EU AI Act raises compliance stakes for financial services
The EU AI Act brings a risk-based framework for governing AI and applies beyond EU borders to any company that provides or uses AI services or products in the EU, including B2B AI services provided to or used by EU citizens. The EU AI Act entered into force on August 1, 2024, and rules related to high-risk systems start coming into play on August 2, 2026. Non-compliance can trigger fines up to 7% of global annual turnover or €35 million, whichever is greater.
Financial institutions face a broad compliance burden because AI is already embedded in fraud and money-laundering detection, customer due diligence, credit scoring, algorithmic trading, asset management decisioning, insurance underwriting and robo-advisors. All AI systems must be risk-assessed and entered into an AI inventory. High-risk systems require conformity assessments, technical documentation, lifecycle risk management, logs, clear user information, post-deployment monitoring and incident reporting.
Providers must ensure systems comply before release, while deployers must use high-risk systems as intended, manage risks, ensure appropriate data use, maintain human oversight where required and report serious problems. Financial institutions should map the Act to existing controls, train staff, classify internal and third-party systems, review documentation, evaluate datasets and plan customer communications.