Reserve Bank Governor Sanjay Malhotra warned on 3 October that artificial intelligence is compounding cyber risk in a financial system without national borders, using a Kautilya Economic Conclave address in New Delhi to outline how Indian regulators are tightening technology governance for banks and non-bank lenders.

Malhotra listed five pressure points on stability, with AI-driven cyber threats ranked alongside geopolitical shocks, private credit growth and tokenisation experiments. His emphasis was practical: autonomous models and third-party dependencies can erode human oversight just as attackers use generative tools to craft convincing fraud.

What regulators already issued in 2026

The governor pointed to directions issued this year for commercial banks that require board-level oversight of technology risk, defined chief information security officer responsibilities, and clearer controls on access management, vendor arrangements and incident response. For non-banking financial companies, a draft model-risk management framework proposes life-cycle safeguards such as explainability tests, red-teaming and mandatory human sign-off on high-impact decisions.

Indian lenders have rushed to deploy chatbots, credit scoring models and voice analytics in call centres. Malhotra’s message was that speed without guardrails exports vulnerability across the payment network. A breach at a midsize NBFC processing loan files can become a systemic incident if its APIs connect to multiple banks’ current accounts.

Why NBFCs are in the spotlight

Shadow banks originate a growing share of consumer and small-business credit, often using cloud-hosted underwriting stacks. Unlike large public sector banks, many NBFCs lack mature security operations centres. The RBI’s draft model-risk guidance would force them to document training data, monitor drift and keep audit trails if AI declines a loan or flags a wallet for fraud.

Fintech founders argue that rules must avoid box-ticking that freezes innovation. Regulators counter that India’s UPI volume and account aggregator frameworks already make the country a high-value target. Malhotra linked cyber resilience to monetary policy credibility: if payment rails fail during a rate announcement week, the shock transmits instantly to household confidence.

Next steps for compliance teams

Bank technology committees are expected to map AI vendors this quarter, classify models by materiality and rehearse breach notifications with the RBI’s reporting templates. NBFCs should watch for the final model-risk circular, which will likely align with global Basel committee language on third-party risk.

For customers, the speech is a reminder that AI-powered scams will keep pace with AI-powered defences. Malhotra did not announce new penalties, but his tone signalled that supervisors will treat weak cyber governance as a safety issue, not an IT inconvenience.