BankSorter
Loans Personal Accounts Savings Accounts Financial Apps Blog Rankings Loans Personal Accounts Savings Accounts
MARKET COMMENTARY

BaFin Now Oversees AI in German Banks: What It Means for You

Since August 2026, Germany's regulator BaFin has been supervising how banks use AI — from chatbots to credit scoring. Here's what changes for customers and what to watch for.

LH
Lukas Hoffmann · 19 August 2026 · 6 min read
BaFin Now Oversees AI in German Banks: What It Means for You
Key takeaways
What BaFin Can Now Actually Do
Chatbots Must Identify Themselves
Credit Scoring Becomes a High-Risk Application
What This Actually Means for Your Everyday Banking

When Your Bank Advisor Turns Out to Be an Algorithm

Since August 2, 2026, a new rule has applied to everyday digital banking in Germany: chatbots, virtual assistants and other AI systems that communicate directly with bank customers must now identify themselves as what they are — artificial intelligence, not a human being. This is made possible by a law with the unwieldy name AI Market Surveillance and Innovation Promotion Act (KI-MIG), which came into force on July 29, 2026, and makes BaFin, Germany's financial regulator, the central supervisory authority for artificial intelligence in the financial sector. For most customers, that may sound like a regulatory footnote. In practice, though, it changes something many people have long taken for granted in daily banking: not actually knowing whether a human or a machine is answering on the other end of the chat window.

What BaFin Can Now Actually Do

Under the KI-MIG, BaFin takes over market surveillance for all AI systems directly connected to a supervised financial service — meaning systems deployed, placed on the market or operated by banks, insurers or payment service providers. Going forward, the authority can also impose fines for violations; the amount depends on the severity and duration of the breach as well as the company's economic capacity.

The timing matters here. The first transparency obligations under Article 50 of the EU AI Act have already applied since August 2, 2026. For so-called high-risk applications — which explicitly include automated creditworthiness checks and credit scoring of private individuals — institutions have until December 2, 2027 to fully implement the considerably stricter requirements.

Germany's supervisory structure sits within a much larger European framework. The EU AI Act generally distinguishes between four risk tiers — from minimal risk through limited and high risk up to applications that are banned outright. Chatbots subject to the disclosure duty fall into the limited-risk category, while credit scoring counts as a high-risk application. Banks across Europe therefore have to follow not just national rules, but a single, cross-border framework that BaFin enforces on the ground in Germany. In an interview marking the KI-MIG's entry into force, a BaFin representative stressed in late July 2026 that plenty of room for innovation remains despite the new supervisory duties — the authority, she said, is not out to block technology, but to ensure it is used responsibly.

Chatbots Must Identify Themselves

Concretely, the first stage means this: any bank that uses an AI chatbot in customer service, in its banking app or on its website must clearly label it as AI. A disclosure requirement also applies to so-called deepfakes — AI-generated video or audio content used in customer communication, for instance. On top of that, supervised companies must train their staff in handling AI responsibly, ensuring what the law calls "AI literacy."

Credit Scoring Becomes a High-Risk Application

The second part of the new rules — arguably more relevant to your personal finances — concerns AI-driven creditworthiness assessment. More and more banks use algorithmic scoring models when granting personal loans, overdrafts or mortgages, automatically evaluating income, payment history and other data points. Because a rejection or a poor score carries real financial consequences, the AI Act classifies such systems as high-risk applications. Going forward, banks will have to document, in a traceable way, how their models arrive at a decision, and be able to provide affected customers with a comprehensible explanation on request.

A simple example shows how this can play out in practice: a scoring model automatically flags a self-employed applicant as a risk case purely because her account shows irregular incoming payments, even though her annual income is stable and more than sufficient. Without traceable documentation, she would simply receive a rejection with no way of finding out why. This is exactly where the new explanation duty comes in: the bank will have to be able to show which factors drove that outcome, so a case like this can be reviewed or corrected instead of just staying in the dark.

What This Actually Means for Your Everyday Banking

The new supervisory regime brings several practical consequences for consumers that should become noticeable over the coming months:

  • More transparency in customer service: If you ask a question about your current account via chat, you should now be able to clearly tell whether a bot or a human is answering. Banks that previously blurred this line will have to adjust their communication.
  • More traceable credit decisions: If you apply for a loan and get rejected, you should eventually be able to understand which factors drove that decision — at least once the high-risk obligations fully take effect in 2027.
  • No free pass for banks: BaFin can fine violations, which raises the pressure on institutions to carefully document and test their AI systems before rolling them out.
  • A new question when switching banks: If you're already considering a switch, you can use this transparency requirement as an extra selection criterion — for example, by checking how openly a bank communicates about its use of AI.

What Still Hasn't Changed

As welcome as the new rules are, they don't solve every problem overnight. The labeling requirement says nothing about how good or bad a chatbot's advice actually is — it only ensures you know who, or what, you're talking to. And with credit scoring, explainability is not the same as being error-free. An algorithm can still reach a result that's unfavorable to you, even if the bank documents the decision in a traceable way. If you get a poor score or unfavorable terms at one institution, you should keep doing what has always made sense: comparing offers actively rather than relying on a single bank — particularly for something like a mortgage, where even small rate differences add up to real money over the decades.

It's also worth keeping the timeline gap in mind: until December 2027, not all the strict high-risk requirements yet apply to credit-scoring systems. Anyone expecting a fully detailed explanation for every loan rejection starting today may be disappointed — the rules will only take full effect gradually.

Bottom Line: Trust Is Good, Comparing Is Better

BaFin's new AI oversight is an important step toward more transparency in digital banking — it makes visible where machines are involved, and it forces institutions to document their algorithms instead of treating them as a black box. For your own financial decisions, though, it's no substitute for independent research. Whether a chatbot is giving you friendly advice or an AI system is assessing your creditworthiness, the terms that ultimately end up on paper still vary considerably from bank to bank. Use the new transparency rules as an extra safety net, but keep relying on a genuine comparison of offers before you open an account or sign a loan agreement.

Ready to find the best offer?
Compare current bank offers and find the best one for you.
See the ranking →
LH
Lukas Hoffmann
Financial Specialist