The EU AI Act’s high-risk obligations became enforceable on 2 August 2026, and for financial services, that deadline lands harder than for any other sector. Credit scoring, loan approval, insurance pricing, and creditworthiness assessment are all named high-risk use cases. These aren’t edge cases or future roadmap items. They’re how the business makes money today.
Yet TrustArc’s 2026 Global Privacy Benchmarks found that 44% of financial firms cite limited in-house privacy and AI expertise as their top barrier to AI compliance, and that number hasn’t moved in a year. The sector with the deepest privacy governance is also the one most likely to say it doesn’t have the people to govern AI.
Strong governance posture is not the same as EU AI Act readiness. This checklist is for the operational layer: the specific steps, owners, and documentation that the Act actually requires before your high-risk systems can legally operate in the EU.
Step 1: Identify and Classify Your High-Risk AI Systems
Before anything else, you need a complete inventory. The Act applies to AI systems that are used in these financial services contexts:
- Credit scoring and creditworthiness assessment: any automated or semi-automated system influencing lending decisions
- Loan approval and pricing: including systems that rank, filter, or recommend
- Insurance pricing and underwriting: risk scoring that materially affects terms or eligibility
- Fraud detection: that influences a decision with legal or similarly significant effect on individuals
Checklist:
- Maintain a current inventory of all AI systems in production and in development
- Classify each system against Annex III of the EU AI Act (the high-risk list)
- Document the geographic scope of each system: does it process data about EU individuals, regardless of where your firm is headquartered?
- Flag any systems approaching deployment that would fall into scope before August 2026
- Assign a named owner to each high-risk system
The geographic trap: Exposure to the EU AI Act is operational, not just where your headquarters sits. A US or Asia-Pacific institution running credit models on European customers falls under the same obligations as a Frankfurt-based bank. A quarter of financial firms in TrustArc’s survey are in exactly this position, headquartered outside Europe but operating within it.
Step 2: Establish a Risk Management System for Each High-Risk System
The Act requires a documented risk management system, not a one-time assessment, but an ongoing process throughout the system’s lifecycle.
Checklist:
- Document the intended purpose of each high-risk AI system
- Identify foreseeable risks to health, safety, or fundamental rights, including risks of bias and discrimination in credit and insurance decisions
- Define risk mitigation measures and confirm they are implemented
- Log residual risks that remain after mitigation, with justification for their acceptability
- Schedule periodic risk reviews, at minimum, after any significant model update or distribution shift
- Confirm your risk management process covers the full lifecycle, from design through decommissioning
Step 3: Audit Your Training Data Against the Act’s Requirements
Data governance is one of the most demanding requirements, and one of the most commonly underestimated. The Act requires that training, validation, and testing data meet specific quality criteria.
Checklist:
- Document the sources of training, validation, and testing data for each high-risk system
- Conduct and record a data quality assessment (relevance, representativeness, completeness, and known limitations)
- Check for and document any biases in training data that could affect protected characteristics (age, gender, ethnicity) in credit or insurance outcomes
- Confirm that personal data used in training was collected lawfully and is being used for a compatible purpose under GDPR
- Ensure validation and test sets are appropriate to the system’s intended deployment context, models trained on one geography’s data deployed in another are a specific risk area
Step 4: Produce Technical Documentation Before Deployment
High-risk AI systems require technical documentation to be completed before the system is placed on the market or put into service. This is not a post-deployment exercise.
Checklist:
- Prepare a technical documentation file for each high-risk system covering: system description, intended purpose, design logic, training methodology, performance metrics, and known limitations
- Document the human oversight measures built into the system (see Step 5)
- Record validation and testing results, including accuracy benchmarks and failure mode analysis
- Maintain version control. Documentation must reflect the current production state of the system
- Confirm the documentation is accessible to national competent authorities on request
The overlap challenge: A credit model in a European institution typically already sits under GDPR’s automated decision-making provisions (Article 22), model-risk management guidelines (EBA), and now the EU AI Act. Your technical documentation should be designed to serve all three regimes. An integrated accountability framework, such as Nymity, can provide the connective layer that ties owners, evidence, and documentation across frameworks.
Step 5: Build Human Oversight Into the System
The Act requires that high-risk AI systems be designed and developed to allow effective human oversight. A human-in-the-loop policy that exists only on paper does not satisfy this requirement.
Checklist:
- Identify the specific points in each decision workflow where a human can intervene, override, or decline to act on the AI’s output
- Ensure the people in those oversight roles have sufficient information about the system’s outputs to make a meaningful review, including confidence levels, key input variables, and flags for edge cases
- Document the qualifications required for human reviewers, and confirm training is in place
- Test override mechanisms; confirm they function in production, not just in design
- Include human oversight procedures in the system’s technical documentation
Step 6: Implement Logging and Post-Market Monitoring
The Act requires automatic logging of events for high-risk AI systems, and post-market monitoring once deployed.
Checklist:
- Confirm each high-risk system generates logs sufficient to reconstruct decisions, particularly for decisions that are disputed or that result in regulatory inquiries
- Define the log retention period (GDPR data minimization requirements apply. Align both obligations)
- Establish a post-market monitoring plan: what signals indicate model drift, bias emergence, or performance degradation?
- Set review thresholds that trigger reassessment; for instance, if refusal rates for a protected group shift materially year-over-year
- Assign responsibility for monitoring to a named team or function, not distributed informally
Step 7: Close the Talent Gap Before the Deadline
Every operational step above requires people who understand both the regulatory requirements and how AI systems actually work. TrustArc’s benchmarks found this is the gap financial firms have been unable to close through investment alone. 43% of firms increasing privacy resources report the same expertise shortage as those holding budgets flat.
Checklist:
- Map each requirement above to a named internal owner with the skills to execute it
- Identify gaps where ownership is unclear or the required expertise doesn’t currently sit in-house
- For gaps that cannot be closed before August 2026, engage external support now — the window for meaningful pre-deadline remediation is closing
- Establish cross-functional working arrangements between privacy, legal, data science, and model risk teams. The Act’s requirements sit at the intersection of all four
- Document your governance structure for AI oversight, including escalation paths for compliance issues that span functions
The Three Mistakes Financial Firms Make Before an AI Deadline
Treating governance as compliance: Strong board oversight and ISO certifications are real advantages, but they describe how AI is governed, not whether the specific technical and documentation requirements of the Act are met. The August deadline is about the build layer.
Assuming EU-only exposure: The Act applies where your AI operates, not where your company is incorporated. Financial institutions running European credit and insurance systems from New York, Singapore, or Hong Kong are in scope. In TrustArc’s data, non-European firms operating in Europe are simultaneously the most privacy-mature group in the sector and the ones most likely to report an expertise gap.
Sequencing documentation after deployment: Technical documentation must be complete before a high-risk system enters service. Firms that have already deployed systems without this documentation need to remediate backwards, a harder and more resource-intensive task than building it in from the start.
FAQ
Which financial AI systems are high-risk under the EU AI Act? The Act’s Annex III specifically names AI systems used in credit scoring, creditworthiness assessment, and evaluation of individuals for insurance and similar purposes. Fraud detection systems may also fall into scope where they have a legal or similarly significant effect on individuals. If your system influences access to financial products or the terms under which they’re offered to EU individuals, treat it as high-risk until you have legal confirmation otherwise.
Does the August 2, 2026 deadline apply to AI systems already in production? Yes. Systems already deployed must comply by the August 2026 enforcement date for high-risk obligations. There is a transitional provision for general-purpose AI models placed on the market before August 2025, but purpose-built high-risk financial AI systems do not benefit from this carve-out.
We’re headquartered outside the EU. Does the Act apply to us? If your AI systems process data about EU individuals or their decisions affect EU individuals, as is the case for any cross-border lending, insurance, or credit operation, the Act applies to you. Roughly a quarter of financial services respondents in TrustArc’s 2026 benchmarks are headquartered outside Europe but in scope through their European operations.
What’s the difference between GDPR Article 22 compliance and EU AI Act compliance for credit decisions? They overlap but are not the same. GDPR Article 22 covers the right not to be subject to solely automated decisions with significant effects, and requires the ability to request human review and explanation. The EU AI Act adds requirements around technical documentation, risk management systems, data governance, logging, and pre-market conformity assessment. A system that satisfies Article 22 may not yet satisfy the AI Act’s additional requirements.
How does the EU AI Act interact with EBA model risk guidelines? Both regimes require documentation of model purpose, validation, performance monitoring, and human oversight, but the specifics differ. The AI Act adds requirements the EBA guidelines don’t explicitly cover, including training data quality documentation and specific transparency obligations. The most efficient path is a unified documentation framework that satisfies both simultaneously rather than maintaining parallel processes.
Next Step
If you want to know where your program stands against the Act’s requirements, TrustArc’s AI Governance solution can show you the gaps.
Explore AI Governance