← Back to analysis
RegulationAugust 3, 20265 min read

How a financial regulator tests AI (and what your HR-tech learns from it)

From 29 July 2026 BaFin can impose penalties. The way it tests AI systems previews the operational bar that procurement will eventually ask of you.

Germany's financial supervisor, BaFin, has held enforcement powers since 29 July 2026. It starts with transparency duties, which apply immediately, and extends its reach to high-risk cases (creditworthiness assessment, for example) around December 2027. It is worth watching how it tests, because financial supervisors tend to move first and their method sets the standard other buyers later demand.

What it asks you to demonstrate

BaFin asks banks and insurers to prove not just that a system works, but how it was built and how it is watched over time. The list is recognisably operational:

  • How the AI system was validated before going into production.
  • What methods are used to detect discrimination in the outputs.
  • How performance is tracked after launch, not only at go-live.
  • Full lifecycle management: approval in production does not close the file.
  • Version control and regression testing of third-party generative models.
  • Adversarial testing: simulated data poisoning, evasion and AI-specific pentesting.

AI as ICT risk, not as innovation

The framing matters. BaFin treats AI as an ICT risk under DORA, not as an innovation initiative with its own rules. The phrase that captures its approach is "monitoring, not supervision": it does not review every model of every entity, but samples the most-used, highest-impact applications. It is a risk-based, evidence-based model, not a form-approval one.

One idea is worth keeping from all this: you cannot test what you have not inventoried. Without an inventory of systems, versions and intended purposes, neither validation nor discrimination monitoring nor third-party version control has anything to stand on.