Germany's financial regulator BaFin has been designated the market surveillance authority for artificial intelligence systems used by banks, insurers, investment firms and other entities under its supervision, under the German AI Act Implementation Act (KI-MIG) that entered into force on July 29, 2026. The mandate lets BaFin check whether supervised firms comply with the EU AI Act (Regulation (EU) 2024/1689) for AI systems tied directly to a regulated financial activity, and impose fines where they do not.
BaFin President Mark Branson framed the move as complementing existing financial-market rules. "The AI Act supplements the existing regulation of the financial market. It creates a framework in which companies can drive innovations forward responsibly," he said. The designation had been awaited as the national precondition before the EU's August 2, 2026 high-risk and Article 50 transparency milestones, and was published in BaFin's press release of July 29, 2026.
Who falls under BaFin's AI surveillance, and what does it cover?
BaFin's remit covers credit institutions, insurers and other financial undertakings under its supervision, but only for AI systems used in direct connection with a regulated financial activity. In practice that brings three AI Act duty sets into BaFin's sight: transparency obligations for AI that interacts directly with people, such as customer-facing chatbots (Article 50); the Article 5 prohibitions on certain AI practices, applicable since February 2, 2025; and high-risk AI systems, including the creditworthiness checks banks use and the risk-assessment models insurers run for life and health insurance.
BaFin will align its AI market surveillance with its ongoing enterprise supervision, Branson said, with transparency, freedom from discrimination and effective risk management as the central expectations. Decisions must remain correctable and reversible by humans, he stressed, and responsibility for AI use stays with the supervised firms and their management bodies.
What must financial firms do, and by when?
The AI Act's obligations apply in staggered stages, and BaFin's surveillance activates against each as it bites. Firms should map their AI inventory against the ladder now.
| AI Act milestone | Date | What BaFin will check |
|---|---|---|
| Prohibited AI practices (Article 5) | February 2, 2025 | No prohibited systems in use, including those collecting and scoring sensitive personal data in ways that cause unjustified disadvantage |
| Article 50 transparency (chatbots, emotion recognition) | August 2, 2026 | Customers told when they interact with AI; generated content labelled |
| High-risk AI (Annex III, including credit scoring and insurance risk assessment) | December 2, 2027 | Risk management, data governance, human oversight, logging and conformity for high-risk systems |
How does BaFin's AI remit split from the Bundesnetzagentur?
The KI-MIG installs the Bundesnetzagentur (BNetzA) as Germany's central AI market surveillance and notifying authority, hosting the Koordinierungs- und Kompetenzzentrum fur die KI-Verordnung (KoKIVO). BaFin is the sectoral surveillance authority for financial services under section 2(3) KI-MIG. The dividing line is functional: BaFin handles AI tied to a regulated financial activity; other AI applications at the same firms, such as HR or personnel-management tools, fall to BNetzA. Firms should not assume one internal AI register maps cleanly to one regulator.
What fines and enforcement can BaFin impose?
BaFin can impose fines for breaches of the AI Act. Under Article 99 of the AI Act, applied through section 15 KI-MIG together with section 30 of the German Administrative Offences Act (OWiG), the most serious violations, including breaches of the Article 5 prohibitions, carry fines of up to EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher. BaFin has signaled it will run AI market surveillance alongside, not instead of, its existing prudential and conduct supervision, with the KI-MIG statute (BGBl. 2026 I Nr. 223) as the national basis.
Take advantage of this real-time watch
For compliance and risk leads at BaFin-supervised firms, the checklist is concrete: confirm whether any in-house or vendor AI system touches a regulated financial activity and route it to BaFin's perimeter; verify Article 50 disclosure for every customer-facing chatbot before August 2, 2026; screen current AI use against the Article 5 prohibitions already in force; and build the governance, data and human-oversight scaffolding high-risk credit and insurance AI will need by December 2, 2027. Continuous, per-jurisdiction monitoring surfaces the moment a national regulator like BaFin publishes this kind of designation.


