Get In Touch
katarzyna.szczudlik@gmail.com
Tel: ‪+48 663 696 999‬
Work Inquiries
Schoenherr Attorneys at Law Plac Małachowskiego 1 Warsaw, Poland
ka.szczudlik@schoenherr.eu
Back

Is Your AI System High-Risk? A Practical Guide for Financial Services and Technology Companies

 


The European Commission has published draft guidelines on high-risk AI classification under the EU AI Act – and for most companies, the critical question is not whether the AI Act applies to them, but whether their specific AI systems fall into the high-risk category, and what that means in practice.

This post walks through the classification framework, the exceptions that matter most for financial services businesses, and the action points you should be working on now.


Why High-Risk Classification Matters

High-risk AI systems are subject to the most demanding obligations under the AI Act — data governance requirements, transparency obligations, human oversight mechanisms, bias testing, and conformity assessments. Getting the classification wrong has real consequences: either you over-comply (costly and operationally burdensome) or you under-comply (regulatory exposure, potential fines).

The draft guidelines clarify several areas that were genuinely ambiguous in the original text. They are non-binding, but they signal how the Commission expects the rules to be applied — and they are worth taking seriously.


How the Classification Works: Two Pathways

There are two routes to high-risk classification under Article 6.

Pathway 1 — Safety components (Article 6(1) + Annex I) Your AI system is a safety component of a regulated product, or is itself such a product, and requires third-party conformity assessment. Think medical devices, machinery, civil aviation systems.

Pathway 2 — Specific use cases (Article 6(2) + Annex III) Your AI system falls within one of the use cases explicitly listed in Annex III. For financial services, the most relevant are:

    • Credit scoring and creditworthiness assessment of natural persons

    • AML/CFT systems

    • Insurance risk assessment and pricing for natural persons

    • Biometrics

If your AI system falls under Pathway 2, read carefully — because there is a filter mechanism that may allow you to step out of high-risk classification.


The Filter Mechanism: When You Can Step Out

Even if your AI system formally falls within an Annex III use case, Article 6(3) allows providers to self-assess and exempt it from high-risk classification — if the system meets at least one of four conditions:

    1. It performs a narrow procedural task

    1. It improves the result of a previously completed human activity

    1. It detects decision-making patterns without replacing human assessment

    1. It performs a preparatory task to an assessment

What you need to know about the filter:

    • The four conditions are exhaustive. You cannot rely on general arguments about low risk.

    • The filter does not apply to Pathway 1 systems at all.

    • The filter does not apply to AI systems that perform profiling of natural persons within the meaning of GDPR Article 4(4). This is a hard rule with no exceptions — and it has significant implications for transaction monitoring, KYC, and customer risk scoring tools.


What This Means for Financial Services

This is where the guidelines get specific — and where most financial institutions and fintechs need to pay close attention.

Credit Scoring and Lending

AI systems used to assess the creditworthiness of natural persons or establish their credit score are explicitly high-risk. This covers banks, neobanks, BNPL providers, and any fintech offering lending products to individuals.

Important carve-out for B2B: AI systems intended solely to assess the creditworthiness of legal persons — evaluating balance sheets, financial statements, corporate data — are not classified as high-risk under Annex III, provided the system is not intended to evaluate the personal finances of natural persons. This is a meaningful distinction for B2B lending platforms and corporate credit tools.

One nuance to flag: where the owner of a legal entity is assessed as a personal guarantor backing a company loan, that individual does not fall under the B2B carve-out, because the primary beneficiary of the credit is the company.

AML, CFT and Fraud Detection

AML/CFT systems are not automatically high-risk — but they can become high-risk if they are functionally linked to and simultaneously intended for creditworthiness evaluation or credit scoring of natural persons.

The fraud detection exception under Annex III point 5(b) does not cover AML/CFT. These are governed by separate EU legislation and assessed differently.

Practical implication: if your transaction monitoring or KYC system uses AI, map its functional links to any credit decision processes before assuming it falls outside high-risk classification.

Post-Credit Monitoring

AI systems used solely for monitoring credit exposures after credit has already been granted — tracking credit-related activity, assessing borrower risk, detecting early warning signs of default — are not classified as high-risk. The high-risk classification applies at the point of creditworthiness assessment, not to post-disbursement portfolio monitoring.

Insurance Underwriting

AI systems used to evaluate risk and set pricing for health and life insurance for natural persons are high-risk. Insurtech companies using AI-driven underwriting models should treat this as confirmed and plan accordingly.

Interaction with CRR and Solvency II: AI systems used exclusively for prudential purposes — such as calculating risk-weighted exposures under the IRB approach (CRR Article 143) or internal models under Solvency II Article 120 — are not high-risk, provided they are not simultaneously intended for credit scoring of natural persons. Where the same system serves both purposes, it is high-risk in its entirety. Map the boundaries between your prudential and retail-facing systems carefully.

General-Purpose AI in Financial Products

Many fintechs deploy LLMs and foundation models for customer-facing applications — chatbots, robo-advisors, automated financial guidance. Under the guidelines, if such a system is presented as broadly applicable and does not explicitly and consistently exclude high-risk financial use cases, it will be treated as high-risk — regardless of disclaimers in your terms of service.

A disclaimer is not a classification strategy. If you want to rely on the filter mechanism or argue that your system falls outside Annex III, that position must be reflected consistently across your technical documentation, instructions for use, promotional materials, and product positioning.


The Value Chain: Third-Party Providers Are Not Off the Hook

Under Article 25 AI Act, distributors, importers, and deployers can become subject to provider obligations if they rebrand, substantially modify, or change the intended purpose of an AI system so that it becomes high-risk.

For the fintech ecosystem — where AI components are routinely sourced from third-party vendors and integrated into regulated financial products — this is a significant point. BaaS providers, API integrators, and white-label solution providers should assess whether their customers’ use of their systems could trigger provider-level obligations for them.


Key Dates

Obligation Date
Article 6(2) high-risk obligations (credit scoring, insurance, AML) 2 December 2027
Article 6(1) high-risk obligations (safety components) 2 August 2028
Financial institutions that are public authorities or deployers 2 August 2030 (latest)

Compliance programmes for regulated financial services businesses typically require 12 to 18 months to implement. If you are in scope, now is the right time to begin.


Three Action Points for Financial Services Businesses

1. Map your AI systems against Annex III use cases. Do not assume you are out of scope. Start with credit scoring, AML/KYC, insurance underwriting, and any customer-facing AI — and document your assessment.

2. Check whether the filter mechanism applies — and can be documented. If you believe your system qualifies for the Article 6(3) exemption, that position must be consistent across all materials: technical documentation, instructions, marketing, and terms of service. A ToS disclaimer alone is not enough.

3. Review your third-party AI supply chain. Understand what AI systems you source, how you use them, and whether your use could trigger high-risk classification — for you or your providers.


The list of high-risk use cases will be reviewed annually. The Commission can add, modify, or remove use cases via delegated acts. These guidelines are non-binding and the ultimate interpretation rests with the CJEU — but they are the clearest signal yet of where the lines will be drawn.

If you have questions about how the AI Act applies to your business or products, get in touch.


Katarzyna Szczudlik is a Partner at Schoenherr in Warsaw, advising international fintech companies, technology businesses and regulated organisations on AI regulation, fintech law and EU market entry. She is ranked by Chambers & Partners, Legal 500 EMEA and Forbes Poland.

high-risk AI classification flowchart EU AI Act Article 6
Katarzyna Szczudlik
Katarzyna Szczudlik
http://www.techlawyer.pl
I help international companies enter and scale in Poland - with a strong focus on fintech, financial regulation and technology-driven businesses. I am one of Poland's leading lawyers specialising in fintech regulation, MiCA and AI law.

Leave a Reply

This website stores cookies on your computer. Cookie Policy