BaFin's 'Guidance on ICT Risks in the Use of AI at Financial Entities' (German original dated 18 December 2025; English version dated 23 January 2026 and published on 30 January 2026) explains how DORA's ICT risk management and ICT third-party risk requirements apply to AI systems. It is aimed in particular at banks (CRR institutions) and Solvency II insurers and walks through the AI lifecycle: governance, development and testing, operation and retirement, and cyber and data security, with a case study on an LLM-based AI assistant. BaFin says it is non-mandatory advice that does not define supervisory expectations or bind BaFin's interpretation of DORA. A bank should treat AI systems as ICT assets inside its DORA ICT risk management framework.
OFFICIAL TEXT: bafin.de ↗ · FINAL · BAFIN
| Document | BaFin guidance on ICT risks in the use of AI — Guidance on ICT Risks in the Use of AI at Financial Entities |
| Issued by | Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin), Germany's Federal Financial Supervisory Authority, working with the Deutsche Bundesbank |
| Type | Guidance |
| Status | Final |
| Published | Dec 18, 2025 |
| Applies to | Financial entities that must comply with the ICT risk management requirements in Articles 5 to 15 of DORA, in particular CRR institutions (banks) and Solvency II insurers; the simplified framework in Article 16 DORA is not covered. The guidance is non-mandatory advice, not a binding interpretation of DORA, and defines no supervisory expectations. |
| Official source | bafin.de ↗ |
| Use cases | Cybersecurity · Third-party & vendor AI · Generative & agentic AI · AI governance (general) · AI-generated code & coding agents · Data & privacy |
What are the key points of BaFin guidance on ICT risks in the use of AI?
- Non-mandatory advice to help financial entities implement DORA when using AI; based on discussions with financial entities; 'does not constitute a binding interpretation of DORA' and 'does not define any supervisory expectations'. Described as a living document.
- Scope: entities subject to the ICT risk management requirements in Articles 5 to 15 DORA, with ICT third-party risk management, the Delegated Regulation (EU) 2024/1774 (RTS RMF) and the Delegated Regulation (EU) 2025/532 (RTS Subcontracting); Article 16 DORA entities are excluded.
- Definition: AI system as in Article 3(1) of the EU AI Act, understood for this guidance as a combination of ICT assets and ICT infrastructure in which a complex mathematical model (itself an ICT asset) is implemented; the guidance does not address autonomy, adaptiveness, modelling methodology or data validation.
- Proportionality (Article 4 DORA): AI used in critical or important functions needs more extensive security and control measures than, for example, a human-supervised self-service assistant.
- Chapter II: AI risk is assessed like other ICT risk; management body responsibility under Article 5(2)(a) and 5(4) DORA; AI systems belong in the ICT risk management framework (Articles 6, 8 and 9), which must be reviewed at least annually (Article 6(5)).
- Chapters III and IV: apply standard software development, testing (RTS RMF Articles 16 and 17), asset identification (Article 8(4) DORA with RTS RMF Articles 4 and 5), monitoring and logging (Article 10), business continuity and recovery (Articles 11 and 12), and secure retirement of models and data; examples include adversarial testing, model-drift monitoring and versioning of model artefacts.
- Cloud and third parties: risk assessment and due diligence (Article 28), subcontracting transparency (Article 30(2)), SLAs for critical or important functions (Article 30(3)), audit rights, exit strategies and portability including models, training data and configuration (Article 28(7) and (8)); references BaFin's and the Bundesbank's cloud outsourcing statement.
- Chapter V and annex: cybersecurity and data security across the lifecycle, and reporting of major ICT-related incidents under Article 19 DORA; the annex case study of an LLM-based assistant (on-premise, own cloud tenant, or provider outside the tenant) is illustrative and expresses no supervisory expectations.
What did BaFin guidance on ICT risks in the use of AI change for banks?
Before this guidance, BaFin's AI papers addressed model governance (2021, 2022). This is its first guidance linking AI directly to DORA: it tells banks that AI systems — including LLM assistants embedded in standard software and AI-generated code — are ICT assets whose lifecycle, third-party dependencies and incidents fall under existing DORA duties, without adding new legal obligations.
What does BaFin's guidance on ICT risks in the use of AI require of banks under DORA?
BaFin's guidance does not create new requirements: it explains how existing DORA duties apply to AI systems. A bank's management body remains ultimately responsible for ICT risk (Article 5 DORA), AI systems must be identified, classified and managed as ICT assets inside the ICT risk management framework (Articles 6 to 11), and the framework must be reviewed at least annually. AI used in critical or important functions requires more extensive controls under the proportionality principle (Article 4). The guidance applies the same logic to development and testing, operation and retirement, third-party and cloud use (Articles 28 to 30), cybersecurity and reporting of major ICT-related incidents (Article 19). It is non-mandatory advice and, in BaFin's words, does not define supervisory expectations.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Article 4 DORA — Proportionality | BaFin | Apply the risk-based approach: AI integrated into critical or important functions needs more extensive security and control measures than AI that is fully human-supervised and not involved in decisions. | Published 18 December 2025 (German); English translation 30 January 2026 |
| Article 5(2)(a) and 5(4) DORA — Management body | BaFin | The management body bears ultimate responsibility for managing ICT risk and must keep sufficient knowledge and skills to assess ICT risks, including AI; responsibilities for the use of AI outputs in decisions should be defined. | Published 18 December 2025 (German); English translation 30 January 2026 |
| Articles 6, 8 and 9 DORA — ICT risk management framework | BaFin | Include AI systems in the framework: identify vulnerabilities in training, data pipelines and inference, document and regularly review measures such as adversarial training and drift monitoring, and review the framework at least annually (Article 6(5)). | Published 18 December 2025 (German); English translation 30 January 2026 |
| Article 8(4) DORA with RTS RMF Articles 4 and 5 — Asset identification | BaFin | Identify, classify, document and monitor AI components — training data sets, model implementations, libraries, hardware and software — as information and ICT assets. | Published 18 December 2025 (German); English translation 30 January 2026 |
| Articles 10 to 12 DORA — Detection, response, recovery | BaFin | Monitor AI systems for anomalies, log AI decisions and model versions risk-based, include critical AI in business continuity and recovery planning, and back up model artefacts and data sets. | Published 18 December 2025 (German); English translation 30 January 2026 |
| Articles 24 and 25 DORA with RTS RMF Article 16 — Testing | BaFin | Test AI systems in proportion to criticality, including source-code review for open-source libraries and, where suitable, adversarial testing, penetration testing and stress tests. | Published 18 December 2025 (German); English translation 30 January 2026 |
| Articles 28 to 30 DORA — ICT third-party risk | BaFin | For AI supplied by third parties or run in the cloud: pre-contract risk assessment, subcontracting transparency, SLAs and security terms for critical or important functions, audit rights and a tested exit strategy including portability of models and data. | Published 18 December 2025 (German); English translation 30 January 2026 |
| Articles 17 and 19 DORA — ICT incidents | BaFin | Capture incidents in AI systems in the ICT incident management process and report major ICT-related incidents promptly to the competent authority. | Published 18 December 2025 (German); English translation 30 January 2026 |
The guidance is an interpretation aid from BaFin's CTF 5 division. It reuses the AI Act's definition of an AI system but deliberately limits itself to ICT risks, leaving modelling methodology, data validation, autonomy and adaptiveness to other regimes such as the EU AI Act and BaFin's model-risk papers. It therefore complements the 2021 BDAI principles and 2022 results paper on model governance.
For supervision, BaFin signals no new examination standard: the requirements it describes derive from DORA, the RTS on ICT risk management and the RTS on subcontracting, and the guidance's own text says it does not define supervisory expectations. Its case study on an LLM-based assistant is explicitly illustrative.
At EU level, the ESAs' July 2026 statement on ICT risks from frontier AI models (JC 2026 25) and the ECB's work cover related ground; they are tracked separately on this site.
WHAT THIS MEANS IN PRACTICE
- Add AI systems, models, training data sets and libraries to the DORA register and asset inventory with criticality classification.
- Include AI incidents, model drift and data poisoning scenarios in ICT incident management, testing and continuity plans.
- Re-run third-party due diligence for AI services consumed via API or embedded in standard software, including subcontractors and data locations.
- Plan exit and portability for AI services supporting critical or important functions, including export formats for models and training data.
- Apply the same change management, code review and testing to AI-generated code and to AI built outside the ICT function.
Does BaFin's DORA AI guidance apply to banks?
Yes. It is aimed in particular at institutions subject to the Capital Requirements Regulation and Solvency II insurers, and more broadly at entities that must meet the ICT risk management requirements in Articles 5 to 15 DORA. Entities under the simplified framework in Article 16 DORA are not covered.
Is the BaFin guidance on ICT risks in AI binding?
No. BaFin calls it non-mandatory advice, says it does not constitute a binding interpretation of DORA, and says it defines no supervisory expectations. The underlying DORA and RTS requirements are binding.
When was the BaFin AI guidance published?
The German-language Orientierungshilfe is dated 18 December 2025. BaFin's English translation, version dated 23 January 2026, was published on 30 January 2026.
What does the guidance say about AI in the cloud?
It applies DORA's third-party rules: pre-contract risk assessment and due diligence, transparency on subcontractors and data processing locations, SLAs and security agreements for critical or important functions, audit rights, and exit strategies ensuring that models, training data and configurations can be exported to another environment.
| Date | Document | Status |
|---|---|---|
| Feb 18, 2022 | BaFin/Bundesbank ML in risk models results — Machine learning in risk models – Characteristics and supervisory priorities: Responses to the consultation paper | Final |
| Jun 15, 2021 | BaFin BDAI principles paper — Big data and artificial intelligence: Principles for the use of algorithms in decision-making processes | Final |
| Sep 30, 2026 | Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey | Final |
| Sep 2, 2026 | FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber Resilience | In force |
| Aug 31, 2026 | FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models | Final |
| Jul 31, 2026 | ESA Statement on ICT risks from frontier AI models (JC 2026 25) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models | In force |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning