Agentic AI could change the most expensive part of financial crime compliance in Indian BFSI: not catching the alert but working it. Indian banks already flag fraud reasonably well. What compliance and fraud teams still struggle with is what happens after the flag, pulling records across core banking, payments, and KYC systems, checking a name against known typologies, and writing a suspicious transaction report that will hold up to scrutiny.
Bank fraud reported to the RBI touched a three-year high in value in FY26, and India’s cyber fraud losses ran into tens of thousands of crores in 2025 alone. The RBI is already using AI at the detection layer through its own MuleHunter. AI initiative. Agentic AI is the next layer under discussion globally, aimed specifically at the investigation stage. This piece lays out what agentic AI actually is, what India’s regulator has already said about it, and what a BFSI compliance or fraud leader here should weigh before going near it.
Key Takeaways
- Detection was never the real bottleneck. Investigation is, and it still eats analyst hours case by case.
- Bank fraud reported to the RBI hit ₹48,021 crore in FY26, up sharply from ₹32,803 crore in FY25.
- Indians lost roughly ₹22,495 crore to cyber fraud in 2025 alone, per I4C data.
- The RBI already runs an in-house AI tool, MuleHunter.AI, to detect mule accounts, now live at 23 banks.
- Agentic AI goes a step further: it plans, pulls data, and works a case end to end, not just flags it.
- The RBI’s FREE-AI framework and its 2026 draft Model Risk Management guidance both apply here, and board-level AI oversight is still rare.
The Bottleneck Was Never Detection

Ask most compliance heads in Indian BFSI what’s broken in their financial crime program, and detection rarely tops the list. The systems flag plenty. The problem is what happens to everything they flag.
The scale alone makes the case. Banks and financial institutions in India reported frauds worth ₹48,021 crore in FY26, up 46.4 percent from ₹32,803 crore in FY25, and more than four times the ₹11,013 crore reported in FY24, according to the RBI’s latest annual report. Source: Deccan Chronicle. Loans and advances, not card or digital payment fraud, now account for the bulk of that value.
Separately, on the retail and cyber side, Indians lost at least ₹22,495 crore to cyber fraud in 2025, across 28.15 lakh reported cases, with investment scams alone accounting for 76 percent of the money lost, according to I4C data. The National Crime Records Bureau has separately noted that online financial frauds make up roughly two-thirds of all cybercrime complaints in India.
Money mule networks sit at the centre of a lot of this. I4C reportedly identifies close to 4,000 new mule accounts a day, accounts opened by ordinary people, knowingly or not, that criminals use to move stolen money before it disappears into another account and another jurisdiction. Every one of those accounts, once flagged, still needs a human to trace the fund flow, check related parties, and decide whether it is genuinely part of a laundering chain or a false alarm. That manual work, repeated across a growing queue, is where the real cost sits, not in the initial flag.
What Agentic AI Actually Is, and What It Isn’t

Most Indian BFSI institutions already run some form of AI in their fraud and compliance stack: rule engines, machine learning risk scores, and increasingly, generative AI copilots that draft text or summarise a case when an analyst asks. Agentic AI is a different architecture, not a better version of the same one.
A generative AI copilot answers a prompt. An agentic system is given a goal, breaks it into steps, decides which tools or data sources it needs, pulls from them, and works through the task with limited human input at each step. Industry analysis in 2026 has framed the shift plainly: earlier AI systems mostly generated insights and left a human to decide what to do next, while agentic systems increasingly execute the task itself inside defined boundaries, with a human still deciding the outcome.
Applied to financial crime investigation, that distinction matters practically. Instead of an analyst manually opening five systems to build a case file on a flagged account, an agent can be designed to assemble that evidence package itself, pull transaction history, check related accounts, match the pattern against known typologies, and hand the investigator a structured case instead of a bare alert and a name.
What India Has Already Done at the Detection Layer

India is not starting from zero here, though what exists so far sits at detection, not investigation.
The RBI’s own innovation arm, the Reserve Bank Innovation Hub, built MuleHunter. AI, an AI and machine learning model trained on 19 distinct patterns of mule account behaviour, designed specifically to replace the static, rule-based checks banks were using to catch mule accounts. It was piloted with two public sector banks starting in late 2024. By late 2025, an RTI response showed the tool had been implemented across 23 banks. The RBI has also asked banks more broadly to collaborate with RBIH to extend the initiative.
In May 2026, RBIH signed an MoU with I4C under the Ministry of Home Affairs to share fraud-risk datasets and further train MuleHunter. AI and related models, tying the banking regulator’s fraud detection work directly to the government’s cybercrime response infrastructure.
That’s a real, working example of AI replacing a slow, rule-based process in Indian BFSI. It is still, by design, a detection tool. It flags an account. Someone still has to investigate it.
Globally, a small number of institutions have already moved a layer further into agentic systems that work the investigation itself. FIS announced a Financial Crimes AI Agent in partnership with Anthropic in May 2026, aimed at compressing AML case investigations from days to minutes by automatically assembling evidence, with general availability planned for later in 2026. It’s a useful reference point for where this is headed, though no comparable agentic investigation deployment has been publicly confirmed at an Indian bank yet.
What Agentic AI Could Change in the Investigation Workflow

If detection in Indian BFSI is starting to move to AI, as MuleHunter does. AI shows, the more interesting question is what an agentic layer could do at the investigation stage that follows.
Automated evidence assembly
Instead of an analyst manually pulling records across core banking, payments, KYC, and case management systems for every flagged mule account or suspicious transaction, an agent gathers and organises that evidence the moment a case opens.
Typology matching
Rather than an analyst mentally checking a flagged pattern against known laundering or fraud typologies, an agent can run that comparison systematically and flag which typology the pattern most resembles, with its reasoning attached for the investigator to check.
STR narrative drafting
Writing a suspicious transaction report that will hold up when it reaches FIU-IND takes real skill and real time. Agentic systems are increasingly being used elsewhere to draft that narrative for an investigator to review and finalise, rather than starting from a blank page each time.
Cross-bank and cross-network correlation
Mule account networks, by design, spread transactions across multiple banks and payment rails specifically to avoid detection inside any single institution’s silo. An agentic architecture built to correlate signals across a wider fusion layer, rather than one bank’s own data, is a more realistic match for how these networks actually move money.
What agentic AI is not being positioned to do, anywhere credible, is make the final call. Every serious design keeps a human as the decision-maker on the case outcome. The agent’s job is to make sure that when the investigator does look at a case, they’re looking at a complete, organised one instead of a raw alert with a name attached.
Where the RBI Stands on This

For a BFSI compliance or risk leader in India, the regulatory backdrop is not abstract or borrowed from elsewhere. The RBI has already moved on AI governance directly.
In August 2025, the RBI released its Framework for Responsible and Ethical Enablement of Artificial Intelligence, built around seven guiding principles, called Sutras, and 26 recommendations across six pillars covering infrastructure, policy, capacity, governance, protection, and assurance.
The committee’s own survey of banks, NBFCs, and fintechs found that only around a fifth of institutions were actively deploying AI systems at the time, mostly for customer support, sales, credit underwriting, and cybersecurity, even though two-thirds expressed interest in exploring further use cases. More tellingly for anyone planning an agentic pilot, only about a third of respondents, mostly large banks, reported having any board-level oversight structure for AI at all.
That framework has since been followed by a more operational layer. A draft Model Risk Management guidance released in 2026, open for public consultation with comments due by late July, adds the detailed control requirements: board-approved AI frameworks, model inventories, risk-based classification of models, independent validation, and explicit vendor accountability for every AI and decision-making model a regulated entity runs, including ones bought from a third party rather than built in-house.
The direction is clear. The RBI is not opposed to AI in financial crime work; it is actively building tools like MuleHunter. AI itself. What it is insisting on is that institutions be able to explain, audit, and take responsibility for whatever they deploy.
The Risks a Serious BFSI Leader Should Not Skip Past

None of the above is a reason to slow-walk this into irrelevance, but it is a reason to be deliberate. A few things keep surfacing as non-negotiable in serious deployments elsewhere, and they map directly onto what the RBI’s own framework is asking for.
Human-in-the-loop, designed correctly
The checkpoint where a human reviews and signs off has to sit where it actually catches errors, not just where it’s easiest to bolt on. A poorly placed approval step can slow down genuinely time-sensitive cases without improving accuracy.
Traceability and action logging
Every step an agent takes while assembling a case, every data source it queried, every typology it checked, needs to be logged and explainable afterward. This lines up directly with the model inventory and audit expectations in the RBI’s draft Model Risk Management guidance.
Vendor accountability
Most institutions will not build agentic systems from scratch; they will buy or license them. Under the RBI’s draft guidance, outsourcing the technology does not outsource the liability. The institution stays accountable for what the agent does, regardless of who built it.
Frequently Asked Questions
1. Is agentic AI the same as generative AI in banking compliance?
No. Generative AI typically responds to a single prompt, such as summarising a case or drafting a paragraph. Agentic AI is given a broader goal, plans out the steps needed to achieve it, and pulls from multiple tools or data sources with limited human input at each step, completing more of the task end to end.
2. Has any Indian bank actually deployed AI for financial crime detection or investigation?
Yes, at the detection stage. The RBI’s MuleHunter. AI, built by the Reserve Bank Innovation Hub, is live across 23 banks as of an RTI response in late 2025 and is used to detect mule accounts. Agentic AI specifically for the investigation stage has not yet been publicly confirmed at an Indian bank.
3. Will agentic AI replace human investigators in AML and fraud teams?
No credible deployment or regulatory framework being discussed in 2026 positions it that way. Every serious implementation keeps a human as the final decision-maker on a case outcome. The agent’s role is to compress the evidence-gathering and pattern-matching work that currently consumes most of an investigator’s time.
4. What does the RBI expect from Indian banks and NBFCs experimenting with agentic AI?
The RBI’s FREE-AI framework, released in August 2025, sets seven guiding principles and 26 recommendations across governance, infrastructure, and assurance. A follow-up draft of Model Risk Management guidance in 2026 goes further, requiring board-approved AI frameworks, model inventories, independent validation, and vendor accountability for every AI model in use, including ones bought from a third party.
5. How big is the mule account problem in India right now?
I4C reportedly identifies close to 4,000 new mule accounts daily. These accounts are the backbone of how stolen money moves through India’s banking system before it disappears, which is why the RBI built a dedicated AI tool specifically to catch them.



