What financial firms get wrong.
The routes the Act grants, with their conditions.
Three financial deployments.
A lender running a bought credit-scoring model.
- Annex III 5(b): high-risk by listing, deployer duties under Art. 26.
- Art. 27 fundamental-rights assessment applies, pre-filled from the DPIA.
- Art. 26(5) folds monitoring into existing internal governance, declared not assumed.
- GDPR Art. 22 sits on the same register.
An insurer pricing life cover with a model it built.
- Annex III 5(c) and the provider set — Art. 9 through Art. 49 registration.
- Art. 17(4) folds most Art. 17(1) aspects into internal governance.
- (g), (h) and (i) accounted for separately, because the provision stops short.
- The reliance is recorded with the instrument it rests on named.
A bank running fraud detection and scoring on related models.
- The fraud model sits inside the Annex III 5(b) carve-out.
- The scoring model does not, even where the architecture is shared.
- Classification asks about purpose, so the two separate cleanly.
- One register carries both, with different duty sets.
What sits beside the sector duties.
Straight answers for financial services.
Which financial use cases are high-risk?
Annex III point 5(b) names AI used to evaluate creditworthiness or establish a credit score, other than for detecting financial fraud. Point 5(c) names risk assessment and pricing in life and health insurance. Those are high-risk by listing, which means the classification question is not whether but how you will evidence the duties.
We already run internal governance under CRD or Solvency II. Does that count?
In two specific places, yes. Article 17(4) lets a provider that is a financial institution subject to internal governance requirements under Union financial-services law include most of the Article 17(1) quality-management aspects within those arrangements — though (g), (h) and (i) must still be accounted for separately. Article 26(5) does the equivalent for deployer monitoring. Both are routes the Act itself grants; neither is a general exemption.
Does a fundamental rights impact assessment apply to us?
Article 27 binds deployers of the Annex III creditworthiness and insurance-pricing systems, alongside public bodies. Where it applies it can build on a data protection impact assessment you have already carried out — Article 27(4) permits that explicitly, and Veritome pre-fills from the DPIA rather than asking the same questions twice.
Is fraud detection caught?
Annex III point 5(b) carves out AI used for the purpose of detecting financial fraud. That carve-out is narrow and attaches to purpose, so a model used for fraud detection and separately for scoring is not covered by it in the second use. The classification asks about purpose rather than about the model.
How does this sit with DORA and existing model risk management?
Beside them. Operational resilience and model risk management are their own regimes with their own evidence, and much of that evidence is reusable as input. What the EU AI Act adds is a classification, an obligation set derived from it, and a record naming the article behind each item.



