# How does the EU AI Act regulate AI in banking?

Source: https://www.bankingnewsai.com/ai-regulation/eu-ai-act
Last updated: Oct 5, 2026

The EU AI Act (Regulation (EU) 2024/1689) is the only binding, cross-sector AI law that directly regulates banks. Credit scoring of natural persons is explicitly listed as high-risk (Annex III, point 5(b)), which will require risk management, data governance, technical documentation, logging, human oversight, and post-market monitoring. Those high-risk obligations were due to apply on August 2, 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) deferred stand-alone Annex III systems to December 2, 2027 and product-embedded (Annex I) systems to August 2, 2028. Penalties for non-compliance with high-risk obligations reach €15 million or 3% of global annual turnover.

## At a glance

| Field | Value |
| --- | --- |
| Full name | Regulation (EU) 2024/1689 — the EU Artificial Intelligence Act |
| Jurisdiction | European Union |
| Role | Binding horizontal AI law |
| How binding | Binding law |
| Applies to | Any bank, lender, or fintech that develops or uses AI systems in the EU — including non-EU firms whose AI outputs are used in the EU |
| Key document | Regulation (EU) 2024/1689 (in force Aug 1, 2024), as amended by the Digital Omnibus on AI (EU) 2026/1744 |
| Latest move | Regulation (EU) 2026/1744 (Digital Omnibus on AI) entered into force July 27, 2026, deferring Annex III high-risk obligations — including credit scoring — from Aug 2, 2026 to Dec 2, 2027 |

## Overview

The AI Act entered into force on August 1, 2024 and applies in stages. Prohibited practices (such as social scoring) and AI-literacy duties took effect February 2, 2025; obligations for general-purpose AI models followed on August 2, 2025; and Article 50 transparency duties applied from August 2, 2026. The core high-risk regime — the part that matters most to banks — was originally due on August 2, 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) deferred it: stand-alone Annex III systems must comply from December 2, 2027, and AI embedded in regulated products (Annex I) from August 2, 2028.

For banks the two headline classifications are credit scoring of natural persons (Annex III 5(b)) and risk assessment and pricing in life and health insurance (5(c)). The deferral buys time but does not change the substance: from December 2, 2027 these systems need risk management, data governance, technical documentation, logging, human oversight, accuracy and post-market monitoring, and supervisors have signalled they expect remediation of legacy ML portfolios rather than indefinite grandfathering. The EBA published a factsheet on what the Act means for the banking and payments sector in November 2025 and is coordinating supervisory implementation across national authorities through 2026–27.

## What does the EU AI Act require of banks?

The EU AI Act reaches banks mainly as deployers of high-risk AI: a system that evaluates the creditworthiness of natural persons or sets their credit score is high-risk under Annex III point 5(b), as is life and health insurance pricing under 5(c), while AI used to detect financial fraud is expressly excluded. From December 2, 2027 (the date set by the Digital Omnibus, Regulation (EU) 2026/1744) a bank using such a system must use it according to the provider's instructions, assign trained human oversight, keep input data relevant and representative, monitor it, keep its logs for at least six months and run a fundamental-rights impact assessment before first use. A bank that builds its own credit model is also its provider and takes on the provider duties, but the Act lets banks meet the quality-management, monitoring and log-keeping duties through the internal-governance rules they already follow under EU financial services law, and makes the national financial supervisor the enforcement authority. Already in force: the Article 5 bans (since February 2, 2025, fines up to EUR 35 million or 7% of turnover), Article 50 chatbot disclosure (since August 2, 2026) and the duty to take measures supporting staff AI literacy; breaches of the high-risk rules carry fines up to EUR 15 million or 3%.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Annex III, point 5(b) | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high-risk, with the exception of AI systems used to detect financial fraud. | High-risk duties from Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Annex III, point 5(c) | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | AI used for risk assessment and pricing of natural persons in life and health insurance is high-risk — relevant to bancassurance. | High-risk duties from Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Article 26(1)–(5) — deployer duties | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Use the system according to its instructions, assign human oversight to people with the competence, training and authority to exercise it, keep input data you control relevant and sufficiently representative, and monitor operation; for financial institutions the monitoring duty is met by complying with internal-governance rules under financial services law. | From Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Article 26(6) — logs | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Keep the system's automatically generated logs for at least six months; financial institutions keep them as part of the documentation required by financial services law. | From Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Article 26(7) — workers | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Before using a high-risk system at the workplace, inform workers' representatives and affected workers. | From Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Article 27 — fundamental rights impact assessment | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Deployers of Annex III 5(b) and 5(c) systems — credit scoring and life/health insurance pricing — must assess the impact on fundamental rights before first deploying them. | From Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Articles 16–17 — if the bank builds the model | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | A bank that develops its own high-risk system is its provider and takes on provider obligations, including a quality management system; for financial institutions most of the QMS duty is deemed fulfilled by complying with internal-governance rules under financial services law. | From Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Article 74(6) — who supervises | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | For AI used by regulated financial institutions in direct connection with financial services, the market surveillance authority is the national authority responsible for their financial supervision. | In force | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Article 5 — prohibited practices | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Banned AI practices (such as social scoring) may not be used; breaches carry fines up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. | Since Feb 2, 2025 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Article 50(1) — chatbots | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | AI systems that interact directly with people must be designed so they are told they are interacting with an AI system, unless that is obvious; generated content must be machine-readably marked (systems already on the market before Aug 2, 2026 have until Dec 2, 2026). | Since Aug 2, 2026 | [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744) |
| Article 4 — AI literacy (as amended) | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Providers and deployers must take measures to support the AI literacy of their staff; since the Digital Omnibus the duty does not require guaranteeing any specific level of literacy. | Since Feb 2, 2025; amended Jul 27, 2026 | [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744) |
| Article 99(4) — fines for high-risk breaches | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Breaches of provider and deployer obligations (including Article 26) carry fines up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. | With the obligations | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |

The Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on July 24, 2026 and in force from July 27, moved the high-risk regime for stand-alone Annex III systems, including credit scoring, from August 2, 2026 to December 2, 2027, and for AI in products covered by Annex I to August 2, 2028. Nothing else in the list above moved except the AI-literacy wording and the marking grace period.

Many summaries still give August 2, 2026 as the credit-scoring deadline or attach the EUR 35 million / 7% ceiling to high-risk breaches; under Article 99 that ceiling applies to the Article 5 prohibitions, and high-risk obligations carry the EUR 15 million / 3% ceiling.

### What this means in practice

- Inventory every model that scores or prices natural persons and tag which are Annex III 5(b)/5(c) and which are fraud-detection (excluded).
- Decide, model by model, whether the bank is provider (built in-house) or deployer (bought), because the duties differ.
- Map the Article 26 and 27 duties onto existing model-risk and internal-governance processes, which the Act lets financial institutions reuse.
- Add chatbot disclosure checks now: Article 50 has applied since August 2, 2026.

## Documents (12)

- Jul 24, 2026 — [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744): Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (In force)
- Jul 20, 2026 — [Commission guidelines on AI Act Article 50 transparency](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-act-article-50-transparency-2026): Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act) (In force)
- May 19, 2026 — [Draft Commission guidelines on high-risk classification](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-draft-guidelines-high-risk-classification-2026): Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI Act (Proposed · comment period closed)
- Nov 21, 2025 — [EBA factsheet on the AI Act](https://www.bankingnewsai.com/ai-regulation/documents/eba-ai-act-factsheet-banking-payments-2025): AI Act: implications for the EU banking and payments sector (EBA factsheet) (Final)
- Jul 18, 2025 — [Commission GPAI model guidelines](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-gpai-obligations-2025): Commission Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act) (In force)
- Jul 10, 2025 — [General-Purpose AI Code of Practice](https://www.bankingnewsai.com/ai-regulation/documents/eu-gpai-code-of-practice-2025): General-Purpose AI Code of Practice under the AI Act (Transparency, Copyright, and Safety and Security chapters) (In force)
- Feb 6, 2025 — [Commission guidelines on the AI system definition](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-system-definition-2025): Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act) (In force)
- Feb 4, 2025 — [Commission guidelines on prohibited AI practices](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-prohibited-ai-practices-2025): Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act) (In force)
- Jul 12, 2024 — [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689): Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) (In force)
- Oct 30, 2023 — [Consumer Credit Directive (EU) 2023/2225](https://www.bankingnewsai.com/ai-regulation/documents/eu-consumer-credit-directive-2023-2225): Directive (EU) 2023/2225 on credit agreements for consumers (CCD2) — automated creditworthiness assessment provisions (Final · applies from Nov 20, 2026)
- Dec 27, 2022 — [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554): Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act, DORA) (In force)
- May 4, 2016 — [GDPR Article 22](https://www.bankingnewsai.com/ai-regulation/documents/eu-gdpr-article-22-automated-decision-making): Regulation (EU) 2016/679 (GDPR), Article 22 — Automated individual decision-making, including profiling (In force)

## Timeline

- Aug 2, 2028 — [Deferred deadline for high-risk AI embedded in regulated products](https://artificialintelligenceact.eu/implementation-timeline/) — Article 6(1) / Annex I high-risk systems tied to EU product-safety legislation now apply from this date (moved from August 2, 2027 by the Digital Omnibus on AI).
- Dec 2, 2027 — [High-risk AI obligations for stand-alone Annex III systems become applicable](https://artificialintelligenceact.eu/implementation-timeline/) — Deferred from August 2, 2026 by the Digital Omnibus on AI. Annex III high-risk systems — including credit scoring of natural persons — must comply with risk management, data governance, documentation, logging, human oversight, accuracy, and post-market monitoring requirements. Fines up to €15M / 3% of turnover.
- Aug 2, 2027 — [Commission GPAI model guidelines](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-gpai-obligations-2025): Deadline for general-purpose AI models placed on the market before August 2025 — Providers of general-purpose AI models placed on the market before 2 August 2025 must comply with the AI Act's GPAI obligations by this date.
- Dec 2, 2026 — [Commission guidelines on AI Act Article 50 transparency](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-act-article-50-transparency-2026): Article 50(2) marking transition ends — The Digital Omnibus transition period for Article 50(2) machine-readable marking of AI-generated content ends; the rest of Article 50 has applied since 2 August 2026.
- Aug 2, 2026 — [Article 50 transparency obligations apply; Annex III high-risk start deferred](https://artificialintelligenceact.eu/implementation-timeline/) — Transparency duties (e.g., telling customers they are interacting with an AI system, marking AI-generated content) apply from this date as originally scheduled. The Annex III high-risk regime — including credit scoring — did NOT start on this date: Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force July 27, 2026) deferred it to December 2, 2027.
- Jul 24, 2026 — [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744): Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) — Regulation (EU) 2026/1744, the Digital Omnibus on AI, was proposed by the European Commission on November 19, 2025, agreed by Parliament and Council in May 2026, adopted July 8, 2026, published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026.
- Jul 20, 2026 — [Commission guidelines on AI Act Article 50 transparency](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-act-article-50-transparency-2026): Commission guidelines on AI Act Article 50 transparency — Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act) — The European Commission adopted its Guidelines on the transparency obligations under Article 50 of the AI Act on 20 July 2026 (Communication C(2026) 5054), less than two weeks before Article 50 began to apply on 2 August 2026.
- Jun 10, 2026 — [Code of Practice on marking and labelling AI-generated content published](https://digital-strategy.ec.europa.eu/en/news/commission-publishes-code-practice-marking-and-labelling-ai-generated-content) — The Commission published the final Code of Practice on marking and labelling AI-generated content, the voluntary tool for meeting Article 50 transparency duties.
- May 19, 2026 — [Draft Commission guidelines on high-risk classification](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-draft-guidelines-high-risk-classification-2026): Draft Commission guidelines on high-risk classification — Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI Act — On May 19, 2026 the European Commission published draft guidelines on classifying high-risk AI systems under Article 6 of the AI Act, originally due by February 2, 2026.
- Nov 21, 2025 — [EBA factsheet on the AI Act](https://www.bankingnewsai.com/ai-regulation/documents/eba-ai-act-factsheet-banking-payments-2025): EBA factsheet on the AI Act — AI Act: implications for the EU banking and payments sector (EBA factsheet) — On November 21, 2025 the European Banking Authority published a factsheet mapping the AI Act onto EU banking and payments legislation.
- Nov 18, 2025 — [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554): ESAs designate the first critical ICT third-party providers under DORA — The EBA, EIOPA and ESMA published the first list of 19 critical ICT third-party providers subject to EU oversight under DORA, including major cloud providers that host banks' AI workloads.
- Aug 2, 2025 — [General-purpose AI (GPAI) obligations apply](https://artificialintelligenceact.eu/implementation-timeline/) — Transparency and documentation duties for GPAI model providers begin; relevant to banks consuming foundation models through vendors.
- Jul 18, 2025 — [Commission GPAI model guidelines](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-gpai-obligations-2025): Commission GPAI model guidelines — Commission Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act) — The European Commission published its Guidelines on the scope of the obligations for providers of general-purpose AI models on 18 July 2025 (Communication C(2025) 5045), two weeks before the GPAI obligations of Chapter V of the AI Act began to apply on 2 August 2025.
- Jul 10, 2025 — [General-Purpose AI Code of Practice](https://www.bankingnewsai.com/ai-regulation/documents/eu-gpai-code-of-practice-2025): General-Purpose AI Code of Practice — General-Purpose AI Code of Practice under the AI Act (Transparency, Copyright, and Safety and Security chapters) — The General-Purpose AI Code of Practice was published by the European Commission on July 10, 2025 as a voluntary tool for GPAI model providers to demonstrate compliance with Articles 53 and 55 of the AI Act, which applied from August 2, 2025.
- Feb 6, 2025 — [Commission guidelines on the AI system definition](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-system-definition-2025): Commission guidelines on the AI system definition — Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act) — The European Commission published its Guidelines on the definition of an artificial intelligence system on 6 February 2025, four days after the definition and the Article 5 prohibitions began to apply on 2 February 2025; the language versions were formally adopted on 29 July 2025 as C(2025) 5053.
- Feb 4, 2025 — [Commission guidelines on prohibited AI practices](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-prohibited-ai-practices-2025): Commission guidelines on prohibited AI practices — Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act) — On February 4, 2025 — two days after the Article 5 prohibitions began applying — the European Commission published non-binding guidelines interpreting the AI Act's prohibited practices, including harmful manipulation, exploitation of vulnerabilities, social scoring, individual crime prediction, untargeted facial-image scraping, emotion recognition in workplaces and real-time remote biometric identification.
- Feb 2, 2025 — [Prohibited practices and AI-literacy obligations apply](https://artificialintelligenceact.eu/implementation-timeline/) — Bans on unacceptable-risk AI (e.g., social scoring) take effect, along with the duty to ensure staff AI literacy — which applies to banks as deployers.
- Jul 12, 2024 — [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689): Regulation (EU) 2024/1689 — Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — Regulation (EU) 2024/1689, the EU AI Act, was published in the Official Journal on July 12, 2024 and entered into force on August 1, 2024.
- Oct 30, 2023 — [Consumer Credit Directive (EU) 2023/2225](https://www.bankingnewsai.com/ai-regulation/documents/eu-consumer-credit-directive-2023-2225): Consumer Credit Directive (EU) 2023/2225 — Directive (EU) 2023/2225 on credit agreements for consumers (CCD2) — automated creditworthiness assessment provisions — Directive (EU) 2023/2225, the recast Consumer Credit Directive, was published in the Official Journal on October 30, 2023; member states had to transpose it by November 20, 2025 and its rules apply from November 20, 2026.
- Dec 27, 2022 — [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554): DORA (Regulation (EU) 2022/2554) — Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act, DORA) — Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA), was adopted on 14 December 2022, published in the Official Journal on 27 December 2022 and has applied since 17 January 2025 (Article 64).
- May 4, 2016 — [GDPR Article 22](https://www.bankingnewsai.com/ai-regulation/documents/eu-gdpr-article-22-automated-decision-making): GDPR Article 22 — Regulation (EU) 2016/679 (GDPR), Article 22 — Automated individual decision-making, including profiling — Article 22 of the General Data Protection Regulation (Regulation (EU) 2016/679, applicable since May 25, 2018) gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects — with automated credit refusal the textbook example.

## What to watch next

- Final Commission guidelines on high-risk classification (Article 6), expected by end-2026 after the draft consultation closed July 23, 2026
- CEN-CENELEC harmonised standards for high-risk AI, now targeted for late 2026 at the earliest — the practical route to presumption of conformity before Dec 2, 2027
- EBA-coordinated supervisory convergence on how AI Act duties interact with existing model governance (CRD/CRR, EBA guidelines) through 2026–27
- Consumer Credit Directive 2023/2225 rules — including the right to human intervention in automated creditworthiness assessments — applying from November 20, 2026

## FAQ

### Is credit scoring high-risk under the EU AI Act?

Yes. AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are listed in Annex III, point 5(b), and are high-risk regardless of whether the AI makes the final decision or supports a human decision-maker. A narrow exception exists for systems used solely to detect financial fraud.

### When did the AI Act start applying to banks?

In stages: AI-literacy and prohibited-practice rules from February 2, 2025; general-purpose AI model obligations from August 2, 2025; Article 50 transparency duties from August 2, 2026. The high-risk regime that covers credit scoring was deferred by the July 2026 Digital Omnibus and now applies from December 2, 2027 (stand-alone Annex III systems) and August 2, 2028 (AI embedded in regulated products).

### What are the penalties for banks under the AI Act?

Non-compliance with high-risk system obligations carries administrative fines of up to €15 million or 3% of global annual turnover, whichever is higher. Prohibited-practice violations carry up to €35 million or 7%.

### Do credit-scoring models deployed before December 2027 have to comply?

The Act's grandfathering only reaches high-risk systems placed on the market before the application date that are not subsequently significantly modified — and supervisors have made clear they expect legacy ML credit models to be brought into compliance rather than left untouched. With the deadline now December 2, 2027, banks should treat existing credit-scoring models as in scope and use the extra time for remediation, not exemption.

### Did the Digital Omnibus delay the EU AI Act high-risk deadline for credit scoring?

Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026. It moved the application date for stand-alone Annex III high-risk systems — the category that includes credit scoring of natural persons — from August 2, 2026 to December 2, 2027, and for AI embedded in regulated products (Annex I) from August 2, 2027 to August 2, 2028. Article 50 transparency obligations still applied from August 2, 2026.

## Compare

- [EU AI Act vs Colorado AI Act](https://www.bankingnewsai.com/ai-regulation/compare/eu-ai-act-vs-colorado-ai-act): EU AI Act vs Colorado AI Act: AI in Credit Decisions

Related authorities: [EBA](https://www.bankingnewsai.com/ai-regulation/eba), [ECB](https://www.bankingnewsai.com/ai-regulation/ecb), [FSB](https://www.bankingnewsai.com/ai-regulation/fsb).

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/eu-ai-act
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
