Independent EU AI Act information resourceLegal text verified against EUR-Lex

Sector guide

The EU AI Act for financial services and insurance

Two points of Annex III do most of the work here, and both contain carve-outs that decide whether a system is in scope at all. Reading them loosely is how banks end up treating fraud models as high-risk and insurers treating motor pricing as caught.

What the Act actually names in this sector

These are the provisions that reach financial services and insurance, quoted from the Official Journal. Everything below follows from them.

  • AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud
    Annex III, 5(b) →
  • AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance
    Annex III, 5(c) →

Common use cases, classified

Prohibited

Banned outright. There is no compliance route — the practice has to stop or change.

  • General-purpose customer scoring on social behaviour

    Social scoring leading to detrimental treatment in unrelated contexts, or treatment that is unjustified or disproportionate, is prohibited.

    Article 5(1)(c) →

High-risk

Permitted, but carries the full Chapter III obligations: risk management, data governance, documentation, logging, human oversight, accuracy and cybersecurity.

  • Credit scoring and creditworthiness

    Point 5(b) names evaluating the creditworthiness of natural persons or establishing their credit score.

    It applies to natural persons. Scoring a company is not covered by this point.

    Annex III, 5(b) →
  • Life and health insurance pricing

    Point 5(c) names risk assessment and pricing in relation to natural persons for life and health insurance.

    Only life and health. Motor, property and commercial lines are not named in point 5(c).

    Annex III, 5(c) →

Transparency duty

Not high-risk, but people must be told. Disclosure and content-marking duties under Article 50.

  • Customer service chatbot

    A system intended to interact directly with people carries a disclosure duty, but is not high-risk merely for being conversational.

    It becomes high-risk if it decides something in Annex III — creditworthiness, for instance, rather than explaining a product.

    Article 50(1) →

Depends on the detail

The Act does not settle this from the description alone. The note says what decides it.

  • Financial fraud detection

    Point 5(b) expressly excludes AI systems used for the purpose of detecting financial fraud, so fraud detection is not high-risk on that basis.

    The carve-out is narrow. If the same model also decides creditworthiness or account access, that use is assessed on its own terms.

    Annex III, 5(b) →
  • Motor, property or commercial insurance pricing

    Point 5(c) is limited to life and health insurance, so other lines are not high-risk under it.

    Still assess it against the prohibitions and against national insurance and anti-discrimination law, which the Act does not displace.

    Annex III, 5(c) →

What gets misread here

Over-classification is the quieter failure: treating something as high-risk when the Act carves it out costs real money and never triggers a complaint, so nobody catches it.

  • “Our fraud detection scores customers, so it is high-risk like credit scoring.”

    Point 5(b) expressly excludes systems used for detecting financial fraud. The carve-out is in the same sentence that creates the obligation.

    Annex III, 5(b) →
  • “All our insurance pricing models are high-risk.”

    Point 5(c) reaches life and health insurance only. Motor, property and commercial lines are not named in it.

    Annex III, 5(c) →
  • “Scoring businesses for lending is covered too.”

    Point 5(b) is about natural persons. Commercial credit decisions about a company are not caught by it.

    Annex III, 5(b) →

Dates that matter in this sector

  • 2 Dec 2027Annex III high-risk obligations apply — Providers of Annex III high-risk systems (including AI used in employment, education, credit scoring, life and health insurance pricing, essential services, law enforcement and migration) must meet the full Chapter III requirements from 2 December 2027. (date changed by the Omnibus)
  • 2 Feb 2025Prohibited practices and AI literacy apply — Since 2 February 2025 the first eight prohibited AI practices in Article 5 have been unlawful across the EU, and every provider and deployer has owed an AI literacy duty under Article 4. Two further prohibitions were added later and apply from 2 December 2026.

Dates are as amended by the Digital Omnibus. See the full timeline for what each one covers.

What the Commission has said

These guidelines are not binding, but they are the Commission’s own reading of the provisions above, and they are the first place a supervisory authority will look. Where they and this guide differ, follow them.

What to do next

Screen your own systems with the scope finder, run a single system through the risk classifier, or work the obligations in order with the checklist.

This guide points you at the provisions that govern your sector. It is not legal advice, and whether a particular system meets a provision turns on facts about that system and on whether you hold it as provider or deployer — see Article 3 and Article 25.