RBI Governor Sanjay Malhotra warned that DPDP Act compliance alone is insufficient for banks using AI, outlining six critical risks including black-box algorithms, vendor dependencies, and cyber threats.

RBI Governor Warns Banks: DPDP Compliance Alone Insufficient for AI, Identifies Six Critical Risks

The420 Web Correspondent
5 Min Read

Speaking at the FIBAC 2026 banking conference in Mumbai, Reserve Bank of India (RBI) Governor Sanjay Malhotra cautioned financial institutions that mere compliance with the Digital Personal Data Protection (DPDP) Act will not suffice as they rapidly integrate artificial intelligence into their operations. He urged lenders to go well beyond statutory minimums, emphasizing that data privacy, fairness, and governance must be treated as fundamental design requirements rather than superficial compliance checkboxes.

While acknowledging AI’s immense potential to revolutionize credit assessment, streamline operations, and drive financial inclusion across underserved sectors, Malhotra warned against uncritical adoption. He stressed that technological expansion must be anchored by robust internal governance, active risk mitigation, and absolute human accountability, stating firmly that financial institutions—not software algorithms—remain fully responsible for operational and credit outcomes.

The Six Core AI Risks Facing Financial Institutions

During his key address, the central bank governor detailed six specific risks that financial institutions must actively manage while scaling AI capabilities. The primary risk is the explainability problem, often referred to as the black box issue, where automated systems make life-altering decisions such as loan rejections without offering transparent, auditable rationales to auditors, regulators, or customers. The second risk centers on algorithmic bias and exclusion, wherein models trained on historical data risk perpetuating systemic discrimination against specific geographies, occupations, or socio-economic communities.

The remaining risks identified by the governor highlight systemic structural and technical vulnerabilities within the broader banking network. Malhotra cited concentration and herding risks, which arise when multiple lenders rely on identical AI models, potentially turning isolated algorithmic errors into widespread financial contagion. He also highlighted heavy third-party vendor dependence, data privacy gaps that extend beyond basic legal compliance, and emerging cyber risks where adversarial AI tools can actively test, target, and exploit banking security infrastructure.

Accountability, Vendor Governance, and Human Oversight

Addressing vendor reliance, Governor Malhotra made it clear that outsourcing technology does not relieve banks of legal or regulatory duties. Recognizing that smaller banks often lack the capital to build proprietary large language models and advanced AI architecture, he acknowledged the necessity of external tech partnerships while insisting that compliance must extend beyond the institution’s physical perimeter. Lenders are expected to maintain comprehensive inventories of all deployed models and rigorously monitor vendor software for hidden biases or operational defects.

Beyond third-party risk management, the RBI governor warned against the gradual erosion of human judgment and institutional accountability. He emphasized that artificial intelligence should be leveraged to augment human capacity—such as equipping relationship managers with real-time risk flags and product insights—rather than replacing human oversight altogether. In instances of system failure, unfair denial of service, or improper financial assessments, banks will not be permitted to shift blame onto external vendors or automated tools.

Harnessing AI for Inclusive Financial Growth

Despite issuing stern warnings on governance, Governor Malhotra urged Indian lenders to embrace artificial intelligence proactively rather than remaining on the sidelines. He noted that India occupies a unique vantage point globally due to its public digital infrastructure, including Aadhaar, UPI, DigiLocker, ONDC, the Account Aggregator framework, and the Unified Lending Interface (ULI). When combined with AI, this public infrastructure can analyze alternative data points like GST filings, cash flow statements, and utility payments to expand formal credit to micro, small, and medium-sized enterprises (MSMEs) and gig workers.

Concluding his address, Malhotra remarked that the banks that ultimately succeed in the AI era will not necessarily be those that adopt the technology fastest, but those that deploy it with a complete understanding of its risks and systemic implications. He expressed confidence that Indian banks maintain strong balance sheets, sound liquidity, and steady credit growth, leaving them well-positioned to ride out global economic headwinds while building a secure, AI-enabled financial system

Stay Connected