Solvency II

Banks: your AI Act regulator is already your supervisor

Recital 158 of the EU AI Act (Regulation (EU) 2024/1689) designates the authorities that already supervise credit institutions, insurers, and credit intermediaries — under the Capital Requirements Regulation, the Capital Requirements Directive, Solvency II, the Consumer Credit Directive, the Mortgage Credit Directive, and the Insurance Distribution Directive — as the market surveillance authorities for AI systems offered or used by regulated financial institutions, unless a Member State designates someone else instead. And Articles 17(4), 18(3), 19(2), and 26(5)-(6) let those same institutions discharge several AI Act quality-management, documentation, and logging duties by pointing to the internal governance rules they already follow under financial services law. A lot of banks are budgeting for a new AI regulator that, for them, mostly doesn’t exist.

Who your regulator actually is

The default answer is your existing financial supervisor — the authority already responsible for supervising you under CRR, CRD, Solvency II, the Consumer Credit Directive, the Mortgage Credit Directive, or the Insurance Distribution Directive, depending on which regime you sit under. That’s the designated market surveillance authority for the AI systems you offer or use.

The wrinkle is that Member States can designate a different authority for this specific task instead, so the answer is genuinely national rather than uniform across the EU. Check the actual designation in each market you operate in — don’t assume your home supervisor’s role carries over unchanged into every jurisdiction you’re active in.

The ECB pipe

For credit institutions supervised under CRD and participating in the Single Supervisory Mechanism, Recital 158 adds a specific reporting line: when their national supervisor is acting as the AI Act market surveillance authority, it has to report to the European Central Bank, without delay, any information from its market surveillance activities that could potentially be relevant to the ECB’s own prudential supervision tasks. Spell out what that means in practice: an AI Act finding about your systems doesn’t stay inside an “AI compliance” silo. By design, it can land on your prudential supervisor’s desk quickly, through the same channel that already carries your other supervisory information.

The four substitutions, article by article

Four separate provisions let a regulated financial institution meet AI Act obligations through governance it already has, rather than building a parallel structure from nothing.

Article 17(4) deems the quality management system obligation fulfilled by complying with the internal governance rules already required under financial services law — but only for most of Article 17(1). The provision carves out three specific elements by name: the risk management system under Article 9, the post-market monitoring system under Article 72, and the serious-incident reporting procedures under Article 73. Those three still have to be addressed directly under the AI Act, regardless of how mature your existing banking governance is. It’s a partial substitution, not a blanket one, and it’s deliberately calibrated to leave the elements closest to actual AI safety oversight outside the shortcut.

Article 18(3) lets technical documentation retention be discharged as part of the documentation you already retain under financial services law. Article 19(2) does the same for the automatically generated logs your high-risk systems produce. Articles 26(5)-(6) extend the same logic to deployers specifically — the ongoing monitoring obligation and the log-retention duty are both deemed fulfilled by complying with existing internal governance rules under financial services law.

What substitution does not cover

Beyond the Article 9/72/73 carve-out inside Article 17(4) itself, the substitution mechanism doesn’t touch several other obligations at all. The substantive Chapter III Section 2 requirements — Articles 9 through 15 — still have to actually be met; the substitution changes how you evidence quality management, not what a high-risk system has to do. Article 27’s fundamental rights impact assessment, owed by deployers of the Annex III 5(b) and 5(c) categories specifically, is a separate duty with no financial-services equivalent standing in for it. Article 49 registration is still owed. Article 50 transparency, where it applies, is still owed. None of these get a banking-sector shortcut.

What this forces on your operating model

The practical consequence is that AI Act compliance and financial regulatory compliance can’t be run as two separate programmes that happen to share a subject. The same authority reads both, and for SSM banks, findings can flow onward to the ECB. A parallel AI governance stack that doesn’t talk to your existing prudential and conduct compliance function is exactly the failure mode this structure is built to expose — inconsistency between the two becomes visible to the one regulator positioned to see both at once, immediately, rather than eventually.

What is high-risk for a bank at all

Briefly, since this is covered in full in a companion piece on AML and fraud detection: Annex III 5(b) makes creditworthiness assessment and credit scoring of natural persons high-risk, and 5(c) does the same for life and health insurance risk assessment and pricing — with financial fraud detection specifically carved out of 5(b), and further exceptions for fraud detection and prudential capital calculation set out in Recital 58. The detail of where those carve-outs hold and where they collapse is worth reading on its own rather than repeating here.

Frequently asked questions

Do we need a separate AI management system?

Not necessarily a wholly separate one for the quality-management obligation specifically — Article 17(4) lets your existing governance framework serve that function, minus the three carved-out elements. Risk management under Article 9, post-market monitoring under Article 72, and serious-incident reporting under Article 73 need direct attention regardless of how developed your banking governance already is.

Does BaFin or the AI Office supervise us?

Your national financial supervisor by default — BaFin, for a German institution — under the Recital 158 designation, not a separate AI Office function created from scratch. That only changes if your Member State has specifically designated a different authority for this role.

Do our DORA controls count toward this?

DORA isn’t one of the instruments Recital 158 names, and I haven’t found anything establishing that Digital Operational Resilience Act controls substitute for AI Act obligations the way CRD or Solvency II governance does. Treat this as a genuine open question rather than an assumed yes — the overlap may be substantive, but it isn’t a stated legal substitution route.

What about our model risk management framework?

Same answer. A model risk management framework may cover much of the same ground as Article 9’s risk management system in substance, but it isn’t one of the six instruments Recital 158 names as a basis for substitution. Don’t assume it discharges an AI Act obligation without checking whether your supervisor treats it that way.

Does the Omnibus change who supervises us?

Not as far as the current record shows. The Digital Omnibus reform’s substantive changes concentrate on Annex III and Annex I timing, the registration duty, and the safety-component definition — nothing reported so far touches the Recital 158 supervisory-authority designation itself.

Posted by admin in Financial, AML & Regulatory Reporting Knowledge Base