Blogpost

High-risk AI in banking: What the EU AI Act really means for credit institutions

Credit scoring, fraud detection, AML: AI has long been deeply embedded in banks’ core processes. The EU AI Act classifies many of these applications as high-risk AI and sets out specific obligations for banks as operators – with new deadlines introduced by the Digital Omnibus on AI.
03/08/26
28 views
6 minutes reading time
Artificial Intelligence, Compliance, Digitisation, Regulatory Reporting
High-risk AI in banking: What the EU AI Act really means for credit institutions
Contents

Included in this collection:

Open collection

When AI becomes a regulatory issue

Hardly any other sector is as data-driven as the financial sector. This is precisely why the EU AI Act (Regulation (EU) 2024/1689) has a particular impact on the banking sector: many typical banking use cases fall within the regulation’s strictest non-prohibited risk category, namely high-risk AI.

What the EU AI Act means by an ‘AI system’

Before we turn to risk categories, it is worth considering the fundamental question: what actually counts as an AI system within the meaning of the law? This refers to any system that independently derives predictions, content, recommendations or decisions from input data and thereby produces real-world effects – a capability known as ‘derivation capability’. A traditional scoring model that uses customer data to determine a credit decision falls under this definition, as does a self-learning algorithm. Simple payroll software, on the other hand, does not; it lacks this ‘inference capability’. For banks, this means that significantly more systems fall under the regulation than the term ‘artificial intelligence’ might initially suggest.

For most institutions, one role is crucial: that of the operator. The EU AI Act defines this role as

“a natural or legal person, public authority, agency or other body which uses an AI system under its own responsibility.”

This role can be compared to a card terminal at a counter: the device comes from a manufacturer, but the bank ensures it is used correctly when interacting with customers and is liable if anything goes wrong. The EU AI Act applies precisely this principle to AI systems: whoever uses them is liable for their correct handling, regardless of who built them.

What makes an AI system in the banking sector ‘high-risk AI’?

The EU AI Act distinguishes between four risk categories: prohibited practices, high risk, limited risk (in particular transparency requirements, such as for chatbots) and minimal risk. A system is classified as high risk if it constitutes a safety component of an already regulated product or falls within one of the eight sensitive areas of application listed in Annex III.1

Of key importance to banks is Annex III, No. 5(b): AI systems used for creditworthiness checks and credit rating assessments of natural persons are explicitly classified as high-risk AI, regardless of whether a human ultimately makes the formal decision.2 This also includes HR screening in banks’ internal recruitment processes.1

Not all related use cases are legally equally clear-cut: pure fraud detection is expressly excluded2; fully automated lending remains, contrary to what is often claimed, highly relevant to high-risk activities3; and, in the area of anti-money laundering, there is as yet no clear legal basis for a blanket classification.4

Obligations as an operator

If institutions use a high-risk AI system without placing it on the market themselves, they are considered operators within the meaning of the Regulation. In particular, the following six key obligations apply to them:

1. Intended use. The system may only be used in the manner intended by the provider. A scoring model for consumer loans cannot, therefore, simply be applied to business loans.5

2. Qualified human oversight. A purely automated decision without the possibility of review is prohibited. In the lending sector, this means that a case handler must be able to understand the AI recommendation and, where in doubt, correct it, rather than merely signing it off as a formality.6

3. Sector-specific retention periods. The minimum retention period under the EU AI Act is six months. In the financial sector, however, this is significantly extended in many areas:

  • Six to ten years for documents relevant under commercial and tax law (HGB, AO)7
  • Five to seven years for records relating to lending and securities trading (WpHG, WpDVerOV, MiFID II)8,9
  • Five years for automated money laundering detection (GwG)10

4. Reporting of serious incidents. In the event of problems, such as a scoring model that systematically produces incorrect rejections, both the provider and the competent authority must be informed without delay.11

5. Fundamental Rights Impact Assessment (FRIA). The potential impact of the system on the rights of data subjects must be documented prior to its deployment, not afterwards. For banks and insurance companies, this is expressly required in the context of creditworthiness checks and risk assessments for life and health insurance.12

6. Right to an explanation. If a credit application is rejected on the basis of an AI scoring model, the reasons for the rejection must be explained in such a way that the individual concerned can understand which factors led to the decision. Pure ‘black box’ models lacking transparency therefore pose a direct compliance risk.13

When institutions develop their own systems: the obligations of providers

If institutions develop an AI system themselves or have it developed under their own name, they are subject to the more comprehensive provider obligations set out in Articles 9–15. In this case, rather than merely monitoring its correct use, they must themselves ensure the system’s safety throughout its entire life cycle, from data quality to cyber security. Specifically, this encompasses continuous risk management, data governance with active bias detection, technical documentation, record-keeping obligations, transparency towards operators, human oversight as a design principle, as well as robustness and accuracy.14

Breaches are punishable by fines of up to 15 million euros or 3 per cent of global annual turnover, whichever is higher.15

The timetable has been postponed: the Digital Omnibus on AI

Originally, the obligations for high-risk AI systems, such as credit scoring, were due to come into force as early as 2 August 2026. Under the Digital Omnibus, this deadline has been postponed to 2 December 2027, representing a significant gain of 16 months.16,17 However, the bans in force since February 2025 and the general transparency obligations from August 2026 remain unchanged.20

However, this postponement will only become legally binding upon publication in the Official Journal; as things stand, this has yet to take place but must occur by 30 July 2026 at the latest, so that the new deadline takes effect in good time before 2 August 2026.19

What banks should be doing now

The extended deadline is not a licence to sit back and wait, but an important window of opportunity for targeted implementation. Three areas of action are crucial:

  1. Compiling an inventory: A comprehensive list of all AI systems in use – including third-party tools and ‘shadow AI’ – with risk classification is a prerequisite for any further planning.
  2. Leverage governance synergies: Some of the documentation and risk management obligations overlap with existing requirements under DORA and the GDPR; duplication of effort can be avoided here.
  3. Make active use of the time window instead of waiting: Those who use these extra months now for pilot projects and test runs will gain a structural head start and enter the mandatory phase with robust, tried-and-tested processes, rather than resorting to last-minute compliance under time pressure.

Conclusion: Make the most of the time you save, don’t just manage it

The EU AI Act makes credit scoring and related applications one of the most prominent high-risk use cases in the entire regulation. With the Digital Omnibus, the mandatory start date is expected to be postponed to December 2027, subject to its forthcoming publication in the Official Journal.

Those who use this time now for stock-taking, governance and pilot projects will turn a regulatory obligation into a structural advantage.

Quellen
  1. 1European Commission (2024–2026): AI Act Service Desk – Annex III.
  2. 2European Parliament and Council of the European Union: Regulation (EU) 2024/1689, Annex III, point 5(b).
  3. 3TÜV Rheinland Consulting GmbH (Ribbrock, C., 2026, 23 April 2026): High-risk AI as defined in Annex III.
  4. 4German Banking Association / Federal Association of German Banks e. V. (2025, 7 July 2025): Position paper on a legal framework conducive to AI.
  5. 5Section 26 of the AI Act – Operators’ obligations.
  6. 6Section 14 of the AI Act – Human oversight.
  7. 7Lake Constance-Upper Swabia Chamber of Industry and Commerce: Retention periods in accordance with commercial law provisions (Section 257 of the German Commercial Code (HGB); Section 147 of the German Fiscal Code (AO)).
  8. 8Section 83(8) of the Securities Trading Act (WpHG) in conjunction with Section 9(4) of the Securities Services, Conduct and Organisation Regulation (WpDVerOV); Article 16(7) of MiFID II.
  9. 9Regulation specifying the rules of conduct and organisational requirements for investment firms (Investment Services Conduct and Organisation Regulation – WpDVerOV) Section 9: Record-keeping and retention obligations
  10. 10Section 8(4) of the Money Laundering Act (GwG).
  11. 11Section 73 of the AI Act – Reporting of serious incidents.
  12. 12Section 27 of the AI Act – Impact assessment on fundamental rights.
  13. 13Section 86 of the AI Act – Right to an explanation of the decision-making process in individual cases.
  14. 14Sections 9–15 of the AI Act – Obligations of providers (Part 2).
  15. 15Section 99 of the AI Act – Penalties/Fines.
  16. 16Heuking, Kühn, Lüer, Wojtek (2026): AI Omnibus 2026: Trilogue agreement on amendments to the AI Act brings longer deadlines and less red tape.
  17. 17European Parliament, press release (16 June 2026): AI Act: EP approves simplification measures and ban on ‘nudifier’ apps.
  18. 18Binder, Grösswang Solicitors (2026): Digital Omnibus Regulation on AI.
  19. 19Müller-Peltzer, P., SRD Solicitors (2026, 30 June 2026): Digital Omnibus AI: What changes will the AI Regulation bring?
  20. 20Ernst, M. (2026, 3 July 2026): The AI Regulation and the Digital Omnibus on AI: Amendments to Regulation (EU) 2024/1689 and remaining obligations from August 2026.
WORDPRESS_URL: https://admin.banking.vision/wp-json