Updated August 2026
Artificial Intelligence is transforming financial services. From credit scoring and fraud detection to customer onboarding, document processing and investment support, AI is becoming an increasingly integral part of how financial institutions operate.
As adoption accelerates, so does the need for clear governance and regulatory compliance.
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) (‘the AI Act’) is the first comprehensive EU legal framework specifically regulating artificial intelligence. For financial institutions operating in the European Union and, in certain circumstances, organisations established outside the EU, the AI Act is no longer a future consideration. Important requirements already apply.
Where do we stand today?
The AI Act applies progressively, with different provisions becoming applicable at different times. Rules on prohibited AI practices and AI literacy are already applicable, as are obligations concerning providers of general-purpose AI (GPAI) models. From 2 August 2026, the transparency obligations under Article 50 also apply.
At the same time, following the Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744, the application of the principal requirements for high-risk AI systems has been deferred:
- 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III; and
- 2 August 2028 for AI systems classified as high-risk under Article 6(1) and Annex I.
The important message for financial institutions is therefore that the AI Act has not simply been postponed. Certain obligations already apply, while the additional implementation period for high-risk systems should be used to identify AI systems, classify relevant use cases and establish appropriate governance and documentation.
Transparency obligations require attention now
Article 50 is particularly relevant now that its transparency obligations apply.
Depending on the AI system and how it is used, these requirements may include informing individuals when they are interacting directly with an AI system and providing appropriate disclosures or markings in relation to certain AI-generated or manipulated content.
Financial institutions should therefore consider whether AI-enabled customer interfaces, content-generation tools or other applications within their operations trigger these requirements and whether appropriate controls and disclosures are in place.
Not every use of AI in financial services is high-risk
The AI Act follows a risk-based approach. Importantly, an AI system is not automatically high-risk simply because it is used by a financial institution or supports a compliance, risk or financial process.
Classification depends primarily on the system’s specific intended purpose and use.
Credit scoring and creditworthiness assessment is one of the clearest financial-services examples. Annex III expressly identifies AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score as high-risk, subject to an exception for systems used solely for detecting financial fraud.
The fraud-detection exception should not, however, be interpreted too broadly. Where a system combines fraud detection with elements of creditworthiness assessment, its classification requires careful and documented analysis.
Other areas requiring particular attention include certain AI systems used in employment and workforce management and AI used for risk assessment and pricing in relation to life and health insurance.
Understanding the institution’s role
Financial institutions should also determine where they sit in the AI value chain.
An institution may be a deployer where it uses a third-party AI system under its authority. However, depending on the circumstances, an organisation that develops an AI system, has one developed, substantially modifies it or changes its intended purpose may assume additional responsibilities under the AI Act.
This is increasingly relevant as institutions use third-party AI and GPAI models for document processing, analytics, customer support and internal decision-support applications.
The use of third-party AI should therefore be considered not only from an AI Act perspective, but also within existing vendor-governance and technology-risk frameworks.
AI literacy is already a governance requirement
AI literacy should not be overlooked while institutions prepare for the later high-risk requirements.
Organisations are already required to take appropriate measures to ensure, to their best extent, a sufficient level of AI literacy among staff and other persons dealing with the operation and use of AI systems on their behalf.
This may require targeted training for employees using AI-enabled tools, senior management and control functions, as well as technology and business teams involved in developing, implementing or monitoring AI systems.
AI literacy should be viewed as an ongoing governance requirement, rather than a one-off training exercise.
AI governance should build on existing frameworks
For financial institutions, AI governance should not be considered in isolation.
Depending on the use case, the AI Act may interact with existing regulatory and internal control frameworks, including:
- GDPR;
- DORA, particularly in relation to ICT risk, resilience and third-party technology dependencies;
- AML/CFT and sanctions frameworks; and
- MiFID II / MiFIR for investment firms and investment services.
The objective should not necessarily be to create an entirely separate AI compliance structure, but to integrate AI-specific responsibilities into existing governance arrangements while ensuring that the requirements of the AI Act remain clearly identifiable.
What should financial institutions do now?
A practical starting point is to:
- create and maintain an AI inventory;
- identify the purpose and functionality of each AI system and relevant AI-enabled use case;
- determine the institution’s role as provider, deployer or other relevant operator;
- classify relevant AI use cases and document the basis for that classification;
- assess whether any Article 50 transparency obligations apply;
- review third-party AI and GPAI dependencies;
- establish appropriate governance, ownership and escalation arrangements;
- implement appropriate AI literacy and training; and
- identify gaps and establish a proportionate remediation roadmap.
The additional implementation period for high-risk AI systems provides institutions with valuable time. It should be used to build the governance framework properly, rather than as a reason to delay implementation.
DKA FINANCIAL CONSULTANTS LTD supports financial institutions in assessing their readiness for the EU AI Act and integrating AI governance within their existing regulatory and control frameworks.
The question is no longer whether AI will become part of financial services – it already is. The challenge is to ensure that it is deployed responsibly, transparently and within an appropriate governance framework.
Early preparation can help financial institutions manage regulatory and operational risk while continuing to benefit from responsible AI innovation.
This article is provided for general informational purposes only and does not constitute, and should not be construed as, professional advice or a formal opinion. Financial institutions should seek qualified legal advice regarding the application of the EU AI Act and other applicable legal and regulatory requirements to their specific AI systems and use cases.











