BaFin AI Guidance: What Banks and Insurers Should Now Implement for ICT Risks under DORA
6 October 2026

What BaFin published
On 18 December 2025, BaFin published the German original of its guidance on ICT risks in the use of AI at financial entities (“Orientierungshilfe zu IKT-Risiken beim Einsatz von KI in Finanzunternehmen”) — 38 pages, issued by Division CTF 5 of the Cyber Risks and Technology in the Financial Sector directorate. The English translation, “Guidance on ICT Risks in the Use of AI at Financial Entities” (version date 23 January 2026), followed on 30 January 2026. The guidance is expressly non-mandatory advice: it does not define supervisory expectations and is not a binding interpretation of DORA. It is aimed primarily at CRR institutions and Solvency II insurers that apply ICT risk management under Art. 5 to 15 DORA; the simplified framework under Art. 16 DORA is not covered. It is structured in six chapters plus a case study on operating an LLM-based AI assistant.
Why this matters now
DORA has applied since 17 January 2025. BaFin’s sector-specific IT circulars KAIT, VAIT and ZAIT have since been repealed, and the BAIT no longer apply to DORA entities either — they will be repealed in full at the end of 31 December 2026. DORA is therefore the benchmark for these entities’ IT — including AI. In parallel, since 29 July 2026 BaFin has been the market surveillance authority under the KI-MIG (Germany’s AI Act market surveillance and innovation act) for AI systems directly connected with regulated financial activities (section 2(3) KI-MIG); following the postponement by Regulation (EU) 2026/1744, the high-risk obligations under Annex III of the AI Act — for example for creditworthiness assessment of natural persons — apply from 2 December 2027. The guidance, however, does not deal with obligations under the AI Act; it addresses ICT risks under DORA exclusively. It shows how existing DORA requirements can be applied to AI systems, which, according to BaFin, financial entities already use along their entire value chain.
The core idea: an AI system is ICT — along its lifecycle
BaFin adopts the definition of an AI system from Art. 3(1) AI Act and classifies AI systems as a subset of network and information systems under Art. 3(2) DORA; the model itself is considered an ICT asset. It follows that AI systems belong in the existing ICT risk management framework (Art. 6 DORA), in the asset inventory (Art. 8(4) DORA) and — where third parties provide them — in ICT third-party risk management (Art. 28 DORA). The guidance looks at risks not along the value chain but along the AI lifecycle, because they arise from integration into the ICT landscape. The guiding principle is proportionality under Art. 4 DORA: AI in critical or important functions needs more extensive security and control measures than a self-service assistant that is completely under human supervision and not involved in decision-making. A practical pointer from Chapter III: if an application integrates external AI models via an API, it can itself become an AI system.
Governance, risk management framework, development and testing
The management body bears ultimate responsibility for ICT risks (Art. 5(2)(a) DORA); its members must actively keep their knowledge and skills up to date (Art. 5(4)), and staff must receive training appropriate to their tasks (Art. 13(6)). BaFin describes an AI strategy approved by the management body as common practice. AI-specific vulnerabilities in training, data pipelines and inference belong in risk identification (Art. 8 DORA), and the framework must be reviewed at least once a year (Art. 6(5) DORA). For development and testing, the guidance relies almost entirely on the RTS RMF: project management, specifications with protection against manipulation, change management, and testing before going into production with a scope commensurate with criticality (Art. 15 to 17 RTS RMF). The requirements also apply, on a risk basis, to end-user computing (EUC) (Art. 16(9) RTS RMF), and according to BaFin, AI-generated code is subject to the same rules as human-written code. Depending on criticality, BaFin cites adversarial testing, adversarial penetration testing and stress testing as useful practice — and identifies unannounced changes to models obtained from third parties as a particular challenge for testing.
Operation, cloud and third parties
In operation, DORA requires a policy and procedures for ICT asset management (Art. 8(4) DORA in conjunction with Art. 4 and 5 RTS RMF); the guidance explicitly includes training data, model implementations, libraries and hardware. Art. 10 RTS RMF makes automated vulnerability scans and patch deadlines mandatory; for critical or important functions, BaFin recommends thresholds and indicators of anomalous behavior. Because AI systems are often operated in the cloud, Chapter IV.2 applies aspects of BaFin’s Cloud supervisory statement on outsourcing to cloud service providers of 1 February 2024 to AI: a risk assessment and due diligence before the contract is concluded (Art. 28(4) DORA), including model changes made by the provider; transparency on subcontractors such as GPU farms or ML libraries (Art. 29 and 30 DORA); SLAs on latency and computing capacity; and an exit strategy with exportable models, training data and configurations. For retirement, BaFin considers it advisable to lay down rules for removing models irretrievably and deactivating obsolete versions.
Cyber and data security, incident reporting
AI systems belong in the ICT security policies (Art. 9(2) DORA). Mandatory requirements include a network architecture segmented by criticality (Art. 13 RTS RMF) as well as encryption and key management based on data classification (Art. 6 and 7 RTS RMF). BaFin also names as proven measures web application firewalls and API gateways, zero trust for access to AI services, data loss prevention, model signing, and protection against injection attacks and overload. According to BaFin, the most important basis for processing data securely is classifying it by confidentiality, integrity and availability. Incidents in AI systems must be recorded as ICT-related incidents and their root causes identified (Art. 17 DORA); major ICT-related incidents must be reported (Art. 19 DORA). BaFin additionally recommends flagging AI-related incidents and, after such incidents, carrying out a detailed root cause analysis to remedy systematic weaknesses in AI models and processes. BaFin’s analysis of DORA incident reports shows how relevant third parties are in general: around half of the 733 ICT incidents reported in 2025 stemmed from problems at third parties — there are no AI-specific figures.
The case study: one AI assistant, three infrastructure variants
The case study walks through an LLM-based AI assistant for texts, emails and presentations — across six phases from data acquisition to retirement and in three variants: on-premises, with full control but all the risks of development, operation and maintenance; cloud in the entity’s own tenant, where the main risk is dependency on the model operator unless an open-source model is used; and cloud outside the tenant, such as an LLM accessed via an API or an AI assistant in standard software. In the third variant, data leaves the tenant and flows to the model provider — according to the case study, this should be countered contractually and technically, for example with upload restrictions, a Governance Shield that checks inputs for confidential content, or a lower data clearance level. Important: the measures in the case study are expressly illustrative and do not constitute supervisory expectations. Our recommendation: inventory AI features in standard software such as Microsoft 365 Copilot first, because according to the case study, such assistants are sometimes invoked without users’ knowledge — the guidance itself names no products.
What we have published
Our new knowledge page makes the 38 pages actionable and consistently separates obligation under DORA and the RTS, practice per the guidance, and VamiSec recommendation. A Scope Check shows what control depth is appropriate for your AI system. The Lifecycle Navigator guides you through six phases and two cross-cutting topics with risks, legal anchors, audit questions and evidence. The Variant Lab presents the three infrastructure variants as data flows and uses a traffic light to show how we rate each variant per data class. The Citation Navigator opens up all 97 citations by our count. With up to 31 questions across seven action areas, the AI Resilience Check determines your target level based on your profile and shows your biggest gaps and a 30/90/180-day roadmap. In addition, the 50-page whitepaper “KI unter DORA für CISOs” (“AI under DORA for CISOs”, in German) provides 30 audit questions, an evidence matrix and a 12-month roadmap.
All links
Knowledge page on BaFin’s AI guidance: https://vamisec.com/en/wissen/grc/bafin-orientierungshilfe-ki-ikt-risiken · AI Resilience Check: https://vamisec.com/en/wissen/grc/bafin-orientierungshilfe-ki-ikt-risiken#ki-check · Request the whitepaper “KI unter DORA für CISOs”: https://vamisec.com/en/wissen/grc/bafin-orientierungshilfe-ki-ikt-risiken#whitepaper · DORA knowledge page: https://vamisec.com/en/wissen/grc/dora · BaFin news release of 18 December 2025 (German): https://www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Meldung/2025/meldung_2025_12_18_orientierungshilfe_ikt_risiken.html · Guidance (German original): https://www.bafin.de/SharedDocs/Downloads/DE/Anlage/dl_Anlage_orientierungshilfe_IKT_Risiken_bei_KI.html
Do you have questions about your organization's IT security?
Free Initial Consultation →