AI compliance in Germany

AI compliance at a German bank or insurer rests on three authorities: the Bundesnetzagentur as the central AI Act authority, BaFin for AI in regulated financial business, and the data protection authorities for automated decisions about people. BaFin also treats AI as ordinary IT under DORA. Dated events are in the calendar below.

fAInance, an AI conference for financial institutions near Frankfurt Airport

What AI compliance means

AI compliance is the work of making sure an organization builds, buys and uses AI within the law. For a financial firm in Germany that law has several sources. The EU AI Act sets duties by risk class, and the page on the EU AI Act in financial services explains which finance uses are high-risk and what providers and deployers must do. Around it sit the General Data Protection Regulation, the operational resilience rules of DORA, and the sector rules for banks, insurers and investment firms.

In practice an AI compliance function keeps an inventory of AI systems, sorts them by risk, checks contracts with AI vendors, trains staff and documents all of it. Some firms name an AI compliance officer for this; others place it with compliance, information security or model risk management. The AI Act does not require a specific title, but it does require the firm to be able to show what it has done.

Who enforces AI rules in Germany

Germany has passed its act implementing the AI Act. It makes the Bundesnetzagentur (in German), the Federal Network Agency, the central point of contact, market surveillance authority and complaints body for AI. For supervised financial firms the picture is split: under the same act, BaFin supervises AI that banks, insurers and other supervised firms use in direct connection with regulated financial activities, such as credit assessment and risk assessment in life and health insurance. AI the same firm uses elsewhere, for example in HR, falls to the Bundesnetzagentur.

The Bundesnetzagentur runs an AI service desk aimed at small and medium-sized companies and start-ups. Its online tool, the AI compliance compass, walks a company through a few questions to see whether a system falls under the AI Act and in which risk class; the result is guidance, not a binding decision. The AI Act also requires each member state to run at least one AI regulatory sandbox, where firms can test AI under supervision before it goes live.

BaFin: AI is IT, and DORA applies

BaFin added a second layer that has nothing to do with AI Act risk classes. In its guidance on ICT risks from AI (in German), it treats AI systems as network and information systems under DORA. An AI model is therefore an ICT asset like any other, and a firm covers it in its ICT risk management over the whole life cycle: identification, protection, detection, response and recovery. The guidance is aimed at all firms that apply Articles 5 to 15 of DORA, first of all CRR banks and insurers under Solvency II.

For AI compliance this means two checklists for the same system. A chatbot that answers customer questions may be low-risk under the AI Act and still need access controls, logging, vendor checks and an entry in the DORA register of information if it runs on a cloud service. A model bought from a vendor brings its contract into the DORA regime as well.

AI literacy and the SCHUFA ruling

One AI Act duty already applies to every firm that uses AI: Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among the staff who operate AI systems. The Bundesnetzagentur has published guidance on AI literacy (in German) and recommends that firms document their training measures so that they can show at any time that they meet the duty. For a bank that means training that fits the role: a credit officer who reads a model score needs to know different things than a developer.

Data protection law adds a limit on automated decisions. In its SCHUFA judgment, the Court of Justice of the EU held that calculating a credit score can itself be an automated decision under Article 22 GDPR when a lender relies on it decisively to grant or refuse credit. Scoring agencies and lenders in Germany had to review how scores flow into credit decisions and what human review follows. That ruling applies to classic statistical scorecards as much as to machine learning.

What AI compliance teams in finance work on now

The first task is the inventory, and it is harder than it sounds, because AI arrives inside bought software, office tools and cloud services. The second is governance: who approves a new AI use case, who validates the model, who monitors it in production, and how the three lines of defense split the work. Risk management teams bring model validation experience from credit scoring, while information security brings the DORA view covered on the page on cybersecurity in finance in Germany.

Agentic AI is the newest item. An agent that reads documents, calls tools and prepares a decision needs an audit trail, clear limits and a human sign-off where money or customer rights are involved. The book Building AI Agents for Finance by Fayssal El Mofatiche and Hanane Dupouy shows such a pipeline for insurance claims, ending in a compliance sign-off with a full audit trail.

Upcoming events on AI and compliance in Germany

AI compliance at Finance Loop

Finance Loop is the meeting place for compliance officers, model validators, data scientists and lawyers who put AI in banks and insurers under these rules. It connects the finance, IT and AI communities in Frankfurt and holds events in Munich, Berlin and Hamburg as well.

Finance Loop highlighted fAInance, a conference by Sopra Steria and Fraunhofer IAIS for staff of financial institutions, with stations on AI governance, risk and compliance and an AI auditor. Finance Loop announced KI Exchange 2026 in Hamburg, where AI governance and DORA compliance were on the program. Finance Loop has a cooperation with Frankfurt Data Science on data science and AI in finance, and at the AI Week Frankfurt side event talks covered trusted AI and AI testing.

What is AI compliance?

AI compliance means building, buying and using AI within the law and being able to prove it. In a German financial firm that covers the EU AI Act, GDPR, DORA and the sector rules, and it usually starts with an inventory of all AI systems in use.

Who regulates AI in Germany?

The Bundesnetzagentur is the central authority for the AI Act. BaFin supervises AI that supervised financial firms use in regulated activities such as credit and insurance risk assessment, and data protection authorities oversee automated decisions under GDPR.

What does BaFin expect from AI under DORA?

BaFin treats AI systems as ICT assets. Its guidance (in German) asks firms to cover AI in their ICT risk management across the whole life cycle, from identifying the system to response and recovery, in the same way as other IT.

Is there an AI compliance checker?

The Bundesnetzagentur offers the AI compliance compass, an online tool that shows whether a system falls under the AI Act and which risk class may apply. It gives guidance only; the firm remains responsible for its own assessment.

AI compliance in Germany and Finance Loop

AI compliance belongs to the Risk & Compliance track of Finance Loop and reaches into the other two tracks wherever AI scores, trades or pays. Finance Loop highlighted fAInance and KI Exchange, both with AI governance on the program, and cooperates with Frankfurt Data Science. People who work on these rules meet at Finance Loop events across Germany, Austria and Switzerland.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.