Skip to content
For fintech

Fintech AI is high-risk under the EU AI Act.

Credit scoring, fraud detection, and insurance underwriting all fall under Annex III, point 5 (access to essential private and public services). If your AI affects whether individuals get loans, insurance, or financial services, you have until December 2, 2027 to comply.
01 / High-risk

Which fintech AI is high-risk?

Annex III, point 5 covers AI used to evaluate creditworthiness, set insurance premiums, or determine access to essential services.

Credit scoring & lending decisions

AI that evaluates creditworthiness, approves or rejects loan applications, or sets credit limits for individuals.

Fraud detection affecting individuals

Systems that flag, block, or restrict accounts based on fraud risk scores when those decisions affect access to services.

Insurance underwriting & pricing

AI that calculates insurance premiums, assesses risk profiles, or decides coverage eligibility for individual applicants.

Benefits eligibility assessment

AI that evaluates, grants, reduces, or revokes access to public assistance, benefits, or essential financial services.

02 / Probably fine

What's not high-risk in fintech?

Not every fintech AI tool triggers Annex III. The key factor is whether AI decisions directly affect individual access to financial services.

  • Internal fraud analytics that don't directly affect individual accounts
  • Market analysis and trading algorithms (B2B, no individual impact)
  • Anti-money laundering screening (may fall under law enforcement rules instead)
  • Customer service chatbots (limited risk, transparency obligations only)

Even if your system isn't high-risk, Article 50 transparency may still apply. Run the free classifier to find out.

03 / Obligations

What high-risk fintech AI must do

Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.

  1. 01Risk management system (Article 9)
  2. 02Data governance & bias documentation (Article 10)
  3. 03Full Annex IV technical documentation
  4. 04Automatic event logging (Article 12)
  5. 05Transparency & instructions for deployers (Article 13)
  6. 06Human oversight measures (Article 14)
  7. 07Accuracy, robustness & cybersecurity (Article 15)
  8. 08Conformity assessment (Article 43)
  9. 09EU database registration (Article 49)
  10. 10Post-market monitoring (Article 72)
04 / GDPR overlap

Already GDPR compliant?

If you already meet GDPR requirements, your data governance documentation and DPIA processes partially cover Article 10 (data governance) and Article 9 (risk management). But the AI Act adds requirements GDPR doesn't: bias detection, model accuracy documentation, conformity assessment, and continuous post-market monitoring.

See the full GDPR overlap mapping

Find out where your fintech AI stands.

The classifier is free, no account required. Classify your system and start generating the compliance documentation you need.

Classify your AI system