From principles to kill switches: finance AI rulebooks
How are financial regulators turning high-level AI principles into enforceable controls?
Financial regulators started with principles and sandboxes, but by 2026 India, Singapore and the US were writing concrete expectations on inventories, model validation, vendor accountability and kill switches. India shows the full arc from a principles report to draft model-risk rules and promised SEBI controls.
- Rule · In forceINRBI FREE-AI Framework
FREE-AI's 7 sutras and 26 recommendations set India's baseline for AI in finance.
- RBI publishes FREE-AI framework for AI in India's financial sector
The RBI publishes the framework and starts the shift from principles to supervision.
- MAS consults on AI risk management guidelines for all financial institutions
Singapore proposes inventories, risk materiality ratings and lifecycle controls, including for AI agents.
- US Treasury releases AI lexicon and finance-specific AI risk framework
The US opts for a voluntary finance-specific version of the NIST AI RMF instead of binding rules.
- FCA names Barclays, UBS, Experian and others in second AI Live Testing cohort
The UK tests AI, including agentic payments, live with firms before setting expectations.
- RBI drafts model risk rules covering AI/ML for all regulated lenders
The RBI drafts model-risk rules covering third-party and AI/ML models.
- Rule · In forceINSEBI Reg 16C (AI responsibility)
SEBI already makes intermediaries liable for the AI tools they use.
- SEBI chief says AI/ML rules will mandate kill switches and human oversight
SEBI signals mandatory kill switches and human oversight for AI in markets.
Where this line could go next
Connected developments not on this line
- DevelopmentVisa expands Agentic Ready agent-payment testing to Asia Pacific and Latin America29 Apr 2026 · Launch · INTL
- DevelopmentHKMA picks 27 use cases from 20 banks for second GenAI sandbox cohort15 Oct 2025 · Programme · HK
- DevelopmentSenate Democrats ask Treasury and FSOC to probe AI-sector debt risks22 Jan 2026 · Statement · US
- DevelopmentBessent and Powell summon bank CEOs over Anthropic Mythos cyber risk7 Apr 2026 · Statement · US, GB
- DevelopmentGoogle launches AP2, an open protocol for payments made by AI agents16 Sep 2025 · Launch · INTL
- DevelopmentUS CAISI signs national-security testing deals with Google DeepMind, Microsoft, xAI5 May 2026 · Programme · US