Skip to content
ABC Tech
Book a demo

The EU AI Act: what it asks of a bank that scores, serves and automates

Regulation (EU) 2024/1689 sets rules for every AI system a bank buys, builds or puts in front of a customer. Credit scoring of individuals sits in its high-risk tier, and the bank carries duties of its own even when a vendor built the model.

ABC Tech5 min read

What the regulation requires

The AI Act regulates AI by risk. A few banking uses land squarely in the high-risk category, and the bank owes specific duties as the organisation that uses them. Six points matter most.

  • Credit scoring is high-risk. Annex III point 5(b) covers AI systems used to evaluate the creditworthiness of natural persons or establish their credit score. Systems used to detect financial fraud are expressly excluded.
  • Life and health insurance pricing is high-risk too. Annex III point 5(c) covers risk assessment and pricing for natural persons in life and health insurance, which reaches banks that distribute or price bancassurance.
  • Deployers carry their own duties. A bank that uses a high-risk system must follow the provider's instructions for use, assign human oversight to people with the competence, training and authority to act, keep input data relevant, monitor the system, keep its logs and tell people when a high-risk system is used in decisions about them (Article 26).
  • A fundamental rights impact assessment comes first. Before deploying a credit scoring or insurance pricing system, the bank must assess its impact on fundamental rights and notify the market surveillance authority of the results (Article 27).
  • People must know they are talking to AI. A system that interacts directly with people, such as a chat assistant, must make clear it is an AI system, at the latest at the first interaction (Article 50).
  • Staff need AI literacy. Providers and deployers must take measures to support the AI literacy of the staff who operate and use AI systems (Article 4).

Customers affected by a decision based on a high-risk system also gain a right to a clear and meaningful explanation of the role the AI played and the main elements of the decision (Article 86).

The dates

The Act entered into force on 1 August 2024 and applies in stages. Regulation (EU) 2026/1744, the AI omnibus proposed by the Commission on 19 November 2025, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the high-risk deadlines.

ObligationApplies from
Prohibited practices and AI literacy2 February 2025
General-purpose AI models and governance2 August 2025
General application, including transparency to people (Article 50)2 August 2026
High-risk systems in Annex III, including credit scoring2 December 2027 (originally 2 August 2026)
High-risk AI in products covered by Annex I2 August 2028 (originally 2 August 2027)

The deferral buys time. It does not change what a high-risk credit model must do, and the omnibus left the deployer duties and the impact assessment in place.

Where banks get stuck

The obligations read cleanly on paper. The work sits in knowing what the bank runs and proving how it runs.

No inventory of AI in use

Most banks cannot list every AI system in production. Models hide inside vendor scoring engines, fraud tools, document readers and chat assistants. Without an inventory, the bank cannot say which systems are high-risk and which only need transparency.

Provider or deployer

The roles decide the duties. A bank that puts its own name on a high-risk system, substantially modifies one, or turns a general-purpose model into a credit scoring tool becomes its provider under Article 25, with the full provider obligations that follow.

Logs and oversight that exist in theory

The Act expects logs kept for at least six months and oversight by people with the authority to overrule the system. For financial institutions, the logs belong in the documentation already kept under financial services law. Many banks log the model output and lose the context: who reviewed it, what they changed and why.

Explaining a decision to a customer

A declined applicant can ask what role the AI played. A score with no reasons attached cannot answer that. The explanation has to be available at the moment of the decision, in words a customer understands.

Vendor documentation that stops at the contract

The bank can only follow instructions for use it has received. Too often the technical documentation sits with the vendor, and the bank signs off on a system it cannot describe to its supervisor.

What it takes inside the platform

The AI Act is enforced through the supervisor the bank already answers to. Under Article 74, the market surveillance authority for AI used by regulated financial institutions is, as a rule, the national financial supervisor, although a Member State may appoint another authority. Evidence therefore has to meet a supervisor's standard.

  • One register of AI systems. Every model and agent listed with its purpose, its risk category, its provider and the bank's role.
  • Scope set per system. Each AI system acts only within the tasks and data the bank allows, and the boundary is written down.
  • A human in the decision. Where a decision affects a person, a named reviewer with authority to overrule sees the output and signs off.
  • An audit trail on every action. What the system did, on which record, under which rule, and who confirmed it, kept with the bank's other governance records.
  • Documentation the bank holds. Instructions for use, limitations and change history available to the bank, not only to the vendor.
  • Disclosure built into the channel. Customers see that they are dealing with AI before the conversation starts.

Where ABC Tech fits

ABC Tech Agentic banking puts AI agents inside the bank's own core and app, where they execute banking tasks under the bank's rules. The bank sets the scope of each agent, the agents connect to the core through MCP, and every action is written to a verification diary. Before anything reaches the core, the customer confirms it with strong customer authentication or biometrics. The bank chooses the models: open-weight models on its own infrastructure, or its own provider key.

Sources
  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act), EUR-Lex
  2. Regulation (EU) 2026/1744 amending the AI Act (AI omnibus), Official Journal of the EU
  3. European Commission: AI Act, regulatory framework on AI
  4. AI Act Explorer: Article 26, obligations of deployers of high-risk AI systems
  5. Cooley: Digital AI Omnibus delays key deadlines

Transform your operating model
with ABC Tech

Book a demo