RBI Warns Banks AI Can Be Both Weapon and Defence

The420.in Staff
6 Min Read

The Reserve Bank of India has warned that artificial intelligence can strengthen banking operations while also creating new cyber and operational risks, saying financial institutions must combine advanced technology with human judgement, stronger governance and effective security controls.

How Can AI Help and Harm Banks?

The RBI’s September 2026 bulletin describes AI as both a possible instrument of attack and a powerful tool of defence.

Malicious actors can use AI to scale phishing, impersonation, vulnerability exploitation and other cyberattacks. At the same time, financial institutions can deploy AI for continuous threat detection, behavioural anomaly analysis and automated incident response.

AI can also strengthen customer service, improve fraud detection, support risk assessment, increase productivity and help institutions analyse large volumes of information.

However, the RBI cautioned that AI can amplify errors as quickly as it improves efficiency. This is particularly important in financial services, where automated outputs can influence credit decisions, fraud alerts, customer access, pricing and service delivery.

The central bank said AI use must therefore be accompanied by appropriate validation, monitoring, human oversight and clear accountability.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Who Has the Advantage?

The RBI said both attackers and defenders increasingly have access to similar technological tools. As a result, simply possessing advanced technology may not provide a lasting advantage.

The advantage could instead go to institutions capable of understanding, governing and deploying technology with greater discipline and foresight.

The banking ecosystem should move towards coordinated and responsible adoption of AI-enabled cybersecurity capabilities, including centralised threat intelligence and automated detection and response systems.

Such an approach could help identify and contain emerging threats across the ecosystem rather than dealing with incidents only after individual institutions have been targeted.

Why Is Cyber Risk Now a Business Risk?

The RBI said technology risk can no longer be treated merely as an IT department problem.

Technology architecture risk should be viewed as a first-order enterprise risk, comparable in importance to traditional balance-sheet risks. It can no longer be managed solely as a back-office or technical issue.

Technology is now embedded across critical banking functions, from core banking and payments to customer onboarding, credit assessment, fraud monitoring and regulatory reporting.

A failure in the underlying technology architecture can therefore disrupt not merely a system but the delivery of essential financial services.

The risk can also extend beyond a bank’s own systems. A vulnerability involving a connected fintech company, software provider, payment interface or common cloud environment can affect an institution even when the weakness originates elsewhere.

Why Does Human Judgement Still Matter?

The RBI stressed that human judgement remains essential even as technology becomes more advanced.

AI can process information faster, identify patterns, make predictions and support decisions. But in finance, the RBI said AI is beginning to augment something particularly important: human judgement.

Managing these risks requires both technological and human capacity.

On the technology side, institutions need secure architecture, resilient infrastructure, effective monitoring, appropriate redundancy, tested recovery arrangements and the ability to identify and respond to emerging threats.

On the human side, banks require professionals who understand cybersecurity and technology as well as banking operations, risk management, data governance and the implications of interconnected financial systems.

Who Is Responsible for AI and Technology Risk?

The RBI said responsibility for technology governance must rest with boards and senior management, with clear ownership across business risk, compliance, operations and technology functions.

Senior management and boards should have enough technological understanding to question assumptions, evaluate dependencies and assess whether resilience arrangements have genuinely been tested.

This means technology and AI risks cannot simply be delegated to technical teams. They require oversight at the highest levels of financial institutions.

What Is RBI’s Message to Banks?

The RBI called for a balance between innovation and caution as financial institutions adopt AI and other emerging technologies.

Governance should allow innovation to move forward while protecting the resilience and trustworthiness of the financial system.

“We must innovate quickly, but not blindly; embrace AI and emerging technologies, but with accountability.”

The central bank said institutions must innovate quickly but not blindly, embrace AI with accountability, pursue interconnectedness while maintaining resilience, and collaborate on security even while competing on innovation.

AI is also only one part of a wider technological transformation. The RBI pointed to tokenisation, distributed technologies and quantum computing as developments that could create new opportunities while raising fresh questions about digital security and cryptographic resilience.

The420 Takeaway

The RBI’s message is clear: AI can make banking faster and safer, but it can also make cyber threats more powerful. Banks cannot leave AI risk to their IT teams alone. Boards and senior management must ensure strong security, human oversight and clear accountability.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected