EU AI Act Becomes Generally Applicable: Key Annex III High-Risk Obligations Deferred to 2027

A monochrome line drawing of an open door frame on a white background

Fintech · 2026-08-15 · 10 min

The EU AI Act became generally applicable on 2 August 2026. Meanwhile, key obligations for AI used to evaluate the creditworthiness of natural persons, and for risk assessment and pricing in life and health insurance, were deferred to December 2027. Which provisions apply now, and which remain subject to later application dates?

This article is provided for general information only and does not constitute legal, regulatory, or investment advice. How the EU AI Act applies depends on an AI system's intended purpose, whether an organization acts as a provider or a deployer, how the system is used, and how the Act interacts with other legislation. For specific cases, please consult the current legal texts, official guidance, and qualified professional advice. The information in this article was verified as of August 2026.

On 2 August 2026, the EU AI Act became generally applicable.

That was not the date on which the Act entered into force. It entered into force on 1 August 2024, and several provisions — including those on prohibited AI practices, AI literacy, and general-purpose AI models — had already begun to apply in stages.

Meanwhile, the application of key obligations in Chapter III, Sections 1 to 3, to Annex III high-risk AI systems — except Article 6(5) — has been deferred until 2 December 2027.

The question, therefore, is not whether the AI Act has “started”, but which provisions apply now and which remain subject to later application dates. For financial institutions, confusing those timelines can lead to misplaced priorities.

What Actually Happened on 2 August 2026

According to the European Commission’s announcement published on 31 July 2026, 2 August 2026 is the date from which the AI Act became generally applicable, and also the date from which the AI Office and national authorities began enforcing the provisions that apply.

The provisions that became applicable on that date include the transparency obligations in Article 50. Among other things, these obligations cover AI systems that interact directly with natural persons and systems that generate synthetic content.

For financial institutions, the most familiar case is the conversational AI used at customer touchpoints. As set out below, however, the transparency obligations are not a single uniform “label it as AI” duty. What is required depends on the type of system and on whether the organization is acting as the provider or the deployer.

What Was Deferred Is Not “Annex III Itself”

Uses that directly affect a person’s significant opportunities or treatment are classified as high-risk AI systems under Annex III of the AI Act. In financial services, Annex III specifically covers AI systems used to evaluate the creditworthiness of natural persons or establish their credit scores — excluding systems used to detect financial fraud — and AI systems used for risk assessment and pricing in life and health insurance for natural persons.

For this area, an amending regulation known as the AI Omnibus, which entered into force on 27 July 2026, moved the timing of application.

The precise point here is that Annex III itself was not deferred.

What was deferred is the application of Chapter III, Sections 1 to 3 — except Article 6(5) — to AI systems classified as high-risk under Article 6(2) and Annex III. Those provisions, which set out classification, system requirements, and the obligations of providers and deployers, will apply from 2 December 2027.

Put differently: this deferral is confined to the specified sections. Provisions placed elsewhere in the Act, such as the transparency obligations, are not covered by it, and other provisions may follow their own application timelines — Article 86, on the right to an explanation of individual decision-making, is one worth checking in this respect. Reading the change as “nothing connected to Annex III matters until 2027” means overlooking duties that are already in effect.

The Annex III Scope in Financial Services Is Narrower Than It Looks

The second thing that is easy to get wrong is scope.

Annex III does not cover financial institutions’ credit and underwriting activities in general. The financial-sector uses it lists are specifically these two:

  • AI systems intended to be used to evaluate the creditworthiness of natural persons or to establish their credit score, with the exception of AI systems used to detect financial fraud
  • AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance

This is not a provision covering underwriting in general, nor pricing across property and casualty or commercial lines.

Beyond that, even where a use does fall within the listed categories, it may not be treated as high-risk if it meets the conditions in Article 6(3) — for instance, where the system performs a narrow procedural task and does not materially influence the outcome of the decision. Conversely, a system that performs profiling of natural persons is always considered high-risk.

The practical implication is not to assume that everything touching these business lines is automatically high-risk. The intended purpose of the specific system has to be tested against the classification criteria in Article 6.

Why the Deferral Happened

The AI Omnibus recitals identify several reasons for the deferral: delays in preparing the standards needed to implement the high-risk requirements, delays in putting national governance and conformity assessment structures in place, and a compliance burden that had become heavier than originally anticipated.

The European Commission has likewise described the extension as securing time to prepare standards, common specifications, and guidance, and to build supervisory capacity.

In other words, this deferral does not signal that the rationale for regulating high-risk AI has weakened. It is more accurately read as an implementation deferral intended to create conditions under which compliance is actually achievable.

That reading connects directly to the next point.

Transparency Obligations Differ for Providers and Deployers

The transparency obligations are not uniform. The applicable duty depends on the type of system and on whether the organization is acting as a provider or a deployer.

Under Article 50(1), providers of AI systems intended to interact directly with natural persons must design and develop those systems so that people are informed that they are interacting with AI. An exception applies where this is obvious to a reasonably well-informed, observant, and circumspect person, taking the circumstances and context of use into account.

The duty to mark synthetic audio, image, video, and text content in a machine-readable format falls on providers.

By contrast, deployers are responsible for disclosing deepfakes and certain AI-generated text published on matters of public interest. The disclosure obligation for public-interest text does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

There is also an important transition period. Article 50 applies from 2 August 2026, but providers of synthetic-content systems placed on the market before that date have until 2 December 2026 to comply with the machine-readable-marking requirement.

Where a financial institution uses a third-party AI service, it should determine — by reference to the Act’s definitions and the actual arrangement — whether it is acting as a provider or a deployer. Contracts can allocate implementation and verification responsibilities, but they do not by themselves determine the institution’s regulatory role.

A Deferral Is Not a Reason to Pause

The deferral should not be read to mean that governance for creditworthiness decisions and life and health insurance risk and pricing decisions can wait until 2027, for two reasons.

The first is that the deferral moved the timing of a legal obligation. It did not remove the risk that these systems produce erroneous outcomes.

The second is that deferring the AI Act’s high-risk obligations did not suspend any obligations that may already apply under data-protection, privacy, consumer-protection, anti-discrimination, or sector-specific financial law. The AI Act states that it applies without prejudice to those bodies of law.

When AI is integrated into operational decision-making, errors should be treated as an expected possibility rather than an exceptional event. Regardless of when a regulatory obligation starts to apply, if AI is involved in decisions that are hard to reverse and have significant consequences — decisions on individual creditworthiness and life or health insurance risk and pricing among them — the mechanisms for tracing the basis of a decision, and the points at which a person can intervene and correct it, need to be designed in advance.

What is worth checking during the transition period is not only average accuracy at the point of deployment. Whether performance differs across applicant attributes and usage conditions, whether the distribution of input data has shifted, and whether human overrides and appeals are concentrated in particular groups all require continuous monitoring once the system is live. The aim is to design initial validation, post-deployment monitoring, and suspension and remediation as a single, integrated lifecycle rather than three separate events.

The same applies to human oversight. Placing a person in the process as a formality is not sufficient. Those assigned to oversight need the authority and the capability to interpret the output, to decline to use it, to override it, and to stop the process — and the organization needs to be clear about where final operational responsibility sits.

Five Questions to Address During the Transition Period

The following questions are illustrative, not prescriptive. Their content and priority will vary with the organization’s risk appetite and its existing creditworthiness-assessment or life and health insurance processes.

  • Use, classification, and role: Is the system used to evaluate creditworthiness or establish credit scores for natural persons, or for risk assessment and pricing in life or health insurance for natural persons? Does it meet the classification criteria in Article 6? Is the organization the provider, the deployer, or a party that becomes a provider by placing its name or trademark on the system, substantially modifying it, or changing its intended purpose in a way that makes it high-risk?
  • Human oversight and decision boundaries: Who reviews the output, and under what conditions does a person override it, stop it, or switch to manual handling? Do those assigned to oversight have the necessary authority, capability, and training?
  • Monitoring of data, performance, and bias: Is the input data appropriate for the intended purpose? How will differences in performance across attributes and usage conditions, shifts in data distribution, misclassifications, and human override rates be monitored on an ongoing basis?
  • Records, explanation, and review: Can you record the data, model, version, output, and human interventions on which a decision was based? Can you respond when an affected person requests an explanation, human review, or reconsideration?
  • Impact assessment, complaints, and suspension: How will you design the pre-deployment impact assessment, complaint handling, appeals, incident response, and the procedure for suspending the system and reverting to manual processing?

The final item carries particular weight in financial services. Once the deferred provisions become applicable, deployers of the Annex III high-risk systems covered by points 5(b) and 5(c) will be required to carry out a fundamental rights impact assessment before deploying the system. That assessment covers matters such as the processes in which the system will be used, the categories of people affected, the risks anticipated, the human oversight arrangements, the measures to be taken if a risk materializes, and complaint handling.

Under the deferred high-risk framework, conformity assessment is primarily the provider’s responsibility. A financial institution that deploys a third-party system does not automatically assume the provider’s conformity-assessment obligations. The required preparation depends on the institution’s role.

Summary

The AI Act became generally applicable on 2 August 2026, and the Article 50 transparency obligations also became applicable on that date.

For AI systems classified as high-risk under Article 6(2) and Annex III, Chapter III, Sections 1 to 3 — except Article 6(5) — will apply from 2 December 2027.

Getting the distinction right is not about minimizing the compliance burden. It is about directing limited preparation time to the right areas.

In practice, organizations should work on two timelines in parallel: complying with provisions that already apply and preparing for the deferred high-risk obligations.

The deferral is not a reason to pause. As we see it, it is a preparation period in which to classify in-scope uses, determine the organization’s role, and develop effective oversight, record-keeping, fundamental-rights-impact-assessment, complaint-handling, and suspension processes.

Sources and Verification

This article was prepared as of August 2026, drawing principally on the consolidated text of Regulation (EU) 2024/1689 (the AI Act) as of 27 July 2026, Regulation (EU) 2026/1744 (the AI Omnibus), the European Commission’s AI Act implementation timeline, and the European Commission’s announcement of 31 July 2026 concerning the transparency obligations and the start of enforcement.

The AI Act entered into force on 1 August 2024 and became generally applicable, in principle, on 2 August 2026. The AI Omnibus entered into force on 27 July 2026 and moved the application of Chapter III, Sections 1 to 3 — except Article 6(5) — to high-risk AI systems under Article 6(2) and Annex III to 2 December 2027.

The financial-sector Annex III uses referred to in this article are the evaluation of creditworthiness or establishment of credit scores for natural persons (excluding systems used to detect financial fraud), and risk assessment and pricing in relation to natural persons for life and health insurance. Actual high-risk classification depends on the intended purpose of the AI system and on the criteria and exceptions in Article 6.

Legal texts, guidance, and implementation timelines may be updated. When assessing how these rules apply to a specific system, please confirm against the latest official sources and seek professional advice.

Back to articles