The joint AFM and DNB report 'The impact of AI on the financial sector and supervision', published on 9 April 2024, states that financial institutions are expected to use AI responsibly and that existing regulations continue to apply in full. It says supervision objectives and standards are technology-agnostic, that specific references to AI in current financial regulation are few, and that the EU AI Act classifies creditworthiness assessment of natural persons and risk assessment and pricing in life and health insurance as high-risk. The report expects the existing financial regulators (the AFM and DNB in the Netherlands) to monitor AI Act compliance for financial services. It is a supervisory report, not a rulebook.
OFFICIAL TEXT: afm.nl ↗ · FINAL · DNB / AFM
| Document | AFM and DNB report on the impact of AI — The impact of AI on the financial sector and supervision |
| Issued by | De Nederlandsche Bank (DNB) and the Netherlands Authority for the Financial Markets (AFM) |
| Type | Report |
| Status | Final |
| Published | Apr 9, 2024 |
| Applies to | Dutch financial institutions supervised by the AFM or DNB, including banks, insurers and asset managers. The report formulates criteria and areas of attention for AI supervision and does not set binding rules; it excludes AI used by the authorities themselves. |
| Official source | afm.nl ↗ |
| Use cases | AI governance (general) · Credit scoring & underwriting · Fair lending & discrimination · Trading & capital markets · Model risk management · Fraud detection |
What are the key points of AFM and DNB report on the impact of AI?
- Published 9 April 2024 jointly by the AFM and DNB; the aim is to 'formulate criteria and areas of attention when shaping AI supervision', and the report says it does not provide ready-made answers.
- AI is defined as in the EU AI Act (OECD-based definition); Dutch institutions use AI for fraud prevention and detection, anti-money-laundering, creditworthiness assessment and identity verification, and most are cautious with generative AI.
- Risks: data quality, data protection, explainability, incorrect results, discrimination and exclusion, dependence on third parties, inadequate governance frameworks and energy consumption.
- Key message: supervision objectives and standards are technology-agnostic and apply when AI is used; institutions must set up proper risk management for AI, and standards on duty of care, product development and distribution and excessive borrowing also apply (Chapter 2.2.1).
- Chapter 2.2.2: AI is explicit in sector rules for algorithmic trading (MiFID II/MiFIR, citing Articles 17, 18, 26, 27, 45, 47 and 48 of MiFID II), the revised Consumer Credit Directive (CCD2, which the report says is to apply from 20 November 2026, including a right to human intervention in Article 18) and automated advice rules.
- Internal models: the report notes that CRR internal-model requirements, such as consistency and understandability of obligor classification (CRR Article 171) and 'plausible and intuitive' projections (Article 179), may make some AI models difficult to use, and that the framework may need clarification.
- Chapter 2.3: under the AI Act, AI used to check the creditworthiness of natural persons and for risk assessment and pricing in life and health insurance is high-risk; the AFM and DNB support voluntary compliance with high-risk requirements by other AI applications; the AI Act's supervisory role is assigned in principle to existing financial regulators.
- Next steps and supervision: DNB's 2024 thematic examination of AI use by insurers; the authorities said they would hold symposiums and round-table discussions with the sector later in 2024.
What did AFM and DNB report on the impact of AI change for banks?
The report moved Dutch AI supervision from DNB's 2019 principles to a joint, AI-Act-aware position: no new AI rulebook, but a clear statement that responsible-use expectations and existing financial rules apply in full, a mapping of where AI is already regulated, and a signal that the AFM and DNB will step up supervision of AI risk management.
What do the AFM and DNB expect from banks using AI?
The AFM and DNB's 9 April 2024 report expects financial institutions to use AI responsibly: AI must not jeopardise the financial soundness and integrity of institutions, harm customers' interests or damage the integrity of relationships between market players. The objectives of supervision and the standards institutions must meet are technology-agnostic, so existing requirements apply to AI, including proper risk management that covers AI risks, sound and ethical operational management, the duty of care, product development and distribution standards and rules against excessive borrowing. The more important AI becomes in decision-making and the greater the potential consequences, the higher the bar for responsible, explainable use. For credit scoring of natural persons, the AI Act adds high-risk requirements. The report itself sets no new rules.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Key messages — Responsible use of AI | DNB / AFM | Use AI responsibly: AI systems must not jeopardise financial soundness and integrity or harm customers' interests; existing regulations apply in full. | Published 9 April 2024 |
| Chapter 2.2.1 — Sound and ethical operational management | DNB / AFM | Set up proper risk management covering the risks of AI, with special attention to shortcomings in data (input), models (throughput) and results (output), including discrimination. | Published 9 April 2024 |
| Chapter 2.2.1 — Customer-interest standards | DNB / AFM | Apply duty of care, product development and distribution standards and rules against excessive borrowing regardless of whether AI created the product or service. | Published 9 April 2024 |
| Chapter 2.2.2 — Algorithmic trading, CCD2 and automated advice | DNB / AFM | Comply with sector rules that explicitly address algorithms: safeguards for algorithmic trading, creditworthiness assessment and transparency under CCD2, and testing and expertise requirements for automated advice. | Published 9 April 2024 |
| Chapter 2.2.2 — Internal models | DNB / AFM | Meet CRR internal-model requirements (for example Articles 171 and 179) when using machine learning for IRB models; the report notes these may need clarification. | Published 9 April 2024 |
| Chapter 2.3 — AI Act high-risk applications | DNB / AFM | Prepare for the AI Act's high-risk requirements for creditworthiness assessment of natural persons, including risk management, data quality, documentation, human oversight and robustness. | Published 9 April 2024 |
| Chapter 2.4 — Fundamental rights | DNB / AFM | Assess the impact of high-risk AI on the fundamental rights of individuals or groups and avoid discrimination. | Published 9 April 2024 |
The report builds on DNB's July 2019 SAFEST paper and a 2019 joint AFM and DNB paper on AI in insurance, and treats the AI Act as the future framework for high-risk applications while arguing that sector-specific clarification should preferably happen in a harmonised way at European level.
Subsequent AFM publications show the supervisory direction: the AFM Agenda 2026 (19 January 2026) says it is expanding AI supervision and asks institutions to map AI applications, strengthen model risk management and data quality, record decision-making logic and report incidents. DNB's 2024 thematic examination covered insurers' use of AI.
WHAT THIS MEANS IN PRACTICE
- Embed AI inside existing risk management rather than creating a separate regime; check input data, models and outputs for discrimination.
- Check customer-facing AI against duty-of-care and product-governance standards.
- For IRB or other internal models using ML, test the approach against CRR requirements such as consistency, plausibility and explainability.
- Inventory AI-based creditworthiness tools for AI Act high-risk compliance and fundamental-rights impact assessment.
- Keep traceable records of AI decision logic and report AI-related incidents.
Is the AFM and DNB AI report binding?
No. It is a joint report that formulates criteria and areas of attention for AI supervision. The standards it refers to — sound and ethical operational management, duty of care, product governance — are binding rules under existing financial law that apply to AI like any other technology.
Does the AFM and DNB report apply to banks?
Yes. It covers the Dutch financial sector, discusses CRR/CRD risk-management requirements and IRB internal-model rules for banks, and treats AI-based creditworthiness assessment as high-risk under the AI Act.
Who will supervise the AI Act for financial institutions in the Netherlands?
The report says the principle of the AI Act is that existing financial regulators — the AFM and DNB in the Netherlands — monitor compliance where AI is used for financial services, and that the current split of supervision between them is expected to apply.
How does the AFM and DNB report compare with the EU AI Act?
The report is non-binding supervisory analysis; the AI Act is binding law. The report says AI Act requirements for high-risk systems (risk management, data quality, documentation, human oversight, robustness) are mostly in line with existing governance rules and that institutions should also assess fundamental-rights impact.
| Date | Document | Status |
|---|---|---|
| Jul 25, 2019 | DNB SAFEST AI principles — General principles for the use of Artificial Intelligence in the financial sector | Final |
| Sep 30, 2026 | SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act) | Final |
| Sep 30, 2026 | Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey | Final |
| Sep 28, 2026 | AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act) | Final |
| Sep 10, 2026 | Atkins remarks at Investor Advisory Committee (Sep 2026) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information Ecosystem | Final |
| Sep 2, 2026 | FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber Resilience | In force |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning