ARTIFICIAL INTELLIGENCE IN BANKING: CONSTITUTIONAL GUARANTEES OF CLIENT RIGHTS AND A RISK-BASED MODEL OF LEGAL REGULATION IN UKRAINE

ARTIFICIAL INTELLIGENCE IN BANKING: CONSTITUTIONAL GUARANTEES OF CLIENT RIGHTS AND A RISK-BASED MODEL OF LEGAL REGULATION IN UKRAINE

Inna BERNAZYUK
Director of Government Relations, JSC “SENS BANK” GR
Professor, Department of Law
Private Higher Educational Institution “European University,”
Doctor of Law,
Honored Lawyer of Ukraine
e-mail: innabernaziuk@gmail.com

Artificial intelligence is gradually becoming a standard tool in banking. It is used to automate internal processes, provide customer service, personalize banking offers, assess credit risk, detect fraudulent transactions, and conduct financial monitoring. These technologies are transforming not only the internal organization of banks but also the nature of the “customer-bank” relationship. The Bank for International Settlements identifies lending, payments, customer due diligence, fraud prevention, and compliance with regulatory requirements as areas where the use of artificial intelligence can enhance the efficiency of financial institutions.

Practice in the Ukrainian banking market shows that the use of artificial intelligence has already moved beyond experimental automation and now encompasses lending, payments, service personalization, fraud prevention, and direct customer interaction. For example, Dmytro Musienko, a member of PrivatBank’s management board, reports on the use of machine learning for credit risk management and unsecured lending, personalization of offers, and preventive fraud detection. In June 2026, PrivatBank and Mastercard processed Ukraine’s first payment using Mastercard Agent Pay, in which an AI agent was integrated into the payment process. According to Artur Zagorodnikov, Deputy Chairman of the Management Board, PUMB is already using an AI chat assistant, an AI sales assistant, solutions for compliance and regulatory tasks, as well as a secure AI environment for employees.

At other banks, AI is used to analyze documents for lending, collect delinquent debts, and conduct telemarketing of credit products; specifically, JSC “RADABANK” is using an AI agent on a trial basis to offer cash loans and credit cards, and there has even been a recorded instance of a transaction being completed without an operator’s involvement. At the same time, market participants themselves acknowledge the risk of misinterpreting requests and model “hallucinations” and consider it premature to fully delegate final decision-making to artificial intelligence. Thus, for Ukraine, the issues of explainability, the limits of automation, and effective human oversight are already of practical importance.

The legal significance of such use changes when the result of automated analysis becomes the basis for a decision regarding a specific individual. Denial of a loan, determination of material terms of a financial service, classification of a client into a specific risk category, suspension of a transaction, or termination of a business relationship can significantly affect the individual’s factual and legal status. Under such circumstances, the issue extends beyond the scope of banking operations and directly concerns legal guarantees of human dignity, equality, privacy, and effective protection of rights.
The technological method used to prepare a decision should not diminish the level of legal protection afforded to an individual. At the same time, uniformly stringent regulation of any use of artificial intelligence could create unjustified obstacles to the development of banking services. Therefore, the subject of this study is the legal criteria for differentiating requirements for AI systems depending on their functions and consequences.

Constitutional Guarantees in Bank-Client Relations
The constitutional dimension of a bank’s use of artificial intelligence requires a distinction between public and private law relationships. In its ordinary dealings with a client, a bank is a private entity, not a public authority. Therefore, an unfavorable credit decision by a bank should not automatically be classified as a direct violation of Article 24 or any other provision of the Constitution of Ukraine.
The significance of constitutional guarantees in such legal relationships is manifested primarily through the state’s positive obligations to ensure proper legislative regulation of private relations, effective oversight, and judicial protection. This approach is consistent with Article 8 of the Convention for the Protection of Human Rights and Fundamental Freedoms and the case law of the European Court of Human Rights, according to which the State’s positive obligations may include measures aimed at ensuring respect for private life even in relations between private individuals [19, § 23; 36, Art. 8].

This provision is consistent with Article 8 of the Constitution of Ukraine, which enshrines the supremacy of the Constitution and the direct applicability of its provisions, but does not transform every dispute between a bank and a customer into a public-law dispute. Articles 21 and 22 establish the inalienability of rights and prohibit the narrowing of the content and scope of existing rights when enacting new laws; Article 24 guarantees equality; Article 32 guarantees non-interference in personal and family life; Article 55 guarantees the right to judicial protection; and Article 64 defines the constitutional limits on the restriction of rights [27, Articles 8, 21, 22, 24, 32, 55, 64]. The use of a new decision-making method therefore cannot in and of itself serve as a basis for reducing the level of legal protection.
The constitutional basis for this approach is also provided by Articles 3 and 28 of the Constitution of Ukraine, which enshrine the special significance of human dignity and the right of every person to have it respected [27, Art. 3, 28]. The use of automated tools in making legally significant decisions should not deprive a person of the opportunity to be heard or of the right to an effective review of a decision that significantly affects their situation.

In its Decision No. 2-rp/2016 of June 1, 2016, the Constitutional Court of Ukraine held that restrictions on constitutional rights must have a legitimate purpose, be justified by a public necessity, and comply with the requirement of proportionality [46, paras. 2.3–2.4 of the reasoning]. For the use of artificial intelligence in banking, this means that economic expediency, cost reduction, or increased assessment accuracy cannot, in and of themselves, justify the unrestricted use of personal data or the deprivation of necessary procedural safeguards.

The principle of equality takes on particular significance. The Law of Ukraine “On the Principles of Preventing and Combating Discrimination in Ukraine” dated September 6, 2012, No. 5207-VI (hereinafter “Law No. 5207-VI”) defines indirect discrimination as a situation in which, as a result of the application of formally neutral legal norms, evaluation criteria, rules, requirements, or practices result in less favorable conditions for a person or group of persons compared to others without a proper objective justification [30, para. 3, part 1, Art. 1]. For automated assessment, this definition is of direct relevance: a system may not use a protected characteristic directly but may take into account other information statistically linked to it.

Therefore, a legal review must cover not only the list of indicators used but also the consequences of their application. Differential treatment is lawful if the criterion has an objective justification related to the legitimate purpose of assessing banking risk, and the means employed are appropriate and necessary [21; 30].
The practical effectiveness of the prohibition against discrimination also depends on the rules of evidence. A client typically does not have access to the complete assessment system, the documentation regarding its structure, or the data set; therefore, placing the burden of proof on the client to demonstrate the internal mechanism leading to a discriminatory outcome could significantly weaken judicial protection. Law No. 5207-VI guarantees the right to challenge decisions, actions, or omissions that exhibit signs of discrimination and to seek compensation for the harm caused [30, Articles 14–15], while civil procedure law provides for a special rule: once the plaintiff has presented factual evidence confirming the existence of discrimination, the burden of proving its absence falls on the defendant [9, Art. 81(2)]. There is no basis for automatically applying this framework to disputes heard under commercial litigation rules, as the Commercial Procedural Code of Ukraine does not explicitly establish a similar rule.
Thus, the development of artificial intelligence in banking does not require the creation of a new “constitutional right to protection against algorithms.” The necessary level of protection can be ensured by appropriately specifying existing constitutional guarantees in the banking.

Privacy and Limits on Data Use

The effectiveness of artificial intelligence systems depends to a large extent on the volume and quality of the data used. However, the ability to obtain a more accurate forecast does not in itself constitute a legal basis for the unrestricted collection and use of customer information.

Part 2 of Article 32 of the Constitution of Ukraine establishes a special guarantee regarding the collection, storage, use, and dissemination of confidential information about an individual [27, Part 2 of Article 32]. The Constitutional Court of Ukraine, in its Decision No. 2-rp/2012 of January 20, 2012, noted that information about personal and family life includes, in particular, details regarding financial status, personal property relations, and events in the professional and business spheres, and that the list of confidential information about an individual is not exhaustive [45, paras. 3.2–3.3 of the reasoning]. This legal position is of direct relevance to banking assessments, which can form conclusions about an individual based on a comprehensive analysis of numerous individual pieces of information.

The Law of Ukraine “On the Protection of Personal Data” explicitly applies to activities involving the processing of personal data carried out wholly or partially using automated means [29, Art. 1, Part 2]. In addition, a data subject has the right to know the mechanism of automated processing of their data and the right to protection against an automated decision that has legal consequences for them [29, subparagraphs 12 and 13 of Part 2 of Article 8]. The absence of a specific law on artificial intelligence therefore does not imply the absence of legal limits regarding the information a bank uses for automated assessment.

The European Union’s General Data Protection Regulation—Regulation (EU) 2016/679—is of comparative legal significance. It specifically regulates decisions based solely on automated processing that produce legal or similarly significant effects, and establishes information safeguards regarding the logic, significance, and anticipated consequences of such processing [38, Art. 13(2)(f), 14(2)(g), 15(1)(h), 22].

In the case of Rotaru v. Romania, the ECHR recognized that the systematic collection and use of personal data may constitute an interference with the right to privacy [48, §§ 43–46]. Since this case concerned the activities of a government agency, its significance for banking legal relationships lies in defining the scope of the right, the effective protection of which the state must also ensure in private relationships; this decision does not imply a direct transfer of the government agency’s obligations to a bank. The case of Satakunnan Markkinapörssi Oy and Satamedia Oy v. Finland, which concerned the mass processing of personal data by private entities, is particularly illustrative of this horizontal dimension.

Directive (EU) 2023/2225 on consumer credit agreements establishes an even more detailed standard: information used to assess creditworthiness must be necessary, proportionate, relevant, complete, and accurate, and certain specific categories of personal data and information from social media may not be used for such an assessment [39, Art. 18(2)–(4)].

Under Ukrainian law, it is justified to establish a rule whereby a bank uses, for the purpose of assessing a customer, not all available information capable of increasing statistical accuracy, but only data whose necessity and reasonable connection to the relevant banking risk can be demonstrated. This is particularly important with regard to non-traditional sources of information: they can facilitate access to financial services for individuals without a sufficient credit history, but in

A Risk-Based Model of Legal Regulation

Imposing the same legal requirements on all artificial intelligence systems would be disproportionate. To determine the appropriate level of regulatory intervention, it is proposed to apply two interrelated criteria: the intensity of the potential impact on customer rights and the significance of the system for the stability of the bank or the financial system.
For the first criterion, the standard set forth in Article 22 of Regulation (EU) 2016/679 is appropriate: the occurrence of legal or similarly significant consequences [38, Art. 22]. In banking legal relationships, an impact should be considered significant if it is capable of determining or substantially altering a person’s access to a financial service, its essential terms, the ability to manage funds, or the ability to continue a business relationship with the bank.

Differentiating measures based on the likelihood and severity of potential negative impacts is consistent with the Council of Europe’s Framework Convention on Artificial Intelligence, Human Rights, Democracy, and the Rule of Law. The Council of Europe’s methodology specifies this assessment through indicators of scale, scope, likelihood, and the ability to mitigate adverse consequences.
The second dimension consists of potential consequences for operational and financial stability, including dependence on critical external suppliers, the prevalence of identical models, and the scale of a potential failure.
Each dimension is assessed independently and takes into account the substantive content of legal and supervisory requirements. On this basis, it is proposed to distinguish between three groups of systems.
Supporting systems are those whose output does not have a decisive influence on decisions with significant consequences for the customer and which are not material to the bank’s operational stability. For these systems, general requirements regarding information security, proper use, access control, and internal controls are sufficient.

Significant systems are those whose results have a material impact on the preparation of such a decision but are subject to an independent substantive assessment by an authorized bank employee, as well as systems whose failure has a noticeable impact on the bank’s operational stability without direct consequences for a specific customer. This group may include tools for personalizing offers, pre-selecting transactions for additional review, or supporting credit analysis. These require documentation, data quality control, checks for unjustified differentiation, and the ability to override automated recommendations.

In the proposed sectoral classification, high-risk systems are those whose output directly or effectively determines decisions with legal or similarly significant consequences for a customer, or whose use poses a high risk to the stability of the bank or the financial system. This is an author-defined category for banking regulation that is not identical to the formal concept of a high-risk system in Regulation (EU) 2024/1689.

The two proposed criteria determine not only the intensity but also the substance of legal requirements. A significant impact on client rights necessitates, first and foremost, the application of legal safeguards such as non-discrimination, explanation of decisions, human review, and effective appeal. High significance for the stability of a bank or the financial system necessitates, first and foremost, prudential requirements—independent fitness assessments, operational stability, business continuity, and an evaluation of dependence on external suppliers. A single system may score high on one criterion and low on another.

Regulation (EU) 2024/1689 explicitly classifies as high-risk systems those designed to assess the creditworthiness of individuals or determine their credit rating, with the exception of systems for detecting financial fraud [37, Art. 6(2), Annex III, para. 5(b)]. Part 3 of Article 6 provides for a general mechanism under which a specific system listed in Annex III may, under certain conditions, not be considered high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights. However, this exception does not apply explicitly if the system engages in profiling of natural persons: in such a case, a system listed in Annex III is always considered high-risk [37, Art. 6(3)]. This is of particular significance for automated credit scoring, as the use of personal data for predictive creditworthiness assessment often constitutes profiling by its very nature.

Thus, the European legislator takes into account the heightened risk associated with this category of decisions and does not permit a reduction in the level of safeguards solely on the basis of a formal assertion regarding the limited role of a specific system.
The enhanced requirements must cover not only the accuracy of the result but also the quality of the input data and the system’s resilience to external influences. Distortion of the data on which the system’s operation is based, or deliberate interference in the formation of its result, creates risks that go beyond traditional unauthorized access. The European Banking Authority links the proper use of advanced analytical tools to data governance, traceability and verifiability, fairness, personal data protection, and security.

The assessment of a high-risk system’s suitability must therefore cover the origin and representativeness of the data, resilience to external interference, the ability to track significant changes, and the timely detection of deteriorating results.

Creditworthiness Assessment and the Customer’s Procedural Rights

Automated creditworthiness assessment is the most telling example of heightened legal risk. It simultaneously involves the bank’s freedom of contract, credit risk management, consumer protection, privacy, and equality.
A bank has the right to assess the risk of default on a loan obligation and is not obligated to enter into a loan agreement with every applicant. The principle of non-discrimination does not create a subjective right to obtain a loan. However, freedom in credit decision-making does not mean the freedom to use criteria that are not reasonably related to creditworthiness or that place certain categories of individuals at an unjustified disadvantage.

The European Banking Authority’s guidelines on credit granting and monitoring require that, when using automated models, a credit institution understand their methodology, input data, assumptions, limitations, and results; have procedures in place to detect and prevent bias; ensure the traceability of results; conduct regular quality reviews; and establish mechanisms for deviating from automated decisions. These requirements combine consumer protection with sound credit risk management: an inadequate assessment of creditworthiness can harm both the borrower and the lender’s financial stability.

The primary procedural safeguard should be the ability to understand the main reasons for an unfavorable decision and to have a real impact on its reconsideration.
Article 18 (8) Directive (EU) 2023/2225 provides that, in the case of automated creditworthiness assessment, the consumer has the right to request human intervention by the lender, to receive a clear explanation of the creditworthiness assessment and the functioning of the automated processing, to express their position, and to request a review of the assessment and the credit decision.
The amount of information provided to the customer should be sufficient to enable them to identify the key circumstances that significantly influenced the decision, verify the accuracy of the data used in their case, provide additional information, and request a reconsideration. Disclosure of source code, technical documentation that is not necessary for understanding the reasons behind the decision, or information constituting a trade secret is generally not required to fulfill this guarantee.

This approach to explaining the decision is consistent with the OECD Recommendation on Artificial Intelligence: a person adversely affected by the system’s outcome should be provided with understandable information sufficient to comprehend and challenge the relevant outcome; at the same time, responsible use entails human involvement and oversight, as well as adequate reliability and security of the systems [44, Principles 1.2–1.4].

Human review cannot be a mere formality. An authorized bank employee must have sufficient competence and authority to verify material data, take into account circumstances that the system did not consider, and, where warranted, reject or adjust the automated result. International studies on financial sector regulation also link genuine human oversight to the responsible person’s authority to intervene in the decision-making process and prevent adverse outcomes.

Financial Monitoring: Limits on Explanations to Clients

The use of artificial intelligence in financial monitoring has a different legal nature. In such legal relationships, a bank not only pursues its own private interests but also fulfills its statutory obligations in the area of preventing and combating money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction.
The Law of Ukraine “On Preventing and Combating the Legalization (Laundering) of Proceeds from Crime, the Financing of Terrorism, and the Financing of the Proliferation of Weapons of Mass Destruction” dated December 6, 2019, No. 361-IX (hereinafter “Law No. 361-IX”) imposes corresponding primary financial monitoring obligations on banks.

Automated systems are capable of identifying atypical transactions, interrelationships, and other indicators that require further analysis. However, it is necessary to distinguish between an automated alert indicating the need for verification and a final decision that significantly restricts the client’s rights. The statistical atypicality of a transaction does not, in and of itself, constitute proof of improper conduct on the part of an individual.
The scope of the explanation that may be provided to a client in the context of financial monitoring is defined by specific legislative restrictions. Law No. 361-IX separately regulates the confidentiality of financial monitoring as information obtained by a specially authorized body during state financial monitoring [32, para. 59, Part 1, Art. 1], and establishes a separate prohibition on primary financial monitoring entities and other specified persons from informing clients and third parties about the submission of relevant information to the specially authorized body and about certain related actions [32, Part 10 of Article 16].

Therefore, the internal auditability of an automated decision—the bank’s ability to reproduce its rationale for internal control, for the National Bank of Ukraine, the specially authorized body, or a court—is not equivalent to the scope of explanation that may be provided to a client in accordance with the law. In cases specified by law, the scope of information disclosed to the customer may be limited in the interest of effective financial monitoring.

At the same time, such a restriction should not result in a general lack of control over automated decisions. In certain cases, the law specifically defines the permissible scope of information to be provided to the client, particularly regarding decisions to extend the suspension of financial transactions [32, Art. 23]. Therefore, an appropriate model must simultaneously ensure the internal verifiability of the decision, the possibility of regulatory and judicial oversight, and compliance with the statutory prohibition on the disclosure of certain information.

The Regulations on Financial Monitoring by Banks, approved by Resolution No. 65 of the Board of the National Bank of Ukraine dated May 19, 2020 (hereinafter “NBU Regulation No. 65”), are already based on a risk-based approach and require banks to document their risk assessments and decisions. Automated analysis can therefore be integrated into the existing financial monitoring mechanism without creating a separate, parallel regulatory system.

Bank Liability, Third-Party Providers, and Bank Secrecy

The use of artificial intelligence should not alter the general principle of a bank’s legal liability for its activities. Delegating a specific analytical function to an automated system or a third-party provider does not relieve the bank of its liability to the customer for the banking decision made.
This conclusion also applies to systems that use external computing infrastructure or general-purpose models. The provider’s contractual or other legal liability to the bank may exist in parallel, but the customer should not have to trace the entire chain of technological and contractual relationships to determine the party responsible to them for decisions regarding banking services.
A similar approach is justified for another regulated segment of the financial market—insurance. A previous study concluded that engaging an external provider of an artificial intelligence system does not relieve a financial institution of its liability to the client, and that human oversight must be substantive: an authorized person must be able to verify the automated result and override it if there are grounds to do so. This conclusion confirms a broader principle applicable to regulated financial services: the use of an automated system changes the way a decision is made, but does not alter the party legally responsible for it.

Bank secrecy is of fundamental importance for the external use of such systems. The Law of Ukraine “On Banks and Banking Activities” explicitly classifies as bank secrecy information about an individual who intends to enter into a consumer loan agreement, obtained during the assessment of that individual’s financial condition [28, para. 9, part 2, Art. 60].
At the same time, the law permits the disclosure of information constituting banking secrecy to private individuals and organizations so that they may perform functions or provide services to the bank under a contract; such persons are obligated not to disclose the confidential information received and not to use it for their own benefit or for the benefit of third parties [28, Art. 61]. Thus, engaging an external service provider is not in itself incompatible with banking secrecy, but it does not relieve the bank of its obligation to control the legal basis, scope, purpose, security, and subsequent use of the disclosed information.

Agreements with external service providers must at least provide for restrictions on the use of the received data for a specific purpose, an appropriate access regime, an obligation to notify the bank of security breaches, the ability to verify compliance with established requirements, and the cessation of information use upon termination of the relevant legal relationship.

Dependence on external suppliers also has prudential implications. The Financial Stability Board notes that the proliferation of artificial intelligence increases financial institutions’ dependence on specialized equipment, computing infrastructure, and external models, and that concentration among suppliers can create systemic operational vulnerabilities.

The management of such risks must be incorporated into the bank’s existing corporate governance framework. The Regulations on the Organization of Risk Management Systems in Ukrainian Banks and Banking Groups, approved by Resolution No. 64 of the Board of the National Bank of Ukraine dated June 11, 2018 (hereinafter “NBU Regulation No. 64”), already provide for the separation of duties, the responsibilities of management bodies, and the risk management and internal control systems.
Within this system, a bank may maintain an internal list of significant artificial intelligence systems, designate responsible persons, establish risk levels, conduct preliminary and periodic suitability reviews, document material changes and incidents, and monitor external suppliers. For high-risk systems, it is advisable to organizationally separate the functions of development, use, and independent verification.

Systemic Risk Measurement and Banking Supervision

The second dimension of the proposed model—the system’s significance for the stability of a bank or the financial system—requires a separate supervisory assessment. A system that has virtually no direct impact on the situation of a specific client may, at the same time, be critical to the continuity of banking operations. The Financial Stability Board identifies the following as key vulnerabilities: dependence on external suppliers and their concentration, the correlation of financial institutions’ behavior, cyber risks, model risks, poor data quality, and deficiencies in internal governance [16, pp. 15–23].
The Bank for International Settlements further highlights interconnectedness, procyclicality, and the potential for single points of failure. The European Central Bank links the significant penetration of artificial intelligence and the concentration of its suppliers to increased operational and cyber risks, market concentration, homogeneity of behavior, and heightened market correlation.
This confirms the need for a two-dimensional supervisory approach. A small bank’s credit scoring system may pose a high risk to customer rights but not constitute a significant threat to the financial system. Conversely, a liquidity management system or a critical external computing resource may have almost no impact on the rights of a specific customer but be of high operational or systemic importance.

The level of supervisory requirements should therefore be determined not by a single “high-risk” indicator, but by a combination of both factors. This makes it possible to differentiate between legal and prudential measures and to avoid both insufficient oversight of legally significant decisions and excessive regulation of ancillary systems.

Assessment of the Impact on Client Rights

For high-risk systems, it is appropriate to conduct an internal assessment of their potential impact on client rights prior to implementation and following any significant change to the system.
The methodology developed by the Council of Europe for assessing the risks and impacts of artificial intelligence systems on human rights, democracy, and the rule of law may serve as a methodological guide. It involves a contextual risk analysis, consideration of stakeholders’ perspectives, assessment of risks and impacts, identification of measures to prevent or mitigate them, and subsequent review. The methodology is not legally binding and explicitly allows for its adaptation to the sectoral context.
The assessment must cover at least the purpose of the system’s use; the group of individuals it may affect; the rights and legitimate interests that may be affected by the outcome; the categories and sources of data; potential discriminatory consequences; the degree of automation; the procedure for human oversight; the possibility of correcting an erroneous result; information security measures; reliance on external providers; and the procedure for monitoring actual results. The assessment is conducted taking into account the risk criteria set forth in Section 3 of this article.

The practical significance of such a mechanism lies in its verifiability. The bank must document the identified risks, the results of their assessment, the measures taken, and the allocation of responsibility. Such documentation is important for internal control, banking supervision, and, if necessary, legal defense.

Directions for the Development of Ukrainian Legal Regulation

Ukraine already has the basic regulatory framework for sector-specific regulation: legislation on banks, personal data, non-discrimination, consumer lending, financial monitoring, and general rules for protecting customers in the financial services market.
The Law of Ukraine “On Financial Services and Financial Companies” enshrines, among the principles governing the provision of financial services, risk management, the protection of confidential information, the prevention of unjustified discrimination against consumers, quality control, and the proper handling of complaints [18, Part 1 of Article 5]. Customer rights include the right to receive necessary and accurate information, confidentiality, and the protection of violated rights [18, Art. 6]. Supervisory regulation combines the objectives of customer protection with ensuring the stability of the financial market [18, Arts. 21, 24–25].

The White Paper of the Ministry of Digital Transformation of Ukraine is based on a phased model for regulating artificial intelligence, which aims to balance the protection of human rights with the promotion of innovation. A 2026 discussion paper by the National Bank of Ukraine already establishes sector-specific principles for the responsible use of artificial intelligence in the financial services market and covers risk-based management, consumer rights, data requirements, operational resilience, organizational accountability, and self-assessment.
The next step should not be general declarations about the need for regulation, but rather concrete changes.

The National Bank of Ukraine is already taking practical steps in this direction. NBU Governor A. Pyshnyy, summarizing the Bank for International Settlements’ discussion on the use of artificial intelligence by central banks, emphasizes the advisability of starting with low-risk system trials and gradually expanding their use, while simultaneously developing internal expertise, governance mechanisms, model validation standards, and control procedures. According to his statement, the National Bank of Ukraine has already approved a Policy on the Responsible Use of Artificial Intelligence and is testing potential areas of its application.

It is telling that the banking and fintech communities themselves recognize the need to combine technological development with proper risk management. Rostislav Dyuk, Chairman of the Board of the Ukrainian Association of Fintech and Innovative Companies (UAFIC), draws attention not only to the potential of AI but also to the ethical, legal, and business risks of its implementation, particularly dependence on external technology platforms and their licensing terms. At the institutional level, UAFIC has consistently included artificial intelligence on the financial sector’s professional agenda, particularly within the framework of UAFIN.TECH, and in 2026, in collaboration with the National Bank of Ukraine, launched AI Discussion Day as a platform for dialogue between the regulator and the market regarding the future regulation of AI use. Bank representatives also highlight related risks: Andriy Begunov, Director of the Information Technology Department at PUMB, emphasizes the problem of confidential information being used outside the bank’s secure information perimeter, while Andriy Kashperuk, Deputy Chairman of the Board at UKRSIBBANK, links the next stage of mobile banking development to Open Banking and the use of AI agents to provide simpler banking services. This practice confirms the validity of a risk-based model, under which legal requirements should be determined not by the mere fact of AI use, but by the nature of the data, the degree of system autonomy, and the consequences its solutions for the client and the bank’s level of dependence on external suppliers.

First, the Law of Ukraine “On Consumer Lending” should be amended to include a provision stipulating that, when an automated system is used that has a decisive influence on the creditworthiness assessment or the decision to grant a loan, the consumer has the right to be informed of the automated nature of the assessment, to receive clear information about the main reasons for an unfavorable decision, to submit additional information, and to request a review by an authorized employee of the lender.

Second, this Law should stipulate that the information used for automated creditworthiness assessment must be necessary, relevant, up-to-date, and reasonably related to the corresponding credit risk. The use of protected characteristics or other indicators as de facto substitutes for them should not result in unjustified discrimination.

Third, NBU Regulation No. 64 should be supplemented with requirements regarding the internal accounting of significant artificial intelligence systems, their classification by risk level, the designation of responsible persons, the procedure for preliminary and periodic suitability reviews, the monitoring of actual results, the documentation of material changes and incidents, as well as the assessment of dependence on external suppliers.

Fourth, NBU Regulation No. 65 requires further clarification regarding the use of automated financial monitoring systems. An automated risk alert must be subject to a proper substantive review in cases where a decision with significant consequences for the client is planned based on it. At the same time, the internal verifiability and documentation of the decision should not be interpreted as an obligation to disclose to the client information whose disclosure is prohibited by Law No. 361-IX.

Fifth, for systems that have a significant impact on clients’ rights, the National Bank of Ukraine may recommend—or subsequently mandate through regulations—the conduct of a preliminary human rights impact assessment integrated into existing bank risk management procedures. For systems with high operational or systemic significance, the concentration of external suppliers, the possibility of replacing a critical supplier, and the consequences of its unavailability should be additionally assessed.

The transition to mandatory requirements should be carried out gradually. At the initial stage, the most appropriate measures are sector-specific recommendations from the National Bank of Ukraine and banks’ internal self-assessments; subsequently, controlled testing of new systems, the accumulation of supervisory practices, and information on significant incidents. This proactive yet proportionate approach is consistent with the conclusion by Truby, Brown, and Dahdal regarding the need for timely regulatory intervention in the financial sector without unduly stifling innovation. Mandatory requirements should primarily apply to systems with a high impact on human rights or high significance for the stability of a bank or the financial system.
This approach allows for the use of existing banking supervision mechanisms rather than creating a separate, cumbersome regulatory regime. Legal regulation should respond in a timely manner to identified risks without imposing abstract prohibitions that unreasonably preempt technological development.

Conclusions
The use of artificial intelligence in banking is a natural and promising direction for the development of the financial sector, capable of increasing the speed, accuracy, and accessibility of banking services. When its output determines creditworthiness, the essential terms of a financial service, the ability to manage funds, the continuation of banking services, or other decisions with significant consequences, a constitutional and legal dimension arises concerning the protection of human dignity, equality, privacy, and the right to effective legal protection.

Constitutional rights in “bank-client” relationships should not be understood as public-law obligations automatically imposed on the bank. Their impact on private legal relationships is realized primarily through the state’s positive obligations to establish appropriate legislative regulation, banking supervision, and judicial protection. There is no need to create separate constitutional rights for different uses of artificial intelligence: the necessary level of protection is ensured by specifying the guarantees set forth in Articles 3, 8, 21, 22, 24, 32, 55, and 64 of the Constitution of Ukraine. The practical application of the prohibition on discrimination resulting from automated assessment must take into account a specific rule of civil procedure: once the plaintiff has presented factual evidence confirming discrimination, the burden of proving its absence falls on the defendant.

The most appropriate model for banking activities is a risk-based approach, in which the scope of legal and regulatory requirements is determined not by the mere fact of using artificial intelligence, but by the nature of its consequences. The proposed assessment should be conducted along two axes: the impact on customer rights and the system’s significance for the stability of the bank or the financial system. On this basis, it is proposed to distinguish between auxiliary, significant, and high-risk systems, while these two axes determine not only the level but also the substance of regulatory requirements. A high risk to customer rights primarily entails requirements regarding non-discrimination, explanation, human review, and effective protection; a high risk to the stability of a bank or the financial system entails requirements regarding independent verification of suitability, operational stability, and dependence on external suppliers. A single system may have different risk levels along each of these axes.

The primary procedural safeguard for a legally significant automated banking decision should be the ability to obtain a clear explanation of its underlying rationale and to secure a substantive review by an authorized bank employee. This safeguard does not entail a general obligation to disclose source code, technical documentation that is not necessary for understanding the reasons behind the decision, or information constituting a trade secret. Human oversight is meaningful only when an authorized person can independently verify the result, take into account additional information and the client’s position, and provided that

The general rule regarding the explanation of automated decisions requires a special caveat in the area of financial monitoring. It is necessary to distinguish between the internal verifiability of a decision—which ensures that the bank, regulator, or court can reproduce and verify its grounds—and the extent of the explanation that may be provided to the customer in accordance with the law. Distinguishing between an automated risk alert and a final decision makes it possible to combine the effectiveness of financial monitoring with safeguards against unjustified restrictions on banking services.

The use of artificial intelligence and the engagement of an external provider do not alter the principle of the bank’s legal liability for its decisions. Management of the relevant systems must be integrated into the existing corporate governance, risk management, and internal control frameworks. The transfer of information to an external provider must comply with legislation on personal data and banking secrecy, in particular the special regime governing information obtained during creditworthiness assessments. For systems of high operational or systemic importance, supervision must also cover the risk of concentration and dependence on external providers.

Ukraine should develop its legal framework in stages: sector-specific recommendations from the National Bank of Ukraine and self-assessments by banks; controlled testing of new solutions; accumulation of supervisory practices and information on significant incidents; and, in the future, mandatory requirements—primarily for systems with high individual or systemic risk. The top priorities for change should be enshrining in consumer lending legislation the right to an explanation and a human review of an automated decision, as well as requirements for the data used to assess creditworthiness; establishing, by the National Bank of Ukraine, requirements for banks’ internal accounting of significant systems and the management of their risks; and specifying requirements for automated financial monitoring. It is advisable to integrate such rules into existing mechanisms for banking supervision, risk management, personal data protection, anti-discrimination, consumer lending, and financial monitoring. Under this approach, innovation in banking, the protection of customer rights, and financial stability are interrelated objectives of legal regulation.