The European Union’s rules for AI systems that decide who gets credit will not apply on August 2, 2026, the date originally set by Regulation (EU) 2024/1689, the AI Act. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the EU’s Official Journal on July 24 and entered into force on July 27. It pushes the obligations for the standalone high-risk systems listed in Annex III, which include creditworthiness assessment, back to December 2, 2027.
The delay changes the timetable, not the scope. Banks, payment service providers and buy now, pay later (BNPL) platforms still face a regime that will move part of their AI models out of a regulatory gray zone and into a compliance framework close in spirit to the certification of an industrial product: documentation, logging, testing, and human oversight.
The AI Act has applied in stages since it entered into force in 2024. The bans on prohibited practices and the AI literacy duty have applied since February 2025, and the rules for general-purpose AI models since August 2025. The high-risk systems of Annex III were the next and, for finance, the most consequential wave.
Credit scoring is high risk by law
The provision that matters most for payments is point 5(b) of Annex III. It lists as high risk “AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score.” The wording reaches directly into the decision engines that approve or decline a loan, an overdraft or an installment plan in a few milliseconds.
- Consumer credit scoring and automated lending decisions, including for cards and overdraft facilities.
- Buy now, pay later: an engine that grants an installment plan at the point of sale is assessing creditworthiness. BNPL enters the AI Act’s scope just as it moves under consumer credit law.
- Underwriting and pricing in life and health insurance (point 5(c) of Annex III), a closely related use already common at bancassurers.
- Remote biometric identification (point 1), as distinct from simple 1:1 identity verification, which is excluded from the high-risk regime.
Providers and deployers carry different duties
The regulation assigns obligations by role. The provider develops the model and places it on the market. The deployer is the institution that uses it. A bank can be both: a provider for a scoring engine it built in-house, a deployer for one it buys from a vendor.
| Obligation | Provider | Deployer |
|---|---|---|
| Risk and quality management system | Yes, across the full life cycle | Monitors and reports incidents |
| Technical documentation and logging | Yes, available to the authorities | Keeps the logs the system generates |
| Conformity assessment and marking | Yes, before placing on the market | Checks that the system is compliant |
| Registration in the EU database | Yes | In some cases (public-sector deployers in particular) |
| Human oversight and information for individuals | Designs the oversight tools | Ensures effective oversight and informs the person concerned |
In practice, a scoring engine will have to be documented (training data, logic, limitations), logged so each decision can be traced, tested for robustness and for discriminatory bias, and overseen by a person able to understand a decision and, if needed, override it. In its November 2025 analysis, the EBA noted that these requirements largely overlap with existing obligations on model governance, credit explainability and data protection. The AI Act tightens them and makes them enforceable under its own penalty regime.
Payments decisions now run on models
Consumer credit and payments have become heavily algorithmic. Approving an installment plan at checkout, setting a card limit, onboarding a merchant: statistical models now make these calls. By classifying them as high risk, the EU is saying that such decisions govern people’s access to essential services and cannot remain black boxes. The timing is deliberate. BNPL is being brought under consumer credit law, in the UK since July 2026 and in France from November 20, 2026, while the rules for the AI that runs it tighten.
The high-risk regime will not change how a payment is executed. It changes how a firm may decide who gets to pay on credit. The regulation puts creditworthiness under close scrutiny and leaves fraud outside the heavy regime, a distinction that shows precisely what Europe considers a risk to individuals. The extra 16 months buy time, not an exemption. For payment firms, the work ahead is less about reading the text than about proving, with logs and documentation, that their models already comply. Next to watch: the first guidance from national authorities, and the still-unclear division of labor between AI supervisors and financial regulators.