Skip to main content

AI supervision: Bafin becomes market surveillance authority

What banks, insurers and asset managers need to do now

Under the German AI Market Surveillance and Innovation Promotion Act, Bafin assumes market surveillance for AI systems directly linked to regulated financial activities. Financial institutions should now integrate AI governance with compliance, risk management, DORA, MaRisk and GDPR frameworks and implement the applicable and upcoming requirements of the EU AI Act in a structured manner.

Bafin assumes AI market surveillance

Following the entry into force of the German AI Market Surveillance and Innovation Promotion Act (KI-MIG), Bafin is the market surveillance authority for AI systems directly linked to regulated financial activities. Compliance with the EU AI Act thus becomes part of day-to-day financial supervision. Horizontal applications, such as recruiting tools or general administrative software, may remain within the remit of the Federal Network Agency. Institutions should document the competent authority for each AI use case.

Phased obligations and key dates

The prohibitions on certain AI practices and the AI literacy obligation have applied since 2 February 2025. Since 2 August 2026, transparency requirements are particularly relevant for chatbots, synthetic content and deepfakes. Requirements for the relevant high-risk AI systems will apply from 2 December 2027. These include, in particular, systems used to assess the creditworthiness of natural persons and systems used for risk assessment and pricing in life and health insurance.

Determine roles and risks

The applicable obligations depend largely on whether a financial institution acts as provider, deployer or downstream provider. An institution initially acting as deployer may become a provider through in-house development, substantial modification or a change of intended purpose. Role allocation should therefore form part of the AI inventory and approval process.

Six implementation priorities

Financial institutions should focus their AI supervision programme on the following measures:

  • establish a complete AI inventory recording risk classification, role and competent authority;
  • assign responsibilities across the three lines of defence;
  • document role-based AI literacy programmes;
  • implement use-case-specific transparency notices and labelling processes;
  • establish a high-risk roadmap running to 2 December 2027; and
  • supplement contracts with AI service providers with proportionate information, audit, logging, change and cooperation rights.

The new AI supervision framework does not operate in isolation. It must be aligned with DORA, MaRisk, GDPR, model risk management and outsourcing requirements. Management bodies should therefore treat AI governance not merely as an IT or innovation matter, but as part of their compliance, governance and organisational responsibility.

Article "AI supervision: Bafin becomes market surveillance authority"

Did you find this useful?

Thanks for your feedback

Insights and Further Information