BaFin has received new responsibilities for the supervision of artificial intelligence in the German financial sector. Since 29 July 2026, it has acted as market surveillance authority for AI systems that are directly connected to regulated financial activities. This includes, among others, banks, insurers and other financial institutions under BaFin supervision.
For financial institutions, this is an important turning point. AI governance is becoming part of ongoing supervision. AI systems are no longer merely an innovation, efficiency or IT topic. They are becoming a governance, risk and compliance topic that must be documented, controlled and auditable.
The key question is therefore no longer only: Where can AI create value? The more important question is: Can we prove where AI is used, which risks exist, which obligations apply, who is responsible and which controls are in place?
Key Takeaways
BaFin has been the market surveillance authority for certain AI systems in the financial sector since 29 July 2026. Its responsibility applies to AI systems that are directly linked to regulated financial activities.
This affects financial institutions under BaFin supervision, including banks, insurers and other regulated financial companies. In practice, this means that AI governance is moving closer to established supervisory expectations around risk management, compliance, internal control systems and auditability.
Initially, the focus is likely to include transparency obligations, prohibited AI practices and measures to ensure sufficient AI literacy among employees. From December 2027, BaFin is also expected to supervise high-risk AI systems in the financial sector, such as AI used in creditworthiness assessments or certain insurance pricing models.
For GRC teams, the message is clear: AI inventories, risk assessments, roles, controls, vendor governance and audit trails need to become robust and defensible.
Why BaFin’s New Role Matters
The EU AI Act is a horizontal regulation. It applies across sectors. At the same time, regulated industries are not starting from scratch. Existing supervisory structures are being connected with AI regulation, and this is exactly what is now happening in the German financial sector.
BaFin will supervise AI systems that are directly connected to regulated financial activities. As a result, AI Act compliance in banks, insurers, fintechs and other financial companies will become more closely linked to familiar supervisory practices: risk governance, documentation, management responsibility and internal controls.
This matters because AI in finance can affect sensitive decisions. AI can be used in customer communication, credit scoring, fraud detection, insurance risk assessment, pricing, customer classification, compliance monitoring, anti-money laundering or portfolio risk models. Many of these use cases touch consumer protection, data protection, discrimination risks, model risk, cybersecurity and operational resilience.
For GRC leaders, this creates a clear mandate. AI must become visible, manageable and auditable.
AI Governance Needs More Than a Policy
Many organisations already have AI policies or general guidelines for the use of generative AI. That is a useful starting point, but it is not enough for supervised financial institutions.
Supervisors do not only look for principles. They look for implementation. Financial institutions need to be able to show which AI systems are used, in which business process they operate, which regulatory role the company has, whether the use case is connected to a regulated financial activity and which risks arise for customers, market integrity, data protection or fundamental rights.
The same applies to transparency obligations, prohibited AI practices, human oversight, provider dependencies and training measures. It is not enough to state that AI is used responsibly. Companies need evidence that the relevant risks were assessed, that controls were defined and that responsibilities are clear.
AI governance therefore becomes a classic GRC process: identify, classify, assess, control, document, monitor and improve.
The First Step: A Reliable AI Inventory
Without an AI inventory, no financial institution can reliably determine which systems fall under BaFin’s market surveillance or other AI Act obligations. The inventory is the foundation of every serious AI governance structure.
A useful AI inventory should go beyond large models or central IT projects. It should also capture business-unit tools, external SaaS solutions, chatbots, analytics tools, agency services and AI functions embedded in existing applications.
The inventory should document the purpose of the AI system, the business process it supports, the responsible owner, the provider or internal development team, the user groups, the data involved, the connection to regulated financial activities and the initial classification under the AI Act. It should also capture data protection relevance, third-party dependencies, transparency obligations, controls, review cycles and available evidence.
In the financial sector, an AI inventory is not just a list. It is the basis for supervisory readiness.
Transparency Obligations as a Control Process
Since 2 August 2026, transparency obligations under Article 50 of the AI Act apply to certain AI systems. This includes, for example, interactive AI systems such as chatbots and certain AI-generated or AI-manipulated content.
For financial institutions, this is highly relevant. A chatbot on a bank website, an AI assistant in customer service or AI-generated customer communication can trigger transparency obligations. At the same time, the information provided to customers must be legally sound, understandable, consistent with privacy notices and operationally feasible.
This makes transparency more than a wording exercise. It is a control process. Companies need to know where customer-facing AI is used, who approved it, what information is provided to users, how changes are reviewed and which evidence is available.
A short disclaimer may be part of the solution. But the real GRC question is whether the company can prove that the obligation was identified, assessed and implemented correctly.
Prohibited AI Practices Require Early Scope Checks
BaFin’s supervisory role also makes the assessment of prohibited AI practices more important. Financial institutions should review AI use cases before they go live, especially where systems classify, influence, score or support decisions about individuals.
The risk is not limited to obviously problematic systems. Even well-intended applications can create compliance issues if they affect vulnerable customer groups, produce opaque scoring outcomes or shift decision-making in practice from humans to automated systems.
This is why AI use cases need an early scope and risk review. Companies should document whether a use case could fall into a prohibited category, whether fundamental rights or discrimination risks are involved and whether additional controls or restrictions are necessary. This review should not happen only once. AI systems change, data changes and providers update their models. Governance needs to account for that.
AI Literacy Becomes a Compliance Topic
The AI Act requires providers and deployers of AI systems to take measures ensuring an appropriate level of AI literacy among employees and other persons involved in the operation or use of AI systems on their behalf.
For financial institutions, this is especially important. Employees in compliance, risk, IT, customer service, product management, HR, sales and management need to understand what AI can do, where its limits are and which risks arise in their specific context.
AI literacy should therefore not be treated as a generic awareness module. It should be role-based. Customer service teams need to understand chatbot escalation and AI-generated responses. Risk teams need knowledge about model risk, data quality and validation. Compliance teams need to understand AI Act obligations, data protection and internal approvals. IT and security teams need to address monitoring, access controls and incident response. Management needs a clear view of risk acceptance and governance responsibilities.
For GRC teams, this creates a new evidence requirement. Companies need to show who was trained, when, on what topic and with which relevance to the AI systems they use.
High-Risk AI: More Time, but No Reason to Wait
BaFin is expected to supervise high-risk AI systems in the financial sector from December 2027. Examples may include AI systems used by banks for creditworthiness assessments or by insurers for certain individual risk assessments and pricing models.
That may sound like a distant deadline, but financial institutions should not wait. High-risk AI typically requires significantly more robust governance. This includes risk management, data quality, technical documentation, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.
Trying to retrofit these requirements shortly before the deadline will be difficult. Existing AI systems need to be identified, classified, documented and controlled early. This is particularly important for systems that already support important customer, risk or pricing decisions.
The practical challenge is that many AI systems will not sit neatly in one department. They may involve business owners, IT, external providers, data teams, risk management and compliance. Without a central governance structure, readiness will be fragmented.
The Link to Data Protection, DORA and Vendor Risk
AI governance in the financial sector does not stand alone. It overlaps with several existing GRC areas.
Data protection is one of the most important interfaces. Many AI systems process personal data. This means that legal bases, transparency obligations, data protection impact assessments, retention rules and data subject rights need to be considered.
Operational resilience is another key area. AI systems may support critical or important functions. In such cases, availability, integrity, incident response, testing, business continuity and third-party risk management become relevant. This creates a clear link to DORA.
Vendor risk management is equally important. Many AI systems are provided by external vendors, cloud platforms or specialised technology providers. Financial institutions need to understand dependencies, data flows, subcontractors, access rights, monitoring obligations and exit options.
Finally, model risk and internal controls need to be addressed. AI systems can support or influence decisions. Companies need to ensure that model changes, performance, bias, drift and error rates are monitored and that decisions remain explainable and controlled.
This shows why AI governance should not run next to the GRC system. It needs to become part of it.
Conclusion: BaFin Makes AI Governance in Finance Auditable
With BaFin’s new responsibility, AI Act compliance in the German financial sector becomes more concrete. AI systems that are directly connected to regulated financial activities are moving into the market surveillance remit of the financial supervisory authority.
For GRC leaders, this is a clear signal: AI governance must now move from general principles into auditable processes. The key elements are a reliable AI inventory, clear roles, risk assessments, transparency controls, AI literacy, vendor risk management and audit-ready evidence.
Companies that start early will not only reduce regulatory risk. They will also strengthen trust with customers, supervisors, management and business partners.
Zazoon helps financial institutions build BaFin-ready AI governance: from AI use case inventories and risk assessments to controls, evidence, audits and management reporting.
FAQ
What has changed at BaFin?
BaFin has become the market surveillance authority for certain AI systems in the German financial sector where those systems are directly connected to regulated financial activities.
Which companies are affected?
Affected companies include banks, insurers and other financial institutions under BaFin supervision.
Which AI systems are in scope?
Relevant AI systems may include chatbots, creditworthiness assessments, insurance risk models, fraud detection, compliance monitoring or AI-supported customer classification, provided they are connected to regulated financial activities.
Which obligations are particularly relevant now?
Short-term priorities include transparency obligations, prohibited AI practices and AI literacy measures. High-risk AI requirements will become especially important for many financial use cases at later stages.
Why is this a GRC topic?
Because AI supervision connects risks, controls, roles, data protection, DORA, vendor risk, documentation and audit trails. A standalone AI policy is not enough.
What should financial institutions do now?
They should build an AI inventory, classify use cases, assess BaFin and AI Act relevance, evaluate risks, define controls and document evidence centrally.
How does Zazoon support BaFin-ready AI governance?
Zazoon connects AI use cases, regulatory requirements, risks, controls, responsibilities, vendor reviews and evidence in one central GRC system. This makes AI governance traceable, efficient and audit-ready.
Table of Contents
- Key Takeaways
- Why BaFin’s New Role Matters
- AI Governance Needs More Than a Policy
- The First Step: A Reliable AI Inventory
- Transparency Obligations as a Control Process
- Prohibited AI Practices Require Early Scope Checks
- AI Literacy Becomes a Compliance Topic
- High-Risk AI: More Time, but No Reason to Wait
- The Link to Data Protection, DORA and Vendor Risk
- Conclusion: BaFin Makes AI Governance in Finance Auditable
- FAQ
- What has changed at BaFin?
- Which companies are affected?
- Which AI systems are in scope?
- Which obligations are particularly relevant now?
- Why is this a GRC topic?
- What should financial institutions do now?
- How does Zazoon support BaFin-ready AI governance?