The EU AI Act's high-risk system provisions apply from August 2026. For payment and credit providers using AI in fraud detection, credit scoring or customer risk assessment, the conformity assessment obligations are more demanding than most compliance teams have planned for: and the August deadline is not far away.
Which AI systems are in scope
The EU AI Act classifies certain AI systems used in financial services as high-risk. The relevant categories for payment and credit firms include AI systems used in creditworthiness assessment and credit scoring, AI systems used in risk assessment and pricing in life and health insurance, and, critically for payment firms, AI systems used in the context of biometric verification where this is used for identity verification in payment processes.
Fraud detection systems are an area of active interpretation. AI-based fraud detection systems that make or significantly influence decisions affecting individuals' access to financial services are likely to be classified as high-risk under the Act's broad framing. This is a significant scope issue for payment companies: fraud detection is one of the most AI-intensive functions in the industry, and many firms have deployed machine learning models that make real-time decisions affecting transactions.
What conformity assessment requires
High-risk AI systems must undergo conformity assessment before deployment. The requirements include technical documentation covering the system's purpose, capabilities and limitations; data governance documentation demonstrating that training data meets quality criteria and is free from problematic biases; logging and record-keeping enabling post-hoc audit of system decisions; transparency obligations to users of the system; and human oversight mechanisms that allow human intervention in the decision process.
The human oversight requirement is particularly operationally complex for real-time fraud detection. A fraud model making decisions in milliseconds cannot pause for human review on each transaction: the requirement is interpreted as meaning that humans must have the ability to intervene, override and shut down the system, and that the system's boundaries and limitations are clearly communicated to those monitoring it.
Preparing for August 2026
Most payment and credit firms have not completed a systematic inventory of their AI systems against the EU AI Act's high-risk criteria. The first step is that inventory: identifying every AI or ML system that makes or significantly influences decisions affecting customers, then assessing each against the high-risk classification criteria.
For systems that fall within scope, the conformity assessment documentation must be prepared before August 2026. For firms that discover gaps in their technical documentation, data governance records or human oversight mechanisms, the time available is short. Engaging now is necessary to have any realistic prospect of meeting the deadline.