“An AI-generated alert is not a finding,” SEBI Chairman Tuhin Kanta Pandey said, drawing a line between using AI to identify potential risks and allowing machines to make regulatory decisions. Pandey was speaking during a panel discussion at the Global Fintech Fest 2026, moderated by Dilip Asbe, MD and CEO of NPCI. The panel also featured Tajinder Singh, Deputy Secretary General of the International Organization of Securities Commissions (IOSCO), and Hanso van Wurssum, executive board member of the Dutch Authority for the Financial Markets.
The discussion focused on how regulators can use AI while managing the risks created by increasingly technology-dependent financial markets. Pandey said SEBI was already using AI for cybersecurity compliance, social media monitoring and surveillance, but warned that regulatory decisions must remain subject to human oversight.
SEBI is using AI to make supervision more predictive: Pandey said SEBI is moving supervision from periodic checks to proactive monitoring. “AI can process large data sets, detect patterns, direct supervisory attention to emerging risks,” he said. This could make supervision “more off-site than on-site, and near real-time, rather than periodic”.
He pointed to SEBI’s Cyber Security Audit Compliance Portal, or CSAC, which analyses cybersecurity controls under SEBI’s framework across market participants and flags gaps and non-compliance. “It can move very much faster; it can indicate gaps, and it can pose them to the regulated entities. They can plug it,” he said.
Similarly, Pandey said SEBI uses Sudarshan to monitor social media for unregistered advisers and Radar to scan for potentially misleading advertisements and social media content. He said there had been more than 150,000 takedowns from social media platforms following the use of these systems.
However, Pandey stressed that an AI-generated alert cannot itself establish a violation. “An AI-generated alert is not a finding,” he said. “Enforcement and adjudication cannot be delegated to the black box.”
‘Humans can also overtrust machines’: Pandey said simply keeping a person in the decision-making process would not be enough. “Humans can also overtrust machines,” he said. “Oversight must be competent, empowered and accountable.”
He said safeguards must cover the AI model as well as its deployment, including “human oversight, explainability, validation, continuous testing, data quality, bias controls, model drift monitoring and cybersecurity”. Every production AI system, he added, needs “a stop mechanism, auditable usage, change logs”.
The requirements become stricter with agentic AI, which can autonomously or near-autonomously perform complicated tasks. Pandey said regulators must define “access, autonomy, permissible actions, and reversibility”. “Agentic AI also needs hard boundaries on what it may do,” he said.
Van Wurssum similarly said firms using agentic AI needed clear governance around who was deploying it, why and how. “You need to make sure that you can see what’s been done, when, where and how,” he said, calling for immutable record-keeping. He added that there was no ban on agentic AI in financial markets, but said regulators would continue to hold firms responsible for its use.
AI could create its own concentration risk: While AI can improve supervision, Pandey also warned that the technology could create risks across financial markets. “AI can create its own concentration risk,” he said, pointing to “common models, cloud infrastructure of providers” that could become “shared points of failure”.
This concern also shaped Pandey’s approach to technology providers serving regulated financial institutions. “Technology may be outsourced but regulatory responsibility cannot,” he said. A financial institution, he added, “cannot transfer responsibility for compliance, resilience or market integrity to a technology provider, or a vendor”.
He said oversight should be “risk-based and proportionate”, with scrutiny increasing according to a provider’s proximity to trading, settlement, sensitive data and investor outcomes. “Criticality matters more than labels,” Pandey said. Cloud, AI and hosted service providers could become part of critical market infrastructure, with concentration, substitutability and the impact of failure determining the level of concern.
Pandey said a provider serving several institutions could turn an individual failure into a wider problem. “When one provider serves several institutions, an entity-level failure can become a market-wide risk,” he said. He called for vendor audits, continuous monitoring, recovery arrangements and concentration-risk assessments. “Critical technological dependencies must not become regulatory blind spots,” he said.
Regulators are using SupTech to keep pace with financial markets: IOSCO’s Tajinder Singh said supervisory technology, or SupTech, could help regulators identify risks earlier, use resources more efficiently and strengthen cooperation between regulators. “AI, advanced analytics can process enormous volumes of data, identify patterns, and detect anomalies that traditional supervision may miss,” he said.
Singh recalled his time at SEBI, when the introduction of an integrated market-surveillance system caused the number of alerts received by supervisors to rise sharply. “Clearly, there were things that we were not seeing that we started seeing, maybe too much of them,” he added.
He said SupTech could help regulators move “from sampling to broader data analysis” and “from more retroactive supervision to more forward-looking, targeted, risk-based supervision”. It could also help regulators share experience rather than requiring every jurisdiction to develop its own systems independently.
Pandey also stressed that regulators themselves needed sufficient expertise to challenge the systems they deploy. “Supervisors must have people who can understand, challenge and override AI outputs,” he said.
Also read:

