Does the AI Act apply to your Fintech?
The AI Act (Regulation (EU) 2024/1689) regulates artificial intelligence systems placed on the market or put into service in the European Union. For the fintech sector, the risk classification depends on the specific use case, not on the sector itself. The key question is: what is the AI used for in your product?
Credit scoring (high risk): Annex III, point 5(b) of the AI Act expressly classifies as high-risk AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score. These systems require conformity assessment, technical documentation, registration in the EU database and data governance.
Fraud detection (excluded): Annex III expressly excludes "AI systems used for the purpose of detecting financial fraud". This means payment anti-fraud, AML and KYC systems are not considered high-risk under this route, although they must comply with the general obligations of the AI Act and the GDPR.
Robo-advisory and investment: Automated investment advice is not expressly named as high-risk in Annex III, unless the system is used for one of the listed use cases (credit scoring, insurance 5(c)). It must be analysed case by case.
Payments and AML: AI used in payment services for anti-money laundering is generally not high-risk under Annex III, unless it performs credit scoring or falls under prohibited practices of Art. 5.
Art. 27 FRIA mandatory: Deployers of credit scoring systems under Annex III point 5(b) must carry out a Fundamental Rights Impact Assessment (FRIA), even if they are private entities. This is in addition to the GDPR DPIA.
- Precise classification — We identify whether your system is high-risk, limited or minimal under Annex III
- Art. 27 FRIA — We carry out the mandatory Fundamental Rights Impact Assessment for credit scoring deployers
- Conformity assessment — Technical documentation, EU database registration and data governance
- GDPR coordination — We integrate AI Act and GDPR: FRIA + DPIA in a single process
- Prohibited practices analysis — We verify your AI does not engage in subliminal manipulation (Art. 5(1)(a))
AI Act obligations for high-risk Fintech
If your fintech develops or uses credit scoring systems (Annex III point 5b), the AI Act obligations are as follows:
For providers (developers):
- Risk management system (Art. 9)
- Data quality and training datasets (Art. 10)
- Technical documentation and record-keeping (Art. 11)
- Transparency and information for deployers (Art. 13)
- Human oversight (Art. 14)
- Accuracy, robustness and cybersecurity (Art. 15)
- Conformity assessment before market placement (Art. 6 + Annex III)
- Registration in the EU database (Art. 49)
For deployers (professional users):
- Designate staff with competence and authority for human oversight (Art. 26(2))
- Carry out FRIA — Fundamental Rights Impact Assessment (Art. 27)
- Notify serious incidents to the authority (Art. 73)
- Follow the provider's instructions
- Keep records of use
Timeline: High-risk systems under Annex III must comply before 2 December 2027. Prohibited practices under Art. 5 have been in force since 2 February 2025.
Fines: Up to €35 million or 7% of global turnover for prohibited practices; up to €15 million or 3% for breach of high-risk obligations. For SMEs and startups, the lower absolute amount applies.
AI use cases in Fintech and their classification
| Use case | AI Act classification | Applicable rule |
|---|---|---|
| Credit scoring of natural persons | High risk | Annex III, point 5(b) |
| Financial fraud detection | Not high-risk (excluded) | General obligations + GDPR |
| Robo-advisory / investment advice | Case by case | Individual analysis |
| Anti-money laundering (AML) | Not high-risk (generally) | GDPR + Directive (EU) 2015/849 |
| Customer service chatbots | Limited risk | Art. 50(1) transparency |
| Market sentiment analysis | Minimal (generally) | GDPR |
| Facial recognition for KYC | High-risk or prohibited | Annex III point 1 + Art. 5 |
Real enforcement cases in the financial sector
Although the AI Act has not yet generated fines (the high-risk regime enters into force in December 2027), the AEPD has already sanctioned financial institutions for GDPR breaches affecting AI systems:
- CaixaBank, €6,000,000 (2021) — Breach of Arts. 6, 13 and 14 GDPR in data processing for profiling. Source: EDPB
- BBVA, €5,000,000 (2020) — Breach of Arts. 6 and 13 GDPR. Source: Enforcement Tracker
- CJEU Schufa judgment (C-634/21, 7 Dec 2023) — Credit scoring constitutes an automated decision under Art. 22 GDPR. Source: EUR-Lex
AI Act compliance checklist for Fintech
- Identify all AI systems used in the product
- Classify each system under Annex III (is it credit scoring 5b?)
- Verify no prohibited practices under Art. 5
- Implement risk management system (Art. 9)
- Document training data quality (Art. 10)
- Prepare technical documentation (Art. 11)
- Establish human oversight mechanisms (Art. 14)
- Ensure accuracy, robustness and cybersecurity (Art. 15)
- Carry out conformity assessment (Art. 6 + Annex III)
- Register the system in the EU database (Art. 49)
- Carry out Art. 27 FRIA (credit scoring deployers)
- Integrate FRIA with GDPR DPIA (Art. 35)
- Designate EU representative if not established in the EU (Art. 22)
- Establish serious incident notification procedure (Art. 73)
Official sources
- Regulation (EU) 2024/1689 (AI Act): EUR-Lex
- Annex III (high-risk use cases): AI Act Service Desk
- Art. 5 (prohibited practices): AI Act Service Desk
- Art. 27 (FRIA): AI Act Service Desk
- High-risk classification guidelines (draft): European Commission
- Schufa judgment (C-634/21): EUR-Lex
- AEPD — GDPR compliance for AI processing (2020): AEPD
Related resources
- AI Act Hub — Resource centre on the European AI Regulation
- AI Act Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- AI Act Compliance Checker — Self-assess your AI system
- AI & Data Regulation Service — Integrated advisory
- GDPR for Fintech — Sectoral GDPR guide for fintech
This page is general information, not legal advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.