EU AI Act for Financial Services — High-Risk AI, Credit Scoring and GPAI Compliance
EU AI Act compliance for banks and asset managers: Annex III high-risk AI classification, credit scoring obligations under Category 5, GPAI model rules, conformity assessment, and how the framework interacts with GDPR Article 22 right to explanation.
Educational content, not professional advice — AI output and figures here can be wrong. Verify before you rely on it. Full disclaimer →
The EU AI Act: A New Compliance Layer for Financial AI
The EU Artificial Intelligence Act (Regulation EU 2024/1689) entered into force on August 1, 2024 and applies progressively through 2026–2027. For financial institutions operating in or serving EU markets, it creates a tiered compliance framework that intersects with existing obligations under MiFID II, GDPR, CRD, and the Consumer Credit Directive. The core structure is a risk-based pyramid: prohibited AI practices at the top (Article 5), high-risk AI requiring conformity assessment (Articles 6, 9–17, and Annex III), general-purpose AI (GPAI) with transparency obligations (Articles 51–56), and all other AI systems with minimal requirements.
For finance teams, the immediate priority is two questions: (1) which AI systems your institution deploys fall into the high-risk Annex III categories, and (2) what obligations those systems trigger. Getting this classification wrong — under-classifying a high-risk system or failing to complete a conformity assessment — creates enforcement exposure as national competent authorities ramp up activity in 2026.
Annex III High-Risk AI in Financial Services
Annex III lists eight categories of high-risk AI systems. Category 5 is the one most directly applicable to mainstream financial services activity: "AI systems intended to be used for creditworthiness assessment or credit scoring, when this assessment or scoring pertains to natural persons." This is a broad definition — it covers automated scoring in retail lending, BNPL decisioning, mortgage pre-approval, SME lending platforms, and any AI system that inputs into a credit decision affecting individuals.
But Category 5 is not the only relevant entry. Financial institutions also need to assess exposure to:
- Category 1 (remote biometric identification) — applicable to facial recognition-based identity verification for account opening or transaction authentication
- Category 6 (employment and worker management) — applicable to AI screening tools used in HR, including automated candidate screening for financial services hiring
- Category 7 (access to essential private services) — applicable to AI systems that determine access to insurance products, particularly life insurance and health insurance
- Category 8 (law enforcement, migration, and administration of justice) — applicable where financial institutions cooperate with law enforcement on financial crime investigations using AI
Credit Scoring AI — The Category 5 Deep Dive
A Category 5 high-risk classification triggers nine chapters of obligations (Articles 9–17). The most operationally intensive are the risk management system (Article 9), data governance (Article 10), technical documentation (Article 11), transparency and information to deployers (Article 13), human oversight (Article 14), and accuracy/robustness requirements (Article 15).
- "I need to build a compliance checklist for our retail credit scoring AI under EU AI Act Annex III Category 5. The system uses gradient boosting to combine bureau data, open banking transaction history, and application data to output a probability-of-default score and a binary approve/decline decision. Walk through each Article 9–17 obligation: (1) Article 9 risk management system — what ongoing risk identification, evaluation, and mitigation processes are required and what documentation must the risk register include? (2) Article 10 data governance — what training data, validation data, and bias testing requirements apply specifically to credit scoring models? (3) Article 11 technical documentation — what Annex IV documentation must be created and maintained? (4) Article 13 transparency — what information must we provide to the bank deploying this system? (5) Article 14 human oversight — what does 'appropriate human oversight' mean for a fully automated credit decision, and how does this interact with GDPR Article 22 right to meaningful human review? (6) Article 15 accuracy and robustness — what accuracy metrics and stress-testing requirements apply?"
- "Map the EU AI Act Article 9 risk management system requirements to our existing credit model governance framework (which follows SR 11-7 / SS1/23 model risk management principles). Identify: (a) requirements in Article 9 that are already met by a mature model risk management framework, (b) requirements that are new or more prescriptive than SR 11-7 / SS1/23, (c) documentation gaps we need to fill. Key Article 9 requirements to address: ongoing identification of known and foreseeable risks, risk estimation and evaluation, identification of risk mitigation measures, testing for robustness against errors/faults/inconsistencies, monitoring post-deployment performance, and establishing a risk management log."
- "Our credit scoring model has a post-hoc explainability layer (SHAP values) that explains individual credit decisions. Assess whether this meets EU AI Act Article 13 (transparency) and Article 14 (human oversight) requirements, and whether it satisfies the GDPR Article 22 right to meaningful explanation. Specifically: (1) Does SHAP-based explanation constitute 'meaningful information about the logic involved, the significance and the envisaged consequences' under GDPR Recital 71? (2) What does Article 14's requirement for humans to 'understand the functioning' of the AI system mean in practice — does it require that loan officers understand the model, or just that they can override it? (3) What additional transparency measures would close any gaps?"
Conformity Assessment Requirements
Article 43 requires high-risk AI systems to undergo conformity assessment before being placed on the market or put into service. For most Annex III systems — including credit scoring AI (Category 5) — providers may conduct self-assessment (internal conformity assessment) against the requirements of Articles 9–15. Third-party conformity assessment by a notified body is required only for remote biometric identification systems (Category 1, Article 43(1)) and certain safety-critical categories. This means most financial institutions building or deploying credit AI can use internal conformity assessment — but the documentation burden is substantial.
- "Design an internal conformity assessment process for our credit scoring AI under EU AI Act Article 43. We are the provider (we developed the model) and also the deployer (we use it in our own lending business). The assessment must demonstrate compliance with Articles 9–17. Structure the assessment as: (1) scope definition (which system version, deployment context, and use cases are covered), (2) risk management system documentation review (Article 9), (3) data governance review (Article 10), (4) technical documentation completeness check against Annex IV, (5) accuracy and robustness testing results, (6) human oversight procedures verification, (7) declaration of conformity (Article 47) and EU database registration (Article 49). Include the key questions the assessment must answer for each step."
GPAI Models: Obligations for Claude and Similar Foundational Models
Articles 51–56 apply to General Purpose AI (GPAI) models — models that "can be used for a variety of purposes, both for direct use and for integration into other AI systems." This is relevant to financial institutions in two ways: (1) if your institution fine-tunes or deploys a GPAI model (like Claude, GPT-4, or Llama) as a component in a high-risk system, the provider of the GPAI model has disclosure obligations toward you as the downstream provider; (2) if your institution builds a GPAI-based system that another party deploys as part of a high-risk application, you have GPAI provider obligations.
- "Our financial services firm uses Claude (Anthropic's GPAI model) as the reasoning layer in a credit report analysis tool. The tool reads FICO report data and provides a credit analyst narrative — a human reviewer then makes the credit decision. Classify this system under the EU AI Act: (1) Is the underlying GPAI model (Claude) subject to GPAI provider obligations under Articles 51–56? (2) Is our credit report analysis tool a high-risk AI system under Annex III Category 5 (credit scoring for natural persons)? (3) If it is high-risk, who bears the provider obligations — Anthropic (GPAI provider) or our firm (downstream provider)? (4) What information must Anthropic provide us under Article 53(1)(b) to enable our downstream compliance? (5) What additional safeguards do we need to add before deploying this system to ensure human oversight under Article 14 is meaningful?"
- "Map the GPAI model transparency obligations under EU AI Act Article 53 to what we need from our AI vendors. We use three GPAI-based APIs in our business: (1) a large language model for earnings call analysis, (2) a computer vision model for document verification in KYC, (3) a speech recognition model for call center compliance monitoring. For each vendor, what documentation must they provide under Article 53, and what contract clauses should we require to ensure we receive the information needed to meet our own downstream obligations?"
Interaction with GDPR Article 22
For financial institutions operating in the EU, the EU AI Act high-risk obligations and GDPR Article 22 (automated decision-making) create overlapping frameworks for credit AI. Article 22 prohibits automated decisions that "significantly affect" an individual without either explicit consent, contractual necessity, or authorisation by Union or Member State law — with a right to human review and explanation. The EU AI Act Article 14 human oversight requirement does not satisfy GDPR Article 22 by itself: Article 14 requires that designated individuals have the ability to oversee and intervene, but GDPR Article 22 requires that individuals whose data is processed actually receive human review on request.
- "Our retail lending platform makes automated credit decisions under Article 22(2)(b) (contractual necessity, permitted by EU/UK law with appropriate safeguards). We are implementing EU AI Act Article 14 human oversight. Identify the gaps between what Article 14 requires (human oversight capability for the system) and what GDPR Article 22(3) requires (right of the data subject to obtain human intervention, express point of view, and contest the decision). Create a compliance matrix that shows: (a) what Article 14 requires, (b) what Article 22(3) additionally requires, (c) the operational procedures needed to satisfy both, and (d) how we document that GDPR Article 22 safeguards are in place when regulators enquire."
Where to Start: EU AI Act Implementation Roadmap
For most financial institutions, a practical sequencing is: (1) complete an AI inventory to identify all AI systems in use or planned; (2) classify each system against Annex III and identify high-risk candidates; (3) for each high-risk system, gap-assess current documentation against Annex IV; (4) build or update the Article 9 risk management system; (5) complete the Article 43 conformity assessment and draft the Article 47 declaration; (6) register the system in the EU AI Act database (Article 49). Note: the EU's Digital Omnibus (Regulation (EU) 2026/1744, in force July 2026) extended the Annex III high-risk compliance deadline from August 2, 2026 to December 2, 2027 — a 16-month extension reflecting standards-readiness gaps, not a reduction in what's required, so this sequencing is still the right order of operations, just on a longer clock than earlier guidance assumed. The AI Governance for Finance Teams guide covers the broader governance framework and model inventory practices. The GDPR & CCPA Financial Data guide covers the GDPR Article 22 right-to-explanation requirements in detail.
Connect Claude to live financial data via MCP — EDGAR, FDIC, BIS, CME and 18 more.
New guides & tools — free
Get notified when we add new MCP servers, finance AI guides, and eval results.