EU AI Act compliance for fintech, lending and payments companies
Fintech sits on both sides of an Annex III boundary. Creditworthiness assessment for natural persons is high-risk under point 5(b). Fraud detection is explicitly excluded from that category.
Working out which of your models fall where is the whole exercise, and doing it precisely saves a great deal of unnecessary compliance work.
Are you a provider or a deployer?
Using a third-party scoring model makes you a deployer. Building your own and offering it to others makes you a provider, with conformity assessment and EU database registration on top.
How this is classified under the Act
Consumer credit scoring and creditworthiness evaluation are high-risk under Annex III point 5(b). Financial fraud detection is carved out. Internal tooling, customer support automation, and marketing models generally sit outside Annex III entirely.
What changes the answer: Life and health insurance risk assessment and pricing is separately high-risk under point 5(c). Any behavioural model inferring emotional state of a customer raises Article 5 questions.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Articles 6 and 9 Model-by-model classification
Assess each model separately. A single memo covering the whole company will not survive scrutiny when some models are high-risk and others are not.
- Article 27 Fundamental rights impact assessment for credit scoring
Deployers of Annex III point 5(b) systems must assess fundamental rights impact before first use.
- Article 26(2) Human oversight of adverse outcomes
Declines and adverse pricing need a person able to review the basis of the decision, which also connects to Article 22 GDPR on automated decision-making.
- Article 4 Literacy for risk and operations staff
Staff acting on model output need to understand its limits. This is due now and does not wait for the high-risk timeline.
Common mistakes
- Labelling a general credit model as fraud detection to claim the Annex III exclusion.
- Assuming existing financial supervision covers the AI Act. They are separate regimes with separate documentation.
- Writing one company-wide classification instead of per-model assessments.
- Missing Article 27, which applies to credit scoring deployers and is easy to overlook in the general document set.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.