AI Compliance

EU AI Act for Banks and Insurers: Credit Scoring, Life and Health Pricing, and the 2027 Deadline

Assessing the creditworthiness of individuals, setting their credit scores, and underwriting or pricing life and health insurance are high-risk uses under Annex III of the EU AI Act, with obligations from 2 December 2027. The exceptions, the deployer duties and their financial-sector adjustments, the FRIA, who supervises, how DORA and model risk management fit, and a checklist.

The EU AI Act for banks and insurers makes two uses high-risk: AI that evaluates the creditworthiness of individuals or sets their credit score, and AI that assesses risk or sets prices for individuals in life and health insurance. Under the Digital Omnibus those obligations apply from 2 December 2027. Fraud detection is carved out of the credit category, and the Article 5 bans already apply.

The two Annex III points for banks and insurers

Annex III point 5 covers access to essential private and public services, and two of its four entries reach financial institutions directly:

  • Point 5(b): AI intended to evaluate the creditworthiness of natural persons or establish their credit score, except AI used to detect financial fraud.
  • Point 5(c): AI intended for risk assessment and pricing in relation to natural persons in life and health insurance.

Recital 58 gives the reasons. Credit decisions control access to housing, electricity and telecoms as well as money, and life and health insurance pricing can lead to financial exclusion and discrimination. The same recital says AI provided for by Union law to detect fraud in financial services, or to calculate the capital requirements of banks and insurers, should not be treated as high-risk.

The Commission’s draft classification guidelines, published for consultation in May 2026, work through financial examples. They were still a draft in October 2026 (verified October 2026), so the last column may change:

UseHigh-risk?Basis
Scoring an individual for a consumer loan or mortgageYesPoint 5(b)
A credit bureau score that lenders, landlords or telecoms firms rely onYes, even though the bureau does not make the decisionDraft guidelines
Assessing a company on company data, including its owner as guarantor of the company loanNo, only natural persons are coveredDraft guidelines
Spotting forged documents or anomalies in credit applicationsNoFraud exception in point 5(b)
AML and counter-terrorist-financing screeningNo, unless it also assesses creditworthinessDraft guidelines
A pricing engine kept separate from the credit assessmentNo; yes if both run as one integrated processDraft guidelines
Internal ratings-based (IRB) models used only for capital requirementsNo; yes if the same system also scores individualsRecital 58 and draft guidelines
Collateral valuation, margin lending, early-warning monitoring after credit is grantedNoDraft guidelines
A chatbot that helps applicants complete a credit formNo, though Article 50 disclosure appliesDraft guidelines
Life insurance underwriting on health, family history and lifestyleYesPoint 5(c)
Pricing a health insurance risk group from expected medical costsYesPoint 5(c)
Credit life insurance sold with a mortgageYes, it counts as life insuranceDraft guidelines
Motor, home and other non-life pricingNo; accident and sickness cover counts as healthDraft guidelines
Claims handling and product designNoDraft guidelines

Two cautions from the draft apply across the table. Human sign-off does not change the classification, because it does not change the system’s intended purpose. And a system’s main purpose is beside the point: if scoring individuals is one of its purposes, it is high-risk even when it mostly serves the IRB approach.

Article 5 already applies to credit and insurance

The prohibitions have applied since 2 February 2025, and the Commission’s guidelines on them lean on financial examples:

  • Social scoring. An insurer that sets life premiums from unrelated spending data obtained from a bank, or a credit agency that decides housing loans on unrelated personal characteristics, is engaged in prohibited social scoring. Credit scoring based on income, expenses and other financial circumstances under consumer credit law, fraud screening on transaction data, and telematics motor pricing that is proportionate to driving behaviour all stay lawful.
  • Exploiting vulnerabilities. Aiming predatory financial products at people in low-income postcodes who are in financial distress, or steering older customers towards unnecessary insurance or deceptive investments, can be prohibited where significant harm is likely. A lender that knows its model unlawfully discriminates against people in a vulnerable economic situation, and does not correct it, can be treated as exploiting them.
  • Predicting crime. AML screening stays outside the ban on predicting offences from profiling alone when it uses the data AML law specifies, those data are objective and verifiable, and humans assess the results.

Our overview of prohibited practices covers the full Article 5 list and its fines of up to €35 million or 7% of worldwide turnover.

Dates for financial institutions

  • 17 January 2025. DORA, Regulation (EU) 2022/2554, applies.
  • 2 February 2025. The Article 5 prohibitions and the AI literacy duty apply.
  • 2 August 2025. The AI Act’s penalty provisions apply, and market surveillance authorities had to be designated.
  • 2 August 2026. Article 50 transparency applies to customer-facing chatbots and voice agents.
  • 20 November 2026. Member States must apply the second Consumer Credit Directive, (EU) 2023/2225. Its Article 18 excludes special-category data and social networks as sources for creditworthiness assessment and gives consumers a right to human intervention when the assessment uses automated processing.
  • 2 December 2027. The Annex III high-risk obligations apply under the Digital Omnibus, Regulation (EU) 2026/1744 (verified October 2026).

Article 111(2) spares high-risk systems already placed on the market or put into service before 2 December 2027 unless their design changes significantly after that date. For credit scoring inside the IRB approach, the draft guidelines point to the material-change rules of prudential regulation when judging what counts as a significant change, so your model change policy and your AI Act inventory should use the same trigger. The EU AI Act timeline sets these dates against the rest of the Act.

Deployer duties and the financial-sector adjustments

A bank or insurer using a vendor’s scoring system is its deployer, and Article 26 requires it to follow the instructions for use, assign competent human oversight, keep input data it controls relevant, monitor the system, report serious incidents, keep logs and tell people when the system makes or assists decisions about them. Article 86 lets those people ask for a clear explanation of the system’s role in a decision that affects them adversely.

The Act folds part of this into existing financial regulation:

  • Monitoring. For deployers subject to internal governance rules under Union financial services law, complying with those rules counts as meeting the monitoring duty in Article 26(5).
  • Logs. Such deployers keep the logs as part of the documentation they already maintain under financial services law (Article 26(6)).
  • In-house models. A bank that builds a scoring model and uses it under its own name is its provider. Its quality management system obligation is deemed met through internal governance rules, except for the AI Act risk management system, post-market monitoring and serious incident reporting (Article 17(4)). Technical documentation and logs sit with financial-services records (Articles 18(3) and 19(2)), and post-market monitoring can be built into existing systems (Article 72(4)). Conformity assessment follows the internal-control route in Article 43(2), and the system must be registered.

Nothing adjusts the duties that face the customer: human oversight, notices, explanations and the fundamental rights impact assessment. A rejected applicant can rely on three overlapping rights:

RightSourceWhen it applies
Not to be subject to a solely automated decision, with human intervention, a chance to give one’s view and to contest where an exception allows such a decisionGDPR Article 22The decision rests solely on automated processing and has legal or similarly significant effects
An explanation of the assessment and its logic, a chance to give one’s view, and a review of the assessment and the credit decisionConsumer Credit Directive Article 18(8), from 20 November 2026The creditworthiness assessment for consumer credit involves automated processing of personal data
A clear and meaningful explanation of the AI system’s role and the main elements of the decisionAI Act Article 86, once the Annex III rules applyThe decision rests on output from an Annex III high-risk system and adversely affects the person

In SCHUFA (C-634/21), the Court of Justice held that a credit agency’s automated score can itself be an Article 22 decision when a lender draws strongly on it, so a bureau score can bring Article 22 into play even when a credit officer formally decides.

The fundamental rights impact assessment

Article 27 requires deployers of the systems in points 5(b) and 5(c) to assess the impact on fundamental rights before first use, and recital 96 names banking and insurance entities as examples. The assessment covers the processes the system supports, how often it runs, who is affected, the specific risks to them, the human oversight in place, and the remedies and complaint routes if a risk materialises. For a retail credit model, that means the origination flow, every applicant segment including thin-file customers, proxy risks such as postcode, the officers who can override a score, and the appeal route. Results go to the market surveillance authority, using the template the AI Office must develop, the assessment must be updated when any element changes, and under the Digital Omnibus it can cross-refer to the GDPR data protection impact assessment. Our DPIA and FRIA use case shows how to run both from one body of evidence.

Who supervises banks and insurers under the AI Act

Article 74(6) makes the national authority responsible for an institution’s financial supervision its market surveillance authority for high-risk AI placed on the market, put into service or used in direct connection with financial services. A Member State can designate another authority if it ensures coordination, and authorities supervising credit institutions within the Single Supervisory Mechanism must report relevant findings to the European Central Bank. Under the Omnibus, the AI Office’s exclusive competence for AI systems built by a general-purpose model’s own provider stops short of systems that fall under Article 74(6).

The European supervisory authorities have already taken positions:

  • EBA, November 2025. Its mapping of the AI Act against banking and payments law found no significant contradictions, saw no immediate need for new or revised EBA guidelines, and noted that integrating the two frameworks takes some effort.
  • EIOPA, August 2025. Its Opinion to national supervisors covers insurance AI that is neither high-risk nor prohibited, sets no new requirements, and groups expectations under data governance, record-keeping, fairness, cybersecurity, explainability and human oversight.

DORA runs alongside all of this. An AI platform, model provider or scoring vendor supplies ICT services, so the arrangement goes in the register of information under Article 28(3), and the financial entity stays fully responsible for its obligations under Article 28(1).

Model risk management and the AI Act

Model risk teams will recognise much of what the AI Act asks for. The difference is that the Act also looks past the model to the people it affects. Using the headings of SR 26-2 as a reference point:

AreaFamiliar from model risk practiceAdded by the AI Act for points 5(b) and 5(c)
Development and dataModel development and useData governance for training, validation and test data, including examination for possible biases (Article 10), and a risk management system (Article 9)
Validation and monitoringValidation and ongoing monitoringAccuracy, robustness and cybersecurity requirements (Article 15), post-market monitoring (Article 72) and serious incident reporting (Article 73)
GovernanceGovernance, policies and controlsA quality management system, largely met through internal governance (Article 17(4)), plus conformity assessment and registration for in-house systems
Vendor modelsValidation of vendor and third-party productsDeployer duties tied to the provider’s instructions for use, and provider status under Article 25 if you rebrand or substantially modify the system
People affectedNot the subject of model risk guidanceDesigned-in human oversight (Article 14), notices (Article 26(11)), explanations (Article 86) and the fundamental rights impact assessment (Article 27)

For US banks, SR 26-2 replaced SR 11-7 on 17 April 2026. It covers traditional statistical and quantitative models and non-generative, non-agentic AI, leaves generative and agentic AI to each bank’s own risk management and governance, and is aimed mainly at banking organisations with more than $30 billion in assets (verified October 2026). A group active in both markets should map the two regimes control by control instead of assuming one set of validation evidence satisfies both.

Checklist for banks and insurers

  1. Inventory. List every system that touches an individual’s credit or life and health insurance, including bureau scores and vendor models, and fix each system’s boundaries.
  2. Classify. Test each against points 5(b) and 5(c) and their limits, such as fraud detection, prudential-only use and legal persons, and record the reasoning.
  3. Settle the role. In-house models make you the provider, and rebranding or substantially modifying a vendor system can too.
  4. Screen against Article 5 now. Check data sources unrelated to the purpose, sales targeting of vulnerable customers, and any emotion analytics on contact-centre staff.
  5. Run the FRIA. One per 5(b) or 5(c) system before first use, cross-referred to the DPIA and notified to the authority.
  6. Design oversight once for three regimes. Reviewers need the authority to change outcomes under AI Act Article 26(2), GDPR Article 22 and, for consumer credit, Article 18(8) of the Consumer Credit Directive from 20 November 2026.
  7. Prepare notices. Cover Article 26(11), Article 50 for chatbots, the Consumer Credit Directive’s rejection notice and GDPR transparency on automated decisions.
  8. Keep logs with your records. Store them with financial-services documentation, for at least six months, under a retention period that also respects GDPR.
  9. Update DORA records. Add AI vendors to the register of information, with audit rights, data locations and exit terms in the contract.
  10. Align change control. Use one definition of a significant change for prudential model changes and AI Act grandfathering, and keep the classification, FRIA and logs ready for your financial supervisor.

How VDF AI fits

VDF AI’s banking and insurance agents are built for the assistive side of these workflows. The credit underwriting agent drafts credit memos from borrower, financial, collateral and policy context while officers keep the final decision, and the insurance underwriting agent grades a submission against your appetite and leaves pricing and acceptance to an underwriter. If an output like that evaluates an individual’s creditworthiness or a life or health risk, it sits inside Annex III whatever the human sign-off, so classify by use.

VDF AI Router can pin models per workload, restrict regulated domains to approved models and return each routing decision with its reason, which helps with change control and with the records banks keep under Article 26(6). In an on-premises deployment those records stay on the bank’s own hardware. For the buying side, see on-premise AI for banks and our insurance solutions.

Sources

Frequently asked questions

Is credit scoring high-risk under the EU AI Act?

Yes, when it concerns natural persons. Annex III point 5(b) makes AI intended to evaluate the creditworthiness of natural persons or establish their credit score high-risk, with an exception for AI used to detect financial fraud. Under the Commission's draft guidelines, scoring a company on company data is outside the category, while a score that a credit bureau passes to lenders is inside it. The obligations apply from 2 December 2027, after the Digital Omnibus moved them from August 2026.

Does the EU AI Act apply to insurance companies?

Yes. Annex III point 5(c) makes AI used for risk assessment and pricing of natural persons in life and health insurance high-risk from 2 December 2027, and that point has no fraud-detection carve-out. The Commission's draft guidelines leave motor and home insurance, claims management and product design outside it. Every insurer is already bound by the Article 5 prohibitions, and its customer chatbots by the Article 50 transparency duties, whatever line of business they serve.

Do banks have to carry out a fundamental rights impact assessment?

Banks and insurers that deploy credit scoring or life and health insurance pricing systems do. Article 27 names deployers of the systems in Annex III points 5(b) and 5(c) explicitly, alongside public bodies. The assessment must be done before first use and cover the processes, frequency, affected groups, specific risks, human oversight and remedies, and its results go to the market surveillance authority. Since the Digital Omnibus it may cross-refer to the GDPR data protection impact assessment instead of repeating it.

Who supervises EU AI Act compliance for banks?

For high-risk AI used in direct connection with financial services, Article 74(6) makes the authority responsible for the institution's financial supervision its market surveillance authority, unless the Member State designates another body. Authorities supervising credit institutions in the Single Supervisory Mechanism must pass relevant findings to the European Central Bank. In its November 2025 mapping, the EBA found no significant contradictions between the AI Act and EU banking law and saw no immediate need for new guidelines.

How does the EU AI Act relate to DORA?

They regulate different things and apply side by side. DORA, which has applied since 17 January 2025, governs ICT risk management, incident reporting, resilience testing and third-party risk, so contracts with AI vendors are ICT service arrangements that belong in the register of information. The AI Act adds rules for specific AI uses, such as data governance, human oversight, logging and a fundamental rights impact assessment for credit scoring and life and health insurance pricing.

Are fraud detection and AML models high-risk under the EU AI Act?

Fraud detection is not, at least under the credit point: Annex III point 5(b) excludes AI used to detect financial fraud, and recital 58 says fraud detection provided for by Union law should not be high-risk. The Commission's draft guidelines add that AML and counter-terrorist-financing tools are not covered by that exception but fall outside point 5(b) unless they also assess creditworthiness. The ban on predicting crime from profiling alone still shapes how AML models may be used.

Filed under
EU AI ActAI compliancefinancial services AIAI in insurancemodel risk managementregulated AI
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading