The integration of Artificial Intelligence (AI) and Machine Learning (ML) into financial services? It’s genuinely reshaping global securities markets at an unprecedented pace. I am deeply involved in Corporate & Commercial Law and Securities & Financial Regulations. I’ve been tracking these developments with keen interest. The Securities and Exchange Board of India (SEBI)’s latest consultation paper on AI/ML guidelines was released yesterday, June 20, 2025. It feels like such a pivotal moment. It firmly places India among the early jurisdictions to craft sector-specific AI governance for our securities markets. This isn’t only about drawing regulatory lines. It’s SEBI’s smart, proactive move. They aim to harness AI’s immense benefits while carefully managing its inherent risks. SEBI’s goal is to safeguard investors, develop and regulate securities market. And hence it is concerned for the securities market integrity.
Now, let’s really dig into SEBI’s proposed framework. Its emphasis on human oversight, in particular, reveals a fascinating dynamic when we compare it to other global models. International frameworks, like Singapore’s broader AI governance approach, might initially strike as more operationally prescriptive. However, I believe SEBI’s principles-based stance is far more sophisticated. It could be an adaptive regulatory strategy for the long haul.
SEBI’s Framework: What It Means in Practice
The consultation paper, which I just reviewed, lays out some very clear, practical requirements for market participants. Let’s break down the immediate impact:
Right Away: Governance Requirements
- Dedicated Internal Teams: Firms will need to establish dedicated internal teams. These persons must possess “adequate skills, expertise, and experience”, to actively monitor and oversee AI/ML depolyment. They must oversee performance, controls, testing, efficacy, and security throughout the algorithm’s entire lifecycle. Thus, internal teams need to have continuous vigilance and deep technical know-how.
- Senior Management in Charge: Crucially, designated senior management will be directly accountable for overseeing the entire AI/ML model lifecycle. They are equipped with the right technical knowledge and experience. This responsibility covers initial development and validation, testing, deployment, ongoing monitoring, and robust controls. This ensures that high-level strategic oversight isn’t just a concept, but a tangible responsibility.
- Keeping an Eye on Vendors: It’s not just about what happens in-house. Firms will also be required to monitor their third-party AI/ML vendors and periodically report model accuracy directly to SEBI. That’s a vital step for broader accountability.
Transparency and Disclosure Obligations
- To Customers, Clearly: Firms need to disclose if they use AI/ML in ways that directly impact customers. They absolutely must inform their clients. Examples include trading algorithms, asset management, portfolio management, or advisory services. Transparency, plain and simple, is key here.
- Communicating Risk Effectively: These disclosures aren’t just a tick-box exercise. They need to comprehensively cover risks, limitations, accuracy results, any associated fees, and even the quality of the data used. And the most important part: this information has to be presented in simple, client-friendly language. No jargon allowed!
- Serious Documentation: Firms are mandated to maintain detailed data logs and documentation for a minimum of five years. This is so important for ensuring both explainability and traceability of any AI-driven decisions.
Testing and Validation Protocols
- Separate Testing Environments: Before any AI/ML model goes live, it must undergo rigorous testing. This testing happens in environments completely separate from live systems. This minimizes disruption and risk big-time.
- Real Stress Tests: Models won’t just be tested under normal conditions. They must be validated under both stressed and unstressed market scenarios to truly prove their resilience.
- Continuous Monitoring: The validation doesn’t end once the model is deployed. Ongoing validation and monitoring of AI/ML model results will be a continuous, mandatory process. It’s about constant vigilance.
Data Governance and Security
- Robust Data Governance: Expect clear norms around data ownership, stringent access controls, and robust encryption requirements. It’s all about protecting the data that feeds these systems.
- No Bias, Please: A truly critical aspect is ensuring that AI/ML tools are designed and deployed carefully. This approach actively prevents favoring or discriminating against any customer group. Fairness isn’t just a buzzword; it’s paramount.
- Stronger Cybersecurity: The framework also calls for robust cybersecurity measures. This includes vigilant human oversight systems and sophisticated suspicious activity monitoring. Quick circuit breakers are needed for any AI-driven market volatility.
One thing I particularly appreciate is SEBI’s “regulatory lite” approach for AI/ML usage. This approach focuses on aspects that do not directly impact customers, such as internal research, analytics, or administrative functions. This offers some welcome operational flexibility for non-customer-facing applications, which is a smart move.
Singapore’s AI Governance Landscape: A Different Regulatory Tune
Now, let’s shift our gaze to Singapore. They’ve put together a comprehensive AI governance framework through their Personal Data Protection Commission (PDPC). This framework famously includes distinct levels of human intervention: Human-in-the-Loop (HITL), Human-on-the-Loop (HOTL), and Human-in-Command (HIC). It’s important to note that this framework originates from Singapore’s broader national AI governance documents. It is not specifically from the Monetary Authority of Singapore (MAS) for financial institutions. Still, it provides a really interesting contrast in regulatory philosophy.
Singapore’s HITL/HOTL/HIC Framework – A Quick Overview:
These three models offer crisp conceptual distinctions for how humans can be involved:
- Human-in-the-Loop (HITL): Here, humans hold the ultimate decision-making power. The AI provides analysis and recommendations, but it’s the human’s judgment that makes the final call. Think of it as AI as a very smart assistant, but you’re still the boss.
- Human-on-the-Loop (HOTL): In this scenario, AI operates autonomously, but with constant human monitoring. Humans can step in or override decisions if they spot anomalies or if the situation simply demands it. It’s about vigilance, not constant approval.
- Human-in-Command (HIC): This signifies that humans maintain ultimate authority and accountability. The AI operates seamlessly within predefined parameters. These mandates have already been set by humans. The AI is a highly trained specialist following strict rules.
How This Could Apply to Financial Services (Hypothetically):
While MAS hasn’t explicitly mandated this for specific financial products, this framework could theoretically translate very well into various financial services scenarios:
- Investment Advisory: For those really complex investment portfolios, a HITL approach might be ideal. In this approach, human advisors meticulously review AI recommendations. For more standard portfolios, an HOTL model could work nicely. AI offers advice. Humans keep a watchful eye for any unusual patterns.
- Algorithmic Trading: High-risk trading strategies could certainly warrant human approval mechanisms (HITL). Medium-risk trading might involve real-time human monitoring capabilities (HOTL), while lower-risk trading could comfortably operate within human-set parameters (HIC).
MAS’s Actual Regulatory Approach
MAS’s practical regulatory approach focuses more on leveraging AI for its own supervisory purposes. This conclusion is drawn from my research and available documents. It does this rather than imposing prescriptive operational requirements on financial institutions for their AI usage. MAS has notably deployed machine learning to optimize risk targeting for supervisory actions. They also use it to identify potential market manipulation. Furthermore, they enhance their enforcement capabilities through natural language processing. This, to me, is a crucial differentiator.
Practical Operational Differences: SEBI vs. MAS
Let’s quickly see how these differing philosophies might play out in the daily operations of firms:
- For Algorithmic Trading:
- SEBI: Requires senior management oversight, dedicated internal monitoring teams, customer disclosure if the algorithm affects clients, and segregated testing environments.
- MAS (focus): Emphasizes its own risk-based supervision, actively using AI tools for market surveillance and enforcement by the regulator itself. It’s about MAS’s internal tools.
- For Investment Advisory:
- SEBI: Calls for clear disclosures to customers, thorough documentation of advice algorithms, and periodic accuracy reporting to regulators.
- MAS (focus): Uses AI internally to identify high-risk advisory representatives for its own supervisory purposes.
- For Risk Management Systems:
- SEBI: Requires firms to have internal expertise teams, robust fallback procedures, and clear exception handling protocols.
- MAS (focus): Deploys AI internally for suspicious activity detection and proactive threat identification across the broader financial system.
Compliance Costs and Resource Implications
Implementing SEBI’s proposed framework, while strategically sound, will definitely have practical implications for market participants:
- Human Resources: There’s a clear need for dedicated AI/ML teams, and they’ll require specialized technical expertise. This isn’t just a minor reshuffle.
- Technology Infrastructure: Firms will need to invest in building segregated testing environments and robust continuous monitoring systems. That’s a significant IT undertaking.
- Documentation Overhead: The requirement for five-year data retention and ensuring explainability will undoubtedly lead to considerable documentation efforts. It’s all about maintaining a clear audit trail.
- Reporting Burden: Regular periodic accuracy reporting to SEBI and comprehensive customer disclosures will add to the overall compliance workload.
But let’s remember, SEBI’s “regulatory lite” approach for AI/ML usage that doesn’t directly impact customers provides welcome operational flexibility. Areas like internal research, analytics, and administrative functions are specifically covered. That’s a key benefit.
SEBI’s Principles-Based Advantage: A Strategic Masterstroke
Frameworks like Singapore’s PDPC model offer greater operational clarity. However, I remain convinced that SEBI’s principles-based approach demonstrates profound strategic sophistication. It’s not simply a less prescriptive regulatory stance. To me, it’s a deliberate design choice that intelligently fosters innovation. This choice maintains robust governance and accountability.
An Innovation-Friendly Regulatory Architecture:
SEBI sets clear governance guardrails. It wisely allows market participants the freedom to develop optimal operational implementations. These implementations are tailored to their specific use cases and risk profiles. This approach isn’t about stifling innovation; it’s designed to encourage it within safe boundaries. It permits diverse AI deployments across different market segments. Critically, it enables rapid adaptation to technological evolution. This effectively reduces that dreaded “regulatory lag.”
Driving Market-Driven Operational Excellence:
By focusing on robust governance oversight without dictating the minute operational specifics, SEBI actively encourages:
- The organic emergence of best practices through real-world market experimentation.
- Competition-driven improvement in human oversight models.
- Sector-specific optimization. What works perfectly for a large broker might be quite different for a mutual fund. It could also differ for an exchange. It’s about letting the market find its own efficient solutions.
A Learning and Adaptive Regulator:
SEBI’s strategic position allows it to be a truly learning regulator. It can:
- Observe firsthand how market implementations unfold through its governance oversight.
- Identify emerging best practices through careful supervisory observations.
- Refine its guidance based on invaluable real-world experience. This approach consciously avoids premature “regulatory lock-in” to specific technologies. Such technologies might quickly become outdated.
Echoes in International Regulatory Trends
SEBI’s principles-based stance isn’t an isolated incident; it perfectly aligns with a growing, sensible trend in international regulatory evolution:
- UK’s Outcomes-Based Regulation: The Financial Conduct Authority (FCA) in the UK, for example, emphasizes achieving desired outcomes. It does so rather than prescribing detailed rules. This empowers firms to determine the most effective implementation methods. Recent initiatives, like the FCA’s AI Live Testing, further highlight this adaptive approach.
- Canada’s Principles Approach: Canadian financial regulators have adopted high-level principles for AI in financial services. Notably, the Office of the Superintendent of Financial Institutions (OSFI) promotes their “EDGE” (Explainability, Data, Governance, Ethics) principles. They expect firms to develop appropriate operational controls, rather than dictating them.
- Australia’s Pragmatic Framework: Australia’s approach to AI in financial services focuses on overarching governance requirements. It generally allows operational flexibility. It often leverages existing regulations rather than inventing entirely new, highly specific ones.
The Strategic Benefits of SEBI’s Consultation Phase
The consultation phase is currently ongoing. Comments are due by July 11, 2025. This phase is incredibly important for SEBI to further hone its strategy. It’s a critical window.
Unlocking Market Intelligence:
This period is a goldmine for SEBI. It allows the regulator to:
- Observe emerging best practices from the myriad of market participants.
- Identify practical implementation challenges that might not be apparent in theoretical frameworks.
- Truly understand the nuanced, sector-specific needs across various market intermediaries.
- Evaluate how different human oversight models are working in real-world scenarios.
A Graduated Regulatory Response:
SEBI can smartly adopt an iterative regulatory approach:
- Start with clear governance principles.
- Closely monitor how the market implements them.
- Issue supplementary guidance as needed, based on concrete observations.
- And critically, develop sector-specific operational guidance only where a clear, demonstrated need arises.
A Global Leadership Opportunity:
SEBI’s thoughtful approach positions India as a leader in adaptive regulation that genuinely evolves with technology. It showcases innovation-friendly governance that prioritizes investor protection. This approach can powerfully influence emerging market regulatory approaches worldwide.
My Recommendations: Optimizing SEBI’s Approach During Consultation
To further strengthen what is already a robust framework, I believe SEBI could certainly consider a few key enhancements during this consultation period:
Boosting Governance Accountability:
While keeping operational flexibility intact, SEBI could reinforce:
- Requiring explicit board-level AI governance policies.
- Mandating regular, documented effectiveness reviews of human oversight models.
- Establishing clear, actionable escalation and exception handling protocols.
Creating Market Learning Mechanisms:
Fostering a culture of shared learning within the industry would be invaluable:
- Organizing industry roundtables for sharing practical implementation experiences.
- Conducting regular surveys to gauge human oversight effectiveness.
- Undertaking thematic reviews of different operational models to truly pinpoint what works best.
My Strategic Recommendation: A Smart Hybrid Approach
Ultimately, I truly believe SEBI could optimize its framework by adopting what I’d call a “smart hybrid approach.” This would mean holding firm to its principles-based core while thoughtfully providing:
- Illustrative examples of effective human oversight models (and I can’t stress this enough, these would be examples, not mandatory approaches).
- Practical risk assessment frameworks to help firms determine the appropriate oversight levels for their specific AI applications.
- Flexible implementation timelines that allow for the gradual sophistication of oversight models, rather than an abrupt shift.
- Dedicated industry consultation mechanisms for sharing and evolving emerging best practices, ensuring the rules keep pace with reality.
This kind of approach would beautifully preserve the encouragement for innovation. It would offer practical guidance without becoming overly prescriptive. It would enable market-driven optimization within well-defined governance boundaries. In my view, it would solidify SEBI’s position as a truly sophisticated and adaptive regulator on the global stage.
Conclusion: SEBI’s Strategic Sophistication in Action
SEBI’s June 2025 consultation paper on AI/ML guidelines, with its strong emphasis on a principles-based governance framework, truly stands out. I genuinely see it as strategically superior to overly prescriptive models. By establishing robust governance accountability while allowing operational flexibility, SEBI is effectively achieving multiple crucial goals:
- It’s fostering innovation within safe and responsible boundaries.
- It’s enabling market-driven optimization of human oversight models.
- And, it’s providing crucial regulatory “future-proofing” against the breakneck pace of technological change.
This approach, to me, reflects a deep regulatory maturity. It shows an understanding that effective AI governance isn’t about rigid, static rules. Instead, it’s about continuous evolution and adaptation. The ongoing consultation process presents a crucial opportunity. It allows for further refinement of this delicate balance. This process ensures both vigorous innovation and robust investor protection in India’s dynamic, AI-driven securities markets.
This analysis is based on SEBI’s consultation paper released on June 20, 2025. The comment period extends until July 11, 2025. As regulatory frameworks continue to evolve, market participants should always monitor official updates and seek professional guidance for compliance planning.
