Seven Sutras of AI in India: RBI's FREE-AI Framework Explained

TL;DR
RBI's FREE-AI framework gives India seven simple rules, or "sutras," for using AI responsibly in finance: Trust, People First, Innovation over Restraint, Fairness, Accountability, Understandability, and Safety. They sit on six pillars and 26 recommendations, and India's national AI guidelines have now adopted them for every sector. The big idea is "do both": innovate boldly with AI, and build the controls to keep it safe. For banks and enterprises, that means every AI system needs a clear owner, human escalation, ongoing monitoring and a plan for silent failures, before it goes live.

RBI's seven sutras are the base of India's new AI governance framework for finance. Knowing them is now as important as knowing what AI can do.
Banks, NBFCs, fintechs and insurers already use AI. They use it for customer support, catching fraud, checking credit, watching risk and staying compliant. But now AI is starting to make its own decisions. So a second question is becoming just as big:
AI can do so much today. But can we use it in the right way?
RBI answered this with a framework called FREE-AI. The full form is Framework for Responsible and Ethical Enablement of Artificial Intelligence.
It gives us seven simple rules, called Sutras. It also gives six pillars and 26 recommendations. Later, India's national AI Guidelines took the same seven sutras and used them for every sector. That is why this banking rulebook now matters for everyone.
So what are these seven sutras? And what do they mean in real life? Let us go one by one.
What are the Seven Sutras of AI in India?
The seven sutras from RBI's FREE-AI framework are:
Trust is the Foundation
People First
Innovation over Restraint
Fairness and Equity
Accountability
Understandable by Design
Safety, Resilience and Sustainability
RBI says these are not separate boxes to tick. They are linked. And they should run through the full life of any AI system.
The best part is simple:
Use AI boldly. And build controls to keep it safe. Not one or the other. Do both.
What is AI Governance, and why does it matter in Finance?
AI governance means the rules and checks that keep AI safe, fair and answerable. This runs from the data stage to daily use.
In most fields, this is just good practice. But in finance, it is a must. Because financial AI does not only write summaries. It decides who gets a loan. It decides which payment looks fishy. It decides how a customer is treated.
That is why all seven sutras matter so much.

The Seven Sutras in AI Explained
1. Trust is the Foundation
Every other sutra comes back to this one. RBI is very clear here. You cannot break trust just to move faster.
Here is why finance is different. One AI system can quietly decide:
if a customer gets a loan
how a strange payment is flagged
how a complaint is handled
how a person's risk is scored
what info the customer sees
When AI handles people's money, you cannot just assume it is safe:
Trust is not something you say. It is something you build.
So you must be able to see how the AI works. What data it uses. What happens if it fails. And who is responsible when things go wrong.
For companies: treat trust like a number you track. Not just a nice line in a policy.
2. People First
This sutra keeps people at the centre. AI should help humans decide. The final call should stay with a human when safety matters. And customers should always know when they are talking to a machine, not a person.
This becomes very important when AI stops only suggesting and starts doing:
AI suggests → a human checks → then it happens
is very different from
AI decides → AI does it → someone finds out later
Example: an AI sees a big, odd money transfer. In a "People First" setup, it should hold it and flag it. Then pass it to a human for the final call. It should not act on its own.
RBI also says customers must be able to complain easily. And they must be able to reach a real person when needed.
For companies: this does not mean a human approves every action. It means you decide in advance where a human must step in.
3. Innovation over Restraint
This is where RBI's thinking is really smart. Most people ask, "how do we stop AI from causing trouble?" FREE-AI asks a better question:
How do we let good AI ideas grow, and still stay safe?
To make this happen, RBI suggests some very practical steps:
shared data for the finance sector
an AI Innovation Sandbox to build and test safely
India's own AI models made for finance
easy access to computing power
linking AI with India's Digital Public Infrastructure
rewards for building the right way
The sandbox is the big idea. It is a safe, closed space. Banks and fintechs can build and test AI there before it reaches real customers.
The thinking is simple. Do not choose between trying new things and staying safe. Just make a space where trying new things is already safe.
For companies: governance should be the clear road to launch. Not the reason your AI stays stuck in a test forever.
4. Fairness and Equity
AI's biggest strength is that it works at scale. That is also its biggest danger.
AI scales up good decisions. Sadly, it scales up unfair ones just as fast.
RBI links fairness with financial inclusion. It warns that AI should not make old gaps worse. The tricky part? A model can look great and still treat some people unfairly.
Example: a credit model shows 92% accuracy. Everyone is happy, so it goes live. But break the results down by region or income. The approval rate quietly drops for one group. The big number was hiding the problem.
So fairness cannot be a one-time test before launch. You must check it at every step:
training data → building the model → testing → launch → live monitoring → real results
For companies: a model that works is not the same as a model that works fairly. Make fairness testing a habit, not a formality.
5. Accountability
If you remember only one line from this whole framework, remember this:
You cannot blame the AI model or the algorithm.
RBI says the company using the AI is responsible. No matter how smart or independent the system is. This matters a lot if you buy AI from an outside vendor:
Buying a model does not mean you are off the hook for what it does in your company.
So the company using the AI must still know:
what it is used for, and who owns it
what data it can reach
what decisions it can affect
which vendors are involved
what happens if it fails, and who can step in
how its decisions are checked later
RBI's answer is a board-approved AI policy. It should cover governance, risk limits, safeguards, checks, customer protection, disclosures and liability.
Today, AI can access systems and run tasks on its own. So "the model made a mistake" is just not good enough.
For companies: every AI system needs a clear owner, a way to escalate, and a record of its decisions. No exceptions.
6. Understandable by Design
AI does not need to show every technical detail. But you must understand enough to control it.
Example: an AI rejects someone's loan. Saying "the model predicted this" helps no one. Not the customer. Not the manager. Not the regulator.
What the company really needs to know is:
what led to this decision
was it in line with policy
did any bias creep in
did the model behave as expected
does a human need to review it
Explainability is not about making AI fully open. It is about making its behaviour easy to control.
For companies: match the level of explanation to the risk. A product suggestion needs far less than a loan rejection.
7. Safety, Resilience and Sustainability
The last sutra takes "safety" much further than just accuracy. It also covers security. It covers staying strong under pressure. It even covers saving energy. And it wants early alerts to catch problems.
The risks here are very real:
cyber attacks and targeted attacks
data poisoning and tampering
data drift and model drift over time
wrong or unreliable outputs
system failures and breakdowns
And here is the part most teams miss:
A normal IT breakdown is easy to spot. But an AI failure can stay hidden. The system looks fine and keeps running. Meanwhile, its decisions slowly get worse.
That silent failure is exactly why RBI wants constant monitoring, red teaming (testing the system by attacking it on purpose), incident reporting, AI backup plans and fallback options.
For companies: being resilient means planning for the day your AI fails without looking like it has failed.
Inside the RBI FREE-AI AI Governance Framework: SIX pillars and 26 Recommendations
Stopping at the seven sutras means you miss half the story. These rules stand on six pillars. They are split into two groups. This matches the "do both" idea.
To encourage new ideas
Infrastructure: the data, computing and tech base for responsible AI
Policy: flexible rules that allow new ideas and handle new risks
Capacity: building AI know-how across boards, staff and regulators
To manage risk
Governance: clear structures for decisions and oversight
Protectio: keeping customers, data and systems safe
Assurance: testing, watching and checking AI all the time
Under these pillars sit 26 recommendations. They cover a lot. Data setup, sandboxes and Indian AI models. Also board-approved AI policies, lifecycle management, red teaming, incident reporting and regular checks. For example, RBI wants regulated companies to build board-approved AI policies. It also wants regular red teaming, with more testing for higher-risk uses.
The whole point is this:
AI governance is not a document you write once and forget. It is a system for how you build, run, watch and improve AI every day.
From RBI's Sutras to India's National AI Governance Framework
These sutras matter beyond banking too. India's national AI Guidelines have adopted them for every sector. So there is a clear path here:
RBI FREE-AI → AI governance for finance → national AI governance principles
One point to remember. The national guidelines are advisory. That means they are suggestions. But a regulator like RBI can make its own rules for the companies it controls. For a bank, that is the difference between what is encouraged and what is expected.
AI in Banking: What the Sutras Mean in Real Use
The biggest change in enterprise AI is this. It has moved past simple chatbots. Now AI is linked to core systems:
company databases → CRM → banking platforms → workflow tools → APIs → internal knowledge bases
In short, AI is moving from just answering questions to actually doing tasks. That is why these sutras are urgent, not just theory. Before launching an AI agent, a company should be able to answer seven simple questions:

The real question today is not "do we have an AI policy." It is "can we prove our AI is properly governed in real use."
A Simple AI Governance Checklist for Companies
Before any AI system goes live, cover these five basics:
Know your AI. Track every model, agent and vendor you use.
Fix ownership. Each system needs a business owner, a tech owner and a risk owner.
Add human escalation. Decide where AI can act alone and where a human must review.
Keep watching. Track performance, drift, security and fairness after launch, not only before.
Plan for failure. Keep rollback, fallback, incident reporting and backup plans ready.
These match RBI's FREE-AI recommendations almost exactly. That is, governance, assurance, red teaming, incident reporting and AI backup planning.
From Principles to Real Use: What Companies Need Next
The seven sutras tell you where to go. The hard part is actually getting there in daily use. This is where most companies get stuck.
Fluid AI helps banks and enterprises put responsible AI into action. It builds agentic AI systems with proper records, human escalation, constant monitoring and on-premise deployment. And it keeps them aligned with what regulators expect, instead of adding this later. With 14+ years in enterprise AI, ISO 27001 and SOC 2 Type II certifications, and 14+ live production deployments, Fluid AI is built for exactly this move from principle to real use.
[See how Fluid AI deploys governed, production-grade agentic AI →]
Frequently Asked Questions (FAQs)
1. What are the seven sutras of AI in India?
Trust is the Foundation, People First, Innovation over Restraint, Fairness and Equity, Accountability, Understandable by Design, and Safety, Resilience and Sustainability. They come from RBI's FREE-AI framework.
2. What is AI governance?
AI governance means the rules and checks that keep AI safe, fair and answerable. This runs from the data stage to daily use.
3. What is an AI governance framework?
It is a clear set of rules and controls for building and using AI the right way. RBI's FREE-AI framework is one example. It is built on seven sutras, six pillars and 26 recommendations.
4. What is the RBI FREE-AI framework?
It is RBI's Framework for Responsible and Ethical Enablement of AI. It has seven sutras, six pillars and 26 recommendations for using AI responsibly in finance.
5. How is AI used in banking?
For catching fraud, checking credit, customer support, watching risk, staying compliant and working faster. And more and more, through agentic systems that do tasks, not just answer questions.
6. What is the future of AI in banking?
It is the shift from chatbots to well-governed, large-scale agentic systems. The banks that win will be the ones that can run AI with accountability, monitoring and human oversight.
Book your Free Strategic Call to Advance Your Business with Generative AI!
Fluid AI is an AI company based in Mumbai. We help organisations kickstart their AI journey. If you're seeking a solution for your organisation to enhance customer support, boost employee productivity and make the most of your organisation's data, look no further.
Take the first step on this exciting journey by booking a Free Discovery Call with us today and let us help you make your organisation future-ready and unlock the full potential of AI for your organisation.