High-risk use case · Annex III §5(b)(c)
EU AI Act — Essential services — credit & insurance
AI to evaluate creditworthiness (excluding fraud detection) or price life and health insurance — high-risk under Annex III §5.
Key obligations apply from
2 August 2026
Risk tier
high risk
Full AI Act applies by Aug 2027 for remaining Annex I scope
Scope notes: Credit scoring and insurance pricing AI are explicitly high-risk. Fraud detection is carved out but must still comply with other applicable law.
Also on AML Map: Credit and insurance AI may also trigger AML obligations for financial institutions.
Also see AML Map — credit institutions & financial sectorsFirst steps before 2 August 2026
- 1Separate fraud-detection models from creditworthiness scoring for classification
- 2Conduct fundamental rights impact assessments before deploying scoring AI
- 3Ensure explainability and human review for adverse credit decisions
Who supervises you?
Market surveillance authorities in each Member State enforce the AI Act. The European AI Office supports coordination, GPAI oversight, and cross-border cases.
AI Act implementation & AI OfficePriority mandates for you
3 instrumentsHigh-risk AI systems — requirements and conformity
Guidelines on the practical implementation of Chapter III requirements — risk management, data governance, transparency, human oversight, accuracy, and robustness (Art. 96(1)(a)).
Why it matters: Primary interpretive guide for Chapter III conformity once published — distinct from the Art. 6 classification consultation now open.
View on mapApplication of requirements to Annex III use cases
Guidelines on how Chapter III requirements apply to each category of high-risk AI listed in Annex III.
Why it matters: Maps abstract obligations to concrete use cases — essential for deployers in HR, credit, insurance, and biometrics.
View on mapFundamental rights impact assessment for deployers
Guidelines on conducting fundamental rights impact assessments before deploying high-risk AI — required for deployers of Annex III systems (except where exempt).
Why it matters: Deployer-side obligation distinct from provider conformity — critical for banks, insurers, and public bodies using third-party AI.
View on mapThis page is an independent orientation guide — not legal advice. National implementation and sector-specific rules may apply. Always verify scope against the official AI Act text and your supervisor.