Home/ Compliance/ SEBI AI and ML Governance
Securities and Exchange Board of India

Evidence for accountable AI in Indian securities markets.

Govern client data, model and tool actions, human responsibility, retention, and audit reconstruction across advisory, trading, and market-infrastructure workflows.

Applies to: SEBI-regulated intermediaries, MIIs, funds, advisers, analysts, and supporting platforms Status: Binding responsibilities plus reporting circulars; 2025 AI guidance began as consultation Reviewed: 31 July 2026

Separate live obligations from proposed guidance

SEBI's AI/ML position is layered. Reporting circulars have applied to several securities-market populations since 2019. Regulation 16C strengthened the regulated entity's responsibility for client data, output, and legal compliance in 2025. SEBI's June 2025 responsible-AI paper was a consultation, so teams should verify whether later circulars have adopted specific proposals.

Reporting

Know where AI and ML are used

Applicable firms need a defensible inventory and reporting path across internally developed and third-party systems.

Responsibility

Outsourcing does not remove accountability

The regulated entity remains responsible for client-data safeguards, outputs, and compliance even when an external AI tool is used.

Market integrity

Control material automated action

Advisory, research, trading, surveillance, and investor-facing outputs require traceable policy and human responsibility.

From request to securities-system evidence

Review questionRuntime controlEvidence path
Was client data exposed?Detect configured personal and financial identifiers before model or connector access.Detection category, policy action, request context, and downstream access logs.
Who was responsible for the output?Attach user, system, tenant, model, and policy context to governed activity.Correlated record plus the firm's system inventory and accountable owner.
Was a material action reviewed?Pause configured advisory, trading, disclosure, or customer-impacting actions.Reviewer identity, decision, reason, timestamp, and execution outcome.
Can the event be reconstructed?Carry correlation context across policy, model, connector, and downstream systems.AxonFlow decision records joined to order, trade, communication, or case logs.
Is the evidence ready for review?Use licensed SEBI-oriented retention, readiness, dashboard, and export workflows.Scoped export plus gaps identified before internal audit or regulator engagement.

High-value workflows to assess first

Investment advice and research

Control client-specific context, disclosure, unsupported claims, and the human responsibility for recommendations or published research.

Trading and order actions

Require deterministic policy and approval outside the model before a tool can place, modify, or cancel an order.

Market surveillance support

Record how an AI-assisted alert was generated, triaged, escalated, and resolved without treating the model as final authority.

Investor communications

Protect personal data and preserve the model, policy, source context, and reviewer path behind material communications.

Third-party AI services

Enforce controls at the runtime boundary even when the regulated entity does not own the model or external tool.

Incident and stop procedures

Test the ability to stop affected workflows, preserve records, correct downstream effects, and demonstrate accountable recovery.

Product boundary

AxonFlow supports

  • Policy and PII controls around AI requests and actions
  • Human-review records and runtime traceability
  • SEBI-oriented retention, readiness, dashboard, and export workflows
  • Correlation with the firm's downstream books and records

The regulated entity still owns

  • Accuracy and suitability of advice, research, and outputs
  • Market-conduct controls and statutory books and records
  • Model validation, fairness testing, disclosures, and supervision
  • Interpretation of final rules and regulatory submissions

Test the control path against a real workflow.

Use the Evaluation license to assess policy enforcement, human review, evidence records, and deployment boundaries before a regulated rollout.