Regulation & Compliance

AI Personalization in Banking: What the EU AI Act, GDPR, and MaRisk Allow

AI personalization in banks under the EU AI Act, GDPR, and MaRisk: key obligations, deadlines, and practical guidelines with supporting sources.

acceleraid Editorial Team

7 min. read

Customer Lifecycle Management

Customer Lifecycle Management

Customer Lifecycle Management

01

Acquire

Recognize signals

02

Onboard

Control activation

03

Grow

Next Best Action

04

Retain

Reduce churn

05

Reactivate

Reclaim potential

Data → AI Score → Trigger → Channel → Feedback

Data → AI Score → Trigger → Channel → Feedback

Compliance-Team prüft KI-Modelldokumentation vor dem Hintergrund von EU-Gesetzestexten

Part 3 of our series on AI personalization in banking, following the practical guide and the use cases with proven added value. AI personalization in banking operates within a dense legal framework of the EU AI Act, GDPR, and MaRisk — three sets of regulations that interlock: the AI Act as product-related AI law, the GDPR as the framework for profiling and automated decisions, and MaRisk as BaFin's regulatory model risk standard. Anyone who only checks one regularly overlooks requirements from the other two. This article contextualizes the central reference points and shows practical guardrails — it does not replace legal advice or institution-specific assessment, but offers structured guidance for business departments.

AI Personalization in Banking: When Models Are Classified as High-Risk AI

The AI Act classifies certain AI systems in Annex III as high-risk. Central for banks is Annex III No. 5 lit. b: AI systems "intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud" (EU AI Act, Annex III). Other relevant cases: No. 5 lit. c (risk assessment and pricing in life and health insurance), No. 1 lit. c (emotion recognition), No. 4 lit. a (recruiting) (EU AI Act, Annex III).

An often-overlooked clause in Art. 6 is crucial: Although Art. 6(3) allows exceptions to the high-risk classification, for example in the case of a narrow procedural task, these do not apply if the system performs profiling of natural persons: "an AI system referred to in Annex III shall always be considered high-risk where the AI system performs profiling of natural persons" (EU AI Act, Art. 6). Since AI personalization in banking is fundamentally based on profiling, this exception is eliminated for many Annex III-relevant use cases.

EU AI Act: Prohibited Practices with Direct Relevance for Credit and Account Offers

Art. 5(1) of the AI Act completely prohibits certain AI practices. Relevant for credit and overdraft offers: lit. a prohibits manipulative or deceptive techniques with significant potential for harm; lit. b prohibits the exploitation of vulnerabilities due to age, disability, or a "specific social or economic situation"; lit. c prohibits social scoring (EU AI Act, Art. 5). Personalization logics that specifically target financially tight customers with overdraft or credit offers require careful legal evaluation in individual cases.

EU AI Act: Transparency Obligations and Right to Explanation

Art. 50 of the AI Act regulates transparency obligations towards natural persons: Paragraph 1 requires disclosure in direct interaction with AI systems such as chatbots, unless this is obvious; Paragraph 5 requires that this information be provided "in a clear and obvious manner at the latest at the time of the first interaction or exposure" (EU AI Act, Art. 50). Particularly relevant is Art. 86: It grants the right to "clear and meaningful explanations on the role of the AI system in the decision-making procedure and the main elements of the decision taken" (EU AI Act, Art. 86). Personalization models that output scores without comprehensible justification structurally fail to meet this requirement.

EU AI Act: Sanction Framework and Timeline

The threat of fines is staggered: Art. 5 violations up to EUR 35,000,000 or 7% of the global annual turnover (Art. 99(3)); violations of operator obligations (Art. 26) and transparency obligations (Art. 50) up to EUR 15,000,000 or 3% (Art. 99(4)); a third framework up to EUR 7,500,000 or 1% (Art. 99(5)). For SMEs, the lower amount applies in each case (EU AI Act, Art. 99).

The timeline according to Art. 113 is staggered: Chapters I and II have been applicable since February 2, 2025; Chapter III Section 4, V, VII, XII and Art. 78 since August 2, 2025; general applicability begins on August 2, 2026; Art. 6(1) — the high-risk classification according to Annex III — not until August 2, 2027 (EU AI Act, Art. 113). Institutions with Annex III-relevant models should actively plan these deadlines into their roadmap.


Zeitplan der EU-AI-Act-Anwendbarkeit für Banken

GDPR: Profiling, Automated Decisions, and Right to Object

Art. 22(1) of the GDPR grants the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning him or her or similarly significantly affects him or her. Paragraph 2 names three exceptions: necessity for entering into, or performance of, a contract; authorization by Union or Member State law; or explicit consent. If an exception applies, Paragraph 3 nevertheless requires minimum guarantees — the right to obtain human intervention, to express his or her point of view and to contest the decision. Paragraph 4 fundamentally prohibits automated decisions based on special categories of data under Art. 9(1) (GDPR, Art. 22 · English version).

Particularly relevant for marketing personalization is Art. 21(2) of the GDPR: In the case of direct marketing — "including profiling to the extent that it is related to such direct marketing" — the data subject has an unconditional right to object; after which the data may no longer be processed for these purposes. Paragraph 4 requires explicit, separate notification at the latest at the time of the first communication; Paragraph 5 allows automated objection in connection with the use of information society services (GDPR, Art. 21). The legal bases for processing itself arise from Art. 6(1) GDPR, from lit. a (consent) to lit. f (legitimate interests) (GDPR, Art. 6).

A groundbreaking clarification comes from the ECJ: In its judgment of December 7, 2023 (Case C-634/21), it established that credit "scoring" constitutes an automated individual decision fundamentally prohibited by the GDPR, provided that the scoring provider's customer — such as a bank — attributes a "decisive role" to the score in the credit decision (ECJ, Press Release No. 186/23 · English version). The more the score determines the actual credit decision, the more likely Art. 22 GDPR applies.

MaRisk AT 4.3.5: Model Risk Governance Explicitly Applies to AI

BaFin's MaRisk — specified in Circular 05/2023 (BA) — contain their own module on model risks with AT 4.3.5, which explicitly also applies to AI. Paragraph 1: "The requirements of this module apply to models used for the processes regulated in this circular. They also apply to automated models, technology-enabled innovation and artificial intelligence." (BaFin Circular 05/2023 (BA), MaRisk AT 4.3.5).

Five requirements from AT 4.3.5 are particularly relevant in practice for AI personalization models:

Paragraph

Requirement

Para. 2

Model choice is the responsibility of the institution; plausibly justify assumptions; check appropriateness before use and regularly thereafter

Para. 3

Suitable procedures to ensure data quality; detect and rectify quality weaknesses

Para. 4

Appropriate regulations for using model results, including handling overrides

Para. 5

Regular validation; critical examination of model limits; analysis of accuracy, stability, consistency

Para. 6

Explainability explicitly required for AI models as well

Source: BaFin Circular 05/2023 (BA), MaRisk AT 4.3.5

Para. 6 clearly formulates the explainability obligation: "In addition to the targeted accuracy, attention must also be paid to sufficient explainability. This applies in particular to models that exhibit characteristics of technology-enabled innovation and artificial intelligence." (MaRisk AT 4.3.5). In terms of content, this coincides with the right to explanation under Art. 86 of the AI Act — making a model auditable for both purposes at the same time avoids double governance efforts.

The Governance Gap: Why This Is Relevant

These three sets of regulations run into a vacuum if no institutional framework exists to operationalize them. Remarkably: Only 14% of banks have a specific AI governance framework (McKinsey, Getting personal) — precisely the gap that the AI Act and MaRisk AT 4.3.5 address together: documented model choice, validation, explainability, ongoing review. Contractual obligations also exist for outsourced AI and CDP services: Art. 30(3)(e) DORA requires "unrestricted rights of access, inspection and audit" for critical functions, and lit. f additionally requires exit strategies with a binding transition period (DORA, Art. 30) — regardless of whether the AI component is operated internally or externally.

Practical Guardrails for Implementation

Four guardrails can be derived from the references cited above, which do not replace a final legal assessment, but can serve as a starting point for internal institutional assessment:

  1. Annex III Assessment Before Model Launch: Assess every personalization model related to creditworthiness or insurance pricing against Annex III No. 5 AI Act before going live — including the question of whether a profiling reference excludes the exceptions under Art. 6(3).

  2. Explainability as a Design Principle: Build models in such a way that they meet Art. 86 AI Act and Para. 6 MaRisk AT 4.3.5 at the same time — auditable, comprehensible scores instead of black-box outputs.

  3. Contact Frequency and Vulnerability Guardrails: Personalization logics for credit and overdraft offers should include mechanisms against the exploitation of economic weakness phases within the meaning of Art. 5(1)(b) AI Act.

  4. Technically Mapping the Right to Object: The right to object under Art. 21(2) GDPR against profiling-based direct marketing should be technically implemented in such a way that an objection reliably and verifiably ends processing.

Acceleraid's Prediction Engine & AI Framework is designed for explainable, auditable scores; the CDP & Data Governance module processes consent, data origin, and PII protection according to GDPR-by-design with German hosting; the Regulatory Reporting module supports MaRisk reporting as well as FINREP, COREP, and AnaCredit requirements (Acceleraid Platform). This does not replace your own legal review, but can serve as a technical basis for the guardrails.

AI Personalization in Banking: Regulation as a Framework, Not a Brake

The EU AI Act, GDPR, and MaRisk do not contradict effective AI personalization in banks — they formulate the conditions for it. Those who think about explainability, data quality, and governance from the very beginning not only avoid risk of fines, but also build the basis of trust that, according to part one of this series, decides the long-term success of personalization. This article does not replace legal advice; for the binding assessment of individual use cases, institutions should involve their legal and compliance function and, if necessary, external legal counsel.

Illustration: AI-generated. AI-supported content: In creating our articles, we use AI technologies and automated agents, including from Microsoft, Google, OpenAI, Anthropic, and other providers. Topics, technical direction, and final approval lie with our team.

We use cookies 🍪

Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent, we also use Google Analytics (analytics) and Leadfeeder (visitor identification). Learn more in our Privacy Policy.

Decline

Decline

Accept all

Accept all