Since August 2, 2026, core provisions of the EU AI Act have been legally binding. Banks and insurers must act immediately: all AI systems with which customers or employees interact directly must be clearly marked as AI. Failure to comply risks substantial fines.
Key Facts
- Labeling requirement effective now: Chatbots, voicebots, and AI advisory assistants must be clearly identifiable as AI – visible to humans and machine-readable (e.g., via metadata or watermarks)
- Transition period until December 2026: Existing systems have until December 2, 2026 to retrofit technically
- High-risk AI until 2027: Systems for credit assessment, fraud detection, or anti-money laundering must be converted by December 2, 2027
- Fines up to €35 million: Violations of transparency requirements can result in fines of up to €35 million or 7% of global annual turnover
What Specifically Requires Labeling
The regulations affect financial institutions and insurance companies across multiple areas. Affected are chatbots in online banking, voicebots for damage reporting, and AI-powered advisory assistants on websites and in apps. Labeling must be visible to users and machine-readable.
Additionally, there is a disclosure requirement for synthetic content – AI-generated or manipulated text, images, and videos (deepfakes) intended for public use without human editorial review. In the financial sector, this can include financial analyses or product descriptions.
High-Risk AI: Extended Deadlines, Stricter Requirements
Some relief comes from extended deadlines for high-risk AI systems. These cover particularly sensitive areas:
| Area | Deadline | Requirements |
|---|---|---|
| Transparency & Labeling | August 2, 2026 | Immediately applicable |
| Existing systems (general) | December 2, 2026 | Technical retrofitting |
| High-risk AI (credit, fraud, AML) | December 2, 2027 | Data quality, documentation, monitoring |
High-risk AI systems must be designed so that natural persons can monitor functionality and intervene if needed. Additional strict requirements apply to accuracy, robustness, and cybersecurity.
Fines in Focus of Regulators
Competent authorities – in Germany, BaFin – can monitor compliance and impose sanctions for violations. The penalty scale is substantial:
- Violations of prohibitions (Art. 5): up to €35 million or 7% of global annual turnover (whichever is higher)
- Violations of high-risk requirements: up to €15 million or 3% of global annual turnover
Violations of existing obligations for general-purpose AI models can be sanctioned as of August 2, 2026.
What This Means for German Financial Institutions
This regulation is not an announcement but legally binding. For German banks and insurers, this means: compliance departments must now review which AI systems are in use and where labeling is missing. BaFin has already announced it will monitor AI deployment in the industry accordingly. Those who fail to retrofit by December 2026 must expect inspections. High-risk systems are particularly critical – early documentation and risk analysis will pay off when facing BaFin audits.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




