Financial Services AI: High-Risk by Default
The EU AI Act classifies most financial services AI as high-risk (Annex III, Point 5b). Credit scoring, insurance pricing, loan origination, and anti-money laundering systems all fall into this category. Combined with existing financial regulation (DORA, MiFID II, PSD2, CRD), financial institutions face the most complex AI compliance landscape in any sector.
High-Risk AI Classifications in Financial Services
Explicitly High-Risk (Annex III)
- Credit scoring — AI evaluating creditworthiness of natural persons (Art. 6(2), Annex III, 5b)
- Insurance pricing — AI determining risk assessment and pricing for life and health insurance
- Recruitment AI — If banks use AI for hiring decisions
Potentially High-Risk (Case-by-Case)
- Fraud detection — May be high-risk if decisions directly affect customer access to services
- AML/KYC screening — Customer due diligence AI that flags or blocks transactions
- Algorithmic trading — Market-making and execution algorithms (MiFID II already regulates these)
- Robo-advisory — AI-driven investment advice (high-risk when replacing human advisors)
Key Compliance Requirements for Financial AI
Art. 9 — Risk Management System
Financial institutions must establish continuous risk management for AI throughout its lifecycle:
- Known and foreseeable risks identification (model risk, data risk, bias risk)
- Risk estimation and evaluation using appropriate metrics
- Risk mitigation measures (guardrails, thresholds, human escalation)
- Testing for residual risk acceptability
Art. 10 — Data Governance
Training, validation, and testing datasets must meet quality criteria:
- Representative of the population the AI will be used on
- Free from errors and data quality issues
- Appropriate statistical properties for the intended purpose
- Consideration of bias, especially in credit scoring across demographics
Art. 14 — Human Oversight
Critical for financial AI — human oversight must enable:
- Understanding of AI system capabilities and limitations
- Ability to override or reverse AI decisions (especially credit denials)
- Interpretation of AI outputs before acting on them
- "Stop button" capability for systematic model failures
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Multi-Regulation Compliance Matrix
| AI Use Case | EU AI Act | DORA | Other |
|---|---|---|---|
| Credit scoring | High-risk (Annex III) | ICT risk mgmt | CRD, GDPR Art. 22 |
| Fraud detection | Case-by-case | Incident reporting | PSD2 |
| AML screening | Case-by-case | Resilience testing | AMLD6 |
| Algo trading | Case-by-case | TLPT | MiFID II Art. 17 |
Practical Compliance Roadmap for Banks and Fintechs
Phase 1 (Now — Q1 2027): Inventory all AI systems, classify by risk level, identify high-risk systems requiring conformity assessment
Phase 2 (Q1 — Q3 2027): Implement risk management systems, data governance, technical documentation for high-risk AI
Phase 3 (Q4 2027, ahead of the 2 December 2027 deadline): Conformity assessments, register high-risk AI in EU database, ongoing monitoring and compliance reporting
Automating Azure DevTest Labs
Automate lab management and integrate with CI/CD pipelines.
Start on Pluralsight →Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
