Finance

High-risk AI in financial services, and what it actually means for you

21 July 2026 · 8 min

High-risk AI in financial services, and what it actually means for you

A credit model that decides whether a person gets a mortgage is not, in the eyes of the European legislator, the same kind of software as a chatbot that answers questions about your opening hours. The EU AI Act draws that line explicitly, and it runs straight through the middle of a modern bank or insurer. If your firm uses a model to score an applicant's creditworthiness, or to set the price of a life or health policy, you are operating what the Act calls a high-risk AI system. That classification carries a specific set of duties. It is worth knowing exactly which of your systems are caught, what the duties are, and when they apply, because the honest answer to the last question changed in the summer of 2026.

What the Act actually classifies as high-risk

The high-risk categories are listed in Annex III of the Act. Two of the eight points speak directly to financial services, both sitting under the heading of access to essential private services.

The first is credit. Annex III, point 5(b) covers "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud." Read that carve-out precisely. It is narrow. A model that decides whether Ms Schmidt can be trusted to repay a loan is high-risk. A model that flags a transaction on her card as likely fraudulent is not. The exception is for fraud detection, and only fraud detection. It does not extend to affordability checks, risk-based pricing, or the general question of whether to lend.

The second is insurance. Annex III, point 5(c) covers "AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance." Again, note the boundary. It is life and health, and it is risk assessment and pricing for individuals. Motor, property, casualty, and commercial lines are not named here. An underwriting model for a term life product is in scope. A pricing engine for fleet motor insurance is not, at least not on the basis of this point.

That distinction matters because the temptation, when a large regulation lands, is to sweep everything in and treat all models as if they carried the same weight. The Act does not ask you to do that. It asks you to be precise.

The exit that usually is not one

There is a provision that looks like a way out, and for credit and insurance models it usually is not. Article 6(3) lets a provider treat an Annex III system as not high-risk where it "does not pose a significant risk of harm" and does not materially influence the outcome of a decision. But the same article states that a system is "always" high-risk where it "performs profiling of natural persons."

A creditworthiness model builds a picture of an individual from their data in order to predict behaviour. That is profiling in the ordinary meaning of the word. So is risk rating a person for a life policy. In practice, the derogation in Article 6(3) is closed to exactly the financial use cases most likely to reach for it. If you are scoring people, assume you are high-risk and document the reasoning rather than the escape.

What high-risk obligates

Classification is the start, not the finish. A high-risk system has to be built and run against a defined set of requirements, most of them in Articles 9 to 15 of the Act. The list is long but it is not exotic to anyone who has worked in a regulated environment.

  • Risk management system. A continuous, documented process that runs across the model's life, not a one-off sign-off. Identify the risks the system poses to health, safety and fundamental rights, mitigate them, and keep the record current (Article 9).
  • Data and data governance. Training, validation and test data must be relevant, representative and, to the extent possible, free of errors. Bias that could lead to discrimination has to be examined and addressed. For a credit or underwriting model this is where the substantive work sits (Article 10).
  • Technical documentation. A file, structured along the lines of Annex IV, that lets a supervisor understand how the system was built and why it is compliant. It exists before the system goes live and stays current (Article 11).
  • Record-keeping and logging. The system logs its operation automatically, so events can be reconstructed after the fact. Retention has to match the purpose (Article 12).
  • Transparency and instructions for use. Deployers get clear information on the system's capabilities, limitations and intended purpose (Article 13).
  • Human oversight. The system is designed so a competent person can understand its output, override it, and stop it. This has to be real, evidenced by actual interventions, not a line in a policy (Article 14).
  • Accuracy, robustness and cybersecurity. Appropriate levels declared and maintained, with resilience against error and against attempts to manipulate the model (Article 15).

On top of the seven requirements sit the process duties: a quality management system (Article 17), a conformity assessment before the system is placed on the market or put into service, an EU declaration of conformity, and registration of the system in the EU database. For most Annex III financial systems the conformity assessment is an internal, self-assessment route rather than a third-party audit, which is a lighter path procedurally but not a lighter standard of evidence.

How it stacks with the rules you already follow

None of this arrives on empty ground. Banks and insurers are among the most heavily supervised firms in Europe, and the Act was written with that in mind rather than in ignorance of it.

The clearest signal is on enforcement. Under Article 74(6), for high-risk AI used by financial institutions regulated under Union financial services law, the market surveillance authority is the same national authority that already supervises those institutions. In Germany that means BaFin, not a new AI regulator. Your AI Act compliance will be assessed by the people who already know your book.

The Act also lets you build on structures you have. Article 17(4) says a financial institution can meet the quality management obligation by complying with the internal governance rules it is already bound by under financial services law. Recital 158 anticipates the conformity assessment being folded into existing supervisory review. The European Banking Authority, in its November 2025 report on the Act's implications for the banking and payments sector, took the same line, pointing firms toward their existing model risk management, outsourcing and governance frameworks rather than a parallel regime.

Then there is DORA, the Digital Operational Resilience Act, which governs ICT risk. An AI model is an ICT asset, and the two regimes meet at that point. Germany's supervisor made the connection concrete on 30 January 2026, when BaFin published its "Guidance on ICT Risks in the Use of AI at Financial Entities." The document is non-binding orientation rather than new law, and it is deliberately practical. It treats an AI system as part of the network and information systems already covered by DORA, and it organises the expectations around the model's full life, from data sourcing and development through operation to retirement. If you run a DORA ICT risk framework, BaFin's message is to bring AI inside it rather than alongside it. The theme is consistent across the picture: integrate, do not duplicate.

When it bites

This is the part that moved. The high-risk obligations under Annex III were due to apply from 2 August 2026. Through the first half of 2026 the European institutions negotiated a simplification package, the Digital Omnibus on AI, and it changed the calendar. Parliament voted on 16 June 2026, the Council gave final approval on 29 June, and the text was signed on 8 July. At the time of writing it is awaiting publication in the Official Journal.

The effect is a deferral. The standalone high-risk obligations under Annex III now apply from 2 December 2027. Systems that are high-risk because they are embedded in products already regulated under Annex I move to 2 August 2028. The earlier drafts had tied the delay to the availability of harmonised standards through a conditional trigger; the final text replaced that with fixed dates, which at least gives you a firm number to plan against.

Do not read the deferral as a reprieve. Two things still hold. The obligations that already applied, on prohibited practices and on transparency, remain in force, and the governance architecture of the Act is live. And the substance of what December 2027 requires, representative data, documented risk management, evidenced human oversight, is not something a firm assembles in a quarter. Sixteen extra months is roughly the time it takes to do this properly once, rather than the time to keep not doing it.

A practical way to start

You do not need a consultant in the room to take the first useful steps. You need an inventory and an honest reading of it.

  1. List every AI system that touches a decision about a person. Include models bought from vendors, not only those built in-house. Procurement is where scope quietly expands.
  2. Classify each against Annex III, point 5. Is it creditworthiness or credit scoring of a natural person? Is it life or health risk assessment or pricing for an individual? If yes, it is high-risk. If it is fraud detection, note the carve-out and keep the evidence for why it qualifies.
  3. Resist the false exits. If a system profiles people, Article 6(3) will not lower it out of high-risk. Record that judgement rather than assuming the derogation.
  4. Map each requirement to a control you already run. Model risk management, data governance, DORA ICT controls, internal audit. Find the gaps rather than rebuilding the parts that already work.
  5. Name an owner and a market surveillance contact. For most firms that supervisor is the one you already report to. Knowing who assesses you shapes how you document.
  6. Write the technical file as you go. The documentation is easier to build alongside the model than to reconstruct from memory two years later.

The takeaway

The Act has not asked financial firms to reinvent themselves. It has asked them to be specific about which of their models decide things about people, and to hold those models to a standard of evidence that a supervisor can inspect. Credit scoring of individuals and the risk rating and pricing of life and health cover are high-risk, plainly and by name. The deadline is now December 2027 rather than August 2026, which is more runway than it sounds and less than it looks. The firms that come out of this well will be the ones that treated the inventory as a genuine exercise in knowing their own systems, rather than a form to be filed.

← All insights

Where do you stand?

A short diagnostic tells you exactly where you are on the EU AI Act, and what to do next. No pressure.

Book an intro call →