Banking Law And Crisis Management Through Robotics Spain .
1. Introduction
Spanish banking crisis management operates within a multi-level legal framework:
- Spanish banking law
- European Union banking law
- Single Supervisory Mechanism (SSM)
- Single Resolution Mechanism (SRM)
- Data protection and automated decision-making law
- Digital operational-resilience and cybersecurity regulation
- EU Artificial Intelligence Act
The principal Spanish statutes are:
- Law 10/2014 of 26 June (Ley 10/2014) on the organisation, supervision and solvency of credit institutions.
- Law 11/2015 of 18 June (Ley 11/2015) on recovery and resolution of credit institutions and investment firms.
- EU Regulation 806/2014, establishing the Single Resolution Mechanism.
- EU Directive 2014/59/EU (BRRD) on bank recovery and resolution.
- EU Regulation 2022/2554 (DORA) on digital operational resilience.
- EU Regulation 2024/1689 (AI Act).
- GDPR, particularly Article 22 concerning automated individual decision-making.
The Banco de España itself identifies EU Regulation 1024/2013 establishing the Single Supervisory Mechanism as part of the current legal foundation of banking supervision.
2. What is banking crisis management?
A banking crisis occurs when a bank experiences serious problems such as:
- liquidity shortage;
- insolvency;
- inadequate capital;
- excessive losses;
- inability to meet payment obligations;
- cyberattack or technological failure;
- massive deposit withdrawals;
- governance failures;
- market contagion.
The modern Spanish/EU approach is not simply to rescue a failing bank with public money.
The objective is instead to:
prevent bank failure where possible, prepare for failure, and, where necessary, resolve the bank in an orderly manner while protecting financial stability and critical banking functions.
Spanish law therefore distinguishes between recovery and resolution.
3. Recovery vs Resolution
A. Recovery
Recovery is the stage where the bank is still potentially viable.
The bank prepares a recovery plan explaining what it will do if its financial position deteriorates.
Possible measures include:
- raising capital;
- selling assets;
- reducing costs;
- restructuring;
- obtaining liquidity;
- changing management;
- reducing risk exposure.
The purpose is to restore the bank's viability without resolution.
B. Resolution
Resolution occurs when the bank has reached, or is approaching, a condition where normal business cannot continue safely.
The EU/Spanish framework generally asks whether:
- the bank is failing or likely to fail;
- there is no reasonable private or supervisory alternative capable of restoring viability; and
- resolution is necessary in the public interest.
The SRB describes these as the core conditions for resolution.
4. Spanish authorities involved
Banco de España
The Banco de España has an important supervisory and preventive role.
In the Spanish resolution framework, it prepares banks for possible resolution during the preventive phase. The FROB becomes particularly important during the executive resolution phase.
FROB
Fondo de Reestructuración Ordenada Bancaria (FROB) is Spain's national resolution authority.
It implements resolution measures in the circumstances provided by the Spanish/EU framework.
European Central Bank
For significant banks within the Banking Union, the ECB exercises direct prudential supervision under the Single Supervisory Mechanism.
Single Resolution Board
The SRB/JUR is responsible for resolution decisions concerning banks falling within the Single Resolution Mechanism.
Thus, Spanish banking crisis management is not purely national.
5. Where does robotics/AI enter banking crisis management?
This is the particularly important part of the question.
“Robotics” can be understood as RPA + AI + automated monitoring + machine learning + algorithmic decision systems.
A bank can use these technologies throughout the crisis-management cycle.
Example
Imagine a Spanish bank with €100 billion in assets.
An automated system continuously analyses:
- liquidity;
- capital ratios;
- deposit withdrawals;
- market prices;
- loan defaults;
- cyber incidents;
- suspicious transactions;
- payment-system interruptions;
- interbank exposures.
The system identifies a rapid deterioration.
It can automatically:
Detect → Alert → Analyse → Escalate → Recommend → Execute predefined actions → Report to management/regulator.
But the crucial legal principle is:
Automation does not eliminate the bank's legal responsibility.
This principle is especially clear under DORA. Financial entities remain fully responsible for compliance even where ICT services are provided by third parties.
6. Robotics in early-warning systems
One of the most useful applications is early detection of financial distress.
An AI/RPA system could monitor:
| Risk | Automated indicator |
|---|---|
| Liquidity crisis | abnormal deposit withdrawals |
| Credit crisis | sudden increase in non-performing loans |
| Market crisis | rapid fall in securities prices |
| Capital crisis | deterioration of CET1 ratio |
| Cyber crisis | abnormal network activity |
| Operational crisis | payment-system failures |
| Fraud | unusual transaction patterns |
| Contagion | increased exposure to distressed institutions |
DORA specifically requires financial entities to have mechanisms capable of promptly detecting anomalous activities and ICT incidents. It also contemplates automated alert mechanisms.
Thus, technology can become part of a bank's preventive crisis-management architecture.
7. Robotics and liquidity crisis management
Liquidity is often the immediate trigger of a banking crisis.
An automated system can continuously calculate:
Liquidity Coverage Ratio (LCR)
Net Stable Funding Ratio (NSFR)
cash-flow projections
deposit outflow scenarios
collateral availability
For example:
If deposits fall by 10% within 24 hours and projected liquidity falls below the bank's internal threshold, the system generates an emergency alert.
The system may then:
- notify treasury;
- notify senior management;
- freeze selected non-essential expenditures;
- calculate available collateral;
- prepare regulatory reports;
- activate elements of the contingency funding plan.
However, a robot should not automatically make legally irreversible decisions unless the legal framework and internal governance permit it.
8. Robotics and capital adequacy
AI can also monitor:
- CET1;
- Tier 1 capital;
- total capital;
- risk-weighted assets;
- concentration risk;
- stress-test results.
Machine-learning systems can identify relationships between:
credit deterioration → provisions → losses → capital reduction → possible breach of regulatory requirements.
This can allow a bank to take corrective action earlier.
Spanish prudential regulation developed significantly after the financial crisis, including through Banco de España's supervisory framework and Circular 2/2016, later amended by Circular 5/2021.
9. Robotics and stress testing
Banks can use automated systems to run thousands of crisis scenarios.
For example:
Scenario 1
10% deposit withdrawal.
Scenario 2
20% decline in real-estate values.
Scenario 3
Major cyberattack.
Scenario 4
Failure of a major counterparty.
Scenario 5
Combination of recession + unemployment + interest-rate shock.
AI can calculate potential effects on:
- capital;
- liquidity;
- profitability;
- credit losses;
- market risk;
- operational risk.
This helps supervisors and bank management determine whether the bank is resolvable and whether recovery measures are sufficient.
10. Robotics and bank resolution
This is where technology becomes particularly interesting legally.
Resolution authorities need accurate information extremely quickly.
Automated systems can help identify:
- critical functions;
- depositors;
- assets;
- liabilities;
- creditors;
- capital instruments;
- intra-group transactions;
- collateral;
- payment systems;
- contractual relationships.
This supports the resolution authority in determining how to apply resolution tools.
Under the EU resolution framework, resolution seeks to maintain critical functions and financial stability rather than simply allowing a disorderly collapse.
11. Bail-in and automated systems
One major resolution technique is bail-in.
Instead of taxpayers absorbing all losses, certain shareholders and creditors can bear losses.
An automated resolution system could help determine:
Who owns what?
Which liabilities are eligible?
What losses must be absorbed?
What amount should be written down or converted?
But this is an area where human/legal oversight is essential.
An incorrect algorithm could cause:
- wrongful deprivation of property;
- discrimination between creditors;
- incorrect valuation;
- breach of procedural rights;
- litigation.
Therefore, automation should support—not replace—the legally responsible authority.
12. The landmark case: Banco Popular
The most important Spanish banking-crisis case is Banco Popular Español.
Facts
Banco Popular experienced a severe liquidity crisis in 2017.
On 6 June 2017, the ECB determined that Banco Popular was failing or likely to fail.
On 7 June 2017, the SRB adopted a resolution decision.
The bank was resolved through a sale of business, ultimately transferring it to Banco Santander.
The resolution involved:
- write-down of shares;
- conversion of certain capital instruments;
- transfer of the business;
- protection of critical functions;
- continuation of banking services.
The SRB's official records document the Banco Popular resolution and the subsequent valuation/compensation process.
13. Why Banco Popular is important for robotics
Banco Popular was not a robotics case.
That distinction is essential.
There was no court decision establishing that AI or robots may legally resolve a bank.
Instead, Banco Popular provides the crisis-management legal framework into which automated technologies could be integrated.
The case demonstrates that crisis management may require decisions to be made within hours.
That makes reliable automated systems extremely valuable for:
- liquidity monitoring;
- valuation;
- data aggregation;
- creditor identification;
- resolution planning;
- communication;
- operational continuity.
14. Banco Popular case law
The Banco Popular resolution generated numerous legal challenges.
In June 2022, the General Court of the European Union dismissed five actions challenging the resolution. The Court upheld the legality of the resolution and the sale to Santander, and held that imposing losses on shareholders and creditors did not, in the circumstances, violate their EU-law rights.
This is an extremely important principle:
Bank-resolution measures can lawfully impose losses on investors where the statutory resolution conditions and safeguards are satisfied.
The SRB later determined that affected shareholders and creditors were not entitled to compensation, because they would not have been better off under ordinary insolvency proceedings.
15. “No creditor worse off” principle
A fundamental safeguard is the principle commonly described as:
No Creditor Worse Off Than in Liquidation
The idea is:
A creditor should not be worse off as a result of resolution than that creditor would have been in ordinary insolvency proceedings.
The SRB expressly describes this safeguard in relation to Banco Popular.
This principle becomes particularly important when automated valuation systems are used.
Example
Suppose an AI valuation system calculates:
- recovery under resolution = €500 million;
- recovery under ordinary insolvency = €400 million.
The resolution may be defensible.
But if the algorithm incorrectly calculates the insolvency counterfactual as €200 million when the correct figure is €450 million, affected creditors could argue that their statutory rights were violated.
Therefore:
AI valuation → must be auditable → must be legally reviewable.
16. Artificial intelligence and credit decisions
Robotics in banking is not limited to crisis management.
Banks use automated systems to decide:
- whether to grant loans;
- credit limits;
- interest rates;
- fraud alerts;
- risk classifications.
This raises a separate legal problem: automated decision-making and fundamental rights.
The EU AI Act is particularly important.
It expressly recognises that AI systems used to evaluate the creditworthiness or credit score of natural persons should be treated as high-risk systems because they can determine access to financial resources and may produce discriminatory effects.
17. SCHUFA case — C-634/21
A major European case relevant to Spanish banks is:
SCHUFA Holding (Scoring), C-634/21, EU:C:2023:957
The Court of Justice decided on 7 December 2023.
The case concerned automated credit scoring.
The significance is enormous for banks using AI.
The Court dealt with Article 22 GDPR and automated decision-making.
The Court's approach means that a scoring system can fall within the legal protection applicable to automated decisions where its output plays a determining role in a decision having significant effects on the person.
The official InfoCuria record confirms the judgment of 7 December 2023 in C-634/21.
Banking significance
Suppose:
AI gives customer X a credit score of 42/100 → loan automatically rejected.
The bank cannot simply argue:
“The robot made the decision.”
The bank must consider GDPR obligations and the safeguards surrounding automated decision-making.
18. Dun & Bradstreet Austria — C-203/22
Another important case is:
Dun & Bradstreet Austria and Others, C-203/22
Judgment: 27 February 2025.
The case concerned automated credit scoring and the individual's right to receive meaningful information about the logic underlying automated processing.
The Court addressed the relationship between:
- automated decision-making;
- transparency;
- access to information;
- trade secrets;
- third-party personal data.
The Court's subsequent jurisprudence is highly relevant to financial institutions using algorithmic credit scoring.
Practical significance for Spain
A Spanish bank using an AI credit-scoring model cannot treat its algorithm as an absolute legal black box.
There must be sufficient transparency to allow applicable data-protection rights to operate.
19. DORA — perhaps the most important technology law
For the “robotics” aspect of your question, DORA — Regulation (EU) 2022/2554 — is extremely important.
DORA creates a harmonised framework for digital operational resilience in the financial sector.
It requires financial entities to establish an ICT-risk management framework.
The framework covers:
- ICT security;
- operational resilience;
- incident management;
- detection;
- response;
- recovery;
- business continuity;
- ICT third-party risk.
20. Robotics can itself create a crisis
This is a crucial legal point.
Technology is both:
A. A solution to banking crises
and
B. A potential source of banking crises.
For example:
Bad algorithm → wrong risk classification → excessive lending → losses → liquidity problems → systemic crisis.
Or:
Software failure → payment interruption → customer panic → deposit withdrawals → liquidity crisis.
Or:
AI fraud detection incorrectly blocks thousands of legitimate transactions → operational disruption → reputational damage.
DORA therefore requires financial entities to manage ICT risk systematically.
DORA requires incident-management processes capable of detecting, managing and reporting ICT incidents and requires early-warning indicators.
21. Automated cybersecurity response
DORA even contemplates automated mechanisms for dealing with cyberattacks.
Financial entities must have mechanisms for detecting anomalous activities, and their systems may include automatic alert mechanisms and automated mechanisms for isolating affected information assets.
Thus:
Robotics/automation is legally compatible with crisis management, but it must exist within a controlled governance framework.
22. Third-party robotics and cloud providers
Modern banks rarely build everything themselves.
They may use:
- cloud providers;
- AI providers;
- cybersecurity companies;
- robotic-process-automation providers;
- data analytics companies.
This creates third-party ICT risk.
DORA specifically regulates ICT third-party risk.
An important principle is:
Outsourcing does not outsource legal responsibility.
The financial institution remains responsible for compliance even where technology is supplied by an external ICT provider.
23. Legal liability for robotic banking
Suppose a bank's AI system makes a wrong decision.
Who is responsible?
Potentially:
- the bank;
- senior management;
- the technology provider;
- the data processor;
- cybersecurity provider;
- individual employees;
- potentially other parties depending upon the facts.
The answer cannot simply be:
“The robot is responsible.”
A robot/AI system does not replace the legal personality or regulatory responsibility of the bank.
24. Human oversight
A robust Spanish banking AI system should therefore follow:
Human-in-the-loop model
AI detects problem
↓
AI analyses data
↓
AI generates recommendation
↓
Human decision-maker reviews
↓
Legal/regulatory decision
↓
Automated execution where appropriate
This is preferable for high-impact decisions.
The distinction is also relevant to GDPR Article 22. If a genuine human makes a meaningful assessment and has authority to change the automated result, the legal analysis of whether the decision is “solely automated” can change. The European jurisprudence on automated decision-making makes this distinction particularly important.
25. Main legal risks of banking robotics
| Risk | Legal problem |
|---|---|
| Algorithmic bias | Equality/non-discrimination |
| Wrong credit decision | Consumer/data-protection liability |
| Lack of transparency | GDPR/AI Act issues |
| Cyberattack | DORA/ICT-risk obligations |
| Software failure | Operational-resilience liability |
| Wrong valuation | Resolution litigation |
| Data breach | GDPR |
| Outsourced AI failure | Third-party ICT risk |
| Autonomous execution | Governance/accountability |
| Model manipulation | Fraud/cybersecurity |
| Poor training data | Accuracy/discrimination |
| Black-box AI | Explainability/transparency |
26. Relationship between AI Act and banking law
The AI Act does not replace banking regulation.
Instead, the laws operate together.
Banking law
asks:
Is the bank solvent, adequately capitalised and properly governed?
Resolution law
asks:
What happens if the bank is failing or likely to fail?
DORA
asks:
Is the bank digitally operationally resilient?
GDPR
asks:
How can personal data be processed and how are individuals protected?
AI Act
asks:
Is the AI system being developed/deployed in accordance with the applicable AI-risk requirements?
Therefore, one banking AI system may simultaneously be subject to banking law + DORA + GDPR + AI Act + consumer law.
27. Important case-law framework
For an examination answer, I would remember the following:
1. Banco Popular litigation
General Court, June 2022 — Banco Popular resolution cases
Principle:
Resolution of a failing bank and imposition of losses on shareholders/creditors can be lawful where the statutory EU resolution framework is satisfied.
2. SCHUFA Holding — C-634/21
CJEU, 7 December 2023
Principle:
Automated credit scoring can engage the GDPR's rules on automated individual decision-making.
3. Dun & Bradstreet Austria — C-203/22
CJEU, 27 February 2025
Principle:
Individuals affected by automated profiling have important rights concerning meaningful information about the logic underlying the processing, subject to the legal balancing of interests such as trade secrets and third-party data protection.
28. Hypothetical examination problem
Problem
A Spanish bank uses an AI robot to monitor liquidity.
The robot predicts that the bank is about to suffer a €5 billion liquidity shortage.
The bank automatically transfers €3 billion of assets and blocks certain transactions.
The AI was incorrectly trained and the prediction was wrong.
Customers suffer losses.
Legal questions
1. Was the bank entitled to use automation?
Generally, yes, provided its use complies with applicable banking, ICT, data-protection and AI rules.
2. Does automation eliminate liability?
No.
3. Was there adequate governance?
This is critical under DORA and prudential governance principles.
4. Was there human supervision?
If not, the bank may face greater legal and regulatory risk.
5. Was personal data used?
If yes, GDPR must be considered.
6. Was AI used to determine creditworthiness?
If yes, the AI Act's high-risk rules may become relevant.
7. Did the technological failure constitute an ICT incident?
Potentially yes, depending upon the circumstances, triggering DORA incident-management requirements.
29. How robotics could improve Spanish bank-crisis management
A legally compliant system could operate as follows:
Stage 1 — Continuous monitoring
AI continuously analyses:
- liquidity;
- capital;
- credit;
- market;
- cyber;
- operational indicators.
Stage 2 — Early warning
The system detects abnormal conditions.
Stage 3 — Escalation
An automatic alert goes to:
- risk management;
- compliance;
- senior management;
- relevant crisis committee.
Stage 4 — Human assessment
Experts verify whether the algorithm is correct.
Stage 5 — Recovery
The bank activates its recovery plan.
Stage 6 — Supervisory communication
Relevant information is supplied to the competent authorities.
Stage 7 — Resolution
If recovery fails and the legal conditions are met, the resolution framework is activated.
Stage 8 — Resolution execution
Automated systems can assist with:
- customer/depositor records;
- liability mapping;
- valuation;
- capital instruments;
- asset transfers;
- payment continuity.
Stage 9 — Audit
Every significant automated action should leave an audit trail.
30. Key principle: Technology cannot replace law
The most important conclusion is:
Robotics can automate the technical execution of banking crisis management, but it cannot replace the legal authority, accountability, procedural safeguards and human responsibility required by Spanish and EU banking law.
This is especially clear when comparing the two major areas:
Banco Popular demonstrates the legal requirements for resolving a banking crisis.
SCHUFA/Dun & Bradstreet demonstrate that algorithmic decision-making in financial services itself is subject to fundamental legal constraints.
DORA connects the two by making digital resilience and ICT-risk management an integral part of financial-sector governance.
31. Short conclusion for an exam
Banking crisis management in Spain is governed by a combination of Spanish and EU prudential supervision and bank-resolution law. Law 10/2014 establishes the principal Spanish framework for the supervision and solvency of credit institutions, while Law 11/2015 provides the Spanish framework for recovery and resolution. The Banco de España, FROB, ECB and Single Resolution Board play complementary roles. Robotic process automation, artificial intelligence and algorithmic systems can significantly improve crisis prevention by monitoring liquidity, capital, credit risk, cyber threats and operational failures and by supporting resolution planning and execution. However, automated systems do not possess independent legal responsibility. Their use remains subject to banking governance, DORA, GDPR, the EU AI Act, transparency, human oversight and fundamental-rights safeguards. The Banco Popular litigation illustrates the legality and safeguards of modern bank resolution, while SCHUFA (C-634/21) and Dun & Bradstreet Austria (C-203/22) demonstrate the legal limits applicable to automated financial decision-making. Therefore, robotics should be understood as a tool supporting legally accountable banking authorities and institutions, rather than as a substitute for legal judgment.

comments