The EU's AI Act is back in the headlines: 2 August 2026 turned out to be two milestones, not one. The compliance deadline for high-risk AI systems was pushed back by the European Parliament and the Council, while a separate set of transparency obligations under Article 50 took effect as planned. Worth knowing before filing this under "not urgent": the high-risk list does not cover Anti-Money Laundering (AML) monitoring in the first place. What it covers, what moved, and why AML models still need the same governance regardless.
The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence, and it sets out how organisations operating in the EU may use it. Its aim is that AI systems are safe, transparent, and respectful of human rights, including privacy and non-discrimination. It entered into force in August 2024 and its obligations are phasing in over several years: bans on prohibited practices since February 2025, governance and general-purpose AI model rules since August 2025, and the high-risk regime still ahead.
The next milestone was meant to be the big one: from 2 August 2026, the full set of obligations for high-risk AI systems was due to apply. That date has moved.
As part of the EU's Digital Omnibus simplification package, co-legislators reached a provisional agreement in May 2026, which the European Parliament approved on 16 June 2026. The resulting Regulation (EU) 2026/1744 has been in force since 27 July 2026. It pushes the deadline for standalone high-risk systems back by sixteen months, to 2 December 2027, largely because the technical standards institutions need to benchmark against were not ready in time. High-risk AI embedded in other regulated products gets a separate, smaller delay, from August 2027 to August 2028.
The delay is limited to the high-risk chapter. What that chapter will eventually require has not changed: risk classification, data quality and governance standards, human oversight, and monitoring and incident reporting.
This is where a lot of coverage overshoots, so it is worth being precise. Annex III of the AI Act lists the high-risk use cases. For a bank, broker or insurer, the ones that bite are:
AML transaction monitoring, sanctions screening, customer due diligence and counterparty risk rating are not on that list. The exclusion is deliberate and it is written into the text twice: Annex III, 5(b) carves out "AI systems used for the purpose of detecting financial fraud" in the same sentence that makes credit scoring high-risk, and Recital 58 states that AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services, and for prudential purposes to calculate credit institutions' and insurance undertakings' capital requirements, should not be considered high-risk.
So the honest version of the headline is this: for most compliance teams, the AI Act's high-risk regime is not the binding constraint. Something else is.
Explainability, human oversight, data quality, continuous monitoring and documented incident handling are not AI Act inventions. They are what AMLR, the EBA guidelines on ML/TF risk management, and any serious model risk framework already ask of a system that decides who gets onboarded and which alerts get escalated. A supervisor reviewing a customer risk rating will ask how the score was produced, who checked it, and what happens when it is wrong. The answer cannot be "the model decided".
Which is why the useful way to read December 2027 is not as a deadline institutions have been let off, but as a standard worth building to on purpose. Institutions that use the extra time to make their AML models explainable and their oversight documented will pass the AI Act check if their use case ever moves into scope, and pass the AMLR one either way. Institutions that treat the delay as a pause will do the same work later, under more time pressure, on systems that have grown in the meantime.
The disclosure duties under Article 50, such as telling people they are interacting with an AI system and labelling deepfakes, took effect on 2 August 2026 exactly as originally planned. Only the requirement to machine-mark AI-generated content received a short extension, to 2 December 2026, and only for systems already placed on the market before 2 August 2026.
Article 50 splits its duties by role, and the split matters:
The practical consequence for a bank running a vendor-supplied customer-service chatbot: the disclosure duty sits with the vendor, until the bank makes it its own. Under Article 25, a deployer that puts its own name or trademark on a system, substantially modifies it, or changes its intended purpose becomes the provider of that system, with the provider's obligations attached. Brand the chatbot and the duty follows the branding. A vendor's compliance is not automatically the deploying institution's compliance.
Non-compliance with these transparency duties can attract fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
This kind of machine-marking is already visible in practice: a Content Credentials tag on a LinkedIn image, showing it was generated through OpenAI's Media Service API.
Compliance teams will stop reviewing every file and start reviewing the model that reviews the files. That changes what the job is, not just how long it takes. Two shifts are already visible.
Supervisory authorities in EU member states are expected to lean on AI in their own investigations of financial institutions. Anomaly detection already plays a substantial role in identifying suspicious transactions, and the same techniques work on a dossier population. Banks and brokers need a dependable system for managing dossiers before that arrives, because the weakness a regulator's own tooling will find fastest is inconsistency. Take counterparty risk estimates: filtering thousands of files a day against the wrong risk parameters produces a pattern, and a pattern is exactly what an AI-assisted investigation is good at spotting.
Quality control is the other area where banks and brokers gain the most. As risk assessments come to rely on AI systems, the straightforward majority of dossiers can be handled with very little manual work, which frees the second line for judgement and gives internal audit, the third line, something new to test: not just whether files were reviewed, but whether the model reviewing them still performs. Instead of reading every case, team members go deeper on a smaller number of high-risk files while sampling the AI's work on the easy ones.
That brings us to the part of the AI Act that will outlast any deadline: institutions have to keep evaluating how their AI systems perform. Compliance teams become the people who compare the AI model against the traditional rule-based one, and who decide what to do when the two disagree.
The obvious question is what to measure. A workable starting set:
None of that works without somewhere to record it. New roles are emerging around exactly this: deciding where AI fits in the compliance toolkit, and keeping the systems aligned with the compliance framework, transparently and on the right parameters.
Meeting this calls for a human-in-the-loop architecture: AI can support analysts on data extraction, classification and hit matching, while counterparty acceptance, risk classification and STR filing to the FIU always require human authorisation. Risk scores need to be explainable by design, decomposing into the factors, values and thresholds that produced them, so there is no black-box decision left to defend to a supervisor or an auditor. Add risk models and parameters that adapt to each institution's own policies, and integrations that extend the same governance to transaction monitoring, and the picture is complete.
Human-in-the-loop, audit-ready, always in control. That is the standard the AI Act describes for high-risk systems, and the standard AMLR expects of an AML model whether the Act calls it high-risk or not.
What changed on 2 August 2026 was the calendar, not the substance. Transparency obligations took effect as planned, the high-risk regime was rescheduled to December 2027, and AML and fraud detection sit outside that regime anyway. What has not changed is the expectation: an AI-assisted compliance decision has to be explainable, overseen by a person, and monitored over time. Sixteen months is enough runway to build that properly. It is not a reason to wait.
The EU AI Act is the European Union's regulatory framework for artificial intelligence, the first of its kind in the world. It classifies AI systems by risk level and attaches obligations to each level, from outright bans on the riskiest uses to transparency duties for systems that interact directly with people.
Generally not. Annex III lists the high-risk use cases, and AML transaction monitoring, sanctions screening and customer due diligence are not among them. Annex III, 5(b) explicitly carves out AI used to detect financial fraud, and Recital 58 confirms that fraud detection in financial services should not be considered high-risk. Credit scoring, life and health insurance pricing, biometric categorisation and HR uses are in scope, and AMLR and the EBA guidelines set comparable governance expectations for AML models regardless.
Standalone high-risk systems were due to comply from 2 August 2026, but the Digital Omnibus on AI pushed that back sixteen months, to 2 December 2027. High-risk AI embedded in other regulated products moves from August 2027 to August 2028.
Yes. The deferral is limited to the high-risk chapter. The bans on prohibited practices, the governance and general-purpose AI model rules, and the Article 50 transparency obligations are all in force and were not affected. The Digital Omnibus also made other changes, including a narrower reading of when an AI system counts as a safety component.
Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Harmoney orchestrates the whole counterparty lifecycle, from onboarding to continuous monitoring, in one auditable flow. Human-in-the-loop, audit-ready, always in control. Want to see how that works for your AML and risk assessment processes? Talk to us or explore the Harmoney platform, or stay in touch via our newsletter ⬇️.
This article provides general information only and does not constitute legal advice. Financial institutions should consult qualified legal counsel to assess how the EU AI Act and the Digital Omnibus package apply to their specific circumstances.