Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

EU AI Act Compliance KRIs: 8 Metrics for the August 2, 2026 Deadline — Before Your Supervisor Asks

August 2, 2026 is the full enforcement date for EU AI Act high-risk system obligations. Banks, fintechs, and insurers using credit scoring, AML, or underwriting AI need more than a compliance checklist — they need KRIs that show whether the program is actually running. Here's the framework.

By Rebecca Leung · June 5, 2026 ·
Table of Contents

TL;DR:

  • August 2, 2026 is the full enforcement date for EU AI Act high-risk AI obligations. Banks and fintechs using credit scoring, AML, or insurance underwriting AI are in scope.
  • The gap most compliance teams are discovering: they have checklists of what the Act requires, but no ongoing KRIs showing whether the compliance program is actually functioning.
  • 8 KRIs — mapped to specific EU AI Act articles — cover inventory coverage, technical documentation, conformity assessment, human oversight, post-market monitoring, bias testing, and incident reporting.
  • Provider and deployer obligations differ significantly; your KRI framework needs to reflect which role your institution occupies for each system.

Fifty-Seven Days Out and the Program Isn’t Running

As of today, August 2, 2026 — the date high-risk AI system obligations under the EU AI Act become fully enforceable — is 57 days away.

Most financial services AI teams know what the Act requires. They’ve read the Annex III list, they’ve classified their credit scoring models as high-risk, they understand the provider/deployer distinction. What they don’t have is a repeatable, measurable way to know whether the compliance program is actually functioning — whether technical documentation is being maintained, whether post-market monitoring plans are being followed, whether bias assessments have been completed and documented, whether incident reporting procedures have been tested.

That’s what EU AI Act compliance KRIs are for. Not a one-time audit checklist. Ongoing metrics that show whether the program is running and whether it would hold up when a national competent authority examiner asks to see evidence.

Penalties under Article 99 for high-risk system violations reach €15 million or 3% of global annual turnover, whichever is higher. The EBA’s November 2025 analysis of AI Act implications for the banking sector makes clear that EU supervisors expect banks to treat AI Act compliance with the same rigor applied to prudential requirements. KRIs are how you demonstrate that rigor.

Who Is In Scope: High-Risk AI in Financial Services

Annex III of the EU AI Act classifies three categories of AI systems as high-risk when used in financial services:

  1. Creditworthiness assessment and credit scoring of natural persons. Retail lending models, mortgage origination systems, credit line decisioning. This covers any AI system that evaluates an individual’s creditworthiness or generates a credit score used in a lending decision. Financial fraud detection is explicitly excluded from this category.

  2. Risk assessment and pricing in life and health insurance. AI underwriting models that affect whether a natural person can obtain insurance or what premium they pay.

  3. AML and CFT transaction monitoring. The EBA’s November 2025 guidance confirmed that AML and CFT transaction monitoring systems operated by supervised institutions fall within the Annex III scope as systems used in law enforcement-adjacent contexts affecting individuals.

If your institution uses any of these systems for EU customers or in EU-regulated subsidiaries, you’re a provider, a deployer, or both — and August 2, 2026 is your compliance date.

The Provider vs. Deployer Split

Most financial institutions are deployers for vendor-supplied AI and providers for internally built models — and sometimes both for the same use case. Provider KRIs focus on technical documentation, conformity assessments, EU database registration, post-market monitoring plans, and incident reporting to national competent authorities. Deployer KRIs focus on human oversight protocols, staff training, and log maintenance. The KRIs below cover both. Identify which role applies to each system before assigning ownership.

8 EU AI Act Compliance KRIs

1. High-Risk AI System Inventory Coverage Rate

Definition: % of AI systems in use that have been assessed for Annex III high-risk classification (documented assessment, not just classification assumption)

Relevant Articles: Article 6 + Annex III

You can’t manage what you haven’t inventoried. Many institutions have a rough list of their AI systems but haven’t formally assessed each one against the Annex III criteria with documented rationale. A system assumed to be low-risk without a documented assessment is an undocumented gap.

ThresholdSignal
100% of known AI systems assessedGreen
85–99% assessedAmber — complete by month end
< 85% assessedRed — material gap, remediate immediately

2. Technical Documentation Completeness Rate

Definition: % of high-risk AI systems with technical documentation meeting Annex IV requirements (for providers)

Relevant Articles: Article 11 + Annex IV

Annex IV sets the content requirements for technical documentation: general description of the AI system, design specifications, data governance, accuracy and robustness testing results, and instructions for use. Incomplete documentation is one of the most common compliance gaps — often because teams treat it as a one-time project rather than a living document.

ThresholdSignal
100% with compliant Annex IV docsGreen
80–99%Amber
< 80%Red — prioritize before August 2

Track separately: “documentation exists” vs. “documentation is current” (updated within 12 months or when the system is materially modified).

3. Conformity Assessment Completion Rate

Definition: % of high-risk AI systems with completed conformity assessments (for providers)

Relevant Articles: Article 43

Most financial services AI systems under Annex III don’t require third-party notified body assessment — providers can conduct internal conformity assessments. But “internal” doesn’t mean undocumented. The assessment must demonstrate compliance with Chapter III, Section 2 requirements and be documented in the technical file.

ThresholdSignal
100% completedGreen
75–99%Amber — complete gap analysis
< 75%Red — enforcement risk

4. EU AI Database Registration Rate

Definition: % of applicable high-risk AI systems registered in the EU AI database (for providers of Annex III systems)

Relevant Articles: Article 49

Providers of Annex III high-risk AI systems must register in the EU database before placing the system on the market or putting it into service. The registration creates a public record of system type, intended purpose, and conformity status. This is verifiable by supervisors and the public — making it a straightforward compliance test.

ThresholdSignal
100% of required systems registeredGreen
Any required system unregisteredRed

5. Human Oversight Protocol Coverage and Testing Rate

Definition: % of high-risk AI systems with documented, tested human oversight procedures in place (for deployers)

Relevant Articles: Article 14

Article 14 requires that high-risk AI systems be designed so that humans can effectively oversee them — understanding the system’s capabilities and limitations, monitoring for anomalies, and being able to intervene or override. For deployers, this means maintaining documented oversight procedures and demonstrating that the humans responsible for oversight have been trained and tested.

ThresholdSignal
100% with documented + tested protocolsGreen
80–99% documented; testing incompleteAmber
< 80% documentedRed

Track training completion separately: the oversight procedure exists vs. the responsible staff member has completed training on it.

6. Post-Market Monitoring Cadence Adherence

Definition: % of high-risk AI systems where the post-market monitoring plan’s review schedule is being followed (for providers)

Relevant Articles: Article 72

Article 72 requires providers to actively and systematically collect and analyze performance data throughout the system’s lifetime. The monitoring plan must define what data is collected, how often it’s reviewed, and what triggers corrective action. This KRI measures whether you’re actually running the plan, not just whether you wrote one.

ThresholdSignal
100% of systems on monitoring scheduleGreen
Any system with overdue monitoring reviewAmber
Multiple systems with overdue reviews or no planRed

For consumer-facing credit scoring systems, most monitoring plans call for at least quarterly performance reviews. For AML systems, the frequency should reflect transaction volume and the pace of money laundering tactic evolution.

7. Bias and Accuracy Testing Completion Rate

Definition: % of high-risk AI systems with a current bias and accuracy assessment completed per the monitoring plan (for providers and deployers)

Relevant Articles: Article 10 (data governance), Article 9 (risk management)

Article 10 requires training, validation, and testing data to be sufficiently representative and free from errors. In practice, this means ongoing testing for protected characteristic proxies, demographic performance disparities, and accuracy degradation. For credit scoring models in scope of fair lending regulation, this obligation overlaps with existing ECOA/CCPA requirements in the US context — but the EU AI Act standard applies independently.

ThresholdSignal
100% with current assessment (per plan cadence)Green
Last assessment > 12 months agoAmber
No bias assessment documentedRed

Coordinate with your existing fair lending monitoring program. Duplication of effort is avoidable; the documentation can satisfy both EU AI Act Article 10 and domestic fair lending requirements if structured correctly.

8. Serious Incident Reporting Timeliness

Definition: % of serious incidents reported to the relevant national competent authority within the required timeframe (for providers)

Relevant Articles: Article 73

Article 73 requires providers to report serious incidents — AI system malfunctions or failures that result in death, serious harm, or significant disruption to critical infrastructure — to the market surveillance authority without undue delay. In practice, this means having an incident classification process that distinguishes “serious incident” from general model performance issues and a notification workflow that’s been documented and tested before an incident occurs.

ThresholdSignal
100% of incidents reported on timeGreen
Any incident reported lateAmber — investigate and document
No incident reporting procedure in placeRed

Track whether an incident reporting procedure exists, whether it’s been tested (tabletop or drill), and whether any actual incidents have occurred and been reported.

So What? August 2 Is a Line, Not a Finish

The August 2, 2026 enforcement date is not a compliance checkbox — it’s the start of ongoing regulatory scrutiny. EU national competent authorities and financial supervisors (including the EBA in its coordinating role) will be looking for evidence that institutions with high-risk AI in production have functioning compliance programs, not just audit reports saying they achieved compliance as of a specific date.

The KRIs above give you that evidence. Each one produces a data point that, reviewed monthly or quarterly, shows whether the program is running and where it’s degrading. When a supervisor asks “show me your post-market monitoring cadence for your credit scoring model” or “have all staff responsible for human oversight completed training,” the answer should come from your KRI dashboard — not from a rushed document pull.

For a comprehensive AI risk assessment framework that maps EU AI Act Article requirements to compliance documentation, bias testing templates, and model risk governance workflows, the AI Risk Assessment Template & Guide is built for financial services teams navigating both EU Act obligations and domestic model risk requirements simultaneously.

For EU AI Act background: EU AI Act High-Risk AI in Financial Services covers the full Annex III obligations and documentation requirements. AI Governance Dashboard: What KRIs Belong in Committee Reporting covers how to structure AI risk reporting at the committee and board level. For the NIST AI RMF measurement framework that maps closely to EU Act monitoring requirements, see NIST AI RMF MEASURE Function: TEVV, Bias Testing, and Metrics That Actually Matter.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Which AI systems in financial services qualify as high-risk under the EU AI Act?
Annex III of the EU AI Act classifies three financial services AI categories as high-risk: AI used for creditworthiness assessment and credit scoring of natural persons (retail lending, mortgage origination, credit line decisions); AI used for risk assessment and pricing in life and health insurance; and, per the EBA's November 2025 guidance, AML and CFT transaction monitoring systems. Financial fraud detection AI is explicitly excluded from the creditworthiness classification, though it may qualify under other Annex III categories depending on how it's configured.
What's the difference between provider and deployer obligations under the EU AI Act?
Providers build or substantially modify the high-risk AI system and are responsible for technical documentation, conformity assessments, EU database registration, and post-market monitoring plans. Deployers put a vendor-supplied system into service for a specific use case and are responsible for implementing human oversight procedures, training staff, maintaining logs, and reporting serious incidents. Most large banks building proprietary credit models are providers. Most mid-size institutions licensing vendor scoring tools are deployers. Many institutions are both simultaneously, and their compliance KRI frameworks need to reflect both roles.
What are the penalties for EU AI Act non-compliance?
Under Article 99, violations of obligations for high-risk AI systems carry penalties of up to €15 million or 3% of global annual turnover, whichever is higher. Providing false information to national competent authorities can result in penalties up to €7.5 million or 1% of global annual turnover. Prohibited AI practices (Article 5) carry the highest penalties: up to €35 million or 7% of global annual turnover.
What is post-market monitoring under Article 72 and what does it require?
Article 72 requires providers of high-risk AI systems to actively and systematically collect, document, and analyze performance data throughout the system's lifetime. The post-market monitoring plan must be part of the technical documentation. It must define which metrics are collected, how frequently they're reviewed, what triggers corrective action, and how findings are fed back into the risk management system. Deployers must cooperate by providing relevant data to providers when requested. In practice, this means every high-risk AI system needs defined performance KRIs with review cadences documented before the August 2, 2026 deadline.
Do US financial institutions need to comply with the EU AI Act?
If your institution uses AI systems to make decisions affecting individuals located in the EU — including credit scoring, insurance pricing, or AML screening of EU-based customers — then your AI system is subject to EU AI Act requirements regardless of where your institution is headquartered. Many US banks, fintechs, and insurers with European customer relationships or EU subsidiaries are squarely in scope. The key question is whether the AI system's outputs affect natural persons in the EU, not where the model runs.
What should financial institutions do if they miss the August 2 deadline?
The August 2, 2026 enforcement date applies to high-risk systems under Annex III. If your institution is not fully compliant, prioritize: document your current state in writing, identify the highest-risk gaps (incomplete conformity assessments, missing technical documentation, no post-market monitoring plan), and implement an accelerated remediation plan with executive sign-off. Regulatory guidance generally looks favorably on institutions that identified gaps, documented them, and acted with urgency. Silence is not a strategy — especially when supervisors are specifically examining AI governance programs.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.