On November 21, 2025 EBA Chair José Manuel Campa wrote to the Commission's DG FISMA and DG CNECT (EBA/2025/D/5384) with the outcome of the EBA's AI Act mapping exercise. The letter's annex lists, obligation by obligation, the EU banking and payments provisions that already address AI Act high-risk requirements for credit scoring — noting that DORA extensively covers the Act's cybersecurity and business-continuity requirements and that CRR/CRD already provide a technology-neutral governance and risk-management framework — and offers it as input to the Commission's Article 96(1)(e) guidelines on the interplay between the AI Act and sectoral law.
| Document | EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384) — Outcome of EBA's AI Act mapping exercise — letter to DG FISMA and DG CNECT |
| Issued by | European Banking Authority |
| Type | Letter |
| Status | Final |
| Published | Nov 21, 2025 |
| Applies to | European Commission (DG FISMA, DG CNECT and the AI Office) as input to guidelines on the interplay between the AI Act and EU sectoral law; indirectly EU credit and payment institutions |
| Official source | eba.europa.eu ↗ |
| Use cases | Credit scoring & underwriting · AI governance (general) · Cybersecurity · Model risk management |
What are the key points of EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384)?
- Dated November 21, 2025; reference EBA/2025/D/5384; addressed to John Berrigan (DG FISMA) and Roberto Viola (DG CNECT), copied to the AI Office.
- Mapping workstream launched January 2025, focused on creditworthiness assessment and credit scoring of natural persons (Annex III(5)(b)).
- Points out that the AI Act provides derogations or synergies for some high-risk obligations but not others (human oversight, data governance, cybersecurity) where financial-services law already has extensive requirements.
- DORA cited as extensively covering the AI Act's cybersecurity and business-continuity requirements; CRR/CRD as the governance and risk-management base.
- Annex maps AI Act obligations to CRR, CRD, the IRB assessment-methodology RTS (2022/439), EBA internal-governance, PD/LGD and loan-origination guidelines, DORA and its RTS (2024/1772, 2024/1774), and CCD2.
- Intended to inform Commission guidelines under Article 96(1)(e) and to facilitate management of overlaps.
What did EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384) change for banks?
This letter is the detailed evidence behind the factsheet's 'no contradictions' conclusion. Its annex is the closest thing banks have to an official crosswalk from each AI Act high-risk obligation to the CRD/CRR, DORA and EBA-guideline provisions that already cover it — useful for building the compliance mapping supervisors will expect, and a marker of what the Commission's interplay guidelines are likely to say.
Does DORA cover AI Act cybersecurity requirements for banks?
The EBA's November 2025 letter to the Commission states that the DORA framework extensively covers the cybersecurity and business-continuity requirements set out in the AI Act for high-risk systems, and that CRR/CRD supply the governance and risk-management framework.
Where is the EBA's mapping of AI Act obligations to banking rules?
In the annex to EBA Chair letter EBA/2025/D/5384 of November 21, 2025, which lists the sectoral provisions relevant to each AI Act high-risk requirement, published alongside the EBA's AI Act factsheet.
| Date | Document | Status |
|---|---|---|
| Jul 31, 2026 | ESA Statement on ICT risks from frontier AI models (JC 2026 25) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models | In force |
| Nov 21, 2025 | EBA factsheet: AI Act implications for the EU banking and payments sector — AI Act: implications for the EU banking and payments sector | Final |
| Oct 1, 2025 | EBA Work Programme 2026 — EBA Work Programme 2026 — AI Act implementation and digital-finance priorities | In force |
| Sep 25, 2025 | EBA report: Rising application of AI in EU banking and payments (Sep 2025) — Rising application of AI in EU banking and payments sector | Final |
| Aug 4, 2023 | EBA follow-up report on machine learning for IRB models (EBA/REP/2023/28) — Machine Learning for IRB Models — Follow-up report from the consultation on the Discussion paper on machine learning for IRB models | Final |
| Nov 11, 2021 | EBA discussion paper on machine learning for IRB models — Discussion Paper on machine learning for IRB models | Superseded |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →