BaFin vs the EU AI Act

On 30 January 2026, Germany's Federal Financial Supervisory Authority (BaFin) published its Guidance on ICT Risks in the Use of AI at Financial Entities. It sits alongside a regulation that already applies across the EU: the EU AI Act. Both cover AI. Both apply to banks and insurers operating in Germany. But they look at an AI system through completely different lenses.
BaFin treats AI as an ICT asset that has to stay resilient. The EU AI Act treats AI as a product that has to be safe for the people it affects. The same credit-scoring model or LLM assistant can fall under both at once. This article breaks down what each expects, where they diverge, and how to manage a single AI system that answers to both.
1. BaFin's guidance: AI as an ICT risk
BaFin's guidance is non-binding advice. It is designed to help financial entities apply the Digital Operational Resilience Act (DORA) when they use AI. It is aimed in particular at institutions under the Capital Requirements Regulation (CRR) and insurers supervised under Solvency II.
Non-binding does not mean optional. In supervisory practice, guidance like this becomes a de-facto benchmark. Deviate from it, and the burden shifts to you to show your alternative controls offer an equivalent level of protection when the regulator asks.
The core message is simple. AI is not a special case that sits outside your existing frameworks. It is an ICT asset, and it must be governed, secured, and monitored inside your DORA-compliant setup. In practice, the guidance expects:
- A management-approved AI strategy. The management body carries ultimate responsibility under DORA. Board members do not need to write code, but they are expected to understand concepts such as model drift and the risks of LLM hallucinations.
- A complete inventory of AI systems. This explicitly includes "shadow AI" and AI components buried inside purchased standard software, such as HR tools and ticketing systems.
- Lifecycle-based risk management. ICT risks are examined across the full AI life cycle, from data sourcing through to retirement.
- ICT third-party and cloud risk management. Given the reliance on cloud providers and proprietary models, the guidance expects thorough due diligence, clear contractual terms, exit strategies, and attention to concentration risk.
- Cybersecurity and data controls across the lifecycle. Access controls, logging, encryption, and a strong focus on data quality, especially training data. Measures should be specific to the risk. An adversarial-attack risk calls for a technical response such as adversarial training, not a generic policy.
- AI-related incident detection and reporting. Major ICT incidents are reportable under DORA, and that can include incidents in AI systems.
The lens is operational resilience. The question BaFin is asking is: what happens to the firm, and to the financial system, if this AI system fails, drifts, or is manipulated?
2. The EU AI Act: AI as a product that affects people
The EU AI Act (Regulation (EU) 2024/1689) is binding law with direct effect. It entered into force on 1 August 2024 as the first comprehensive horizontal AI framework, and it applies extraterritorially to any system placed on the EU market or whose output is used in the EU.
Its logic is risk-based. AI systems fall into four tiers: prohibited, high-risk, limited-risk (transparency obligations), and minimal-risk (no new obligations). For financial institutions, the relevant tier is almost always high-risk. Annex III names the exposure directly: credit scoring and creditworthiness assessment of natural persons (point 5(b), with fraud detection carved out), and risk assessment and pricing for life and health insurance (point 5(c)).
High-risk classification triggers a demanding set of obligations, including a continuous risk management system, data governance and bias testing, technical documentation, logging, human oversight, accuracy and cybersecurity requirements, a quality management system, conformity assessment, and registration in the EU database. The Act also splits accountability between the provider that builds the system and the deployer that uses it. Deployers of high-risk financial AI must, among other things, complete a fundamental rights impact assessment before first use.
On timing, the picture shifted in 2026. Under the Digital Omnibus agreed by EU legislators in May 2026, the high-risk obligations for standalone Annex III systems, including credit scoring and insurance pricing, were moved from 2 August 2026 to 2 December 2027. Embedded high-risk AI under Annex I follows on 2 August 2028. Transparency obligations under Article 50 stay on the original 2 August 2026 date, and the AI literacy duty has applied since February 2025.
The lens here is product safety and fundamental rights. The question the EU AI Act is asking is: what happens to the person this AI system makes a decision about?
3. Key divergences: BaFin guidance vs EU AI Act
The two regimes are not in conflict. They are simply pointed at different things. That is exactly what makes them hard to run together. We have summarised the main differences below.
4. The real problem: one AI system, two lenses
Consider a single AI system: an LLM-based assistant, or a ML based credit scoring system. Under BaFin's guidance it is an ICT asset that needs an owner, a resilience profile, third-party and cloud controls, and incident reporting. Under the EU AI Act the same system is high-risk AI that needs a conformity assessment, technical documentation, human oversight, and a fundamental rights impact assessment.
Same system. Two owners, two sets of artefacts, two lifecycles, two audiences asking different questions.
Trying to force both into one rigid framework flattens the distinction and satisfies neither regulator. Running two separate frameworks in parallel creates duplication, constant reconciliation, and silos between the operational-resilience team and the AI-governance team. And this is only two regimes. Add sector guidance, national supervisory expectations, and other jurisdictions, and the number of lenses each team has to satisfy only grows.
5. Managing overlapping regimes with Yields Multi-Governance
Yields solves this by structuring the complexity rather than flattening it. The Multi-Governance framework lets a single AI system answer to multiple regulatory lenses at once, without being duplicated.
- The "Triplet" architecture. Yields abandons the assumption that a system belongs to one framework. Every use case is structured as a triplet: Model (version) × Usage × Governance. The model is the underlying analytical or AI component. The usage is the business context it operates in. The governance is the specific framework assessing it, whether that is BaFin's DORA/ICT lens, the EU AI Act, an internal AI governance policy, or all three. One system can carry several governance lenses without being registered several times.
- Independent attributes and lifecycles. Each framework decides for itself how a use case is represented. Viewed through the BaFin/DORA lens, the platform exposes ICT risk, third-party dependencies, resilience testing, and incident workflows. Viewed through the EU AI Act lens, that same system exposes risk classification, technical documentation, human oversight, and the fundamental rights impact assessment. Neither lens is forced to adopt the other's structure.
- A single source of truth, without duplication. Core system information is held once, as a shared object. The operational-resilience team and the AI-governance team work from the same record instead of maintaining separate inventories that drift apart.
- Shared visibility and reuse. Because both lenses point at the same underlying use case, the relationship is explicit. Evidence gathered for one regime, such as data-quality or documentation work, can be reused for the other, cutting manual reconciliation and duplicated effort.
The result is clear oversight across both regimes, less manual reconciliation, and work that carries over from one lens to the next.
6. Conclusion
BaFin and the EU AI Act are not competing rulebooks. They are two lenses on the same technology. BaFin asks whether an AI system is resilient enough to run in a regulated institution. The EU AI Act asks whether it is safe for the people it makes decisions about. Both questions are valid. Both apply to the same banks and insurers. And increasingly, both apply to the same AI system at the same time.
Forcing these lenses into one framework breaks down fast. Running them as separate silos creates duplication and endless reconciliation. Yields structures the complexity instead. The Triplet architecture (Model × Usage × Governance) lets a single system carry both lenses without ever being duplicated, while core information lives once as a single source of truth.
Teams stay in control, and stay ready when the regulator asks, whichever lens they are answering to.
Sources: BaFin, "Guidance on ICT Risks in the Use of AI at Financial Entities" (30 January 2026); Regulation (EU) 2024/1689 (EU AI Act), Annex III and Articles 6, 9–15, 26–27; Digital Omnibus political agreement, May 2026.
About the
Author(s)

Jos Gheerardyn is the co-founder and Chief Executive Officer (CEO) of Yields. Prior to his current role, he worked as both a manager and an analyst in the field of quantitative finance. With nearly 20 years of experience, he has worked with leading international investment banks and start-up companies. Jos is the author of multiple patents that apply quantitative risk management techniques to the energy balancing market. Jos holds a PhD in superstring theory from the University of Leuven.


