The use of artificial intelligence in the financial sector is becoming a supervisory topic in its own right. With the German AI market surveillance and innovation act entering into force, the Federal Financial Supervisory Authority (BaFin) has been given new responsibilities for supervising AI systems.
The scope covers AI systems directly connected to a regulated financial activity. Examples include applications in customer communication, credit decisions, and risk and premium assessment in insurance. For banks, insurers and other supervised financial firms this means AI governance is no longer only an IT strategy question – it becomes part of regulatory corporate steering. (BaFin)
What the new BaFin mandate changes
As a market surveillance authority, BaFin will assess whether AI systems in the financial sector meet the requirements of the European AI Act. The mandate applies exclusively to systems directly linked to a regulated financial activity.
AI applications without a direct link to financial market regulation generally fall under other authorities. A recruiting system that screens applications inside a bank, for instance, may be supervised by the Federal Network Agency (Bundesnetzagentur). An AI system for creditworthiness assessment, on the other hand, falls under BaFin. What matters is therefore not the company alone, but the specific intended purpose of each system. (German Bundestag)
BaFin names three areas it will start supervising immediately:
- transparency obligations for certain AI systems
- compliance with the prohibitions on certain AI practices
- measures to ensure sufficient AI literacy among staff
From 2 December 2027, comprehensive supervision of high-risk AI systems will be added. This includes systems for creditworthiness assessment as well as certain AI systems for risk and pricing assessment in life and health insurance. (BaFin)
Transparency obligations apply from August 2026
The first transparency obligations of the AI Act apply from 2 August 2026. Companies must in particular ensure that people can tell when they are interacting directly with an AI system.
This affects chatbots, automated customer assistants and dialogue-based advisory systems, among others. Customers must not be left with the impression that they are speaking only to a human when an AI system is in fact involved. For high-risk systems, transparency requirements apply in addition to the more extensive requirements of that risk class. (European Commission)
For financial firms this means the review cannot stop at publicly visible chatbots. Embedded AI functions in customer portals, apps, voice assistants or automated service processes may be in scope as well.
The AI literacy obligation already applies
Since 2 February 2025, providers and deployers of AI systems must make their best efforts to ensure that people involved in development, operation or use have a sufficient level of AI literacy.
The required level depends among other things on:
- the technical knowledge of the people involved,
- their experience and training,
- the specific context of use,
- the risks of the system deployed,
- the customers or groups of people affected.
A generic introduction to ChatGPT or generative AI is therefore not automatically sufficient. Staff must understand the capabilities, limits and risks of the systems they actually work with. That includes faulty decisions, biased results, inadmissible data input, data protection risks and the duty of human oversight. (Bundesnetzagentur)
As part of its market surveillance, BaFin can check whether firms have put appropriate measures in place. Companies should therefore not only offer training, but also document who needs which qualification for which AI use case – and who has received it.
High-risk AI in the financial sector
The European AI Act follows a risk-based approach. AI systems are assigned to risk classes depending on their intended purpose and their potential impact on health, safety and fundamental rights.
In the financial sector the following applications are particularly relevant:
- creditworthiness assessment of natural persons
- automated or AI-supported credit decisions
- risk assessment in life insurance
- risk assessment and pricing in health insurance
These systems can influence access to essential private services and can have significant financial or personal consequences for the people affected. They are therefore generally treated as high-risk AI. (European Commission)
Future requirements for high-risk systems include:
- risk management
- quality and suitability of the data used
- technical documentation
- logging and traceability
- human oversight
- accuracy and robustness
- cybersecurity
- post-market monitoring
- reporting of serious incidents
Providers must collect, document and analyse relevant performance data across the entire lifecycle. Deployers must use and monitor systems in line with the provider's instructions and react to identifiable risks or incidents. (European Commission)
Accountability stays with the company
Using an externally developed model or a cloud-based AI platform does not shift regulatory accountability entirely to the vendor.
Financial firms must be able to explain:
- what a system is used for,
- which decisions it influences,
- which data is processed,
- which limitations exist,
- how results are reviewed,
- when humans must intervene,
- how faulty decisions can be corrected.
In BaFin's view, AI-supported decisions must remain correctable and reversible by humans. Responsibility for the use of these systems lies with the supervised firms and their management boards. (BaFin)
AI projects should therefore not be steered by innovation units, data science teams or external service providers alone. What is needed is shared accountability across management, business units, IT, information security, data protection, risk management and compliance.
Likely consequences for financial firms
AI applications become audit-relevant
AI systems may become the subject of regulatory information requests, spot checks and audits. Companies must be able to explain at short notice and with evidence which systems they use and how these are controlled.
Undocumented experiments, independently procured AI services and decentralised business-unit solutions thus turn into a regulatory risk.
Existing processes need to be reassessed
A system can fall under the AI Act even if it was not procured as a standalone AI product. AI functions are increasingly embedded in CRM systems, core banking applications, fraud prevention, document processing, scoring solutions and standard software.
The review must therefore not be limited to internally developed models.
Supervisory responsibility can vary per use case
Within a single financial firm, BaFin and the Bundesnetzagentur may be responsible for different AI systems. This increases organisational effort and requires clean classification.
A company-wide AI register must therefore map not only risks and owners, but also the likely competent authority.
Evidence matters more than declarations of intent
An internal AI policy alone will not be enough. Companies must be able to show that requirements are actually implemented.
This includes:
- up-to-date system inventories
- documented risk assessments
- approval decisions
- training records
- test and validation reports
- technical logs
- escalation procedures
- monitoring metrics
- documented human control steps
Vendor management becomes a central factor
Many financial firms use models and AI functions from external providers. For their own compliance they will still need information on functionality, limitations, data processing, security measures and performance quality.
Where such information or contractual cooperation rights are missing, a company may not be able to meet its own evidence and monitoring obligations. It follows that AI-specific requirements must be reflected in tenders, contracts and third-party reviews going forward. (EUR-Lex)
Potential sanctions
The AI Act provides for tiered fines. The highest sanctions apply to violations of prohibited AI practices, where fines of up to EUR 35 million or up to seven percent of global annual turnover are possible.
Other violations – for example against deployer obligations or transparency requirements – carry lower but still substantial caps. Incorrect, incomplete or misleading information provided to competent authorities can also be sanctioned. For small and medium-sized enterprises, the lower of the absolute cap and the turnover-based amount generally applies. (EUR-Lex)
Beyond fines, further risks exist:
- supervisory measures
- restriction or termination of an AI deployment
- required rework on running processes
- liability and data protection risks
- discrimination allegations
- reputational damage
- delays in rolling out new applications
Recommended actions for the next 90 days
1. Build a complete AI inventory
All AI applications must be recorded company-wide. The register should contain at least:
- name and purpose of the system
- responsible business unit
- technical operator
- vendor and model used
- data processed
- people affected
- decisions influenced
- degree of automation
- human control mechanisms
- risk class
- competent supervisory authority
Pilot projects, embedded software features and independently used cloud services must be included as well.
2. Classify applications by risk and supervisory responsibility
For each system, check:
- Does it legally qualify as an AI system?
- Is a prohibited practice involved?
- Do transparency obligations apply?
- Might the system qualify as high-risk AI?
- Is the use directly connected to a regulated financial activity?
- Is BaFin or the Bundesnetzagentur likely to be competent?
The European Commission's guidelines are not legally binding, but are intended to support interpretation and later enforcement. (European Commission)
3. Implement transparency obligations immediately
All applications with direct human-AI interaction should be reviewed before 2 August 2026.
What is needed in particular:
- clear notices about the AI interaction
- understandable and clearly visible wording
- consistent labelling across all channels
- a defined handover to human staff
- documentation of the technical implementation
4. Build AI literacy by role
Companies should introduce a mandatory training concept covering different roles:
- management board
- developers and data scientists
- business users
- customer service
- risk management and compliance
- data protection and information security
- procurement and vendor management
- internal audit
Training should be recurring and documented in a verifiable way.
5. Establish clear AI governance
Every AI system needs a business owner and a technical owner. In addition, a binding approval process should be set up.
It should include at least the following checks:
- business suitability
- data protection
- information security
- model and data quality
- discrimination risks
- legal classification
- human control options
- monitoring in live operation
- exit and fallback procedures
6. Make human oversight technically real
Human oversight must not exist only on paper. It has to be genuinely possible in the system.
That includes:
- manual override
- traceable decision rationale
- escalation under uncertainty
- four-eyes approval for critical decisions
- defined thresholds
- kill switches
- alternative manual processes
7. Standardise documentation and logging
A structured documentation file should be maintained for every relevant system, bringing together technical, business and regulatory information.
For high-risk applications in particular, companies should ensure early on that decisions, model versions, input data, outputs, human interventions and changes can be logged traceably.
8. Review contracts with AI vendors
Existing contracts should be checked for whether the vendor provides sufficient information and cooperation.
Relevant contractual elements include:
- documentation obligations
- information rights
- changes to models and systems
- performance and quality metrics
- log access
- security requirements
- support for regulatory inquiries
- incident notifications
- data locations and subprocessors
- exit and migration provisions
9. Do not postpone high-risk readiness to 2027
The full requirements for certain high-risk systems only apply from 2 December 2027. But building data quality controls, documentation, logging, governance and technical monitoring takes considerable lead time.
Systems that must be compliant at the end of 2027 are being developed, procured or contractually locked in today. The requirements should therefore already be part of new projects and tenders.
Conclusion
With BaFin's new mandate, the operational phase of AI regulation begins for the financial sector. Companies do not need to stop all AI projects. But they must know at any time which systems they run, which risks come with them and how compliance is evidenced.
The decisive success factor is integrated AI governance. Technology, business processes, risk management and compliance cannot be treated separately.
Firms that establish a solid AI inventory, clear ownership, traceable controls and documented approval processes now do not only reduce regulatory risk. They also create the basis for deploying AI faster, in a more controlled way and productively over the long term.
Official sources
- BaFin: press release "Überwachung von KI: BaFin erhält neue Kompetenzen", published 29 July 2026. (BaFin)
- BaFin: interview "Es bleibt viel Raum für Innovation", published 29 July 2026. (BaFin)
- German Bundestag: adoption of the act implementing the European AI Act, 11 June 2026. (German Bundestag)
- German Bundestag: delineation of responsibilities between BaFin and the Bundesnetzagentur. (German Bundestag)
- European Commission: overview of risk classes, obligations and application dates of the AI Act. (European Commission)
- European Commission: guidelines on the classification of high-risk AI systems. (European Commission)
- Bundesnetzagentur: requirements for high-risk AI systems. (Bundesnetzagentur)
- Bundesnetzagentur: transparency obligations for providers and deployers of AI systems. (Bundesnetzagentur)
- Bundesnetzagentur: requirements for AI literacy of staff. (Bundesnetzagentur)
- EUR-Lex: Regulation (EU) 2024/1689 on artificial intelligence. (EUR-Lex)
