AI Act · Fintech

AI Act for Fintech: Credit Scoring, Fraud and Compliance

Regulation (EU) 2024/1689 classifies credit scoring as a high-risk AI system (Annex III, point 5b). Learn the specific obligations for your fintech, the fraud detection exclusion, the Art. 27 FRIA and applicable fines.

Does the AI Act apply to your Fintech?

The AI Act (Regulation (EU) 2024/1689) regulates artificial intelligence systems placed on the market or put into service in the European Union. For the fintech sector, the risk classification depends on the specific use case, not on the sector itself. The key question is: what is the AI used for in your product?

Credit scoring (high risk): Annex III, point 5(b) of the AI Act expressly classifies as high-risk AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score. These systems require conformity assessment, technical documentation, registration in the EU database and data governance.

Fraud detection (excluded): Annex III expressly excludes "AI systems used for the purpose of detecting financial fraud". This means payment anti-fraud, AML and KYC systems are not considered high-risk under this route, although they must comply with the general obligations of the AI Act and the GDPR.

Robo-advisory and investment: Automated investment advice is not expressly named as high-risk in Annex III, unless the system is used for one of the listed use cases (credit scoring, insurance 5(c)). It must be analysed case by case.

Payments and AML: AI used in payment services for anti-money laundering is generally not high-risk under Annex III, unless it performs credit scoring or falls under prohibited practices of Art. 5.

Art. 27 FRIA mandatory: Deployers of credit scoring systems under Annex III point 5(b) must carry out a Fundamental Rights Impact Assessment (FRIA), even if they are private entities. This is in addition to the GDPR DPIA.

  • Precise classification — We identify whether your system is high-risk, limited or minimal under Annex III
  • Art. 27 FRIA — We carry out the mandatory Fundamental Rights Impact Assessment for credit scoring deployers
  • Conformity assessment — Technical documentation, EU database registration and data governance
  • GDPR coordination — We integrate AI Act and GDPR: FRIA + DPIA in a single process
  • Prohibited practices analysis — We verify your AI does not engage in subliminal manipulation (Art. 5(1)(a))

AI Act obligations for high-risk Fintech

If your fintech develops or uses credit scoring systems (Annex III point 5b), the AI Act obligations are as follows:

For providers (developers):

  • Risk management system (Art. 9)
  • Data quality and training datasets (Art. 10)
  • Technical documentation and record-keeping (Art. 11)
  • Transparency and information for deployers (Art. 13)
  • Human oversight (Art. 14)
  • Accuracy, robustness and cybersecurity (Art. 15)
  • Conformity assessment before market placement (Art. 6 + Annex III)
  • Registration in the EU database (Art. 49)

For deployers (professional users):

  • Designate staff with competence and authority for human oversight (Art. 26(2))
  • Carry out FRIA — Fundamental Rights Impact Assessment (Art. 27)
  • Notify serious incidents to the authority (Art. 73)
  • Follow the provider's instructions
  • Keep records of use

Timeline: High-risk systems under Annex III must comply before 2 December 2027. Prohibited practices under Art. 5 have been in force since 2 February 2025.

Fines: Up to €35 million or 7% of global turnover for prohibited practices; up to €15 million or 3% for breach of high-risk obligations. For SMEs and startups, the lower absolute amount applies.

AI use cases in Fintech and their classification

Use caseAI Act classificationApplicable rule
Credit scoring of natural personsHigh riskAnnex III, point 5(b)
Financial fraud detectionNot high-risk (excluded)General obligations + GDPR
Robo-advisory / investment adviceCase by caseIndividual analysis
Anti-money laundering (AML)Not high-risk (generally)GDPR + Directive (EU) 2015/849
Customer service chatbotsLimited riskArt. 50(1) transparency
Market sentiment analysisMinimal (generally)GDPR
Facial recognition for KYCHigh-risk or prohibitedAnnex III point 1 + Art. 5

Real enforcement cases in the financial sector

Although the AI Act has not yet generated fines (the high-risk regime enters into force in December 2027), the AEPD has already sanctioned financial institutions for GDPR breaches affecting AI systems:

  • CaixaBank, €6,000,000 (2021) — Breach of Arts. 6, 13 and 14 GDPR in data processing for profiling. Source: EDPB
  • BBVA, €5,000,000 (2020) — Breach of Arts. 6 and 13 GDPR. Source: Enforcement Tracker
  • CJEU Schufa judgment (C-634/21, 7 Dec 2023) — Credit scoring constitutes an automated decision under Art. 22 GDPR. Source: EUR-Lex

AI Act compliance checklist for Fintech

  • Identify all AI systems used in the product
  • Classify each system under Annex III (is it credit scoring 5b?)
  • Verify no prohibited practices under Art. 5
  • Implement risk management system (Art. 9)
  • Document training data quality (Art. 10)
  • Prepare technical documentation (Art. 11)
  • Establish human oversight mechanisms (Art. 14)
  • Ensure accuracy, robustness and cybersecurity (Art. 15)
  • Carry out conformity assessment (Art. 6 + Annex III)
  • Register the system in the EU database (Art. 49)
  • Carry out Art. 27 FRIA (credit scoring deployers)
  • Integrate FRIA with GDPR DPIA (Art. 35)
  • Designate EU representative if not established in the EU (Art. 22)
  • Establish serious incident notification procedure (Art. 73)

Official sources


This page is general information, not legal advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.

Featured Services

Frequently Asked Questions

Is credit scoring always high-risk under the AI Act?

Yes. Annex III, point 5(b) of the AI Act expressly classifies as high-risk AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score. It does not matter whether the fintech is the provider or the deployer: both have obligations. The only express exclusion in this point is financial fraud detection, which is not considered high-risk under this route.

Is fraud detection subject to the AI Act?

Annex III point 5(b) expressly excludes 'AI systems used for the purpose of detecting financial fraud'. This means payment anti-fraud, AML and KYC systems are not considered high-risk under this route. However, they must comply with the general obligations of the AI Act (Art. 50 transparency if chatbots are used, no prohibited practices under Art. 5) and the GDPR.

What is the FRIA and when is it mandatory for a fintech?

The FRIA (Fundamental Rights Impact Assessment, Art. 27) is a mandatory assessment for deployers of high-risk systems under Annex III. For fintech, it is mandatory when deploying credit scoring systems (5b) or life and health insurance systems (5c). It must identify the groups of people affected, the specific risks to their fundamental rights and the mitigation measures. It is additional to the GDPR DPIA.

When do high-risk obligations for fintech enter into force?

High-risk systems under Annex III must comply before 2 December 2027. Prohibited practices under Art. 5 have been in force since 2 February 2025. Transparency obligations under Art. 50 (chatbots, deepfakes) enter into force on 2 August 2026. It is advisable to start compliance early, especially technical documentation and FRIA.

Can a non-EU fintech market AI in Europe?

Yes, but it must designate an authorised representative in a Member State (Art. 22) before placing its systems on the EU market. The representative acts before national supervisory authorities and is responsible for compliance. A2 Estudio Legal offers this AI Act representative service for non-European fintech.

What fines does the AI Act provide for fintech?

Maximum fines are: up to €35 million or 7% of global annual turnover for prohibited practices (Art. 5); up to €15 million or 3% for breach of high-risk obligations; up to €7.5 million or 1.5% for incorrect information to authorities. For SMEs and startups, the lower absolute amount applies. Fines are imposed by the competent national authority (AESIA in Spain).

How does the AI Act relate to the GDPR in credit scoring?

Both regulations apply simultaneously. The AI Act regulates the AI system (the product), while the GDPR regulates the processing of personal data (the rights). The CJEU confirmed in the Schufa case (C-634/21, 2023) that credit scoring constitutes an automated decision under Art. 22 GDPR. Compliance with the AI Act does not exempt from the GDPR. Both regulations require assessments (FRIA and DPIA) that can be integrated.

Which authority supervises the AI Act in Spain for fintech?

The AESIA (Spanish Agency for the Supervision of Artificial Intelligence) is the competent authority in Spain. At European level, the European AI Office coordinates enforcement between Member States. The AEPD intervenes when there is intersection with the GDPR (processing of personal data). In cross-border cases, cooperation between authorities is channelled through the EDPB.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us