AI risk classifications and compliance timelines for financial services
The EU Artificial Intelligence Act, effective from August 1, 2024, establishes a regulatory framework governing AI development, deployment, and use within the European Union. The legislation aims to ensure AI systems are safe, transparent, traceable, non-discriminatory, and environmentally friendly. It applies to any provider or deployer of AI systems whose outputs are utilized in the EU, regardless of the provider’s location. The Act focuses on regulating specific AI applications rather than the technology itself, imposing stricter requirements on higher-risk applications.
The European Commission's AI Office, together with national authorities, began enforcing the Artificial Intelligence (AI) Act from 2 August 2026.
Compliance timeline
The EU AI Act follows a phased implementation schedule for organizations to align with the new requirements:
The framework delineates AI systems into four risk categories, each with distinct compliance obligations.
|
risk category |
DESCRIPTION AND EXAMPLES |
COMPLIANCE OBLIGATIONS |
| Unacceptable risk | Systems threatening safety, rights, and livelihoods (e.g., social scoring or real-time biometric identification). | Complete prohibition on deployment within the EU. |
| High risk | Systems used in critical infrastructure, education, employment, law enforcement, and credit scoring. | Strict obligations including risk mitigation, high-quality datasets, detailed logging, and human oversight. |
| Limited risk | Systems with specific transparency risks, such as conversational chatbots, image generators, or deepfakes. | Mandatory disclosure informing users that they are interacting with AI. |
| Minimal risk | Systems that pose little to no risk, such as AI-enabled video games or spam filters. | No additional obligations, though voluntary codes of conduct are encouraged. |
Technology providers must be aware of the following:
Financial services firms must evaluate how they leverage AI models in their operations, particularly in areas such as risk management, credit assessment, and compliance reporting:
Regnology proactively embeds compliance measures into its product and service delivery: