Skip to content
RiskTemplates · The Daily Brief Thursday, September 17, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature AI Risk

The EU AI Act Gave You 16 More Months for Credit Scoring AI. Don't Waste Them.

Regulation (EU) 2026/1744 deferred high-risk AI obligations to December 2027 — but Article 50, GPAI, and prohibited practices still apply now. Here's what changed, what didn't, and what financial services teams need to do before the clock runs out.

By Rebecca Leung · September 16, 2026 ·
Table of Contents

TL;DR

  • Regulation (EU) 2026/1744 — the “Digital Omnibus” — deferred Annex III high-risk AI compliance for financial services from August 2, 2026 to December 2, 2027 (16 months). Credit scoring, insurance pricing, and employment screening AI all fall under this deferral.
  • The deferral is not a pause. Article 50 transparency duties, Article 5 prohibited practices, and GPAI obligations remain in effect now. If your AI chatbot doesn’t identify itself as AI, you’re already out of compliance.
  • Financial services firms have two distinct compliance tracks: providers (who train or substantially modify models) face Annex IV documentation and conformity assessment; deployers (who use third-party models as-is) face FRIA, human oversight, and AI literacy obligations.
  • Teams that treat December 2027 as an open runway will miss it. Conformity assessments, bias documentation, and FRIA completion are each multi-month projects.

When the EU AI Act’s August 2, 2026 high-risk AI deadline arrived, a lot of financial services teams exhaled. Brussels had quietly handed back sixteen months. Regulation (EU) 2026/1744 — the “Digital Omnibus on AI” — had pushed the Annex III compliance deadline to December 2, 2027. Credit scoring AI, insurance pricing models, employment screening tools: all deferred.

What the compliance calendar update didn’t come with was a warning label: deferred, not cancelled — and less time than you think.

The teams that understand exactly what changed, what didn’t, and what the 16-month window actually requires will be in a categorically different position than the teams that read the headline and shelved their AI governance roadmaps. Here’s what you need to know.

What the Digital Omnibus Actually Changed

Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026 and in force July 27, was a targeted amendment to the AI Act — not a wholesale rewrite. It did two primary things:

1. Extended two compliance deadlines.

  • Annex III standalone high-risk AI systems: August 2, 2026 → December 2, 2027
  • Annex I high-risk AI embedded in regulated products: August 2, 2026 → August 2, 2028

For financial services, the Annex III extension is what matters. Credit scoring under Category 5(b), insurance pricing and risk assessment under Categories 5(b) and 6, and AI used in employment and education decisions under Categories 4 and 3 all fall under Annex III. All deferred.

2. Added a new prohibited practice.

The Omnibus added AI systems whose reasonably foreseeable output is non-consensual intimate imagery or child sexual abuse material to the Article 5 prohibited-practices list. A transitional period runs to December 2, 2026 — meaning that prohibition is nearly already in effect.

That’s it for what changed. The headline is shorter than the footnotes.

The Part That Didn’t Move

Three compliance tracks stayed on the original schedule and are live right now:

Article 5 — Prohibited Practices (February 2025)

Subliminal manipulation, social scoring, real-time biometric surveillance in public spaces, emotion recognition in workplaces and educational institutions — these have been prohibited since February 2025. If any of your AI systems were doing these things, you were out of compliance a year and a half ago.

GPAI Provider Obligations (August 2025)

If your firm develops or fine-tunes general-purpose AI models and makes them available in the EU — including via API — you have been subject to GPAI transparency, technical documentation, and copyright compliance obligations since August 2025. Providers of systemic-risk GPAI models (those with training compute exceeding 10^25 FLOPs) face adversarial testing and incident reporting requirements on top of those baseline obligations.

Article 50 — Transparency and AI Content Labeling (August 2, 2026)

This is the one most financial services teams missed. As of August 2, 2026:

  • AI systems that interact with people must disclose they are AI, in real time and in a comprehensible format.
  • AI-generated content that could deceive users — synthetic images, audio, video — must be labeled as AI-generated.
  • AI-generated text published for public informational purposes must be machine-detectable as AI-generated where technically feasible.

If your customer-facing chatbot, virtual assistant, or AI-powered correspondence system does not identify itself as AI, you are currently non-compliant. This isn’t an Annex III issue — Article 50 applies regardless of high-risk classification.

The Financial Services Compliance Map

The EU AI Act creates two fundamentally different compliance tracks depending on your relationship to the AI system.

Are You a Provider or a Deployer?

Provider: You developed the AI system, or you substantially modified a system you acquired — for example, by fine-tuning a base model on your lending portfolio data, retraining a vendor model for your specific underwriting criteria, or building a proprietary credit scoring model from scratch.

Provider obligations under Annex III are substantial: Annex IV technical documentation package, conformity assessment under Article 43 (generally a self-assessment for Annex III systems, but with rigorous documentation requirements), registration in the EU AI database, and ongoing post-market monitoring with annual updates.

Deployer: You operate a high-risk AI system developed and maintained by a provider without making substantial modifications. The third-party credit scoring model from Experian, FICO, or your fintech vendor — operated as delivered — puts you in deployer status.

Deployer obligations are real but narrower: implementing the provider’s human oversight instructions, ensuring technical capacity for human override, conducting Fundamental Rights Impact Assessments where required, fulfilling AI literacy training obligations, and maintaining automated logs for at least six months.

Critical point: deployer status cannot be contractually transferred. If your vendor contract says they assume all AI Act compliance obligations, it’s not enforceable for your deployer duties. You own them regardless.

The Fraud Detection Carve-Out

Annex III, Category 5(b) covers AI used to assess creditworthiness or assign credit scores. But the regulation includes an explicit note at Category 5: AI intended solely to detect financial fraud is not classified as high-risk under this provision.

If your fraud detection model operates independently of creditworthiness assessment — it is not being used to determine whether to extend credit, approve a transaction, or price a product — it may fall outside Annex III classification. This requires a documented analysis, not a commercial assumption. The carve-out is narrow, and enforcement will test its boundaries.

What the December 2027 Compliance Build Actually Looks Like

The deferral gives you until December 2, 2027. That is 15 months from today. Here is what the work actually requires:

For Providers

Annex IV Technical Documentation — the most underestimated task. This is not a description of what your model does. It is a structured package including: general description of the system, detailed description of system elements and development process, information on training data (dataset characteristics, provenance, labeling methodology), validation and testing procedures and results, bias monitoring approach, cybersecurity measures, and post-market monitoring plan. For organizations with five or more Annex III AI systems, this is months of work per system.

Conformity Assessment — For Annex III systems not covered by a notified body, providers generally conduct their own conformity assessment under Article 43. The assessment must verify compliance with each applicable Chapter III obligation. It produces documentation that must be updated on substantial modification.

EU AI Database Registration — Providers must register their high-risk systems in the publicly accessible EU AI database before placing them on the market. If you are a provider, the clock on registration starts before deployment.

Post-Market Monitoring — Continuous monitoring for unexpected behavior, adverse outcomes, and performance drift against the documented design. This feeds annual conformity updates and incident reporting.

For Deployers

Fundamental Rights Impact Assessment (FRIA) — Mandatory for deployers that are: public bodies, private entities providing public services, or entities deploying Annex III Category 5 systems (essential services, including credit). The FRIA is a pre-deployment assessment of potential impacts on rights guaranteed by the Charter of Fundamental Rights of the EU. It is separate from — but can be conducted in parallel with — a GDPR DPIA.

Human Oversight Implementation — The provider’s technical documentation will specify what human oversight the system requires. Deployers must implement it and confirm that override is technically possible and operationally accessible. “A compliance officer can in theory override the system” is not sufficient if the workflow makes override practically inaccessible.

AI Literacy Training — Staff who operate or are affected by high-risk AI systems must receive appropriate training. The standard is proportionate to the role and the nature of the system.

Log Retention — Automated logs generated by the system must be retained for at least six months.

What You Should Be Doing Right Now

Sixteen months is enough time — if you start now. It is not enough time if you start in six months and discover your credit underwriting model is provider-classified and has no Annex IV documentation.

Step 1: Map your EU-touching AI systems against Annex III. Every AI system that could influence a decision for an EU customer, employee, or counterparty needs a classification decision: Is it Annex III high-risk? If yes, are you provider or deployer?

Step 2: Confirm your Article 50 status. Any AI customer interaction must identify itself as AI. Check your chatbots, virtual assistants, and automated correspondence workflows. This obligation is in effect now.

Step 3: Run the fraud detection carve-out analysis. If you are relying on the Category 5(b) carve-out for your fraud detection systems, document the analysis. Show that the system is not used for creditworthiness assessment, insurance pricing, or any other Annex III function.

Step 4: For deployers, begin FRIA preparation. The FRIA is a pre-deployment requirement. If you are acquiring or renewing a third-party credit scoring or insurance pricing model, the FRIA needs to exist before deployment — not after.

Step 5: For providers, begin Annex IV scoping. Identify which systems are provider-classified, map the Annex IV requirements against existing documentation, and identify the gaps. The technical documentation requirement is where most organizations underestimate the workload.

The teams that use the 16 months to build compliant infrastructure will enter 2028 in a dramatically better position than the teams that spend the first 12 months convincing themselves they have time. December 2, 2027 will arrive the same way every regulatory deadline does: faster than expected, with no partial credit for almost-ready.

The SR 26-2 model risk management update provides a useful parallel for US firms trying to build governance simultaneously for domestic and EU requirements — the documentation disciplines overlap more than they differ. For state-level AI law timelines, see our tracker on Texas TRAIGA and the 2026 state AI law wave.

If you missed the original August 2 credit scoring technical documentation deadline and are now recalibrating against December 2027, our earlier post on what EU AI Act enforcement means for credit scoring AI in September 2026 lays out the baseline documentation expectations.

So What?

The Digital Omnibus extended a deadline, not a direction. The EU AI Act’s obligations for high-risk financial services AI are coming — 16 months later than originally planned, with full force. Three things apply right now regardless of the deferral: Article 50 AI transparency labeling, Article 5 prohibited practices, and GPAI provider obligations.

The financial services teams that will be ready in December 2027 are the ones treating this quarter as the start of a 15-month compliance build — not a second pause.


External Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the EU AI Act Digital Omnibus (Regulation 2026/1744) actually change?
The Digital Omnibus deferred the compliance deadline for standalone Annex III high-risk AI systems (including credit scoring and insurance pricing) from August 2, 2026 to December 2, 2027. AI embedded in regulated products under Annex I was deferred to August 2, 2028. Article 50 transparency duties, Article 5 prohibited practices, and GPAI obligations were not deferred.
Does the deferral apply to credit scoring AI specifically?
Yes. Credit scoring is classified under Annex III, Category 5(b) — AI used to assess the creditworthiness of natural persons or assign credit scores. The Digital Omnibus deferred Annex III obligations to December 2, 2027. However, fraud detection AI may be carved out under the Annex III 5(b) exception and may not qualify as high-risk.
What AI obligations are in force RIGHT NOW in September 2026?
Three sets of obligations apply now: Article 5 prohibited practices (since February 2025), GPAI provider obligations (since August 2025), and Article 50 transparency and AI-content-labeling duties (since August 2, 2026). If your chatbot is AI-powered, it must identify itself. If you're providing a GPAI model in the EU, registration and documentation obligations are live.
What is the difference between a provider and a deployer under the EU AI Act?
A provider develops or substantially modifies a high-risk AI system. A deployer operates a provider's system without modification. Providers face heavier obligations: Annex IV technical documentation, conformity assessment under Article 43, EU AI database registration, and post-market monitoring. Deployers must implement human oversight, conduct Fundamental Rights Impact Assessments (FRIAs) where required, and fulfill AI literacy obligations. Deployer status cannot be contracted away.
What is a Fundamental Rights Impact Assessment (FRIA) and who needs one?
A FRIA is a pre-deployment assessment of how a high-risk AI system may impact fundamental rights protected by EU law. It is mandatory for deployers that are: bodies governed by public law, private entities providing public services, or entities deploying Annex III Category 5 systems (essential services including credit scoring). The FRIA is separate from a GDPR Data Protection Impact Assessment, though the two can be conducted in parallel.
Can we start EU AI Act compliance work after December 2026 and still meet the December 2027 deadline?
Not comfortably. Conformity assessment, Annex IV documentation, EU AI database registration, and bias assessments are each multi-month projects. If you have multiple credit scoring or underwriting AI systems, 12 months of lead time will be tight. Teams that start in September 2026 will be in a fundamentally different position than teams that start in October 2027.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.