Introduction

The National Payments Corporation of India (“NPCI”) launched Agentic Orchestration & Messaging (“AtOM”), an open-source platform designed to manage the full lifecycle of a specification change across India’s payments ecosystem. AtOM takes a change from an initial idea through research, design documents and schemas, out to partner banks and payment service providers over an Agent-to-Agent (“A2A”) protocol, into generated code against a live repository, and finally through certification, with an AI agent handling each stage and an evaluation gate between them.

AtOM is a significant step in a broader trend: the movement of agentic AI from customer-facing use cases into the operational core of financial infrastructure, including code generation, partner negotiation and certification. For banks, payment service providers and fintechs that will engage with platforms of this kind, whether as adopters or as ecosystem partners, this raises a set of governance and accountability questions that are worth considering alongside the operational benefits.

Agentic AI in Financial Services Now Sits Within a Defined Regulatory Frame

The Reserve Bank of India’s Framework for Responsible and Ethical Enablement of Artificial Intelligence (“FREE-AI”), released in August 2025, sets out seven guiding principles and twenty-six recommendations across six pillars, including governance, protection and assurance, applicable to banks, non-banking financial companies, payment system operators and fintech entities under RBI’s regulatory ambit. Among its recommendations is a graded liability and supervisory approach for AI, together with a call for AI-related governance, audit and incident-reporting mechanisms. A draft Model Risk Management guidance released in 2026 builds on this, contemplating board-approved AI governance frameworks, model inventories, independent validation and vendor accountability for AI and machine-learning models used by regulated entities.

A platform such as AtOM, which generates code, negotiates specification changes and drives certification through AI agents, sits squarely within the kind of use case this regulatory direction is designed to address. Regulated entities engaging with such platforms, whether as the entity deploying the agents or as a partner responding to them, would benefit from mapping that engagement against their existing AI governance frameworks, rather than treating it as a purely technical integration.

Accountability for AI-Generated Code in Critical Infrastructure

AtOM’s code-generation function operates against a real repository, with a human opening the merge request before code advances. This human checkpoint is a meaningful control, but it also means that the ultimate legal responsibility for code that affects live payment infrastructure continues to rest with the entity that merges and deploys it, not with the AI agent that generated it. Institutions engaging with agent-generated code would benefit from ensuring that existing software change-management, testing and sign-off requirements are applied to that code with the same rigour as code written directly by developers, and that the underlying review and evaluation gates are themselves auditable.

Cross-Organisational Data Flows Over the A2A Protocol

AtOM’s partner-distribution function operates over the A2A protocol, involving a negotiation loop and implementation-status tracking across registered partner organisations, secured through multiple independent layers at the A2A boundary, including Transport Layer Security (TLS), JSON Web Tokens (JWT), Hash-Based Message Authentication Code (HMAC) envelopes, mutual TLS (mTLS), Internet Protocol (IP) allow-lists, rate limiting, audit trails and key-lifecycle management.

Where these exchanges involve personal data, whether relating to employees, customers or other individuals, the applicable requirements under the Digital Personal Data Protection Act, 2023 would continue to apply in the ordinary course, including in relation to purpose limitation and security safeguards. Institutions participating in such A2A exchanges would benefit from confirming, as part of onboarding, exactly what categories of data move across the protocol and on what basis.

Open-Source Distribution and Vendor Governance

AtOM, along with NPCI’s related platforms, has been released as open source. This may support adoption and transparency, since a signed, machine-readable audit trail is itself intended to support compliance and audit requirements. It also means that institutions deploying or extending the platform are effectively stepping into a vendor-governance role of their own, in respect of any forks, extensions or integrations they build. The FREE-AI framework’s emphasis on vendor accountability, and its expectation that regulated entities will flow down relevant obligations through their contractual arrangements with technology providers, applies with equal force where the technology provider is an open-source project rather than a conventional commercial vendor.

AMLEGALS Remarks

As agentic AI platforms such as AtOM move from specification design into code generation and cross-organisational negotiation within India’s payments infrastructure, banks, payment service providers and fintechs would be well advised to assess such platforms against their existing AI governance frameworks under the FREE-AI recommendations and the draft Model Risk Management guidance, rather than treating them as routine technical tooling. This includes confirming that human sign-off, testing and audit requirements apply to agent-generated code with the same rigour as manually written code, and that data flows over protocols such as A2A are mapped against applicable requirements under the DPDP Act.

Given the open-source nature of these platforms, institutions that deploy, fork or extend them would also benefit from treating that role as a vendor-governance responsibility in its own right, with appropriate internal ownership, documentation and periodic review, particularly as RBI’s AI-specific regulatory expectations continue to develop through 2026 and beyond.

For any queries or feedback, feel free to connect with Hiteashi.desai@amlegals.com or Khilansha.mukhija@amlegals.com

Leave a Reply

Your email address will not be published. Required fields are marked *

 

Disclaimer & Confirmation

As per the rules of the Bar Council of India, law firms are not permitted to solicit work and advertise. By clicking on the “I AGREE” button below, user acknowledges the following:

    • there has been no advertisements, personal communication, solicitation, invitation or inducement of any sort whatsoever from us or any of our members to solicit any work through this website;
    • user wishes to gain more information about AMLEGALS and its attorneys for his/her own information and use;
  • the information about us is provided to the user on his/her specific request and any information obtained or materials downloaded from this website is completely at their own volition and any transmission, receipt or use of this site does not create any lawyer-client relationship; and that
  • We are not responsible for any reliance that a user places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof.

However, the user is advised to confirm the veracity of the same from independent and expert sources.