← Back to News
Regulation

EU delays AI Act credit-scoring rules to December 2027

The AI Act’s high-risk regime for credit scoring was due to apply on August 2, 2026. The Digital Omnibus on AI moved it to December 2, 2027. BNPL scoring and credit decisions stay in scope, fraud detection stays out, and banks and PSPs get 16 more months.

The European Union’s rules for AI systems that decide who gets credit will not apply on August 2, 2026, the date originally set by Regulation (EU) 2024/1689, the AI Act. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the EU’s Official Journal on July 24 and entered into force on July 27. It pushes the obligations for the standalone high-risk systems listed in Annex III, which include creditworthiness assessment, back to December 2, 2027.

The delay changes the timetable, not the scope. Banks, payment service providers and buy now, pay later (BNPL) platforms still face a regime that will move part of their AI models out of a regulatory gray zone and into a compliance framework close in spirit to the certification of an industrial product: documentation, logging, testing, and human oversight.

The AI Act has applied in stages since it entered into force in 2024. The bans on prohibited practices and the AI literacy duty have applied since February 2025, and the rules for general-purpose AI models since August 2025. The high-risk systems of Annex III were the next and, for finance, the most consequential wave.

ℹ️
Several compliance clocks at once
The AI Act never had a single go-live date. Prohibitions have applied since February 2025 and general-purpose AI models since August 2025. The Annex III high-risk obligations, first set for August 2, 2026, now apply from December 2, 2027, and AI built into products covered by EU product-safety law moves from August 2, 2027, to August 2, 2028. High-risk systems already on the market before the rules apply are covered only if their design changes significantly after that date. A single institution may have to run several compliance clocks side by side.

Credit scoring is high risk by law

The provision that matters most for payments is point 5(b) of Annex III. It lists as high risk “AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score.” The wording reaches directly into the decision engines that approve or decline a loan, an overdraft or an installment plan in a few milliseconds.

  • Consumer credit scoring and automated lending decisions, including for cards and overdraft facilities.
  • Buy now, pay later: an engine that grants an installment plan at the point of sale is assessing creditworthiness. BNPL enters the AI Act’s scope just as it moves under consumer credit law.
  • Underwriting and pricing in life and health insurance (point 5(c) of Annex III), a closely related use already common at bancassurers.
  • Remote biometric identification (point 1), as distinct from simple 1:1 identity verification, which is excluded from the high-risk regime.
🔑
Fraud detection stays outside the heavy regime
Point 5(b) carries a decisive carve-out: “with the exception of AI systems used for the purpose of detecting financial fraud.” Lawmakers drew a clear line between AI that judges a person, meaning their creditworthiness, and AI that analyzes a transaction, meaning its legitimacy. The first is high risk. The second stays outside the most demanding regime. PSPs’ fraud engines and transaction risk scoring therefore fall outside the Annex III obligations, although they remain subject to the GDPR and to anti-money laundering rules.
Regulatory documents and a pen on a table
The AI Act leaves payment rules as they are. It adds a layer of product compliance to the models that make credit decisions.

Providers and deployers carry different duties

The regulation assigns obligations by role. The provider develops the model and places it on the market. The deployer is the institution that uses it. A bank can be both: a provider for a scoring engine it built in-house, a deployer for one it buys from a vendor.

ObligationProviderDeployer
Risk and quality management systemYes, across the full life cycleMonitors and reports incidents
Technical documentation and loggingYes, available to the authoritiesKeeps the logs the system generates
Conformity assessment and markingYes, before placing on the marketChecks that the system is compliant
Registration in the EU databaseYesIn some cases (public-sector deployers in particular)
Human oversight and information for individualsDesigns the oversight toolsEnsures effective oversight and informs the person concerned
Main obligations by role (source: Regulation (EU) 2024/1689, Annex III and Chapter III; EBA, Nov. 2025)

In practice, a scoring engine will have to be documented (training data, logic, limitations), logged so each decision can be traced, tested for robustness and for discriminatory bias, and overseen by a person able to understand a decision and, if needed, override it. In its November 2025 analysis, the EBA noted that these requirements largely overlap with existing obligations on model governance, credit explainability and data protection. The AI Act tightens them and makes them enforceable under its own penalty regime.

Dec. 2, 2027
New start date for the Annex III high-risk obligations, originally August 2, 2026
Digital Omnibus on AI, Regulation (EU) 2026/1744
Aug. 2, 2028
New start date for high-risk AI in regulated products, originally August 2, 2027
Digital Omnibus on AI, Regulation (EU) 2026/1744
€35M or 7%
Maximum fine for prohibited practices (fixed amount or share of worldwide turnover, whichever is higher)
AI Act, penalties
€15M or 3%
Maximum fine for breaching the high-risk obligations
AI Act, penalties

Payments decisions now run on models

Consumer credit and payments have become heavily algorithmic. Approving an installment plan at checkout, setting a card limit, onboarding a merchant: statistical models now make these calls. By classifying them as high risk, the EU is saying that such decisions govern people’s access to essential services and cannot remain black boxes. The timing is deliberate. BNPL is being brought under consumer credit law, in the UK since July 2026 and in France from November 20, 2026, while the rules for the AI that runs it tighten.

⚠️
The AI Act sits on top of GDPR, DORA, and PSD3
The AI Act replaces nothing. It adds a layer. A scoring engine remains subject to the GDPR and its Article 22 rules on automated decisions, to credit explainability requirements, to DORA for operational resilience, and soon to the PSD3/PSR framework. The risk for institutions is not an entirely new rule. It is reconciling several overlapping regimes, each with its own authority and timetable. That is where implementation will get hard.
Screen showing data flows and metrics
Documentation, logging, human oversight: credit scoring will have to account for how it works.

The high-risk regime will not change how a payment is executed. It changes how a firm may decide who gets to pay on credit. The regulation puts creditworthiness under close scrutiny and leaves fraud outside the heavy regime, a distinction that shows precisely what Europe considers a risk to individuals. The extra 16 months buy time, not an exemption. For payment firms, the work ahead is less about reading the text than about proving, with logs and documentation, that their models already comply. Next to watch: the first guidance from national authorities, and the still-unclear division of labor between AI supervisors and financial regulators.

Provenance

Published August 1, 2026

5 sources, 5 distinct domains

↗ EU Artificial Intelligence Act · Annex III: High-risk AI systems · artificialintelligenceact.eu↗ European Banking Authority (EBA) · AI Act implications for the EU banking sector (Nov. 2025) · eba.europa.eu↗ K&L Gates · EU and Luxembourg update on the European harmonised rules on artificial intelligence · klgates.com↗ Powens · EU fintech regulations in 2026: nine changes to prepare for (in French) · powens.com↗ Lewis Silkin, “The Digital Omnibus on AI enters into force” (July 27, 2026) · lewissilkin.com
← All news