BaFin AI Market Surveillance: New Powers Over Financial-Sector AI
Since 29 July 2026, BaFin has had an additional market-surveillance mandate for AI systems placed on the market, put into service or used by entities listed in section 2(3) KI-MIG where the system is directly connected with a regulated financial activity. This mandate sits alongside existing prudential and conduct supervision. BaFin may exercise the market-surveillance powers assigned by Regulation (EU) 2019/1020 and the AI Act within that remit.
The trigger is the German Gesetz zur Durchführung der europäischen Verordnung über Künstliche Intelligenz, whose Article 1 enacted the KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz (KI-MIG). Section 2(3) assigns BaFin market-surveillance responsibility for AI systems placed on the market, put into service or used by the listed BaFin-supervised entities where the system is directly connected with a regulated financial activity. The AI Act supplies the principal substantive obligations, while the KI-MIG assigns authorities, enforcement powers and German administrative-offence rules. The KI-MIG entered into force on 29 July 2026.
This is a supervisory-perimeter and governance change. For relevant high-risk systems, however, the AI Act creates formal registration and notification requirements. Article 49 requires providers to register Annex III systems, and Article 27 requires deployers of high-risk systems under Annex III points 5(b) and 5(c) to complete a fundamental-rights impact assessment and notify the market surveillance authority using the prescribed questionnaire template once those provisions apply. Firms must therefore assess scope, application dates, operator roles, registration and notification duties, and governance requirements.
Related reading: EU AI Act Compliance for Financial Institutions
The dates that now bind
The AI Act applies in stages. Most Article 5 prohibitions have applied since 2 February 2025, but Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) apply from 2 December 2026. Article 50 generally applies from 2 August 2026; providers of relevant synthetic-content systems placed on the market before that date have until 2 December 2026 to comply with Article 50(2). BaFin became the competent market-surveillance and administrative-fine authority within its statutory remit when the KI-MIG entered into force on 29 July 2026.
The high-risk timetable is split. Regulation (EU) 2026/1744, which entered into force on 27 July 2026, moved the application of Chapter III, Sections 1 to 3, other than Article 6(5), to 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III, and to 2 August 2028 for AI systems classified as high-risk under Article 6(1) and Annex I. Article 111(2) separately limits the treatment of high-risk AI systems placed on the market or put into service before 2 August 2026: the Regulation generally applies to those systems only if they undergo significant changes in their design from that date. Providers and deployers of high-risk AI systems intended for use by public authorities must in any case take the necessary compliance steps by 2 August 2030. The Article 5, Article 50 and legacy-system rules must therefore be assessed by provision and system.
What BaFin’s AI market surveillance covers
BaFin has described its mandate across three areas of the AI Act. It will monitor compliance with the prohibitions on certain AI practices. It will check the transparency obligations for AI systems intended to interact directly with natural persons, including Article 50(1)’s disclosure rule. And its surveillance covers high-risk AI systems, which for the financial sector means the models banks use to assess creditworthiness and the models insurers use to assess risk in life and health cover.
The boundary is functional: BaFin supervises AI used in direct connection with regulated financial activities. Where an AI system used by a BaFin-supervised firm is not directly connected with a regulated financial activity and no other special allocation applies, the Bundesnetzagentur (the Federal Network Agency) is the default market-surveillance authority under section 2(1) KI-MIG. A single institution can therefore have some of its AI supervised by BaFin and some by the Bundesnetzagentur, split on what each system actually does.
The legal basis: Article 74(6) and the German split
The German statute implements a choice the EU AI Act had already made. Article 74(6) of the AI Act provided that, for high-risk AI systems placed on the market, put into service, or used by financial institutions regulated under Union financial services law, the market surveillance authority is the national authority responsible for the financial supervision of those institutions, so far as the system is used in direct connection with the provision of those financial services. The German implementing law operationalises that choice and allocates the wider AI Act surveillance work between BaFin and the Bundesnetzagentur, with the Bundesnetzagentur acting as the central market surveillance authority and coordination point.
For credit institutions participating in the Single Supervisory Mechanism, Article 74(7) states that national market-surveillance authorities supervising institutions regulated under Directive 2013/36/EU should report without delay to the European Central Bank information that may be of potential interest to its prudential-supervisory tasks. Section 9(6) KI-MIG permits BaFin to transmit information under Article 74(7).
Which AI systems count as high-risk here
Annex III point 5(b) lists AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, except systems used to detect financial fraud. Point 5(c) lists AI systems intended for risk assessment and pricing in relation to natural persons in life and health insurance. Listing in Annex III does not end the classification analysis: Article 6(3) provides a derogation where the system does not pose a significant risk and meets one of the specified conditions, while systems that perform profiling of natural persons are always high-risk.
Point 5(b) excludes AI systems used for the purpose of detecting financial fraud. A system intended only for transaction-fraud detection therefore falls outside point 5(b); a system intended to evaluate creditworthiness or establish a credit score must be assessed under point 5(b) and Article 6(3). A dual-purpose system requires a documented analysis of each intended purpose. For a chatbot intended to interact directly with natural persons, Article 50(1) places the design-and-disclosure duty on the provider unless the AI interaction is obvious; chatbot status alone does not determine whether Annex III applies.
What this changes for reporting and governance teams
The near-term task is an AI inventory. Firms need to identify AI systems used in connection with regulated services, assess the currently applicable Article 5 and Article 50 duties, and determine whether any systems may fall under Article 6(2) and Annex III points 5(b) or 5(c). Chapter III, Sections 1 to 3 apply from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Article 6(1) and Annex I product-related high-risk systems, other than the Article 6(5) exception.
Much of the underlying documentation may already exist under adjacent regimes. Model risk management, which we cover in our note on AI model risk in prudential reporting, and the ICT and third-party governance firms maintain under DORA and the ECB’s ICT expectations, both touch the same systems, though neither discharges the AI Act duties by itself. BaFin has been explicit that responsibility for the use of AI sits with supervised firms and their management boards. Firms should assign documented senior-management accountability for the AI inventory and classification accordingly. Where a high-risk AI system is procured, provider and deployer obligations must be allocated by operator role under Articles 16, 25 and 26. A distributor, importer, deployer or other third party becomes the provider if it applies its name or trade mark, makes a substantial modification to the high-risk system, or changes an intended purpose so that the system becomes high-risk. Vendor documentation does not displace the deployer’s own obligations, including use, monitoring and human oversight.
Frequently Asked Questions
Our credit-scoring model is licensed from a vendor outside the EU. Does BaFin still supervise us?
BaFin’s market surveillance follows the use of the system by the supervised firm in connection with regulated financial services, so a German bank deploying a foreign vendor’s scoring model is within scope for its deployer obligations. The provider’s own AI Act conformity duties are a separate strand that a foreign provider may still owe when placing a high-risk system on the EU market.
Is a customer-service chatbot a high-risk system we have to treat like a credit model?
A chatbot sits under Article 50’s transparency obligation, which requires telling people they are dealing with an AI system, in force since 2 August 2026. Annex III high-risk classification applies only if the system performs a listed function such as creditworthiness assessment.
The high-risk date moved to December 2027. Can we pause AI Act work until then?
No. Most Article 5 prohibitions have applied since 2 February 2025 and Article 50(1) has applied since 2 August 2026. Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) apply from 2 December 2026. Chapter III, Sections 1 to 3 apply from 2 December 2027 for Article 6(2) and Annex III high-risk systems and from 2 August 2028 for Article 6(1) and Annex I high-risk systems, other than Article 6(5).
Related Articles
- EU AI Act Compliance for Financial Institutions: how the AI Act’s classification, transparency and high-risk duties map onto EU banks and insurers.
- AI Model Risk in Prudential Reporting: where model governance and supervisory expectations meet for AI-driven models.
- DORA, AI Risk and ICT Incident Reporting: the ECB’s expectations on AI and ICT risk that overlap with AI Act governance.
- BaFin on Tokenised Securities: The MiCAR and MiFID Perimeter: another case where BaFin has drawn a supervisory perimeter around new technology.
Key Takeaways
BaFin has been the market-surveillance authority since 29 July 2026 for AI systems placed on the market, put into service or used by entities within section 2(3) KI-MIG where the system is directly connected with a regulated financial activity. The Bundesnetzagentur is the default authority where KI-MIG does not assign another authority. Article 74(6) provides the EU default for qualifying high-risk systems used by financial institutions. Annex III point 5(b) covers creditworthiness and credit scoring, excluding systems used to detect financial fraud, and point 5(c) covers life and health insurance risk assessment and pricing; Article 6(3) must also be assessed. Most Article 5 prohibitions have applied since 2 February 2025, Article 50 generally since 2 August 2026, Annex III high-risk requirements apply from 2 December 2027, and Annex I product-related high-risk requirements apply from 2 August 2028. Immediate work should cover inventory, intended-purpose and operator-role classification, current Article 5 and Article 50 controls, and preparation for future registration and Article 27 notification duties.
Sources and References
- BaFin, “Market surveillance of AI: BaFin granted new powers” (press release, 29 July 2026): bafin.de
- BaFin, KI-Verordnung topic pages: bafin.de/ki-verordnung
- Bundesregierung, “Umsetzung der KI-Verordnung”: bundesregierung.de
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated version of 27 July 2026, including Articles 6, 25, 27, 49, 50, 74, 99, 111 and 113 and Annex III, EUR-Lex: eur-lex.europa.eu
- Regulation (EU) 2026/1744, amending Regulation (EU) 2024/1689, OJ L, 24 July 2026, EUR-Lex: eur-lex.europa.eu
- Germany, KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz (KI-MIG), 22 July 2026, BGBl. 2026 I Nr. 223, Gesetze im Internet
Where the 2 December 2027 clock leaves German firms
Classification work should begin now, but the legal dates must be recorded by provision and system. Most Article 5 prohibitions and Article 50(1) are already applicable; Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) apply from 2 December 2026. For systems classified as high-risk under Article 6(2) and Annex III points 5(b) or 5(c), Chapter III, Sections 1 to 3 apply from 2 December 2027, other than Article 6(5). The inventory should record intended purpose, operator role, Article 6 classification, applicable date, required registration or notification, and the competent authority under section 2 KI-MIG.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
