Live 20 practitioner certifications live · First lesson free on every course Back to main site →

RBI FREE-AI to MeitY. How India's AI governance stack was built in two documents

Most practitioners read the MeitY Guidelines of 5 November 2025 and stop there. That is a mistake. The 7 Sutras in the MeitY Guidelines were lifted verbatim from the RBI FREE-AI Committee Report of 13 August 2025. To understand what the Sutras actually mean, you must read FREE-AI first. This lesson draws the two-document map.

Free preview 12 min read Verified

I had a client call me in January this year to say she had read the MeitY Guidelines three times and still could not tell what the Sutras actually required her to do. The language was elegant. The operational meaning was elusive. I asked her whether she had read the RBI FREE-AI Report. She said no, because her organisation was not a bank. I told her to put the Guidelines down and read FREE-AI first.

She called back two days later and said she now understood the Guidelines. The confusion had not been in the Guidelines; the confusion had been in reading them in isolation. The Guidelines borrow the Sutras from FREE-AI, which spells them out in the context of a working financial-sector programme with 26 specific recommendations. Read FREE-AI first, read the Guidelines second, and the operational meaning falls into place.

The stack has two documents, in this order

The first document is the Reserve Bank of India\'s "Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector", released on 13 August 2025 [L2-C1]. The Committee was constituted under the chairmanship of a Deputy Governor. The remit was to produce a framework for the financial sector, but the output overflowed sector boundaries. The 7 Sutras [L2-C2], the 6 Pillars and the 26 Recommendations [L2-C3] are written in general enough terms that MeitY was able to adopt them wholesale for the national AI governance regime three months later.

The second document is the MeitY "India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation" released on 5 November 2025 under PIB PRID 2186639. MeitY added the 6 Pillars framing [L2-C4] across three domains (Enablement, Regulation, Oversight), articulated the three institutions (AIGG, TPEC, AISI) and set the voluntary posture. But the operational language of the Sutras is RBI language.

The practical consequence is important. If you work in the financial sector, FREE-AI is directly applicable with its 26 Recommendations as a running checklist. If you work outside the financial sector, FREE-AI is still your best interpretive key for what the MeitY Sutras mean in practice. Read FREE-AI even if you are a healthcare AI deployer or an e-commerce AI deployer, because the Sutras it defines are the ones MeitY expects you to live by.

What the 7 Sutras actually say

Sutra 1, Trust is the Foundation. Trust in AI systems must be built through demonstrable safeguards, documented transparency and accountability. "Trust" is not aspirational language in the Sutras. It is an operational test: can a reasonable regulator, a reasonable Board and a reasonable user believe the AI system is doing what you say it is doing? If no, you have not built trust yet.

Sutra 2, People First. Human-centric design, human oversight and human empowerment especially for high-impact decisions. This is the sutra that drives the human-in-the-loop requirement.

Sutra 3, Innovation over Restraint. Enable innovation; use targeted interventions where risk crystallises. This is why the Indian regime is voluntary at the national level and interventionist at the sectoral level. SEBI, RBI and IRDAI intervene where their mandate reaches; MeitY sets the frame.

Sutra 4, Fairness and Equity. AI must not entrench or amplify unfair bias. Measurement is expected. "Fair in the abstract" is not an acceptable defence; a bias-testing report is.

Sutra 5, Accountability. Accountability follows function. The developer answers for development choices. The deployer answers for deployment choices. The data provider answers for data quality. This is the single most important Sutra for an AI Governance Officer because it structures the entire programme.

Sutra 6, Understandable by Design [L2-C5]. Disclosures and explanations the intended user and the regulator can actually understand. "Technical documentation that only PhD data scientists read" fails Sutra 6.

Sutra 7, Safety, Resilience and Sustainability. AI systems must be safe for the user, resilient to attack and sustainable in operation. The sustainability part is new in the 2024-25 wave of international standards work and tracks the OECD update of 3 May 2024.

The 6 Pillars and what they operationalise

MeitY groups the 6 Pillars under three domains. Enablement covers Pillar 1 Infrastructure and Pillar 2 Capacity Building. These are the IndiaAI Mission [L2-C6] deliverables: compute, datasets, skills. For the AI Governance Officer in a deployer organisation, this domain is largely background music; you consume the public infrastructure.

Regulation covers Pillar 3 Policy and Regulation and Pillar 4 Risk Mitigation. This is where you spend most of your time. Pillar 4 Risk Mitigation structures the AI DPIA, the pre-deployment testing and the post-deployment monitoring.

Oversight covers Pillar 5 Accountability and Pillar 6 Institutions. Pillar 5 is the accountability-follows-function model operationalised. Pillar 6 is where AIGG, TPEC and AISI live. AIGG was formally constituted on 16 April 2026 and TPEC on 18 April 2026; AISI is incubated under the IndiaAI Mission with Director recruitment closed 2 June 2026 and appointment pending public confirmation as of 9 October 2026. The course flags implementation output from each as a "watch" item on your calendar.

Five failure modes in reading the stack

Reading MeitY in isolation. The Guidelines quote the Sutras in headline form; FREE-AI defines them in working form. Read both.

Treating FREE-AI as "only for banks". Non-financial deployers get the clearest operational reading of the Sutras from FREE-AI. Read it anyway.

Treating the 26 FREE-AI Recommendations as advisory wallpaper. They are the single best running checklist available in Indian AI governance literature today. Use them.

Assuming the Guidelines will become mandatory on a known date. The Guidelines are explicitly voluntary. MeitY has signalled that voluntary measures "may eventually lead to mandatory ones" without a date. Operate on a prudential schedule aligned to ISO/IEC 42001 [L2-C7] annual surveillance rhythm, not a statutory deadline.

Missing the Standing Committee on IT Report of 30 March 2026 which recommends a comprehensive AI law. If the Winter Session 2026 tables a Bill, the voluntary posture will shift. Track Parliament.

Your artifact from Lesson 2

Build a one-page tracker spreadsheet with the three columns: Instrument, Date, Our organisation\'s posture. Pre-populate with FREE-AI (13 August 2025), MeitY Guidelines (5 November 2025), DPDP Act 2023, DPDP Rules 2025, SEBI AI Advisory (5 May 2026), RBI Draft Model Risk (2026 cycle), IRDAI AI Working Group (19 June 2026), IT Rules 2026 amendment (10 February 2026), Standing Committee on IT Report (30 March 2026). Save it as Artifact 2 in your capstone workbook. Review monthly.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (55 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
RBI AI, RBI FREE-AI Report (13 August 2025) (RBI FREE-AI Report) L2-C1
Framework for Responsible and Ethical Enablement of AI in the Financial Sector. Advisory. Birthplace of the 7 Sutras.
RBI AI, FREE-AI 7 Sutras (FREE-AI Sutras) L2-C2
Seven principles that MeitY later adopted verbatim in its November 2025 Guidelines.
RBI AI, FREE-AI 26 Recommendations (FREE-AI Recommendations) L2-C3
26 actionable recommendations across the FREE-AI framework.
MeitY AI Governance Guidelines 2025, Pillar 4 Risk Mitigation (Pillar 4) L2-C4
Risk classification, controls and mitigation across the AI lifecycle.
MeitY AI Governance Guidelines 2025, Sutra 6 Understandable by Design (Sutra 6) L2-C5
Disclosures and explanations the intended user and regulators can actually understand.
IndiaAI Mission, Cabinet approval (7 March 2024) (IndiaAI Mission approval) L2-C6
IndiaAI Mission approved by Union Cabinet 7 March 2024 with budget Rs 10,371.92 crore over five years.
ISO Standards, ISO/IEC 42001:2023 (ISO 42001) L2-C7
AI Management System standard published December 2023. Annex A has 38 controls under 9 control objectives.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The India AI Governance Perimeter and Why You Are Reading This
Module 2: The MeitY Guidelines, Section by Section
  • The 7 Sutras, one by one, with the Indian context behind each
  • The 6 Pillars across Enablement, Regulation and Oversight, and the two Pillars where you actually spend time
  • Developer, deployer, data provider. Three functions, three parallel sets of duties documented, signed and defended
  • Transparency reporting under Sutra 6, aligned to DPDP, and what a disclosure a regulator can understand actually looks like
  • AIGG, TPEC and AISI. The three institutions, the current state on 9 October 2026 and how to track
Module 3: RBI FREE-AI and Financial-Sector AI
  • The FREE-AI Committee, the Report of 13 August 2025 and the 26 Recommendations that preceded MeitY
  • The Model Risk Management Framework. RBI Draft of 5 August 2024 and the expanded 2026 cycle
  • AI in credit underwriting. Borrower scoring, bias testing and challenger models at an NBFC gold-loan and personal-loan book
  • The AI kill-switch and incident reporting. FREE-AI expectations, the Chapter 5 form and the CERT-In six-hour interface
  • The Bank and NBFC Board policy on AI. The twelve-clause specimen outline
Module 4: SEBI AI Vulnerability Advisory and Market Infrastructure
  • The SEBI AI Vulnerability Advisory of 5 May 2026. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026
  • Annexure A, ten items. The deep walk through items 2, 6c, 9 and 10
  • Market SOC onboarding. What M-SOC is, what it ingests and how an entity integrates
  • How the AI Advisory expands CSCRF audit scope. project-cyber-suraksha.ai and advisor obligations
  • Running the SEBI AI programme end-to-end on Aarti Capital Markets
Module 5: DPDP x AI
  • Section 10 Significant Data Fiduciary. The six-factor test and why nobody has been notified yet
  • Section 10(2)(c) proviso. Algorithmic due diligence, verbatim text and operational meaning
  • Rule 13. Twelve-month DPIA, independent audit and the Board reporting cadence
  • Rule 7 breach notification. AI incidents, the DPB clock, the MeitY expectation and the CERT-In six-hour window
  • Why DPDP has no Article 22. India chose a de facto automated decision regime through Section 10(2)(c)
Module 6: The AI Governance Officer's Playbook
  • The appointment Board resolution in detail. Five authorities, eleven paragraphs, one specimen
  • The AI inventory and model register. Columns, worked rows, and the "one-page in thirty minutes" test
  • The twelve-clause AI governance policy. Scope to third-party management, one clause at a time
  • The Board reporting cadence and the five KPIs that matter
  • Personal liability and the due-diligence defence. DPDP Schedule, sectoral penalties, Section 79 safe harbour
Module 7: Risk Assessment, DPIA and the Model Lifecycle
  • High-impact decision classification. The method MeitY left to you
  • The AI-specific DPIA. Ten sections that satisfy DPDP Section 10(2)(c) and Rule 13
  • Pre-deployment testing. Bias, robustness and security batteries that satisfy a regulator
  • Post-deployment monitoring. Drift, feedback loops, shadow mode and the thresholds that trigger review
  • Change control, retraining and incident response. Closing the lifecycle loop
Module 8: Transparency, Explainability and Human Oversight
  • User-facing transparency notices. Operationalising Sutra 6 for Aarti Capital's three AI use cases
  • Model cards and datasheets for datasets. The two documents a regulator will ask for first
  • Explainability for high-impact decisions. What SHAP, LIME and counterfactuals buy you, and where they fail
  • Human-in-the-loop oversight. Three stages, one SOP, and how to document that a human actually reviewed
  • Audit trail and immutable logging. Reconstructing a specific AI decision three years later
Module 9: Synthetic Media and the IT Rules 2026 Amendment
  • The new Synthetically Generated Information category under the IT Rules 2026 amendment
  • Labelling and provenance metadata. Watermarks, C2PA and metadata that survives re-encoding
  • The three-hour takedown and the two-hour non-consensual sexual imagery window
  • Deepfake case law. Rashmika Mandanna, Lok Sabha 2024 and Images Bazaar PIL
  • The MeitY advisories of 1 March and 15 March 2024. How India iterates fast
Module 10: Sectoral Deep-Dives: IRDAI, Telecom, Health and Public Services
  • IRDAI AI Working Group and the framework insurers should pre-build
  • The IRDAI 2026 Cyber Security Guidelines and AI as a threat vector
  • The Telecom Cyber Security Rules 2024 and where AI sits in a silent framework
  • TRAI's AIDAI proposal and why MeitY picked AIGG, TPEC and AISI instead
  • Healthcare, education and public-services AI: the gaps and the practitioner playbook
Module 11: The International Reference Layer
  • EU AI Act. The four risk tiers and the phased timeline that quietly binds Indian GCCs
  • NIST AI RMF 1.0 and the GenAI Profile. Four functions and twelve generative risks
  • OECD AI Principles. The common vocabulary that lets a Mumbai team talk to a Munich team
  • ISO/IEC 42001. The voluntary conformity path and the clause-by-clause map to the MeitY 7 Sutras
  • The GCC compliance architecture. One baseline plus two overlays, when EU plus India plus US arrives at once
Module 12: Capstone and Final Exam
  • Build your ten-week AI governance programme. The scope document and the stakeholder map
  • Weeks 1-10 Gantt and the twelve artifacts of the capstone workbook
  • The Board briefing deck and the year-1 operating calendar
  • The 25-anchor exam reference card
  • The final exam. 45 questions from a 70-item pool, 90 minutes, 75 percent pass