BaFin KI-MIG law puts on-prem AI in the credit-scoring compliance path
KI-MIG entered force on 29 July 2026 and only pinned, signed, on premise models produce the evidence a BaFin inspection will accept.

On 29 July 2026 Germany's KI-MIG entered force and gave BaFin direct authority over AI systems used by supervised banks and insurers, including credit scoring, insurance pricing and customer chatbots. The EU AI Act penalty ceilings KI-MIG mirrors reach €35m or 7% of global turnover. Only versioned, auditable, on premise models produce the evidence that survives a BaFin inspection. SIOS runs those models inside the bank's own perimeter.
What KI-MIG actually did on 29 July 2026
Germany's KI-Marktüberwachungs- und Innovationsförderungsgesetz, shortened to KI-MIG, entered into force on 29 July 2026. It designates the Bundesnetzagentur as the national general enforcer of the EU AI Act and gives BaFin, the Bundesanstalt für Finanzdienstleistungsaufsicht, direct sector authority over AI systems used by supervised banks, insurers and other regulated financial entities.
The fine ceilings KI-MIG carries over from the EU AI Act are tiered. Prohibited practices attract fines up to €35m or 7% of worldwide annual turnover, whichever is higher. High risk system violations, the tier that covers creditworthiness assessment and insurance risk pricing, attract fines up to €15m or 3% of worldwide annual turnover. False information to regulators sits at €7.5m or 1%.
The transparency obligations under Article 50 of the EU AI Act, including the rule that any customer facing AI system must inform the person that they are interacting with an AI, took effect on 2 August 2026. The full high risk AI regime, which includes Annex III systems for creditworthiness assessment and insurance risk pricing, becomes enforceable on 2 December 2027 following the Digital Omnibus deferral. Both timelines land on the same institutions.
Why hyperscaler endpoints put a bank in the crosshairs
A KI-MIG inspection is not a review of the vendor. It is a review of the deploying bank. When a mortgage decisioning stack calls a US frontier vendor endpoint, the bank cannot present the inspector with a pinned model version, a full training data lineage or a reproducible inference log. The vendor rolls the model, changes safety filters and deprecates checkpoints on its own release schedule.
That is not a compliance failure the bank can push back on the vendor. Under KI-MIG and the existing MaRisk framework, the accountable party is the institution using the model, and the institution has to produce the evidence. A vendor Statement of Applicability is not a substitute for a bank's own reproducible audit trail.
What a BaFin inspector will actually want
- A pinned model version, with a signed hash tied to a specific inference in a specific customer file
- A training data lineage sufficient to defend an adverse decision explanation to the customer and to an ombudsman
- An audit trail of every input, output and human override for that decision, timestamped and tamper evident
- A rollback path to a previous signed model version if a drift or bias alarm fires
- A written record of who approved deployment of the current version and when, tied to a change management ticket
A cloud endpoint cannot produce any of that at the level a BaFin inspector will accept. An on premise deployment with signed audit built in produces all of it as a byproduct of running.
An architecture that survives inspection
The architecture that survives has four properties. The model runs inside the bank's own perimeter, on hardware the bank controls. The model version is pinned and signed, so the inference in a customer file today is reproducible next year and the year after. Every consequential action, including refusals and human overrides, is signed into a tamper-evident ledger. And that ledger can be verified offline by an inspector, with no network and no trust in the vendor.
MICKAI is built for that architecture. 63 studios sit on one Sovereign Intelligence Operating System, 10 production ready at launch and 53 in development, and every studio writes to the same Open Audit Record. Credit scoring, insurance pricing, KYC review and customer chatbot each run in their own studio inside the same perimeter.
| KI-MIG evidence requirement | On premise SIOS deployment property |
|---|---|
| Pinned model version tied to a specific decision | Deterministic model versioning with signed hashes |
| Reproducible inference for adverse decision explanation | Local replay against the signed action ledger |
| Audit trail of overrides and refusals | Every consequential action written into the Open Audit Record |
| Rollback if a drift or bias alarm fires | One operator rollback to a previous signed model version |
Insurance pricing and customer chatbots
AI systems used for risk assessment and pricing in life and health insurance are classified as high risk under Annex III of the EU AI Act and now sit directly under BaFin's KI-MIG mandate. Pricing engines that use AI to set premiums, and the underwriting tooling that supports them, have to meet the same evidentiary bar as credit scoring by the December 2027 deadline.
Customer chatbots have a lower ceiling but a shorter fuse. From 2 August 2026 a chatbot that does not disclose it is AI is a transparency violation under Article 50. That is a settlement in weeks, not a five year inspection, and it applies to every retail facing channel including WhatsApp bots and in app assistants.
Why 2 August 2026 matters this month
German banks and insurers reading this in August 2026 have already crossed the first KI-MIG line. The chatbot disclosure obligation is live and BaFin has signalled it will act on it. Every retail facing AI channel needs an explicit AI disclosure, a written policy, and a signed record that the customer saw it. That is a straightforward fix if the channel runs on infrastructure the bank controls. If it runs on a US vendor's white label, the fix becomes a procurement decision under time pressure.
Does KI-MIG apply to a German subsidiary of a US bank?
Yes. KI-MIG binds any institution supervised by BaFin, regardless of the parent's location. A US parent's group compliance framework does not substitute for a KI-MIG audit trail on the German legal entity, and the group cannot indemnify away regulatory liability that BaFin holds against the German subsidiary directly.
What does BaFin mean by opaque AI in credit scoring?
A system where the deploying bank cannot reproduce the decision for an individual customer, cannot show the model version that produced it, and cannot defend the adverse decision explanation with a training data lineage. Any of those three failures is a KI-MIG problem, and all three together is a ceiling event under the €15m or 3% high risk tier.
Can a bank keep using a US cloud AI vendor and stay compliant?
It depends on whether the vendor gives the bank pinned versions, reproducible inference, full audit and an offline verification path. In practice no US frontier vendor offers that combination today. On premise deployment is the shortest route to the evidence base BaFin wants and the only route that removes vendor release cycles from the compliance perimeter.
When does the full high risk AI regime bite?
Full high risk AI obligations, covering creditworthiness assessment and insurance risk pricing, become enforceable on 2 December 2027 following the EU Digital Omnibus deferral. Transparency obligations already apply from 2 August 2026, and BaFin has enforcement authority over both.
What AI deployment architecture survives a BaFin KI-MIG inspection at a retail bank or insurer?
One that runs inside the bank's own perimeter on hardware the bank controls, with pinned signed model versions, an offline verifiable action ledger and reproducible inference for every customer decision. Cloud endpoints cannot supply that combination and MaRisk holds the institution accountable when they cannot.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System built in Britain that runs on hardware the customer owns, on premise and air gapped, with no data egress. Every consequential action is signed into the Open Audit Record, a post-quantum tamper-evident ledger any outside party can verify offline. 63 studios sit on the operating system, 10 production ready at launch and 53 in development, backed by 104 filed UK patent applications across 2,340 claims.