EU AI Act for fintech and credit-scoring AI
Credit-decisioning, insurance-pricing, and fraud-detection AI under Annex III point 5 — what fintech providers and deployers must do before 2 December 2027.
Financial services is one of the regulatory thickest sectors in Europe, and AI inside fintech now sits at the intersection of the EU AI Act, GDPR, DORA, and existing prudential supervision. Most credit-decisioning and insurance-pricing AI is high-risk under Annex III point 5. This guide is the practical interpretation for fintech vendors and the financial institutions deploying them.
What Annex III point 5 covers
Annex III point 5 — “access to and enjoyment of essential private and public services” — includes:
- Creditworthiness assessment and credit scoring of natural persons (with an explicit carve-out for AI used to detect financial fraud)
- Risk assessment and pricing in life and health insurance
- Public benefits eligibility decisions
- Emergency dispatch and triage AI
The credit-scoring inclusion is the load-bearing one for fintech. Almost every modern lending product uses ML for underwriting, scoring, and pricing. If natural persons are the credit subjects, Annex III applies.
What’s in vs out
| System | Annex III? | |---|---| | Consumer-loan underwriting AI | Yes | | SME loan scoring (where the SME is a natural person, e.g., sole trader) | Yes | | SME loan scoring (incorporated entity only) | Likely no — the natural-person trigger doesn’t fire | | Fraud-detection model flagging suspicious transactions | Explicit carve-out — not Annex III | | Insurance underwriting AI for life or health policies | Yes | | Insurance underwriting for property only | Likely no — Annex III names life and health specifically | | Credit-card pricing AI (interest rate decision) | Yes if natural-person borrower | | Robo-advisor AI for portfolio allocation | Likely no — not creditworthiness | | KYC AI matching IDs to documents | Depends on implementation — simple document-matching may be limited-risk, but KYC involving biometric identification/verification, fraud scoring, eligibility decisions, or customer risk-profiling needs a separate prohibited-practice, Annex III, GDPR, and Article 50 analysis | | AI customer-support chatbot for a bank | Limited risk — Art. 50 disclosure |
The fraud-detection carve-out is important and easy to misread. It applies when the AI’s purpose is detecting fraud, not when the AI happens to incidentally identify fraud while doing something else. A credit-scoring model that occasionally surfaces “this application looks fraudulent” is still credit scoring, not fraud detection — Annex III still applies.
What fintech AI providers owe
If you build credit-scoring or insurance-pricing AI and put it on the EU market from 2 December 2027 (postponed from 2 August 2026 to 2 December 2027 under the Digital Omnibus, agreed May 2026 and pending formal adoption):
- Risk-management system (Art. 9) — including risks to financial inclusion, accuracy across demographic groups, and adverse impact
- Data governance (Art. 10) — examined for bias by gender, age, ethnicity, postcode (a notorious proxy for ethnicity in many EU markets)
- Technical documentation per Annex IV — including the rationale for feature selection, performance benchmarks, and limitations
- Logging (Art. 12) — every decision, every input
- Transparency to deployers (Art. 13) — instructions covering accuracy bounds, intended use, and out-of-scope conditions
- Human oversight design (Art. 14) — the deployer must be able to disagree with or override the AI’s decision
- Accuracy and robustness (Art. 15) — model performance metrics published
- Conformity assessment under Annex VI
- EU database registration under Article 49
- Post-market monitoring under Article 72
- Serious-incident reporting under Article 73
What financial institutions deploying fintech AI owe
As deployers under Article 26, banks, insurers, and lending platforms owe:
- Use the system per the provider’s instructions
- Assign human oversight to a competent named person with authority to override
- Ensure input data is relevant
- Monitor the system for drift
- Retain logs for at least 6 months
- Inform affected persons when a high-risk AI is part of the credit/insurance decision
Plus — important and easy to miss — Article 27 mandates a Fundamental Rights Impact Assessment for financial institutions deploying credit-scoring or insurance-pricing AI. This is one of the few private-sector cases where the FRIA is mandatory. See DPIA vs EU AI Act risk assessment.
The Article 22 GDPR overlap — explicit credit-decisioning exception
GDPR Article 22 prohibits solely-automated decisions with significant effects, but Article 22(2)(a) carves out decisions “necessary for entering into, or performance of, a contract” — which has historically been used to justify automated credit decisions.
Even within the exception, Article 22(3) requires:
- The right to obtain human intervention
- The right to express the data subject’s point of view
- The right to contest the decision
Practically: a fully-automated credit decision is allowed only if the customer can easily request a human review, see the reasoning, and contest the outcome. Burying that right in a privacy policy is not enough.
The DORA interaction
For financial institutions subject to DORA — Digital Operational Resilience Act (Regulation 2022/2554) (applicable from January 2025) — the AI Act stacks on top:
- DORA covers ICT risk management, third-party risk, incident reporting, operational resilience testing
- The AI Act adds AI-specific risk management, AI-specific transparency, AI-specific human oversight
For a fintech using AI in a regulated context, the two regimes overlap on:
- Incident reporting (DORA Art. 19, AI Act Art. 73)
- Third-party risk (DORA Art. 28–30, AI Act Art. 25)
- Operational resilience (DORA Art. 6, AI Act Art. 15)
Build one integrated risk and incident-response programme; document the mapping to both regulations.
What to do this quarter
Fintech vendor:
- Confirm Annex III classification for every AI in your stack — credit, pricing, decisioning, scoring
- Bias evaluation as a deliverable — broken out by protected characteristics
- Adverse-impact analysis — particularly for postcode-based scoring (proxy risk)
- Document the human-oversight design the deployer is expected to implement
- Map your obligations under both AI Act and (if applicable) DORA
Financial institution deployer:
- Demand AI Act compliance evidence from every fintech vendor — risk classification, EU database ID, conformity assessment status
- Identify the human-oversight role for each high-risk system
- Run the FRIA (mandatory under Article 27 for credit/insurance use)
- Update customer disclosures — application UI, contract terms, decision letters
- Brief the supervisory authority if material decisions move to AI-driven workflows
What Maditon is built to do
Track each AI system across both regimes — AI Act and DORA — with a single audit trail. Generate the dossier that satisfies both supervisory authorities. Capture the human-oversight decisions so the audit trail is defensible if a customer contests an outcome.