The EU AI Act and financial services AI vendors
The high risk compliance date moved. On 27 July 2026, six days before the original deadline, Regulation (EU) 2026/1744 entered into force and pushed the core high risk obligations for standalone Annex III systems from 2 August 2026 to 2 December 2027. A large amount of guidance written for banks, insurers and fintechs still carries the old date, and a good deal of it also misstates which financial use cases the Act names at all. This page sets out both, and then what the vendors serving those use cases actually document today.
Reviewed 2026-08-21. Vendor figures generated 2026-08-24 from 490 indexed vendors and 7,350 capability assessments. No vendor pays to appear in this index. This page records dates and scope and is not legal advice.
-
Applies now2 February 2025
Prohibited practices
All providers and deployersThe Article 5 bans have applied since this date and were never in scope of the deferral. The Digital Omnibus added further prohibited practices when it entered into force on 27 July 2026.
-
Applies now2 February 2025
AI literacy duty
All providers and deployersArticle 4 places a direct duty on providers and deployers to support AI literacy among staff dealing with the systems, taking account of their knowledge, experience and the context of use. The wording of the duty was amended on 27 July 2026. The duty itself did not move.
-
Applies now2 August 2025
General purpose AI provider obligations
Foundation model providersObligations on providers of general purpose AI models have applied since this date. They were not deferred. An institution building on a foundation model is generally a deployer here rather than a provider, but the model provider obligations are what its own documentation package ultimately rests on.
-
Applies now2 August 2026
Transparency and AI content disclosure
Customer facing and generative systemsArticle 50 duties apply from this date to systems placed on the market from this date. This is the obligation that reaches a customer facing assistant: a person interacting with an AI system has to be told, and synthetic content has to be disclosed. It applies regardless of whether the system is high risk, which is why the deferral does not help here.
-
Applies from2 December 2026Next live date
Machine readable marking of AI generated content
Generative systems already on the marketA four month transitional period added by the Digital Omnibus for generative systems that were already on the market before 2 August 2026. Those systems have until this date to implement machine readable marking of the content they produce. This is the next date in the table that has not already passed, and it is the one most likely to be missed because it arrived as a concession rather than as a headline.
-
Applies from2 December 2027
High risk obligations, standalone Annex III systems
Credit scoring, insurance pricing and other Annex III usesThe Chapter III obligations that attach to Annex III classification: risk management, data governance, technical documentation, record keeping, transparency to deployers, human oversight, accuracy and robustness. Deferred from 2 August 2026 by Regulation (EU) 2026/1744. The deferral is unconditional and is enacted law rather than a proposal.
-
Applies from2 August 2028
High risk obligations, AI embedded in regulated products
Annex I product integrated systemsWhere the AI system is a safety component of a product already regulated under the Annex I sectoral legislation, the same obligations apply from this later date. Rarely the relevant branch for a financial services buyer, listed so the table is complete.
-
Applies from2 August 2030
High risk systems supplied to public authorities
Public sector deploymentsAn extended deadline applies to high risk systems intended for use by public authorities. Relevant to vendors selling into public sector financial functions rather than to a commercial bank buyer.
Source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal of the European Union on 24 July 2026 and in force from 27 July 2026. This table records dates and scope. It is not legal advice, and a classification decision on a specific system should be taken with counsel.
The next deadline in this market is not a high risk deadline
Most of the attention went to the date that moved. The date that matters sooner is one the Digital Omnibus created: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to implement machine readable marking of the content they produce. Article 50 transparency duties have applied to new systems since 2 August 2026 and were never deferred, because they attach to a customer interacting with an AI system rather than to a risk tier.
That is the obligation reaching the largest customer facing surface in this index. The customer and banking agents lane holds 112 vendors, and 74 of them document an autonomy and oversight model in public. An institution running an assistant that went live before August 2026 has roughly fifteen weeks from the date of this page, not sixteen months.
What Annex III names, and what it does not
Classification follows the intended purpose of a system, not the sector a vendor sells into and not the product category on a website. A single platform can hold one model that is high risk and another that is not. These four readings are where guidance aimed at financial services most often goes wrong, and the error usually runs toward over scoping rather than under scoping.
Creditworthiness and credit scoring of natural persons
Annex III point 5(b) covers AI systems intended to evaluate the creditworthiness of natural persons or to establish their credit score. The test is intended purpose rather than product label: a score, a decision engine, an affordability check and a risk rating are all the same thing if the system is intended to assess whether a person is creditworthy. Business lending is not named, but it can be reached where the owner is personally assessed.
Risk assessment and pricing in life and health insurance
Annex III point 5(c) covers AI systems used for risk assessment and pricing in relation to natural persons in life and health insurance. It does not name property, casualty or commercial lines, and it does not name claims handling. An insurance vendor is in scope for what its system decides, not for the sector it sells into.
Fraud detection
Point 5(b) carries an explicit exception for AI systems used to detect financial fraud. This is the single most misreported point in the published guidance aimed at this market, and the error runs in the direction of over scoping. The carve out is narrow: a model that also feeds a creditworthiness decision, or that profiles individuals in a way that reaches another Annex III point, comes back into scope. Classify by intended purpose, system by system.
Anti money laundering transaction monitoring
AML monitoring is not named in Annex III. It is governed by the anti money laundering regime and by sector supervisors, and national competent authorities retain primary competence over financial institutions. That does not make an AML model unregulated. It makes the AI Act the wrong instrument to read first, and it means the December 2027 date is not the relevant clock for it.
The two lanes the Act names are twelve points apart on the obligation it imposes
Annex III names two financial use cases, and the Chapter III obligations that follow include data governance and bias testing under Article 10 and, for deployers of credit scoring systems, a fundamental rights impact assessment under Article 27. The closest public measure of readiness for that work is whether a vendor documents its governance and bias testing at all.
Same obligation, same new date, 12 points apart. Credit decisioning is the highest documenting lane in this index on that axis, which is roughly what decades of fair lending supervision look like in a public record. Insurance, named just as plainly by point 5(c), sits at 12 percent. The deferral gives both until December 2027, and the lane that needs the time most is the one that has it.
Human oversight under Article 14 is the better prepared side of the picture and it is worth saying so: 99 of 136 credit decisioning vendors and 64 of 81 insurance vendors document an autonomy and oversight model. The gap in this market is evidence of testing, not the presence of a human.
What these shares measure and what they do not. A low share means the public record is thin, not that a control is absent, and a lane is a proxy for scope rather than a scope determination. Annex III point 5(c) reaches life and health pricing specifically, not every product an insurance vendor sells. Classify the system, not the lane.
Four things that land on the institution rather than the vendor
A deployer cannot buy its way out of the obligation
The Act separates providers, who develop a system, from deployers, who use one. Both carry duties. An institution that buys a high risk system still owes human oversight, monitoring, log retention and the use of the system in line with the instructions it was given, and it needs technical documentation from the vendor good enough to make that possible. If the vendor cannot supply it, the gap lands on the buyer.
Fine tuning a bought model can make you its provider
Substantially modifying a high risk system, including training a purchased scoring model on your own book, can move an institution from deployer to provider under Article 25 and bring the conformity assessment obligations with it. Teams tend to discover this after the model is in production. It is worth settling before the pilot, in writing.
A fundamental rights impact assessment is not optional for credit
Article 27 requires deployers of Annex III credit scoring systems to carry out a fundamental rights impact assessment. It overlaps with a data protection impact assessment without being satisfied by one, and it is the deployer obligation most often missing from a vendor supplied compliance pack, because it is not the vendor obligation.
There is still no harmonised standard to build against
No harmonised technical standard has yet been cited in the Official Journal, so nothing currently confers a presumption of conformity. That absence is a large part of why the date moved. The practical consequence is that the extra time is for building an evidence file rather than for waiting on a certification route that does not exist yet.
The EU AI Act high risk compliance date for standalone Annex III systems moved from 2 August 2026 to 2 December 2027 under Regulation (EU) 2026/1744, in force 27 July 2026. Article 5 prohibitions, general purpose AI obligations, the Article 4 AI literacy duty and Article 50 transparency did not move, and generative systems already on the market have until 2 December 2026 to implement machine readable content marking. In financial services Annex III names two use cases: creditworthiness assessment of natural persons, with fraud detection expressly excepted, and risk assessment and pricing in life and health insurance. Across 490 AI vendors indexed by the AI FinTech Index, the two lanes serving those use cases document governance and bias testing at 24 percent and 12 percent respectively.
Source: AI FinTech Index, August 2026
Common questions
Did the EU AI Act high risk deadline get delayed?
Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original date. The core high risk obligations for standalone Annex III systems moved from 2 August 2026 to 2 December 2027, and high risk AI embedded in products regulated under Annex I moved to 2 August 2028. The deferral is unconditional and is enacted law rather than a proposal, so guidance still citing 2 August 2026 as the high risk date is out of date. Several obligations did not move at all, including the Article 5 prohibitions, the general purpose AI provider obligations, the Article 4 AI literacy duty and the Article 50 transparency duties.
Is fraud detection AI high risk under the EU AI Act?
Not by itself. Annex III point 5(b) covers AI intended to evaluate the creditworthiness of natural persons and carries an explicit exception for AI systems used to detect financial fraud. A great deal of published guidance aimed at fraud and financial crime teams states the opposite. The carve out is narrow rather than absolute: if the same system also feeds a creditworthiness decision, or profiles individuals in a way that reaches another Annex III point, it is back in scope, and a system that functionally denies access to a financial service raises the question again on different grounds. Classify by intended purpose, one system at a time, and do not classify a platform as a whole.
Is AML transaction monitoring high risk under the EU AI Act?
AML transaction monitoring is not named in Annex III. It sits under the anti money laundering regime and its own supervisors, and national competent authorities retain primary competence over financial institutions. The practical consequence for a buyer is that the December 2027 date is not the clock for an AML system, and that a vendor marketing an AML product primarily on AI Act readiness is answering a question the Act did not ask. The obligations that do reach it are sector obligations, which have not moved.
What are the EU AI Act requirements for AI vendors in financial services?
It depends on what the system decides rather than on what kind of firm sells it. Two financial use cases are named as high risk in Annex III: creditworthiness evaluation and credit scoring of natural persons, and risk assessment and pricing for natural persons in life and health insurance. Those carry the Chapter III obligations from 2 December 2027. Separately and regardless of risk tier, any system a customer interacts with owes Article 50 transparency, which has applied since 2 August 2026, and generative systems already on the market before that date have until 2 December 2026 to implement machine readable marking of AI generated content. A vendor selling only internal drafting tools into a bank may owe nothing beyond the AI literacy duty.
Should financial institutions stop preparing now that the date has moved?
The deferral moved a date, not an obligation, and there is a specific reason not to treat it as relief. No harmonised technical standard has yet been cited in the Official Journal, so there is currently no route to a presumption of conformity and nothing to certify against. The extra time is for assembling an evidence file, mapping which systems fall under points 5(b) and 5(c), settling provider and deployer roles in contracts, and getting the fundamental rights impact assessment work started. Institutions that read the delay as cancellation will be starting from nothing in late 2027.
What is the next EU AI Act deadline for financial services?
2 December 2026, and it is not a high risk deadline. Generative AI systems that were already on the market before 2 August 2026 have until that date to implement machine readable marking of the content they produce, under a transitional period added by the Digital Omnibus. For a bank or insurer running a customer facing assistant that went live before August 2026, that is roughly fifteen weeks of engineering time from the date this page was published, and it arrives more than a year before the high risk obligations do.