HomeFuture Tech FrontierTrusted Computation Is Going to Be Core to AI Frameworks: Kiran Gopinath,...

Trusted Computation Is Going to Be Core to AI Frameworks: Kiran Gopinath, Sahamati

AI agents are becoming increasingly autonomous, but their growing intelligence is also raising a fundamental question for financial services: who controls what an AI agent can access and do with customer data? Sahamati’s proposed framework for AI agents in the Account Aggregator ecosystem attempts to answer that question through standards for agent identity, authorisation, traceability and real-time enforcement. In an interaction with Tech Achieve Media, Kiran Gopinath, Chief Innovation Officer, Sahamati, explains the thinking behind the framework and why trusted computation could emerge as a critical layer of India’s AI infrastructure.

TAM: Sahamati has recently released a framework for AI agents in the Account Aggregator ecosystem, outlining standards around agent identity, authorisation and, importantly, traceability. Why is such a framework needed at this stage, particularly when companies are racing to build increasingly autonomous and intelligent AI agents?

Kiran Gopinath: The key driver for AI is data. What Open Finance does is provide consented data to the entire AI ecosystem. The first thing we have to do is ensure that the consent given by the customer is respected. The processing of that data must happen within the boundaries set when the consent is shared. If I am sharing my data with, for example, a lending institution and its agents, I would want that data to be used for a specific purpose and for a specific period of time.

Also read: AI Success Will Be Defined by Trust, Data and Real Business Outcomes

When we say that the Account Aggregator ecosystem is going to be one of the biggest pipes through which data will flow in India, the first thing we have to look at is how we protect our customers. What are the guardrails we need to build to ensure that data is being used for the purposes stated and within the specified limits of time and purpose? That was the starting point for us. The question was: how do we build these guardrails? That is how the framework came about.

TAM: Under Sahamati’s new framework, how do you verify the identity of an AI agent? And how is giving consent to an AI agent different from giving consent to a human or an application?

Kiran Gopinath: In the framework, we have something called an Agent Registry, where only registered agents or agents with verifiable credentials can participate in or access customer data within the ecosystem. That is the first guardrail. Any agent that is not certified or is not part of the registry will simply not get access to this data. How is this different from a human or an application? It is not fundamentally different. An agent behaves on behalf of a corporation or a person in any case. The difference is that agents are much smarter and could start behaving autonomously. But that is not to say that humans would not go down that path anyway.

The processing needs to be controlled in either case, whether it is a human, an application or an agent. For an agent, however, we need to be even more careful to ensure that the data does not leak and that it is used only for the purpose for which consent has been given. That is important for us. Hopefully, these guardrails will be effective enough to ensure that agents do not run amok with the data.

TAM: The black-box nature of AI continues to be a challenge for the industry, particularly when AI agents make multiple decisions behind the scenes. For financial institutions, traceability is extremely important. How does your framework ensure traceability when an AI agent is making numerous decisions autonomously?

Kiran Gopinath: Our primary aim is to ensure that data flowing through the Account Aggregator ecosystem is used strictly for the purpose for which it was shared. For instance, if a customer shares data for a loan application, that data should be used only for that specific purpose. A lender may undertake several activities as part of the loan-processing journey, such as income assessment, debt assessment and other related evaluations. These tasks could be performed by a single agent or multiple agents. However, each agent must operate within the specific scope for which it has been registered.

For example, if an income-assessment agent is authorised to perform an income assessment but attempts to undertake any activity beyond that scope, the processing can be blocked within a confidential environment. This is the level of granularity our framework is designed to provide. The objective is to enable real-time enforceability. Any deviant or malicious behaviour can therefore be identified and blocked immediately.

TAM: India built UPI as a major layer of public digital infrastructure around trusted digital payments. Could a standardised AI-agent framework similarly become a national digital infrastructure layer that allows AI applications to securely and responsibly act on behalf of users?

Kiran Gopinath: Our view is that trusted computation is the next critical layer. The focus should not be limited to AI agents alone; classical AI, machine learning and other forms of computation also need to operate within a trusted environment. Ultimately, it is not just about how data is accessed, but also where the computation takes place and how trustworthy that environment is. That will be fundamental to building a secure and responsible AI ecosystem.

TAM: Technology adoption is moving rapidly, but governance often struggles to keep pace. Fintech startups, in particular, are deploying autonomous agents at a rapid rate. Is regulatory compliance keeping up, or do we risk heading towards a “shadow AI” bubble in Indian financial markets?

Kiran Gopinath: Looking at the proposed framework we released in June, I believe the timing is right. We expect to have our proof of concept and pilots underway in 2026 itself. We also expect the regulatory ecosystem to continue evolving in parallel. The RBI has been at the forefront of this conversation, including through its guidance on AI guardrails and governance. From an ecosystem perspective, we believe the necessary guardrails should be in place in the near term to support the responsible adoption of AI.

TAM: Looking ahead, it is possible that Indians will increasingly manage their financial data with the help of multiple AI agents. If that future is to work safely, what needs to be done today to ensure that we do not end up facing a systemic financial crisis tomorrow?

Kiran Gopinath: We need to have the right guardrails in place from the outset. It is critical to ensure that data flows through trusted channels, such as the Account Aggregator framework, so that the data being accessed is authentic and reliable. At the same time, protecting consumers and customers must remain central to this approach. I believe these two elements will be critical to building a secure and trusted AI ecosystem.

TAM: Before we conclude, is there anything else you would like to highlight that we may have missed?

Kiran Gopinath: One of the key considerations in any AI framework is where the computation takes place and the environment in which agents access and process data. How confidential and trustworthy that environment is will be critical. This is what we refer to as trusted computation, and it is central to our framework. We believe trusted computation will be a core component of AI frameworks going forward. From our perspective, confidential computing is one of the most effective privacy technologies available today and can be applied meaningfully in frameworks such as ours.

While our current framework is focused on the Account Aggregator ecosystem, similar approaches could potentially be adopted across other sectors and use cases. Most importantly, it is about creating a trusted environment for both data and computation. This could extend beyond protecting data access through confidential computing to enabling models themselves to operate within confidential environments. This can provide a stronger layer of protection for customers and consumers.

Author

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

spot_img
Dhrubabrata Ghosh
spot_img
Dhrubabrata Ghosh