Centraltec

AI Consulting

BaFin becomes an AI supervisor: what banks, insurers and financial services firms must prepare now

BaFin will supervise AI systems in the financial sector. What applies from August 2026, which use cases count as high-risk, and what firms should get done within 90 days.

The use of artificial intelligence in the financial sector is becoming a supervisory topic in its own right. With the German AI market surveillance and innovation act entering into force, the Federal Financial Supervisory Authority (BaFin) has been given new responsibilities for supervising AI systems.

The scope covers AI systems directly connected to a regulated financial activity. Examples include applications in customer communication, credit decisions, and risk and premium assessment in insurance. For banks, insurers and other supervised financial firms this means AI governance is no longer only an IT strategy question – it becomes part of regulatory corporate steering. (BaFin)

What the new BaFin mandate changes

As a market surveillance authority, BaFin will assess whether AI systems in the financial sector meet the requirements of the European AI Act. The mandate applies exclusively to systems directly linked to a regulated financial activity.

AI applications without a direct link to financial market regulation generally fall under other authorities. A recruiting system that screens applications inside a bank, for instance, may be supervised by the Federal Network Agency (Bundesnetzagentur). An AI system for creditworthiness assessment, on the other hand, falls under BaFin. What matters is therefore not the company alone, but the specific intended purpose of each system. (German Bundestag)

BaFin names three areas it will start supervising immediately:

From 2 December 2027, comprehensive supervision of high-risk AI systems will be added. This includes systems for creditworthiness assessment as well as certain AI systems for risk and pricing assessment in life and health insurance. (BaFin)

Transparency obligations apply from August 2026

The first transparency obligations of the AI Act apply from 2 August 2026. Companies must in particular ensure that people can tell when they are interacting directly with an AI system.

This affects chatbots, automated customer assistants and dialogue-based advisory systems, among others. Customers must not be left with the impression that they are speaking only to a human when an AI system is in fact involved. For high-risk systems, transparency requirements apply in addition to the more extensive requirements of that risk class. (European Commission)

For financial firms this means the review cannot stop at publicly visible chatbots. Embedded AI functions in customer portals, apps, voice assistants or automated service processes may be in scope as well.

The AI literacy obligation already applies

Since 2 February 2025, providers and deployers of AI systems must make their best efforts to ensure that people involved in development, operation or use have a sufficient level of AI literacy.

The required level depends among other things on:

A generic introduction to ChatGPT or generative AI is therefore not automatically sufficient. Staff must understand the capabilities, limits and risks of the systems they actually work with. That includes faulty decisions, biased results, inadmissible data input, data protection risks and the duty of human oversight. (Bundesnetzagentur)

As part of its market surveillance, BaFin can check whether firms have put appropriate measures in place. Companies should therefore not only offer training, but also document who needs which qualification for which AI use case – and who has received it.

High-risk AI in the financial sector

The European AI Act follows a risk-based approach. AI systems are assigned to risk classes depending on their intended purpose and their potential impact on health, safety and fundamental rights.

In the financial sector the following applications are particularly relevant:

These systems can influence access to essential private services and can have significant financial or personal consequences for the people affected. They are therefore generally treated as high-risk AI. (European Commission)

Future requirements for high-risk systems include:

Providers must collect, document and analyse relevant performance data across the entire lifecycle. Deployers must use and monitor systems in line with the provider's instructions and react to identifiable risks or incidents. (European Commission)

Accountability stays with the company

Using an externally developed model or a cloud-based AI platform does not shift regulatory accountability entirely to the vendor.

Financial firms must be able to explain:

In BaFin's view, AI-supported decisions must remain correctable and reversible by humans. Responsibility for the use of these systems lies with the supervised firms and their management boards. (BaFin)

AI projects should therefore not be steered by innovation units, data science teams or external service providers alone. What is needed is shared accountability across management, business units, IT, information security, data protection, risk management and compliance.

Likely consequences for financial firms

AI applications become audit-relevant

AI systems may become the subject of regulatory information requests, spot checks and audits. Companies must be able to explain at short notice and with evidence which systems they use and how these are controlled.

Undocumented experiments, independently procured AI services and decentralised business-unit solutions thus turn into a regulatory risk.

Existing processes need to be reassessed

A system can fall under the AI Act even if it was not procured as a standalone AI product. AI functions are increasingly embedded in CRM systems, core banking applications, fraud prevention, document processing, scoring solutions and standard software.

The review must therefore not be limited to internally developed models.

Supervisory responsibility can vary per use case

Within a single financial firm, BaFin and the Bundesnetzagentur may be responsible for different AI systems. This increases organisational effort and requires clean classification.

A company-wide AI register must therefore map not only risks and owners, but also the likely competent authority.

Evidence matters more than declarations of intent

An internal AI policy alone will not be enough. Companies must be able to show that requirements are actually implemented.

This includes:

Vendor management becomes a central factor

Many financial firms use models and AI functions from external providers. For their own compliance they will still need information on functionality, limitations, data processing, security measures and performance quality.

Where such information or contractual cooperation rights are missing, a company may not be able to meet its own evidence and monitoring obligations. It follows that AI-specific requirements must be reflected in tenders, contracts and third-party reviews going forward. (EUR-Lex)

Potential sanctions

The AI Act provides for tiered fines. The highest sanctions apply to violations of prohibited AI practices, where fines of up to EUR 35 million or up to seven percent of global annual turnover are possible.

Other violations – for example against deployer obligations or transparency requirements – carry lower but still substantial caps. Incorrect, incomplete or misleading information provided to competent authorities can also be sanctioned. For small and medium-sized enterprises, the lower of the absolute cap and the turnover-based amount generally applies. (EUR-Lex)

Beyond fines, further risks exist:

Recommended actions for the next 90 days

1. Build a complete AI inventory

All AI applications must be recorded company-wide. The register should contain at least:

Pilot projects, embedded software features and independently used cloud services must be included as well.

2. Classify applications by risk and supervisory responsibility

For each system, check:

The European Commission's guidelines are not legally binding, but are intended to support interpretation and later enforcement. (European Commission)

3. Implement transparency obligations immediately

All applications with direct human-AI interaction should be reviewed before 2 August 2026.

What is needed in particular:

4. Build AI literacy by role

Companies should introduce a mandatory training concept covering different roles:

Training should be recurring and documented in a verifiable way.

5. Establish clear AI governance

Every AI system needs a business owner and a technical owner. In addition, a binding approval process should be set up.

It should include at least the following checks:

6. Make human oversight technically real

Human oversight must not exist only on paper. It has to be genuinely possible in the system.

That includes:

7. Standardise documentation and logging

A structured documentation file should be maintained for every relevant system, bringing together technical, business and regulatory information.

For high-risk applications in particular, companies should ensure early on that decisions, model versions, input data, outputs, human interventions and changes can be logged traceably.

8. Review contracts with AI vendors

Existing contracts should be checked for whether the vendor provides sufficient information and cooperation.

Relevant contractual elements include:

9. Do not postpone high-risk readiness to 2027

The full requirements for certain high-risk systems only apply from 2 December 2027. But building data quality controls, documentation, logging, governance and technical monitoring takes considerable lead time.

Systems that must be compliant at the end of 2027 are being developed, procured or contractually locked in today. The requirements should therefore already be part of new projects and tenders.

Conclusion

With BaFin's new mandate, the operational phase of AI regulation begins for the financial sector. Companies do not need to stop all AI projects. But they must know at any time which systems they run, which risks come with them and how compliance is evidenced.

The decisive success factor is integrated AI governance. Technology, business processes, risk management and compliance cannot be treated separately.

Firms that establish a solid AI inventory, clear ownership, traceable controls and documented approval processes now do not only reduce regulatory risk. They also create the basis for deploying AI faster, in a more controlled way and productively over the long term.

Official sources

  1. BaFin: press release "Überwachung von KI: BaFin erhält neue Kompetenzen", published 29 July 2026. (BaFin)
  2. BaFin: interview "Es bleibt viel Raum für Innovation", published 29 July 2026. (BaFin)
  3. German Bundestag: adoption of the act implementing the European AI Act, 11 June 2026. (German Bundestag)
  4. German Bundestag: delineation of responsibilities between BaFin and the Bundesnetzagentur. (German Bundestag)
  5. European Commission: overview of risk classes, obligations and application dates of the AI Act. (European Commission)
  6. European Commission: guidelines on the classification of high-risk AI systems. (European Commission)
  7. Bundesnetzagentur: requirements for high-risk AI systems. (Bundesnetzagentur)
  8. Bundesnetzagentur: transparency obligations for providers and deployers of AI systems. (Bundesnetzagentur)
  9. Bundesnetzagentur: requirements for AI literacy of staff. (Bundesnetzagentur)
  10. EUR-Lex: Regulation (EU) 2024/1689 on artificial intelligence. (EUR-Lex)

Back to news

BaFin becomes an AI supervisor: what banks, insurers and financial services firms must prepare now | Centraltec