EU AI Act compliance for AI credit scoring and lending decisions
AI that evaluates creditworthiness or sets a credit score for a natural person is named directly in Annex III point 5 of Regulation (EU) 2024/1689. This is high-risk, and lending is one of the areas where the Act overlaps most heavily with existing financial regulation.
One obligation here goes beyond the general deployer set. Certain deployers must carry out a fundamental rights impact assessment before putting the system into use.
Are you a provider or a deployer?
A lender using a third-party scoring model is a deployer. Building your own model and offering it to others makes you a provider, with conformity assessment and registration duties on top.
How this is classified under the Act
Annex III point 5(b) covers AI intended to evaluate creditworthiness or establish a credit score, excluding systems used to detect financial fraud. Consumer lending decisions therefore sit in the high-risk tier.
What changes the answer: Fraud detection is carved out of the high-risk category. Where one model does both scoring and fraud detection, document the boundary carefully rather than claiming the exclusion for the whole system.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 27 Fundamental rights impact assessment
Deployers of Annex III point 5(b) credit scoring systems must assess the impact on fundamental rights before first use, covering affected groups, specific risks of harm, and mitigation.
- Article 26(2) Human oversight of adverse decisions
A competent person needs the information and authority to reconsider a refusal. Automated adverse decisions also engage Article 22 of the GDPR.
- Article 86 Explanation to the applicant
An applicant affected by a decision taken with a high-risk system has a right to a clear and meaningful explanation of the AI’s role in it.
- Article 26(5) Monitoring and incident reporting
Monitor operation against the provider’s instructions, and report serious incidents and risks to the provider and market surveillance authority.
Common mistakes
- Missing the Article 27 fundamental rights impact assessment, which is specific to certain deployers and not part of the standard document set.
- Claiming the fraud detection exclusion for a general scoring model that happens to include fraud signals.
- Handling this purely as a GDPR Article 22 matter and producing no AI Act documentation.
- Assuming supervisory approval under financial regulation covers AI Act obligations. They are separate regimes.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.