Part of the AI Regulation News hub.
BaFin took over AI market surveillance for the German financial sector when the KI-MIG entered into force on 29 July 2026
The German implementing act did not create a new AI regulator for banks and insurers. It handed the job to the supervisor those firms already answer to, and BaFin says it will run the new surveillance alongside its ordinary prudential work.
Bottom line: Binding. The implementing act entered into force on 29 July 2026 and BaFin is now the market surveillance authority for AI systems that stand in direct connection with a regulated financial activity.
Who this affects: Compliance officers, model risk and IT risk functions, and management boards at BaFin-supervised and ECB-supervised banks, insurers and payment firms; issuers of significant asset-referenced tokens; the Versorgungsanstalt des Bundes und der Laender.
Issue date: Press release dated 29 July 2026, the day the act entered into force. First AI Act transparency duties apply from 2 August 2026; high-risk requirements from 2 December 2027.
What changed: Competence, not substance. The AI Act obligations already existed; the KI-MIG names who enforces them in Germany and splits the work between BaFin and the Bundesnetzagentur by subject matter.
Analysis: The split runs through the firm, not around it. A bank's credit scoring model sits with BaFin; the same bank's HR screening tool sits with the Bundesnetzagentur. One institution, two market surveillance authorities, and the boundary is the use case.
Primary sources: Bafin press release, 29 July 2026 · Bafin: KI-Marktueberwachung
- Instrument (EN)
- Act implementing Regulation (EU) 2024/1689, containing the AI Market Surveillance and Innovation Promotion Act (KI-MIG)
- Authority
- Bundesanstalt fuer Finanzdienstleistungsaufsicht (Bafin)
- Jurisdiction
- Germany
- Status
- In force
- Bindingness
- Binding national law; BaFin states it may impose fines for breaches of the AI Regulation
- Issue date / next deadline
- 29 July 2026 / transparency duties from 2 August 2026, high-risk requirements from 2 December 2027
- Scope trigger
- AI systems standing in direct connection with a regulated financial activity
- Residual competence
- Bundesnetzagentur, for AI uses without that connection
- Primary source
- https://www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Pressemitteilung/2026/pm_2026_07_29_ki_verordnung.html
What BaFin now supervises
On its own account, BaFin monitors three things from day one: whether the AI systems firms deploy contain practices prohibited under Article 5 of the AI Regulation, whether the transparency duties in Article 50 are met, and whether firms have taken measures under Article 4 to build AI literacy among their staff.
The transparency limb is the one that bites first. BaFin's example is a chatbot in customer communication: a person must be able to tell that they are interacting with AI and that content was generated by AI. Some of those duties, the authority notes, have to be taken into account already during the development phase of the system.
The literacy limb is easy to underrate. BaFin's own framing is that Article 4 is not a wholly new obligation but an extension of existing ones, and that what is new is mainly its reach: it captures not only classic model development and validation functions but in principle everyone who operates or uses AI systems.
The perimeter, and who is outside it
Competence is set by section 2(3) of the KI-MIG. BaFin lists the categories: financial undertakings supervised by BaFin or by the ECB, issuers of significant asset-referenced tokens, and the Versorgungsanstalt des Bundes und der Laender.
Membership of that list is not sufficient on its own. The system also has to stand in direct connection with a regulated financial activity. BaFin gives the counter-example directly: other AI applications, for instance in the personnel management of financial undertakings, fall within the remit of the Bundesnetzagentur.
So a supervised bank can hold two AI supervisors at once. Nothing in the press release suggests firms get to pick which one applies.
December 2027 and the two Annex III entries
From 2 December 2027 BaFin will also monitor compliance with the high-risk requirements. Its market surveillance page names the two Annex III number 5 entries it means: systems intended for creditworthiness evaluation and credit scoring of natural persons, excluding systems used to detect financial fraud, and systems intended for risk assessment and pricing in relation to natural persons for life and health insurance.
That fraud-detection carve-out is worth reading twice. A scoring engine that decides whether a customer gets credit is in. A model whose job is spotting fraud is, on this listing, out of the high-risk category, which does not mean it is out of the Article 5 or Article 50 analysis.
BaFin advises firms not to wait. Its stated position is that even though the high-risk requirements apply only from 2 December 2027, financial undertakings should engage with them early enough to meet them on time.
Governance: BaFin points at DORA
The practical starting point BaFin offers is an inventory. Firms should have an overview of the AI systems they use and know how far the Regulation applies to them, and the authority suggests they orient themselves on the inventory of information and ICT assets already required by DORA.
Beyond that, the guidance is to fold the AI Regulation into existing governance, risk and compliance structures rather than build a parallel one. The established regulatory framework of the financial sector, and DORA above all, is the base BaFin expects firms to build on.
Mark Branson's framing in the press release puts the allocation plainly: transparency, freedom from discrimination and effective risk management are central; decisions must remain correctable and reversible by humans; and responsibility for the use of AI lies with the supervised firms and their management boards.
What we did not verify
We opened the BaFin press release of 29 July 2026 and the BaFin KI-Marktueberwachung supervision page, both in German, and took every fact and quotation from those two pages.
We did not open the consolidated text of the KI-MIG in the Bundesgesetzblatt, and we did not read section 2(3) in the original. The list of covered entities here is BaFin's summary of that provision, not our reading of it.
We make no claim about how BaFin will exercise its fining powers, about the treatment of any specific model, or about where the boundary falls for a system that serves both a regulated financial function and an internal one. The press release does not address that case.
Competence questions are compliance questions. Before a German financial firm can answer whether an AI system complies, it has to answer which authority is asking, and the KI-MIG makes that turn on the use case rather than on the entity. Build the inventory BaFin points to, tag each system with its regulated-activity nexus, and you have answered both questions at once.
Source File
Open the BaFin press release of 29 July 2026 and confirm the date of entry into force, the Bundesnetzagentur carve-out for personnel management applications, and the staged dates of 2 February 2025, 2 August 2026 and 2 December 2027. Then open the BaFin KI-Marktueberwachung page and confirm the section 2(3) entity list and the two Annex III number 5 entries.
Die Verantwortung fuer den Einsatz von KI liegt bei den beaufsichtigten Unternehmen und ihren Geschaeftsleitungen. [Responsibility for the use of AI lies with the supervised undertakings and their management boards.] ยท Mark Branson, Bafin President, 29 July 2026
FAQ
Does the KI-MIG create new obligations for banks and insurers?
Not on BaFin's account. The substantive duties come from the AI Regulation. What the implementing act does is designate which German authority supervises which AI systems, and the press release presents BaFin's role as an extension of its mandate rather than a new rulebook.
Is BaFin the only AI supervisor a German bank deals with?
No. BaFin's remit stops at AI systems in direct connection with a regulated financial activity. The press release names personnel management applications as an example of what falls to the Bundesnetzagentur instead.
What applies before December 2027?
BaFin lists prohibited practices, which have applied since 2 February 2025, the first transparency obligations from 2 August 2026, and the Article 4 AI literacy measures. The high-risk requirements are the part that starts on 2 December 2027.
Can BaFin fine a firm under the AI Regulation?
The press release states that BaFin can impose fines for breaches of the AI Regulation. It gives no figures, no procedure and no enforcement examples, and we do not extrapolate any.
Related briefings
- Germany: KI-MIG and the Bundesnetzagentur covers the horizontal enforcement architecture the same Act sets up, including the coordination centre at the Bundesnetzagentur. That page was corrected on August 21, 2026 to reflect the Act having been in force since July 29, 2026. This page has carried the in-force date since it was published.
- Germany: implementing act and BaFin carve-outs
- EU: Article 50 transparency from 2 August 2026
- CPAs and finance hub
- AI Regulation News hub
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.