AI Regulation Tracker / Banking and finance
DNB's SAFEST Principles Are the Dutch Supervisory Baseline for AI in Finance
These are supervisory expectations, not binding rules. De Nederlandsche Bank set out six principles for responsible AI in finance, soundness, accountability, fairness, ethics, skills, and transparency, in a 2019 discussion paper. On March 27, 2025, DNB reinforced them with a sector update on AI at insurers that flagged where AI can create prudential risk. Here is what actually binds and what does not.
De Nederlandsche Bank is the Dutch central bank and, together with the AFM, one of the two financial supervisors in the Netherlands. DNB is the prudential side, the regulator that worries about whether firms are financially sound and well run. Years before the EU AI Act existed in anything like its current form, DNB put out a paper telling the firms it supervises how it expected them to handle AI. That paper is titled General principles for the use of Artificial Intelligence in the financial sector, and it introduced an acronym the Dutch market has used ever since: SAFEST.
The paper is direct about what SAFEST stands for. In DNB's own words, the principles are divided over six key aspects of responsible use of AI, "namely (i) soundness, (ii) accountability, (iii) fairness, (iv) ethics, (v) skills, and (vi) transparency (or 'SAFEST')." That is the whole framework in one line. Each principle then gets a section with suggestions on how a firm can operationalize it inside its own organization, from model validation to board-level understanding of the tools in use.
Read the status precisely: this is guidance, not a rule
Here is the part that gets flattened in summaries, so I want to be exact. The SAFEST document is a discussion paper. DNB says so on the first page. It presents DNB's "preliminary view on a set of possible principles in this discussion paper" and invites comment. It is dated 2019. It is not a regulation, it did not go through a legislative process, and on its own it does not create a new legal obligation you can be fined for breaching. Anyone who tells you the Netherlands has a binding AI rulebook for finance because of SAFEST is overstating it.
That does not make it optional to ignore. Supervisory expectations from a prudential regulator carry real weight even when they are not law. They tell you what your examiner will ask about, what a good answer looks like, and where a weak answer will draw follow-up. And SAFEST does not float free of binding law. It reads existing duties through an AI lens and points back to the rules that already apply to financial firms, from the Financial Supervision Act to Solvency II to the GDPR. The EU AI Act now adds a genuinely binding layer on top of all of it. So the accurate framing is a stack: binding EU and Dutch law at the base, and DNB's SAFEST expectations telling you how DNB will judge your AI governance against that law.
Soundness carries the prudential weight
Of the six principles, soundness is the one a prudential supervisor cares about most, and DNB says as much. In the paper's own words, "From a prudential perspective, soundness is the aspect of AI that is of DNB's primary concern." Soundness means AI applications should be reliable and accurate, behave predictably, and operate within the boundaries of applicable rules, including non-financial rules like the GDPR.
What makes soundness more than a model-quality checklist is DNB's concern about correlation across firms. The paper flags that soundness "becomes particularly important when financial firms start to apply identical (or relatively similar) AI-driven solutions and systemic risks might arise." That is the concentration-risk point in plain terms, and it sits in the 2019 principles rather than in any later update. If a whole sector leans on the same handful of models, vendors, or data sources, a flaw is no longer one firm's problem. It can move across the market at once. For anyone thinking about foundation models and shared AI vendors in 2026, that 2019 sentence reads as ahead of its time.
The March 2025 insurers update: from surveying to examining
On March 27, 2025, DNB published a sector update, AI at insurers: opportunities and risks, based on a request for information sent to a selection of non-life, life, health, and reinsurers, followed by deeper conversations with several of them. It is not a new rule. It is DNB reporting what it found and telling the sector what it expects next.
The numbers are worth holding. Of the 36 insurers involved in the study, 15 reported using AI applications, in areas DNB chose specifically because it expected AI there to raise prudential risk. Those uses ran from analyzing unstructured data and estimating risk, to offering personalized products, to fraud detection and estimating claim amounts, with limited experimentation using AI to optimize capital and allocate investments. DNB reported that insurers rate financial risks lower than non-financial ones overall, but foresee financial risk in particular where AI is used to optimize investments and reserving. Reputational damage and business continuity rated higher for AI used in sales optimization, risk management, and customer experience.
Three things in that update matter for how you read DNB going forward. First, DNB said it would conduct deeper, risk-based examinations of a selection of insurers in the second half of 2025. That is the shift from surveying AI use to inspecting it. Second, DNB told insurers to manage not only the AI systems they build themselves but also the AI systems supplied by external parties, which is the vendor-risk edge of the same soundness concern. Third, DNB pointed insurers straight back to the SAFEST paper as the reference for responsible AI, which is why a 2019 discussion paper still functions as the live baseline. DNB also flagged that additional guidance from EIOPA was expected during 2025 and that the AI Act's requirements would phase in on top.
What this means for US banking and insurance groups
For a US institution, the question is whether DNB supervises any part of your group. Many large US banking and insurance groups run Dutch-authorized entities, subsidiaries, or branches, and those entities are supervised by DNB on the prudential side. Where that is the case, the SAFEST expectations already apply to how that Dutch entity governs its AI, regardless of what your US regulators do. You inherit the expectation, even if your headquarters never reads a DNB paper.
The practical move is to map your group's AI governance against the six SAFEST headings for any DNB-supervised entity, and to treat soundness and concentration risk as first-order questions rather than model-team detail. Be able to show your examiner that you know which models and vendors your Dutch entity depends on, whether those same dependencies are shared across peers, and what happens if a shared model behaves unexpectedly. If a Dutch insurer sits in your group, read the March 2025 update as notice that DNB is now examining AI use where it touches capital, investment, and reserving, and make sure your reserving and asset-allocation models can withstand that kind of look. None of this is triggered by a new binding rule. It is triggered by a supervisor that has told you, in writing and more than once, exactly what it will ask.
Questions professionals are asking
Is DNB's SAFEST framework a binding AI law?
No. SAFEST comes from a 2019 discussion paper, General principles for the use of Artificial Intelligence in the financial sector, that sets out DNB's preliminary view and supervisory expectations. It is not a regulation and creates no new statutory duty on its own. It sits alongside binding law such as the Financial Supervision Act, Solvency II, the GDPR, and now the EU AI Act.
What does SAFEST stand for?
It is DNB's acronym for six aspects of responsible AI use in finance: soundness, accountability, fairness, ethics, skills, and transparency. DNB says soundness is, from a prudential perspective, the aspect of AI that is of its primary concern.
What did the March 2025 AI at insurers update actually say?
Published March 27, 2025, it reported that of 36 insurers surveyed, 15 were using AI, mostly for risk estimation, personalized products, fraud detection, and claims estimation, with limited experimentation in capital and investment optimization. DNB said it would run deeper, risk-based examinations of selected insurers in the second half of 2025, told insurers to manage third-party AI, and pointed firms back to the SAFEST principles.
How does SAFEST treat concentration risk?
Through the soundness principle in the 2019 paper. DNB warns that soundness becomes particularly important when firms apply identical or relatively similar AI-driven solutions and systemic risks might arise. In plain terms, if many firms rely on the same models, vendors, or data, a single flaw can move across the market at once.
Does this affect US banking and insurance groups?
Yes, where the group has a Dutch-authorized bank, insurer, subsidiary, or branch supervised by DNB. Those entities already sit under DNB's SAFEST expectations regardless of US rules, and the March 2025 update signals DNB is now examining AI use, not just surveying it. Map your group's AI governance to the six SAFEST headings for any DNB-supervised entity.
RELATED BRIEFINGS
- Browse the full AI Regulation Tracker
- DNB SAFEST principles for AI in the financial sector (primary source, PDF)
- DNB AI at insurers: opportunities and risks, March 27, 2025 (primary source)
- The Netherlands' decentralized AI Act implementation
- EU supervisors on frontier AI, cyber, and DORA
- IAIS on AI and cyber underwriting for insurers
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how DNB's expectations and any binding requirement apply to your situation with qualified counsel in the relevant jurisdiction.