Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstalliTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Fintechs should start EU AI Act readiness by inventorying each AI system, recording its intended purpose and use, and classifying it against the Act—not by assuming every financial AI tool is high-risk. Creditworthiness and credit-scoring systems for natural persons are the clearest trigger; life and health insurance risk assessment and pricing are also named. The deadlines are phased, with Annex III high-risk requirements now scheduled to apply from 2 December 2027.
What applies now, and what comes later?
The AI Act entered into force on 1 August 2024, but its provisions have different application dates. The European Commission’s current timeline reflects the amendment that entered into force on 27 July 2026. The dates below distinguish requirements that already apply from later high-risk obligations.
| Milestone | Application date | What it means for fintechs |
|---|---|---|
| Prohibited AI practices and AI literacy | 2 February 2025 | Prohibitions and AI-literacy requirements already apply. Identify relevant staff and build literacy into training and operating practices. |
| General-purpose AI model obligations | 2 August 2025 | Obligations for general-purpose AI models began to apply. Assess relevant model roles and uses in your products and workflows. |
| General application of the AI Act | 2 August 2026 | The Act generally applies, subject to its staggered provisions. The Commission says AI Office and national competent authority enforcement powers also apply from this date. |
| Annex III high-risk systems | 2 December 2027 | High-risk systems in Annex III, including covered creditworthiness and insurance uses, become subject to the applicable high-risk requirements. |
| High-risk AI in regulated products under Annex I | 2 August 2028 | The later application date covers high-risk AI embedded in products governed by the listed Union product-safety legislation. |
Do not use 2 August 2026 as the Annex III high-risk deadline: the Commission’s updated timeline and the consolidated regulation place that deadline on 2 December 2027. Confirm the current consolidated text and Commission implementation pages when making decisions, because dates and implementation material can change.
Which fintech AI systems may be high-risk?
Creditworthiness and credit scoring
Annex III point 5(b) covers AI systems intended to assess the creditworthiness of natural persons or establish their credit score. It excludes systems used for financial-fraud detection. That exception is specific: it does not mean all fraud-related tools are automatically outside the Act, nor does it make every financial-sector AI system high-risk. Classify the system by its intended purpose and actual workflow, not a vendor’s product label.
Life and health insurance
Annex III point 5(c) names AI systems intended for risk assessment and pricing in relation to natural persons for life and health insurance. Check what the system is designed to do and whom its decisions concern; do not extend this category to insurance uses the text does not name.
Other uses and the limited Article 6(3) derogation
A use that appears in Annex III does not always have to be classified as high-risk. Article 6(3) allows a provider to conclude that certain Annex III systems are not high-risk if they do not pose a significant risk of harm and do not materially influence decision-making. The provision gives examples such as narrow procedural or preparatory tasks. A system that profiles natural persons remains high-risk under the text.
Rank #2
A human making the final decision does not, by itself, settle the classification. Assess whether the system materially influences that decision and whether it profiles people. If a provider relies on the Article 6(3) derogation for a listed system, it must document the assessment before placing the system on the market or putting it into service and complete the required registration.
Free tools Windows power users keep installed
One-click scans. No signup required.
How to build a fintech AI Act readiness playbook
Use a maintained system-and-use inventory as the foundation. The following sequence is a practical way to organize the work; it is not a verbatim statutory checklist.
Rank #3
- Inventory systems and workflows. Include internally developed models, third-party tools, AI embedded in products, and generative AI uses. For each entry, record the business process, intended purpose, affected people, inputs, outputs, and where the system is used.
- Map roles and accountable owners. For every system, establish whether the fintech is acting as a provider, deployer, or both in different parts of the stack. Assign a legal or compliance owner, model owner, business owner, and operational monitoring owner. A contract’s labels alone do not determine the role; consider how the system is placed on the market or put into service and how it is used.
- Write down the classification rationale. Record whether the use matches an Annex III category, how outputs affect decisions about individuals, whether profiling occurs, and whether a specific exception is relevant. Note differences between the provider’s stated purpose and the fintech’s deployment. Where a provider concludes a listed system is not high-risk, document the Article 6(3) assessment and meet the registration requirement.
- Map controls to the system lifecycle. For systems classified as high-risk, plan for risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, and post-market monitoring. Assign owners and define how each control is maintained as the model and workflow change.
- Connect the work to existing financial-sector governance. Compare AI Act requirements with the financial-services rules that apply to the institution, and identify which requirements can be met through existing processes. Do not treat sectoral governance as a general exemption: the Act deems certain quality-management and monitoring duties fulfilled through relevant Union financial-services governance rules for covered institutions, not all AI Act obligations for every fintech.
- Train relevant staff and revisit classifications. AI literacy requirements already apply. Train people according to their role and exposure to AI systems, and revisit the inventory when a model, business process, affected population, or decision-making role changes.
What high-risk controls need to cover
The AI Act treats high-risk compliance as a lifecycle program rather than a one-time model approval. Article 9(1) of Regulation (EU) 2024/1689 states: “A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.” The European Parliament and Council’s consolidated regulation is the controlling source for the detailed requirements.
- Risk management: identify and address risks associated with the system over its lifecycle.
- Data governance: establish appropriate controls for the data used by the system.
- Documentation and records: maintain technical documentation and records needed to understand and trace system operation.
- Transparency and human oversight: provide relevant information and arrange meaningful oversight for the system’s use.
- Performance and security: address accuracy, robustness, and cybersecurity.
- Monitoring: arrange post-market monitoring and a process for acting on relevant changes or issues.
The specific obligations differ between providers and deployers. A fintech that develops its own system, deploys a supplier’s system, or performs both roles across a product stack should map duties system by system rather than assign one blanket status to the company.
Rank #4
How existing financial regulation fits
Existing financial-sector governance can help organize controls, but it does not erase AI Act duties. The regulation provides that certain quality-management and monitoring requirements are deemed fulfilled through relevant Union financial-services governance rules for covered institutions. That limited interaction depends on the institution and the rules that apply; it is not a general exemption for fintechs.
Recommended Free Tools
The European Banking Authority’s November 2025 paper maps high-risk AI requirements—especially those concerning creditworthiness and credit scoring—against banking-sector requirements. It is useful sector context, but it predates the July 2026 amendment. Use it alongside, not in place of, the current consolidated regulation and an assessment of the institution’s actual regulatory status.
Best Value
What to settle before the high-risk deadlines
Starting before the applicable high-risk date gives teams time to resolve classification and ownership questions, connect existing controls, and establish records and monitoring. A readiness review should be able to answer these questions for each relevant system:
- What is the system’s intended purpose, and how is it actually used?
- Does it assess a natural person’s creditworthiness or credit score, or perform life or health insurance risk assessment or pricing?
- Does it profile people, materially influence decisions, or rely on a documented exception?
- Is the fintech acting as provider, deployer, or both, and who owns each responsibility?
- Which lifecycle controls are in place, who maintains them, and what records show how the system operates?
- How will staff literacy, human oversight, monitoring, and classification review be handled when the use changes?
Keep the inventory and rationale current rather than treating them as a one-off compliance exercise. The legal classification depends on purpose and use, so a material change to either can require a fresh assessment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

