AI Regulation Tracker / Financial services
BaFin Publishes Guidance on ICT Risks When Financial Firms Use AI
Non-binding, but it tells you how Germany reads DORA for AI. On December 18, 2025, Germany's financial supervisor BaFin published guidance on managing information and communication technology risks when regulated financial entities use artificial intelligence. It is an orientation aid, not a new rule, and it maps the whole AI lifecycle onto the binding obligations firms already carry under the EU Digital Operational Resilience Act.
Germany's financial supervisor has put its cards on the table about AI. On December 18, 2025, BaFin published a piece of guidance on how regulated financial entities should manage information and communication technology risks when they use artificial intelligence. The document is what German regulators call an Orientierungshilfe, an orientation aid. That word matters. It is not a statute, not a regulation, and not an enforceable rule in its own right. It is BaFin telling supervised firms how it expects them to think, and by extension how it will judge them when it comes to look.
The reason this lands with weight even though it is non-binding is the framework it sits on top of. The EU Digital Operational Resilience Act, DORA, is binding law and has applied to financial entities since January 2025. DORA already requires firms to manage ICT risk, keep tight control of ICT third-party providers, and stay operationally resilient. In BaFin's own words, the guidance is intended to "help financial entities implement the regulatory requirements under the Digital Operational Resilience Act (DORA) and manage their ICT risks effectively when using AI." So the guidance does not invent a new obligation. It shows how the obligations you already carry apply once AI enters the picture.
What does the guidance actually cover?
The core idea is that AI does not get its own separate risk silo. It runs through the ICT risk you already manage, and BaFin wants firms to trace it across the entire lifecycle of an AI system. That means data acquisition, model development, provision and deployment, ongoing operation, and eventual retirement. Security and resilience are expected at every one of those phases, not just at go-live. BaFin gives, in its framing, "particular consideration to ICT risk management and ICT third-party risk management," which is the tell for where the supervisor is most worried. A great deal of AI in finance is bought in or built on external models, cloud, and data, and that is precisely the third-party exposure DORA was written to control.
The guidance is aimed principally at two populations: institutions subject to the Capital Requirements Regulation, which is the banking side, and insurers supervised under Solvency II. It also reflects industry experience with AI rollouts and points firms toward the relevant DORA technical standards, including the regulatory technical standards on ICT risk management and on subcontracting ICT services that support critical or important functions. In other words, it connects the AI conversation back to the specific DORA instruments a compliance team is already supposed to be operating against.
Read the status precisely: this is guidance, not a new rule
I want to be exact here because it is easy to oversell. Nothing in this document creates a new legal duty. It does not "require" or "mandate" anything that DORA did not already require. What it does is remove the excuse of ambiguity. Once a supervisor has written down how it expects AI to be governed under an operational-resilience regime, a firm that ignores that view is choosing to diverge from the supervisor's stated expectation, and that is a conversation you do not want to have during an examination. Guidance of this kind tends to become the practical benchmark long before anyone tests it in a formal proceeding, because supervisors examine against their own published expectations.
Why should US finance professionals care about a German aid?
Two reasons. First, reach. US banks, insurers, and asset managers with EU subsidiaries, branches, or EU-facing services are inside DORA's perimeter, and BaFin is one of the largest supervisors interpreting it. If you touch the German or wider EU financial market, this is the lens you will be read through. Second, direction of travel. US operational-resilience and model-risk expectations, from the banking agencies to insurance regulators, run on the same instincts: govern the vendor, document the lifecycle, prove human oversight of the model. A US risk officer who wants to see where AI governance in finance is heading can learn a lot from how a serious EU supervisor is bolting AI onto an existing resilience regime rather than writing a standalone AI rulebook.
The practical move is not to panic or to translate this into US policy line by line. It is to check that your AI inventory, your model documentation, and your third-party risk assessments already speak the language BaFin is using: lifecycle coverage, ICT third-party control, and demonstrable resilience of the AI systems that touch critical functions. If your EU entities cannot show that today, this guidance is the polite early warning that a supervisor will expect it tomorrow.
Questions professionals are asking
Is BaFin's AI guidance legally binding?
No. It is an orientation aid (Orientierungshilfe) published on December 18, 2025, setting out supervisory expectations. It does not create a new legal obligation on its own. The framework it interprets, the EU Digital Operational Resilience Act, is binding law, so the guidance shows how to meet duties firms already have.
Who does it apply to?
It is aimed mainly at financial entities BaFin supervises: banks subject to the Capital Requirements Regulation and insurers under Solvency II, along with their ICT and AI third-party providers. It is written for the compliance, risk, and audit teams inside those firms.
How does it connect to DORA?
DORA requires financial entities to manage ICT risk, control ICT third parties, and stay operationally resilient. The guidance maps those binding requirements onto AI, expecting firms to manage ICT risk across the full AI lifecycle, from data acquisition and model development through operation and retirement, with particular attention to third-party risk.
Does it affect US financial firms?
Indirectly but really. US banks, insurers, and asset managers with EU subsidiaries, branches, or EU-facing services fall inside DORA's scope, and BaFin is a major interpreter of it. Even firms with no EU footprint can use it as a preview of how AI governance is being folded into operational-resilience supervision.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how DORA or any supervisory guidance applies to your situation with qualified counsel in the relevant jurisdiction.