The AI Act connects duties to an AI system’s purpose and the role of the organisation involved. The same technical platform can therefore require different treatment in a bank depending on whether it searches documents or evaluates a person’s creditworthiness. The July 2026 amendment changed the application dates for high-risk systems.
The AI Act and its scope
The AI Act, Regulation (EU) 2024/1689, regulates AI systems and specified duties for general-purpose AI models. It has been in force since 1 August 2024, with duties applying in stages. An institution’s assessment starts with the intended use and its own role. AI Act consolidated as at 27 July 2026
The social-scoring prohibition in Article 5 is not limited to public authorities. Its application depends on the assessment and adverse-treatment conditions set out in that provision. Annex III point 5(b) covers AI systems evaluating the creditworthiness of natural persons or establishing their credit score. Systems used to detect financial fraud are expressly excluded from that category. Classification follows intended purpose and Article 6, rather than the label chatbot or agent. AI Act consolidated as at 27 July 2026
The role follows the actual deployment. A bank may deploy an AI system and also incur provider duties when developing a system itself. Sourcing a general-purpose AI model and classifying the resulting system require separate assessments; Article 25 addresses specified role changes for high-risk systems. AI Act consolidated as at 27 July 2026
Current application dates
The table shows key application stages. The July 2026 amendment is already in force. Regulation (EU) 2026/1744 amending the AI Act
| Date | Content | Legal basis |
|---|---|---|
| 1 Aug 2024 | AI Act enters into force | Art. 113 |
| 2 Feb 2025 | First prohibitions and AI-literacy duties | Art. 4, 5, 113 |
| 2 Aug 2025 | General application of GPAI duties to new models | Art. 111, 113 |
| 2 Aug 2026 | General application, including Article 50; specific transitions remain relevant | Art. 50, 111, 113 |
| 2 Dec 2026 | Article 50(2) for legacy systems covered by Article 111(4) | Art. 111(4) |
| 2 Aug 2027 | GPAI models placed on the market before 2 August 2025 | Art. 111(3) |
| 2 Dec 2027 | Relevant Annex III high-risk duties | Art. 113; VO (EU) 2026/1744 |
| 2 Aug 2028 | Relevant Annex I high-risk duties | Art. 113; VO (EU) 2026/1744 |
The amendment to the AI Act under Regulation (EU) 2026/1744 has been in force since 27 July 2026. The relevant obligations for Annex III high-risk systems apply from 2 December 2027; those for Annex I high-risk systems apply from 2 August 2028. Regulation (EU) 2026/1744 amending the AI Act European Commission: AI Omnibus enters into force
High-risk classification in the institution
Annex III point 5(b) covers AI systems evaluating the creditworthiness of natural persons or establishing their credit score. Systems used to detect financial fraud are expressly excluded from that category. Classification follows intended purpose and Article 6, rather than the label chatbot or agent. AI Act consolidated as at 27 July 2026
Annex III No. 5(b) therefore covers AI for creditworthiness assessment and credit scoring of natural persons; AI used to detect financial fraud is expressly excluded. Further bank-relevant high-risk cases: Annex III No. 5(c) (risk assessment and pricing for natural persons in life and health insurance) and Annex III No. 4(a) and (b) (AI in employment: recruitment, promotion, dismissal and performance monitoring), which applies to every bank as an employer.
Provider and deployer roles
The AI Act's obligations fall differently on providers and deployers. Provider (Art. 3(3)) means anyone who develops or has developed an AI system and places it on the market under their own name or brand. Deployer (Art. 3(4)) means anyone who uses an AI system under their own responsibility. Where a bank purchases a ready-made AI solution, it is typically the deployer.
The role follows the actual deployment. A bank may deploy an AI system and also incur provider duties when developing a system itself. Sourcing a general-purpose AI model and classifying the resulting system require separate assessments; Article 25 addresses specified role changes for high-risk systems. AI Act consolidated as at 27 July 2026
Key deployer obligations for high-risk AI include: retaining operational logs for at least 6 months under Art. 26(6); informing affected workers before deploying high-risk AI in the workplace under Art. 26(7); and conducting a fundamental rights impact assessment under Art. 27. The latter is expressly required of deployers of Annex III No. 5(b) and No. 5(c) systems before first use.
AI literacy under Article 4
Article 4 requires measures supporting the development of AI literacy among people working with AI systems. Their scope depends on the work and deployment context; the amended wording does not require a guaranteed individual level of competence. AI Act consolidated as at 27 July 2026
The institution should connect tasks and learning needs with the systems actually used. Developers need different content from staff using results in customer-facing work. The selected measures and their delivery should be documented. AI Act consolidated as at 27 July 2026
Transparency under Article 50
Article 50 transparency duties generally apply from 2 August 2026. Article 111(4) provides a transition until 2 December 2026 for providers of specified systems placed on the market before 2 August 2026, limited to machine-readable marking under Article 50(2). Regulation (EU) 2026/1744 amending the AI Act
Article 50 distinguishes several duties. Direct AI interaction generally requires disclosure unless the AI nature is obvious. For text published to inform the public on matters of public interest, paragraph 4 includes an exception involving human review or editorial control and editorial responsibility held by a natural or legal person. Not every AI-generated text therefore requires the same visible label. AI Act consolidated as at 27 July 2026
Integration with existing governance
The AI Act allows specified financial entities to integrate certain duties into existing documentation and governance processes. Each provision has its own scope. The institution needs to assess its conditions and remaining duties for each system. AI Act consolidated as at 27 July 2026
| Article | Content |
|---|---|
| Art. 17(4) | Relationship between quality management and financial-services law; expressly remaining elements still apply |
| Art. 18(3), 19(2) | Integration of technical documentation and logs into existing documentation duties for covered providers |
| Art. 26(5), 26(6) | Specific rules for monitoring and logs of covered deployers |
| Art. 74(6) | Sectoral market surveillance for covered high-risk AI use |
The practical recommendation is therefore: Integrate AI Act requirements into the existing MaRisk and DORA governance rather than building parallel structures and duplicate documentation. The relief clauses presuppose that the existing systems actually function and are documented.
Relationship with DORA, MaRisk and GDPR
For banks, four regulatory frameworks overlap when deploying AI. The table below maps them:
| Framework | Subject and bank relevance | Key reference |
|---|---|---|
| AI Act (Reg. (EU) 2024/1689) | Product and deployment rules for AI; credit scoring is high-risk AI (Annex III No. 5(b)) | Art. 6, Annex III |
| DORA (Reg. (EU) 2022/2554) | Digital operational resilience; the BaFin guidance of 18 December 2025 (BaFin) classifies AI systems as ICT assets within DORA ICT risk management: AI inventory, lifecycle, third-party management (non-binding guidance, not a circular) | Article on DORA |
| MaRisk (Circular 06/2026) | Model risk in bank management: current MaRisk module AT 4.3.4 covers the use of models, including data quality, understanding results and validation (Circular 06/2026). | Article on MaRisk |
| GDPR | Processing of personal data; the CJEU held in case C-634/21 of 7 December 2023 (SCHUFA) that even the creation of a score may constitute an automated individual decision under Art. 22 GDPR (EUR-Lex) | Art. 22 GDPR, CJEU C-634/21 |
Key takeaway: the same credit-scoring AI can be subject to all four frameworks simultaneously. The AI Act governs the system and its deployment, DORA the stable IT operations, MaRisk the model risk, the GDPR the data.
Supervisory responsibility in Germany
Germany’s AI Market Surveillance and Innovation Promotion Act has been in force since 29 July 2026. For financial entities, responsibility for a particular AI use must be determined under the sectoral supervisory framework and Article 74 of the AI Act. BMDS: Neues KI-Gesetz tritt in Kraft AI Act consolidated as at 27 July 2026
The EBA's factsheet of 21 November 2025 (PDF, EBA Special Topic) found no material conflicts between the AI Act and banking regulation and sees no immediate need for new EBA guidelines. BaFin has previously published its principles paper of 15 June 2021 on Big Data and Artificial Intelligence and a 2024 BaFinJournal article on AI at banks.
Penalty provisions and responsibilities
Penalty provisions distinguish the infringement and the responsible role. Article 99 principally addresses infringements by providers and deployers; Article 101 sets out the separate procedure for providers of general-purpose AI models. The respective application and transition rules also matter. AI Act consolidated as at 27 July 2026
AI inventory: one editable record per use case
A model list alone does not explain where AI affects the institution. The same model might draft internal text or support a decision about a person. Maintain one record per use case and connect reused systems and models through shared identifiers. The template supports discovery; risk classification must not be inferred from a product name.
| Field group | What to record |
|---|---|
| Identity and purpose | Unique use-case ID, business process, intended use and explicitly excluded uses. |
| System and role | Application, model/version, system and model providers, and a reasoned account of your own role. |
| Data and people | Data categories, sources, affected people, recipients and a reference to the recorded data flow. |
| Classification | Assessment of prohibited practices, possible high-risk status and transparency duties, with source, date and rationale. |
| Accountability | Business owner, operations, human oversight, escalation and approval authority. |
| Evidence | Instructions, business test cases, output/source checks, access tests and, where applicable, DPIA or fundamental-rights impact assessment. |
| Lifecycle | Status, approved scope, conditions, review date and triggers for reassessment. |
A useful first record might describe an internal policy assistant: permitted documents, users, source display, cases receiving no answer and the responsible editorial team. Assess additional obligations against the actual use. A credit-decision workflow must not be classified as low concern by copying that assessment.
Inventory and approval are separate steps. Unresolved legal grounds, missing tests and unclear data flows remain open with an owner and deadline. Reassess the affected record when purpose, model or data sources change.
Legal and professional sources: Europäische Kommission, AI Act Service Desk: Artikel 26, Betreiberpflichten bei Hochrisiko-KI; AI Act: konsolidierte Fassung vom 27.07.2026; BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbank.
Download the AI inventory (Markdown)
Practical checks for institutions
01Record the system and purpose
Record the task, processed data and person responsible for deployment.
02Map role and duties
For each system, record its purpose, responsible business area, model and system providers, and the bank’s role. Consider development under the bank’s own name and subsequent changes when assigning that role.
03Support AI literacy
Article 4 requires measures supporting the development of AI literacy among people working with AI systems. Their scope depends on the work and deployment context; the amended wording does not require a guaranteed individual level of competence.
04Review existing processes
Assess each applicable integration rule. MaRisk AT 4.3.4 and DORA do not replace a separate AI Act classification.
05Check transparency in use
For each relevant Article 50 duty, identify its implementation and supporting evidence.
06Prepare high-risk duties
Add the duties applicable to each system to the implementation plan, with owners and target dates. Use the deadlines and transitions above as the starting point; reassess classification when the intended use changes.
The EBA concludes in its analysis of 21 November 2025 (Factsheet, PDF) that the AI Act operates complementarily to existing banking regulation; it has not identified any material conflicts.
- DORA Regulation (EU) 2022/2554: AI systems as ICT assets in the DORA framework; BaFin guidance of 18 December 2025.
- MaRisk: current version Circular 06/2026: Module AT 4.3.4 "Models" and its relation to high-risk AI classification.
- Regulatory roadmap 2026 to 2028+: all banking regulation deadlines in annual tables, including AI Act stages.
Frequently asked questions on the EU AI Act
Sources & further reading
- Regulation (EU) 2024/1689 (AI Act), official full text on EUR-Lexeur-lex.europa.eu
- German Bundestag, resolution on AI Implementation Act, 11 June 2026bundestag.de
- BaFin, principles paper "Big Data and Artificial Intelligence" (15 June 2021)bafin.de
- BaFin, BaFinJournal "AI at banks and insurers: Automatically fair?" (2024)bafin.de
- BaFin, announcement of 18 December 2025 on the guidance note on ICT risks from AIbafin.de
- BaFin, guidance note on ICT risks from the use of AI (PDF)bafin.de
- EBA, Factsheet "AI Act: implications for the EU banking and payments sector" (21 November 2025, PDF)eba.europa.eu
- EBA, Special Topic "Artificial Intelligence"eba.europa.eu
- BaFin: Circular 06/2026 (BA), MaRisk of 30 June 2026bafin.de
- CJEU, judgment of 7 December 2023, C-634/21 (SCHUFA), EUR-Lexeur-lex.europa.eu
- AI Act consolidated as at 27 July 2026eur-lex.europa.eu
- Regulation (EU) 2026/1744 amending the AI Acteur-lex.europa.eu
- European Commission: AI Omnibus enters into forcedigital-strategy.ec.europa.eu
- BMDS: Neues KI-Gesetz tritt in Kraftbmds.bund.de
- Europäische Kommission, AI Act Service Desk: Artikel 26, Betreiberpflichten bei Hochrisiko-KIai-act-service-desk.ec.europa.eu
- BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbankbundesbank.de
An offer from T-NEX GmbH
Discuss the project with T-NEX
An AI project needs a defined use case and testable boundaries. T-NEX combines business scoping with evaluation or a limited pilot. Legal classification remains a separate task.
Management: Andreas Unruh and Christoph Gembruch.
Published by T-NEX GmbH.
