Banking AI Under the EU AI Act
Credit scoring and creditworthiness assessment AI is explicitly listed in Annex III as high-risk. For banks, this affects the core of their business: lending decisions, risk modelling, anti-money laundering, and increasingly, customer onboarding. The EU AI Act adds a layer of regulation on top of existing EBA guidelines and ECB supervisory expectations.
High-Risk Banking AI Systems
Annex III Category 5(b): Creditworthiness
- Credit scoring models: ML models that determine credit scores for consumer and commercial lending — directly affects access to financial services
- Loan approval/rejection: Automated or semi-automated lending decisions
- Pricing models: Risk-based pricing using ML — interest rates set by algorithmic assessment
- Limit management: AI-driven credit limit adjustments (credit cards, overdrafts)
Other High-Risk Banking AI
- AML/CFT screening: Transaction monitoring and suspicious activity detection — false positives deny service, false negatives enable money laundering
- KYC automation: AI-driven identity verification and customer risk assessment
- Internal risk models: IRB approach models using ML — ECB already supervises these under CRD/CRR
- Fraud detection: Real-time transaction fraud scoring
Key Compliance Requirements for Banks
Explainability (Art. 13 + ECB Guide on AI)
Banks face dual explainability requirements:
- EU AI Act Art. 13: Transparency — deployers must understand AI system capabilities, limitations, and accuracy levels
- ECB supervisory expectations: Banks must be able to explain model decisions to supervisors. "The model says so" is not acceptable.
- Consumer rights: Under GDPR Art. 22, individuals have the right to an explanation of automated decisions. Combined with EU AI Act, this means lending decisions must be explainable at individual level.
- Practical implication: Black-box models (deep neural networks) are problematic for credit scoring. Interpretable models (logistic regression, gradient boosting with SHAP) are preferred by regulators.
Bias & Fairness Testing
- Protected characteristics: Gender, race, ethnicity, religion, disability — credit models must not discriminate directly or indirectly
- Proxy variable detection: Postcode, employer, shopping behaviour can be proxies for protected characteristics
- Testing methodology: Adverse impact ratio testing, equalised odds, demographic parity — choose metrics appropriate to the use case
- EBA/ECB alignment: EBA guidelines on loan origination already require non-discrimination in lending — EU AI Act reinforces this with specific technical requirements
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Implementation Roadmap
- AI model inventory with risk classification — which models are in scope for EU AI Act?
- Bias audit of credit scoring models — independent fairness assessment against protected characteristics
- Explainability assessment — can each model's individual decisions be explained to customers and regulators?
- Documentation per Art. 11 — technical documentation for each high-risk model
- Human oversight design — define where human review is required in lending and AML workflows
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton