Germany's financial regulator BaFin began overseeing the use of artificial intelligence at the country's banks and insurers on Wednesday, wielding new powers granted by legislation that took effect the same day. The move gives the watchdog authority to fine firms that misuse AI, directly affecting how financial institutions handle customer data, credit decisions, and automated interactions.
New legal powers for BaFin
The expanded oversight stems from a law that came into force on July 29, 2026. BaFin can now order fines against companies that fail to meet transparency and anti-discrimination standards. The regulator's mandate is to protect fundamental rights when AI systems are deployed in financial services.
Monitoring AI transparency and prohibited practices
BaFin will focus on compliance with transparency rules for chatbots used with customers. It will also scrutinize high-risk AI systems, such as those that measure creditworthiness. The watchdog said it will ensure financial firms avoid prohibited AI practices, including the collection and analysis of sensitive personal information that could unfairly disadvantage people.
Financial institutions that rely on AI for Finance functions like credit scoring will need to demonstrate that their models do not lead to discriminatory outcomes. Similarly, insurers using AI for Insurance underwriting or claims handling face new scrutiny over how they process applicant data.
Fair access to financial services
"People have to be able to trust that their fundamental rights will be protected when AI is used. BaFin will ensure, for example, that everyone has fair access to financial services and that no one is discriminated against as a result of AI," said BaFin President Mark Branson.
The regulator's announcement makes clear that automated systems must not lock certain groups out of loans, insurance policies, or other products based on sensitive attributes.
Why this matters for finance professionals
For risk managers, compliance officers, and data teams, BaFin's new oversight means AI governance is no longer optional. Systems that measure creditworthiness or interact with customers must be auditable and transparent. Professionals who design or procure these tools should expect sharper questions from regulators about training data, bias testing, and customer notification. The law turns internal AI ethics discussions into enforceable requirements, with fines on the table for violations.
Your membership also unlocks: