In August 2025, the Reserve Bank of India's FREE-AI Committee asked every regulated entity to adversarially stress-test its AI systems and to obtain independent audits of them. Zortium is the tool that does the stress-testing and produces the evidence — a board-ready report showing exactly where your AI can be made to misbehave, and by how much.
Every AI a bank ships is a fresh way in for an attacker — and a fresh question from the board. Here is where Zortium turns that exposure into evidence.
RiskA jailbroken assistant dispenses prohibited financial advice, impersonates the bank, or spills one customer's data to another.
With ZortiumWe red-team the assistant for jailbreaks, impersonation and context leakage before it ever faces a customer.
RiskA doctored ID, or an instruction hidden inside an uploaded document, steers the model's extraction — quietly waving through a fraudulent onboarding.
With ZortiumWe plant those visual injections and image tampering ourselves, so the failure shows up in a test — not in a fraud loss.
RiskA prompt-injected input nudges an LLM copilot toward a non-compliant or biased recommendation that an analyst then trusts.
With ZortiumWe probe the copilot for manipulation and hand you a scored, dated record for model-risk sign-off.
RiskRBI holds you accountable for a bought model you can't see inside — yet you have no way to prove it is safe.
With ZortiumA black-box red-team needs no model internals — independent evidence you can put in front of a supervisor.
FREE-AI — the Framework for Responsible and Ethical Enablement of Artificial Intelligence — is the report of an expert committee the RBI constituted in December 2024, chaired by Dr. Pushpak Bhattacharyya of IIT Bombay. It was published on 13 August 2025.
It sets out seven guiding principles (the "Sutras") and translates them into 26 recommendations across six pillars — Infrastructure, Policy, Capacity, Governance, Protection and Assurance. It is the RBI's clearest statement yet of how it expects banks, NBFCs and other regulated entities to adopt AI responsibly.
Three of those recommendations describe, almost word for word, what an adversarial testing tool does. That is where Zortium fits.
Plain-English readings of the recommendations most relevant to adversarial testing. The wording below paraphrases the FREE-AI report.
Regulated entities should regularly stress-test their AI systems to surface hidden vulnerabilities and strengthen resilience — with scope and frequency proportionate to the risk of the application, and additional "trigger-based" testing as new threats emerge.
Pillar 5 — ProtectionCybersecurity frameworks should be extended to cover threats unique to AI — model manipulation, adversarial inputs, data poisoning and deepfakes — not just traditional network and application security.
Pillar 5 — ProtectionAI systems should undergo periodic, independent audits, with depth and frequency set by the system's risk tier and how sensitive its use case is — producing evidence a board and a supervisor can rely on.
Pillar 6 — AssuranceSource: RBI FREE-AI Committee Report (PDF, 13 Aug 2025) · RBI press releases
Zortium is not a checklist or a policy template. It actually attacks your AI the way an adversary would, then hands you the record of what happened.
Running Zortium is the adversarial stress-test. It launches a library of known attacks against your model and measures how often each one succeeds — repeatable on demand and re-runnable whenever a new threat appears.
Every run produces a dated report: a success rate per attack category, a severity tier, and a clear pass/fail. That is the independent-audit artifact a board committee and an RBI supervisor can be shown.
The attack library maps onto the threats the framework names — adversarial inputs and model manipulation are directly covered. We are candid about what we do not test (training-time data poisoning is out of scope), because honesty is the point of an audit.
Recommendation 24 asks for independent assurance, and RBI's draft Model Risk Management directions already say a model cannot validate itself and hold the institution accountable even for outsourced models. A model graded by its own builder is marking its own homework. Zortium is an external red-team run by a party with no stake in the result — the natural fit for the third line of defence.
No dashboards to interpret. Each attack family gets an attack-success-rate — the share of attempts the model failed to resist — a severity tier, and a pass or fail against a threshold you set.
The same report is the CI gate that blocks an unsafe model from going live, and the dated artifact you file for the independent-audit obligation.
Whether you are drafting a board AI policy, preparing for supervisory questions, or simply want to know how your assistant holds up — we can walk your risk and technology teams through a live scan.
This page summarises publicly available material for context and is not legal or compliance advice. FREE-AI is a committee report and set of recommendations, not (yet) a binding direction; readings above paraphrase the source. Refer to the RBI's published FREE-AI report and the RBI Model Risk Management directions, together with your own advisors, for authoritative guidance.