Live Updates

Artificial intelligence: BaFin publishes guidance on ICT risks

The Federal Financial Supervisory Authority (BaFin) has issued its โ€œGuidance on ICT Risks in the Use of Artificial Intelligence at Financial Entitiesโ€. The guidance will help entities manage ICT risks in accordance with the requirements under DORA.

AI Analysis

BaFin's "Guidance on ICT Risks in the Use of Artificial Intelligence at Financial Entities," published December 18, 2025, provides non-mandatory advice to help financial entities manage ICT risks from AI under DORA across the AI lifecycle. It matters because it integrates AI explicitly into existing ICT risk frameworks, emphasizing security, resilience, and third-party risks for supervised institutions, aligning with RTS on ICT risk management (EU 2024/1774) and subcontracting (EU 2025/532). This clarifies supervisory expectations amid growing AI adoption in finance, reducing ambiguity in DORA compliance.

BankInsuranceAll Firms