EU AI Act
What does the EU AI Act require of banks and insurers using AI?

Two financial uses of AI are high-risk under the EU AI Act: scoring the creditworthiness of individuals, and risk assessment and pricing in life and health insurance. Deployers of both must run a fundamental rights impact assessment. Financial institutions get carve-outs that let them meet several duties through the governance rules they already follow, and their usual supervisor enforces. After the July 2026 amendment, the rules apply from 2 December 2027.
Quotations are from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the consolidated text of 27 July 2026 on 2 October 2026. This is not legal advice.
Which financial uses of AI are high-risk?
Annex III, point 5, covers access to essential private and public services. Two of its four entries reach financial services:
- Point 5(b): "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud".
- Point 5(c): "AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance".
Read the limits. Point 5(b) is about natural persons, so scoring companies is not in it, and fraud detection is carved out. Point 5(c) names life and health insurance only. Article 6(3) can take a listed system out of high-risk status where it poses no significant risk of harm and meets one of four narrow conditions, but never where it profiles people, and credit scoring typically involves profiling. Our guide to Annex III and the Article 6(3) test walks through it.
When do these rules apply?
From 2 December 2027. Before the July 2026 amendment, the Annex III rules would have applied from 2 August 2026; Regulation (EU) 2026/1744 moved Chapter III, Sections 1 to 3, to 2 December 2027 for Annex III systems. The AI literacy duty in Article 4 and the Article 5 prohibitions already apply. Our guide to the Digital Omnibus changes has the rest.
Do lenders and insurers need a fundamental rights impact assessment?
Yes, as deployers. Article 27(1) requires an assessment from public bodies and private entities providing public services, and also from "deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III". The assessment covers six things: the deployer's processes that use the system, the period and frequency of use, the categories of people affected, the specific risks of harm to them, the human oversight measures, and what the deployer will do if the risks materialize, including governance and complaint mechanisms. It applies to the first use, must be updated when things change, and its results are notified to the market surveillance authority on the AI Office's template. Since July 2026, Article 27(4) lets the assessment cross-refer to, or include parts of, the GDPR data protection impact assessment. Our guide to AI impact assessments compares the documents.
Training obligation register (AI Act and DORA)
Law,Article,Does it apply to us? (yes or no and why),Who must be trained,What the text requires (summary),Applies since,Our measure,Owner,Evidence kept (where),Review date,Notes EU AI Act (Regulation (EU) 2024/1689),Article 4 as amended by Regulation (EU) 2026/1744,,Staff and other persons dealing with AI systems on our behalf,Take measures to support the development of AI literacy; no specific level required,2 February 2025,,,,,The Commission's Q&A says no certificate is needed; keep an internal record. EU AI Act (Regulation (EU) 2024/1689),Article 26(2),,People assigned to human oversight of high-risk AI systems,"Necessary competence, training and authority, and support",2 December 2027 (Annex III) or 2 August 2028 (Annex I),,,,,Only for deployers of high-risk AI systems. NIS2 (Directive (EU) 2022/2555),Article 20(2),,Members of the management body; employees (encouraged),Management body members required to follow training; entities encouraged to offer similar training to employees regularly,National transposing law (Member States to apply measures from 18 October 2024),,,,,A directive: check your national law for the exact duty. DORA (Regulation (EU) 2022/2554),Article 13(6),,All employees and senior management staff; ICT third-party service providers where appropriate,ICT security awareness programs and digital operational resilience training as compulsory modules,17 January 2025,,,,,Article 5(2)(g): the management body allocates and reviews the budget for this training. GDPR (Regulation (EU) 2016/679),Article 39(1)(b),,Staff involved in processing operations,The DPO monitors compliance including awareness-raising and training of staff,25 May 2018,,,,,A task of the DPO; not a free-standing duty to train all staff. ,,,,,,,,,, "Read from the Official Journal texts on 2 October 2026. Template from credentialpress.com/guides/eu-laws-that-require-staff-training. Not legal advice.",,,,,,,,,,
What do financial institutions get that others do not?
Several duties can be met through the internal governance rules of Union financial services law:
| Provision | What it allows |
|---|---|
| Article 17(4) | A provider's quality management system is deemed in place by complying with financial governance rules, except the risk management system, post-market monitoring and serious incident reporting in Article 17(1)(g) to (i) |
| Articles 18(3) and 19(2) | Providers keep technical documentation and logs as part of the documentation required by financial services law |
| Article 26(5) and (6) | A deployer's monitoring duty is deemed fulfilled through financial governance rules, and logs are kept within that documentation |
| Article 72(4) | Providers can integrate AI post-market monitoring into existing systems and plans for Annex III, point 5 systems |
| Article 74(6) | The market surveillance authority is the national financial supervisor, for AI used in direct connection with the financial services |
These relieve paperwork, not substance. The risk management system, human oversight, data governance, accuracy and transparency requirements still apply in full to a high-risk system, and the deployer still owes the impact assessment and human oversight under Article 26(2).
Who is the provider: the bank or the vendor?
A lender that builds its own scoring model and uses it is both provider and deployer. A lender that buys a scoring system is the deployer, and the vendor is the provider, unless the lender puts its own name on the system or substantially modifies it, which can make it a provider under Article 25. Since July 2026, Article 25(2) also lists what an original provider must give a new one: technical documentation, known limitations and failure modes, and targeted technical access. Our guide to provider and deployer roles covers the tests.
How does this fit with DORA?
DORA has applied since 17 January 2025, and its Article 13(6) makes ICT security awareness and digital operational resilience training compulsory for all employees and senior management. Under the AI Act, staff who oversee a high-risk system need "the necessary competence, training and authority" (Article 26(2)), and everyone using AI needs AI literacy measures under Article 4. One training register can track all three; our guide to EU laws that require training quotes each.
What should a risk team do before December 2027?
Inventory every model that scores individuals for credit or prices life and health cover, and record which are AI systems in the Act's sense; for each, name the provider and the deployer; draft the fundamental rights impact assessment from the provider's Article 13 information; map the governance carve-outs above to your existing policies; and brief the people who will exercise human oversight. For the risk professionals who run this work, the FRM Part I study guide covers the quantitative risk side, and the AI Governance Framework handbook the AI Act itself, written to the 2024 text.
What should you do this week?
List your credit scoring and life and health pricing models, and flag the ones that use AI. Credential Press is independent of the EU institutions and every regulator named here.
Frequently asked questions
Is AI credit scoring high-risk under the EU AI Act?
Yes. Annex III, point 5(b) lists AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used to detect financial fraud. Scoring of companies is not in that point.
Is AI in insurance high-risk under the EU AI Act?
For life and health insurance, yes. Annex III, point 5(c) lists AI systems intended for risk assessment and pricing in relation to natural persons in life and health insurance. Other lines, such as motor or property, are not named in that point.
When do the AI Act's rules for credit scoring apply?
From 2 December 2027. Regulation (EU) 2026/1744 moved the high-risk rules for Annex III systems to that date in July 2026.
Do banks need a fundamental rights impact assessment?
Deployers of credit scoring and life and health insurance pricing systems do, under Article 27(1), even as private firms. It covers the processes, the period and frequency of use, the people affected, the risks, human oversight and the response if risks materialize, and the results are notified to the market surveillance authority.
Who supervises AI used by banks under the AI Act?
Article 74(6) makes the national authority responsible for the financial supervision of the institution the market surveillance authority, so far as the AI system is used in direct connection with the financial services provided.
Does DORA overlap with the AI Act?
On training and governance, yes. DORA Article 13(6) makes ICT security awareness and digital operational resilience training compulsory for all staff, and the AI Act lets financial institutions meet some AI governance duties through their existing financial services governance rules.
EU AI Act: test yourself in five minutes
Which books help risk and governance teams?

Building one that survives the EU AI Act. 22 chapters, 384 pages.

Sources
Every quotation above was read on 2 October 2026 through the EU Publications Office.
- Regulation (EU) 2024/1689 (AI Act), Articles 4, 6, 17, 18, 19, 25, 26, 27, 72, 74 and Annex III
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- Regulation (EU) 2024/1689, consolidated text dated 27 July 2026 (no legal effect)
- Regulation (EU) 2022/2554 (DORA), Article 13
Credential Press is independent of the European Commission, GARP and every supervisor. This is not legal advice.