Regulation & Compliance
AI Personalization in Banks: What the EU AI Act, GDPR and MaRisk Allow
AI personalization in banking under the EU AI Act, GDPR, and MaRisk: key obligations, deadlines, and practical guardrails with source citations.
•
acceleraid Redaktion
7 min read
01
Acquire
Signale erkennen
02
Onboard
Aktivierung steuern
03
Grow
Next Best Action
04
Retain
Churn reduzieren
05
Reactivate
Potenziale zurückholen

Part 3 of our series on AI personalization in banking, following our practical guide and our piece on use cases with proven impact. AI personalization in banking operates within a dense legal framework spanning the EU AI Act, GDPR, and MaRisk — three frameworks that interact: the AI Act as product-focused AI law, GDPR governing profiling and automated decisions, MaRisk as BaFin's supervisory model-risk standard. Reviewing only one routinely misses requirements from the other two. This article maps the key provisions and practical guardrails — it does not constitute legal advice, but offers structured orientation for business teams.
AI personalization in banking: when models qualify as high-risk AI
The AI Act classifies certain AI systems in Annex III as high-risk. For banks, the central provision is Annex III(5)(b): AI systems "intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud" (EU AI Act, Annex III). Other relevant cases: 5(c) (life/health insurance pricing), 1(c) (emotion recognition), 4(a) (recruitment) (EU AI Act, Annex III).
A frequently overlooked clause in Article 6 is decisive for personalization models. Article 6(3) allows exceptions from the high-risk classification, e.g. for a narrow procedural task. Crucially, these don't apply if the system performs profiling of natural persons: "an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons" (EU AI Act, Art. 6). Since AI personalization is built on profiling, many Annex III use cases cannot rely on this exception.
EU AI Act: prohibited practices with direct relevance to credit and overdraft offers
Article 5(1) of the AI Act bans certain AI practices outright. Two bans are directly relevant to credit and overdraft offers: point (a) bans manipulative or deceptive techniques capable of causing significant harm; point (b) bans exploiting vulnerabilities due to age, disability, or a "specific social or economic situation"; point (c) bans social scoring (EU AI Act, Art. 5). Personalization logic targeting financially stretched customers with overdraft or credit offers warrants careful, case-by-case legal review.
EU AI Act: transparency obligations and the right to an explanation
Article 50 of the AI Act sets transparency obligations toward natural persons: paragraph 1 requires disclosure when a person interacts directly with an AI system such as a chatbot, unless obvious from context; paragraph 5 requires this "at the latest at the time of the first interaction or exposure... in a clear and distinguishable manner" (EU AI Act, Art. 50). Especially relevant is Article 86, granting a right to "clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken" (EU AI Act, Art. 86). Models that output scores without a traceable rationale don't structurally satisfy this.
EU AI Act: penalties and timeline
Fines are tiered: Article 5 violations trigger fines up to €35,000,000 or 7% of worldwide turnover (Art. 99(3)); operator (Art. 26) and transparency (Art. 50) violations up to €15,000,000 or 3% (Art. 99(4)); a third tier caps at €7,500,000 or 1% (Art. 99(5)). For SMEs, the lower amount applies (EU AI Act, Art. 99).
The rollout under Article 113 is staggered: Chapters I and II have applied since February 2, 2025; Chapter III Section 4, V, VII, XII, and Article 78 since August 2, 2025; general applicability begins August 2, 2026; Article 6(1) — the Annex III high-risk rule — only from August 2, 2027 (EU AI Act, Art. 113). Institutions with Annex III exposure should plan around these deadlines.

GDPR: profiling, automated decisions, and the right to object
Article 22(1) GDPR grants a right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects or similarly affects a person. Paragraph 2 lists three exceptions: necessity for a contract, an explicit legal basis, or explicit consent. Even where an exception applies, paragraph 3 still requires minimum safeguards — the right to obtain human intervention, express one's view, and contest the decision. Paragraph 4 generally prohibits automated decisions based on special categories of data under Article 9(1) (GDPR, Art. 22).
Particularly relevant for marketing personalization is Article 21(2) GDPR: for direct marketing — "which includes profiling to the extent that it is related to such direct marketing" — the data subject has an unconditional right to object; once exercised, the data may no longer be processed for that purpose. Paragraph 4 requires this be explicitly and separately communicated at first contact; paragraph 5 allows automated objection for information society services (GDPR, Art. 21). The legal bases for the processing itself come from Article 6(1) GDPR, from point (a) (consent) to point (f) (legitimate interests) (GDPR, Art. 6).
A landmark clarification comes from the CJEU. In its ruling of December 7, 2023 (Case C-634/21), it held that credit "scoring" is an automated individual decision generally prohibited under GDPR wherever the recipient — such as a bank — attributes to it "a determining role" in the credit decision (CJEU, Press Release No. 186/23). The more heavily the score drives the decision, the more likely Article 22 GDPR applies.
MaRisk AT 4.3.5: model-risk governance explicitly covers AI
Germany's MaRisk, issued by BaFin — specified in Circular 05/2023 (BA) — contains a dedicated module on model risk, AT 4.3.5, that explicitly extends to AI. Item 1: "The requirements of this module apply to models used for the processes governed by this circular. They also apply to automated models, technology-enabled innovation, and artificial intelligence" [translated] (BaFin Circular 05/2023 (BA), MaRisk AT 4.3.5).
Five requirements under AT 4.3.5 are especially relevant:
Item | Requirement |
|---|---|
Item 2 | Model choice is the institution's responsibility; underlying assumptions must be justified and reviewed for appropriateness before and after deployment |
Item 3 | Suitable procedures must ensure data quality; quality weaknesses must be detected and remediated |
Item 4 | Adequate rules for using model outputs, including handling of overrides |
Item 5 | Regular validation; critical assessment of model limitations; ongoing analysis of accuracy, stability, and consistency |
Item 6 | Explainability explicitly required, specifically for AI models |
Source: BaFin Circular 05/2023 (BA), MaRisk AT 4.3.5
Item 6 states the explainability requirement explicitly: "In addition to the desired accuracy, sufficient explainability must also be ensured. This applies in particular to models exhibiting characteristics of technology-enabled innovation and artificial intelligence" [translated] (MaRisk AT 4.3.5). This overlaps with the right to an explanation under Article 86 — auditability for both purposes avoids duplicating governance work.
The governance gap: why this matters
All three frameworks fall short without a structure to operationalize them. Only 14% of banks have a specific AI governance framework (McKinsey, Getting personal) — exactly the gap where the AI Act and MaRisk AT 4.3.5 converge. Contractual obligations also apply to outsourced AI and CDP services: Article 30(3)(e) of DORA requires "unrestricted rights of access, inspection and audit" over providers for critical functions, while point (f) requires exit strategies with a binding transition period (DORA, Art. 30) — regardless of whether the AI component runs in-house or externally.
Practical guardrails for implementation
The provisions cited above suggest four guardrails, which do not substitute for a definitive legal assessment but can serve as a starting point for internal review:
Screen against Annex III before launch: Check any model touching creditworthiness or insurance pricing against Annex III(5) before going live — including whether profiling rules out the exceptions under Article 6(3).
Build explainability in, don't bolt it on: Design models to satisfy both Article 86 of the AI Act and Item 6 of MaRisk AT 4.3.5 — auditable, traceable scores rather than black-box outputs.
Contact-frequency and vulnerability guardrails: Include mechanisms that rule out exploiting periods of economic vulnerability, consistent with Article 5(1)(b) of the AI Act.
Make the right to object technically enforceable: Objections under Article 21(2) GDPR should reliably and demonstrably halt processing once exercised.
Acceleraid's Prediction Engine & AI Framework produces explainable, auditable scores; its CDP & Data Governance module handles consent, data lineage, and PII protection under GDPR-by-design with German hosting; its Regulatory Reporting module supports MaRisk reporting plus FINREP, COREP, and AnaCredit (Acceleraid Platform). This doesn't replace legal review, but can serve as a technical foundation for the guardrails above.
AI personalization in banking: regulation as a framework, not a brake
The EU AI Act, GDPR, and MaRisk don't contradict effective AI personalization — they define the conditions for operating it on a sound legal footing. Institutions that build in explainability, data quality, and governance from the start avoid fines and build the trust that, as noted in part one of this series, determines long-term success. This article does not constitute legal advice; institutions should involve legal and compliance, and external counsel where appropriate, before making binding decisions.
Illustration: AI-generated. AI-assisted content: We use AI technologies and automated agents in the creation of our articles, including from Microsoft, Google, OpenAI, Anthropic and other providers. Topics, editorial direction and final approval remain with our team.
We use Cookies 🍪
Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent we also use Google Analytics (analytics) and Leadfeeder (visitor identification). More in our Privacy Policy.