Germany's financial regulator is moving to bring artificial intelligence inside its everyday supervisory framework, rather than treating it as a separate innovation project. As the EU AI Act's high-risk provisions approach full application on August 2, 2026, BaFin has issued guidance that folds AI systems used by banks and insurers into existing risk management structures, particularly under the Digital Operational Resilience Act, known as DORA.

The shift matters because it changes the practical question institutions face. It is no longer only whether a system counts as high-risk AI under the EU framework. It is whether that system sits in the bank's asset inventory, carries a risk classification, is monitored continuously, and has a tested exit strategy if it fails.

How Germany's AI Oversight Actually Works

Germany operates a dual supervisory structure for AI in financial services, and the division of labor is easy to misread.

  • The Bundesnetzagentur, Germany's Federal Network Agency, serves as the formal market surveillance authority for the EU AI Act.
  • The Deutsche Akkreditierungsstelle acts as the national notifying authority under the same regulation.
  • BaFin, meanwhile, supervises AI through its existing prudential and conduct mandate, treating AI systems as components of a bank's operational technology rather than as a standalone regulatory category.

In February 2026, BaFin issued orientation guidance addressing AI use under DORA, with voice and phone-based AI agents as a concrete example. The guidance defines AI systems in plain technical terms as network and information systems, which effectively removes the special status that AI might otherwise carry under a pure risk-classification approach. For banks, this means an AI phone agent handling customer calls is treated the same way as any other ICT asset: it must be inventoried, risk-assessed, monitored, and covered by continuity planning.

What the EU AI Act Requires of Banks

The EU AI Act itself follows a staggered timeline that has been building since it entered into force in August 2024.

  • Prohibitions on unacceptable AI practices took effect in February 2025.
  • Rules covering general-purpose AI models, notified bodies, and governance structures became applicable in August 2025.
  • Full application of high-risk AI requirements arrives on August 2, 2026.
  • AI systems that are components of large-scale IT systems receive an extended transition period running until the end of 2030.

For banks, the high-risk category is the one that matters most. Under Annex III of the regulation, AI systems used for credit scoring, creditworthiness assessment, fraud detection, and insurance underwriting are explicitly classified as high-risk. That classification brings obligations around data quality, bias testing, human oversight, and documentation that go well beyond what many institutions have historically applied to internal models.

Non-compliance carries real financial exposure. Penalties for breaches of the AI Act can reach €35 million or 7 percent of a company's total global turnover, whichever is higher, a scale of fine that puts AI governance on par with the most serious prudential violations a bank can commit.

Why This Creates a Compliance Puzzle, Not Just a Checklist

The practical challenge for German banks is that they now answer to two overlapping frameworks that were not designed together.

  • The EU AI Act classifies systems by risk category and imposes technical requirements on model design, testing, and documentation.
  • DORA and BaFin's supervisory approach classify the same systems by operational role, asking whether they are properly governed as ICT assets regardless of their AI risk tier.

Industry advisers increasingly argue that institutions which have already built out DORA-compliant ICT risk frameworks have a head start, since much of the infrastructure needed for AI Act evidence, such as asset inventories and vendor oversight, overlaps with what DORA already demands. The European Banking Authority has signaled that national competent authorities plan to fold AI Act compliance evidence into their regular supervisory review and evaluation process (SREP), meaning AI governance will be assessed alongside capital adequacy and liquidity risk rather than as a separate audit exercise.

The Bigger Picture for Germany's Financial Sector

For an economy where banking remains central to corporate financing, the stakes extend beyond compliance departments. German lenders have leaned on AI to cut costs in customer service, speed up credit decisions, and strengthen fraud detection at a moment when margins are under pressure from competition and rate normalization. Regulatory clarity, even when it adds obligations, tends to reduce the uncertainty that has slowed some institutions from deploying AI more broadly.

At the same time, the dual supervisory regime adds complexity that smaller regional banks and savings institutions may struggle to absorb without external support. The gap between large universal banks with dedicated compliance teams and smaller cooperative banks could widen as the August 2026 deadline approaches, a dynamic worth watching as a broader indicator of consolidation pressure in Germany's fragmented banking landscape.