# AI security and governance built for banks.

> AI governance for banks, in ColossalX, means knowing which models, agents and third-party AI touch customer data, keeping account and card numbers out of prompts and answers, refusing the next AI request after a customer withdraws consent, and handing examiners evidence graded by how it was obtained.

Keep customer data out of prompts, check consent at each AI request, and hand examiners evidence graded by how it was obtained, with the dates in view.

Canonical page: https://colossalx.tech/solutions/banking · Last reviewed: 6 Oct 2026

*Illustration:* Customer data · at the gateway: copilot to ColossalX (prompt); kyc-agent refused before ColossalX (consent withdrawn); payments-bot held for a person before ColossalX (held for approval); ColossalX with data redacted, to provider A (card data redacted).

## Why banks are looking hard at AI now.

Indian financial firms pay the most for a breach, are attacked more often, and are still building AI controls.

- INR 40.9 crore: average cost of a breach in Indian financial services (INR 409 million), the highest of any sector in India (IBM Cost of a Data Breach India 2026, 3 Aug 2026, https://in.newsroom.ibm.com/India-Records-its-Highest-Average-Cost-of-a-Data-Breach-2026)
- 1.6 times: the global average: the rate at which Indian banking, financial services and insurance are attacked (DSCI-BCG, 28 May 2026, https://www.dsci.in/files/content/press-release/2026/cyber-threats-escalate-across-indian-financial-institutions-as-ai-reshapes-the-cybersecurity-landscape.pdf)
- Over half: of successful cyberattacks on AI agents through 2029 are expected to exploit access control weaknesses and prompt injection (Gartner, 26 Aug 2026, https://www.gartner.com/en/newsroom/press-releases/2026-08-26-gartner-forecasts-the-market-for-securing-ai-will-reach-almost-5-billion-in-2027)

DSCI and BCG found that AI-specific controls such as formal AI governance, agent monitoring and runtime guardrails are "still being built across the sector" (DSCI-BCG, Indian BFSI cyber threat study, 28 May 2026, https://www.dsci.in/files/content/press-release/2026/cyber-threats-escalate-across-indian-financial-institutions-as-ai-reshapes-the-cybersecurity-landscape.pdf)

## Where AI meets customer data, and what holds it.

Four places, each held by a control.

- **The threat:** A copilot pastes account and card numbers into a prompt to a model. **The control:** Guardrails redact personal data both ways, with India banking and payments presets. [Runtime guardrails](https://colossalx.tech/platform/runtime-guardrails)
- **The threat:** A customer withdraws consent, and an agent keeps sending their data. **The control:** The next AI request carrying that data is refused, and the refusal logged. [Runtime consent](https://colossalx.tech/platform/runtime-consent)
- **The threat:** Model risk teams cannot list the models, agents and third-party AI in use. **The control:** One inventory of models, agents and AI vendors, each with an owner. [AI inventory and agent map](https://colossalx.tech/platform/ai-inventory)
- **The threat:** An examiner asks for evidence that AI controls ran, and gets a spreadsheet. **The control:** Evidence collects itself, graded A to D by how it was obtained. [Compliance and AI governance](https://colossalx.tech/platform/compliance)

## What regulators ask for, and how ColossalX relates.

Mapped frameworks, context, and the dates that matter.

| Instrument | What it asks for | How ColossalX relates |
| --- | --- | --- |
| India DPDP | Consent and purpose limits for personal data, with consent managers. | Mapped to |
| PCI DSS | Cardholder data protected wherever it travels, prompts and answers included. | Mapped to |
| ISO/IEC 42001 | An AI management system: policy, roles, risk and controls. | Mapped to |
| NIST AI RMF | Govern, map, measure and manage AI risk across its life. | Mapped to |
| EU AI Act | For banks serving the EU: duties scaled to risk, from transparency up. | Mapped to |
| RBI FREE-AI | Board-approved AI policy, governance and assurance, as recommendations. | Context only |
| CERT-In AI blueprint | AI asset inventories, shadow AI monitoring and emergency shutdown. | Context only |

### Regulatory clock

- 13 Nov 2026: India DPDP consent manager rules start (PIB, DPDP Rules 2025, https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)
- 13 May 2027: India DPDP core obligations start (PIB, DPDP Rules 2025, https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf)

## What you see, and what you can show an examiner.

Lineage from real gateway traffic, beside the evidence pack an examiner can take away and check.

- Which agent sent which kinds of personal data to which model, from gateway traffic.
- Each redaction, refusal and approval hold, with the policy that made it.
- Evidence graded A to D by how it was obtained, verified by a second person.
- A sealed, timestamped audit archive, with findings carried into the risk register.

*Illustration:* An illustrative data lineage map for a bank, drawn from gateway traffic: client KYC records and a card ledger read by named agents, through the gateway to two models. The PAN is withheld at the gateway, the name is sent on, and the cross-border flow is marked.

*Illustration:* Evidence pack · an outline: Inventory Models, agents and vendors, owned; Runtime Refusals, redactions, approval holds; Consent The log of real refusals; Audit A sealed, timestamped archive. Graded A to D.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## What ColossalX does not do

- Runtime consent covers the inference-context purpose for signed-in users, and fails open on error.
- RBI and CERT-In publications are context. ColossalX does not map its controls to them.
- ColossalX holds no certification and is delivered as SaaS only.
- Redaction finds the identifiers its presets and your own patterns describe, not ones nobody defined.

*Illustration:* Consent · at the request: 10:02:14 Consent withdrawn (signed-in customer, inference context); 10:02:15 Next request refused (kyc-agent, carrying that data); 10:02:15 Refusal logged as evidence.

## Questions

### What do banking regulators expect for AI governance?

Expectations are converging on board-approved AI policy, an inventory of the models in use including third-party AI, testing and monitoring, and clear accountability. ColossalX maps to India DPDP, PCI DSS, ISO/IEC 42001, NIST AI RMF and the EU AI Act; RBI and CERT-In guidance is explained as context.

### How do banks manage AI model risk?

They start with an inventory of the models, agents and third-party AI in use, then test them, monitor them and record who decided what. ColossalX keeps that inventory, attacks your own AI with authorisation and turns findings into owned work and graded evidence.

### How does India's DPDP Act affect AI in banking?

India's Digital Personal Data Protection Act, 2023 makes consent and purpose central. When a customer withdraws consent, AI systems using their data have to stop. ColossalX refuses the next AI request carrying that person's data, for the inference-context purpose of signed-in users, with a log of real refusals.

### Which frameworks does ColossalX map for banks?

India DPDP, PCI DSS, NIST AI RMF, ISO/IEC 42001, the EU AI Act, SOC 2 and GDPR, alongside SEBI and IRDAI cyber circulars for capital markets and insurance. Frameworks are mapped to or assessed against, never certified; ColossalX holds no certification of its own.

### How is customer data kept out of prompts and answers?

Guardrails at the AI gateway detect personal data in prompts and answers and redact it, using presets for India banking and payments, PCI DSS, India DPDP and others, plus your own identifiers. Data lineage then shows which agent sent which kinds of personal data to which model.

## Sources

- Reserve Bank of India, FREE-AI committee report (press release), 13 Aug 2025: https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=61018
- CERT-In AI security blueprint, as reported by MediaNama, 25 May 2026: https://www.medianama.com/2026/05/223-cert-in-releases-blueprint-for-defending-against-ai-assisted-cyber-threats/

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
