High-Risk AI

Is Credit Scoring AI High-Risk Under EU AI Act?

Creditworthiness and credit-score AI is listed in EU AI Act Annex III 5(b), subject to Article 6 and the financial-fraud exclusion.

12 min read
Joe Braidwood
Joe Braidwood
CEO, GLACIS
12 min read

Quick Answer: LISTED IN ANNEX III. APPLY ARTICLE 6.

EU AI Act Annex III, Category 5(b), lists AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with a financial-fraud-detection exclusion.[1] Providers must still apply Article 6, including the documented Article 6(3) analysis; profiling systems remain high-risk under Article 6(3).

This classification can apply to banks, fintechs, credit bureaus, buy-now-pay-later providers, and other organizations using covered AI to assess the creditworthiness or credit score of natural persons in the EU. Relevant Annex III high-risk obligations apply from December 2, 2027 under the AI Omnibus.

Specified Broker-Dealer Records Require WORM or a Qualifying Audit-Trail Alternative

SEC Rule 17a-4 governs specified broker-dealer records and, after 2022 amendments, permits either WORM storage or an audit-trail alternative meeting the rule. It does not define the EU AI Act Article 12 standard or automatically apply to a lender’s credit-scoring logs.

Where both regimes are relevant, map each record category, retention rule and evidentiary purpose separately rather than importing one framework’s storage rule into another.

ART. 6
Classification Analysis
Dec 2027
Relevant Annex III date
3%
Max Fine (Turnover)
7
Core Articles (9-15)

In This Guide

Annex III Classification: Essential Private Services

The EU AI Act organizes listed high-risk intended uses into eight categories in Annex III. Natural-person creditworthiness evaluation and credit-score establishment appear under Category 5: “Access to and enjoyment of essential private services and essential public services and benefits,” subject to Article 6 and the stated financial-fraud exclusion.

Specifically, Annex III, paragraph 5(b) states:[1]

“AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.”

This is an expressly listed intended use for natural persons, with financial-fraud detection excluded. Providers must still apply Article 6, including the documented Article 6(3) analysis where they contend a listed system does not pose a significant risk; profiling systems remain high-risk under Article 6(3).

Why Credit Scoring Is Listed in Annex III

The EU AI Act’s risk-based approach lists this intended use because of its potential impact on fundamental rights and access to essential private services. The policy concerns include:

What Counts as “Creditworthiness Assessment” AI

The regulation covers AI systems that evaluate creditworthiness. The harder question is what exactly falls within scope. Understanding the boundaries is critical for compliance planning.

Clearly Within Scope

AI System Type Classification Rationale
Credit scoring models HIGH-RISK Directly establishes credit scores
Loan approval AI HIGH-RISK Evaluates creditworthiness for lending
Mortgage underwriting AI HIGH-RISK Assesses borrower creditworthiness
BNPL approval systems HIGH-RISK Credit decision at point of sale
Credit limit AI HIGH-RISK Determines access to credit
Risk-based pricing models HIGH-RISK Creditworthiness determines terms
Alternative data scoring HIGH-RISK Evaluates creditworthiness via non-traditional data

Key Determining Factors

When assessing whether your AI system is in scope, consider these factors:

When Credit Scoring AI IS High-Risk

Many consumer-lending systems may perform the Annex III 5(b) intended use, but prevalence and classification cannot be inferred from the sector label alone. Apply Article 6 to each system. Common scenarios requiring analysis include:

Banks and Traditional Lenders

  • • Consumer loan underwriting models
  • • Credit card approval systems
  • • Mortgage pre-qualification AI
  • • Overdraft eligibility assessment
  • • Line of credit decisioning

Fintechs and Alternative Lenders

  • • BNPL approval algorithms
  • • Peer-to-peer lending risk models
  • • Alternative data credit scoring
  • • Instant loan approval systems
  • • Embedded finance credit checks

Limited Exemption: Fraud Detection Carve-Out

The Annex III text includes one explicit exemption: “with the exception of AI systems used for the purpose of detecting financial fraud.”[1]

This creates a narrow carve-out, but the boundaries require careful analysis:

Likely NOT High-Risk (Fraud Detection)

  • ✓ Transaction fraud detection (identifying suspicious payments)
  • ✓ Identity verification for fraud prevention
  • ✓ Anti-money laundering screening
  • ✓ Account takeover detection

Caution: Gray Areas

These systems may still be high-risk if they influence credit decisions:

  • ⚠ Fraud scores used in credit decisioning (dual-purpose systems)
  • ⚠ Application fraud detection that blocks legitimate applicants
  • ⚠ Risk models that combine fraud signals with creditworthiness

Key principle: If your “fraud detection” system affects whether someone can access credit, it likely falls back into high-risk classification. The exemption is narrow and purpose-specific.

High-Risk Requirements: Articles 9-15

Once classified as high-risk, credit scoring AI must meet comprehensive requirements spanning Articles 9 through 15. These aren’t optional guidelines. They’re legally binding obligations with significant penalties for non-compliance.

Article 9: Risk Management System

Establish and maintain a continuous risk management system that:

  • → Identifies and analyzes known and foreseeable risks
  • → Estimates risks based on intended use and reasonably foreseeable misuse
  • → Adopts suitable risk management measures
  • → Tests to identify appropriate risk management measures

Article 10: Data Governance

Training, validation, and testing datasets must meet quality criteria:

  • → Relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the intended purpose
  • → Appropriate statistical properties for intended purpose
  • → Bias examination and mitigation measures
  • → Documented data collection and preparation processes

Article 11: Technical Documentation

Comprehensive documentation before market placement:

  • → General system description and intended purpose
  • → Design specifications and development methodology
  • → Validation and testing procedures and results
  • → Risk management documentation per Article 9

Article 13: Transparency

Design systems to enable deployers to:

  • → Interpret system output appropriately
  • → Understand capabilities and limitations
  • → Implement human oversight effectively
  • → Provide explanations to affected individuals

Article 14: Human Oversight

Enable effective oversight by natural persons:

  • → Fully understand system capacities and limitations
  • → Monitor operation and detect anomalies
  • → Override or disregard output when necessary
  • → Interrupt system operation (“stop button”)

Article 15: Accuracy & Robustness

Achieve appropriate levels of:

  • → Accuracy: Correct outputs for intended purpose
  • → Robustness: Resilience to errors and inconsistencies
  • → Cybersecurity: Protection against exploitation
  • → Address AI-specific vulnerabilities (data poisoning, adversarial attacks)

Article 12 Logging Requirements: GLACIS Core Relevance

Article 12 requires automatic event-logging capabilities for a covered high-risk system. The appropriate design depends on intended purpose and the wider risk, monitoring and sector-law context; it is not a universal “continuous compliance” record.

Article 12: Record-Keeping Requirements

High-risk AI systems shall be designed with logging capabilities that:

  • 1. Enable automatic recording of events (“logs”) throughout the system lifecycle
  • 2. Ensure traceability appropriate to the system’s intended purpose
  • 3. Support identification of situations that may result in risk or substantial modification and facilitate post-market monitoring
  • 4. Maintain logs with appropriate security measures
  • 5. Retain records for a period appropriate to the intended purpose

What This Means for Credit Scoring

For a credit-scoring system, the following may be useful design and legal-analysis questions. Article 12 does not itself prescribe this field list:

Operational implication: Policy documents may not show how a credit-scoring workflow operated in a particular case. Preserve the records the applicable regime requires and evidence of selected control decisions, while keeping the distinction clear: a log can report what a control recorded; it does not by itself prove continuous compliance or control effectiveness.

Fairness and Bias Requirements Specific to Credit

Credit scoring AI faces heightened fairness obligations due to its impact on protected groups. The EU AI Act addresses this through multiple provisions:

Article 10: Data Quality and Bias

Training datasets must be examined for possible biases “in view of the possible impact on the health and safety of persons, have any negative impact on fundamental rights, or lead to discrimination prohibited under Union law.”[1]

For credit scoring, this means:

Interaction with Existing EU Law

The AI Act operates alongside existing EU anti-discrimination frameworks:

US Regulatory Comparison

Organizations operating in both the EU and US face overlapping but distinct regulatory frameworks. Understanding the differences is critical for global compliance strategies.

EU AI Act vs. US Credit AI Regulation

Aspect EU AI Act US (ECOA/FCRA/CFPB)
Regulatory Approach Prescriptive, process-focused Outcome-focused, principles-based
Pre-Market Requirements Conformity assessment required No pre-market approval
Documentation Comprehensive technical documentation (Art. 11) Model risk management (SR 11-7)
Logging/Audit Trail Mandatory automatic logging (Art. 12) Recordkeeping duties can arise under ECOA/Regulation B, FCRA, prudential guidance and other applicable rules
Explainability Transparency to deployers (Art. 13) Adverse action notices (ECOA/FCRA)
Bias Testing Data governance requirements (Art. 10) Fair lending testing (CFPB guidance)
Human Oversight Explicit requirements (Art. 14) Implicit in fair lending
Maximum Penalties €15M or 3% turnover Varies; CFPB consent orders

Key US Frameworks

Strategic implication: EU and US requirements overlap but are not supersets of one another. A control or record designed for the EU AI Act does not automatically satisfy US fair-lending, adverse-action, privacy, or state-law duties, and the reverse is also true. Map each applicable obligation separately.

Implementation Checklist

Use this checklist to prepare for the relevant Annex III high-risk obligations that apply from December 2, 2027 under the AI Omnibus. Other provisions retain their own dates.

Phase 1: Assessment (Months 1-2)

  • Inventory all AI systems used in credit decisions
  • Classify each system against Annex III criteria
  • Identify provider vs. deployer obligations for each system
  • Gap analysis against Articles 9-15 requirements
  • Assess current logging and documentation capabilities

Phase 2: Risk Management (Months 3-6)

  • Establish Article 9 risk management system
  • Document risk identification and mitigation measures
  • Implement bias testing and monitoring processes
  • Define human oversight procedures (Art. 14)
  • Establish quality management system (Art. 17)

Phase 3: Technical Implementation (Months 6-12)

  • Implement Article 12 logging infrastructure
  • Complete Article 11 technical documentation
  • Validate data governance processes (Art. 10)
  • Test accuracy, robustness, cybersecurity (Art. 15)
  • Build explainability capabilities (Art. 13)

Phase 4: Conformity (Months 12-18)

  • Conduct internal conformity assessment (Art. 43)
  • Prepare EU declaration of conformity
  • Register in EU database (if required)
  • Establish post-market monitoring procedures
  • Train relevant personnel on compliance obligations

Frequently Asked Questions

Is credit scoring AI high-risk under the EU AI Act?

Annex III point 5(b) lists AI intended to evaluate the creditworthiness of natural persons or establish their credit score, excluding financial-fraud detection. Scope depends on operator role and Article 2; “affecting EU residents” is not a substitute for the Act’s territorial test. Providers must also apply Article 6.

What compliance requirements apply to credit scoring AI?

Covered creditworthiness-evaluation and credit-scoring AI must comply with the applicable requirements in Articles 9 to 15, including risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy, robustness, and cybersecurity. Relevant Annex III high-risk obligations apply from December 2, 2027 under the AI Omnibus; required conformity assessment must be completed before placing a covered system on the market or putting it into service once those rules apply.

Is fraud detection AI also high-risk under the EU AI Act?

Fraud detection AI used solely for detecting payment fraud is generally NOT high-risk, as it doesn’t assess creditworthiness. However, if fraud scores influence credit decisions or loan approvals, the system may be caught by high-risk classification. The key distinction is whether the AI output affects access to credit or financial services.

When must credit scoring AI comply with EU AI Act requirements?

Relevant Annex III high-risk obligations apply from December 2, 2027 under the AI Omnibus. Transitional treatment for systems already on the market depends on the Act’s specific provisions and whether a system undergoes a significant change; obtain legal advice for a particular system.

What are the penalties for non-compliant credit scoring AI?

Specified non-compliance with operator obligations can carry an administrative-fine ceiling of EUR 15 million or 3% of total worldwide annual turnover; Article 99 applies the lower applicable fixed or percentage ceiling to SMEs, including startups. Authorities may also require corrective action or restrict a non-conforming system. Actual exposure depends on the actor, infringement, and facts.

How does EU AI Act credit scoring regulation compare to US requirements?

The regimes use different triggers. The AI Act applies role- and system-specific requirements to covered high-risk systems. US ECOA, Regulation B, FCRA, model-risk guidance, privacy law and regulator expectations can impose explanation, fairness, recordkeeping, validation and other duties. Neither is accurately summarized as only process-focused or only outcome-focused.

What logging requirements apply to credit scoring AI under Article 12?

Article 12 requires automatic event-logging capabilities over the high-risk system’s lifetime at a level appropriate to its intended purpose. It does not prescribe a universal credit-scoring field list. Inputs, model versions, outputs, explanation context and oversight actions may be relevant under the wider legal and risk analysis.

References

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act), Official Journal of the European Union, July 12, 2024. EUR-Lex
  2. European Commission, “Regulatory Framework for AI,” Digital Strategy, 2024. EC Digital Strategy
  3. Consumer Financial Protection Bureau, “Consumer Financial Protection Circular 2022-03: Adverse action notification requirements in connection with credit decisions based on complex algorithms,” May 2022.
  4. Board of Governors of the Federal Reserve System, Office of the Comptroller of the Currency, “Supervisory Guidance on Model Risk Management” (SR 11-7), April 2011.

Related Guides