Feature AI Risk
The EU AI Act Gave You 16 More Months for Credit Scoring AI. Don't Waste Them.
Regulation (EU) 2026/1744 deferred high-risk AI obligations to December 2027 — but Article 50, GPAI, and prohibited practices still apply now. Here's what changed, what didn't, and what financial services teams need to do before the clock runs out.
Table of Contents
TL;DR
- Regulation (EU) 2026/1744 — the “Digital Omnibus” — deferred Annex III high-risk AI compliance for financial services from August 2, 2026 to December 2, 2027 (16 months). Credit scoring, insurance pricing, and employment screening AI all fall under this deferral.
- The deferral is not a pause. Article 50 transparency duties, Article 5 prohibited practices, and GPAI obligations remain in effect now. If your AI chatbot doesn’t identify itself as AI, you’re already out of compliance.
- Financial services firms have two distinct compliance tracks: providers (who train or substantially modify models) face Annex IV documentation and conformity assessment; deployers (who use third-party models as-is) face FRIA, human oversight, and AI literacy obligations.
- Teams that treat December 2027 as an open runway will miss it. Conformity assessments, bias documentation, and FRIA completion are each multi-month projects.
When the EU AI Act’s August 2, 2026 high-risk AI deadline arrived, a lot of financial services teams exhaled. Brussels had quietly handed back sixteen months. Regulation (EU) 2026/1744 — the “Digital Omnibus on AI” — had pushed the Annex III compliance deadline to December 2, 2027. Credit scoring AI, insurance pricing models, employment screening tools: all deferred.
What the compliance calendar update didn’t come with was a warning label: deferred, not cancelled — and less time than you think.
The teams that understand exactly what changed, what didn’t, and what the 16-month window actually requires will be in a categorically different position than the teams that read the headline and shelved their AI governance roadmaps. Here’s what you need to know.
What the Digital Omnibus Actually Changed
Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026 and in force July 27, was a targeted amendment to the AI Act — not a wholesale rewrite. It did two primary things:
1. Extended two compliance deadlines.
- Annex III standalone high-risk AI systems: August 2, 2026 → December 2, 2027
- Annex I high-risk AI embedded in regulated products: August 2, 2026 → August 2, 2028
For financial services, the Annex III extension is what matters. Credit scoring under Category 5(b), insurance pricing and risk assessment under Categories 5(b) and 6, and AI used in employment and education decisions under Categories 4 and 3 all fall under Annex III. All deferred.
2. Added a new prohibited practice.
The Omnibus added AI systems whose reasonably foreseeable output is non-consensual intimate imagery or child sexual abuse material to the Article 5 prohibited-practices list. A transitional period runs to December 2, 2026 — meaning that prohibition is nearly already in effect.
That’s it for what changed. The headline is shorter than the footnotes.
The Part That Didn’t Move
Three compliance tracks stayed on the original schedule and are live right now:
Article 5 — Prohibited Practices (February 2025)
Subliminal manipulation, social scoring, real-time biometric surveillance in public spaces, emotion recognition in workplaces and educational institutions — these have been prohibited since February 2025. If any of your AI systems were doing these things, you were out of compliance a year and a half ago.
GPAI Provider Obligations (August 2025)
If your firm develops or fine-tunes general-purpose AI models and makes them available in the EU — including via API — you have been subject to GPAI transparency, technical documentation, and copyright compliance obligations since August 2025. Providers of systemic-risk GPAI models (those with training compute exceeding 10^25 FLOPs) face adversarial testing and incident reporting requirements on top of those baseline obligations.
Article 50 — Transparency and AI Content Labeling (August 2, 2026)
This is the one most financial services teams missed. As of August 2, 2026:
- AI systems that interact with people must disclose they are AI, in real time and in a comprehensible format.
- AI-generated content that could deceive users — synthetic images, audio, video — must be labeled as AI-generated.
- AI-generated text published for public informational purposes must be machine-detectable as AI-generated where technically feasible.
If your customer-facing chatbot, virtual assistant, or AI-powered correspondence system does not identify itself as AI, you are currently non-compliant. This isn’t an Annex III issue — Article 50 applies regardless of high-risk classification.
The Financial Services Compliance Map
The EU AI Act creates two fundamentally different compliance tracks depending on your relationship to the AI system.
Are You a Provider or a Deployer?
Provider: You developed the AI system, or you substantially modified a system you acquired — for example, by fine-tuning a base model on your lending portfolio data, retraining a vendor model for your specific underwriting criteria, or building a proprietary credit scoring model from scratch.
Provider obligations under Annex III are substantial: Annex IV technical documentation package, conformity assessment under Article 43 (generally a self-assessment for Annex III systems, but with rigorous documentation requirements), registration in the EU AI database, and ongoing post-market monitoring with annual updates.
Deployer: You operate a high-risk AI system developed and maintained by a provider without making substantial modifications. The third-party credit scoring model from Experian, FICO, or your fintech vendor — operated as delivered — puts you in deployer status.
Deployer obligations are real but narrower: implementing the provider’s human oversight instructions, ensuring technical capacity for human override, conducting Fundamental Rights Impact Assessments where required, fulfilling AI literacy training obligations, and maintaining automated logs for at least six months.
Critical point: deployer status cannot be contractually transferred. If your vendor contract says they assume all AI Act compliance obligations, it’s not enforceable for your deployer duties. You own them regardless.
The Fraud Detection Carve-Out
Annex III, Category 5(b) covers AI used to assess creditworthiness or assign credit scores. But the regulation includes an explicit note at Category 5: AI intended solely to detect financial fraud is not classified as high-risk under this provision.
If your fraud detection model operates independently of creditworthiness assessment — it is not being used to determine whether to extend credit, approve a transaction, or price a product — it may fall outside Annex III classification. This requires a documented analysis, not a commercial assumption. The carve-out is narrow, and enforcement will test its boundaries.
What the December 2027 Compliance Build Actually Looks Like
The deferral gives you until December 2, 2027. That is 15 months from today. Here is what the work actually requires:
For Providers
Annex IV Technical Documentation — the most underestimated task. This is not a description of what your model does. It is a structured package including: general description of the system, detailed description of system elements and development process, information on training data (dataset characteristics, provenance, labeling methodology), validation and testing procedures and results, bias monitoring approach, cybersecurity measures, and post-market monitoring plan. For organizations with five or more Annex III AI systems, this is months of work per system.
Conformity Assessment — For Annex III systems not covered by a notified body, providers generally conduct their own conformity assessment under Article 43. The assessment must verify compliance with each applicable Chapter III obligation. It produces documentation that must be updated on substantial modification.
EU AI Database Registration — Providers must register their high-risk systems in the publicly accessible EU AI database before placing them on the market. If you are a provider, the clock on registration starts before deployment.
Post-Market Monitoring — Continuous monitoring for unexpected behavior, adverse outcomes, and performance drift against the documented design. This feeds annual conformity updates and incident reporting.
For Deployers
Fundamental Rights Impact Assessment (FRIA) — Mandatory for deployers that are: public bodies, private entities providing public services, or entities deploying Annex III Category 5 systems (essential services, including credit). The FRIA is a pre-deployment assessment of potential impacts on rights guaranteed by the Charter of Fundamental Rights of the EU. It is separate from — but can be conducted in parallel with — a GDPR DPIA.
Human Oversight Implementation — The provider’s technical documentation will specify what human oversight the system requires. Deployers must implement it and confirm that override is technically possible and operationally accessible. “A compliance officer can in theory override the system” is not sufficient if the workflow makes override practically inaccessible.
AI Literacy Training — Staff who operate or are affected by high-risk AI systems must receive appropriate training. The standard is proportionate to the role and the nature of the system.
Log Retention — Automated logs generated by the system must be retained for at least six months.
What You Should Be Doing Right Now
Sixteen months is enough time — if you start now. It is not enough time if you start in six months and discover your credit underwriting model is provider-classified and has no Annex IV documentation.
Step 1: Map your EU-touching AI systems against Annex III. Every AI system that could influence a decision for an EU customer, employee, or counterparty needs a classification decision: Is it Annex III high-risk? If yes, are you provider or deployer?
Step 2: Confirm your Article 50 status. Any AI customer interaction must identify itself as AI. Check your chatbots, virtual assistants, and automated correspondence workflows. This obligation is in effect now.
Step 3: Run the fraud detection carve-out analysis. If you are relying on the Category 5(b) carve-out for your fraud detection systems, document the analysis. Show that the system is not used for creditworthiness assessment, insurance pricing, or any other Annex III function.
Step 4: For deployers, begin FRIA preparation. The FRIA is a pre-deployment requirement. If you are acquiring or renewing a third-party credit scoring or insurance pricing model, the FRIA needs to exist before deployment — not after.
Step 5: For providers, begin Annex IV scoping. Identify which systems are provider-classified, map the Annex IV requirements against existing documentation, and identify the gaps. The technical documentation requirement is where most organizations underestimate the workload.
The teams that use the 16 months to build compliant infrastructure will enter 2028 in a dramatically better position than the teams that spend the first 12 months convincing themselves they have time. December 2, 2027 will arrive the same way every regulatory deadline does: faster than expected, with no partial credit for almost-ready.
The SR 26-2 model risk management update provides a useful parallel for US firms trying to build governance simultaneously for domestic and EU requirements — the documentation disciplines overlap more than they differ. For state-level AI law timelines, see our tracker on Texas TRAIGA and the 2026 state AI law wave.
If you missed the original August 2 credit scoring technical documentation deadline and are now recalibrating against December 2027, our earlier post on what EU AI Act enforcement means for credit scoring AI in September 2026 lays out the baseline documentation expectations.
So What?
The Digital Omnibus extended a deadline, not a direction. The EU AI Act’s obligations for high-risk financial services AI are coming — 16 months later than originally planned, with full force. Three things apply right now regardless of the deferral: Article 50 AI transparency labeling, Article 5 prohibited practices, and GPAI provider obligations.
The financial services teams that will be ready in December 2027 are the ones treating this quarter as the start of a 15-month compliance build — not a second pause.
External Sources:
- EU AI Act Digital Omnibus — Regulation (EU) 2026/1744, EUR-Lex
- EU AI Act’s High-Risk Deadline: Deferred, Not Cancelled — Cloud Security Alliance
- EU AI Omnibus Enters Into Force, Amending the AI Act — White & Case
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn
- AI Act compliance for banks — credit scoring Annex III §5(b), DORA & FRIA (deadline 2 December 2027) — Sprinkling Act
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the EU AI Act Digital Omnibus (Regulation 2026/1744) actually change?
Does the deferral apply to credit scoring AI specifically?
What AI obligations are in force RIGHT NOW in September 2026?
What is the difference between a provider and a deployer under the EU AI Act?
What is a Fundamental Rights Impact Assessment (FRIA) and who needs one?
Can we start EU AI Act compliance work after December 2026 and still meet the December 2027 deadline?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
SR 26-2 Covers Your Models. It Doesn't Cover Your AI Agents.
The Fed, OCC, and FDIC rewrote model risk management in April 2026. SR 26-2 preserves the validation-first framework that's governed banking AI for 15 years — and explicitly carves out generative and agentic AI, leaving a governance gap at exactly the moment banks need it most.
Sep 12, 2026
AI Risk
Texas's TRAIGA Has Been in Effect for Eight Months. If Your AI Touches Financial Decisions for Texas Residents, Here's What's Actually Required.
The Texas Responsible AI Governance Act (TRAIGA) took effect January 1, 2026. The final law is narrower than feared — but financial services firms using AI in credit, insurance, or banking decisions have real obligations. Here's what they are.
Sep 11, 2026
AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
Sep 10, 2026