Skip to main content

Is AI credit scoring high-risk under the EU AI Act?

The system being classified

You build a system that evaluates the creditworthiness of natural persons or establishes their credit score, and offer it in the EU.

Verdict

High-risk system

Your system falls under Annex III or is a regulated product safety component. The full high-risk obligation set applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) — postponed by the 2026 Omnibus. Any Article 50 transparency duties apply already, and the runway is what makes conformity achievable in-house.

14 applicable obligations
Maximum fine tier: €15,000,000 or 3% of global annual turnover
Key date: 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus)

This is the classification of the configuration described above, not of your system. One different answer can move it — which is exactly what the comparison further down shows, and what the free assessment settles in about ten minutes.

What produced this verdict

These are the entire inputs. The engine is deterministic, so these answers always produce the verdict above.

Annex III categories

  • · Access to essential services

Scope and role

  • · Provider — you build it or place it on the market under your name
  • · Placed on the EU market, or output used in the EU

What applies, and from when (14)

Every entry cites the article it comes from and the date it binds. That second column is the part most summaries of the Omnibus get wrong.

ArticleObligationBinding from
Art. 4
AI literacy
Ensure staff dealing with AI systems have a sufficient level of AI literacy (training records recommended).
2 February 2025
Best practice
AI system inventory
Maintain a central register of all AI systems in use, their purpose, risk tier and owner.
Good practice
Art. 9
Risk management system
Establish, document and maintain a continuous, iterative risk management process across the system lifecycle.
2 December 2027
Art. 10
Data and data governance
Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation.
2 December 2027
Art. 11 + Annex IV
Technical documentation
Maintain complete Annex IV technical documentation before placing on the market, kept up to date.
2 December 2027
Art. 12
Record-keeping (automatic logs)
The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime.
2 December 2027
Art. 13
Transparency and instructions for deployers
Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance.
2 December 2027
Art. 14
Human oversight by design
Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system.
2 December 2027
Art. 15
Accuracy, robustness and cybersecurity
Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks.
2 December 2027
Art. 17
Quality management system
Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring.
2 December 2027
Art. 43, 47 + 48
Conformity assessment, declaration and CE marking
Run the applicable conformity assessment procedure (Art. 43), draw up and sign the EU declaration of conformity (Art. 47) and keep it for ten years, then affix CE marking (Art. 48).
2 December 2027
Art. 49
EU database registration
Register the high-risk system in the EU public database before placing it on the market.
2 December 2027
Art. 72
Post-market monitoring
Documented plan to actively collect and analyse performance data throughout the system lifetime.
2 December 2027
Art. 73
Serious incident reporting
Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases).
2 December 2027

What would change this verdict

Each row below is the same scenario with one answer changed, re-run through the same engine. These are not predictions about your system; they are what our classifier returns when that single fact differs. Where one change to the scenario necessarily moves a second answer with it, the row says which, and why.

You claim the Article 6(3) derogation

Becomes minimal risk

Available where the system performs a narrow procedural task, improves the result of prior human work, or does no more than preparatory profiling — and never where it profiles natural persons. Claiming it is a documented decision, not a checkbox.

  • Obligations: 142 (-12)
  • +1 flagged for counsel review
  • Key date changes to No dated obligations pending — AI literacy (Art. 4) applies since 2 February 2025; keep the inventory current

You are the lender deploying it, not the vendor

Same risk tier

Deployers of credit-scoring AI are named Article 27 duty-holders, so a fundamental rights impact assessment enters the picture here even though most private-sector deployers owe none.

  • Obligations: 149 (-5)

Your system is not this system

The assessment asks the same questions this page answered for a generic configuration, and produces the verdict, the gap list and the 30-day plan for yours. Ten minutes, free, no sign-up, and it runs entirely in your browser — your answers never reach us.

Classify your own system →

Other configurations

Produced by rule set 1.6.1, legal state 2026-08-05. The engine is deterministic and contains no language model in the verdict path, and every rule is published at /methodology for you to audit.

AnnexWise is preparation software, not legal advice. This page classifies a described configuration; it is not an opinion on any particular organisation or system.