DEEN
AI & Governance

EU AI Act for banks: classification and duties

The AI Act for banks after the July 2026 amendment: high-risk classification, transparency and current application dates.

First version: Updated: Reading time: about 11 minutes

Symbolic image EU AI Act: AI node network with glowing connections on dark blue background, styled as a regulatory framework

The AI Act connects duties to an AI system’s purpose and the role of the organisation involved. The same technical platform can therefore require different treatment in a bank depending on whether it searches documents or evaluates a person’s creditworthiness. The July 2026 amendment changed the application dates for high-risk systems.

The AI Act and its scope

The AI Act, Regulation (EU) 2024/1689, regulates AI systems and specified duties for general-purpose AI models. It has been in force since 1 August 2024, with duties applying in stages. An institution’s assessment starts with the intended use and its own role. AI Act consolidated as at 27 July 2026

The social-scoring prohibition in Article 5 is not limited to public authorities. Its application depends on the assessment and adverse-treatment conditions set out in that provision. Annex III point 5(b) covers AI systems evaluating the creditworthiness of natural persons or establishing their credit score. Systems used to detect financial fraud are expressly excluded from that category. Classification follows intended purpose and Article 6, rather than the label chatbot or agent. AI Act consolidated as at 27 July 2026

The role follows the actual deployment. A bank may deploy an AI system and also incur provider duties when developing a system itself. Sourcing a general-purpose AI model and classifying the resulting system require separate assessments; Article 25 addresses specified role changes for high-risk systems. AI Act consolidated as at 27 July 2026

Current application dates

The table shows key application stages. The July 2026 amendment is already in force. Regulation (EU) 2026/1744 amending the AI Act

Deadline table EU AI Act (Regulation (EU) 2024/1689) including Digital Omnibus
DateContentLegal basis
1 Aug 2024AI Act enters into forceArt. 113
2 Feb 2025First prohibitions and AI-literacy dutiesArt. 4, 5, 113
2 Aug 2025General application of GPAI duties to new modelsArt. 111, 113
2 Aug 2026General application, including Article 50; specific transitions remain relevantArt. 50, 111, 113
2 Dec 2026Article 50(2) for legacy systems covered by Article 111(4)Art. 111(4)
2 Aug 2027GPAI models placed on the market before 2 August 2025Art. 111(3)
2 Dec 2027Relevant Annex III high-risk dutiesArt. 113; VO (EU) 2026/1744
2 Aug 2028Relevant Annex I high-risk dutiesArt. 113; VO (EU) 2026/1744

The amendment to the AI Act under Regulation (EU) 2026/1744 has been in force since 27 July 2026. The relevant obligations for Annex III high-risk systems apply from 2 December 2027; those for Annex I high-risk systems apply from 2 August 2028. Regulation (EU) 2026/1744 amending the AI Act European Commission: AI Omnibus enters into force

High-risk classification in the institution

Annex III point 5(b) covers AI systems evaluating the creditworthiness of natural persons or establishing their credit score. Systems used to detect financial fraud are expressly excluded from that category. Classification follows intended purpose and Article 6, rather than the label chatbot or agent. AI Act consolidated as at 27 July 2026

Annex III No. 5(b) therefore covers AI for creditworthiness assessment and credit scoring of natural persons; AI used to detect financial fraud is expressly excluded. Further bank-relevant high-risk cases: Annex III No. 5(c) (risk assessment and pricing for natural persons in life and health insurance) and Annex III No. 4(a) and (b) (AI in employment: recruitment, promotion, dismissal and performance monitoring), which applies to every bank as an employer.

Provider and deployer roles

The AI Act's obligations fall differently on providers and deployers. Provider (Art. 3(3)) means anyone who develops or has developed an AI system and places it on the market under their own name or brand. Deployer (Art. 3(4)) means anyone who uses an AI system under their own responsibility. Where a bank purchases a ready-made AI solution, it is typically the deployer.

The role follows the actual deployment. A bank may deploy an AI system and also incur provider duties when developing a system itself. Sourcing a general-purpose AI model and classifying the resulting system require separate assessments; Article 25 addresses specified role changes for high-risk systems. AI Act consolidated as at 27 July 2026

Key deployer obligations for high-risk AI include: retaining operational logs for at least 6 months under Art. 26(6); informing affected workers before deploying high-risk AI in the workplace under Art. 26(7); and conducting a fundamental rights impact assessment under Art. 27. The latter is expressly required of deployers of Annex III No. 5(b) and No. 5(c) systems before first use.

AI literacy under Article 4

Article 4 requires measures supporting the development of AI literacy among people working with AI systems. Their scope depends on the work and deployment context; the amended wording does not require a guaranteed individual level of competence. AI Act consolidated as at 27 July 2026

The institution should connect tasks and learning needs with the systems actually used. Developers need different content from staff using results in customer-facing work. The selected measures and their delivery should be documented. AI Act consolidated as at 27 July 2026

Transparency under Article 50

Article 50 transparency duties generally apply from 2 August 2026. Article 111(4) provides a transition until 2 December 2026 for providers of specified systems placed on the market before 2 August 2026, limited to machine-readable marking under Article 50(2). Regulation (EU) 2026/1744 amending the AI Act

Article 50 distinguishes several duties. Direct AI interaction generally requires disclosure unless the AI nature is obvious. For text published to inform the public on matters of public interest, paragraph 4 includes an exception involving human review or editorial control and editorial responsibility held by a natural or legal person. Not every AI-generated text therefore requires the same visible label. AI Act consolidated as at 27 July 2026

Integration with existing governance

The AI Act allows specified financial entities to integrate certain duties into existing documentation and governance processes. Each provision has its own scope. The institution needs to assess its conditions and remaining duties for each system. AI Act consolidated as at 27 July 2026

Integration relief clauses for financial institutions in the AI Act (Regulation (EU) 2024/1689)
ArticleContent
Art. 17(4)Relationship between quality management and financial-services law; expressly remaining elements still apply
Art. 18(3), 19(2)Integration of technical documentation and logs into existing documentation duties for covered providers
Art. 26(5), 26(6)Specific rules for monitoring and logs of covered deployers
Art. 74(6)Sectoral market surveillance for covered high-risk AI use

The practical recommendation is therefore: Integrate AI Act requirements into the existing MaRisk and DORA governance rather than building parallel structures and duplicate documentation. The relief clauses presuppose that the existing systems actually function and are documented.

Relationship with DORA, MaRisk and GDPR

For banks, four regulatory frameworks overlap when deploying AI. The table below maps them:

AI Act, DORA, MaRisk and GDPR compared for banks
FrameworkSubject and bank relevanceKey reference
AI Act (Reg. (EU) 2024/1689)Product and deployment rules for AI; credit scoring is high-risk AI (Annex III No. 5(b))Art. 6, Annex III
DORA (Reg. (EU) 2022/2554)Digital operational resilience; the BaFin guidance of 18 December 2025 (BaFin) classifies AI systems as ICT assets within DORA ICT risk management: AI inventory, lifecycle, third-party management (non-binding guidance, not a circular)Article on DORA
MaRisk (Circular 06/2026)Model risk in bank management: current MaRisk module AT 4.3.4 covers the use of models, including data quality, understanding results and validation (Circular 06/2026).Article on MaRisk
GDPRProcessing of personal data; the CJEU held in case C-634/21 of 7 December 2023 (SCHUFA) that even the creation of a score may constitute an automated individual decision under Art. 22 GDPR (EUR-Lex)Art. 22 GDPR, CJEU C-634/21

Key takeaway: the same credit-scoring AI can be subject to all four frameworks simultaneously. The AI Act governs the system and its deployment, DORA the stable IT operations, MaRisk the model risk, the GDPR the data.

Supervisory responsibility in Germany

Germany’s AI Market Surveillance and Innovation Promotion Act has been in force since 29 July 2026. For financial entities, responsibility for a particular AI use must be determined under the sectoral supervisory framework and Article 74 of the AI Act. BMDS: Neues KI-Gesetz tritt in Kraft AI Act consolidated as at 27 July 2026

The EBA's factsheet of 21 November 2025 (PDF, EBA Special Topic) found no material conflicts between the AI Act and banking regulation and sees no immediate need for new EBA guidelines. BaFin has previously published its principles paper of 15 June 2021 on Big Data and Artificial Intelligence and a 2024 BaFinJournal article on AI at banks.

Penalty provisions and responsibilities

Penalty provisions distinguish the infringement and the responsible role. Article 99 principally addresses infringements by providers and deployers; Article 101 sets out the separate procedure for providers of general-purpose AI models. The respective application and transition rules also matter. AI Act consolidated as at 27 July 2026

AI inventory: one editable record per use case

A model list alone does not explain where AI affects the institution. The same model might draft internal text or support a decision about a person. Maintain one record per use case and connect reused systems and models through shared identifiers. The template supports discovery; risk classification must not be inferred from a product name.

Fields for a traceable AI inventory
Field groupWhat to record
Identity and purposeUnique use-case ID, business process, intended use and explicitly excluded uses.
System and roleApplication, model/version, system and model providers, and a reasoned account of your own role.
Data and peopleData categories, sources, affected people, recipients and a reference to the recorded data flow.
ClassificationAssessment of prohibited practices, possible high-risk status and transparency duties, with source, date and rationale.
AccountabilityBusiness owner, operations, human oversight, escalation and approval authority.
EvidenceInstructions, business test cases, output/source checks, access tests and, where applicable, DPIA or fundamental-rights impact assessment.
LifecycleStatus, approved scope, conditions, review date and triggers for reassessment.

A useful first record might describe an internal policy assistant: permitted documents, users, source display, cases receiving no answer and the responsible editorial team. Assess additional obligations against the actual use. A credit-decision workflow must not be classified as low concern by copying that assessment.

Inventory and approval are separate steps. Unresolved legal grounds, missing tests and unclear data flows remain open with an owner and deadline. Reassess the affected record when purpose, model or data sources change.

Legal and professional sources: Europäische Kommission, AI Act Service Desk: Artikel 26, Betreiberpflichten bei Hochrisiko-KI; AI Act: konsolidierte Fassung vom 27.07.2026; BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbank.

Download the AI inventory (Markdown)

Practical checks for institutions

  1. 01Record the system and purpose

    Record the task, processed data and person responsible for deployment.

  2. 02Map role and duties

    For each system, record its purpose, responsible business area, model and system providers, and the bank’s role. Consider development under the bank’s own name and subsequent changes when assigning that role.

  3. 03Support AI literacy

    Article 4 requires measures supporting the development of AI literacy among people working with AI systems. Their scope depends on the work and deployment context; the amended wording does not require a guaranteed individual level of competence.

  4. 04Review existing processes

    Assess each applicable integration rule. MaRisk AT 4.3.4 and DORA do not replace a separate AI Act classification.

  5. 05Check transparency in use

    For each relevant Article 50 duty, identify its implementation and supporting evidence.

  6. 06Prepare high-risk duties

    Add the duties applicable to each system to the implementation plan, with owners and target dates. Use the deadlines and transitions above as the starting point; reassess classification when the intended use changes.

The EBA concludes in its analysis of 21 November 2025 (Factsheet, PDF) that the AI Act operates complementarily to existing banking regulation; it has not identified any material conflicts.

FAQ

Frequently asked questions on the EU AI Act

Does the EU AI Act already apply?

The amendment to the AI Act under Regulation (EU) 2026/1744 has been in force since 27 July 2026. The relevant obligations for Annex III high-risk systems apply from 2 December 2027; those for Annex I high-risk systems apply from 2 August 2028. Article 50 transparency duties generally apply from 2 August 2026. Article 111(4) provides a transition until 2 December 2026 for providers of specified systems placed on the market before 2 August 2026, limited to machine-readable marking under Article 50(2).

Is our credit-scoring system high-risk AI?

Annex III point 5(b) covers AI systems evaluating the creditworthiness of natural persons or establishing their credit score. Systems used to detect financial fraud are expressly excluded from that category. Classification follows intended purpose and Article 6, rather than the label chatbot or agent.

What does the Digital Omnibus change?

The amendment to the AI Act under Regulation (EU) 2026/1744 has been in force since 27 July 2026. The relevant obligations for Annex III high-risk systems apply from 2 December 2027; those for Annex I high-risk systems apply from 2 August 2028. Article 50 transparency duties generally apply from 2 August 2026. Article 111(4) provides a transition until 2 December 2026 for providers of specified systems placed on the market before 2 August 2026, limited to machine-readable marking under Article 50(2).

Who supervises AI in German banks?

Germany’s AI Market Surveillance and Innovation Promotion Act has been in force since 29 July 2026. For financial entities, responsibility for a particular AI use must be determined under the sectoral supervisory framework and Article 74 of the AI Act.

What penalties are at stake for non-compliance?

Penalty provisions distinguish the infringement and the responsible role. Article 99 principally addresses infringements by providers and deployers; Article 101 sets out the separate procedure for providers of general-purpose AI models. The respective application and transition rules also matter.

An offer from T-NEX GmbH

Discuss the project with T-NEX

An AI project needs a defined use case and testable boundaries. T-NEX combines business scoping with evaluation or a limited pilot. Legal classification remains a separate task.

Management: Andreas Unruh and Christoph Gembruch.

Published by T-NEX GmbH.