AI in Financial Regulation: SEBI Chairman Tuhin Kanta Pandey Draws the Line at "Black Box" Adjudication

MUMBAI — As financial markets become increasingly reliant on artificial intelligence, regulatory authorities are grappling with a dual challenge: harnessing advanced technology to track sophisticated market manipulation while preventing algorithms from overstepping ethical and legal boundaries.

At the recently concluded Global Fintech Fest 2026, Securities and Exchange Board of India (SEBI) Chairman Tuhin Kanta Pandey addressed this delicate balance head-on. Delivering a firm stance on the limitations of automated enforcement, Pandey declared, “An AI-generated alert is not a finding,” drawing a definitive line between utilizing machine intelligence for risk identification and relinquishing regulatory decision-making power to automated systems.

Pandey’s remarks came during a high-profile panel discussion titled navigating technology-dependent financial markets. The session was moderated by Dilip Asbe, Managing Director and CEO of the National Payments Corporation of India (NPCI). It also featured prominent international regulatory voices, including Tajinder Singh, Deputy Secretary General of the International Organization of Securities Commissions (IOSCO), and Hanso van Wurssum, an executive board member of the Dutch Authority for the Financial Markets (AFM).


Main Facts

The panel discussion crystallized several core developments regarding the intersection of artificial intelligence and securities regulation:

  • No Automated Adjudication: SEBI has made it clear that while AI can flag potential regulatory breaches, enforcement, penalties, and formal findings cannot be delegated to automated "black box" systems.
  • Proactive SupTech Integration: Regulatory bodies are transitioning from periodic, on-site, and retroactive checks to near real-time, off-site, and predictive monitoring. SEBI is actively deploying AI to scan for cybersecurity compliance, social media infractions, and misleading financial advertisements.
  • The Rise of Agentic AI Concerns: Regulators are increasingly worried about autonomous or semi-autonomous AI agents capable of executing complex workflows, prompting calls for strict operational boundaries, hard-coded stop mechanisms, and immutable audit trails.
  • Systemic Concentration Risks: The reliance of multiple financial institutions on shared AI models and cloud infrastructure creates a novel concentration risk, turning localized technology failures into potential market-wide vulnerabilities.
  • Non-Transferable Accountability: Financial institutions and market participants can outsource technological functions to third-party vendors, but they can never outsource ultimate regulatory responsibility or compliance accountability.

Chronology of the Discussion and Regulatory Evolution

The evolution of technology in financial markets has forced regulatory agencies worldwide to rethink their supervisory toolkits. The dialogue at the Global Fintech Fest 2026 underscored how this transition has unfolded over recent years.

The Shift Toward Real-Time Surveillance

Historically, financial supervision relied heavily on periodic filings, retroactive audits, and manual sampling of market data. As trading volumes exploded and financial products grew more complex, these traditional methods faced severe blind spots.

Reflecting on this historical transition, IOSCO Deputy Secretary General Tajinder Singh recalled his tenure at SEBI when the market watchdog first introduced an integrated market-surveillance system. The immediate result was a massive surge in supervisory alerts.

"Clearly, there were things that we were not seeing that we started seeing, maybe too much of them," Singh noted, illustrating the initial shockwaves of implementing early-stage supervisory technology (SupTech).

The Modern Regulatory Toolkit (2024–2026)

Over the past couple of years, SEBI has moved aggressively to operationalize AI-driven oversight. Rather than waiting for quarterly reports or investor complaints, the regulator has integrated specialized technological applications:

  1. Cyber Security Audit Compliance Portal (CSAC): Used to continuously analyze cybersecurity controls across market participants, flagging non-compliance gaps so entities can rectify them swiftly.
  2. Sudarshan: An AI tool dedicated to sweeping social media networks to identify and track unregistered investment advisers.
  3. Radar: A surveillance utility designed to scan digital channels and social media platforms for potentially misleading advertisements and fraudulent financial content.

According to SEBI, the deployment of these systems has already yielded tangible enforcement metrics, resulting in more than 150,000 content takedowns across various social media platforms.

Despite these advanced capabilities, the regulatory philosophy remains anchored in human-centric oversight. The consensus among the panelists at the Global Fintech Fest 2026 was that while SupTech successfully bridges the gap in data processing, the ultimate legal and ethical accountability must remain firmly in human hands.


Supporting Data and Technical Metrics

The integration of artificial intelligence into financial markets introduces massive data processing advantages, but it also highlights systemic vulnerabilities. The data points discussed during the panel shed light on both the scale of modern surveillance and the structural risks of technological dependency.

Scale of Digital Infractions and Interventions

  • 150,000+ Takedowns: The cumulative number of fraudulent posts, misleading advertisements, and unauthorized financial advisory content removed from social media platforms through SEBI’s automated scanning tools, Sudarshan and Radar.
  • Near Real-Time Off-Site Supervision: SEBI’s current operational goal relies on processing massive datasets instantly, shifting the regulatory burden away from traditional, periodic, on-site inspections toward continuous, data-driven off-site monitoring.

Emerging Systemic Vulnerabilities

  • Concentration Risk in Cloud and AI Infrastructure: Financial institutions increasingly rely on a handful of major cloud service providers and common foundational AI models. This reliance creates a dangerous "single point of failure." If a shared vendor experiences an outage or a systemic algorithmic error, the disruption is no longer confined to a single institution; it cascades into a market-wide systemic crisis.
  • The "Black Box" Challenge: Machine learning models often operate via non-transparent logic paths. Without robust explainability and continuous validation controls, relying on these models for decision-making introduces legal and operational hazards.

Official Responses and Perspectives

The high-level panel at the Global Fintech Fest 2026 provided deep insights into how domestic and international regulatory bodies view the promises and perils of artificial intelligence.

SEBI Chairman Tuhin Kanta Pandey on Human Oversight and Overtrust

Pandey emphasized that simply having a human present in an automated workflow is insufficient to guarantee safety.

"Humans can also overtrust machines," Pandey warned. “Oversight must be competent, empowered and accountable.”

He detailed that effective governance models must envelop the entire lifecycle of an AI deployment. This includes mandatory framework checks for model explainability, data quality assurance, bias controls, continuous testing, model drift monitoring, and robust cybersecurity. Furthermore, Pandey stated that every production-grade AI system deployed in finance must feature "a stop mechanism, auditable usage, and change logs."

Addressing the frontier of machine intelligence, Pandey highlighted the specific challenges posed by agentic AI—systems capable of operating autonomously or semi-autonomously to complete complex multi-step tasks.

"Agentic AI also needs hard boundaries on what it may do," Pandey said, urging regulators to explicitly define parameters regarding access, autonomy, permissible actions, and reversibility.

IOSCO’s Tajinder Singh on the Power of SupTech

Representing the global regulatory landscape, Tajinder Singh of IOSCO championed the adoption of SupTech as an indispensable tool for modern regulators. He noted that advanced analytics and AI enable regulatory bodies to process enormous volumes of unstructured data, identify hidden patterns, and detect market anomalies that would completely bypass traditional sampling methods.

Singh explained that SupTech allows international regulators to transition "from sampling to broader data analysis" and move "from more retroactive supervision to more forward-looking, targeted, risk-based supervision." Furthermore, shared technological frameworks allow global regulators to pool their experiences rather than forcing every individual jurisdiction to build expensive surveillance infrastructure from scratch.

AFM’s Hanso van Wurssum on Immutable Governance and Vendor Responsibility

Echoing the sentiments of his fellow panelists, Hanso van Wurssum of the Dutch Authority for the Financial Markets stressed that firms deploying agentic AI must maintain absolute transparency regarding their deployment strategies.

"You need to make sure that you can see what’s been done, when, where and how," Van Wurssum stated, advocating for immutable record-keeping and robust audit trails.

While clarifying that European and global regulators are not imposing an outright ban on agentic AI in financial markets, Van Wurssum made it clear that regulatory authorities will hold firms strictly accountable for any adverse outcomes generated by their autonomous systems.


Implications for Financial Markets and Technological Compliance

The definitive positions laid out at the Global Fintech Fest 2026 signal a major shift in how financial institutions must approach technology integration, vendor management, and internal governance.

1. The End of Outsourcing Regulatory Responsibility

One of the most critical takeaways from Pandey’s address was the reaffirmation of non-transferable regulatory responsibility. While financial institutions routinely partner with third-party software vendors, cloud providers, and AI developers to streamline operations, Pandey made it clear that technology may be outsourced, but regulatory responsibility cannot.

Financial institutions cannot hide behind third-party vendors or pass the blame for compliance failures, poor data resilience, or compromised market integrity onto tech companies. Regulatory scrutiny will increasingly follow a "risk-based and proportionate" approach, where the intensity of audits depends heavily on a provider’s proximity to core trading engines, settlement systems, sensitive investor data, and critical market infrastructure.

When a single cloud or AI provider services multiple financial institutions, an entity-level failure instantly transforms into a systemic market threat. Consequently, regulators are demanding rigorous vendor audits, continuous monitoring, and bulletproof disaster recovery arrangements.

2. Redefining the Role of the Financial Regulator

To effectively supervise an AI-driven marketplace, regulatory bodies themselves must undergo a profound cultural and structural transformation. Pandey noted that supervisory agencies cannot police algorithms effectively unless they possess internal expertise capable of challenging machine outputs.

“Supervisors must have people who can understand, challenge and override AI outputs,” Pandey asserted.

As markets march further into the digital age, the regulatory playbook is evolving. The boundary between human judgment and machine assistance is now clearly drawn: AI will serve as an advanced radar to scan the horizon for risks, but the steering wheel—and the ultimate legal responsibility—will remain firmly in human hands.

Back To Top