## Report on SEBI's Approach to AI Regulation in the Indian Securities Market
**1. Executive Summary:**
This report analyzes a keynote address by a representative of the Securities and Exchange Board of India (SEBI) concerning the integration of Artificial Intelligence (AI) and Large Language Models (LLMs) into the Indian securities market. The address, presented as a forward-looking policy statement, outlines SEBI's current stance and planned approach to regulating AI, emphasizing a balanced approach between fostering innovation and mitigating risks, particularly the need to avoid both Type I (failure to prevent wrongdoing) and Type II (stifling innovation) errors. Key findings include the importance of principle-based rules, robust data governance, auditability, explainability, and cyber resilience. The address highlights SEBI's internal AI experimentation, the use of innovation sandboxes, and the need for collaboration with industry and international bodies. The core purpose is to ensure that AI contributes to inclusive growth, efficient markets, and investor protection in the securities market.
**2. Introduction:**
This report aims to provide stakeholders in the Indian securities market with a comprehensive overview of SEBI's evolving regulatory approach to Artificial Intelligence (AI) and Large Language Models (LLMs), as articulated in the provided keynote address. The report is based solely on the information contained within the text of the address.
**3. Policy Overview:**
* This is presented as a forward-looking policy statement and plan, not as an amendment to a specific pre-existing policy.
* **Core Objective(s):**
* To ensure that AI adoption in the securities market strengthens sustained capital formation and protects investors.
* To strike a balance between preventing market misconduct (Type I errors) and fostering legitimate innovation (avoiding Type II errors).
* To establish clear accountability for AI deployments in the financial sector.
* To promote fair, transparent, and data-protected AI practices within the Indian securities market.
**4. Background and Rationale:**
* **New Policy:** The keynote address acknowledges the rapid proliferation of AI in finance, including algorithmic trading, robo-advisors, and smart KYC. This technological advancement presents both opportunities (lower costs, hyper-personalized products, faster inclusion) and risks (misselling, data breaches, flash crash-like dislocations). The rationale for SEBI's proactive approach is to proactively manage these risks and capitalize on the potential benefits of AI while upholding investor protection and market integrity. The address suggests that without regulatory guidance, AI could exacerbate existing market inefficiencies or introduce new vulnerabilities, necessitating a carefully calibrated regulatory framework.
**5. Key Provisions / Changes:**
As this document is presented as a policy statement and plan, rather than an enacted policy, the following are the implied provisions and required actions:
* **Principle-Based Rules with Accountability:** SEBI intends to implement principle-based regulations, focusing on outcomes such as fairness, transparency, and data protection. Accountability will be pinned on the entity that deploys and profits from AI tools.
* **Data Governance:** AI operations must comply with India's Digital Personal Data Protection Act, incorporating consent, purpose limitation, and the right to be forgotten as design requirements.
* **Auditability and Explainability:** Intermediaries using AI systems must maintain model logs capturing inputs, parameters, and decisions to allow for reconstruction of algorithmic chains in case of bias allegations or market disruptions. Emphasis is placed on striving towards explainable AI systems.
* **Cyber Resilience and Systemic Stability:** The cybersecurity framework requires real-time monitoring, segregation of training and production environments, and immutable audit trails to address vulnerabilities like adversarial data poisoning and supply-chain attacks.
* **Innovation Sandboxes:** SEBI will continue to use its Innovation Sandbox to allow startups, brokers, and academic labs to trial AI-enabled products on anonymized or synthetic market data, providing a controlled environment for experimentation.
* **Industry Collaboration:** SEBI suggests the formation of an AI Risk Consortium to address regulatory aspects like shared taxonomies for incidents, stress scenarios, and open-source testing libraries.
* **Capacity Building:** SEBI is recruiting staff with IT skills and upskilling existing staff to ensure regulators can effectively supervise AI models.
* **International Alignment:** SEBI actively engages with international organizations to harmonize disclosure templates and incident-reporting protocols for AI risk.
* **Expectations from Market Participants:**
* *Know Your Algorithm:* Rigorous pre-deployment testing, documentation, and disclosure to investors are required.
* *Explain It to Investors:* AI-driven decisions should be explained to investors in plain language.
* *Respect User Autonomy:* Users should be able to override AI system decisions.
* *Monitor in Real Time:* Continuous validation of AI models is necessary.
* *Report Material Incidents Promptly:* Malfunctions or data leaks must be reported immediately.
* *Engage with Regulators:* Market participants should actively engage with SEBI to help strike the right balance between preventing market misconduct and fostering innovation.
**6. Target Audience and Stakeholders:**
The primary target audience and stakeholders directly affected by this policy direction include:
* **Securities Market Intermediaries:** Brokers, clearing corporations, depositories, and other intermediaries deploying AI in trading, advisory, or customer interfaces.
* **Fintech Companies:** Startups and established technology firms developing and offering AI-powered solutions for the securities market.
* **Investors:** Both retail and institutional investors whose interactions with the market may be influenced by AI-driven systems.
* **Legal Professionals:** Lawyers advising market participants on compliance with AI-related regulations.
* **Academic Institutions:** Researchers and experts in AI and finance who can contribute to the development of regulatory frameworks and best practices.
**7. Implementation Aspects (Inferred):**
* **Responsible Agency/Bodies:** The Securities and Exchange Board of India (SEBI) is the primary agency responsible for implementing and enforcing the AI regulatory framework. Collaboration with exchanges, clearing corporations, fintech associations, academic experts, and international organizations is also emphasized.
* **Timelines/Procedures:** The text does not provide specific timelines for implementing the various provisions. However, the reference to a consultation paper on AI guardrails suggests that SEBI intends to solicit feedback from stakeholders before finalizing the regulatory framework. The 2019 AIML Reporting Framework and the February 2025 Accountability Amendments suggest ongoing evolution and refinement of the regulatory approach.
**8. Expected Outcomes / Impact of Changes:**
The likely intended outcomes of SEBI's approach to AI regulation are:
* **Enhanced Investor Protection:** By mandating transparency, accountability, and robust data governance, SEBI aims to protect investors from potential risks associated with AI-driven misconduct.
* **Promoted Market Integrity:** The focus on auditability, explainability, and cyber resilience should help maintain the integrity and stability of the Indian securities market.
* **Fostered Responsible Innovation:** The innovation sandbox and collaborative approach are intended to encourage the development and deployment of beneficial AI applications while mitigating potential risks.
* **Improved Regulatory Oversight:** Capacity building and international alignment should enhance SEBI's ability to effectively supervise AI models and address cross-border risks.
* **Increased Market Confidence:** By proactively addressing the challenges and opportunities presented by AI, SEBI aims to foster trust and confidence in the Indian securities market.
**9. Conclusion:**
SEBI's articulated approach to regulating AI in the Indian securities market represents a proactive and balanced effort to harness the potential benefits of AI while mitigating its inherent risks. The emphasis on principle-based rules, accountability, data governance, and collaboration signals a commitment to fostering responsible innovation and ensuring investor protection. The address highlights the significance of continuous monitoring, real-time reporting, and ongoing engagement with stakeholders to adapt to the evolving landscape of AI in finance. By creating a robust and transparent regulatory framework, SEBI seeks to promote a safe and efficient securities market that benefits all participants.
Key Entities Referenced
Sh. Ananth Narayan: WTM (Whole Time Member), SEBI (Securities and Exchange Board of India), speaker at ET Legal World dialogue.
SEBI: Securities and Exchange Board of India, a regulatory authority.
ET Legal World: The conference where the keynote address was delivered.
2025 12th June 2025: Date of the keynote address.
Bill Gates: Cited for his observation on technology and automation.
Type I error: Defined as the failure to detect or prevent wrongdoing.
Type II error: Defined as erecting guardrails so cumbersome that legitimate innovation is stifled.
Artificial Intelligence: Technology being discussed in the context of reshaping regulatory authority roles.
Large Language Models: Specific type of AI being discussed.
RegTech: Mentioned in the context of SEBI's PreAI Tech Journey.
SupTech: Mentioned in the context of SEBI's PreAI Tech Journey.
SEBI Intermediary Portal: SEBI's portal that has moved registration and correspondences online
SCORES: SEBI's revamped platform that converts complaints into data workflows.
SEBI’s Case Management System: SEBI’s system that digitally captures the journey of any case from the start of an investigation until the issuance of an order.
SEBI’s 2019 AIML Reporting Framework: SEBI's framework that requires intermediaries deploying AI to report model purpose, data sources, and risk controls.
February 2025 Accountability Amendments: Amendments that hardwire accountability into regulations for AI deployment.
DRHPs: Bulky documents that SEBI is leveraging large language models to process.
PPMs: Bulky documents that SEBI is leveraging large language models to process.
SAARTHI 2.0: SEBI investor-education app with an AI-enabled chatbot.
India's Digital Personal Data Protection Act: Umbrella act under which all financial-sector AI must operate.
SEBI's Innovation Sandbox: Sandbox that allows startups, brokers, and academic labs to trial AI enabled products.
Regulatory sandbox: Environment under which AI enabled products can be tested in a live but contained environment.
AIRisk Consortium: Proposed consortium of exchanges, clearing corporations, fintech associations, and academic experts to deal with regulatory aspects of AI.
IOSCO: International organization that SEBI actively engages with to harmonise disclosure templates and incidentreporting protocols.
FSB: Financial Stability Board, organisation that SEBI actively engages with to harmonise disclosure templates and incidentreporting protocols.
Global Financial Innovation Network: Network that SEBI actively engages with to harmonise disclosure templates and incidentreporting protocols.
AI guardrails for the Indian securities market: Consultation paper based on IOSCO recommendations for AI use by intermediaries.
Speaking notes of the keynote address of Sh. Ananth Narayan, WTM, SEBI, on How
Technology is Reshaping the Role of Regulatory Authorities, at ET Legal World
dialogue, 2025 – 12th June 2025
Good evening, to the many distinguished luminaries and participants in the ET Legal
World conference. I thank the organizers of this timely and topical conference for the
opportunity to be here amongst you.
Bill Gates once observed, “The first rule of any technology used in business is that
automation applied to an efficient operation will magnify the efficiency. The second is
that automation applied to an inefficient operation will magnify the inefficiency”.
Those words resonate deeply with every regulator. Our mandate is clear: as artificial
intelligence sweeps across finance and law, we must collectively ensure that the
magnification effect strengthens the delivery of our mandate of sustained capital
formation, and does not detract from it.
In general, at the Securities and Exchange Board of India, we speak of two kinds of
errors. A Type I error is the failure to detect or prevent wrongdoing: an insider-trading
nexus we miss, a mis-selling scandal or cyber breach that hollows out investor faith. A
Type II error is the opposite: in our zeal to prevent mischief we erect guard-rails so
cumbersome, that legitimate innovation never lifts off. One error destroys confidence;
the other smothers progress.
Striking the balance between them is too important to be left to regulators alone. It
demands co-creation of regulations and the active participation of the lawyers,
technologists, entrepreneurs and other stakeholders in this hall, as trusted advisors.
Today I will outline how technology—particularly Artificial Intelligence and Large
Language Models—is reshaping the way regulatory authorities perform their role, the
compliance expectations we set, and the guard-rails we must collectively build. I will
draw on SEBI’s own journey, discuss the opportunities, lay out some of the risks, and
describe the principles guiding our next steps.SEBI’s Pre-AI Tech Journey
Let me start with SEBI’s Pre-AI Tech Journey, where our initiatives have laid the
foundation for AI adoption in our Reg-Tech and Sup-Tech.
On Market surveillance: SEBI has invested in integrated market surveillance systems,
data warehouses, business intelligence tools, data lakes and high-speed analytics to
detect anomalous trading patterns. Algorithms—continuously refined and evolved by
SEBI and exchange officers—ingest billions of order and trade messages daily,
analyse them and throw up aberration alerts. With terabytes of data now at our
disposal, the next stop is to harness AI/ML to detect patterns and alerts that help
maintain trust in the ecosystem.
On Compliance and reporting: The SEBI Intermediary Portal has moved registration
and correspondences online. By replacing mountains of paper with structured data,
we slashed processing times and created a searchable record—an essential precursor
for effective AI.
On investor grievance redressal: Timely analysis of complaints can serve as an early
warning to systemic issues in the ecosystem. Our revamped SCORES platform
converts complaints into data workflows. SCORES has prepared us for the next wave
of predictive analytics—identifying systemic issues before they erupt.
Automated inspections: Working with exchanges, clearing corporations, and
depositories, we have automated large portions of routine inspections with significant
investments into Sup-tech. This Sup-tech database also lends itself to analytics by
AI/ML.
Investigations: The journey of any case from the start of an investigation until the
issuance of an order is digitally captured in SEBI’s Case Management System,
creating a repository of violators, violations, and regulatory actions taken. This
repository is now ready for deeper analysis.Taken together, all these foundational initiatives have established the digital plumbing
for AI to work through.
Riding the AI Wave: Opportunities and Challenges
Algorithmic trading, robo-advice, and smart KYC are now mainstream realities. AI
promises lower costs, hyper-personalised products, and faster inclusion. Yet the same
algorithms can accelerate mis-selling, data breaches, and flash-crash-like
dislocations. SEBI’s approach has therefore been calibrated and incremental,
weighing both Type I and Type II errors.
SEBI’s 2019 AI/ML Reporting Framework: It requires that every intermediary deploying
AI in trading, advisory, or customer interfaces must report the model’s purpose, data
sources, and risk controls. Sunlight is indeed the best disinfectant.
With the February 2025 Accountability Amendments: We have now hard-wired
accountability into multiple regulations: if you deploy an AI tool, you remain wholly
responsible for its data privacy, outputs, and compliance with all applicable laws,
regardless of vendors or open-source code.
Within SEBI, internal experimentation is underway: We are leveraging large-language
models deployed on-premises to process bulky documents such as DRHPs and
PPMs. Early results suggest a significant reduction in manual effort, yet every output
still passes through human review, reinforcing the principle that machines assist, not
replace, judgment.
Our own SEBI investor-education app: SAARTHI 2.0. now carries an AI-enabled
chatbot that answers queries and explains investment concepts to retail investors.
Regulatory and Compliance Implications of AI Adoption
First, we aim for principle-based rules, anchored by clear accountability. Technology
evolves too quickly for line-by-line prescriptions. Instead, we will set outcomes -
fairness, transparency, data-protection and pin responsibility on the entity that deploysand profits from the tool. This will hopefully keep the rulebook future-proof and yet
enforceable.
Second, we need robust data governance. India’s Digital Personal Data Protection Act
is the umbrella under which all financial-sector AI must operate. Consent, purpose
limitation, and the right to be forgotten are not optional extras. They are design
requirements that need to be baked in from day zero.
Third, we must have auditability and explainability. Black-box models cannot be a
black hole for accountability. Intermediaries using AI systems must maintain “model
logs” that capture inputs, parameters, and decisions. If an investor alleges bias or a
flash crash triggers an investigation, we must be able to reconstruct the algorithmic
chain of events—step by step. We should strive to move towards explainable AI
systems57.
Finally, we need cyber-resilience and systemic stability. AI systems feed on data; they
are also vulnerable to adversarial data poisoning and supply-chain attacks59. Our
cyber-security framework now compels real-time monitoring, segregation of training
and production environments, and immutable audit trails60.
The Way Forward: Innovation Sandboxes and Collaborative Oversight
calibrated experimentation
SEBI’s Innovation Sandbox: It allows start-ups, brokers, and academic labs to trial AI-
enabled products on anonymised or synthetic market data. These products can then
be tested in a live but contained environment under the Regulatory sandbox. By
observing these trials, regulators learn alongside innovators, reducing the friction
between rules and progress.
Industry collaboration: Given the rapid pace of AI development, there is perhaps a
case for a AI-Risk Consortium of exchanges, clearing corporations, fintech
associations, and academic experts could deal with regulatory aspects like shared
taxonomies for incidents, stress scenarios, and open-source testing libraries.Capacity building: Rules without expertise are like radars without screens. SEBI has
therefore been recruiting more staff with IT skills while also upskilling existing staff
through online courses and expert sessions. Regulators must speak the same
mathematical language as the models they supervise.
International alignment: AI risk travels at fibre-optic speed across borders. We actively
engage with IOSCO, the FSB, and the Global Financial Innovation Network to
harmonise disclosure templates and incident-reporting protocols. Divergent rules only
create regulatory arbitrage and weaken everyone. We are currently working on a
consultation paper on AI guardrails for the Indian securities market based on IOSCO
recommendations for AI use by intermediaries.
What We Expect from Market Participants
Know Your Algorithm. Perform rigorous pre-deployment testing—bias audits,
adversarial pen-tests, scenario analysis. Document it, sign it, own it.
Disclose it to investors. If using AI in any investor-facing application, inform the
investors.
Explain It to Investors. If a robo-advisor rebalances a portfolio, disclose the inputs in
plain language, such as: “We use your age, income, and market volatility”. Clarity is
not merely ethical; it is now regulatory.
Respect user autonomy. AI systems should be designed so users can override their
decisions.
Monitor in Real Time. Models drift; markets mutate. Continuous validation is not a
“best practice”—it is a survival necessity.
Report Material Incidents Promptly. If an AI-driven trading strategy malfunctions or a
data leak occurs, the clock for regulatory notification starts immediately. Early
transparency often turns a crisis into a solvable problem.And finally, engage with regulators. We acknowledge the risk that an excessive focus
on Type I errors can open us up to Type II errors. Please engage with us, as trusted
advisors, to get the balance right. Even as you point out the Type II errors and seek
relaxations, you must explain and think through how Type I errors can be avoided or
kept to an acceptable level. If we lose credibility and mutual trust, the capital markets
ecosystem will suffer immensely—we must not kill the goose that lays the golden eggs.
Reflections Beyond Finance: The Legal Sector’s Parallel Journey
While my focus has been capital markets, the same forces are reshaping legal
practice. Contract-review bots, predictive sentencing tools, and generative drafting
assistants all raise similar questions: Who audits the model? Who owns the
hallucination? Which confidentiality norms apply when your brief is processed by an
external interface?
Jurisdictions worldwide are gravitating toward three universal principles:
First – human-in-the-loop accountability: No final legal opinion or regulatory order may
be issued without a qualified professional’s sign-off. Some prefer “Machine in the loop”
to emphasize that humans are and will always be in charge and accountable, while
machines assist or refine human decisions.
Second – Data provenance: Training a model on client-privileged material without
explicit consent is a breach, period.
Third – Audit trails: Every prompt, output, and subsequent edit must be logged for
potential discovery.
SEBI’s own legal affairs department is experimenting under these foundational
principles.Conclusion: A Call to Collective Stewardship
Technological change is indifferent to the ambitions of regulators or the anxieties of
incumbents; it advances because someone, or now something, somewhere, writes the
next line of code. Our responsibility is to ensure that the line of code contributes to
inclusive growth, efficient markets, and protected investors.
Let me return to Bill Gates: automation magnifies the underlying state of a system—
good or bad. SEBI’s mission, and that of every forward-looking regulatory authority, is
to ensure the underlying state is good—anchored in robust governance, transparent
markets, ethical data practices, and a relentless focus on investor welfare.
For that, I emphasise, we need partnership. Traditionally, regulators provide the guard-
rails, industry provides the engine, academia provides the map, and investors provide
the destination. However, if we move together and co-create—openly, responsibly,
and innovatively—AI will not be a net disruptor of trust but a multiplier of it.
***