Break Glass: Inside the RBI's Draft Kill Switch Mandate
Imagine walking into a bank’s server room. Tucked behind rows of blinking hardware sits a giant red button under glass. The label reads: IN CASE OF AI EMERGENCY, BREAK GLASS.

Sounds like science fiction. But on June 24, 2026, the Reserve Bank of India (RBI) turned it into policy.

The RBI released a draft circular “Guidance on Regulatory Principles for Model Risk Management, 2026” which mandates an instant kill switch for every AI system running inside an Indian bank, NBFC, or financial institution. If an AI hallucinates, discriminates, or starts making erratic decisions, human supervisors must be able to shut it down immediately. No waiting or rebooting. Just a complete, immediate freeze.

Why Is the RBI Pulling the Emergency Brake?

Banks have been sprinting to integrate AI into everything. It approves your loans. It scores your credit risk. It hunts for fraud. It powers the chatbot you use to complain about a failed UPI transaction.

But AI has a chaotic side. It hallucinates - making things up with full confidence. It develops bias, quietly discriminating against certain applicants based on flawed training data. 

72 percent of banks cannot shut down a malfunctioning AI

That 72% number is not from India alone: it’s a global survey. But India’s banks face the same reality. The RBI isn’t creating a new problem. It’s making an existing one visible.

Convenience cannot come at the cost of control. The RBI is preventing a scenario where an out-of-control algorithm causes market panic before humans even realize what went wrong.

The 4 Non-Negotiables for Every Bank in India

The 4 controls RBI is mandating

  • The Kill Switch: Every AI system must have a documented emergency stop, one that works independently of the model itself. Think of it like a circuit breaker. The breaker doesn’t depend on the appliance to function. If the AI is compromised, the override still must work. The RBI is requiring the same principle.
  • Escape the Bot: We have all been trapped in an endless loop with a chatbot. The RBI is ending that. Banks must disclose when you’re talking to an AI. And they must give you a seamless, one-click option to switch to a live human at any point. Not buried three menus deep. One click.
  • No More “Pass the Buck”: Many banks buy AI tools from tech vendors and startups. When something breaks, it’s easy to blame the vendor. The RBI is shutting that loophole. Banks are now 100% accountable for every third-party AI model they deploy. They must validate the vendor’s code and ensure it has a client-side kill switch. The vendor cannot be a black box anymore.
  • Boardroom Sign-Off: AI risk is no longer just an IT headache. High-risk algorithms need explicit approval from the Board’s Risk Management Committee before they see a single rupee of real-world data. The Board can’t say “we didn’t know.”

Who Needs to Act — and How Fast

Every single category of RBI-regulated entity must have this in scope - no exceptions, no minimum size threshold.

But the clock isn't ticking equally for everyone. If you are a large bank running AI in credit, fraud, and customer service at scale, your Board Risk Committee will be fielding questions about this within weeks. If you are a digital-first NBFC or fintech that built AI-heavy underwriting without formal model governance, you have the biggest gap to close and the least time to close it. If you are a payments bank with AI in KYC and onboarding, the customer disclosure and human handoff requirements hit your core product. And if you're a credit bureau, your models don't just affect one institution, they underpin decisions across the entire sector. Expect the RBI to start here.

The common thread: if AI touches a decision that affects a customer, a loan, or a risk score - it's in scope. And the Board is now personally accountable for it.

Three Questions Every BFSI Leader Should Be Asking Today

Before the final circular lands, every CTO, CRO, and CDO at a regulated entity should be asking three questions about every AI platform in production:

  • Can our vendor give us a kill switch we can show our regulator, one that works even if the model itself is compromised?
  • Can they produce model documentation and explainability evidence to the standard our Board Risk Committee will now require?
  • If something goes wrong tomorrow, do we have the audit trail to prove we had oversight, or are we relying on the vendor to produce it after the fact?

If the answer to all three is yes, that vendor is your compliance partner. If the answer to any one is no, FI’s are carrying a regulatory risk that lands on your Board.

The RBI has made one thing non-negotiable: the bank owns the outcome, regardless of who built the AI. Your vendor list is now your compliance checklist.

What Happens Next?

The RBI has opened the floor for public comments until July 24, 2026. The final circular is expected in Q3/Q4 2026. That gives institutions a narrow window — weeks, not quarters — to assess where they stand.

The institutions that move now will shape how AI governance works in Indian banking. The ones that wait for the final circular will be playing catch-up under a deadline.

The machines can do the heavy lifting. But the humans will always keep their hands on the plug.

Official RBI Press Release: Read here

< RECOMMENDED >