your consent architecture against the 13 November 2026 framework, our consent manager breakdown covers the registration route and integration mechanics. For the wider DPDP Act obligation set, including SDF designation and the Rule 13 audit and DPIA duties, start with our resources library.
The Governor's line deserves to outlive the news cycle. Fairness in AI is not a compliance checkbox — and in India, as of today, it is not even in the privacy statute. That is exactly why boards, not compliance teams, were the audience.