Use case · Annex III point 5

The EU AI Act for fintech AI

If your model decides whether a person gets money, you're named in Annex III. If it evaluates businesses or detects fraud, you're probably not — the line between those decides everything.

Last updated 8 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

Fintech is one of the few sectors named directly in the EU AI Act's high-risk list. Annex III, point 5 covers AI that evaluates creditworthiness or establishes a credit score, and AI used for risk assessment and pricing in life and health insurance. If your model decides — or materially influences — whether a person gets money, that's the category you're in.

But "fintech" spans everything from consumer credit scoring to B2B invoice tooling, and the Act treats those completely differently. The dividing line, as everywhere in this regulation: is a natural person the subject of the evaluation?

Where fintech AI lands

SystemLikely tierWhy
Consumer credit scoring / loan decisioningHigh-riskAnnex III 5(b) — the named case. Profiles individuals, so no 6(3) exit
Life / health insurance risk pricingHigh-riskAnnex III 5(c), explicitly listed
Fraud detection on transactionsUsually not high-riskAnnex III 5(b) carves out AI for detecting financial fraud — one of the few explicit exemptions in the Act
AML / transaction monitoringContext-dependentAnalysing transactions is fine; scoring customers as risks starts to look like profiling — document the position
B2B credit / invoice risk (companies only)MinimalEvaluating a business is not evaluating a natural person — sole traders blur this, check your book
Robo-advisory, PFM, chat supportLimitedArticle 50 disclosure, live now; investment advice isn't an Annex III area
Internal ops copilotsMinimalArticle 4 literacy, little else

Two traps worth naming. "Materially influences" counts as deciding — a model that only "recommends" approval, where officers follow it 95% of the time, is doing the deciding for Annex III purposes. And the fraud-detection carve-out is narrow: it covers detecting fraud, not repurposing the same model to score creditworthiness "while we're at it". Same model, new purpose, new classification.

If you're high-risk: the 2027 workplan

Provider obligations land 2 December 2027: risk management (Art 9), data governance with bias examination (Art 10 — acute for credit, where training on historical lending decisions reproduces historical lending discrimination), technical documentation, logging, human-oversight design (Art 14 — an officer must be able to understand and override, not just click approve), accuracy and robustness evidence, conformity assessment, CE marking, registration. Realistically 12–18 months of work — December 2027 means starting in 2026, which is the point most fintech teams are currently missing.

Banks and licensed institutions get one structural break: much of this can be integrated into governance you already run under CRD/Solvency — model risk management, internal audit, documentation discipline. For regulated institutions the Act is largely a formalisation of existing model governance. For unregulated lending startups it's a new spine, and the longer pole.

Already enforceable, already overlapping

Since 2 August 2026: Article 50 — your customer-facing bot discloses it's AI; Article 4 — recorded AI literacy for staff running the models; Article 5 — no social scoring, no emotion recognition on staff or customers in prohibited contexts.

And running alongside, with no grace period: GDPR Article 22 — a declined applicant's right to human review of an automated credit decision (coordinate with Art 14 oversight, solve once); DPIA — near-certain for credit scoring, feeds Article 9 directly; and consumer-credit rules that already require decisions you can explain. The overlaps are where the work compounds — or where it halves, if you sequence it.

Where to start

The free two-minute check confirms the tier per system. If you're in credit or insurance pricing, the near-term deliverables are: the role question in writing (provider or deployer — bank-vendor relationships make this genuinely contested), the disclosure fix if a bot talks to customers, the literacy session, and a dated position paper — because your next enterprise partnership, your regulator, or your Series A due diligence will ask for exactly that. The full report produces it referenced to your actual product, with the correct post-Omnibus dates.

Check your model's tier in two minutes

Credit, insurance, fraud or B2B — the free check places it. The full report maps the 2027 workplan with the correct post-Omnibus dates.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.