DORA

Germany’s BaFin published a discussion paper on algorithm-based decision-making in 2018. France’s ACPR began exploratory work on machine learning explainability and governance the same year, formalizing it into a first report in 2019. De Nederlandsche Bank issued its own framework in July 2019. All three did this years before the EU AI Act reached a final text, and none of them were implementing EU legislation when they did it. They were applying old prudential and conduct rules — capital adequacy, sound governance, fair treatment of customers — to a new kind of decision-maker.

That pattern is easy to miss if you only track Brussels. The EU AI Act gets the attention because it’s continent-wide, quantifiable, and new: risk tiers, transparency duties, fines set as a percentage of global turnover. But financial firms operating anywhere in the EU have spent years answering to national supervisors who started asking algorithmic-governance questions long before Annex III existed, plus a set of EU-level frameworks — MiFID II, Solvency II, the ECB’s own supervisory manuals, GDPR — that already reach deep into how an AI agent can make decisions about a customer’s money.

The timeline matters more now than it did a year ago, because the AI Act itself just slowed down. In November 2025, the European Commission proposed a «Digital Omnibus» package pushing the compliance deadline for high-risk AI systems — including the two categories that cover most financial-services AI — from August 2026 to December 2027 . Parliament and Council finalized that delay in mid-2026 . The piece of EU law most people associate with regulating AI agents in finance won’t fully apply for more than a year past what most compliance calendars originally assumed. Nearly everything else covered here already does.

National Regulators Got There First, and Independently of Each Other

The three biggest financial centers in the eurozone didn’t coordinate their early AI guidance. They arrived at similar answers on their own, because they were interpreting similar underlying obligations.

BaFin’s approach, formalized in its «Big data and artificial intelligence» principles paper, organizes algorithmic decision-making into a development phase and an application phase, and sets four overarching expectations: clear management responsibility for AI design and use, appropriate risk and outsourcing management, protection against systematically biased outcomes, and a prohibition on using legally forbidden forms of differentiation — gender-based insurance pricing being the example BaFin names directly. BaFin was explicit that these were «preliminary ideas for minimum supervisory requirements,» published before a legal definition of AI existed, but usable immediately as guidance for firms under its supervision.

The Banque de France’s ACPR moved on a similar timeline but with a narrower initial focus. Its work began in 2018, aimed specifically at the explainability and governance of machine learning models, and produced a first report followed by a public consultation in 2019. A second discussion paper in 2020 added technical principles — data quality, model efficiency, model stability, explainability — layered onto governance expectations. By July 2026, that multi-year thread had produced a further discussion paper focused specifically on algorithmic fairness in financial services, working through how institutions should select fairness metrics and set thresholds for their own governance processes. Seven years of continuous, sector-specific work, none of it dependent on the AI Act existing.

DNB’s contribution, published in July 2019, is the one most people outside the Netherlands haven’t heard of, but it’s arguably the most legally interesting of the three. Rather than issuing new supervisory expectations, DNB explicitly grounded its six-part SAFEST framework — soundness, accountability, fairness, ethics, skills, transparency — in an existing statutory duty: the requirement that financial undertakings run «controlled and sound business operations,» applied proportionately to whatever AI application a firm happened to be running . The 17 individual recommendations under that framework read like a supervisory checklist rather than an ethics statement, down to recommendation 17’s call to «advance traceability and explainability of AI-driven decisions and model outcomes» — a sentence that predates the AI Act’s own Article 13 transparency provisions by roughly five years.

Three regulators, three countries, three starting points, and the same underlying conclusion: existing financial law already covers algorithmic decision-making, and firms don’t get a grace period while everyone waits for AI-specific legislation to catch up.

 

MiFID II Reached Every Investment Firm in the EU Before Annex III Did

Some of this oversight didn’t come from national regulators at all. On 30 May 2024, ESMA issued its first EU-wide public statement on AI, aimed at every investment firm providing services to retail clients under MiFID II, regardless of member state . Reuters summarized the core message accurately: EU securities regulators were putting boards on notice that they couldn’t shirk responsibility for AI-driven decisions, even when the underlying technology came from a third party .

That third-party point is the one firms tend to underestimate. ESMA’s statement applies «not only to instances where financial institutions develop or adopt AI tools in-house, but also to the use of third-party AI technologies, such as ChatGPT and Google Bard, even if senior management is not directly involved or aware.» That’s a direct answer to the «shadow AI» problem — employees quietly using consumer-grade chatbots for client-facing work without formal sign-off — and it removes the obvious defense that a firm never approved the tool.

The statement’s substance runs through MiFID II’s existing organizational and conduct-of-business requirements rather than inventing new ones. Management bodies need «appropriate understanding» of how AI is applied inside the firm, not just awareness that it’s happening. Firms need documented governance structures that monitor AI performance against their own risk tolerance, ex-ante controls to prevent AI systems from feeding clients inaccurate information, and ex-post controls to check what the AI actually told clients after the fact. Record-keeping obligations extend to data sources, algorithms implemented, and every modification made to a model over time — a standard that assumes a firm can reconstruct, months later, exactly what a client-facing AI tool was doing and why. ESMA framed this as an initial statement, operating «without prejudice» to the AI Act and DORA frameworks layered on top of it later — but MiFID II didn’t wait for either of those regimes to become binding, and it applies uniformly from Lisbon to Helsinki.

 

Insurance Runs on a Twelve-Year-Old Governance Duty

Insurers across the EU answer to a similar structure. Solvency II’s Article 41 has required an «effective system of governance which provides for a sound and prudent management of the business,» scaled to a firm’s nature, size, and complexity, since well before AI was a supervisory buzzword. EIOPA spent years turning that general duty into AI-specific expectation and its Consultative Expert Group on Digital Ethics published governance principles in June 2021. Proportionality, fairness and non-discrimination, transparency, human oversight, and data governance aimed at insurers using AI for pricing, underwriting, and claims decisions across every member state.

That groundwork became formal supervisory guidance on 6 August 2025, when EIOPA issued its Opinion on Artificial Intelligence Governance and Risk Management to national supervisors across the bloc . The Opinion is careful to note it isn’t creating new law: AI systems in insurance are «already subject to existing sectoral legislation,» and the Opinion exists to clarify how insurers should apply it. It covers data governance, record-keeping, fairness testing, cybersecurity, explainability, and human oversight, with specific instruction to treat Solvency II and DORA obligations as one connected governance system rather than two separate compliance tracks. National regulators have layered their own detail on top — DNB’s insurance-specific guidance, for instance, expects bias audits and diverse training data under «fairness,» a named board-level owner for AI-driven decisions under «accountability,» and documentation «that can be communicated comprehensibly to regulators and, where relevant, to customers» under «transparency.» That’s not a voluntary code of conduct in any member state that applies it. It’s what a prudential supervisor plans to ask for at the next review.

 

Where AI Actually Sits in the AI Act’s Own Risk Tiers

It’s worth being precise about what the AI Act does for finance across the whole EU, because the answer is narrower than most summaries suggest. Two use cases carry the high-risk label under Annex III: point 5(b), covering AI used to evaluate the creditworthiness of natural persons or establish a credit score, and point 5(c), covering AI used to assess risk and set pricing for life and health insurance. Fraud detection is explicitly carved out of both categories — a distinction worth flagging, because a firm might reasonably assume a transaction-monitoring model sits in the same risk tier as a credit-scoring model, when under the Act’s own text it doesn’t.

For firms caught by 5(b) or 5(c), Article 27 imposes a fundamental rights impact assessment, carried out before the system’s first use, covering the deployer’s intended process, the categories of people likely to be affected, the specific risks of harm, the human oversight measures in place, and the internal governance and complaint mechanisms available if something goes wrong . The results have to be filed with the relevant market surveillance authority using a template the EU’s AI Office is required to publish . Article 27(4) allows a firm to fold this into a GDPR Article 35 data protection impact assessment it may already be running, rather than starting from a blank page — a detail easy to miss and expensive to duplicate if missed.

None of that changes the fact that the clock on these obligations just moved for every firm in the EU simultaneously. Under the Digital Omnibus, standalone Annex III high-risk systems — credit scoring and insurance pricing among them — now have until 2 December 2027 to comply, not August 2026. AI embedded in already-regulated products gets until 2 August 2028. What the delay doesn’t touch is Article 50’s transparency requirements, which took effect on 2 August 2026 regardless of the Annex III postponement — meaning a customer-facing chatbot anywhere in the EU still has to disclose that it’s an AI system, even while the deeper risk-management obligations for credit and insurance models get another sixteen months.

 

The AI Act’s National Supervisors Aren’t the Same Everywhere

Here’s where the picture gets genuinely fragmented, in a way that matters for any firm operating across borders. The AI Act sets one EU-wide rulebook, but each member state chose its own competent authorities to enforce the financial-sector provisions, and the choices aren’t identical.

Germany moved fastest on formal legal designation. Under the German AI Market Surveillance and Innovation Promotion Act (KI-MIG), BaFin became the market surveillance authority for AI systems directly linked to regulated financial activities. That means AI Act compliance is now folded directly into BaFin’s day-to-day supervisory work rather than sitting with a separate horizontal regulator. BaFin followed that designation with detailed guidance, published in December 2025, on how AI-based systems — including generative AI and large language models — should be integrated into existing DORA-compliant ICT risk management, covering everything from cloud outsourcing due diligence to secure decommissioning of retired AI systems.

Ireland took a comparable route. The Central Bank of Ireland has confirmed it will act as the AI Act regulator for financial services under its remit, building on groundwork laid in speeches and its Innovation Hub reporting since at least 2024, when the Central Bank was already consulting on new Consumer Protection Code requirements for digital financial services with AI specifically in mind.

The Netherlands split the role rather than concentrating it. The RVO, the Netherlands Enterprise Agency, was named the AI Act’s primary national coordinating authority, but sectoral competence for financial services stayed with AFM and DNB under draft implementing legislation published in 2026 . That split traces back to a May 2024 recommendation from the Dutch Data Protection Authority, which proposed that AFM and DNB be designated market surveillance authorities specifically for the 5(b) and 5(c) Annex III categories insofar as they concern financial services, while the DPA itself would retain competence for comparable systems used elsewhere .

The practical consequence: a firm passporting financial services across Germany, Ireland, and the Netherlands under a single EU authorization is nonetheless dealing with three different AI Act enforcement structures — one where the financial regulator absorbed AI Act enforcement wholesale, one where the financial regulator was confirmed as sole authority for its remit, and one where enforcement is split between a general coordinating body and two sector-specific supervisors. The underlying substantive law is the same. The supervisory experience of building an AI agent under it is not.

 

The Central Bank Rewrote Its Own Model Manual Before the AI Act Applied Anywhere

The most concrete constraint on AI in eurozone banking right now doesn’t come from the AI Act at all — it comes from a chapter buried inside the ECB’s Guide to Internal Models, which applies across every country in the Single Supervisory Mechanism. The ECB rewrote the Guide in July 2025, largely to reflect the EU’s Capital Requirements Regulation 3, and used the update to add specific expectations for machine learning techniques used in banks’ internal models.

The scope is tighter than it sounds. It applies only to Pillar 1 models used to calculate regulatory capital — mainly credit risk, with the same logic reaching into market and counterparty credit risk models — and doesn’t extend to fraud detection, back-office automation, or marketing tools . Within that narrow lane, the ECB is direct about its concerns: model complexity, bias, and dynamism, meaning the tendency of a machine learning model to drift away from validated behavior once underlying data shifts. The operational requirement is simple to state: banks need a documented monitoring process for how these models evolve, and no material change can go live without supervisory sign-off first . A bank across the eurozone can’t let a credit model retrain itself on new data and keep feeding the output into regulatory capital calculations without checking with the ECB first — a constraint entirely outside the AI Act, DORA, or MiCA.

The ECB isn’t only writing these rules. It’s living under a version of them itself, and it’s said so publicly. An October 2025 speech from ECB Banking Supervision described building «Agora,» an internal data lake for prudential information, and a «supervisory cockpit» combining dashboards and AI assistants into «explainable flags and transparent workflows.» The governing principle the ECB applies to its own tools is that AI output must keep «human understanding and judgement at its heart,» not merely a human somewhere «in the loop» . A February 2026 follow-up described workshops the ECB ran directly with supervised banks to understand how AI adoption actually looked in practice, rather than relying on self-reported survey data. A supervisor holding itself to that standard internally, and checking its own assumptions through direct observation across the currency union, is unlikely to accept a looser one from the banks it examines.

 

The Directive the EU Chose Not to Finish

Not every gap in this landscape was filled by a regulator moving early. Some were left open deliberately, and the gap applies identically in every member state. On 31 July 2025, the European Commission confirmed it was withdrawing its proposed AI Liability Directive, alongside a separate proposal on standard essential patents, citing «no foreseeable agreement» among member states. The Commission had signaled the move in its February 2025 work program, and pressure from some lawmakers to keep the proposal alive didn’t change the outcome .

The withdrawal matters specifically for financial firms because of what the Directive would have done: ease the burden of proof for someone harmed by an AI system, including a presumption of causality in certain high-risk cases. Without it, a customer harmed by an automated decision anywhere in the EU — a wrongly frozen account, an insurance quote skewed by a biased pricing model, a trading algorithm executing an order the client never authorized — has to prove causation and fault under whichever national tort law applies. Those rules differ considerably by member state and were never written with autonomous decision-making systems in mind. The EU legislature looked directly at this question and chose not to answer it, at almost exactly the moment the underlying high-risk obligations in Annex III were also pushed back by more than a year.

 

A 2018 Data Protection Rule Still Does More Work Than the AI Act

One provision gets surprisingly little coverage in discussions of AI and financial services, despite giving every EU customer one of the sharpest tools they already have against automated decision-making: Article 22 of the GDPR. It has applied uniformly across all 27 member states since 25 May 2018, and it gives individuals the right not to be subject to a decision «based solely on automated processing» — including profiling — that produces legal effects or similarly significant consequences. Credit approvals, insurance pricing, and account closures fit that description without much argument, regardless of which country the customer or the firm is in.

Article 22 doesn’t prohibit automated decisions outright. It requires a lawful basis, meaningful information about the logic behind the decision, and — the part with real teeth — a route to human intervention, a chance to state a case, and the ability to contest the outcome. An AI agent that closes an account or rejects a loan application anywhere in the EU, with no defined path to a human reviewer, is already in breach of a rule that predates most current AI agent architectures by several years. It doesn’t need the AI Act’s Article 14 human-oversight provisions to become a problem; the exposure already exists, and it existed years before Annex III’s 5(b) credit-scoring category had a compliance date attached to it at all — let alone one that just moved to December 2027.

There’s a structural reason this rule ends up doing more day-to-day work across the EU than the AI Act’s headline provisions. Article 22 requires no risk classification exercise, no market surveillance notification, and no waiting period tied to harmonised technical standards. It simply applies whenever a solely automated decision produces a significant effect on a person, uniformly, and it has applied continuously since 2018 regardless of what happens to Annex III timelines in Brussels. A firm that maps its obligations only against the AI Act, MiCA, or DORA is likely to miss the one regime a European customer is statistically most likely to actually invoke — and the one regime that was never subject to a Digital Omnibus delay in the first place.

 

Building an AI Agent in a Bloc That Was Already Watching

None of this suggests the AI Act doesn’t matter. It sets a genuinely uniform baseline across 27 jurisdictions, gives supervisors a shared vocabulary they didn’t have before, and — once December 2027 arrives — will require formal fundamental rights impact assessments, conformity documentation, and registration for the credit-scoring and insurance-pricing systems at the center of consumer financial services. But a firm operating anywhere in the EU is stepping into a supervisory environment that has spent the better part of a decade asking pointed questions about algorithmic decision-making without waiting for that date to arrive. BaFin and the ACPR started in 2018, DNB in 2019. ESMA extended MiFID II’s existing obligations to AI use across every investment firm in the bloc in May 2024. EIOPA turned years of insurance-specific principles into formal guidance in August 2025. The ECB rewrote its own internal models manual to catch machine learning drift, independent of anything in Brussels’ AI-specific legislation. And national governments have each built their own AI Act enforcement structure on top of the same underlying law, producing genuinely different supervisory experiences from one member state to the next even where the substantive rules read identically on paper.

Practically, that changes where a firm should put its energy first. Rather than building an AI governance program keyed to the AI Act’s now-delayed rollout schedule, a bank, insurer, investment firm, or crypto-asset service provider operating in the EU is better served treating the older instruments as the live exam: the soundness and governance tests national supervisors have applied for years, the MiFID II record-keeping and oversight standard ESMA restated in 2024, the Article 41 governance duty every insurer already carries under Solvency II, the model-monitoring obligations the ECB now expects in writing across the eurozone, and the GDPR right to contest an automated decision that a customer can invoke today, in any member state, not in December 2027. Get those right, and the AI Act’s eventual Annex III obligations become one more layer to reconcile against work already done, rather than the starting point for a program built from nothing.

 


Sources:

National Regulators’ Early AI Guidance (Pre-AI Act)

BaFin — «Big data and artificial intelligence: Principles for the use of algorithms in decision-making processes»

Freshfields — «Putting the human in the loop: supervising AI use in Germany’s financial sector»

Lexology — «German financial regulator BaFin issues principles on big data and artificial intelligence»

ACPR (Banque de France) — «Governance of Artificial Intelligence in Finance»

Banque de France — «Implementing effective surveillance of AI in the financial sector»

ACPR — «Algorithmic fairness in the financial sector» (discussion paper, July 2026)

DNB — «General principles for the use of Artificial Intelligence in the financial sector» (July 2019)

Stibbe — «DNB’s AI Guidance: balancing innovation with prudence»

EU-Level Securities and Insurance Guidance

ESMA — «ESMA provides guidance to firms using artificial intelligence in investment services» (30 May 2024)

ESMA — Public Statement on AI and Investment Services (PDF)

Reuters — «EU watchdog says banks must take full responsibility when using AI»

Walkers — «AI guidance for investment services»

EIOPA — Opinion on Artificial Intelligence Governance and Risk Management (6 August 2025)

EIOPA — Opinion PDF (full text)

EIOPA — «Artificial intelligence governance principles» (Consultative Expert Group, June 2021)

ECB Banking Supervision

ECB Banking Supervision — «Artificial intelligence and supervision: innovation with caution» (14 October 2025)

ECB Banking Supervision — «Technology is neutral, governance is not» (24 February 2026)

ecbwatch (Substack) — «Machine Learning Rules»

AI Liability Directive Withdrawal

Euronews — «EU Commission confirms ditching of AI liability and patents proposals» (31 July 2025)

.

AI Act: Financial-Sector Scope, FRIA, and the Digital Omnibus Delay

regulatoryai.eu — «EU AI Act for Financial Services (2027)»

confir.eu — «Fintech Under the EU AI Act: Credit Scoring and Insurance»

artificialintelligenceact.eu — «Article 27: Fundamental Rights Impact Assessment for High-Risk AI Systems»

European Parliament — «MEPs support postponement of certain rules on artificial intelligence» (March 2026)

European Parliament Legislative Train — «Digital Omnibus on AI»

Reuters — «EU to delay ‘high risk’ AI rules until 2027 after Big Tech pushback» (19 November 2025)

aiactblog.nl — «The Digital Omnibus and the postponement of high-risk obligations»

CSA Research (Cloud Security Alliance) — «EU AI Act High-Risk Deadline Pushed to December 2027»

National AI Act Implementation and Supervisory Structure

Deloitte Legal — «AI supervision: BaFin becomes market surveillance authority»

Jones Day — «BaFin’s Expectations for ICT Risk Management and the Use of AI»

Central Bank of Ireland — Regulatory & Supervisory Outlook Report 2026

Central Bank of Ireland — Speech by Colm Kincaid, «Financial consumer protection and market conduct considerations of AI in finance» (22 May 2024)

Two Birds — «Dutch government publishes draft AI Act implementing legislation»

Loyens & Loeff — «Dutch implementation of the AI Act: decentralised AI supervision»

Dutch Data Protection Authority (Autoriteit Persoonsgegevens) — Second interim advice on the Dutch AI Act supervisory structure (16 May 2024)

agentliability.eu — «EU AI Act national supervisors in 2026: BaFin, AFM, ACPR and others»