EU AI Act for Financial Institutions: The 2027 Deadline and What to Do Now
label Article

EU AI Act for Financial Institutions: The 2027 Deadline and What to Do Now

calendar_today
schedule 5-min Read
person By Dominic Fui Dodzi-Nusenu

If you run credit scoring, creditworthiness assessment or AI-assisted lending decisions in the EU, your systems are high-risk under Annex III and that has not changed. What did change is the clock: the Digital Omnibus moved the high-risk compliance date from August 2026 to 2 December 2027. Read carefully, because the deferral is narrower than the relief it appears to offer — several obligations are already in force, and the work that takes longest was never the part that was postponed.

Published: March 2026 · updated August 2026 · Author: Dominic Fui Dodzi-Nusenu · Reading time: ~8 minutes

Disclosure: This article was drafted using generative AI assistance and subsequently edited, verified, and expanded by human legal and tech policy specialists. The organizational case study presented below is a composite hypothetical scenario designed to illustrate compliance risks.

In brief

Credit scoring and creditworthiness assessment sit in Annex III point 5(b), so most retail lenders, consumer finance providers and neobanks are high-risk providers or deployers whether or not they built the model. The high-risk deadline is now 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in products already regulated under Annex I. But the prohibited-practice ban and the AI literacy duty have applied since 2 February 2025, GPAI obligations since 2 August 2025, and Article 50 transparency lands 2 August 2026 — three sets of duties that are live today. Penalties reach 35 million euros or 7 percent of global turnover for prohibited practices and 15 million or 3 percent for most other breaches. The binding constraint is not the deadline, it is that Articles 9 to 15 demand a documented evidence trail covering a full model lifecycle, and you cannot retroactively produce eighteen months of monitoring records in the final quarter.

Why financial services sits at the centre of this

The AI Act is horizontal — it regulates by use case, not by industry. Financial services nonetheless attracts more of it than almost any other sector, because several of the uses named in Annex III are things banks and insurers do as core business rather than as experiments.

Annex III use case Typical financial application Who carries the duty
Point 5(b) — creditworthiness Credit scoring, loan origination, limit setting Provider if you build or fine-tune; deployer if you buy
Point 5(c) — risk pricing in life and health insurance Underwriting and premium models Insurer, typically as provider
Point 4 — employment CV screening, internal promotion and attrition models Employer as deployer
Point 5(a) — essential services eligibility Basic account access decisioning Institution as deployer

Note the last column. Buying a model does not move the obligation elsewhere. A deployer of a high-risk system carries duties of its own under Article 26 — human oversight, input data relevance, log retention, and monitoring — and those cannot be contracted away to the vendor. This is the single most common misreading we encounter.

What actually changed in 2026, and what did not

The Digital Omnibus deferral was widely reported as “the AI Act being delayed”. That framing is wrong in a way that costs money. Only the high-risk tier moved.

Obligation Applies from Status today
Prohibited practices (Article 5), AI literacy (Article 4) 2 February 2025 In force
GPAI model obligations 2 August 2025 In force
Commission enforcement powers over GPAI 2 August 2026 In force
Transparency duties (Article 50) 2 August 2026 In force
High-risk — standalone Annex III 2 December 2027 Deferred from Aug 2026
High-risk — Annex I embedded products 2 August 2028 Deferred

So an institution that reads “delayed” and stands down has stood down from nothing that was actually deferred, while remaining exposed on four sets of obligations that are enforceable now. The AI literacy duty in particular is frequently overlooked: it applies to every organisation using AI, at every risk tier, with no threshold.

Case scenario: how a mid-sized lender ends up in scope

A German consumer-credit provider with 180 staff licenses a scoring model from a vendor, retrains it quarterly on its own repayment data, and runs it behind a manual review desk. Management’s view is that the vendor is the provider and the desk satisfies human oversight. Three things are wrong with that.

  1. Retraining on own data can make you the provider. Substantially modifying a high-risk system, or placing it on the market under your own name, transfers provider obligations to you under Article 25 — including Annex IV technical documentation for the modified system.
  2. A review desk is not automatically Article 14 oversight. Oversight must be exercised by people with the competence, authority and information to override the system. A desk that sees a score and a recommendation, with no view of the drivers and no realistic mandate to reject, is a rubber stamp with a headcount.
  3. Quarterly retraining without drift records is the gap that closes last. Article 72 post-market monitoring expects evidence over time. Starting to collect it in late 2027 leaves you with a few months of history for a system that has run for years.

This scenario is a composite, but each of its three failure modes is one we see repeatedly — and the third is the one that cannot be fixed by working harder closer to the deadline.

The three gaps that actually delay financial institutions

An AI inventory that stops at the models the CIO knows about

Almost every institution we work with underestimates its own AI footprint, usually by a wide margin. The gap is rarely the flagship scoring model; it is the vendor product with a machine-learning feature nobody classified, the analytics tool that added a generative assistant in a release note, and the department that solved its own problem with a spreadsheet and an API key. You cannot classify what you have not found, and classification is the first gate.

Developer documentation mistaken for statutory evidence

Model cards in a wiki, notebooks in a repository and a data dictionary in Confluence are good engineering practice and they are not Article 11 technical documentation. Annex IV specifies content, and supervisory evidence has to be version-controlled, attributable, and reconstructable as it stood on a given date. The test is simple: if a supervisor asks what your model looked like in Q3 last year, can you produce it without reconstructing it from memory?

Treating the deadline as the project plan

Articles 9, 15 and 72 all describe continuous processes, not deliverables. A risk management system that was stood up the month before the deadline satisfies the letter of nothing — it has no iterations, no identified-and-mitigated risks, and no monitoring history to show. This is why the deferral to December 2027 is less generous than it sounds.

A sequenced 90-day start

You do not need a multi-year programme to reach a defensible position. You need to do the sequence-dependent work first.

  1. Days 1–20 — inventory. Enumerate every AI system in use, including embedded vendor features and anything staff adopted directly. Record purpose, data, owner and vendor.
  2. Days 21–40 — classify. Map each system to prohibited, high-risk (Annex III), transparency-only (Article 50) or minimal. Record the reasoning and the provision, not just the answer — the reasoning is what a supervisor tests.
  3. Days 41–60 — close the live duties. Article 5 prohibitions, Article 4 AI literacy and Article 50 transparency are enforceable now. Finish these before touching 2027 work.
  4. Days 61–75 — start the clock on evidence. Turn on logging, drift monitoring and bias measurement for high-risk systems. Every week you delay is a week of history you will not have.
  5. Days 76–90 — gap-assess against Annex IV. Now you know what you have and what it must become, size the documentation work honestly.

Do you know how many AI systems your institution is actually running?

Run a structured EU AI ActRegulation (EU) 2024/1689The EU's regulation on artificial intelligence. It sorts AI systems into risk tiers — prohibited, high-risk, limited-risk and minimal-risk — and attaches different duties to the provider that builds a system and the deployer that uses it. It entered into force on 1 August 2024 and applies in stages; the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk stages later without changing the penalties. Article 99 leaves those at up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches, including the high-risk and transparency duties.Applies toProviders and deployers of AI systems placed on or used in the EU market.Next dateDecember 2, 2026 — Article 50(2) marking of AI-generated content, for systems already on the market on 2 August 2026Read the source text (opens in a new tab)General information about the instrument named, not legal advice. classification across your estate.

Start your assessment →

Related reading

Frequently asked questions

Has the EU AI Act been delayed?

Only the high-risk tier. Standalone Annex III systems now apply from 2 December 2027 and Annex I embedded systems from 2 August 2028. The prohibited-practice ban and AI literacy duty (2 February 2025), GPAI obligations (2 August 2025) and Article 50 transparency (2 August 2026) are all in force and unaffected.

We license our scoring model from a vendor. Are we still liable?

Yes. Deployers of high-risk systems carry independent obligations under Article 26 covering human oversight, input data relevance, log retention and monitoring. In addition, if you retrain the model on your own data or put it on the market under your own name, Article 25 can make you the provider, which brings the full Annex IV documentation duty with it.

What are the maximum penalties?

Up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher, for prohibited practices. Up to 15 million euros or 3 percent for most other breaches, including high-risk obligations. Supplying incorrect or misleading information to authorities carries its own tier.

Does BaFin supervision replace the AI Act?

No — they stack. BaFin’s MaRisk and BAIT expectations continue to apply to your institution, and Germany’s KI-MIGKI-Marktüberwachungs- und Innovationsförderungsgesetz — Germany's AI Act implementation actThe German act that carries the EU AI Act into national law, in force since 29 July 2026. It designates the Bundesnetzagentur as the central AI market surveillance authority outside regulated sectors, and establishes a coordination centre, KoKIVO, there. BaFin keeps the sector-specific mandate for AI systems used in direct connection with a regulated financial activity, which is why a bank and a housing company answer to different regulators for the same kind of model.Applies toProviders and deployers of AI systems supervised in Germany. Which authority supervises depends on the sector.Read the source text (opens in a new tab)General information about the instrument named, not legal advice. designates market surveillance for the AI Act itself. Institutions should expect to evidence the same systems against both frameworks rather than choosing one.

Is an internal model validation report enough for Article 11?

Usually not on its own. Validation reports address model quality; Annex IV specifies a broader content set including intended purpose, system architecture, data governance, risk management, and post-market monitoring arrangements. Validation output is an input to that documentation, not a substitute for it.

Where should we start if we have done nothing?

Inventory, then classification. Everything else depends on knowing which systems you have and which tier each falls into, and both are cheap relative to the documentation and monitoring work they scope.

Alleina AI

Responsible AI governance platform for European enterprises, SMEs, and startups. EU AI Act compliance, bias detection, and model explainability.

Stay Updated

Get the latest on AI governance, regulatory updates, and platform news.

Gefördert durch

Universität Koblenz EXIST – Existenzgründungen aus der Wissenschaft StArfrica – Startup Germany-Africa Bundesministerium für Wirtschaft und Energie Kofinanziert von der Europäischen Union

Die Europäische Union fördert zusammen mit dem Bundesministerium für Wirtschaft und Energie über den Europäischen Sozialfonds Plus (ESF Plus) das Programm „Existenzgründungen aus der Wissenschaft (EXIST)“ in Deutschland.

Alleina AI ist ein an der Universität Koblenz inkubiertes Startup. Die Gründung wurde durch StArfrica („Startup Germany-Africa“) begleitet, ein Projekt des ZIFET an der Universität Koblenz.

© 2026 Alleina AI. Alle Rechte vorbehalten.