The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It applies to any company that provides or deploys AI systems to users in the European Union, regardless of where that company is based. If your AI touches EU customers, the Act touches you. This guide covers every obligation you need to know, when it kicks in, and what compliant practice looks like for AI and fintech companies.

What is the EU AI Act?

The EU AI Act was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. It is the world's first horizontal, binding AI regulation. Unlike sector-specific rules (such as GDPR for data, or MiFID II for financial markets), the Act covers virtually every AI system across every industry.

The Act works on a risk ladder: AI applications are classified by how much harm they could cause, and obligations scale accordingly. At the top are outright bans. Below that are high-risk AI systems facing detailed compliance requirements. Further down are limited-risk systems with narrow transparency duties. The broad majority of AI applications (low risk) face no specific obligations beyond the general product safety framework.

For fintech and AI companies, the most immediately relevant categories are: GPAI models (general-purpose AI like large language models), high-risk AI in credit scoring and employment, and prohibited uses that must be switched off entirely.

Key dates and the compliance timeline

The Act's obligations phase in over several years. Understanding which date governs which obligation is the first job of any compliance team.

DateWhat appliesWho is affected
1 Aug 2024Act entered into forceAll
2 Feb 2025Prohibited practices (Art 5) apply; AI literacy obligations beginAll providers and deployers
2 Aug 2025GPAI model obligations apply; governance bodies operationalGPAI providers
2 Aug 2026Transparency (Art 50), Article 49 registration, enforcement and market surveillanceAll providers and deployers
2 Dec 2027High-risk Annex III obligations (proposed deferral under Digital Omnibus, not yet settled law)High-risk AI system providers
2 Aug 2030General-purpose AI systems governed solely by EU product safety lawLegacy systems

On 2 December 2027: The Digital Omnibus proposal (a legislative package under review as of mid-2026) proposes deferring high-risk Annex III obligations from August 2026 to December 2027. This is a legislative proposal, not settled law. Companies should plan to the earlier date or watch the proposal closely. The 2 August 2026 obligations for GPAI, transparency, and enforcement are not affected by this proposal.

The risk pyramid: four tiers of AI

The Act classifies every AI system into one of four risk tiers. Your obligations depend entirely on which tier your product lands in.

Tier 1: Unacceptable risk (banned)

Article 5 prohibits certain AI practices outright, effective 2 February 2025. These bans apply to all actors, including non-EU companies whose systems reach EU users. Prohibited practices include:

  • Subliminal or manipulative AI techniques that exploit psychological vulnerabilities
  • Social scoring systems for public authorities
  • Real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions)
  • AI systems that infer emotions in workplaces or educational institutions
  • AI-based profiling of individuals using sensitive attributes to predict criminal behavior
  • Untargeted scraping of facial images to build recognition databases

If any part of your product does any of the above, it must be shut down entirely before operating in the EU. There is no compliance pathway for prohibited practices, only removal.

Tier 2: High risk (Annex III and Annex II)

High-risk AI systems face extensive pre-deployment requirements: conformity assessments, technical documentation, human oversight measures, logging, accuracy standards, and registration in the EU database before going live. Two annexes define this category:

  • Annex II: AI components embedded in safety-critical products already governed by EU product law (medical devices, machinery, aviation, automotive). Timelines align with the relevant product regulation.
  • Annex III: AI systems in eight specific domains where autonomous or semi-autonomous AI decisions could cause significant harm to individuals. This includes credit scoring, employment screening, education, critical infrastructure, migration and border control, access to essential services, and law enforcement.

For fintech companies, the most important Annex III categories are creditworthiness assessment, insurance risk assessment, and fraud detection systems that affect individual access to financial services. If you use ML models to decide whether someone gets a loan, that is very likely an Annex III system.

Tier 3: Limited risk (transparency obligations)

Article 50 of the Act requires certain AI systems to disclose their AI nature to users. This hits a broad range of products on 2 August 2026:

  • Chatbots and conversational AI must identify themselves as AI to users in real time
  • Deepfake images, video, and audio must be labeled as AI-generated
  • AI-generated text intended to inform on matters of public interest must be machine-readable marked
  • Emotion-recognition and biometric categorization systems must notify users

For most SaaS and fintech companies, Article 50 is the first practical obligation they will face. If you have a chatbot, a virtual assistant, or any AI content pipeline facing EU users, the 2 August 2026 deadline is yours to own.

Tier 4: Minimal risk (voluntary)

The vast majority of AI applications (spam filters, AI-powered search, recommendation engines without individual harm potential) face no specific obligations. The Act encourages voluntary codes of conduct for these systems, but there is no enforcement mechanism.

GPAI models: obligations for large language models and foundation models

General-purpose AI (GPAI) models are a new category created by the Act to regulate foundation model providers like those building or offering large language models. GPAI obligations applied from 2 August 2025.

All GPAI providers must:

  • Draw up and maintain technical documentation (model architecture, training data, capabilities, limitations)
  • Comply with EU copyright law (the Act links directly to the DSM Directive exception for text and data mining)
  • Publish a summary of training data that is sufficiently detailed for downstream deployers to understand the model
  • Provide downstream providers with information about the model's capabilities and limitations
  • Register in the EU database before making the model available

GPAI models with systemic risk (those trained above a compute threshold of 10^25 FLOPs, or designated by the European AI Office) face additional requirements:

  • Adversarial testing and red-teaming before and after deployment
  • Incident reporting to the European AI Office within 15 days of serious incidents
  • Cybersecurity measures against model extraction and data poisoning
  • Annual energy efficiency reporting

If you offer an API-based LLM, fine-tune a foundation model, or embed GPAI capabilities in a product you deploy to EU users, you need to trace your supply chain carefully. Even if your immediate product is not the GPAI model, you may have obligations as a downstream deployer under Article 25.

What fintech and financial AI companies need to know

Financial services companies face the Act's most complex intersection: high-risk Annex III categories, tight data rules from GDPR, and sector-specific rules from MiFID II, PSD3, and the AI Act all applying simultaneously.

Credit scoring and underwriting models

Creditworthiness assessment is explicitly listed in Annex III. If your model contributes to decisions on granting, increasing, or revoking credit to natural persons in the EU, it is a high-risk system. That means:

  • Conformity assessment before deployment (self-assessment is permitted for most Annex III systems, with third-party audit required for biometric systems and law enforcement)
  • Technical documentation including dataset provenance, bias testing methodology, and accuracy metrics across demographic groups
  • Human oversight: a natural person must be able to override the AI decision and must be given the information to do so meaningfully
  • Automatic logging of decisions so national authorities can audit decisions after the fact
  • Registration in the EU AI database before deployment

Fraud detection

Fraud detection is a nuanced area. The Act does not ban or categorize all fraud detection as high-risk. But if your fraud model affects individual access to financial services (for example, if a fraud flag leads to account suspension or denial of a transaction), it may qualify as an AI system used to determine access to essential services, which is Annex III.

AML and know-your-customer (KYC)

AI-based AML screening and KYC tools sit at the intersection of the Act and existing AML directives. The key test is whether the AI system makes or substantially influences decisions about individual access to financial services. If it does, treat it as high-risk until proven otherwise.

Practical compliance steps: where to start

Most companies need to execute five things before 2 August 2026:

  1. AI inventory: catalogue every AI system you use or provide, with enough detail to classify each on the risk ladder. Include third-party AI tools you integrate.
  2. Risk classification: apply the Annex III test and the prohibited practices list. For each system, document your classification rationale.
  3. GPAI supply chain review: identify every GPAI model in your stack (including via API). Request the technical documentation and copyright compliance statements required under Article 53.
  4. Article 50 readiness: audit every customer-facing AI touchpoint. Add AI disclosure notices to chatbots, label AI-generated content, and build the disclosure into your product by 2 August 2026.
  5. High-risk roadmap (if applicable): if you have Annex III systems, begin the conformity assessment process. Even if the December 2027 deferral passes, starting now avoids a compliance crunch.

Not sure where your products land? Better Societies runs a 6-week EU AI Act compliance engagement that takes you from inventory to a signed compliance declaration. See the compliance offer.

Enforcement: who is watching, and what are the fines?

The Act creates a layered enforcement architecture. The European AI Office (set up inside the European Commission) is responsible for GPAI model oversight at the EU level. National market surveillance authorities in each member state handle enforcement for other AI systems within their territory.

Fines are graduated by violation type:

  • EUR 35 million or 7% of global annual turnover (whichever is higher) for violations of Article 5 prohibited practices
  • EUR 15 million or 3% of global annual turnover for violations of most other provisions, including GPAI obligations and high-risk requirements
  • EUR 7.5 million or 1.5% of global annual turnover for supplying incorrect or misleading information to authorities

Member states may set lower fines for SMEs and startups, and the Act directs authorities to take company size into account. But the headline numbers establish the upper bound of liability for non-compliant conduct.

Extraterritorial reach: does it apply to you?

The EU AI Act has explicit extraterritorial scope. Article 2 applies the Act to:

  • Providers placing AI systems on the EU market, regardless of where the provider is established
  • Deployers of AI systems located in the EU
  • Providers and deployers established outside the EU whose AI system outputs are used in the EU
  • Importers and distributors of AI systems

This mirrors the GDPR's "effects doctrine." A US or UK fintech serving EU customers through an AI-powered product is in scope. The practical test: if an EU resident receives an output from your AI system (a credit decision, a chatbot response, a risk score), your company is a subject of the Act.

What to do next

The first move for most companies is an AI inventory and risk classification exercise. This does not require legal counsel on day one; it requires your engineering and product teams to document what AI you have and what it does. Once you have that list, a structured compliance engagement can close the gaps.

Better Societies offers a 6-week compliance delivery with documentation, training, and a signed compliance declaration. If you have fewer than 12 months before a relevant deadline, start now.