Written by Devanshi Gupta, a fourth-year B.B.A. LL.B. (Hons.) student at Symbiosis Law School, Pune.
Over the past decade, the problem of concentration risk posed by dominant Artificial Intelligence (AI) service providers has been deliberated by multiple authorities, with little recourse. In 2024, the Governor of the Reserve Bank of India (RBI) raised concerns pertaining to the same issue. This was followed by a 2025 SEBI Consultation Paper on Responsible AI which partially addressed over-reliance as a systemic risk, but never materialized into a concrete legislation. Most recently on 05 May 2026, the SEBI released an Advisory on AI Tools for Vulnerability Detection, but only laid down ‘critical assessment of third-party providers’ as a risk reduction mechanism in this regard.
While deliberations continue, multiple reports reveal the immediate risks posed by these dominant vendors. The Financial Stability Board’s Report on AI revealed how data outages, malfunctions, supply-chain crises and inaccurate processing by even one dominant provider may cause an impact that extends across multiple players. The World Bank 2025 Digital Trends Report further reveals how the AI ecosystem is characterised by concentration at multiple levels. NVIDIA is estimated to control between 70–95% of the AI accelerator market, Microsoft Azure and Google Cloud for around 63% of the cloud infrastructure market, with Bloomberg and LSEG functioning as the primary data providers. These firms not only supply the computational backbone for frontier AI models but also host many of the services which financial institutions increasingly depend upon. Consequent to excessive reliance on an interconnected ecosystem, failures or disruptions at any layer may create systemic operational risks that existing outsourcing frameworks are not designed to address.
This analysis argues that, despite a reformist appearance, the latest advisory and existing regime remain inadequate to address the contemporary issues caused by dominant GenAI vendors. The blog proceeds in two parts. The first half highlights the gaps in the current, fragmented framework and identifies global best practices. Pursuant to the comparative analysis, the second half proposes recommendations tailored to the Indian socio-economic environment.
- REGULATORY BLIND SPOTS
- Absence of a Critical Third-Party Oversight Framework
While multiple Indian bodies have recognized concentrated reliance on major providers like Microsoft and Google as a threat, no tailored regulation has been introduced to identify and regulate them. It is pertinent to note that the while SEBI 2025 Consultation Paper proposed the designation of ‘critical service providers’ for enhanced monitoring as a control measure, the recent May 2026 Advisory has not inculcated such reforms, relegating the entire burden of risk-management on market participants. This is also in divergence with international practices.
Recognising that systemic vulnerabilities may emanate from a handful of dominant technology providers, The European Union (EU) Digital Operational Resilience Act (DORA) laid down an ‘Oversight Framework’ for designated Critical ICT Third-Party Providers (CTPPs). Article 31 of the same authority lays down an extensive set of requirements for qualification. This enables direct supervision of critical ICT vendors, supplementing the outsourcing obligations imposed on financial entities. Pursuant to the same, in November 2025, the ESA published a list of designated CTPPs. Similarly, the UK Critical Third Parties to the Financial Sector Regulations 2024 follows a similar approach. It identifies CTPPs and further segregates them into systemic and non-systemic third-party providers in order to lay down mandatory, additional obligations for the former. This enables a tailored approach to regulate vendors on the basis of the services provided, preventing unnecessary compliance requirements.
Importantly, the 2025 SEBI Consultation Paper also proposed diversification of providers and continuous monitoring as a control measure. However, no legislation has been adopted towards the same.
- Inadequate due diligence and disclosure requirements
Regulation 18D of the Securities Contracts (Regulation) 2025 lays down the obligation to preserve privacy and data security. It further holds the user liable for all outputs. While the regulation marks a step in the right direction, it only applies to stock exchanges and clearing corporations, thereby failing to account for brokers, advisors and other intermediaries. Additionally, no enforcement mechanism has been provided for the same. Furthermore, SEBI’s 2012 Algorithmic Trading Circular prescribes minimum risk control requirements only for pre-programmed algorithms and not self-learning GenAI systems. A similar problem exists within the SEBI (Investment Advisers) Regulations, 2013 which establishes disclosure requirements for robo-advisor platforms, but does not specifically account for AI-enabled services. While the SEBI’s 2016 Consultation Paper on Robo-Advisory Services proposed remedies like advising ‘disclosure of risks’, no such regulation has been promulgated. The 2025 Consultation paper proposed detailed disclosure requirements, however, they have not been adopted by the latest authorities.
The 2025 SEBI Consultation Paper further acknowledged additional risks and proposed measures such as the designation of critical service providers, diversification of AI vendors, and consistent oversight, which are yet to translate into binding legislation. Consequently, the May 2026 Advisory leaves several safeguards, including mandatory exit strategies, mechanisms to prevent and monitor herding behaviour, regulation of foundation models, oversight of subcontracting arrangements, AI-specific supply chain risk assessments, contingency planning for both normal and stressed scenarios, disclosure obligations to clients and regulators, and comprehensive record-keeping and reporting requirements.
Additionally, while the latest advisory calls for stress-testing, the procedure, timelines and documentation for the tests, as laid down in the 2025 Consultation Paper, have not been promulgated. This is exacerbated by the absence of mandates for exit strategies in ordinary and stressed scenarios. This is in contrast with the 2026 International Organization of Securities Commissions (IOSCO) AI Supervisory Toolkit which recommends detailed contingency planning and capability development.
This is also in divergence with global best practices. The EU DORA Framework mandates comprehensive due diligence before permitting ICT service providers, requires ongoing monitoring, contractual safeguards, exit strategies, supply-chain oversight, incident reporting and record-keeping, and establishes direct oversight of designated CTPPs. Similarly, the United Kingdom’s Financial Services and Markets Act 2023 impose enhanced resilience obligations on providers whose services are considered systemically significant. The frameworks represent a shift from a user-centric regulation to towards direct regulation of CTPPs, which remains absent in India’s governance framework.
- Absence of enforcement and liability determination mechanisms
The above-mentioned domestic legislations, advisories and consultation papers do not provide for enforcement mechanisms. The authorities do not clarify SEBI’s investigation powers or the procedure for enforcement. They further fail to prescribe or recommend any penalties or deterrence mechanisms for ensuring compliance. Furthermore, the domestic framework does not account for offshore/cross-border vulnerabilities This is, again, in divergence with foreign legislations.
It is pertinent to note that while Regulation 18-D holds market participants liable for all outputs, the explainability of the algorithms have not been addressed. The Explainability Paradox refers to the inability of AI systems to produce human intelligible explanations for its outputs, thereby making it a concrete transparency principle. In the absence of further clarification, the determination of liability and its extent remain prone to inaccuracy. This is in contrast with EU AI risk-based explainability regime that requires outcome and process transparency with a mandate for full transparency only in high-stakes decisions.
While the necessary recognitions have been made, they must be complimented by binding legislations to prevent the materialization of AI-provider concentration as systemic risk. The following section proposes recommendations based on global aspirational practices.
III. RECOMMENDATIONS
A. Establish a risk-based oversight framework for ‘critical AI service providers’ – SEBI should establish a statutory framework for the identification and supervision of critical AI service providers whose defaults and malfunctions could materially impair the functioning of Indian capital markets. Similar to the EU’s DORA and the United Kingdom’s Critical Third Parties framework, the qualifications for labelling providers as ‘critical’ may be based on objective criteria including, but not limited to, market concentration and types of services provided.
B. Mandate AI-specific due diligence, governance and disclosure obligations – Consistent with IOSCO’s recommendations, entities must conduct supply chain and cybersecurity assessments, document exit-strategies and adopt diversification and implementation strategies for concentration risk management. SEBI should also adopt the detailed guidelines pertaining to disclosure and stress-testing, as laid down in the 2025 Consultation Paper. The IOSCO’s recommendations to promulgate annual reports and provide client-facing documents can also be introduced to ensure transparency.
C. Establish Dedicated Supervisory and Enforcement Powers – The effectiveness of any AI governance framework depends upon credible enforcement. SEBI should therefore be empowered to inspect AI governance practices, require information from designated critical providers, conduct reviews, allow remedial measures and impose proportionate penalties for non-compliance.
CONCLUSION
While the SEBI 2026 Monthly Bulletin listed both the 2026 Advisory and the IOSCO Report recommending concentration risk management controls, the latter’s proposals have not adopted within the domestic regime. As reliance on a handful of AI providers deepens, SEBI must transition from entity-based compliance to a risk-based framework that directly supervises critical service providers, strengthens due diligence obligations, and ensures effective enforcement. Bridging this regulatory gap is essential to ensuring that technological innovation strengthens, rather than undermines, financial stability.


Leave a Reply