Rohit Jain, Deputy Governor of the Reserve Bank of India (RBI), warned that the growing dependence of financial institutions on a limited number of common technology providers, cloud services, and artificial intelligence models could create a new source of systemic risk.
He noted that a failure in one such provider could potentially spread to numerous financial organizations. Jain voiced this concern during the Global Fintech Festival 2026.
According to Jain, financial institutions are increasingly relying on a small number of cloud solution providers, technology vendors, and AI model developers, often using similar infrastructures and overlapping datasets. He emphasized that the issue is not merely the bankruptcy of one organization, but the possibility that shared dependency could transmit a failure or error to multiple institutions simultaneously.
Jain highlighted three key risks associated with the deepening of technology in finance: 'speed, concentration, and opacity.' He added that while these risks are not entirely new, technology can amplify them, allowing consequences to spread through the financial system faster, wider, and sometimes more difficult to detect.
Regarding speed, he explained that automated systems operate significantly faster than human reaction time, requiring financial institutions to build resilience that goes beyond preventing isolated errors. Institutions must be able to quickly identify problems, localize their impact, and intervene before a minor oversight escalates into a major issue.
Furthermore, Jain stated that the increasing complexity of AI models should not weaken accountability in financial decision-making. He stressed that higher complexity does not equate to reduced responsibility, as advanced models can find connections and make decisions in ways that are hard to explain.
He also pointed out that while an institution can outsource computation, it cannot outsource responsibility for the consequences. Jain reminded that fundamental risks of the financial sector remain unchanged despite technological progress: borrowers may default, liquidity may vanish, leverage may increase losses, and operational failures continue to disrupt the provision of financial services.
The RBI Deputy Governor noted that technology does not eliminate these risks but substantially alters their scale, speed, and transmission mechanism. He also pointed to regulatory challenges created by rapidly evolving technologies, as authorities risk either acting too early or too late.
Jain cautioned that overly premature regulation could lead to creating detailed rules for technologies that are not yet fully understood, or for architectures that will change before the rules come into effect. Conversely, regulation that is too late might occur after the technology has been deeply integrated, and its risks have not yet been fully studied and mitigated.
He proposed that policy should focus on outcomes and accountability rather than prescribing every technological choice. For instance, the obligation to ensure fair treatment of customers does not change, even if the decision is influenced by an algorithm. Similarly, the responsibility for risk management does not disappear if the model or technology is provided by a third party.
Regulatory expectations must also align with the consequences of using a specific technology. Jain gave an example: a tool for summarizing an internal document should not be treated the same as a system that autonomously approves loans or executes financial transactions. The higher the consequences of using the technology, the stricter the requirements for governance, auditing, supervision, and intervention.
The central bank also identified quantum computing as a future risk to the financial system, particularly due to its impact on existing cryptographic systems. He called for proactive preparation, following the principle: one should not wait until a future vulnerability becomes a current crisis before reacting.
Jain reported that the RBI's supervisory capabilities must also evolve alongside the technologies used by financial institutions. He mentioned DAKSH and PRAVAAH as examples of technologies enhancing supervisory and regulatory processes, as well as the Digital Payments Intelligence Platform (DPIP), which recognizes that payment fraud is increasingly transcending individual institutions and requires network-level intelligence and near real-time information sharing.
In conclusion, Jain stated that the goal of policy should be to enable beneficial innovation while controlling risks. Good policy should allow innovation room to grow, ensuring that accountability and resilience grow alongside it. Ultimately, technologies should be judged by the outcomes they deliver to financial consumers, not by their complexity.



