EU AI Act for banks & insurers: obligations & timeline

For financial institutions, the EU AI Act (Regulation (EU) 2024/1689) lands on top of an already dense supervisory stack: model-risk management, product governance, outsourcing rules, and conduct supervision. The temptation is to treat it as one more layer of the same. It is not quite that: the Act brings conformity-style documentation duties and a behavioural standard of evidence that most model-risk frameworks were never built to produce. This guide covers which systems are caught, which obligations bite, how the Act interacts with existing supervision, and the timeline as it stands after the 2026 Digital Omnibus.

Which systems are high-risk

Two Annex III entries aim squarely at the sector:

  • Credit scoring and creditworthiness assessment of natural persons (Annex III, point 5(b)). This covers the scoring models behind consumer lending decisions, including AI-assisted affordability assessment. Systems used solely to detect financial fraud are carved out.
  • Risk assessment and pricing for life and health insurance (Annex III, point 5(c)). Pricing and underwriting models for life and health lines are in scope; other lines are not caught by this entry.

Beyond the sector-specific entries, the general ones still apply: AI used in recruitment and employee management (point 4) is high-risk whether you are a bank or a bakery, and biometric or emotion-recognition systems carry their own regimes. Meanwhile, the customer-facing chatbots and agents most institutions are deploying today are typically not high-risk, but they carry the Article 50 transparency duties (disclose that the customer is talking to an AI), which have applied since 2 August 2026, and they still sit inside your own governance perimeter and your supervisor's expectations.

Whether a given system is a provider or deployer question matters too: a bank buying a scoring model is usually a deployer, but a bank that substantially modifies one, or builds its own, takes on provider duties, including the technical documentation described in our Annex IV evidence pack guide.

The obligations that bite

For high-risk systems, the core requirements are Articles 9 through 15:

  • Risk management (Article 9), a documented, iterated risk process across the lifecycle, with tested mitigations.
  • Data governance (Article 10), training, validation, and testing data that is relevant, representative, and examined for bias; documented provenance.
  • Technical documentation and record-keeping (Articles 11–12), the Annex IV pack, plus automatic event logging sufficient to reconstruct what the system did.
  • Transparency to deployers (Article 13) and human oversight (Article 14), honest capability statements and oversight measures a human can actually exercise.
  • Accuracy, robustness, cybersecurity (Article 15), including resilience against manipulation, which for LLM-based systems means prompt injection and adversarial inputs.

Deployers of high-risk systems have their own list, using systems per the instructions, ensuring human oversight, monitoring, and, importantly for the sector, Article 27: bodies providing essential private services, including credit institutions assessing creditworthiness, must complete a fundamental rights impact assessment (FRIA) before first use of a high-risk system.

Penalties scale to the breach: up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for most other infringements, figures designed to register at board level in institutions already accustomed to conduct fines.

How it interacts with existing supervision

The good news: the Act explicitly anticipates the overlap. Financial institutions may integrate parts of the AI Act's process obligations, the Article 17 quality management system in particular, into their existing governance under sectoral law, rather than duplicating them. In practice:

  • Model-risk management gives you a head start on Articles 9 and 15 for classical scoring models: validation, monitoring, and challenge are familiar disciplines. What MRM typically lacks is the AI Act's documentation format, the bias-focused data governance of Article 10, and any methodology at all for agentic or generative systems, whose failure modes are behavioural rather than statistical. Our control framework for agentic AI covers that gap in detail.
  • EBA loan origination and monitoring guidelines and internal governance under CRD already expect explainable, monitored creditworthiness models, supervisory expectations that continue regardless of the AI Act's dates.
  • Solvency II governance plays the equivalent role for insurers: actuarial function oversight and model change control map naturally onto the Act's lifecycle duties.

The practical consequence cuts both ways. You can reuse a lot of machinery, but your supervisor will not wait for the AI Act's application date to ask how you govern AI. EBA and EIOPA expectations on AI governance apply now, on the basis of existing law.

Timeline, post-Omnibus

The dates moved in 2026, and any plan built on the original schedule needs updating:

  • 1 August 2024, the Act entered into force.
  • 2 February 2025, prohibitions (Article 5) and AI-literacy duties applied.
  • 2 August 2025, obligations for general-purpose AI models and the governance structures applied.
  • 2 August 2026, Article 50 transparency duties (AI-status disclosure, marking synthetic content) applied, along with the Commission's fining powers over general-purpose AI providers (Article 101).
  • 2 December 2027, high-risk obligations for stand-alone Annex III systems (credit scoring, insurance pricing, recruitment) apply. This is the Digital Omnibus deferral (Regulation (EU) 2026/1744, in force since 27 July 2026), replacing the original 2 August 2026 date. The same regulation adds two new Article 5 prohibitions and a machine-readable marking grace period for pre-existing systems, both effective 2 December 2026.
  • 2 August 2028, high-risk obligations for AI embedded in Annex I regulated products apply.

Reading the deferral as "sixteen extra months to wait" gets the incentive backwards. The documentation Annex IV demands (data provenance, design decisions, test histories, lifecycle changes) is precisely the material that cannot be reconstructed retroactively. Institutions that use 2026–2027 to stand up inventory, classification, and evidence generation will hit December 2027 with an archive; those that wait will hit it with a drafting project.

A practical readiness path

  1. Inventory every AI system and agent, with owner, purpose, and vendor posture (provider vs deployer).
  2. Classify each against Annex III and Article 50, a fifteen-minute structured assessment per system, not a legal memo.
  3. Prioritise the high-risk and customer-facing population for deep treatment; put the rest on a light governance track.
  4. Generate evidence continuously: behavioural testing before approval and on every material change, logged decisions, immutable exports, so the Annex IV pack is a by-product of operating, not a year-end project.
  5. Integrate, don't duplicate: fold the AI Act process duties into MRM, product governance, and outsourcing frameworks where the Act allows it.

Vidimus is built for steps 2 through 5: structured intake and EU AI Act risk classification, adversarial behavioural testing of live agents with tool calls observed on the wire, judge-graded results, and immutable evidence packs mapped to Annex IV with an append-only audit trail, hosted in the EU end to end. Start with the free EU AI Act readiness check to see where one of your systems lands, or contact us to put a real system through the full loop.