Working paper available on Goethe University Frankfurt’s publication server: 26-02_RPS_Frankfurt.pdf
Banking-as-a-Service (BaaS) is a model in which a licensed bank provides regulated banking products through a service organised by a non-bank partner. The partner may control the customer interface and deploy an AI Banking Agent that communicates with customers and performs tasks through the bank’s infrastructure. This creates legal uncertainty because the agent may communicate, contract or act through systems controlled by different parties. It may also affect the relationship between the bank and the end user. This article examines how control and responsibility for such an agent should be allocated between the bank and the BaaS partner. It considers how the BaaS agreement supports the bank’s duties towards the end user and how automated actions should be attributed. It argues that internal contractual responsibility should follow effective control over the agent’s relevant function. However, this allocation cannot displace mandatory duties imposed on either party by applicable law. The article distinguishes attribution from contractual responsibility and external liability. It proposes an effective control test for BaaS agreements and identifies minimum control conditions. It also identifies a control-responsibility gap, which arises where a party retains a legal duty but lacks the information or intervention rights needed to perform it.









