Annex III, point 5 covers AI used to evaluate creditworthiness, set insurance premiums, or determine access to essential services.
AI that evaluates creditworthiness, approves or rejects loan applications, or sets credit limits for individuals.
Systems that flag, block, or restrict accounts based on fraud risk scores when those decisions affect access to services.
AI that calculates insurance premiums, assesses risk profiles, or decides coverage eligibility for individual applicants.
AI that evaluates, grants, reduces, or revokes access to public assistance, benefits, or essential financial services.
Not every fintech AI tool triggers Annex III. The key factor is whether AI decisions directly affect individual access to financial services.
Even if your system isn't high-risk, Article 50 transparency may still apply. Run the free classifier to find out.
Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.
If you already meet GDPR requirements, your data governance documentation and DPIA processes partially cover Article 10 (data governance) and Article 9 (risk management). But the AI Act adds requirements GDPR doesn't: bias detection, model accuracy documentation, conformity assessment, and continuous post-market monitoring.
See the full GDPR overlap mappingThe classifier is free, no account required. Classify your system and start generating the compliance documentation you need.
Classify your AI system