COMPLIPATHDOC complipath.io/guides/eu-ai-act-fintechRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Industry ·By Yobel Tzegai ·Updated 20 August 2026

Is fintech AI high-risk under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

The core of fintech AI is high-risk under the EU AI Act. AI that evaluates creditworthiness or establishes credit scores is high-risk under point 5(b) of Annex III; AI pricing life and health insurance under point 5(c). Those obligations apply from 2 December 2027 — and two fintech patterns are not high-risk but prohibited.

Quick answer

Which fintech systems does point 5 of Annex III catch?

Point 5 of Annex III ("Access to and enjoyment of essential private services and essential public services and benefits") has two fintech letters. In full:

(b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;

(c) AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;

Under Article 6(2), a system on this list is high-risk. Applied to a typical stack:

How to make and defend these calls: how to classify your AI system.

How far does the financial-fraud carve-out actually reach?

Narrower than most vendors hope. The exception covers only AI "used for the purpose of detecting financial fraud". Three consequences:

When does a fintech system stop being high-risk and become prohibited?

Two boundaries, both binding since 2 February 2025 (Article 113, third paragraph, point (a)), with no conformity route on the other side.

Collections and hardship targeting. Article 5(1), first subparagraph, point (b) bans AI "that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation" to materially distort behaviour in a way that causes or is reasonably likely to cause significant harm — and it bans placing on the market and putting into service, not just use. Reading financial distress as such a situation is an interpretive step, not settled law: the operative text stops there, and recital 29's examples — persons in extreme poverty, ethnic or religious minorities — carry the qualifier "likely to make those persons more vulnerable to exploitation". It is a short step, but no ruling has taken it. On that reading, a collections or re-lending system that finds distressed customers and optimises timing, framing or offers to extract commitments they would not otherwise make is the pattern this ban describes; routine arrears outreach and genuine forbearance are not. What counts as "materially distorting" and "significant harm" is not settled either. Design reviews here start with Article 5, not Annex III.

Alternative-data scoring. Article 5(1), first subparagraph, point (c) bans AI evaluating or classifying people "over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics", where the score leads to detrimental treatment in contexts "unrelated to the contexts in which the data was originally generated or collected", or treatment "unjustified or disproportionate to their social behaviour or its gravity". Credit scoring as such is high-risk, not banned. But a score built on social-media behaviour or other data unrelated to repayment, driving decisions in contexts unrelated to where it arose, drifts toward the elements of the ban. No authority has ruled any specific credit product to be social scoring; the boundary is untested. The Commission's guidelines on the prohibited practices — provided for by Article 96(1), point (b) — are practical-implementation guidance, and their non-binding character is standard EU-law doctrine, not something the Regulation states. Map each input class to a repayment rationale and record it.

Article 99(3) attaches the top penalty tier to Article 5: up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher. The full list of bans: prohibited AI practices.

What can a declined applicant demand from you?

An explanation, from the deployer. Article 86(1) gives a person subject to a decision based on an Annex III high-risk system's output — point 2 is the only excepted area; credit and insurance decisions are covered — with legal or similarly significant adverse effects "the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken". A rejected loan is the paradigm case. Article 86(3) yields where Union law already provides the right; Article 26(11) requires telling people the system is in use at all.

What this means for you

If you're a fintech vendor (provider): by 2 December 2027 a scoring, decisioning or life/health-pricing product needs conformity assessment (internal control under Article 43(2) for points 2 to 8 of Annex III) and the EU declaration of conformity and CE marking (Article 16, points (g) and (h)) — the gap audit is in what high-risk status triggers. Registration is not on that date: Article 49 sits in Chapter III, Section 5, which point (c) does not defer, so Article 49(1) has applied since 2 August 2026 — only the Article 16, point (i) duty to comply with it moves. Audit collections, retention and cross-sell features against Article 5(1), first subparagraph, points (b) and (c) first: the 7% tier, and no conformity route out. Start from a documented classification per system — Complipath's guided risk classification records the category, provisions and reasoning.

If you're a bank, lender or insurer buying tools (deployer): Article 26 binds you directly: use per the instructions, competent human oversight, input-data relevance where you control it, monitoring, six months of logs (Article 26(1), (2), (4), (5) and (6)). Financial institutions under Union financial-services governance rules discharge the monitoring duty through that framework and keep logs within financial-services documentation (Article 26(5) and (6)). Before first use, Article 27(1) requires a fundamental rights impact assessment from deployers of points 5 (b) and (c) of Annex III systems — a category that sweeps in private lenders and insurers, not just public bodies — notified to the market surveillance authority (Article 27(3)). Retraining or repurposing a bought model can make you the provider (Article 25(1)) — see provider vs deployer. Deployer breaches: up to €15 million or 3% of worldwide annual turnover, whichever is higher (Article 99(4)).

Is your credit or fraud model one of them?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Is AI credit scoring banned in the EU? No. Evaluating creditworthiness or establishing a credit score is high-risk under point 5(b) of Annex III — lawful, with obligations applying from 2 December 2027 (Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744). It is prohibited only where a system crosses into Article 5 territory, such as social scoring or exploiting economic vulnerability.

Does the fraud-detection exception cover our AML and transaction-fraud tools? Only partly. The exception in point 5(b) of Annex III covers AI "used for the purpose of detecting financial fraud" — it removes such systems from the creditworthiness point, nothing more. A tool whose output feeds lending decisions is evaluating creditworthiness, and Article 5 still applies.

Is insurance pricing AI high-risk under the AI Act? Only for life and health insurance. Point 5 (c) of Annex III covers "risk assessment and pricing in relation to natural persons in the case of life and health insurance". Motor, home and other general insurance pricing is not listed there, and no other Annex III point catches it.

Do we have to explain automated loan rejections? Yes, on request. Under Article 86(1), a person subject to a decision based on an Annex III high-risk system's output with legal or similarly significant adverse effects can obtain from the deployer "clear and meaningful explanations of the role of the AI system" and the main elements of the decision.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 5, 6, 16, 25, 26, 27, 43, 49, 86, 96, 99, 111, 113 and Annex III, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in force 27 July 2026 — which replaced Article 113, third paragraph, point (c) and Article 111(2). Article 5(1), first subparagraph, points (b) and (c) and their 2 February 2025 date are unamended; the two practices that Regulation added, points (ba) and (bb), apply from 2 December 2026 and are outside this guide's scope. Annex III is unamended. Unsettled at the time of writing: whether financial distress falls within "a specific social or economic situation" under Article 5(1), first subparagraph, point (b) — recital 29's examples are narrower; what counts as "materially distorting" behaviour and "significant harm"; where alternative-data credit scoring meets the social-scoring elements of point (c); and the weight of recital 58's prudential-capital-requirements language against the narrower operative exception in point 5(b) of Annex III. The Commission's prohibited-practices guidelines (Article 96(1), point (b)) are practical-implementation guidance; their non-binding status is standard EU-law doctrine, not stated in the Regulation.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.