This week, Germany’s Federal Financial Supervisory Authority (BaFin) said it will begin monitoring financial entities’ use of AI under the EU AI Act.
“We will look into how banks, insurers and other financial entities use AI in direct connection with regulated financial activities,” Jens Obermöller, BaFin’s Director-General for Cyber Risks and Technology, explained in an interview published on the regulator’s website. “So we will step in when companies use AI for activities for which they need our authorisation — such as for banking and insurance transactions.” Systems used for other purposes, including recruitment, will fall within the remit of other authorities.
BaFin will take a risk-based approach, reviewing samples of applications used widely in areas it considers particularly relevant rather than examining every system. Monitoring begins now and will initially cover transparency requirements, prohibited AI practices, and measures to promote AI literacy among employees. “Starting in December 2027, we will also address high-risk AI,” Obermöller said.
High-risk systems include those used to evaluate individuals’ creditworthiness or credit scores and those used by life and health insurers for risk assessment and pricing. Obermöller said firms should understand how data and models interact in decision-making and formalize relevant processes and data governance before the high-risk requirements take effect.
Financial entities are incorporating the AI Act into existing governance, risk, and compliance structures, with frameworks established under the Digital Operational Resilience Act (DORA) providing a foundation. BaFin also plans to support regulatory sandboxes and real-world testing. “There is plenty of scope for innovation,” Obermöller said.
Firms that fail to comply could face fines of up to €35 million or 7% of annual turnover, Obermöller said. However, early engagement and cooperation should make such penalties exceptional, he added.
Join The Discussion
Sign in and be the first to comment.