Under the German AI Market Surveillance and Innovation Promotion Act, Bafin assumes market surveillance for AI systems directly linked to regulated financial activities. Financial institutions should now integrate AI governance with compliance, risk management, DORA, MaRisk and GDPR frameworks and implement the applicable and upcoming requirements of the EU AI Act in a structured manner.
Following the entry into force of the German AI Market Surveillance and Innovation Promotion Act (KI-MIG), Bafin is the market surveillance authority for AI systems directly linked to regulated financial activities. Compliance with the EU AI Act thus becomes part of day-to-day financial supervision. Horizontal applications, such as recruiting tools or general administrative software, may remain within the remit of the Federal Network Agency. Institutions should document the competent authority for each AI use case.
The prohibitions on certain AI practices and the AI literacy obligation have applied since 2 February 2025. Since 2 August 2026, transparency requirements are particularly relevant for chatbots, synthetic content and deepfakes. Requirements for the relevant high-risk AI systems will apply from 2 December 2027. These include, in particular, systems used to assess the creditworthiness of natural persons and systems used for risk assessment and pricing in life and health insurance.
The applicable obligations depend largely on whether a financial institution acts as provider, deployer or downstream provider. An institution initially acting as deployer may become a provider through in-house development, substantial modification or a change of intended purpose. Role allocation should therefore form part of the AI inventory and approval process.
Financial institutions should focus their AI supervision programme on the following measures:
The new AI supervision framework does not operate in isolation. It must be aligned with DORA, MaRisk, GDPR, model risk management and outsourcing requirements. Management bodies should therefore treat AI governance not merely as an IT or innovation matter, but as part of their compliance, governance and organisational responsibility.