Regulation & Compliance
BaFin Now Monitors AI in Finance: What Applies to Customer-Facing AI Since July
BaFin has been the AI market surveillance authority since 29 July 2026. What applies now to chatbots, what follows in December 2027, what banks should do.
•
acceleraid Redaktion
5 min read

Since 29 July 2026, Germany's Federal Financial Supervisory Authority (BaFin) has had a new role: it is the market surveillance authority for artificial intelligence (AI) in the financial sector. With the entry into force of the national implementing act for the EU AI Act, the AI Market Surveillance and Innovation Promotion Act (KI-MIG), BaFin now monitors, according to its press release, AI systems "directly connected to a regulated financial activity". For banks using AI in customer interactions, this changes less about the rules than about who checks compliance with them. This article sets out what has applied since July, what follows from December 2027 and which preparations make sense now.
Surveillance, not supervision
BaFin itself insists on a distinction. In the words of Jens Obermöller, who is responsible for the topic at BaFin, the mandate under the AI Act is "not supervision. It is surveillance." In an interview with BaFinJournal he describes the approach as "pragmatic and risk-oriented": the authority carries out spot checks at particularly relevant points and does not inspect every single AI system. Unlike ongoing banking supervision, there is no full review of all applications, but targeted sampling with tangible consequences: violations can attract fines of up to 35 million euros or 7 percent of annual turnover.
BaFin President Mark Branson framed the change in the press release as follows: "The AI Act complements the existing regulation of the financial market." And: "Responsibility for the use of AI lies with the supervised companies and their management boards." That matches the line taken by the European Central Bank (ECB). Pedro Machado of the ECB's Supervisory Board said in a speech in February 2026 that more than 85 percent of large banks under European supervision already use AI, and that AI does not dilute responsibility; if anything, it raises the bar.
What has been monitored since July
The scope of responsibility is set out in Section 2(3) of the KI-MIG. According to BaFin's topic page, it covers three areas that apply immediately:
Prohibited practices under Article 5 of the AI Act, such as manipulative techniques or exploiting the vulnerabilities of specific groups; these bans have applied since 2 February 2025.
Transparency obligations under Article 50, in force since 2 August 2026. They concern AI systems that interact directly with people, meaning chatbots and voice assistants in customer communication. Customers must be able to recognise that they are talking to an AI.
AI literacy under Article 4, the obligation to ensure that employees and contracted persons who operate or use AI systems have sufficient knowledge and training.
Anything not directly connected to a regulated financial activity, such as AI in a bank's human resources function, falls under the Federal Network Agency (Bundesnetzagentur). A bank therefore faces different surveillance authorities for different applications.
What follows from December 2027
According to BaFin, the requirements for high-risk AI systems apply from 2 December 2027. For banks, the relevant provision is Annex III, point 5(b) of the AI Act: systems for assessing the creditworthiness and credit scores of natural persons, with the exception of systems used to detect financial fraud. For insurers, point 5(c) applies, covering risk assessment and pricing in life and health insurance. According to a compilation by IT-Boltwise, core high-risk obligations under the AI Act are shifting in part to December 2027 and August 2028, and the transitional rules under Article 111 could extend further for systems already in operation. The deadlines are moving; the direction is not.

What this means for customer-facing AI
For most customer-facing AI applications in a bank, such as service chatbots, reply suggestions for advisers or personalised outreach, the transparency obligation has been the main requirement since August 2026. It is manageable but not trivial: the disclosure must be present on every channel, including where an AI system drafts texts in the background that then appear as a message from the bank. The harder part is the boundary with the high-risk category: as soon as customer-facing AI makes or prepares statements about creditworthiness, for instance in an application dialogue, it moves into the area that from December 2027 comes with conformity assessment, data governance, human oversight and documentation.
BaFin recommends integrating the requirements early into existing governance, risk and compliance structures, and names DORA (Digital Operational Resilience Act, the EU regulation on digital operational resilience) as the foundation. Specifically, it advises financial companies to keep an inventory of their AI systems, modelled on the DORA inventory of information and ICT assets. In our view, this inventory is the decisive first step: it forces a bank to record, for every customer-facing application, which decisions it influences, which data it uses, who owns it and which risk class it falls into. Without that mapping, neither the transparency obligation can be implemented cleanly nor the high-risk deadline planned.
Dialogue with the authority is not uncharted territory either. According to BaFin, the AI Roundtable with the financial industry, the Deutsche Bundesbank, the Federal Office for Information Security (BSI) and the Federal Network Agency has existed since 2023. Banks that participate there or through their associations learn early where the spot checks will land.
Five takeaways
Since 29 July 2026, BaFin has monitored AI systems directly connected to a regulated financial activity. The approach is sample-based and risk-oriented, with fines of up to 35 million euros or 7 percent of annual turnover.
Three areas apply immediately: prohibited practices (Article 5), transparency obligations for chatbots and assistants (Article 50, since 2 August 2026) and AI literacy of staff (Article 4).
High-risk obligations for creditworthiness assessments follow from 2 December 2027; transitional rules may shift the deadlines, but not the requirements.
AI in human resources falls under the Federal Network Agency. A bank therefore needs to map every AI application to the responsible authority and risk class.
The AI inventory recommended by BaFin, modelled on the DORA inventory, is the first concrete step and the basis for all further obligations.
Illustration: AI-generated. AI-assisted content: We use AI technologies and automated agents in the creation of our articles, including from Microsoft, Google, OpenAI, Anthropic and other providers. Topics, editorial direction and final approval remain with our team.