Banking Law And Regulation Of Financial Robotics Spain .

Banking Law and Regulation of Financial Robotics in Spain

1. Introduction

Financial robotics in Spanish banking refers broadly to automated or semi-autonomous technological systems used to perform financial functions traditionally carried out by employees or conventional software processes.

Examples include:

  • Robotic process automation (RPA)
  • AI-powered banking assistants and chatbots
  • Automated credit assessment
  • Robo-advisers
  • Algorithmic portfolio management
  • Automated fraud and AML monitoring
  • Automated payment processing
  • Algorithmic trading systems
  • Automated customer onboarding and KYC
  • AI-supported risk management
  • Smart-contract-based financial processes

Spain does not have one statute called a "Financial Robotics Law." Instead, financial robotics is governed by overlapping Spanish and EU regimes concerning banking supervision, artificial intelligence, data protection, cybersecurity, consumer protection, investment services, payments, outsourcing and operational resilience.

The fundamental legal principle is that automation does not remove responsibility from the regulated financial institution.

2. Principal Spanish Banking Framework

A central Spanish statute is Law 10/2014 on the organisation, supervision and solvency of credit institutions (Ley 10/2014, de ordenación, supervisión y solvencia de entidades de crédito).

Together with Royal Decree 84/2015, it establishes important requirements concerning:

  • Bank authorisation
  • Governance
  • Internal controls
  • Risk management
  • Solvency
  • Supervisory powers
  • Management responsibility

Consequently, a Spanish bank cannot avoid its regulatory responsibilities merely because a decision was generated by an algorithm or robotic system.

If a bank uses AI to determine credit risk, the bank remains the regulated institution.

3. EU AI Act

A major development is Regulation (EU) 2024/1689 — the Artificial Intelligence Act (AI Act).

The AI Act establishes a risk-based regulatory system.

It distinguishes broadly between:

  • Prohibited AI practices
  • High-risk AI systems
  • Systems subject to particular transparency obligations
  • Other AI systems

For banking, an especially important category concerns certain AI systems used to evaluate the creditworthiness of natural persons or establish their credit score.

Such applications can fall within the AI Act's high-risk framework, subject to the Act's precise scope and exceptions.

4. High-Risk Financial AI

Where a financial robotic system qualifies as high-risk under the AI Act, significant requirements can arise.

These include requirements concerning:

  • Risk management
  • Data governance
  • Technical documentation
  • Record keeping
  • Transparency
  • Human oversight
  • Accuracy
  • Robustness
  • Cybersecurity
  • Post-market monitoring

This changes the compliance environment for automated banking.

A bank cannot simply ask:

"Does the algorithm work?"

It must also consider:

"Can the system be legally governed, monitored, documented and challenged?"

5. Automated Credit Decisions

Consider a Spanish bank using AI to evaluate a consumer loan application.

The system examines:

Income + debts + transaction history + credit information + risk indicators

and produces:

Approve / Reject / Manual Review

Several bodies of law may apply simultaneously:

  1. Banking regulation
  2. Consumer-credit rules
  3. GDPR
  4. AI Act
  5. Anti-discrimination requirements
  6. Internal risk-management rules

Therefore, automation does not convert lending into an unregulated technological activity.

6. GDPR and Automated Decision-Making

The General Data Protection Regulation — Regulation (EU) 2016/679 (GDPR) is fundamental.

Article 22 GDPR

Article 22 addresses certain decisions:

  • Based solely on automated processing; and
  • Producing legal effects concerning an individual or similarly significantly affecting that individual.

This can be particularly important for:

  • Automated loan rejection
  • Credit scoring
  • Insurance-related financial decisions
  • Automated customer-risk decisions

Article 22 contains exceptions, but safeguards can still be required.

Depending on the applicable legal basis and circumstances, these can include rights connected with:

  • Human intervention
  • Expressing the person's point of view
  • Contesting the decision

7. Case Law — SCHUFA Holding (Scoring)

CJEU, Case C-634/21, SCHUFA Holding (Scoring), judgment of 7 December 2023

This is one of the most important European decisions for automated financial decision-making.

The dispute concerned automated generation of a creditworthiness score by SCHUFA.

The CJEU held, in substance, that automated establishment of a probability value can amount to an automated individual decision within Article 22 GDPR where a third party draws strongly on that value when establishing, implementing or terminating a contractual relationship.

Importance for Spanish banks

Suppose:

Credit-scoring algorithm → risk score → Spanish bank's loan decision

The bank cannot assume that Article 22 is irrelevant merely because a separate credit-information provider produced the score.

The practical significance of the score in the final decision matters.

This case is directly relevant to financial robotics.

8. Case Law — Dun & Bradstreet Austria

CJEU, Case C-203/22, Dun & Bradstreet Austria, judgment of 27 February 2025

This case further developed the GDPR rules concerning automated credit assessment and the individual's entitlement to meaningful information about the logic involved.

The Court explained that the information provided must enable the data subject to understand which personal data and factors affected the automated decision and their role in the process.

At the same time, this does not necessarily mean disclosure of the entire algorithm or source code.

Importance for Spain

A financial institution should therefore avoid treating an automated lending model as an unexplained:

"computer says no"

system.

Appropriate transparency about the factors and process may be legally required.

9. Algorithmic Explainability

Financial robotics creates tension between:

Transparency

and

Trade secrets / cybersecurity / intellectual property.

Banks may use proprietary systems developed internally or supplied by fintech companies.

Customers may have legitimate rights to information about automated processing, while the bank and software provider may also have legitimate interests in protecting:

  • Source code
  • Algorithms
  • Security architecture
  • Proprietary models

The legal task is therefore generally not to disclose every technical detail, but to provide the level of meaningful information required by applicable law.

10. Robo-Advisers

Financial robotics also includes robo-advice.

A robo-adviser may:

  1. Ask about financial circumstances.
  2. Ask about investment objectives.
  3. Determine risk tolerance.
  4. Generate an investment profile.
  5. Recommend financial instruments.
  6. Automatically rebalance investments.

In Spain, investment services are subject to the Spanish securities framework and applicable MiFID II requirements.

Automation does not remove suitability and conduct obligations.

11. MiFID II and Automated Investment Advice

MiFID II requires investment firms, where applicable, to obtain information concerning matters such as:

  • Client knowledge and experience
  • Financial situation
  • Ability to bear losses
  • Investment objectives
  • Risk tolerance

A robo-adviser therefore cannot simply recommend a product because its algorithm predicts a high return.

The recommendation must satisfy the relevant regulatory requirements.

The regulated entity remains responsible for the service.

12. Case Law — Genil 48 SL v Bankinter SA

CJEU, Case C-604/11, Genil 48 SL and Comercial Hostelera de Grandes Vinos SL v Bankinter SA and BBVA

This Spanish reference concerned investment services and investor-protection obligations under the MiFID framework.

The Court addressed questions concerning investment advice and suitability-related requirements.

Relevance to financial robotics

The case predates today's AI-driven robo-advisers, but its principles remain important.

If an automated platform effectively provides investment advice, using software does not by itself eliminate the regulatory nature of the service.

The legal focus is on what service is actually being provided, rather than whether a human or algorithm generates the recommendation.

13. Case Law — Bankinter v Massó

CJEU, Case C-301/18, Bankinter SA v Marcela Massó Gavarro

This Spanish banking litigation concerned investor protection in relation to financial products and the interaction between sector-specific financial regulation and other legal remedies.

Relevance

Financial robotics increasingly distributes or recommends sophisticated financial products.

Banks must therefore consider that automated distribution does not eliminate:

  • Information requirements
  • Investor protection
  • Suitability/appropriateness requirements where applicable
  • Potential civil liability

14. Automated Trading Systems

Financial robotics can also involve:

  • Algorithmic trading
  • High-frequency trading
  • Automated order execution
  • Machine-learning trading strategies

MiFID II contains specific controls relating to algorithmic trading.

Firms engaging in covered algorithmic trading must maintain appropriate systems and controls designed to ensure that trading systems are:

  • Resilient
  • Properly tested
  • Subject to thresholds and limits
  • Monitored

The objective is to prevent automated systems from creating disorderly markets or uncontrolled exposures.

15. Human Oversight

One of the central principles emerging from modern AI regulation is meaningful human oversight.

This does not necessarily mean that a human must manually approve every transaction.

Instead, appropriate personnel should be capable, where required, of:

  • Understanding system limitations
  • Monitoring performance
  • Detecting anomalies
  • Intervening
  • Overriding or stopping systems
  • Reviewing problematic outcomes

For example:

AI flags transaction as fraudulent

↓

Account restriction proposed

↓

appropriate review/escalation

↓

final action

The exact process depends on the regulatory context and risk involved.

16. Financial Robotics and DORA

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, has applied since 17 January 2025.

It is highly relevant to automated banking systems.

DORA addresses areas including:

  • ICT risk management
  • ICT-related incident management and reporting
  • Digital operational resilience testing
  • ICT third-party risk
  • Information-sharing arrangements

A Spanish bank's robotic infrastructure is therefore not merely an innovation issue; it can be part of the bank's regulated ICT operational-resilience environment.

17. Third-Party AI Providers

Many banks do not build AI systems themselves.

For example:

Technology provider

↓ provides AI system

Spanish bank

↓ uses system

Customer

A contract with a technology company does not automatically transfer the bank's regulatory responsibility.

The bank must consider matters such as:

  • Outsourcing/ICT third-party risk
  • Audit and access rights
  • Data location
  • Security
  • Business continuity
  • Subcontracting
  • Exit arrangements
  • Incident management

DORA has made ICT third-party risk particularly significant.

18. Case Law — Wirtschaftsakademie

CJEU, Case C-210/16, Wirtschaftsakademie Schleswig-Holstein

The CJEU examined responsibility under EU data-protection law where multiple entities participate in processing.

Relevance to financial robotics

Modern AI systems frequently involve multiple actors:

Bank + cloud provider + AI developer + analytics company

The case does not specifically concern banking robots, but it demonstrates an important data-protection principle: responsibility for processing cannot always be avoided simply because another entity supplies the technological infrastructure.

19. Case Law — Fashion ID

CJEU, Case C-40/17, Fashion ID GmbH & Co. KG

This case further examined joint responsibility in data processing.

Banking relevance

If a Spanish bank integrates external technological components into its digital services, it must carefully identify the respective roles of participants under data-protection law.

The legal question is based on the actual involvement in determining processing purposes and means, not merely contractual labels.

20. Case Law — Google Spain

CJEU, Case C-131/12, Google Spain SL and Google Inc. v AEPD and Mario Costeja González

This landmark case arose from Spain and concerned automated processing of personal information by search engines.

Although not a banking case, it remains highly relevant to Spanish digital regulation.

The Court emphasized that technologically automated processing can carry significant legal responsibilities under EU data-protection law.

Financial robotics lesson

An automated platform is not legally neutral merely because its operations occur through algorithms.

21. Bias and Discrimination

An AI lending model can reproduce or amplify bias.

Suppose historical data indicate that certain groups historically received fewer loans.

Training an algorithm blindly on that data could reproduce those patterns.

Banks therefore need controls concerning:

  • Data quality
  • Representativeness
  • Model validation
  • Proxy variables
  • Discriminatory outcomes
  • Periodic testing

This overlaps with both AI governance and equality principles.

22. AML and Financial Robotics

Spanish banks increasingly use automation for:

  • Transaction monitoring
  • Customer-risk scoring
  • Sanctions screening
  • Suspicious-pattern detection
  • Identity verification

AI can potentially improve detection, but excessive automation can also create problems.

For example:

AI alert ≠ automatic proof of money laundering.

A bank needs appropriately designed investigation and escalation procedures.

Spanish AML obligations operate principally within the framework of Law 10/2010 on the prevention of money laundering and terrorist financing, together with implementing rules and EU requirements.

23. Payment Robotics

Automation can also control:

  • Instant payments
  • Fraud detection
  • Authentication
  • Payment routing
  • Transaction blocking

The legal framework includes EU payment-services rules and Spanish implementing legislation, including Royal Decree-Law 19/2018.

Automation therefore must be designed consistently with requirements concerning:

  • Authentication
  • Security
  • Customer rights
  • Unauthorized transactions
  • Fraud controls

24. Case Law — Caixabank v Asociación de Usuarios de Bancos

CJEU, Case C-484/08, Caja de Ahorros y Monte de Piedad de Madrid

and the extensive line of Spanish banking references concerning consumer protection illustrate the strong role of EU consumer law in Spanish banking.

The broader lesson for financial robotics is important:

Digitising or automating a banking product does not remove consumer-protection requirements.

An unfair contractual term does not become fair merely because an algorithm automatically applies it.

25. Liability for a Robotic Error

Consider an automated system that mistakenly blocks thousands of legitimate customer transactions.

Potential issues could involve:

Customer

↓ claim

Bank

↓ contractual/regulatory responsibility

Technology provider

↓ contractual liability to bank

The bank cannot necessarily answer the customer:

"The software provider caused the error, so the bank has no responsibility."

Customer-facing responsibility and the bank's separate contractual rights against the technology supplier must be analysed independently.

26. Supervisory Structure

Several authorities may become relevant.

AuthorityMain relevance
Banco de EspañaBanking supervision
ECB/SSMPrudential supervision of relevant euro-area banks
CNMVSecurities and investment services
AEPDData protection
SEPBLACAML/CFT
EU institutionsAI, banking and financial regulation

Thus, a financial robotic system may fall within more than one supervisory framework.

27. Six Particularly Relevant Cases

For examination or research purposes, the following cases provide a useful legal foundation:

1. SCHUFA Holding (Scoring) — C-634/21

Automated credit scoring can fall within Article 22 GDPR where the score plays the decisive or sufficiently determining role described by the Court.

2. Dun & Bradstreet Austria — C-203/22

Clarifies meaningful information requirements surrounding automated decision-making.

3. Genil 48 v Bankinter — C-604/11

Important Spanish-origin authority concerning MiFID investment advice and investor-protection requirements.

4. Google Spain v AEPD — C-131/12

Major Spanish-origin authority establishing significant data-protection responsibilities in automated digital processing.

5. Wirtschaftsakademie — C-210/16

Important for determining responsibility where multiple entities participate in personal-data processing.

6. Fashion ID — C-40/17

Further develops responsibility for interconnected digital processing arrangements.

These cases do not all concern "financial robots" directly. Rather, they establish legal principles that apply to the automated decision-making, investment, data-processing and technology-provider relationships on which financial robotics depends.

28. Compliance Model for a Spanish Bank

A sound governance structure can be represented as:

Financial robot / AI model

↓

Model validation

↓

Data-protection assessment

↓

AI Act classification

↓

Banking-risk assessment

↓

Cybersecurity/DORA controls

↓

Consumer/MiFID compliance

↓

Human oversight

↓

Continuous monitoring

↓

Audit and documentation

This is preferable to treating AI compliance as solely an IT-department responsibility.

29. Main Legal Risks

RiskRelevant framework
Automated credit discriminationAI Act / equality law
Unlawful automated decisionsGDPR Article 22
Poor explanationGDPR / AI transparency requirements
Robo-advice failureMiFID II
Algorithmic trading failureMiFID II
CyberattackDORA / banking rules
AI-provider failureDORA / outsourcing controls
AML automation failureAML legislation
Consumer harmConsumer/banking law
Personal-data misuseGDPR
Weak model governanceAI Act / prudential governance
Operational outageDORA

30. Conclusion

Banking law and the regulation of financial robotics in Spain should be understood as a combination of Spanish banking law and EU rules on AI, data protection, investment services, payments, AML, cybersecurity and operational resilience.

The regulatory chain can be summarized as:

Bank

→ AI / robotic financial system

→ automated analysis or decision

→ customer or financial market

→ regulatory and legal consequences

The fundamental principle is:

Automation changes how financial decisions are made, but it does not eliminate the legal responsibility of the regulated financial institution.

The EU AI Act increasingly governs high-risk financial AI; GDPR Article 22 controls important forms of solely automated decision-making; MiFID II governs automated investment and algorithmic-trading activities; and DORA addresses the operational and ICT resilience of the technology on which automated banking depends.

The case-law foundation is particularly strong through SCHUFA (C-634/21), Dun & Bradstreet Austria (C-203/22), Genil 48 v Bankinter (C-604/11), Google Spain (C-131/12), Wirtschaftsakademie (C-210/16), and Fashion ID (C-40/17). Together, these authorities demonstrate that algorithms, external technology providers and automated decisions remain subject to substantive legal accountability.

LEAVE A COMMENT