High-risk use case · Annex III §5(b)(c)

EU AI Act — Essential services — credit & insurance

AI to evaluate creditworthiness (excluding fraud detection) or price life and health insurance — high-risk under Annex III §5.

Key obligations apply from

2 August 2026

3d left

Risk tier

high risk

Full AI Act applies by Aug 2027 for remaining Annex I scope

Scope notes: Credit scoring and insurance pricing AI are explicitly high-risk. Fraud detection is carved out but must still comply with other applicable law.

Also on AML Map: Credit and insurance AI may also trigger AML obligations for financial institutions.

Also see AML Map — credit institutions & financial sectors

First steps before 2 August 2026

  1. 1Separate fraud-detection models from creditworthiness scoring for classification
  2. 2Conduct fundamental rights impact assessments before deploying scoring AI
  3. 3Ensure explainability and human review for adverse credit decisions

Who supervises you?

Market surveillance authorities in each Member State enforce the AI Act. The European AI Office supports coordination, GPAI oversight, and cross-border cases.

AI Act implementation & AI Office

Priority mandates for you

3 instruments
GuidelinesIn developmentAML overlap3d leftArt. 96

High-risk AI systems — requirements and conformity

Guidelines on the practical implementation of Chapter III requirements — risk management, data governance, transparency, human oversight, accuracy, and robustness (Art. 96(1)(a)).

Why it matters: Primary interpretive guide for Chapter III conformity once published — distinct from the Art. 6 classification consultation now open.

View on map
GuidelinesIn developmentAML — financial3d leftArt. 97

Application of requirements to Annex III use cases

Guidelines on how Chapter III requirements apply to each category of high-risk AI listed in Annex III.

Why it matters: Maps abstract obligations to concrete use cases — essential for deployers in HR, credit, insurance, and biometrics.

View on map
GuidelinesIn developmentAML — financial3d leftArt. 27(5)

Fundamental rights impact assessment for deployers

Guidelines on conducting fundamental rights impact assessments before deploying high-risk AI — required for deployers of Annex III systems (except where exempt).

Why it matters: Deployer-side obligation distinct from provider conformity — critical for banks, insurers, and public bodies using third-party AI.

View on map
All rules for this roleAI Act on EUR-Lex

This page is an independent orientation guide — not legal advice. National implementation and sector-specific rules may apply. Always verify scope against the official AI Act text and your supervisor.