AI Act impact in the financial sector: the road ahead

20 August 2026

The EU's AI Act is back in the headlines: 2 August 2026 turned out to be two milestones, not one. The compliance deadline for high-risk AI systems was pushed back by the European Parliament and the Council, while a separate set of transparency obligations under Article 50 took effect as planned. Worth knowing before filing this under "not urgent": the high-risk list does not cover Anti-Money Laundering (AML) monitoring in the first place. What it covers, what moved, and why AML models still need the same governance regardless.

AI Act european commission


💡 Key takeaways

  • The high-risk obligations of the EU AI Act, originally due 2 August 2026, have been pushed back sixteen months to 2 December 2027 under the Digital Omnibus on AI.
  • For financial institutions, the high-risk list covers credit scoring, life and health insurance pricing, biometric categorisation and HR uses. AML monitoring and fraud detection are explicitly outside it.
  • That carve-out is not a free pass: AMLR, the EBA guidelines and any serious model risk framework ask for the same explainability, human oversight and monitoring the Act describes.
  • Not every 2 August 2026 deadline moved. The transparency rules in Article 50, covering AI-interaction disclosure and deepfake labelling, took effect exactly as scheduled.
  • Breaching those transparency duties can attract fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

The EU AI Act in a nutshell

The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence, and it sets out how organisations operating in the EU may use it. Its aim is that AI systems are safe, transparent, and respectful of human rights, including privacy and non-discrimination. It entered into force in August 2024 and its obligations are phasing in over several years: bans on prohibited practices since February 2025, governance and general-purpose AI model rules since August 2025, and the high-risk regime still ahead.

The high-risk deadline moved, it did not disappear

The next milestone was meant to be the big one: from 2 August 2026, the full set of obligations for high-risk AI systems was due to apply. That date has moved.

As part of the EU's Digital Omnibus simplification package, co-legislators reached a provisional agreement in May 2026, which the European Parliament approved on 16 June 2026. The resulting Regulation (EU) 2026/1744 has been in force since 27 July 2026. It pushes the deadline for standalone high-risk systems back by sixteen months, to 2 December 2027, largely because the technical standards institutions need to benchmark against were not ready in time. High-risk AI embedded in other regulated products gets a separate, smaller delay, from August 2027 to August 2028.

The delay is limited to the high-risk chapter. What that chapter will eventually require has not changed: risk classification, data quality and governance standards, human oversight, and monitoring and incident reporting.

What is actually high-risk in a financial institution

This is where a lot of coverage overshoots, so it is worth being precise. Annex III of the AI Act lists the high-risk use cases. For a bank, broker or insurer, the ones that bite are:

  • Creditworthiness and credit scoring of natural persons (Annex III, 5(b)).
  • Risk assessment and pricing for life and health insurance (Annex III, 5(c)).
  • Biometric categorisation by sensitive attributes and emotion recognition (Annex III, 1(b) and 1(c)), plus remote biometric identification (1(a)). One-to-one verification that a person is who they claim to be is excluded, which is what most remote onboarding flows actually do.
  • Recruitment and employee evaluation (Annex III, 4), which every institution has, whether or not compliance owns it.

AML transaction monitoring, sanctions screening, customer due diligence and counterparty risk rating are not on that list. The exclusion is deliberate and it is written into the text twice: Annex III, 5(b) carves out "AI systems used for the purpose of detecting financial fraud" in the same sentence that makes credit scoring high-risk, and Recital 58 states that AI systems provided for by Union law for the purpose of detecting fraud in the offering of financial services, and for prudential purposes to calculate credit institutions' and insurance undertakings' capital requirements, should not be considered high-risk.

So the honest version of the headline is this: for most compliance teams, the AI Act's high-risk regime is not the binding constraint. Something else is.

Why the carve-out is not a free pass

Explainability, human oversight, data quality, continuous monitoring and documented incident handling are not AI Act inventions. They are what AMLR, the EBA guidelines on ML/TF risk management, and any serious model risk framework already ask of a system that decides who gets onboarded and which alerts get escalated. A supervisor reviewing a customer risk rating will ask how the score was produced, who checked it, and what happens when it is wrong. The answer cannot be "the model decided".

Which is why the useful way to read December 2027 is not as a deadline institutions have been let off, but as a standard worth building to on purpose. Institutions that use the extra time to make their AML models explainable and their oversight documented will pass the AI Act check if their use case ever moves into scope, and pass the AMLR one either way. Institutions that treat the delay as a pause will do the same work later, under more time pressure, on systems that have grown in the meantime.

Not every obligation moved: Article 50 applied on schedule

The disclosure duties under Article 50, such as telling people they are interacting with an AI system and labelling deepfakes, took effect on 2 August 2026 exactly as originally planned. Only the requirement to machine-mark AI-generated content received a short extension, to 2 December 2026, and only for systems already placed on the market before 2 August 2026.

Article 50 splits its duties by role, and the split matters:

  • Telling users they are dealing with an AI system, and marking synthetic content, are provider obligations.
  • Disclosing emotion recognition and biometric categorisation, and labelling deepfakes or AI-generated text published to inform the public, are deployer obligations.

The practical consequence for a bank running a vendor-supplied customer-service chatbot: the disclosure duty sits with the vendor, until the bank makes it its own. Under Article 25, a deployer that puts its own name or trademark on a system, substantially modifies it, or changes its intended purpose becomes the provider of that system, with the provider's obligations attached. Brand the chatbot and the duty follows the branding. A vendor's compliance is not automatically the deploying institution's compliance.

Non-compliance with these transparency duties can attract fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

This kind of machine-marking is already visible in practice: a Content Credentials tag on a LinkedIn image, showing it was generated through OpenAI's Media Service API.

Two shifts worth preparing for

Compliance teams will stop reviewing every file and start reviewing the model that reviews the files. That changes what the job is, not just how long it takes. Two shifts are already visible.

1. Regulators are using AI too

Supervisory authorities in EU member states are expected to lean on AI in their own investigations of financial institutions. Anomaly detection already plays a substantial role in identifying suspicious transactions, and the same techniques work on a dossier population. Banks and brokers need a dependable system for managing dossiers before that arrives, because the weakness a regulator's own tooling will find fastest is inconsistency. Take counterparty risk estimates: filtering thousands of files a day against the wrong risk parameters produces a pattern, and a pattern is exactly what an AI-assisted investigation is good at spotting.

2. Quality control moves up a line

Quality control is the other area where banks and brokers gain the most. As risk assessments come to rely on AI systems, the straightforward majority of dossiers can be handled with very little manual work, which frees the second line for judgement and gives internal audit, the third line, something new to test: not just whether files were reviewed, but whether the model reviewing them still performs. Instead of reading every case, team members go deeper on a smaller number of high-risk files while sampling the AI's work on the easy ones.

Towards a hybrid model of AI risk assessment

That brings us to the part of the AI Act that will outlast any deadline: institutions have to keep evaluating how their AI systems perform. Compliance teams become the people who compare the AI model against the traditional rule-based one, and who decide what to do when the two disagree.

The obvious question is what to measure. A workable starting set:

  • False positive rate against the rule-based baseline, on the same population, so the comparison means something.
  • Alert-to-STR conversion, which tells you whether the model is finding the right things or just fewer things.
  • Analyst override rate, split by reason. A rising override rate is the earliest signal that a model has drifted away from policy.
  • Precision and recall on a labelled sample, refreshed periodically rather than measured once at go-live.
  • Parameter drift: which risk parameters changed, when, and who approved the change.

None of that works without somewhere to record it. New roles are emerging around exactly this: deciding where AI fits in the compliance toolkit, and keeping the systems aligned with the compliance framework, transparently and on the right parameters.

What this requires in practice

Meeting this calls for a human-in-the-loop architecture: AI can support analysts on data extraction, classification and hit matching, while counterparty acceptance, risk classification and STR filing to the FIU always require human authorisation. Risk scores need to be explainable by design, decomposing into the factors, values and thresholds that produced them, so there is no black-box decision left to defend to a supervisor or an auditor. Add risk models and parameters that adapt to each institution's own policies, and integrations that extend the same governance to transaction monitoring, and the picture is complete.

Human-in-the-loop, audit-ready, always in control. That is the standard the AI Act describes for high-risk systems, and the standard AMLR expects of an AML model whether the Act calls it high-risk or not.

Conclusion

What changed on 2 August 2026 was the calendar, not the substance. Transparency obligations took effect as planned, the high-risk regime was rescheduled to December 2027, and AML and fraud detection sit outside that regime anyway. What has not changed is the expectation: an AI-assisted compliance decision has to be explainable, overseen by a person, and monitored over time. Sixteen months is enough runway to build that properly. It is not a reason to wait.


Frequently asked questions about the EU AI Act

What is the EU AI Act?

The EU AI Act is the European Union's regulatory framework for artificial intelligence, the first of its kind in the world. It classifies AI systems by risk level and attaches obligations to each level, from outright bans on the riskiest uses to transparency duties for systems that interact directly with people.

Is AML software high-risk under the EU AI Act?

Generally not. Annex III lists the high-risk use cases, and AML transaction monitoring, sanctions screening and customer due diligence are not among them. Annex III, 5(b) explicitly carves out AI used to detect financial fraud, and Recital 58 confirms that fraud detection in financial services should not be considered high-risk. Credit scoring, life and health insurance pricing, biometric categorisation and HR uses are in scope, and AMLR and the EBA guidelines set comparable governance expectations for AML models regardless.

When does the EU AI Act's high-risk regime take effect?

Standalone high-risk systems were due to comply from 2 August 2026, but the Digital Omnibus on AI pushed that back sixteen months, to 2 December 2027. High-risk AI embedded in other regulated products moves from August 2027 to August 2028.

Is the EU AI Act still in force despite the delay?

Yes. The deferral is limited to the high-risk chapter. The bans on prohibited practices, the governance and general-purpose AI model rules, and the Article 50 transparency obligations are all in force and were not affected. The Digital Omnibus also made other changes, including a narrower reading of when an AI system counts as a safety component.

What are the fines for breaching the transparency rules?

Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Harmoney orchestrates the whole counterparty lifecycle, from onboarding to continuous monitoring, in one auditable flow. Human-in-the-loop, audit-ready, always in control. Want to see how that works for your AML and risk assessment processes? Talk to us or explore the Harmoney platform, or stay in touch via our newsletter ⬇️.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This article provides general information only and does not constitute legal advice. Financial institutions should consult qualified legal counsel to assess how the EU AI Act and the Digital Omnibus package apply to their specific circumstances.

Latest articles