The EU AI Act for fintech: credit scoring and creditworthiness AI
Few sectors touch the EU AI Act's high-risk tier as directly as financial services. The moment AI decides whether someone gets a loan — or what they pay for insurance — it lands in one of Annex III's named categories. Here is what fintechs, lenders, and insurers actually need to know.
This is an information service to help you orient, not legal advice. For the obligations tied to your own AI use, see which apply to your company.
Credit scoring is high-risk — fraud detection is not
Annex III lists AI used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk. That captures the core of consumer and SME lending: application scoring, affordability and default-risk models, automated lending decisions.
But the same entry contains a deliberate carve-out: AI used to detect financial fraud is not high-risk on that basis. The distinction is functional — deciding whether to lend to a person is high-risk; catching a fraudulent transaction is not. If you run both (many fintechs do), you have to classify each system on its own.
A second financial category is high-risk too: risk assessment and pricing in life and health insurance for individuals. Underwriting and pricing models there sit in the same tier.
Who carries the obligations
If you build the model (provider) — a scoring engine, a decisioning platform — you carry the full stack: risk management, data governance (critical here, because biased training data becomes discriminatory lending), technical documentation, logging, human oversight, accuracy and robustness, a quality-management system, a conformity assessment, and EU-database registration.
If you're the lender or insurer deploying it (deployer) — even using a third-party model — you have real duties (Article 26): use it per the provider's instructions, ensure competent human oversight of automated decisions, monitor and log, and, for many financial institutions, complete a fundamental-rights impact assessment (Article 27) before you put it into use.
One easement worth knowing: where you are already subject to internal-governance and risk-management requirements under EU financial-services law, the Act lets you meet some of its quality-management duties through those existing arrangements rather than duplicating them. Don't assume it covers everything — but it reduces overlap.
The deadline moved — plan around 2 December 2027
The high-risk obligations for Annex III use cases, credit scoring included, were deferred by the Digital Omnibus from 2 August 2026 to 2 December 2027 (Regulation (EU) 2026/1744, in force since 27 July 2026). See what the Digital Omnibus changed.
Two things don't wait: AI literacy (Article 4) already applies to your staff, and if you run a customer-facing chatbot, the Article 50 transparency duty lands on its own timeline.
What to do next
- Split scoring from fraud. Classify each model separately — one is high-risk, the other likely isn't.
- Fix data governance first. In lending, biased or unrepresentative training data is both a compliance failure and a discrimination risk.
- If you deploy a bought-in model, start the deployer basics — human oversight of decisions, monitoring, and the fundamental-rights impact assessment take time to stand up.
The fastest way to get your own dated list: answer three questions about your AI use and we'll show the verified obligations that match, sorted by deadline. Because these dates move, join the waitlist to be told the moment something that affects you changes.
The official text is Regulation (EU) 2024/1689. This article is an information service to help you orient — it is not legal advice.
Frequently asked questions
Is credit-scoring AI high-risk under the EU AI Act?
Yes. AI used to evaluate the creditworthiness of individuals or to establish their credit score is listed in Annex III as a high-risk use case — with one explicit exception: AI used to detect financial fraud is not high-risk on that basis. So a scoring or lending-decision model is high-risk; a fraud-detection model is not.
Does the EU AI Act apply to a bank that uses a third-party scoring model?
Yes. The bank or lender is the 'deployer'. Deployers have their own obligations — using the system per the provider's instructions, ensuring human oversight, monitoring it, keeping logs, and (for many financial institutions) carrying out a fundamental-rights impact assessment before first use.
When do the EU AI Act rules for credit-scoring AI apply?
Creditworthiness AI is an Annex III high-risk use case, and those obligations were deferred by the Digital Omnibus from 2 August 2026 to 2 December 2027. Confirm the current date against the Official Journal. Duties like AI literacy already apply.
Is fraud-detection AI high-risk under the EU AI Act?
No, not on the creditworthiness basis. Annex III expressly carves out AI used for the purpose of detecting financial fraud, so a fraud-detection system is not high-risk simply because it operates on financial data. It may still fall under other obligations depending on what it does.
See which obligations apply to your company → or join the waitlist
This is an information service, not legal advice.