On 29 July 2026 Germany's act implementing the European Regulation on Artificial Intelligence entered into force. Its Article 1 carries the name AI Market Surveillance and Innovation Promotion Act (KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG), and it hands the Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, BaFin) a new role: it will police AI systems that are directly connected to a regulated financial activity. The regulator accompanied this with a press release and an interview in which Jens Obermöller, head of the division for cyber risks and technology in the financial sector, sets out the scope. Both texts are precise. The real finding only emerges, though, once you place them next to a second document.

Because two days before the German act, on 27 July 2026, the Digital Omnibus Regulation on AI entered into force in Brussels and amended more than 40 articles of the AI Act. Among them the provision that determines when the requirements for high-risk systems start to apply. The original cut-off for that was 2 August 2026 – precisely the date the industry is now watching.

At a glance

What: the KI-MIG makes BaFin the market surveillance authority for AI in the financial sector

Since when: 29 July 2026, one day after publication in the Federal Law Gazette

Scope: only AI directly connected to a licensed financial activity; everything else, such as AI in a bank's HR function, sits with the Federal Network Agency (Bundesnetzagentur, BNetzA)

What starts on 2 August 2026: the transparency obligations of Article 50 and the market surveillance regime

What moves to 2 December 2027: the requirements for high-risk systems under Annex III, including creditworthiness assessment of natural persons

Surveillance is not supervision

The most important sentence in the interview is a definitional one. Jens Obermöller separates two activities that everyday usage has long since blurred: „Der Auftrag der KI-Verordnung lautet nicht Aufsicht. Er lautet Überwachung." The AI Act's mandate, in other words, is not supervision but surveillance. Anyone coming from day-to-day banking supervision should take that distinction seriously. Market surveillance under European product law works on a sampling basis, risk-oriented, on products that are already in the market. It knows no continuous institution-level relationship, no supervisory dialogue about every individual system, no annual examination programme covering the entire model landscape.

Jens Obermöller describes the approach accordingly: the regulator will take samples of applications that many financial firms deploy at particularly relevant points. And explicitly: „Wir kontrollieren nicht jedes einzelne KI-System in jedem Finanzunternehmen." Not every single AI system in every financial firm will be checked. For institutions that cuts two ways. The probability of any one system being examined is lower than for core supervisory topics. The drop in an individual case is correspondingly steeper, because a market surveillance authority engages with the product and, in the extreme, with whether it may be made available at all, rather than merely with the quality of the process behind it.

The allocation of responsibilities deserves a second note. BaFin only steps in where AI is tied to a licensed activity; for everything else the Federal Network Agency is the central market surveillance authority, and it will also host a coordination and competence centre for the AI Act (KoKIVO). That is logically sound, but in practice it draws a line straight through a firm's own technology stack: the same language model, the same platform, the same vector database may fall under BaFin in the credit process and under the Federal Network Agency in candidate management. Anyone who has so far catalogued AI by technology now needs a catalogue ordered by purpose.

What actually begins on 2 August

2 August 2026 is the AI Act's general date of application. What becomes practically relevant for financial firms on that day are the transparency obligations of Article 50 and the governance and market surveillance regime that BaFin now occupies. Article 50 covers systems that interact directly with people – BaFin's press release names chatbots in customer communication explicitly – as well as the marking of synthetically generated content.

Here the Digital Omnibus has built in a relief that buys real time in practice: providers of systems generating synthetic audio, image, video or text content that were placed on the market before 2 August 2026 need only comply with the marking duty of Article 50(2) by 2 December 2026. For legacy systems in customer communication, part of the technical implementation therefore shifts by four months. The duty to disclose to the human at the other end remains owed from 2 August.

What does not begin on 2 August, by contrast, are the requirements that stretch institutions hardest in substance. Under the amended text, Chapter III of the AI Act – risk management system, data and data governance, technical documentation, record-keeping, human oversight and accuracy requirements – applies to Annex III systems only from 2 December 2027, and to systems embedded in regulated products under Annex I only from 2 August 2028. These are fixed calendar dates in the legislative text, not target dates, and not deadlines that shift forwards or backwards as harmonised standards appear. The Commission proposal did envisage such a linkage; it is not in the law as adopted.

The AI Act's mandate is not supervision. It is surveillance. Jens Obermöller, Head of Cyber Risks and Technology in the Financial Sector, BaFin

Sixteen extra months are no reason to sit back

The deferral does read like relief, and for project plans that is exactly what it is. It applies, however, to precisely those systems that sit closest to the customer and to fundamental rights in banking. BaFin names them specifically: at banks, as a rule, the AI systems used to assess creditworthiness and the credit standing of natural persons; at insurers, risk assessment and pricing in life and health insurance. Those systems will now run 16 months longer without a formalised data governance under Article 10 being required – and will then land in a regime nobody was obliged to rehearse in the meantime.

Yet the decisive passage is not in the timetable but in the press release. BaFin President Mark Branson puts on record a sentence that no deferral touches: „Die Verantwortung für den Einsatz von KI liegt bei den beaufsichtigten Unternehmen und ihren Geschäftsleitungen." Responsibility for deploying AI rests with the supervised firms and their management boards. Alongside it comes the requirement that decisions must remain capable of being corrected and reversed by humans. That is not a provision with an application date; it is the description of an organisational duty that already follows from applicable supervisory law. Anyone reading December 2027 as the starting line has skipped that sentence.

There is also a transitional rule that works more quietly than it looks. For high-risk systems put into service before Chapter III starts to apply, the requirements bite only if the systems are subsequently changed significantly in their design. That sounds like grandfathering and is, in practice, a model risk question. A scoring model that is retrained regularly and adjusted in its feature selection will at some point cross that threshold. Where exactly will be a documentation question, and it will only be documented if somebody starts keeping the record today.

The duty nobody deferred

Jens Obermöller names three areas BaFin will start on immediately: transparency obligations, prohibited practices, and whether firms are taking measures to build the AI literacy of their staff. On AI literacy that word immediately is worth pausing on, because the duty is not new at all. Article 4 of the AI Act has been binding since 2 February 2025, roughly 18 months. What is new is only that somebody is now checking.

The Digital Omnibus in fact softened Article 4 and inserted a clarification that matters more for implementation than it sounds: the obligation does not require providers or deployers to guarantee any particular level of AI literacy for any given person. What is owed are measures, not a measurable standard of competence. BaFin phrases it the same way when it writes that it will look at „ob die Unternehmen Maßnahmen ergreifen" – whether firms are taking measures. For institutions this means a demonstrable, role-based training concept with attendance records satisfies the norm. A certification programme with guaranteed pass results is not what the law asks for.

On the third area, prohibited practices, the staggering is worth a look. The core of Article 5 has applied since 2 February 2025. The Digital Omnibus added individual prohibitions whose application is set for 2 December 2026. From August, then, the regulator will police a prohibition that will only be complete in December.

The €35m tier belongs to Article 5

Asked about consequences, Jens Obermöller answers with the highest figure the regulation contains: in the extreme, fines of up to €35m or seven per cent of annual turnover are possible. That is correct, and it is not a theoretical magnitude, because prohibited practices fall squarely within BaFin's surveillance mandate.

For calibrating risk in your own house, however, the tiering behind it is what counts. The top tier of €35m or seven per cent attaches to breaches of the prohibited practices in Article 5. Breaches of the obligations for high-risk systems and of the transparency obligations sit one tier below, at €15m or three per cent. The Digital Omnibus left those amounts untouched; it merely sharpened the requirement to take account of small and medium-sized enterprises and, for small mid-cap companies, provided that the lower of the two values applies. Anyone setting an internal risk figure should therefore attach it to the specific set of obligations rather than to the topic of AI as a whole.

The tone in which the regulator frames all this is notable. Jens Obermöller presents sanctions explicitly as the exception where firms approach BaFin early, and stresses: „Es bleibt viel Raum für Innovation." Plenty of room for innovation remains. He points to regulatory sandboxes and testing in real-world conditions as protected spaces in which the regulator contributes its own expertise. The AI Roundtable that BaFin established in 2023 together with the Deutsche Bundesbank, the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI) and the Federal Network Agency remains the channel for it.

What is genuinely new for credit scoring

One Digital Omnibus change will be lost in the coverage and matters more in practice for credit risk models than any deferral. The new Article 4a permits providers of high-risk systems, by way of exception, to process special categories of personal data where this is strictly necessary to detect and correct bias. One condition is that bias detection cannot be carried out just as effectively with other data, for instance synthetic or anonymised data.

With that, the legislator resolves a contradiction on which fairness testing used to founder: freedom from discrimination cannot be demonstrated without looking at the very attributes along which discrimination might occur. Mark Branson names non-discrimination as one of three core themes alongside transparency and effective risk management. Whoever has to furnish that evidence in future now has a legal basis for it – and should know the conditions in Article 4a before the first bias test is designed.

On the wider regulatory frame, the supervisory message is otherwise unchanged and easy to connect to. Jens Obermöller points to existing structures: firms should embed the AI Act into their established governance, risk and compliance structures: „Die bereits etablierten Rahmenbedingungen wie DORA bieten dafür ein sehr gutes Fundament." Frameworks already in place, such as DORA, provide a very good foundation. Anyone who has implemented the Digital Operational Resilience Act (DORA) already holds registers, outsourcing controls and incident processes to which AI systems can be attached. BaFin published guidance on information and communication technology (ICT) risks in the use of AI in December 2025.

Recommendations for operational practice

For chief risk officers, compliance leads and heads of credit and insurance business, this week's twin movement produces four fields of action.

1. Sort the AI inventory by purpose, not by technology

Immediately: the boundary between BaFin and the Federal Network Agency runs along the licensed financial activity, not along the platform in use. Every system needs a documented mapping to a business purpose and, derived from it, to a market surveillance authority. Without that ordering, no statement to the regulator will hold up.

2. Apply Article 50 to customer channels by 2 August

This week: every chatbot and every assistant in direct customer contact needs a disclosure that the interaction is machine-driven. For marking synthetically generated content in legacy systems there is time until 2 December 2026 – but that transition covers only systems placed on the market before 2 August, so it is no buffer for new launches.

3. Be able to evidence AI literacy as homework already done

Before the first sample check: Article 4 has been binding since February 2025, and this is where BaFin starts immediately. What is owed are measures, not a guaranteed level of competence. A role-based training concept with attendance records and a link to the respective deployment context meets the norm – it simply has to exist and be findable.

4. Spend the 16 months on data governance, not on waiting

Until December 2027: creditworthiness assessment and insurance pricing fall under Chapter III from 2 December 2027. Two things reward a head start: a data governance under Article 10, which cannot be retrofitted in a single quarter, and the threshold question of when a regularly retrained model counts as significantly changed and loses its grandfathering. Both are documentation work that only accrues as you go.

Timeline: AI Act deadlines in the financial sector
Position after the Digital Omnibus and the KI-MIG
2 February 2025
Prohibitions and AI literacy apply
Chapters I and II of the AI Act, including Article 4 on AI literacy and the core of the prohibition catalogue.
December 2025
BaFin guidance on ICT risks in AI use
Support for implementing the DORA requirements where financial firms deploy AI.
27 July 2026
Digital Omnibus Regulation on AI in force
More than 40 articles of the AI Act amended, high-risk deadlines reset, new Article 4a on bias detection.
29 July 2026
KI-MIG in force, BaFin becomes market surveillance authority
Responsible for AI directly connected to a licensed financial activity; everything else sits with the Federal Network Agency.
2 August 2026
Transparency obligations and market surveillance bite
Article 50 for systems interacting directly with people, such as chatbots in customer communication.
2 December 2026
Marking for legacy systems, additional prohibitions
Article 50(2) for generative systems placed on the market before 2 August 2026; the added prohibitions in Article 5.
2 December 2027
High-risk requirements for Annex III systems
Creditworthiness assessment of natural persons, risk assessment in life and health insurance.
2 August 2028
High-risk requirements for Annex I systems
AI systems embedded as safety components in regulated products.
Christian Schablitzki

Christian Schablitzki

Strategy & Management Consultant · Agentic AI expert for financial institutions

More than 20 years in investment banking and derivatives trading, followed by over 10 years advising financial institutions. Currently Partner at Infosys Consulting in Germany. Certified in Google AI, Generative AI Leader (Google Cloud) and IBM RAG and Agentic AI.

LinkedIn profile →
newsletter
the agentic banker

Keep reading – every 14 days in your inbox.

Capital markets insights, regulatory updates and AI trends. Concise, well-founded, free.

GDPR-compliant. Unsubscribe at any time.

← Back to overview