The EU AI Act in financial services

This page shows what the EU AI Act changes for banks, insurers and asset managers: which uses count as high-risk, who supervises AI in German finance, what teams work on now and what fines apply. It also names the events where people who put AI under these rules meet.

AI governance in finance, a topic of Finance Loop and Frankfurt Data Science

What the EU AI Act means for financial services

The EU AI Act, Regulation (EU) 2024/1689, sorts AI systems by risk. For most AI in a bank, such as a model that drafts emails or summarizes research, it asks for little beyond AI literacy of staff. It bans a short list of practices, and it sets strict duties for high-risk systems. Two high-risk uses sit squarely in finance: AI that assesses the creditworthiness of natural persons or sets their credit score, and AI that assesses risk and sets prices in life and health insurance. AI that detects financial fraud is expressly outside the credit scoring category, and scoring of companies is not in it either.

Whether a firm is a provider or a deployer decides its duties. A bank that builds its own credit scoring model and puts it into service is the provider and carries the full set of high-risk requirements, from risk management to technical documentation. A bank that buys a scoring system from a vendor is a deployer: it follows the instructions for use, assigns human oversight to trained people and carries out a fundamental rights impact assessment before first use. The knowledge hub answer on the EU AI Act lists the articles and the timeline, including the later start date for high-risk credit scoring set by the Digital Omnibus on AI.

Who supervises AI in German finance

In Germany, BaFin supervises AI that banks, insurers and other supervised firms use in direct connection with regulated financial activities. The German Act Implementing the European Artificial Intelligence Act gave it these powers. BaFin names customer chatbots, creditworthiness assessments by banks and risk assessment in life and health insurance as examples, and it can impose fines. AI outside regulated activities, such as a bank's HR software, falls to the Federal Network Agency (Bundesnetzagentur). BaFin President Mark Branson put the aim this way: "People have to be able to trust that their fundamental rights will be protected when AI is used."

The European authorities add their own layer. ESMA told investment firms in a statement on AI in investment services that MiFID II applies in full when they use AI, including the duty to act in the best interest of the client, and it named algorithmic bias, poor data quality and overreliance on AI as risks. EIOPA, the insurance authority in Frankfurt, published an Opinion on AI governance and risk management. It covers the AI that insurers use in pricing, underwriting, claims and fraud detection outside the high-risk and prohibited categories, and asks for data governance, record-keeping, fairness, cyber security, explainability and human oversight.

What banks, insurers and asset managers work on now

The first job is an inventory. Teams list every AI system in use, mark who built it, and sort it into prohibited, high-risk, transparency-only or minimal. The sorting is rarely obvious: a model that flags unusual card payments counts as fraud detection, while a model that decides who gets an overdraft counts as credit scoring. Customer chatbots need a clear notice that the customer is talking to AI.

The second job is governance. Model risk management in banks already validates scoring models for capital purposes; the AI Act adds documentation, logging, human oversight and bias checks on top. Legal teams read Article 99 closely: fines reach up to EUR 35 million or 7 % of worldwide turnover for banned practices and up to EUR 15 million or 3 % for breaches of most other duties, with the lower amount for SMEs and start-ups. AI also touches DORA: a scoring system bought from a vendor is an ICT service contract and belongs in the DORA register of information.

What someone new to AI regulation in finance should know

Start with the two high-risk lines on credit scoring and insurance pricing and the difference between provider and deployer. Then read the sector rules that already applied before the AI Act: MiFID II for investment advice and trading, the insurance rules behind EIOPA's Opinion, and the banking rules on model risk. Fintechs that sell AI to banks should expect their customers to ask for instructions for use and test results, because the bank's deployer duties build on them.

Upcoming events on AI in finance in Germany

AI regulation at Finance Loop

Finance Loop is the meeting place for model validators, compliance officers, data scientists and product owners who put AI in banks and insurers under the new rules. It connects the finance, IT and AI communities in Frankfurt, Munich, Berlin and Hamburg and works with partners in Paris.

Finance Loop highlighted fAInance, a conference by Sopra Steria and Fraunhofer IAIS next to Frankfurt Airport, open only to staff of financial institutions. Its program had stations on AI governance, risk and compliance, an AI auditor and AI against financial crime. Finance Loop has a cooperation with Frankfurt Data Science with a focus on AI governance and responsible AI in financial institutions. At the AI Week Frankfurt side event, presented by Finance Loop, talks covered trusted AI and AI testing and AI as an investigator in anti-financial crime. Finance Loop also announced KI Exchange 2026 in Hamburg, where AI governance and DORA compliance were on the program, and was a partner of AI in Finance Paris with Finteda. Related pages: DORA in Germany, cybersecurity in finance in Germany and risk management in Frankfurt.

What is the impact of the EU AI Act on banks?

For most AI in a bank the impact is small: staff need AI literacy, and chatbots must say they are AI. The large impact falls on consumer credit scoring, which is high-risk. A bank that uses such a system must follow the instructions for use, keep human oversight with trained staff, monitor the system and assess its effect on fundamental rights before first use. A bank that builds its own model also carries the provider duties.

Is credit scoring high-risk under the EU AI Act?

Yes, when it concerns natural persons. Annex III lists AI that evaluates the creditworthiness of natural persons or establishes their credit score as high-risk. Fraud detection is excluded from that line, and the rating of companies is not covered by it.

Does BaFin supervise the EU AI Act?

For supervised financial firms, yes. Under the German implementing act, BaFin supervises AI systems that these firms use in direct connection with regulated financial activities, such as credit assessment and insurance risk evaluation. Other AI in the same firm, for example in HR, is supervised by the Bundesnetzagentur.

What are the EU AI Act financial penalties?

Article 99 sets three levels: up to EUR 35 million or 7 % of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3 % for most other breaches, and up to EUR 7.5 million or 1 % for false or incomplete information to authorities. The higher amount applies to large companies, the lower one to SMEs and start-ups (Article 99).

About Finance Loop: the EU AI Act in finance

Finance Loop brings people who build, buy and check AI at financial firms together with the vendors, researchers and supervisors they deal with, at Finance Loop events across Germany, Austria and Switzerland.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.