Skip to content

3 June 2026

EU AI Act for banks: credit scoring, fraud detection, and AI models under new regulatory pressure

conformis

AI in banks was largely unregulated, that is changing fundamentally

Banks have relied on AI for years: credit decisions, fraud detection, anti-money laundering, customer scoring. Nearly every critical function in a modern financial institution today is supported by algorithmic systems. Regulatory oversight of these systems has so far been fragmented and incomplete.

The EU AI Act ends that. From August 2026, binding requirements apply to a broad category of AI systems in the financial sector, with fines of up to €35 million or 7 percent of global annual turnover for violations.

This article explains which AI systems at banks are classified as high-risk, what that means in practice, and what compliance teams need to do now.

The risk classification: which AI systems are affected?

The EU AI Act distinguishes four risk categories.

Prohibited AI practices (in effect since February 2025): social scoring by public authorities, manipulative AI, real-time biometric surveillance in public spaces. Of little relevance to banks in the classic sense, but AI-driven customer segmentation based on personality-psychological profiles can fall into this category.

High-risk AI systems (the main category for banks, fully in effect from August 2026): this is where it gets concrete for financial institutions. The EU AI Act explicitly lists:

  • Systems for creditworthiness assessment and credit decisions
  • AI-driven risk assessment in insurance
  • Systems that affect access to financial services

Broad interpretation also brings in AML risk-scoring systems, fraud detection, automated trade surveillance, and behavior-based risk models.

Limited-risk AI: chatbots and AI-assisted document processing. Transparency obligations apply here.

Minimal risk: spam filters and simple data analysis. No specific obligations apply here.

What high-risk AI specifically requires

From August 2026, the following core obligations apply to all AI systems in the high-risk category.

Risk management system

High-risk AI systems must be accompanied by a documented risk management system throughout their entire lifecycle. That means:

  • Risk identification and assessment before the system is deployed
  • Continuous monitoring of the system in operation
  • Documentation of all identified risks and measures taken
  • Regular review upon system updates or changed conditions of use

Technical documentation and record-keeping

Complete technical documentation must be created and kept up to date for every high-risk system, including:

  • The system's purpose and scope of application
  • A description of the training data used and its origin
  • Metrics on system performance and accuracy
  • Measures to ensure cybersecurity and robustness

Explainability and transparency

Every AI-assisted decision that significantly affects a person, for example a loan rejection, must be explainable, in a way the affected person can understand. That poses a considerable technical challenge for banks: many machine learning models in use, especially deep learning models, are inherently hard to interpret and not easily traceable.

Possible solutions include SHAP values, LIME, or rule-based explanation layers on top of complex models. In any case, explainability must be built into the system and documented.

Human oversight

High-risk AI systems must be designed so that humans can effectively intervene, monitor, and override them when needed. That includes:

  • Clear escalation paths for unusual system outputs
  • Training staff in how to handle AI recommendations
  • Documented processes for manually reviewing AI decisions

Audit trail and logging

All relevant decisions and events must be logged automatically and tamper-proof: when did the system produce which output, what data was it based on, and what human review took place?

The particular challenge: third-party AI

Many banks don't develop their own AI systems but use solutions from third-party providers: credit-scoring models, AML platforms, automated surveillance systems. The EU AI Act distinguishes here between the AI provider (manufacturer) and the deployer.

As deployers, banks have their own independent obligations:

  • Ensuring the system is used as intended
  • Implementing their own monitoring and human oversight
  • Ensuring system outputs are documented in a way that can be reviewed
  • Reporting serious incidents to the competent authority

In other words: even those who buy a ready-made AI solution remain regulatorily responsible.

What compliance teams need to do now

The good news: there's still time until August 2026. The bad news: the preparation work is substantial.

Step 1: Build an AI inventory

Record every AI system used at the institution, both internally developed and third-party solutions. For each system: purpose, provider, area of use, data basis.

Step 2: Carry out risk classification

Assess which risk category each system falls into. Pay particular attention to systems that affect credit decisions, systems that affect customers' access to the market, and systems in the AML space.

Step 3: Gap analysis against high-risk requirements

For every system classified as high-risk, check which statutory requirements are already met and where gaps exist in documentation, explainability, human oversight, and audit trail.

Step 4: Create or complete technical documentation

Create the legally required technical documentation for every high-risk system. It must be complete before the system is deployed.

Step 5: Build governance structures

Define clear responsibilities for AI compliance at the institution. Who owns ongoing monitoring? Who decides on the deployment of new AI systems?

BaFin's perspective

BaFin is positioned as the competent supervisory authority for overseeing the EU AI Act in the German financial sector. It has already signaled that AI governance will be integrated into regular examination practice, similar to how ICT requirements were integrated through DORA.

BaFin pays particular attention to how the EU AI Act interacts with existing requirements such as DORA for technical robustness, MaRisk for governance, and BaFin's own guidance on explainable AI. These frameworks overlap, and banks need to ensure their systems meet all requirements at once.

Conclusion

The EU AI Act is not an abstract AI ethics law. It is a concrete, examination-relevant regulation with direct relevance to the core operations of every bank. Credit scoring, fraud detection, and AML systems will be assessed against strict standards from August 2026.

Institutions that start now with a complete AI inventory, a clear risk classification, and documented governance processes will meet the requirements in time. Institutions that wait risk fines and the loss of their most important systems.

conformis supports the structured mapping of EU AI Act requirements onto existing systems and processes, with full source attribution and a complete audit trail for every compliance statement.

Back to overview

See in 15 minutes where you stand.

Live, against your own policies, no obligation.