Why the EU AI Act matters to financial services beyond compliance

Drawing on previously unpublished insights from Zango’s AI governance research, this article examines how financial institutions are using the EU AI Act in practice - as a compliance framework, an internal governance standard and a reference point for wider AI oversight - and what that means for compliance teams now.

The EU AI Act is usually discussed as a regulatory framework which firms inside its scope must comply with. Yet when we interviewed 27 senior risk, compliance and legal practitioners for our research programme on The Future of AI Governance and Compliance in Financial Services, it became apparent that the EU AI Act’s governance impact goes far beyond firms simply adapting to come into compliance with the regime. 

In short, the EU AI Act may matter to financial services not only because of the obligations imposed on different AI systems at different risk levels - but crucially, because firms are adopting its taxonomy and governance architecture as a global internal standard.

What the EU AI Act means for financial services

Before the findings, a short recap of what the regime asks of financial services firms. The Act governs how AI systems are developed, placed on the market and used across the EU, with requirements proportionate to risk.

Two of its high-risk categories specifically relate to financial services: AI used to assess the creditworthiness or credit score of individuals, and AI used for risk assessment and pricing in life and health insurance. Both sit in Annex III, and systems that fall into them face requirements around governance, documentation, data quality, human oversight and monitoring.

Annex III point 5(b) makes creditworthiness and credit scoring systems high-risk “with the exception of AI systems used for the purpose of detecting financial fraud”. That exception does not extend to anti-money laundering or counter-terrorist financing screening.

However, those requirements no longer apply on the original schedule. Delays to harmonised standards, common specifications, guidance and national implementation arrangements raised concerns about whether firms could comply effectively and proportionately on time.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It pushed the Annex III high-risk deadline back to 2 December 2027. AI embedded in regulated products, covered separately under Annex I, has longer still - those obligations don't apply until 2 August 2028.

Transparency obligations were not deferred and have applied since 2 August 2026, so customer-facing chatbots and certain AI-generated and synthetic content are already in scope. Most other financial-services use cases attract no risk-specific requirements under the Act at all, though other regulation still applies to them.

What the classification guidelines changed

It is also worth noting the context that in May 2026, the Commission published draft guidelines clarifying how the AI Act’s high-risk categories should be interpreted. They remain in draft, with final guidelines expected.

For financial services, the main points are:

  • Many common financial-services use cases fall outside the high-risk category, including customer segmentation, marketing, complaints handling, post-origination credit monitoring and collateral valuation.
  • For credit, pricing alone is not high-risk unless it forms part of the same system or integrated process as creditworthiness assessment or credit scoring.
  • Life and health insurance is interpreted broadly, including long-term care, personal pensions and credit life insurance.
  • System design can affect classification: where the same system performs both credit scoring and another function, such as IRB capital calculation, the whole system may be treated as high-risk.

In practice, relatively few of the everyday use cases we hear about most fall into the high-risk category.

How the Act fits with existing financial services regulation

Where use cases do fall into the high-risk classification, it is worth being aware of two key provisions:

  • Articles 17(4) and 26(5) allow regulated financial institutions to satisfy specific AI Act requirements through existing financial-services governance: the quality-management requirement for providers and the monitoring requirement for deployers. Risk management, post-market monitoring and incident reporting are carved out and still need to be addressed separately.
  • Article 74(6) generally places market-surveillance responsibility with the institution’s existing financial supervisory authority, rather than a separate AI authority, where the high-risk system is directly connected with the provision of financial services.

The EBA reached the same conclusion independently, with its November 2025 mapping of the Act against EU banking and payments legislation finding no significant contradictions and no need for new guidance, on the basis that existing controls already cover most of it.

Yet not everything folds into existing governance. Article 27 requires deployers of the Annex III credit scoring and life and health insurance systems to complete a fundamental rights impact assessment (FRIA) before first use, covering the people affected, the specific risks to them, the oversight in place and the complaints route available. A deployer can cross-reference an existing GDPR impact assessment, but the FRIA complements it rather than being satisfied by it, making it the clearest example of the Act adding a distinct exercise rather than mapping onto an existing control.

Even so, a meaningful share of a regulated institution's EU AI Act compliance is already handled by rules it follows as part of other, existing regimes.

What our research uncovered

While the EU AI Act inevitably imposes additional compliance obligations for firms, its significance for financial services is likely to extend well beyond that. Its greater influence may come from the way firms are adopting its risk taxonomy, governance concepts and control architecture as a broader internal standard for AI.

That was a key theme in Zango’s research programme, involving interviews with 27 senior practitioners across legal, risk and compliance. Their responses suggest that firms are already using the Act as a reference point for how AI should be classified, governed and overseen more widely - including in areas that may fall outside its strict legal scope.

1. The Act has become a de facto global baseline, including for firms outside its direct scope

Firms with an EU entity describe getting on top of what is required of them for that entity, then applying the result everywhere.

“We've done the read-across and consciously adopted globally, because we don't want to adopt different standards for each jurisdiction as that creates complexities. Normally when there is a requirement somewhere in the world, every entity aligns to that higher threshold because it's easier to have one common process.”

- Chief Compliance Officer UK at an international digital bank

There is a clear operational reason for this. A Head of Model Risk at a European bank explained: "We are getting flooded with AI governance frameworks from around the world. The way that we try to work is to go to the most prescriptive first and then work from there."

This logic was also reported by firms headquartered outside the EU and by UK subsidiaries of EU banks, for whom the higher EU standard becomes the baseline.

2. One of the Act’s key functions is triage

Practitioners use the Act as a lens inside approval gateways they already run, and extend it to third-party AI, where it provides a shared vocabulary for supplier notifications.

"In that gateway process I talked about, [the] responsible AI committee would be looking at AI use cases basically with the prism of the EU act. It's not enforced, but it's just really helpful to understand, so we can sort of triage between higher and lower risk, or things that we just shouldn't do."

- Head of Legal, UK wealth manager

Other interviewees were sceptical of internally built AI risk ratings that change no downstream decision, one describing the attempt to aggregate an overall AI risk rating as "a Frankenstein monster approach". The Act's classification is valued because it does change a decision.

3. Practitioners preferred principles to prescription

When asked which was preferable between the EU’s prescriptive approach to AI regulation and the UK’s principles-based approach, the dominant objection was the risk of prescriptive rules becoming obsolete.

"You'd get into more trouble if they write a prescriptive rule book now, because frankly, by the time it's printed, it'll be out of date. And I think that's the experience that people are seeing in some of the EU regulations."

- General Counsel, UK wealth manager

A second argument levelled against more prescriptive rules is the capacity to game the system. Specific requirements are easier to engineer around than outcome tests that put the burden of demonstrating good faith on the firm. 

Several interviewees resisted technology-specific rulemaking on principle, asking why this technology and not others, and would prefer supervisory statements with worked examples of good and bad practice. 

While that may seem to sit oddly alongside the first finding - that the Act has become a de facto global baseline - it makes sense because prescription is valued as an internal taxonomy: a written classification, drafted by someone else, that a firm can apply consistently across jurisdictions and point to when a use case needs to be escalated or stopped. 

Principles are preferred as the external standard, because that is what a supervisor will hold the firm to in five years, once the specific rules written today are rendered outdated by the technology.

In other words, firms want a detailed rulebook to run their own governance against, and a flexible supervisor to answer to. 

4. The Act is valued for setting red lines - and the authority they give compliance teams

Where the Act was defended, it was praised for its setting of red lines, which set a floor no individual firm can realistically set on their own.

“Inconsistency between firms creates competitive pressures which may then lead us collectively to kind of sleepwalk into a society we don't quite want to see".

- Group Head of Responsible AI, large UK bank

Participants also welcomed that it provides internal authority, an argument voiced most clearly by legal and second-line respondents. A Head of Legal at a UK wealth manager explained: "I don't have to argue so much for asking difficult questions."

5. There is a live risk that the Act becomes a compliance ceiling

One of the key critiques was that a complete-looking framework stops an organisation asking further questions.

"You can end up [thinking], well, I've got this thing, it's a framework, it's working, it's based on the EU [AI Act], no more thinking, that's it, all done. But we know what's in the AI box. There's more in it than just what's in the act... If it stops organisations from asking questions, then I think they'll get in trouble."

- Head of Legal, UK wealth manager

This risks certain issues not receiving the attention they deserve, such as harms outside the Act's categories, workforce and colleague impacts among them. 

What compliance teams should do now

The research suggests five priorities:

  • Put the global-standard decision in writing now. Several firms already treat the EU standard as an internal taxonomy, applying it beyond the entities formally in scope. The rationale was not always formally documented in our interviews. If the firm chooses to adopt the EU framework beyond its strict legal scope, make that an explicit, owned and minuted governance decision rather than allowing it to emerge informally.
  • Build the classification inventory, or update it in light of the May 2026 draft guidelines, which clarify how some categories should be interpreted. A register covering bought, built and embedded AI, each intended use classified separately, decides which use cases get enhanced review, which get escalated, and which don't proceed. Treat any classification made before the guidelines landed as provisional until it's re-checked, well before the Annex III obligations apply on 2 December 2027.
  • Map the Act onto existing controls before 2 December 2027. Model risk governance, third-party risk, data protection and existing approval processes already cover much of what the Act asks, so the priority should be identifying where genuinely new controls or processes are required. Be explicit about which obligations are already met through existing governance and where gaps remain.
  • Complete the fundamental rights impact assessment before first use, and in any case before 2 December 2027. Unlike many of the other priorities here, the FRIA introduces a distinct assessment requirement, although firms may be able to build on existing impact-assessment processes such as DPIAs rather than starting entirely from scratch.
  • Don't mistake being out of the Act's scope for being out of regulatory scope altogether. Wider issues including workforce impacts can still trigger employment or discrimination law; wider conduct risks can still trigger existing conduct regimes. And even where no rule applies at all, the risk still needs careful consideration, because it's the responsible thing to do.

Classification works best with both lines involved, not one instead of the other. First line, the team closest to the system, should make the initial call, since they understand its intended purpose and how it was built. Second line should then independently review it and be able to challenge it before it's finalised. Document who does which, so the basis for each classification decision is clear, reviewable and capable of being challenged.

Beyond the classification question

Firms still need to establish whether they are acting as provider, deployer, importer or distributor for each system; identify any contractual terms that could change that role; take measures that support AI literacy among staff; and ensure applicable transparency obligations are being met.

But it is clear that the Act’s significance for financial services may depend less on how many systems ultimately fall into its scope than on how widely firms adopt its language, thresholds and governance structure. Our research suggests its most useful role may be as a framework for making decisions inside processes firms already run - provided they continue to test where the framework itself is incomplete.

Zango is the AI compliance layer for financial institutions. Our research programme on The Future of AI Governance and Compliance in Financial Services draws on interviews with senior risk, compliance and legal practitioners across banking, payments, wealth and digital assets. Read the full report.

Continue reading