No spam - just the latest insights!
Join over 30,000 industry professionals who subscribe for free
Subscribe for free!
We'll never share your information or send you spam
Dr. Joachim Jung is a Partner at Möhrle Happ Luther and specialises in AI, data protection, intellectual property and emerging technologies. He advises established companies, high-growth businesses and investors on the legal and regulatory challenges arising from digital transformation, AI deployment and data-driven business models. As a Certified Specialist in Intellectual Property Law and Certified Data Protection Officer, he combines deep expertise in technology, privacy and regulatory compliance. Dr. Jung regularly supports clients in highly regulated industries, including financial services, healthcare and digital platforms, where innovation, data governance and AI regulation increasingly intersect.
Axel von Goldbeck is a Partner at Möhrle Happ Luther, focusing on financial regulation, capital markets, digital assets and blockchain-based financing structures. He advises financial institutions, corporates, fintechs and investors on innovative financing solutions, tokenisation projects and regulatory frameworks for digital business models. Before joining Möhrle Happ Luther, he held senior positions at J.P. Morgan, White & Case, Luther and DWF Germany and served as Chief Executive of the German Property Federation (ZIA). With extensive experience at the intersection of finance, regulation and emerging technologies, he regularly advises on tokenised securities, crypto assets and digital capital markets.
The use of artificial intelligence (AI) in the banking and financial services sector has undergone dynamic development in recent years. AI applications have evolved from experimental technologies into integral components of the business model of many financial institutions. According to recent reports by the Association of German Banks, more than two thirds of banks in the German market already use AI applications. The financial industry expects AI to generate a significant increase in revenue over the coming years, with a 22 percent reduction in operational costs forecast by 2030. This technological transformation is, however, accompanied by a parallel development of the regulatory framework, which aims to harness the opportunities offered by AI while simultaneously controlling the associated risks. This article provides an overview of current and emerging legal developments at European and national level.
The provisions of the AI Regulation do not all apply at once. Instead, they are being phased in over several years. The first set of rules, covering general principles and the prohibition of certain unacceptable AI practices, has applied since February 2025. A second set of rules, covering AI models with broad, general-purpose capabilities and related oversight arrangements, has applied since August 2025. The remaining rules, including the detailed requirements for high-risk AI systems, were originally due to apply from August 2026 (or, for certain AI embedded in already-regulated products, from August 2027). However, a subsequent EU amendment that took effect in July 2026 (commonly referred to as the “Digital Omnibus on AI”) pushed these later deadlines back further: the requirements for high-risk AI systems generally now apply from December 2027, and those for AI embedded in regulated products now apply from August 2028. The earlier rules on general principles, prohibited practices and general-purpose AI models were not affected by this postponement and remain in force on their original timeline.
The AI Regulation follows a risk-based approach that distinguishes between different categories of AI systems. Article 5 generally prohibits certain AI practices, including systems for subliminal influence, the exploitation of vulnerabilities of certain groups of persons, social scoring systems, and AI systems for the risk assessment of natural persons with regard to criminal offences. These prohibited practices have already been banned since 2 February 2025.
Of particular relevance to the financial sector is the classification of AI systems as “high-risk AI systems” pursuant to Article 6 in conjunction with Annex III of the AI Regulation. The AI Regulation classifies, for example, AI-supported creditworthiness assessments as a high-risk area under Article 6(2) in conjunction with Annex III paragraph 5(b). High-risk AI systems are subject to strict requirements under Articles 8 to 15 of the AI Regulation, including the establishment of a risk management system, data governance requirements, technical documentation, record-keeping through automatic logging, transparency and provision of information to deployers, human oversight, and accuracy, robustness and cybersecurity. Providers and deployers are subject to further obligations under Articles 16 to 27, including a quality management system, conformity assessment, EU database registration under Article 49, and, for certain deployers, a fundamental rights impact assessment under Article 27. As set out above, these obligations for stand-alone high-risk systems under Annex III, originally scheduled to apply from 2 August 2026, now apply from 2 December 2027 following the Digital Omnibus on AI.
Another important European development is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (the “DORA Regulation”), which became fully applicable on 17 January 2025. DORA establishes a comprehensive framework for ICT risk management in the financial sector, which also covers the use of AI (Art. 64 DORA Regulation). The Federal Financial Supervisory Authority (BaFin) has published guidance in this regard to support financial undertakings in implementing the DORA requirements when using AI. With the implementation of DORA, BaFin’s circular on the “Supervisory Requirements for IT in Financial Institutions” (BAIT) was repealed with effect from 17 January 2025.
At European level, enforcement of the AI Regulation is the responsibility of the newly established European Artificial Intelligence Office, which is located within the European Commission (Commission Decision of 24 January 2024 establishing the European Artificial Intelligence Office). This office develops the Union’s expertise and capabilities in the field of the AI Regulation and performs tasks relating to market surveillance and control of general-purpose AI systems.
At national level, Germany has taken an important step towards implementing European requirements with the Act on the Digitalisation of the Financial Market (FinMaDiG). The FinMaDiG entered into force on 30 December 2024 and consolidates the necessary provisions for implementing the European regulations in the field of digital finance. To implement the DORA Regulation and the DORA Directive, targeted amendments were made to the German Banking Act and to a number of other sector-specific statutes.
As early as 2021, BaFin made an important contribution to the regulation of AI use in the financial sector with its “Principles for the Use of Algorithms in Decision-Making Processes”. These principles set out preliminary considerations regarding minimum supervisory requirements for the use of AI and serve as guidance for financial market participants supervised by BaFin. In this context, BaFin defines AI as a combination of big data, computing resources and machine learning.
The BaFin principles include overarching principles such as the clear responsibility of the management board, adequate risk and outsourcing management, the avoidance of bias in algorithm-based decision-making processes, and the exclusion of legally prohibited differentiations. The management board is responsible for company-wide strategies and guidelines on the use of algorithm-based decision-making processes and for establishing risk management adapted to the use of AI.
BaFin has also published guidance on ICT risks in the use of AI in financial undertakings, which is intended in particular to support CRR institutions and Solvency II insurance undertakings in implementing the DORA requirements. This guidance addresses ICT risk management and ICT third-party risk management, including the Delegated Regulation on ICT risk management and the Delegated Regulation on the subcontracting of ICT services.
The German legislative process implementing the AI Regulation has since been completed. On 29 July 2026, the “Act on the Market Surveillance and Innovation Promotion of Artificial Intelligence” (KI-Marktüberwachungs- und Innovationsförderungsgesetz, “KI-MIG”) entered into force. Under the KI-MIG, the Federal Network Agency (“Bundesnetzagentur”) is the central coordination and competence centre, notifying authority and, in most sectors not otherwise covered, the competent market surveillance authority, while BaFin retains supervisory responsibility for AI systems used in connection with regulated financial activities of the supervised institutions listed in the Act, and existing sector-specific market surveillance authorities (e.g. in fully harmonised product areas) continue to be used to avoid duplicate structures (one-stop-shop principle).
Financial undertakings use AI along the entire value chain: credit institutions use AI in sales to predict customer churn, while in lending AI applications can support case handlers in examining annual financial statements. In fund management, AI is used to summarise large volumes of analyst reports on investment instruments.
Insurance undertakings use interactive AI assistants (chatbots) in sales and customer communications. Product pricing can be tailored more precisely to insured risks by means of complex models, potentially using real-time data (dynamic pricing or telematics). In underwriting, AI applications can assist in assessing risks. Automated input management allows a large number of incoming documents to be routed efficiently. In claims management, insurers use AI applications to support claims handlers in claims settlement, for example in the automated payment of small claims. In benefit processing, AI applications are used for fraud detection.
Specific use cases also include stock market forecasts, market analyses, sentiment analyses, algorithmic trading, portfolio management, risk management, compliance, insolvency forecasts, modelling of creditworthiness assessments (credit scoring and rating), lending, robo-advising, chatbots and virtual assistants. Other typical areas of application include the creation of scores, automated handling of anti-money laundering processes, algorithmic trading and portfolio management
Across sectors, the use of AI assistants can be observed, most of which are large language models that process and generate unstructured data such as text and images. Such assistance systems can be used broadly to create presentations, program code or videos. The size of the AI fintech market is estimated at USD 44.08 billion in 2024 and is expected to reach as much as USD 50.87 billion by 2029.
The use of AI in the financial sector also entails significant challenges and risks. AI applications carry risks of misuse, breaches of data protection requirements, inadequate data infrastructure, behavioural manipulation of persons, lack of transparency in decision-making, and vulnerability to cyberattacks. A particular problem is the so-called “black box” nature of many AI systems. Since AI can produce results that even developers cannot fully understand, this creates a transparency issue that is particularly critical in the highly regulated financial sector.
AI algorithms also carry the risk of adopting, reinforcing or expanding existing discrimination. This becomes particularly vivid in the assessment of the creditworthiness of natural persons by means of AI. An AI system learns on the basis of the empirical data that its developer provides to it. Persons belonging to a group that has historically had difficulty obtaining credit will initially also be classified by the AI system as risky candidates. This may lead to violations of the General Equal Treatment Act and of fundamental rights.
The AI Regulation addresses these challenges through various requirements. Article 4 requires providers and deployers of AI systems to take measures to ensure, to the best of their ability, that their staff and other persons dealing with the operation and use of AI systems on their behalf have a sufficient level of AI literacy.
Strict transparency obligations apply to high-risk AI systems. Under Article 13 of the AI Regulation, high-risk AI systems must be designed to be sufficiently transparent to enable deployers to interpret and appropriately use the system’s output, and providers must supply instructions for use accordingly. Deployers of certain high-risk systems must, under Article 26(11), inform natural persons where the system is used to take or assist in decisions concerning them. In addition, Article 86 grants persons affected by a decision based on the output of certain Annex III high-risk AI systems, where that decision produces legal effects or similarly significantly affects them, the right to obtain from the deployer a clear and meaningful explanation of the role of the AI system in the decision-making procedure and the main elements of the decision taken. The AI Regulation also contains extensive requirements regarding data quality and data governance under Article 10 in order to avoid bias and discrimination.
The use of AI in the financial sector is also subject to the data protection requirements of the General Data Protection Regulation (GDPR). AI systems often process large quantities of personal data in order to recognise patterns and make predictions. This raises questions regarding the lawfulness of data processing, data subject rights and the transparency of data processing.
In this context, Article 22 GDPR is particularly relevant as it gives individuals the right not to be subject to a decision made purely by a computer, without any human involvement, if that decision has legal or similarly significant effects on them. This applies unless the decision is needed to enter into or carry out a contract, is allowed by law, or the person has clearly agreed to it. Even then, the person must still be able to ask for a human to review the decision, explain their side, and challenge the outcome.
This is highly relevant for AI-supported credit decisions and other automated decision-making processes in the financial sector: in 2023, the Court of Justice of the European Union ruled that automatically calculating a person’s credit score already counts as such a decision if a bank relies heavily on that score when deciding whether to grant credit. As of today, the GDPR itself has not been changed to reflect the rise of AI. The EU has proposed adjustments as part of the European Commission’s Digital Omnibus proposal of 19 November 2025, but, unlike the AI-Act-specific part of the Digital Omnibus package, these GDPR amendments had not been adopted as at the date of this article and remain under negotiation in the Council and the European Parliament.
In its principles, BaFin emphasises that the focus of the supervisory authorities is not on the algorithm itself, but on the entire decision-making process based on the algorithms. This is also consistent with the data protection approach, which does not regulate the technology as such, but rather its use in the specific context.
Liability for damage caused by the use of AI in the financial sector is a complex legal question that has not yet been conclusively resolved. The AI Regulation itself does not contain specific liability rules but focuses on preventing harm through the regulation of the development and use of AI systems.
At European level, on 28 September 2022 the Commission presented a proposal for a directive regulating AI liability. This proposal refrains from introducing strict liability for AI and instead provides for rules on the burden of proof for fault-based non-contractual liability claims. This is intended to make it easier for injured parties to assert claims for damages without fundamentally changing the liability system.
In the financial sector, the specific liability rules of the German Banking Act, the German Securities Trading Act and other special statutory provisions also apply. The management board bears responsibility for the use of AI systems and may be held liable for damage caused by defective AI systems. Liability extends both to the development and implementation of AI systems and to their ongoing operation and monitoring.
The use of AI in the financial sector is frequently outsourced to third parties, in particular to specialised technology providers and FinTech companies. This creates particular challenges for ICT third-party risk management, which is regulated in detail by DORA (Art. 64 DORA Regulation).
BaFin already published guidance on outsourcing to cloud providers in 2018, which is also relevant for AI applications. With the implementation of DORA, these requirements have been further tightened and systematised. Financial undertakings must now ensure that their ICT service providers, including providers of AI systems, comply with the requirements for digital operational resilience.
BaFin’s guidance on ICT risks in the use of AI emphasises that financial undertakings must develop a comprehensive understanding of the AI systems they use, even where these are provided by third parties. This includes knowledge of how the AI systems work, the data used, the potential risks and the means of remediating errors.
The legal regulation of the use of AI in the financial sector remains in a dynamic process of development. In the coming years, the AI Regulation will be further specified by delegated acts and implementing acts of the Commission (Art. 6 AI Regulation). The Commission has already published guidelines on the definition of an AI system and on prohibited practices.
The European Commission also promotes the development of codes of practice at Union level in order to contribute to the proper application of the AI Regulation (Art. 56 AI Regulation). These codes of practice are intended to cover at least the obligations provided for in Articles 53 and 55, including the means of ensuring the currency of information, the appropriate level of detail in summaries of content used for training, and measures for assessing and managing systemic risks (Art. 56 AI Regulation).
At national level, the KI-MIG has restructured supervision of AI systems in Germany, entering into force on 29 July 2026. The Act follows a hybrid approach: the Federal Network Agency acts as the central coordination and competence centre, notifying authority and general market surveillance authority, while BaFin has been given extended supervisory competence for AI systems used in connection with regulated financial activities of supervised institutions, including credit servicers within the meaning of the Credit Servicing Directive Implementation Act (Kreditzweitmarktgesetz).
This sectoral allocation of supervisory responsibility to BaFin for AI in the financial sector avoids a fragmentation of supervision and demarcation difficulties vis-à-vis sector-specific supervisory law. Questions remain, however, as to the practical coordination between the Federal Network Agency and BaFin where a single AI system is used across multiple business areas, and as to the independence of AI market surveillance, since BaFin is subject to the legal and technical supervision of the Federal Ministry of Finance.
In the long term, the potential applications of AI in the financial sector could develop considerably further. Experts are already speculating about scenarios involving artificial general intelligence. One likely concept is that of so-called “self-driving finance”, in which an intelligent AI agent manages the finances of private or business customers by automating routine decisions or advising customers on more complex decisions.
Even more futuristic is the concept of a machine-to-machine (M2M) economy, in which smart, autonomous, networked and economically independent machines or devices act as participants that carry out the necessary activities of production, distribution and allocation with little or no human intervention. These scenarios raise entirely new legal questions that have not yet been conclusively resolved.
The legal developments relating to the use of AI in the banking and financial services sector in Germany and Europe are characterised by increasing regulatory density. The AI Regulation creates a comprehensive European framework, supplemented by DORA in the area of digital operational resilience. At national level, Germany has taken important steps with the FinMaDiG and the BaFin principles to implement and specify these European requirements.
The risk-based approach of the AI Regulation, which imposes particularly strict requirements on high-risk AI systems such as AI-supported creditworthiness assessments, reflects the fact that AI applications in the financial sector can have significant effects on the rights and interests of consumers and on the stability of the financial system. Following the deferral introduced by the Digital Omnibus on AI, financial undertakings now have until 2 December 2027 to achieve compliance with the Annex III high-risk obligations, rather than the originally envisaged 2 August 2026. At the same time, the legislator seeks not to unnecessarily hinder innovation in order to safeguard the competitiveness of the European financial sector.
For financial undertakings, this means that they must carefully plan and implement the use of AI systems. Compliance with regulatory requirements calls for a comprehensive understanding of AI technology, robust risk management and close cooperation with supervisory authorities. Only in this way can the opportunities offered by AI be used while the associated risks are controlled.
The coming years will show whether the chosen regulatory approach is suitable for appropriately balancing innovation and protection. The dynamic further development of AI technology and the increasing spread of AI applications in the financial sector will certainly require further adjustments and additions to the legal framework.