EU AI Act for financial services
Point 5(b) makes creditworthiness assessment high-risk and the fraud carve-out is drafted around purpose, not features. But financial services also gets the single most useful simplification in the Regulation: Article 17(4) deems institutions subject to Union financial services internal governance requirements to satisfy the quality management obligation.
What is in scope, and what is not
| Detail | |
|---|---|
| In scope — point 5(b) | Credit scoring, affordability assessment, automated and semi-automated underwriting, limit setting where it evaluates creditworthiness |
| Excluded from 5(b) | AI systems used for the purpose of detecting financial fraud |
| Elsewhere in the Act | Customer-facing chatbots and generative features — Article 50, live now. Robo-advice and pricing outside credit, assess separately; not named in point 5 |
Expert analysis. Classification turns on the intended purpose of each system. This is our reading of common deployments, not an authoritative classification.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The fraud carve-out is about purpose, not features
Point 5(b) excludes AI used for the purpose of detecting financial fraud. That exclusion is doing far more work in the market than the drafting supports.
A system whose purpose is fraud detection is outside. A creditworthiness model that happens to carry fraud-related features is still a creditworthiness model, and calling it a fraud engine does not bring it within the exclusion. The intended purpose you document and register is what will be read.
The related argument, that the model only produces a score and a human underwriter decides, also fails. Point 5(b) is drafted around the activity of evaluating creditworthiness or establishing a credit score. Producing the score is the activity. And the Article 6(3) threshold gate asks whether the system materially influences the outcome of decision-making, which a score an underwriter is expected to follow plainly does. Point 5 in detail →
Two simplifications and one addition
- Article 17(4) is a genuine simplification. Financial institutions subject to requirements regarding internal governance, arrangements or processes under Union financial services law are deemed to fulfil the Article 17 quality management system obligation, with certain exceptions. Check whether it applies to you before building a parallel QMS.
- Existing model risk governance transfers substantially. Institutions already running model validation and model risk management have much of the Article 9 and Article 15 evidence base, though it is oriented to risk to the institution rather than risk to people.
- DORA sits alongside, not underneath. Digital operational resilience obligations and their incident reporting are separate from Article 73, with different triggers and deadlines. Map them; do not assume one discharges the other.
- Consumer and mortgage credit rules continue to apply to the assessment itself. AI Act conformity is not a defence to a creditworthiness assessment that breaches sectoral requirements.
What applies before December 2027
Article 50 applies now to customer-facing chatbots and any generative feature. Article 4 literacy applies across the institution.
The deferral in Regulation (EU) 2026/1744 covers Chapter III Sections 1 to 3. It does not cover Article 5, Article 4, Chapter V general-purpose AI, Article 49 registration or Article 50 transparency. Full timeline →
Status labels on this page
Verified fact: The Annex III points, article references and dates cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The in-scope/out-of-scope allocation, the sector edge case, and the parallel-regulation reading.
Unsettled: Harmonised standards remain in development and the Commission's Annex III guidelines are in draft. Sector supervisory practice has not yet formed.
Check Article 17(4) before you build a second QMS
If the deeming rule applies to your institution, the largest single piece of Chapter III work may already be done. That is worth twenty minutes with counsel before a programme is scoped.
Classify before you build
Twelve questions mapping your system against Articles 5, 6, 50 and Annex III. No email required.
Frequently asked
Is credit scoring high-risk under the EU AI Act?
Yes. Annex III point 5(b) covers AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud. A system producing a score for a human underwriter remains within the point, because the point is drafted around the activity rather than around who makes the final decision.
Do banks have to build a separate quality management system?
Possibly not. Article 17(4) provides that providers that are financial institutions subject to requirements regarding internal governance, arrangements or processes under Union financial services law are deemed to fulfil the Article 17 quality management system obligation, with certain exceptions. Whether it applies depends on the institution and should be confirmed with counsel.
How does the EU AI Act interact with DORA?
They are separate instruments with different objects. DORA governs digital operational resilience for financial entities including ICT risk management and incident reporting; the AI Act governs AI systems as products. Both can apply to the same system, and their incident reporting obligations have different triggers, deadlines and recipients.