Artificial intelligence is becoming embedded in the operating models of European banks, supporting activities ranging from fraud detection and anti-money laundering to credit underwriting, customer service, and operational resilience. While AI moves into critical banking functions, the European Union has established a comprehensive legal framework through the AI Act, DORA, GDPR and existing prudential legislation. The next challenge is supervision.

While regulation defines legal obligations, supervision determines whether those obligations are implemented consistently, safely and effectively across the financial system. As AI systems become more dynamic, interconnected and increasingly dependent on external providers, supervisory authorities face a growing challenge: assessing how multiple regulatory frameworks interact in practice during a single supervisory review.

The supervisory integration challenge

As banks embed AI into core business processes, supervisory authorities increasingly face questions that extend beyond the scope of any single regulation.

Consider a bank deploying a generative AI model to strengthen anti-money laundering monitoring. The institution may comply with the AI Act's requirements for high-risk systems, satisfy DORA's operational resilience obligations and continue to meet prudential expectations regarding governance and model risk.

Yet an important supervisory question remains unanswered: how should supervisors assess the interaction between these frameworks during a single supervisory review?

Today, responsibility is distributed across multiple regulatory domains. AI governance, ICT resilience, outsourcing, model risk and data governance are assessed through different supervisory lenses. Each framework is justified individually.

Together, however, they create an increasingly complex supervisory environment in which the quality of oversight depends not only on regulatory compliance but also on supervisors' ability to evaluate how these obligations interact in practice.

Why is AI different

The discussion is important because AI systems differ from many technologies traditionally assessed within prudential supervision.

Foundation models may evolve through updates outside the direct control of financial institutions. Third-party AI providers increasingly become critical infrastructure. Models may change more frequently than traditional statistical systems and interact dynamically with other operational processes.

Existing supervisory approaches already address governance, model validation and operational resilience, but provide only limited public guidance on how supervisors should assess continuously evolving AI systems built upon external foundation models.

Building on what already exists

European institutions have already addressed many of the individual risks associated with AI, but not yet the supervisory integration challenge.

The European Central Bank has highlighted concentration risk, operational resilience and increasing dependence on a limited number of technology providers. The Basel Committee on Banking Supervision has identified AI as an emerging prudential issue, while the European Banking Authority has expanded its work on AI, innovation and model governance.

Taken together, these initiatives significantly strengthen the supervisory framework. However, they still stop short of providing supervisors with a common methodology for assessing AI across regulatory domains.

Toward a common supervisory methodology

Rather than creating another layer of regulation, European policymakers should focus on developing a common supervisory methodology for AI-enabled banking activities. Such a methodology would build upon the work already underway within the EBA, the ECB and national competent authorities. Its purpose would not be to introduce additional legal obligations, but to create greater consistency in how supervisors evaluate governance, accountability, model validation, human oversight, third-party dependencies and continuously evolving AI systems across the Single Supervisory Mechanism.

For example, consider a hypothetical supervisory review involving two significant banks within the Banking Union that use the same foundation model to support anti-money-laundering monitoring. Both institutions comply with the AI Act, DORA and existing prudential requirements. However, one supervisory team places greater emphasis on third-party concentration risk, while another focuses primarily on model validation and human oversight. Both assessments may be justified, yet they could produce different supervisory expectations for comparable AI deployments.

A common supervisory methodology would not alter the underlying legal obligations or remove supervisory judgment. Rather, it would provide a shared assessment framework, ensuring that AI systems are evaluated through a consistent supervisory lens across the Single Supervisory Mechanism.

Such a methodology could include a practical assessment matrix covering areas such as governance, model validation, third-party dependencies, operational resilience and human oversight, enabling supervisors to evaluate AI systems in a structured and comparable manner.

The objective is therefore not uniform supervisory outcomes, but a uniform supervisory methodology. Consistency should exist in how supervisors assess AI risks, not necessarily in the conclusions they ultimately reach.

This distinction is more important than it may first appear. The success of the AI Act will ultimately depend not only on the quality of its legal provisions but also on the consistency with which supervisory authorities interpret and apply them in practice.

Two institutions using comparable AI systems should be able to expect broadly comparable supervisory expectations irrespective of where they are supervised within the Banking Union. Achieving that level of supervisory convergence may become one of Europe's most important competitive advantages in financial regulation.

Supervisory capability is just as important as the regulation

Internationally, regulatory approaches are already diverging. While the European Union has adopted a comprehensive legislative framework, the United Kingdom has largely relied on existing regulators to apply cross-sector principles. Europe should not attempt to compete by producing additional regulation. Its comparative advantage should instead lie in demonstrating that complex AI systems can be supervised consistently across a highly integrated financial market.

The next phase of European AI policy should therefore focus less on developing additional rules and more on building a common supervisory methodology for AI-enabled banking activities.

Strengthening supervisory capability and convergence across the Single Supervisory Mechanism may prove just as important as the legal framework itself. Europe has already demonstrated global leadership in AI regulation. Its next opportunity is to demonstrate that complex AI systems can also be supervised consistently across an integrated financial market.

Share