Digital wallets already use artificial intelligence more than most users realise - flagging a suspicious top-up, deciding which offer to show you, or powering the chatbot that answers a failed-transaction query. Nepal Rastra Bank's new Artificial Intelligence Guidelines put a formal structure around all of that, and the category it applies to - Payment System Operators (PSOs) and Payment Service Providers (PSPs) - is exactly where wallets like eSewa and Khalti sit. Here is what actually changes, for the companies running these apps and for the people using them.
Quick answer
Yes - NRB's Artificial Intelligence Guidelines explicitly list Payment System Operators and Payment Service Providers within scope, which covers digital wallet operators like eSewa and Khalti. Wallets that use AI for fraud detection, KYC checks, credit scoring for micro-loans, or chat-based support now need board-approved AI governance, must classify those systems for risk, and must disclose AI involvement, obtain consent, and offer an opt-out to users whose data feeds an AI system. The guideline was released in draft form for public feedback in December 2025, so wallet operators and users should check NRB's official guidelines page for the current, in-force status.
Are eSewa and Khalti actually covered?
Directly, yes. The guideline's scope section names "Payment System Operators (PSOs) and Payment Service Providers (PSPs)" alongside commercial banks, development banks, finance companies and microfinance institutions. In Nepal's regulatory structure, PSPs are the companies licensed to provide payment services to end users - the category eSewa, Khalti and comparable wallet apps fall under - while PSOs typically operate the underlying switching and settlement infrastructure. Both categories are named explicitly, so there is no ambiguity about whether wallet operators are in scope: they are.
What differs from a traditional bank is less the rulebook and more the risk profile. A wallet's AI footprint tends to concentrate around fraud and anomaly detection, onboarding and KYC verification, customer support automation, and increasingly, alternative credit scoring for small merchant or consumer loans - rather than large-scale corporate credit decisioning.
Where AI already shows up in a wallet app
Fraud and anomaly detection
Models that flag unusual top-ups, transfers or login patterns in real time, often the first AI use case any wallet deploys.
Onboarding and KYC checks
Document verification, face-matching and risk scoring during account opening, increasingly AI-assisted to speed up onboarding.
Customer support chatbots
First-line automated responses to failed transactions, refund status queries and account issues.
Micro-credit and BNPL scoring
Alternative credit scoring using transaction history to approve small consumer or merchant loans - the use case most likely to be classified high-risk.
Personalisation and offers
Recommending cashback deals, merchant offers or bill-payment reminders based on usage patterns.
What actually changes for wallet users
This is the part most coverage of the guideline skips, but it's arguably the more relevant section for the millions of people who use these apps daily. Four rights become explicit for anyone whose data or transactions feed an AI system at a licensed wallet:
- You should be told. If an AI system is involved in a decision that affects you - a blocked transaction, a rejected loan application, a flagged account - the wallet is required to disclose that AI was used.
- You are owed an explanation. The explanation has to be accessible, not a technical printout - what the decision was and, in general terms, what influenced it.
- Your data needs consent. Wallets must obtain explicit consent before your data goes into an AI system, and cannot bundle that consent invisibly into a blanket terms-of-service click-through.
- You can opt out. Opting out of AI-driven processing cannot result in the wallet denying you essential services - though note some AI-backed functions, like real-time fraud screening, may be difficult to disable without limiting what the app can safely offer.
Practically, expect wallets to update their in-app disclosures, consent flows during onboarding, and grievance or support channels to explicitly cover AI-related complaints as this guideline is implemented.
The outsourcing question most wallets will face
Very few digital wallets build fraud-detection or credit-scoring models entirely in-house. Most license or integrate third-party AI tools - a fraud engine from a specialist vendor, a chatbot platform, a credit-scoring model from a fintech partner. NRB's guideline draws a specific line here that matters a lot for wallet operators:
Internal use vs. outsourced service
If a wallet uses a third-party AI tool purely for internal work - drafting internal reports, summarising data - that is not outsourcing, and the wallet's own governance policies simply apply. But if a third party's AI is used to deliver a service to the wallet's own customers - a vendor-run fraud engine screening live transactions, for example - that counts as outsourcing. It requires due diligence on the vendor, contract terms covering data security and audit rights, board approval before the arrangement goes live, and notification to NRB's relevant supervision department.
For wallets running on multiple third-party AI integrations - which describes most of the market - this means a contract review cycle: checking whether existing vendor agreements already cover audit rights and data-security terms, or whether they need to be renegotiated to meet the new bar.
Which wallet AI use cases count as high-risk
The same five-criteria test from the core guideline applies to wallets: potential for serious harm, broad/systemic impact, minimal human oversight, risk to individual rights, and use of sensitive data. Applied to a typical wallet's AI stack, the likely picture looks like this:
| AI use case | Likely classification | Why |
|---|---|---|
| Micro-credit / BNPL scoring | High-risk | Can deny essential services or credit access; affects individual financial outcomes directly |
| KYC face-match and identity verification | High-risk | Processes biometric data and can block account access |
| Real-time fraud/anomaly detection | Depends on design | High-risk if it can auto-block funds with minimal human review; lower risk if flags are human-reviewed before action |
| Customer support chatbot | Not high-risk (typically) | Low potential for serious harm if escalation to a human agent is available |
| Offer personalisation | Not high-risk (typically) | Limited impact on essential services or individual rights |
These classifications are illustrative, not official determinations - each wallet operator must run its own documented assessment per system, exactly as the guideline requires.
Banks versus wallets: obligations compared
| Obligation | Banks / BFIs | Digital wallets (PSPs) |
|---|---|---|
| Board-approved AI governance framework | Required | Required |
| High-risk classification per system | Required | Required |
| Customer disclosure and consent | Required | Required |
| Outsourcing due diligence and NRB notification | Applies mainly to specialised model vendors | Applies broadly - most wallets rely heavily on third-party AI |
| Annual AI activity report to NRB | Required, standardised template | Required, standardised template |
| Incident reporting (critical/quarterly) | Required | Required |
Common misconceptions
"This means wallets can't use AI for fraud checks anymore"
Not true. Fraud detection is one of the explicitly named use cases the guideline expects institutions to manage responsibly, not eliminate.
"Only banks need to worry about this"
Payment service providers are named in the scope section by name - wallets are not an afterthought here.
"Consent is already covered by the app's terms of service"
The guideline calls for explicit consent for AI-driven data use specifically, which general terms-of-service acceptance may not satisfy on its own.
"This is already fully in force with a hard deadline"
The document was published as a draft for public feedback in December 2025. Confirm current status before assuming a compliance deadline has passed or been set.
Know Your AI Rights - Quick Wallet Checklist
Answer based on your own experience with your wallet app. This gives an informal sense of where a wallet's AI disclosure practices may need improvement - it is not a compliance audit of any specific company.
1. Were you told AI is used for fraud checks or automated decisions when you signed up?
2. If a transaction was ever blocked or flagged, did you get a clear reason?
3. Do you know how to raise a complaint specifically about an automated decision?
4. Have you ever seen an option to opt out of personalised, AI-driven offers or recommendations?
Frequently asked questions
Conclusion
For digital wallet operators, NRB's AI Guidelines mean the fraud engines, KYC tools and chatbots already running quietly in the background now need documented governance, risk classification and vendor oversight behind them. For users, the practical upside is a clearer set of rights: to know when AI is involved in a decision about your account, to get an explanation, and to have somewhere to complain if something goes wrong. Neither side should expect AI features to disappear - the point of the guideline is to make their use accountable, not to remove them.
Want the full regulatory picture, including governance and reporting requirements for banks and financial institutions? Read Nepal Rastra Bank's New AI Guideline: What Banks Must Know.
Discussion