What the EU AI Act Means for Banks in 2026
The Annex III deadline moved to 2 December 2027. Every European bank still needs a defensible answer to a simple supervisory question: which of your AI systems are high-risk, and can you prove how they are controlled?
Updated 18 August 2026 to reflect Regulation (EU) 2026/1744, which entered into force on 27 July 2026.
Reviewed by Nils André, Co-Founder & Legal Officer, on 18 August 2026.
Most European banks have spent the last two years experimenting with generative AI - copilots inside operations, retrieval-augmented assistants for analysts, and pilots in credit, AML and customer servicing. Far fewer have a clear, board-defensible answer to the question that will define the next supervisory cycle: which of those systems will be classified as high-risk under the EU AI Act, and what evidence will you produce when asked?
Under the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, the main obligations for stand-alone high-risk AI systems under Annex III of the AI Act, Regulation (EU) 2024/1689 apply from 2 December 2027, and 2 August 2028 for high-risk systems embedded in regulated products under Annex I. Transparency obligations apply from 2 August 2026 and content marking from 2 December 2026 (see the European Commission AI Act pages). For banks, those dates sit inside the same horizon as DORA enforcement maturity, the ongoing rollout of EBA model risk expectations, and continued ECB attention on internal models and outsourcing. This article sets out, in plain terms, what banks should plan for - and what should already be in motion.
1. The use cases that trigger high-risk obligations
Annex III of the EU AI Act lists the use cases that are presumptively high-risk. For banks, three areas are immediately in scope:
- Creditworthiness assessment and credit scoring of natural persons - explicitly listed under Annex III(5)(b)
- Risk assessment and pricing in life and health insurance, where it sits inside a bancassurance group - see also EIOPA's opinion on AI governance and risk management
- AI used for the recruitment, evaluation or management of bank employees
Beyond Annex III, banks should assume that AI systems embedded in AML triage, sanctions screening and certain fraud-detection workflows will draw supervisory attention even when the legal classification is debated. The pragmatic posture is to govern those systems as if they were high-risk - because by the time the legal question is settled, the operational gap is too expensive to close in time.
2. Annex IV: the documentation that will be asked for
The EU AI Act gives high-risk AI systems a documentary spine, and that spine is Annex IV. It is the file an internal auditor, a notified body or a national competent authority will request when they want to know how a system actually works. Annex IV requires, among other things, a clear description of the system and its intended purpose, the data governance practices behind training and validation sets, a record of validation and performance, an articulation of the risk management measures and residual risks, and a post-market monitoring plan.
In most banks today, this information exists - but distributed across model cards, MRM validation memos, Confluence pages, vendor documentation and engineers' heads. The work between now and December 2027 is to consolidate it into a maintained, versioned dossier per high-risk system, owned by a named first-line model owner and independently reviewed by the second line.
3. Governance: extending model risk management to generative AI
Existing model risk management (MRM) frameworks in European banks were largely built around traditional statistical models: credit scoring, market risk, capital and stress-testing. The EU AI Act forces an honest conversation about whether that perimeter still holds. Generative and agentic AI systems behave differently. They are non-deterministic, frequently rely on third-party foundation models, ingest unstructured data, and produce outputs that are harder to validate with classical challenger methods.
A credible governance posture today requires four things: an enterprise AI inventory that includes shadow and vendor AI; risk classification per use case against Annex III; extended MRM standards that cover generative and agentic systems; and human oversight design that is real, not nominal. The latter is the area where supervisors will probe hardest. 'Human in the loop' written into a policy document is not the same as a documented operator workflow with training records and override telemetry.
Where the second line needs to invest
- AI-specific validation methods, including red-teaming, prompt-injection testing and hallucination measurement
- Third-party AI due diligence aligned with the EBA guidelines on outsourcing arrangements and DORA, Regulation (EU) 2022/2554
- Continuous monitoring of drift, bias and post-deployment performance
- Independent review of human oversight design, not just its existence on paper
4. The intersection with DORA, EBA and ECB expectations
The EU AI Act does not arrive into an empty room. For banks, it overlays an already dense regulatory stack: DORA on operational and ICT resilience, EBA SREP guidance on internal models, ECB expectations on risk data aggregation and outsourcing, and GDPR Article 22 on automated decision-making. The right answer is not four parallel programmes but one integrated control set. A single AI inventory, a single set of risk classifications, and a single evidence base that can be sliced for AI Act, DORA, EBA and GDPR purposes.
5. The timeline you are actually planning against
The sequence set by Regulation (EU) 2026/1744 is now fixed, and it is the only calendar worth planning against. Transparency obligations, including disclosure where people interact with an AI system, apply from 2 August 2026. Marking of AI-generated content applies from 2 December 2026. Obligations for stand-alone high-risk systems under Annex III, which is where credit scoring and HR use cases sit for banks, apply from 2 December 2027. High-risk systems embedded in regulated products under Annex I follow on 2 August 2028. The Commission's digital omnibus pages track the implementing work behind those dates.
- 2 August 2026: transparency obligations apply, including disclosure to people interacting with an AI system
- 2 December 2026: marking and machine-readable labelling of AI-generated content applies
- 2 December 2027: obligations for stand-alone Annex III high-risk systems apply, including credit scoring of natural persons
- 2 August 2028: obligations for Annex I high-risk systems embedded in regulated products apply
Translating that into a bank programme: transparency and content marking are 2026 work and largely sit with customer-facing channels and marketing operations. Annex III readiness is 2027 work, but the evidence it requires, an AI inventory, written classification rationales, Annex IV dossiers, extended model risk standards and a documented human oversight design, takes four to six quarters to build and one internal audit cycle to test. Banks aiming to be defensible on 2 December 2027 should have classification complete and dossier production under way well before the end of 2026.
Two caveats worth stating plainly. First, the sectoral supervisors move on their own schedule: EBA and EIOPA expectations on outsourcing, governance and model risk apply today, irrespective of AI Act phase-in. Second, classification depends on the intended purpose of each system, not on the sector you operate in. An AML monitoring model is not automatically high-risk; a credit scoring model very likely is.
6. A pragmatic 12-month plan
- Months 1-2: enterprise AI discovery and risk classification against Annex III
- Months 2-4: extended MRM standards, governance operating model, board AI oversight pack
- Months 3-7: Annex IV dossiers for the top tier of high-risk systems
- Months 5-9: human oversight redesign and operator training for in-scope systems
- Months 7-10: third-party AI due-diligence remediation and post-market monitoring rollout
- Months 9-12: internal audit dry-run, supervisory readiness pack, board sign-off
Done in this sequence, the work is demanding but tractable. Done in reverse, assembling evidence after a supervisory request has already landed, it is neither.
Primary sources
Primary legislative texts and supervisory publications referenced above.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal textIn force 27 July 2026. Sets the revised application dates cited above.
- Regulation (EU) 2024/1689 (AI Act), Official Journal textAnnex III high-risk use cases and Annex IV technical documentation.
- European Commission - regulatory framework for AICommission guidance, implementing acts and standardisation work.
- European Commission - digital omnibus
- EBA guidelines on outsourcing arrangementsRelevant to third-party and vendor AI due diligence.
- EIOPA opinion on artificial intelligence governance and risk management
- Regulation (EU) 2022/2554 (DORA), Official Journal text
Frequently asked questions
When do EU AI Act high-risk obligations apply to banks?
Following Regulation (EU) 2026/1744, the main obligations for stand-alone high-risk AI systems under Annex III apply from 2 December 2027, and from 2 August 2028 for high-risk systems embedded in regulated products under Annex I. Transparency obligations apply from 2 August 2026 and AI-generated content marking from 2 December 2026.
Which bank AI systems are most likely to be classified as high-risk?
Creditworthiness assessment and credit scoring of natural persons are explicitly listed in Annex III(5)(b). Recruitment and employee evaluation AI are also high-risk. AML triage, sanctions screening and certain fraud workflows are not always legally high-risk but will draw supervisory attention and should be governed as if they were.
Do banks need to redo their model risk management to comply?
Not redo - extend. Existing MRM frameworks (EBA / SR 11-7 derived) cover the spine. The EU AI Act adds requirements around generative and agentic systems, Annex IV documentation, post-market monitoring and human oversight that need to be layered on top of the existing standard.
What is the relationship between the EU AI Act and DORA for banks?
AI systems are increasingly treated as ICT services under DORA. The cleanest approach is a single AI register and a single control set that satisfies AI Act technical documentation, DORA ICT third-party requirements and EBA outsourcing expectations simultaneously.
How long does it take to reach an audit-ready EU AI Act posture?
For a mid-sized European bank with a known AI estate, a credible programme runs 9-12 months end-to-end, plus remediation. Against the December 2027 Annex III date, that means starting in good time rather than assembling evidence under audit pressure.
Prepare for the December 2027 Annex III obligations
A confidential discovery call to scope your AI estate, exposure and the right path to an audit-ready posture.
Request Executive Briefing