The EU AI Act names two financial services uses as high-risk: credit scoring of individuals and pricing of life and health insurance. After the Digital Omnibus on AI, their duties apply from 2 December 2027. Banks, insurers and asset managers already owe AI literacy. Since 2 August 2026 they must also tell clients when they are dealing with AI.1,2

Summary

  1. High-risk duties start on 2 December 2027, not 2 August 2026. Many guides still show the old date. Most AI in banking, such as fraud models and internal assistants, is not high-risk.
  2. Building in-house makes the institution a provider. Four in ten AI use cases at EU securities firms are built in-house; at credit institutions the share is 59 percent.
  3. Banking law replaces only two AI Act duties outright. Data governance, human oversight, accuracy and explanation get no relief. The financial supervisor enforces.

Which AI uses in financial services are high-risk under the EU AI Act?

Annex III lists the high-risk uses. Two are financial. Point 5(b) covers AI that evaluates the creditworthiness of natural persons or sets their credit score, except fraud detection. Point 5(c) covers risk assessment and pricing for natural persons in life and health insurance.3 Recruitment tools are high-risk in every sector, banks included.

Profiling settles most borderline cases. Article 6(3) lets a provider argue that an Annex III system is not high-risk, for example because it only prepares a decision. That route is closed when the system profiles natural persons.1 A consumer credit score always does.

Common financial services AI uses under the AI Act

Use case AI Act basis Main duties apply from
Credit scoring of individuals Annex III, point 5(b) 2 Dec 2027
Life and health insurance pricing Annex III, point 5(c) 2 Dec 2027
CV screening and hiring Annex III, point 4(a) 2 Dec 2027
Emotion recognition of staff Article 5(1)(f) 2 Feb 2025
Fraud detection Excluded from point 5(b) 2 Feb 2025
Scoring of companies Point 5(b) covers persons only 2 Feb 2025
Motor and property pricing Not in point 5(c) 2 Feb 2025
Selfie ID check at onboarding Excluded from point 1(a) 2 Feb 2025
Robo-advice, portfolio tools Not in Annex III 2 Feb 2025
Client chatbot Article 50 transparency 2 Aug 2026
Internal assistant Article 4 AI literacy 2 Feb 2025

Prohibited High-risk Lighter duties

Sources: Regulation (EU) 2024/1689, Articles 4, 5, 6 and 50 and Annex III, dates as amended by Regulation (EU) 2026/1744; AI Act Service Desk; accessed 29 September 2026. Lighter duties: AI literacy for all, plus Article 50 where clients deal with AI. Biometric onboarding data remains special category data under GDPR Article 9.

Much of a bank's AI sits outside Annex III: fraud models, corporate credit, motor pricing, portfolio tools and internal assistants. In 2025 workshops with 13 banks, the ECB found that institutions expect fraud detection to be classed as low-risk.4 None of the 13 used generative AI for credit scoring. They cited development time, cost and trustworthiness.

When do AI Act obligations apply to banks and insurers?

Many compliance guides still give 2 August 2026 as the high-risk deadline. That date no longer holds. The Digital Omnibus on AI, in force since 27 July 2026, moved Annex III duties by 16 months.2

  • 2 February 2025. Prohibited practices and AI literacy.
  • 2 August 2026. Article 50 transparency: clients must know when they deal with AI.
  • 2 December 2027. High-risk duties for credit scoring, life and health pricing and hiring tools.

Systems in use before 2 December 2027 fall under the high-risk rules only if their design later changes significantly.1 A bank's model change policy therefore decides when a legacy scoring model comes into scope. The EU AI Act timeline lists every date.

Is a bank the provider or the deployer of its AI?

The AI Act assigns duties by role. A provider develops a system and puts it into service under its own name, including for its own use. A deployer uses a system under its own authority. The EBA notes that a bank building in-house is both.6

Providers carry the heavier load: risk management, technical documentation, conformity assessment and registration. A deployer that puts its name on a high-risk system, or modifies it substantially, becomes its provider under Article 25.1 Exhibit 1 shows how often financial firms build rather than buy.

Many firms build their own AI

In-house development is the most common single approach at EU securities market firms.

Four in ten AI use cases at EU securities firms are built in-house. For a high-risk system, that makes the firm the provider.

AI use cases by development approach, % of 823 use cases

Model from an external provider Built by the firm
0 10 20 30 40 50 Built in-house¹ 43% Off-the-shelf model 36% External model, customised² 15% Bespoke, built by a vendor 6%

¹ Fully in-house or with support from consultants. At credit institutions, 59% of use cases were built in-house. ² Externally developed model customised by the firm, for example fine-tuned on its own data. Survey of 728 securities market firms in 19 EU countries, June to September 2025. Participation was voluntary and the sample is weighted towards Portugal, Malta and Ireland.

Source: ESMA, TRV Risk Analysis: AI adoption and trends in securities markets, EU evidence, 20 February 2026, Chart 10

Credit institutions build most: 59 percent of their AI use cases.5 Generative AI is different. Most of it runs on commercial models, and only about 8 percent of the AI providers firms named are domiciled in the EU.5 Insurers mostly expect to be deployers, EIOPA found. Some were unsure whether fine-tuning or retrieval on a third-party model makes them providers.16

What does banking law already cover?

The EBA mapped the AI Act's high-risk duties against CRD, CRR, DORA, the consumer and mortgage credit directives and its own guidelines. It found no significant contradictions and no immediate need for new EBA guidelines.6 The Act lets banking rules stand in for some duties. Articles 17(4) and 26(5) deem the quality management and monitoring duties met through internal governance rules. Article 26(6) lets logs sit in the documentation banking law already requires.1

High-risk duties and EU banking law, as read by the EBA

AI Act duty Who owes it AI Act article
Quality management system, in part Provider Art. 17(4)
Monitoring of the system in use Deployer Art. 26(5)
Risk management system Provider Art. 9
Technical documentation Provider Art. 11
Log-keeping Both Art. 12, 19, 26(6)
Post-market monitoring plan Provider Art. 72
Fundamental rights impact assessment Deployer Art. 27
Data governance Provider Art. 10
Human oversight Both Art. 14, 26(2)
Accuracy, robustness, cyber security Provider Art. 15
Explanation of individual decisions Deployer Art. 86

Replaced by banking rules Fold into existing framework No relief in the Act

Source: EBA, AI Act: implications for the EU banking and payments sector, 21 November 2025, table of regulatory synergies; AI Act Articles 17(4), 26(5) and 26(6); accessed 29 September 2026. CCD2: Consumer Credit Directive (EU) 2023/2225. The EBA mapping is not guidance or a legal position.

The real work sits in the grey rows. Data governance, human oversight, accuracy and the right to an explanation get no relief in the Act, though DORA, CRR and consumer credit rules give a base. The fundamental rights impact assessment is new for private lenders and life and health insurers. Article 27 requires it before first use, with the results sent to the market surveillance authority. For insurers' AI outside the high-risk list, EIOPA's August 2025 opinion sets similar expectations: data governance, fairness, explainability and human oversight.17

Who supervises AI Act compliance at financial institutions?

Article 74(6) makes the financial supervisor the market surveillance authority for high-risk AI used by regulated financial institutions, where the use is directly connected with financial services. A Member State may appoint another authority, provided coordination is ensured.1

Germany shows how this looks. Since 29 July 2026, BaFin has supervised AI used in direct connection with regulated financial activities: high-risk systems, chatbot transparency and prohibited practices.7 The supervisor that reviews credit risk models will now also ask for AI Act evidence.

Does a logistic regression pricing model count as AI?

This is the open question for insurers and lenders. In April 2026, EIOPA asked the co-legislators to exclude generalised linear and additive models, including logistic regression, from point 5(c). It pointed to decades of actuarial use and cited an ECB opinion of March 2026 in the same direction.8 The final Omnibus text did not include the change.

EIOPA followed with a technical annex for the Commission. It concluded that the conditions for a targeted amendment of Annex III are met.9 The Commission can amend Annex III by delegated act. Its guidelines on high-risk classification were published in draft on 19 May 2026 and are not yet final.10 Until they are, each scoring and pricing model needs a documented view on whether it is an AI system at all.

What are the AI Act fines for banks and insurers?

Article 99 sets three tiers of fines. Some compliance guides quote 6 percent of turnover for high-risk breaches. That figure is not in the adopted text.1 Exhibit 2 compares the real caps with the GDPR.

High-risk breaches cap at 3 percent

The AI Act's high-risk tier sits below the GDPR's upper tier.

Breaching high-risk duties costs up to 3% of worldwide turnover, less than the GDPR maximum.

Maximum administrative fine, % of total worldwide annual turnover

EU AI Act GDPR
0 1 2 3 4 5 6 7 8 AI Act, prohibited practices 7% GDPR, upper tier 4% AI Act, high-risk duties¹ 3% GDPR, lower tier 2% AI Act, misleading information 1%

¹ Article 99(4): duties of providers (Article 16) and deployers (Article 26), and Article 50 transparency, among others. Fixed caps apply where higher: €35 million, €15 million and €7.5 million under the AI Act; €20 million and €10 million under the GDPR. Lower caps apply to SMEs and, since the Omnibus, small mid-caps.

Source: Regulation (EU) 2024/1689, Article 99(3) to (5); Regulation (EU) 2016/679, Article 83(4) and (5); EUR-Lex, accessed 29 September 2026

A breach of high-risk provider or deployer duties costs up to €15 million or 3 percent of worldwide turnover, whichever is higher. The GDPR's upper tier reaches 4 percent.11 For lenders, GDPR stays the sharper risk. In the SCHUFA case, the Court of Justice held that a credit score can itself be an automated decision under Article 22.13 DORA leaves penalties for financial entities to national law.12

What should banks, insurers and asset managers do before December 2027?

AI is already routine. The EBA reports that 92 percent of EU banks deploy AI, and 55 percent of surveyed banks use general-purpose or agentic AI in consumer-facing processes.14 ECB data show more than 90 percent of directly supervised banks integrate AI and 85 percent use generative AI.15 Lindstead advises this order:

  1. List every AI system, vendor tools included, and link each to the DORA register of information.
  2. Classify each against Annex III and record the role, provider or deployer, with the reasoning.
  3. For credit scoring and life and health pricing, start the impact assessment and logging design now.
  4. Set a policy for public generative AI tools. ESMA found 74 percent of securities firms let staff use them; only 32 percent have a policy.5
  5. Agree with vendors the documentation a deployer needs under Articles 13 and 26.

Asset managers carry the lightest load. Portfolio management and investment advice are not in Annex III, so their main duties are AI literacy, chatbot transparency and hiring tools. Still, 76 percent of ESMA's respondents expect the Act to affect them strongly or moderately.5

The financial services sector page covers DORA exit plans and critical providers. Lindstead maps AI Act, DORA and GDPR duties to each AI system an institution runs, and tests open-weight models for model risk teams. It also deploys a first use case on infrastructure the institution controls. The guide to on-premise and private cloud AI sets out where each option leaves the data.

Frequently asked questions

  • Yes, for individuals. Annex III, point 5(b) lists AI that evaluates the creditworthiness of natural persons or sets their credit score, except fraud detection. Because a credit score profiles a person, the Article 6(3) exemption for preparatory or narrow tasks does not apply. Duties start on 2 December 2027.

  • No. Point 5(b) expressly excludes AI used to detect financial fraud. The AI literacy duty of Article 4 still applies, and GDPR applies to the transaction data.

  • Prohibitions and AI literacy have applied since 2 February 2025, and Article 50 transparency, for example for client chatbots, since 2 August 2026. High-risk duties for credit scoring apply from 2 December 2027, after the Digital Omnibus on AI. Systems already in use before then are covered only if their design later changes significantly.

  • For high-risk AI used in direct connection with financial services, the national financial supervisor acts as market surveillance authority under Article 74(6), unless a Member State designates another authority. In Germany, BaFin took on this role on 29 July 2026.

  • Yes, if they deploy AI for risk assessment and pricing of individuals in life and health insurance. Lenders using AI credit scoring of individuals must do the same. The assessment is due before first use, its results go to the market surveillance authority, and it can build on an existing GDPR impact assessment.

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 4, 5, 6, 17, 25, 26, 27, 50, 74, 99 and 111. eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal, 24 July 2026; in force 27 July 2026. eur-lex.europa.eu/legal-content/EN/TXT/
  3. European Commission, AI Act Service Desk, Annex III: high-risk AI systems. ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
  4. ECB Banking Supervision, AI workshops with banks 2025, annex, November 2025. www.bankingsupervision.europa.eu/ecb/pub/pdf/annex/ssm.nl251120_1_annex.en.pdf
  5. ESMA, TRV Risk Analysis: AI adoption and trends in securities markets, EU evidence, 20 February 2026. www.esma.europa.eu/sites/default/files/2026-02/ESMA50-481369926-30599_TRV_Risk_Analysis_AI_adoption_and_trends_in_securities_markets.pdf
  6. EBA, AI Act: implications for the EU banking and payments sector, 21 November 2025. www.eba.europa.eu/sites/default/files/2025-11/d8b999ce-a1d9-4964-9606-971bbc2aaf89/AI%20Act%20implications%20for%20the%20EU%20banking%20sector.pdf
  7. BaFin, Market surveillance of AI: BaFin granted new powers, 29 July 2026. www.bafin.de/SharedDocs/Veroeffentlichungen/EN/Pressemitteilung/2026/pm_2026_07_29_ki_verordnung_en.html
  8. EIOPA, Letter on the AI Act and EU insurance legislation, EIOPA-26/323, 13 April 2026. www.eiopa.europa.eu/document/download/b67ede29-8217-46df-bb46-526e004d34bb_en
  9. EIOPA, Technical annex on the exclusion of GLMs and GAMs from the AI Act high-risk classification, 30 April 2026. www.eiopa.europa.eu/document/download/95a805a3-791c-4502-b167-00dae8bb1444_en
  10. European Commission, Draft guidelines on the classification of high-risk AI systems, 19 May 2026. digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems
  11. Regulation (EU) 2016/679 (GDPR), Articles 22 and 83. eur-lex.europa.eu/eli/reg/2016/679/oj
  12. Regulation (EU) 2022/2554 (DORA), Article 50. eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
  13. Court of Justice of the EU, Press release 186/23, SCHUFA Holding (Scoring), C-634/21, 7 December 2023. curia.europa.eu/jcms/upload/docs/application/pdf/2023-12/cp230186en.pdf
  14. EBA, Rising application of AI in EU banking and payments sector, 25 September 2025. www.eba.europa.eu/sites/default/files/2025-09/146b3558-d026-47bf-a872-f05e93ed30d2/Rising%20application%20of%20AI%20in%20EU%20banking%20and%20payments%20sector.pdf
  15. Claudia Buch, Digital innovation: hindrance or booster for banks' business models?, ECB speech, 22 September 2026. www.bankingsupervision.europa.eu/press/speeches/date/2026/html/ssm.sp260922~6d21ed7918.en.html
  16. EIOPA, Generative AI Market Survey: Outlook, Use Cases and Risk Management, February 2026 (survey July 2025). www.eiopa.europa.eu/document/download/bec886e2-dea0-4bbe-9624-d5f23f85700a_en
  17. EIOPA, Opinion on AI governance and risk management, 6 August 2025. www.eiopa.europa.eu/eiopa-publishes-opinion-ai-governance-and-risk-management-2025-08-06_en

Method: provisions read from the AI Act text and the Commission's AI Act Service Desk; supervisory data from the EBA, ECB, ESMA and EIOPA. All sources accessed 29 September 2026. General information, not legal advice. Corrections: contact@lindstead.com.