Bafin to Supervise AI in the Financial Sector: What Organizations Need to Know

3. August 2026

Bafin has been assigned new authority to oversee AI systems in the financial sector. The legal basis is Germany’s AI Act Implementation Act, which entered into force on 29 July 2026. Going forward, Bafin will be responsible for AI systems that are directly linked to regulated financial activities.

For banks, insurers, and other supervised financial institutions, this is more than a formal question of regulatory responsibility. The announcement signals that supervisory authorities will increasingly view AI as part of existing governance and risk management frameworks. Bafin intends to closely align its market surveillance activities with its ongoing prudential supervision. As a result, AI is being treated not as a standalone technology issue, but as an integral component of a regulated business environment.

Particularly relevant are applications that support or influence decisions with a direct impact on customers. Bafin specifically highlights systems used for creditworthiness assessments in banking, as well as risk assessment systems in life and health insurance. According to Bafin, the relevant requirements for high risk AI systems will apply from 2 December 2027. Initial transparency obligations will already take effect on 2 August 2026.

These deadlines are part of the phased implementation of the EU AI Act. Recent adjustments introduced through the Digital Omnibus on AI have modified key timelines, particularly for high risk AI systems. We have already provided a detailed analysis of the specific changes in a separate article on the Digital Omnibus on AI.

Why This Development Matters for Financial Institutions

Many financial institutions have been using data driven and automated processes for years, including fraud detection, risk management, customer communications, and credit or insurance decision making. Technology regulation is not new to the financial sector. However, the AI Act establishes more explicit requirements for transparency, non-discrimination, human oversight, and risk management that are directly tied to specific AI systems. Bafin President Mark Branson has emphasized that decisions must remain subject to human intervention and reversal. Supervised institutions and their management bodies remain responsible for the use of AI.

The focus is therefore on the ability to govern, safeguard, and demonstrate compliance for the organization's specific AI use cases, as well as on the effective oversight of external service providers that supply models, interfaces, or complete AI systems.

For organizations, this means addressing questions such as:

  • Which data sources are being used?
  • How do models and decision making processes interact?
  • Where do risks arise for customers or for the organization itself?
  • How can organizations ensure that human oversight mechanisms are not merely documented on paper, but are effective in practice?
  • And at what point does a statistical method qualify as an AI system?

Our Evaluation: AI Assurance Is Becoming a Prerequisite for Trustworthy AI Deployment

For regulated organizations, Bafin’s announcement reinforces a trend that has already become evident across the financial sector: the value of an AI system is no longer measured solely by its performance. Organizations must be able to demonstrate that AI is deployed in a transparent, controllable, and secure manner and provide evidence of this to regulators and auditors.

"Existing governance and risk management frameworks already provide important foundations for this. These include DORA, Information Security Management, Third Party Risk Management, Internal controls, and Incident Management Processes. The challenge is to bring together regulatory requirements, technical security assessments, and the ability to demonstrate compliance for AI systems. This convergence is what we refer to as AI Assurance."

Dr. Christian Schwartz, Executive Board Member usd Security Consulting, usd AG

Organizations should therefore take an early inventory of the AI systems they use, identify which of them are subject to heightened regulatory scrutiny, and assess how existing control and security frameworks can be expanded to address AI specific requirements.


For more information, see the official Bafin press release.

Auch interessant:

Kategorien

Kategorien