EU AI Act High-Risk Series, Part 2: Finance & Insurance
Credit scoring and life/health insurance pricing are named high-risk under the EU AI Act - with a specific carve-out for fraud detection. Heres what changed, what did not, and what a lender or insurer actually has to build.
This is Part 2 of our five-part series on high-risk AI under the EU AI Act. Each instalment covers one regulated vertical - what "high-risk" means for it, what the current timeline actually requires, and what has to be different about how you build or buy AI in that space. Part 1 covered recruitment and HR tech; Part 3 covers education and EdTech; Part 4 covers healthcare and MedTech; Part 5 covers critical infrastructure.
If your product scores a person's creditworthiness or prices their life or health insurance, the EU AI Act treats that decision as high-risk - full stop. Unlike recruitment, there's no separate "this specific feature is banned outright" trap here. But finance has something recruitment doesn't: a named, mandatory impact assessment that applies specifically to this category of AI, on top of everything else in this series. This post covers what's actually in scope, what isn't, and what a lender or insurer needs to build before the clock runs out.
What just changed
As covered in Part 1, the "Digital Omnibus on AI" - Regulation (EU) 2026/1744, published 24 July 2026 and in force since 27 July 2026 - pushed the compliance deadline for standalone high-risk AI systems back from 2 August 2026 to 2 December 2027. That applies to credit scoring and insurance risk assessment exactly as it applies to recruitment - one fixed date, applied uniformly across every Annex III category.
What wasn't touched by the delay:
- Since 2 February 2025: prohibited AI practices are banned outright, and staff AI-literacy obligations apply (though the literacy standard was softened by the Omnibus, from "ensure" to "support").
- Since 2 August 2025: obligations for general-purpose AI models, plus the Act's governance and penalty framework, apply.
- From 2 August 2026 (unaffected by the delay): transparency duties apply wherever relevant - for example, disclosing that a customer is interacting with an AI system.
Finance doesn't have a vertical-specific prohibited practice the way recruitment and education do with emotion recognition. But it does have a vertical-specific obligation that most other sectors don't get by default - covered below.
Why credit and insurance AI counts as "high-risk" - and where it doesn't
The Act names two specific uses in financial services as high-risk, under Annex III, point 5:
- 5(b): AI used to evaluate a person's creditworthiness or establish a credit score - with one explicit exception: systems used purely to detect financial fraud are excluded.
- 5(c): AI used for risk assessment and pricing in life and health insurance - specifically for individual natural persons. The fraud-detection exception attaches only to credit scoring (5(b)) - it doesn't extend to insurance pricing (5(c)).
Two scope boundaries are worth being precise about, because they change whether you're in this category at all:
- Fraud detection is carved out - for credit only. If your model's job is spotting fraudulent transactions or applications rather than deciding whether someone qualifies for credit, it sits outside this specific high-risk category - though it may still be regulated elsewhere.
- Only life and health insurance are named. Motor, property, and general/commercial insurance pricing aren't covered by this Annex III category, even though they also use AI-driven risk models.
Also worth knowing: being listed in Annex III isn't automatically the end of the analysis. The Act includes a narrower derogation (Article 6(3)) for systems that don't pose a significant risk and meet specific conditions - but that derogation has its own carve-back: an Annex III system is always treated as high-risk if it profiles natural persons. Since most individual credit-scoring and insurance-pricing models do exactly that, this escape hatch is unlikely to be available in practice for the systems this post is about.
What actually has to change by December 2027
For a credit scoring or insurance pricing system in scope, the obligations map onto concrete build work:
- Data governance with a bias lens. Training and validation data has to be examined for discriminatory patterns - not just obvious ones, but proxy variables like postcode standing in for demographic characteristics.
- A human who can actually override the score. Meaningful human review of a lending or pricing decision, not a rubber-stamp approval step bolted on afterward.
- Full technical documentation and automatic logging covering how the model was built, validated, and how it behaves in production.
- Conformity assessment and EU database registration before the system goes to market.
- Ongoing monitoring for accuracy and drift once the system is live, not just at launch.
Finance and insurance carry one obligation the other verticals in this series don't get by default: under Article 27, deployers of Annex III points 5(b) and 5(c) systems - credit-scoring and life/health insurance pricing AI - must always complete a Fundamental Rights Impact Assessment before deployment, regardless of whether the deployer is a public body. Most other Annex III categories only trigger this duty for public-sector deployers or entities providing public services; here, it applies to any deployer, public or private.
If you're using a third-party scoring model rather than building your own: you're a deployer, not a provider, and the obligations are lighter but not absent - you still need the Fundamental Rights Impact Assessment, meaningful human oversight, and audit logging on your end. Under Article 25, though, retraining or fine-tuning the vendor's model beyond its intended parameters - a "substantial modification" not foreseen in the original conformity assessment - can reclassify you as a provider, inheriting the full obligation set.
What we've left out of this piece, on purpose
To keep this readable, we've deliberately skipped some detail: the fuller mechanics of the Article 6(3) derogation, the general-purpose AI model rules (a separate part of the Act), and how this overlaps with existing financial services regulation - the EBA has already flagged substantial overlap between these obligations and CRR/CRD, DORA, and the Consumer Credit Directive, and EIOPA has published its own AI governance guidance for insurers. Those overlaps are real and matter, but they're a conversation with your compliance team, not a paragraph in a primer.
What's actually at stake
Fines follow a tiered structure under Article 99, and none of these tiers were changed by the Digital Omnibus:
- Up to €35M or 7% of global annual turnover, whichever is higher - reserved for violations of the Act's outright prohibitions (Article 5), not the obligations this post covers.
- Up to €15M or 3% - the tier that actually applies to non-compliance with the high-risk obligations described above, including a missed or inadequate Fundamental Rights Impact Assessment.
- Up to €7.5M or 1% for supplying incorrect or misleading information to a regulator.
- For SMEs, including fintech startups, each cap applies as whichever figure is lower, not higher.
Financial services already sits under heavy existing regulatory scrutiny - a discriminatory credit model is simultaneously an AI Act problem and a consumer-protection problem, and, in the UK and EU alike, exactly the kind of finding that turns a routine audit into an enforcement action. Institutional and enterprise counterparties are increasingly asking AI Act questions in vendor and partner due diligence - a scoring or pricing model that can't produce its documentation on request is a deal that stalls before it closes.
Governance and audit trails aren't an afterthought in how we build - every system we ship carries the logging and human-oversight scaffolding these obligations assume, the same approach we've used for regulator-grade audit trails on enterprise AI platforms. It's a different starting point to bolting compliance onto a model that was never built to explain itself.
Getting ready
If you're building or running AI anywhere in credit or insurance decisioning and aren't sure where you stand, get in touch - we'll help you work out whether you're in scope, what's already binding today, and what to prioritise before December 2027 arrives faster than expected.
This is our take on the operational and technical side of compliance, not legal advice - pair it with your own legal counsel for formal sign-off. Next in the series: Part 3, Education & EdTech.