Germany Just Made a Bank Regulator Answerable for Its Chatbot.
Everyone argues about who should regulate AI. Germany handed it to the supervisors who already regulate the business — the dullest answer, and maybe the only workable one.
For about two years I ran a private scoring system for AI laws, and I am now fairly sure it was worthless.
The test was one question: does the country build a new agency? A dedicated AI authority — its own address, its own director, "Artificial Intelligence" on the letterhead. If yes, I read the law properly. If no, if the text just parceled the work out among offices that already existed, I filed it under not serious. I have said that out loud at more than one dinner table, in the settled voice of a man who has never had to staff a regulator.
Which is how I nearly walked past the most interesting AI law of the summer. It builds no new institution; it hands the job to agencies that were already busy. And the paragraph I would have skipped is the one that changes what happens to a person told no by a machine.
The boring part, which is where the power went
Germany's implementing act — the Gesetz zur Durchführung der Verordnung über künstliche Intelligenz, the KI-MIG in shorthand — was promulgated on July 22, 2026 and entered into force on July 29, four days before the EU's first AI transparency duties began to apply on August 2, 2026. Four days: a legislature sprinting for a deadline it had known about for two years.
The Bundestag passed the bill on June 11, 2026, and it is worth being precise about who "Germany" is there: CDU/CSU and SPD for, AfD, the Greens and the Left against. The coalition answered; the country did not answer with one voice. The law then cleared the Bundesrat on July 10, 2026, where a motion to send it to mediation failed.
Now the architecture. Germany's default AI market surveillance authority is the Bundesnetzagentur — the federal network agency, the people who already regulate telecoms, post, electricity and rail. But §2(1) gives it the job only soweit in diesem Gesetz nichts anderes bestimmt ist: insofar as the statute does not provide otherwise. Even the Bundesrat's write-up grants it the central role only im Wesentlichen, essentially. Keep that hedge. It is load-bearing.
Because §2(3) is where the money is. There the statute names BaFin — the Bundesanstalt für Finanzdienstleistungsaufsicht, Germany's financial supervisor — as the market surveillance authority for AI systems standing in direct connection with a regulated financial activity, at firms BaFin already supervises, then enumerates exactly twenty-five categories of them. Not "all AI at banks." Only AI that touches the regulated business.
Why carve it that way? The government said so. Its explanatory memorandum, in the draft bill of February 5, 2026, argues that existing structures should be used because the alternative builds duplicate structures at the firms' expense, and that the design draws on sector-specific expertise. Stripped of the officialese: you already answer to somebody; that somebody now handles your AI.
BaFin's own account is one sentence long. It will align AI market surveillance closely with its ongoing supervision of firms. No new building, no new commissioner, no new acronym.
So what does BaFin get? Its press release says market surveillance covers the transparency duties for AI systems that interact directly with people — such as chatbots in customer communication. That word is BaFin's, not the statute's; the law never says "chatbot." The release also names the high-risk tier: creditworthiness checks at banks, risk pricing in life and health insurance. The Regulation's annex adds two qualifiers people keep dropping: credit scoring is high-risk except where the system detects financial fraud, and the insurance limb is life and health only.
The timetable matters most. Certain practices have been banned since February 2, 2025; the first transparency duties applied from August 2, 2026 — that is now; the high-risk requirements, the credit-scoring and insurance ones, do not bite until December 2, 2027. Anyone telling you a German regulator is auditing credit models this week is describing 2028.
Then §15(2), which is why I am writing this at all. The KI-MIG makes it a punishable administrative offense for a deployer of certain high-risk systems to fail to ensure that an affected person is given the explanation Article 86 of the Regulation promises them. Not a guideline — an offense, and the statute makes the market surveillance authorities the administrative bodies for its own offenses and for the Regulation's fines. BaFin writes the ticket.
Before you get excited, read what the regulator says about itself
Jens Obermöller, who heads BaFin's department for cyber risks and technology in the financial sector, gave an interview the day the act took effect. Its most useful sentence is a disclaimer. BaFin will review a sample of the AI applications many financial entities use in particularly relevant areas — not, he says, every single AI system in every financial entity. Then, flatly: "What the AI Act mandates is not supervision; it is monitoring." On penalties: in extreme cases fines reach €35 million or 7% of annual turnover, but where firms engage early and cooperate, such penalties will remain the exception.
And that €35 million figure, in every headline this fortnight, does not mean what it is made to mean. Under Article 99 of the Regulation the €35 million / 7% tier attaches only to the prohibited practices in Article 5. The transparency duties — the chatbot ones, the live ones — sit one paragraph down at €15 million or 3% of worldwide turnover: roughly $17.3 million rather than $40.4 million, at the European Central Bank's euro reference rate of 1.1535 for August 7, 2026. And for small and medium enterprises the ceilings invert: the fine is the lower figure.
Germany's own contribution is smaller again. The KI-MIG's offenses — including the §15(2) explanation offense — top out at fifty thousand euros, about $57,700 at that rate. The government's memorandum calls §15 what it is: a residual catch-all for breaches the Regulation does not already sanction.
Fifty thousand euros, for leaving a human being without an explanation of a decision that changed their life.
The experts saw the seams too. At the digital committee's hearing on March 23, 2026, Jonas Botta of the German Research Institute for Public Administration said the choir of authorities in AI oversight is fairly large — and a large choir carries the risk of disharmony, with no sufficient conflict-resolution mechanism yet in the bill. Lajla Fetic of the appliedAI Institute for Europe noted that Poland and Spain manage with one supervisory authority while Germany bets on a highly complex federal and sectoral network with potentially a hundred authorities involved — then added "Das kann funktionieren." It can work, if the agency in the middle is properly resourced. Most summaries cut that caveat, and cutting it inverts her.
A rout, then? No — the record runs the other way. Both Bundestag accounts report that naming the Bundesnetzagentur trifft bei Sachverständigen auf Zuspruch: it met with approval among the experts, and the skepticism landed on the states' notification competences and the sandboxes. The agency's own president, Klaus Müller, argued there for more bundling. And Bitkom, whose board member Susanne Dehmel warned that if the states do not pull together certain AI systems risk a patchwork of sixteen readings instead of one German line, aimed that at the Länder — the same release calls the designation a pragmatic step and good news for business.
The critique the law answers least convincingly comes from digital rights. AlgorithmWatch argued that the Regulation demands independence and expertise for high-risk oversight, and that the data protection authorities have more of both than the Bundesnetzagentur. The law's answer is a chamber that "acts entirely independently" — chaired by the Bundesnetzagentur's own president, and covering policing, migration and justice. Finance is not in it.
What America has had on the books since 1976
Here is where I give up the ending I wanted. I came in expecting to write that Europe acts and America talks. The record will not carry it.
Since a 1976 amendment, the Equal Credit Opportunity Act has entitled every applicant against whom adverse action is taken to a statement of reasons from the creditor — and says a statement qualifies only if it contains the specific reasons for the adverse action taken. Regulation B closes the obvious dodge: the statement must be specific and indicate the principal reasons, and a statement that the applicant failed to achieve a qualifying score on the creditor's credit scoring system is insufficient.
Read that with 2026 eyes. "The model said no" has never been a legal answer in America. Not since Ford was president.
Now set the two side by side — this is what changed my mind about my own headline. Germany's §15(2) makes it a fineable offense to deny someone the Article 86 explanation. And Article 86 gives an affected person the right to clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken.
The role of the system. The main elements of the decision. That describes the process. Regulation B demands the specific principal reasons for the outcome — why you, why no. The same instinct from opposite directions, fifty years apart, and the American rule is stronger on paper. By some margin.
So why does nobody in America feel protected by it?
Because a rule and its enforcement are different objects. In 2022 the Consumer Financial Protection Bureau issued a circular saying creditors using complex algorithms, including artificial intelligence or machine learning, must still disclose the specific principal reasons for an adverse action, and cannot justify noncompliance because the technology is too complicated or opaque to understand — and that circular was withdrawn on May 12, 2025. Its then-director Rohit Chopra had put it plainly: companies are not absolved of their legal responsibilities when they let a black-box model make lending decisions.
Be careful what the withdrawal did. The Bureau pulled both adverse-action circulars in one notice saying the guidance "should not be enforced or otherwise relied upon by the Bureau while this review is ongoing" and, in the same breath, that "such withdrawal is not necessarily final." Its own withdrawn-guidance index lists both. A suspension pending review — not a repeal, and nobody repealed the underlying duty. As the National Consumer Law Center put it, there are no changes to underlying statutes, regulations, or official interpretations of regulations.
The duty really is still there. In April 2026 the Bureau rewrote parts of Regulation B — disparate impact, discouragement of applicants, special purpose credit programs — effective July 21, 2026. Adverse-action notification was not among them: NCLC's sharply critical analysis lists adverse action notices among what was left alone, and the federal code records §1002.9's last amendment as March 20, 2023. Per a Mayer Brown alert, organizations filed a complaint in the District of Columbia on May 27, 2026 asking the court to declare that rewrite unlawful — allegations, not findings, and no injunction sought.
Meanwhile the agency that wrote that guidance is, per Chuck Bell of Consumer Reports, essentially on life support — the advocacy program director's characterization in February 2026, not a finding.
America wrote the better sentence and then spent fifty years deciding how hard to mean it.
The move is not foreign to America, either. New York's Department of Financial Services got there two years earlier, telling insurers in 2024 they may not rely on the proprietary nature of a third-party vendor's algorithmic processes to justify vagueness about an adverse underwriting or pricing action. State-regulator guidance, not a statute — but Germany's instinct exactly, arrived at first.
Just imagine December 2027
Picture a Tuesday sixteen months from now, when the clock runs out.
A woman in Duisburg applies online for a modest loan. A model scores her; she is declined. She asks why through the chat window, which since August 2026 has to be honest that it is a machine. Under Article 86 she is owed the role the system played and the main elements of the decision, and the bank sends a competent paragraph: an automated creditworthiness system was used; the factors were repayment history, existing obligations and account tenure; a human reviewed the file. She never learns the model treated a three-year-old address change as instability — never gets a specific reason, because the European right does not ask for one.
Six weeks later BaFin pulls a sample of creditworthiness systems from several institutions in a relevant area. Her bank's model is in it — not because she complained, but because it was Tuesday and the sample came up. That is the part no American counterpart offers: an examiner already in the building.
Now run the same morning in Ohio. The applicant gets a form listing the principal reasons, one of them length of residence at current address — a genuinely better answer to why me. And then nothing happens. No examiner walks in. Her recourse is a complaint to an agency reviewing its own guidance, or a lawyer she pays for.
One woman gets the right answer, badly enforced. The other gets a vaguer answer from a system that might come looking. Neither sees the model.
What the smart people are saying
The sharpest critics on both continents aim at the same soft spot.
Simona Demkova of Leiden Law School argues the AI Act's right to explanation becomes the weakest link of the AI responsibility chain, and that requiring only the role of the AI and the main elements renders it nearly ineffective — one scholar's commentary, not settled consensus, but it lands where the text is thinnest. Sandra Wachter of the Oxford Internet Institute goes wider, writing in the Yale Journal of Law & Technology that lobbying produced weak oversight and investigatory mechanisms resting on self-certification — a critique of the European Regulation, not Germany's implementation.
The deepest objection is American and predates the chatbot era. Talia Gillis of Columbia Law School argues in the Minnesota Law Review that fair lending law has traditionally policed discrimination by scrutinizing inputs, but that input scrutiny has become a fallacy in the world of algorithms and threatens an algorithmic myth of colorblindness. She is not saying reason-giving is worthless — she is saying it cannot carry the weight alone, and outcomes must be measured too. Fifty-two years of specific-reasons notices, and a leading fair-lending scholar says we have been auditing the wrong end of the machine.
From the free-market side, Adam Thierer of R Street told Congress that AI-related harms can already be addressed under many existing laws, regulations and court-based standards — cutting both ways, endorsing the sectoral venue while denying a new statute was needed. From the progressive side, the Center for American Progress argued in 2024 that US regulators should use the authorities they hold, since advances in technology do not render existing risk management and compliance requirements inapplicable.
Free-marketeers and progressive think tanks agree on almost nothing. They agree on this: the regulator you need probably already exists.
What does this mean for you?
Denied credit in the United States? Ask for the specific principal reasons in writing. "You did not meet our scoring threshold" is not compliant — Regulation B says so expressly. Use those words; note the date.
Do not let anyone tell you the adverse-action duty was repealed. Two CFPB circulars were withdrawn in May 2025, and the notice itself says that withdrawal is not necessarily final. Statute and regulation are untouched.
If you bank or insure in the EU, mark December 2, 2027 — not today. Transparency duties are live; credit-scoring and life-and-health insurance duties are not.
Notice when you are talking to a machine, and when nobody told you. In Germany's financial sector, the office that hears about it is BaFin.
If you build or buy these systems, find out which regulator owns you. A bank's creditworthiness model goes to BaFin; its recruiting model goes to the Bundesnetzagentur — because, as BaFin's own official put it, a credit-scoring system "is very different from the one it uses when recruiting staff."
Ignore the €35 million headlines. That ceiling belongs to prohibited practices. Transparency breaches carry €15 million or 3%, Germany's own offenses cap at fifty thousand euros, and small firms get the lower figure.
Ask your bank a boring question: which decisions about me involve an automated system, and who supervises it? The answer — or the silence — tells you where you stand.
The dullest answer usually wins
The lesson I take, having thrown out my scoring system, is that the question everybody argues about — who should regulate AI? — is the wrong shape. It invites an answer with a ribbon-cutting. The real question is quieter: which institution already has the right to walk into the building, read the file, and ask a rude question on a Tuesday?
Germany's answer is unglamorous and possibly correct. Give it to the supervisors who already regulate the business and accept the coordination costs — the draft budgeted roughly €15.9 million a year federally and €33.1 million for the states, about $18.3 million and $38.2 million at that ECB rate, estimates in a bill rather than receipts. The act also schedules a first evaluation of the supervisory structure within eighteen months: standard German legislative housekeeping, not a confession of doubt.
America's answer, written in 1976, is better drafted and worse tended. In one sentence: a strong rule in a weak institution and a weak rule in a strong institution fail differently, and both fail. The country that gets this right will stop arguing about the logo on the door and start asking who is scheduled to walk through it.
Sixteen months. Then we find out whether "answerable" was a verb or a press release.
The HAIA Foundation argues that AI accountability lives in institutions, not announcements — and that ordinary people deserve to know which office answers for the machine in front of them. If that is a question you would like followed properly, subscribe.




