Guide,

The EU AI Act for Fintechs: What Is High-Risk and What Is Not (2026)

A fintech guide to the EU AI Act's four risk tiers: which lending, hiring and biometric uses are high-risk, which chatbots carry transparency duties, and the dates on which each obligation applies.

A fintech’s AI estate usually splits three ways under the AI Act: a small number of uses that are high-risk, a larger set that carries transparency duties only, and a majority that the regulation leaves alone. The hard part is drawing those lines correctly and putting the right controls in place before each date falls due. This guide sets out the tiers, the fintech uses that fall into each, the obligations that follow, and the order in which to do the work.

How the AI Act sorts risk

The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026, with staged exceptions for particular categories of system. It is built as a risk-based regulation: it sorts AI systems by the harm they could do and attaches obligations to each tier, rather than regulating a technology as such. The AI Act defines four levels of risk for AI systems: unacceptable risk, high risk, transparency risk, and minimal or no risk. For a fintech, classification is the whole exercise. If the tier is right, the obligations follow mechanically. If it is wrong, a firm either over-builds controls for a spam filter or under-builds them for a lending model.

The top tier is a ban. All AI systems considered a clear threat to the safety, livelihoods and rights of people are banned, and the AI Act prohibits nine practices. Prohibited AI practices and AI literacy obligations entered into application from 2 February 2025. A fintech rarely runs anything on the banned list on purpose. The one to watch, in our view, is any design that manipulates users or exploits their vulnerabilities, because behavioural nudging in a consumer app can drift towards that line if nobody is checking the design intent against it.

Which fintech uses are high-risk

AI use cases that can pose serious risks to health, safety or fundamental rights are classified as high-risk. The Commission’s summary lists the areas, and three of them land squarely on a fintech.

The first is lending. The high-risk list includes certain AI use cases used to give access to essential private and public services, and the Commission’s own example is credit scoring that denies a citizen the opportunity to obtain a loan. A model that scores, ranks or declines an applicant for credit should be treated as a candidate for this category. On our reading that reaches affordability models, limit-setting engines and automated pre-approval, wherever the output decides whether a customer gets the product.

The second is people. AI tools for employment, management of workers and access to self-employment, such as CV-sorting software for recruitment, are high-risk. A fintech that screens candidates with an AI tool, or uses AI to allocate shifts or score staff performance, is likely inside this category regardless of what the firm sells.

The third is biometrics. AI systems used for remote biometric identification, emotion recognition and biometric categorisation are high-risk. Most digital onboarding relies on some form of face matching. The question whether a given verification flow counts as remote biometric identification turns on the facts and the legal definitions, and a firm should take legal advice on it rather than assume either answer.

The tools not on the list matter as much. Fraud detection, transaction monitoring, portfolio construction and trading tools do not appear among the Commission’s high-risk examples, so in our reading they are likely to sit outside the high-risk tier unless one of them also acts as the gate to an essential service. A fraud model that silently blocks an account opening could, on that logic, be doing the work of a credit decision, and should be assessed as one.

In our reading, the line for most fintechs runs between the model that decides who gets the loan and the chatbot that explains it.

A working map of fintech uses

Typical fintech use Likely tier Rules apply from
credit scoring, affordability or pre-approval models that decide access to a loan High-risk (Annex III) 2 December 2027
CV screening, worker allocation or performance scoring tools High-risk (Annex III) 2 December 2027
remote biometric identification, emotion recognition, biometric categorisation High-risk (Annex III) 2 December 2027
AI safety component inside a regulated product High-risk (Annex I) 2 August 2028
customer-facing chatbots and virtual assistants Transparency August 2026
generated text, images or audio shown to customers Transparency August 2026
back-office tools such as spam filters, document search and coding assistants Minimal or no risk No AI Act rules
nudging designed to manipulate or exploit vulnerable users Prohibited 2 February 2025

The tier column is a starting position, not a legal conclusion. Each entry should be confirmed against the system’s actual purpose, its output and who it affects.

What high-risk status requires

Starting on 2 December 2027, high-risk AI systems will be subject to strict obligations before they can be put on the market. The Commission’s summary lists seven of them, and together they describe a complete model-governance framework:

  • Adequate risk assessment and mitigation systems.
  • High-quality datasets feeding the system, to minimise the risk of discriminatory outcomes.
  • Logging of activity to ensure traceability of results.
  • Detailed documentation providing all the information authorities need to assess the system’s compliance.
  • Clear and adequate information to the deployer.
  • Appropriate human oversight measures.
  • A high level of robustness, cybersecurity and accuracy.

The duties do not end at launch. After a system is placed on the market, market surveillance falls to the authorities, human oversight and monitoring fall to deployers, and providers must run post-market monitoring. A fintech that builds its own credit model is, in most cases, a provider. A fintech that buys a scoring engine and runs it is, in most cases, a deployer. Many firms are both, across different systems. The role a firm plays for each system is likely to determine which of the duties above it owns outright and which it must obtain evidence of from its vendor.

The transparency tier

Most fintech AI that touches a customer is a chatbot or a generative assistant, and those sit in the transparency tier rather than the high-risk one. Under the Act, people dealing with a chatbot or a similar system must be told that it is a machine, so that they can decide how far to rely on it. The transparency rules of the AI Act come into effect in August 2026. For a fintech this is a disclosure and labelling exercise: tell customers when they are talking to a machine, and make sure generated content that is meant to inform them is identifiable as generated.

A firm that builds on a foundation model inherits a further layer. The AI Act rules on general-purpose AI models became effective in August 2025. Those rules bind the model provider, not the fintech that calls its interface, but a firm should expect its vendor to be able to show how it meets them and should ask before signing.

What the AI Act leaves alone

The AI Act does not introduce rules for AI that is deemed minimal or no risk. The internal productivity tools, document search and spam filtering that most firms run fall here. The right response is not zero governance, because existing outsourcing, data protection and conduct rules still apply to those tools, but it is not AI Act governance either. An inventory that records why each such system is minimal risk is enough to show the reasoning was done.

The dates that matter

From 2 August 2026, the AI Office and authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act. The high-risk obligations for the Annex III use cases, which include credit scoring, employment tools and biometrics, follow on 2 December 2027, as set out above. Rules for high-risk AI systems embedded into regulated products under Annex I have an extended transition period until 2 August 2028. Those two dates were set by the AI Omnibus, the simplification proposal that was adopted on 19 November 2025, reached political agreement on 7 May 2026 and entered into force on 27 July 2026.

The gap between the start of enforcement and the start of the high-risk obligations suggests supervisors are likely to spend the interval on the prohibitions, the transparency duties and general-purpose models, where the rules already bite. It also suggests that a fintech which treats the interval as spare time will likely find that dataset governance and logging cannot be built in the last quarter.

How to implement, in order

  • The first step is an inventory. List every AI system the firm builds, buys or embeds, and record its purpose, its output, who it affects, and whether the firm is provider or deployer for that system.
  • The second step is classification against the four tiers, documented per system, with the reasoning written down and legal advice taken on the marginal cases, such as biometric onboarding and fraud tools that gate access.
  • The third step is a gap assessment for each high-risk system against the seven obligations above. A lending firm is likely to find it already holds model risk documentation; the gaps tend to appear in activity logging, information to deployers and evidence of human oversight.
  • The fourth step is the transparency fixes for chatbots and generated content, because that date arrives first.
  • The fifth step is vendor work: contract terms and evidence requests for every third-party model, covering the provider duties the firm cannot perform itself.
  • The sixth step is training, since the literacy duties already apply and the inventory will show who needs what.

A firm that wants help sequencing that programme can draw on Taft’s AI and automation work, which is built around exactly this classify-then-control sequence.

Questions fintechs ask

Does a firm that only buys AI have obligations? Yes. The deployer carries human oversight and monitoring duties for high-risk systems, and the disclosure duties for chatbots fall on whoever puts the chatbot in front of the customer. Buying rather than building changes which duties a firm owns; it does not remove them.

Is a fraud model high-risk? Fraud detection is not among the Commission’s high-risk examples, so on our reading it is likely to fall outside the tier. The exception is a fraud tool whose output decides whether a customer can open or keep an account, which may be doing the work of an access decision and should be assessed as one.

Is a robo-adviser high-risk? The Commission’s examples do not include investment advice tools, so on our reading they are likely outside the high-risk tier. A firm should still check whether the tool decides access to a product rather than merely recommending one.

Does a firm have until December 2027 to begin? The obligations bite when a high-risk system is placed on the market after that date, and they cover the datasets the model was trained on and the logs it has kept. In our view, both of those take longer to put right than the remaining time suggests, so classification and gap work should start as soon as the inventory exists.

Does the AI Act replace existing rules on outsourcing, data protection and conduct? No. It sits alongside them. A high-risk classification adds obligations; it does not switch off anything a fintech already has to do.

Where Taft helps

Taft works with fintechs to inventory and classify AI systems against the AI Act tiers, and to build the documentation, logging and oversight controls that the high-risk rules require. Through Taft’s AI and automation work, we turn the classification into a programme with owners and dates. Taft does not give legal advice; where a classification turns on a legal definition, we say so and work alongside counsel.

Questions

Is a fintech's credit scoring model high-risk under the AI Act?

In most cases, yes. The AI Act lists AI used to give access to essential private and public services as high-risk, and the Commission's own example is credit scoring that denies a citizen a loan. The high-risk obligations apply from 2 December 2027.

Are customer chatbots high-risk under the AI Act?

No. Chatbots sit in the transparency tier: customers must be made aware that they are interacting with a machine so they can take an informed decision. The transparency rules apply from August 2026.

When do the high-risk rules apply?

From 2 December 2027 for the Annex III use cases, which include credit scoring, employment tools and biometrics, and from 2 August 2028 for high-risk AI embedded in regulated products under Annex I.

Who enforces the AI Act?

From 2 August 2026, the AI Office and the authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act.

Sources

  1. AI Act, European Union

Taft does not provide legal advice. Content is for informational purposes only and subject to regulatory guidance.

Related

Talk it through with an expert.