EU AI Act readiness for financial services firms
Financial services sits squarely in the EU AI Act's crosshairs: creditworthiness assessment for natural persons and risk assessment and pricing in life and health insurance are explicitly designated high-risk uses, and AI used in employment decisions, common across the industry, is high-risk as well. For firms in scope, that classification triggers the Act's full obligations: risk management systems, data governance, technical documentation, human oversight, accuracy and robustness requirements, and conformity assessment before deployment. The Act applies extraterritorially, so non-EU firms serving EU customers or whose AI outputs are used in the EU are not exempt.
The compounding factor for financial services is that AI Act obligations land on top of an already dense supervisory stack: model risk management expectations, consumer protection and fair lending rules, and DORA's ICT risk requirements. The efficient response is not a standalone AI Act project but an AI governance program that serves all of these masters at once, anchored on a complete inventory of AI systems (including AI embedded in vendor tools your firm never labeled as such), classification against the Act's risk tiers, and gap assessment of the high-risk systems against obligations that phase in through 2026 and 2027.
Key considerations for financial services teams
Classification is the load-bearing analysis. Credit scoring of natural persons and life/health insurance pricing are named high-risk in Annex III; the boundary questions (fraud detection is largely excepted, marketing models mostly out of scope) need documented, defensible answers per system.
Deployer obligations apply even when you buy rather than build. Using a vendor's high-risk AI still obligates you to human oversight, input data relevance monitoring, logging, and impact assessment; procurement contracts need AI Act clauses, and your vendor inventory needs an AI dimension.
Existing model risk management is a head start, not a finish line. Model inventories, validation, and documentation traditions map well onto the Act's requirements, but the Act adds fundamental-rights impact assessment, registration, transparency, and post-market monitoring that MRM programs never contemplated.
General-purpose AI in the workflow is in scope. Foundation-model tools your teams use for drafting, summarization, or research carry transparency obligations and, when integrated into high-risk workflows like underwriting, can inherit high-risk requirements.
The timeline is staged and already running. Prohibited practices and AI literacy obligations took effect in 2025, general-purpose AI obligations have begun, and the bulk of high-risk obligations arrive through 2026-2027; readiness sequencing should mirror that calendar.
This work is part of our AI Governance practice
Adopt AI with controls you can defend to customers, regulators, and the board.
Explore AI GovernanceFrequently asked questions
We are a US firm with EU customers. Does the AI Act reach us?
Very likely yes. The Act applies to providers placing AI systems on the EU market and to situations where an AI system's output is used in the EU, regardless of where the provider or deployer sits. A US lender or insurer serving EU residents, or a platform whose scores are consumed by EU institutions, should assume exposure and classify accordingly.
Is our credit scoring model automatically high-risk?
AI systems used to evaluate creditworthiness or establish credit scores of natural persons are listed as high-risk, with a carve-out for AI used to detect financial fraud. Systems serving only commercial credit decisions about legal entities fall outside that specific listing. The analysis is per-system and worth documenting even when the answer is out of scope.
How does the AI Act interact with DORA?
They are complementary: DORA governs ICT risk and operational resilience for financial entities, while the AI Act governs the AI systems themselves. An AI model running in production is simultaneously an ICT asset under DORA and potentially a high-risk system under the AI Act; a unified inventory and control mapping prevents duplicate, inconsistent compliance work.
See where your EU AI Act program stands today.
Start with a structured readiness review scoped to your organization, or run a self-serve risk assessment to get an initial read.
RiskSensai content is informational only. It is not an audit opinion, assurance, or legal or accounting advice.
Related readiness guides
EU AI Act for Technology
Technology companies face the EU AI Act from the hardest side: as providers.
SOC 2 for Financial Services
In financial services, SOC 2 usually arrives through the vendor door: banks, broker-dealers, and insurers are themselves regulated on third-party risk, so they push examination-grade expectations down to every fintech, data provider, and outsourced service they touch.
ISO 27001 for Financial Services
ISO 27001 certification carries particular weight in financial services because it attests to a management system, not just a snapshot of controls.
NIST AI RMF for Financial Services
Financial services has governed models for decades: SR 11-7 made model risk management a supervisory expectation, with inventories, independent validation, and documentation as table stakes.
GLBA for Financial Services
GLBA's reach is wider than its name suggests.
