Germany’s BaFin Becomes AI Market Surveillance Authority for Insurers

Germany’s BaFin Becomes AI Market Surveillance Authority for Insurers

Germany's new AI implementation law hands BaFin market surveillance powers over high-risk AI systems, including those insurers use for life and health risk assessment. The mandate is active now, well ahead of the AI Act's 2 December 2027 high-risk compliance deadline.

Germany’s financial supervisor has taken on a new role: policing artificial intelligence systems used directly in the country’s regulated financial sector, insurance included. The legal basis is the German Act Implementing the European Artificial Intelligence Act, which entered into force on 29 July 2026, and it hands BaFin oversight that reaches into how insurers build and use AI to assess life and health risk — well before most of the underlying EU rules for those systems actually bite.

Germany hands BaFin a standing AI market surveillance mandate

Germany’s legislature has expanded BaFin’s mandate to make it the market surveillance authority for AI systems used directly in regulated financial activities. The new responsibilities extend to credit institutions, insurers and other financial companies already under BaFin’s supervision, meaning the AI oversight layer follows the same institutional map as prudential supervision rather than creating a separate regulator. As BaFin President Mark Branson put it, the European AI Act supplements existing financial market regulation and gives companies a framework in which to innovate responsibly, in comments accompanying the regulator’s announcement of its new powers.

The move follows swiftly on from a separate but related development: the European Supervisory Authorities’ joint statement telling insurers to prove their AI governance, published days earlier. That statement set expectations at EU level; Germany’s new law gives BaFin the statutory tools to enforce them domestically.

What BaFin can now inspect, and where

BaFin’s market surveillance mandate is not a single check-the-box exercise; it spans three distinct categories of AI use. First, the regulator will monitor compliance with transparency obligations for AI systems that people interact with directly, such as chatbots used for communicating with customers. Second, BaFin will also monitor compliance with the AI Act’s provisions on prohibited AI practices among the insurers and other firms it supervises. Third — and most consequential for underwriting — BaFin’s market surveillance will cover high-risk AI systems, including those insurers use to assess risk in life and health insurance, alongside bank systems used to assess creditworthiness.

That high-risk category is not BaFin’s own invention. The EU AI Act’s Annex III defines high-risk AI systems as those falling within a specific list of use-case areas, and Annex III(c) specifically classifies AI systems used for risk assessment and pricing of natural persons in life and health insurance as high-risk. In practice, that pulls underwriting and pricing models — the core of how insurers decide who to cover and at what premium — squarely into BaFin’s inspection remit, alongside the transparency and prohibited-practice checks it already runs today. The concern about opacity in AI-driven pricing is not unique to Germany: the UK’s FCA Mills Review has separately warned that AI-set insurance pricing risks producing opaque value for customers, a theme BaFin’s own transparency and non-discrimination mandate echoes on the continent.

Why the high-risk clock runs to December 2027

BaFin’s authority to police high-risk insurance AI exists now, but the underlying compliance obligations for those systems are not yet in force — and the calendar behind that gap has moved. The EU AI Act entered into force on 1 August 2024 and became generally applicable on 2 August 2026, subject to certain exceptions. Two of those exceptions matter here. Certain prohibited AI practices, including systems that collect and analyze particularly sensitive personal information in ways that could unfairly disadvantage people, have been banned since 2 February 2025 — already well in effect. The AI Act’s first transparency obligations, covering systems like customer-facing chatbots, take effect on 2 August 2026.

High-risk obligations are the exception that moved. the application deadline for Annex III high-risk use cases, including life and health insurance risk assessment, was pushed from August 2026 to 2 December 2027 following the political agreement on the ‘AI Omnibus’ simplification proposal. The requirements for high-risk AI systems, including those insurers use for life and health risk assessment, formally enter into force on 2 December 2027. The result is a sequencing that looks counterintuitive at first glance: the supervisor with the mandate to inspect high-risk insurance AI is already in place, more than a year before the substantive high-risk obligations it will enforce actually apply. Germany is not alone in tightening the supervisory net around insurance AI ahead of binding deadlines: Switzerland’s FINMA has flagged cybersecurity findings that put Swiss insurers’ AI governance under fresh scrutiny, even without an equivalent statutory market-surveillance mandate.

Fines on the table once BaFin starts inspecting

BaFin will have the power to impose fines on supervised companies for violations of the European AI Act, giving the market surveillance mandate direct financial consequences rather than functioning as a purely advisory check. The scale of those fines is set at EU level rather than by Germany. Fines of up to €35m or 7% of worldwide annual turnover, whichever is higher, apply to infringements involving prohibited AI practices or non-compliance with data requirements. A second tier caps fines at up to €15m or 3% of worldwide annual turnover for non-compliance with other requirements of the Regulation, including the obligations that will apply to high-risk systems.

Financial supervisors elsewhere have already shown a willingness to use fines of that order for compliance failures short of AI: the UK’s PRA fined HDI Global SE over three years of FSCS data errors, a reminder that supervisory fines for governance and data failings are not merely theoretical once a regulator has both the mandate and the appetite to inspect.

Boards, not vendors, remain on the hook

BaFin has been explicit about where responsibility sits once an AI system is in production. Branson has said that using AI must ensure transparency, non-discrimination and effective risk management, that it must remain possible for people to correct and reverse decisions, and that supervised companies and their management boards are responsible for the use of AI. For insurers, that puts accountability for life and health underwriting models squarely with the board, not with whichever vendor supplied the underlying model. Combined with BaFin’s new inspection powers and the fine structure above, the message to German insurers is that the mandate to check high-risk AI is already active, even if the high-risk compliance obligations themselves are not due until 2 December 2027.

Sources used

Frequently Asked Questions

When do the AI Act’s high-risk obligations apply to insurers’ life and health AI systems?
The requirements for high-risk AI systems, including those insurers use for life and health insurance risk assessment, enter into force on 2 December 2027, after the Annex III deadline was pushed back from August 2026 following the political agreement on the ‘AI Omnibus’ simplification proposal.
What can BaFin fine insurers for under the AI Act?
BaFin can impose fines on supervised companies for violations of the European AI Act. Fines of up to €35m or 7% of worldwide annual turnover apply to prohibited-practice and data-related infringements, while fines of up to €15m or 3% of worldwide annual turnover apply to non-compliance with other requirements, including high-risk system obligations.
Which insurance AI systems now fall under BaFin’s market surveillance?
BaFin’s market surveillance covers high-risk AI systems, including those insurers use to assess risk in life and health insurance, based on Annex III(c) of the EU AI Act, which classifies AI systems used for risk assessment and pricing of natural persons in life and health insurance as high-risk.
N

Nicolas Martin

InsuraBeat correspondent

Senior reporter at InsuraBeat covering commercial and property & casualty markets, M&A, and underwriting performance across Europe and North America. Twelve years in the industry: started as an analyst on the broker side at a global reinsurance intermediary placing casualty and specialty risks for European corporates, then five years on the underwriting side at a Tier-1 European insurer, last managing D&O and cyber portfolios. Holds a Master in Reinsurance Economics and Capital Markets from the Kwang-Hwa Institute of Financial Sciences (Taipei) and is a CFA charterholder. Writes from Paris, on US morning markets.

All articles by Nicolas Martin →

Daily Beat newsletter

Never miss a beat in global insurance.

Get the day’s top deals, executive moves and regulatory shifts in your inbox every morning.

Free. No spam. Unsubscribe anytime.