AI Regulation in Practice: What Supervisors Really Expect to See from AI in the Financial Sector | ALLES LEGAL #126

🎧Artificial intelligence in the financial sector is firmly on supervisors’ radar – but what are they actually looking for? In this episode, Annerton partner Josefine Spengler joins Dana Wondra from Payment & Banking to discuss how supervisory authorities assess AI systems in practice. In part two of our “AI in Finance” series, the focus shifts from strategy to supervisory reality. – Tune in!

Podcast: https://paymentandbanking.podigee.io/797-alles-legal-126-ki-regulierung-in-der-praxis-was-dieaufsicht-zu-ki-im-finanzsektor-wirklich-sehen-will/

AI under supervision: not a special case, but part of IT governance

The key takeaway: from a supervisory perspective, AI is not treated as a stand-alone innovation project. Instead, it is primarily regarded as an IT/ICT system with specific risk characteristics and assessed under existing regulatory frameworks – in particular DORA.

Governance over hype: what really matters in supervisory reviews

The decisive question is not whether AI is used, but how it is embedded, governed and monitored within the organisation. Supervisory reviews therefore concentrate on fundamental governance aspects:

  • Who is accountable for AI-driven decisions?
  • How was the model developed and validated?
  • How is it continuously monitored?
  • How can outcomes be explained and traced?

Performance metrics alone are not enough. Supervisors increasingly focus on traceability, controllability and clear allocation of responsibilities.

DORA meets the AI Act: breaking down silos

Complexity increases where DORA and the EU AI Act apply simultaneously. While DORA addresses operational resilience, risk management and third-party oversight, the AI Act follows a risk-based approach with requirements relating to transparency, documentation and human oversight.

For financial institutions, this means AI governance cannot be organised in silos. Treating regulatory requirements separately may lead to parallel structures instead of an integrated control framework.

From snapshot reviews to continuous supervision

International discussions, including at OECD level, highlight that the real challenge lies less in creating new rules and more in applying them to dynamic, evolving systems. Supervisory practice is therefore shifting – from one-off assessments towards ongoing monitoring and more dialogue-driven reviews.

Conclusion: AI is a management responsibility

The future of AI regulation will not be determined solely by legislation, but by practical controllability. AI is no longer merely an IT topic – it is a management issue.

Institutions using AI must be able to demonstrate:

  • how decisions are generated,
  • how risks are monitored, and
  • how intervention is ensured where necessary.

About this podcast

Alles Legal – Fintech Recht Kompakt delivers sharp, weekly insights into legal and compliance matters in the world of banking. (in German only)
This podcast is a collaboration between Payment & Banking and PayTechLaw.
Each Wednesday, we unpack the legal developments shaping the financial world – clearly, concisely, and without the legal jargon.
Since 2021, PayTechLaw authors and Annerton attorneys have brought depth and clarity to complex topics.
Whether it’s PSD3, DORA, or FiDA – we provide the legal context you need.
In 20 minutes. No detours.



By continuing, you accept our privacy policy.
You May Also Like
Hochleistungs-KI als IKT-Risikotreiber unter DORA
Read More

Frontier AI as an ICT Risk Driver under DORA

Frontier AI is changing the cyber risk landscape for financial entities – and with it the requirements for appropriate ICT risk management under DORA. A new statement by the European Supervisory Authorities explains how existing DORA requirements should be applied in light of faster, more scalable and more complex AI-enabled attacks. This article examines the supervisory expectations and identifies where financial entities should review their existing processes and controls.
Read More
AI Act: Explanation of the icons suggested by the EU to identify AI-Generated content and entry into force of the transparency requirements under the AI Act
Read More

AI Act: Explanation of the icons suggested by the EU to identify AI-Generated content and entry into force of the transparency requirements under the AI Act

AI transparency rules are now a reality. From 2 August 2026, Article 50 of the EU AI Act requires providers and deployers of certain AI systems to disclose AI-generated and AI-manipulated content. This article explains the European Commission's newly introduced transparency icons, the respective obligations for providers and deployers, and the practical steps organisations should take to ensure compliance.
Read More