Systemy Legacy - A8

The AI Act is already in force and applies to banks and insurers, but not all provisions come into effect at once. Prohibited practices will apply from February 2025, obligations for general-purpose AI models (GPAI) from August 2025, and transparency requirements (Article 50) from August 2026. The most onerous obligations – for high-risk systems, including credit scoring – were postponed in June 2026 (as part of the Digital Omnibus package) to December 2027 for systems listed in Annex III and to August 2028 for AI embedded in regulated products (Annex I). However, this is not a reprieve that allows the matter to be put on hold: the most difficult part – the inventory and classification of AI systems – takes precisely that long.

What is the AI Act and who in the finance sector does it affect?

The AI Act (EU Regulation 2024/1689) came into force on 1 August 2024 and is the first comprehensive piece of legislation on artificial intelligence. It is based on a risk-based approach: it classifies AI systems into prohibited, high-risk, limited-risk (transparency obligations) and minimal-risk categories. Obligations vary depending on the category and the role of the entity – the system provider has different obligations to the deployer. Banks and insurers most often act as deployers, but they also sometimes act as providers of their own solutions.

Current timetable (following the Digital Omnibus)

The Digital Omnibus Package on AI was finally approved by the Council of the EU on 29 June 2026, and some of the deadlines were amended. This is the current situation.

Prohibited AI practices have been in force since February 2025.

The rules for general-purpose models (GPAI) have been in force since August 2025. The Digital Omnibus did not affect them.

From 2 August 2026, the transparency requirements set out in Article 50 will come into force – these include, amongst other things, informing users that they are interacting with an AI system and labelling AI-generated content.

From 2 December 2026, new prohibitions (including those relating to the generation of illegal intimate content) and an obligation to label content (Article 50(2)) will come into force for systems already on the market.

From 2 December 2027, the requirements for high-risk systems set out in Annex III will come into force – and this is a key date for the financial sector.

From 2 August 2028, requirements for high-risk AI embedded in regulated products (Annex I) will come into force.

It is worth bearing in mind that the postponement of deadlines for high-risk cases is linked to the readiness mechanism and registration in the database maintained by the AI Authority. The clock has not simply been turned back, but has been reorganised around the registration of systems.

What constitutes ‘high risk’ in banking and insurance?

For the financial sector, the three areas set out in Annex III are of paramount importance. The first is the credit assessment and scoring of individuals – with one significant exception: systems used exclusively for the detection of financial fraud are not considered high-risk. The second is risk assessment and pricing in life and health insurance. The third is HR systems – recruitment, assessment and employment decisions.

For high-risk systems, the AI Act imposes specific obligations: a risk management system, data quality requirements, technical documentation, event logging, ensuring human oversight, transparency towards users, and system registration. These are not things that can be implemented in the week leading up to the deadline.

What to do right now, despite the postponement of deadlines

The temptation to put the matter on the back burner following the postponement of the deadlines is understandable – and misguided. The hardest part of complying with the AI Act is not filling in a documentation template. It lies in identifying all the areas where the organisation uses AI, assigning each use case to the appropriate risk category, and keeping this information up to date as new systems are developed. It is a task that does not get any easier over time.

A reasonable approach is to: take stock of all AI applications (including GenAI and rules embedded in legacy systems), risk classification for each, and then establishing the foundations of governance—human oversight, logs, and documentation. Separately, it’s worth keeping an eye on Article 50, because August 2026 is fast approaching, and the transparency requirements apply to, among other things, chatbots and AI-generated content.

This is where we start during the GenAI workshop and as part of IT consulting: we map out AI applications, classify risks, and set priorities based on a realistic timeline.

The AI Act, GenAI and legacy systems

These three topics are more closely linked than they might seem. GenAI used to assist consultants or summarise documents usually falls into the low-risk category (transparency obligations). But the moment we apply it to creditworthiness decisions, the application enters the high-risk zone – subject to a completely different regulatory regime.

To classify risks at all, you need to know what the system does. And that leads back to taking stock of processes and documentation – including where the decision-making logic is embedded in legacy applications written in Delphi, VB6 or Java EE. Without this visibility, risk classification is based on guesswork, and guesswork is a weak foundation for compliance.

FAQ

Does the AI Act already apply to banks and insurers?

Yes, but in phases. The prohibited practices will come into force in February 2025, whilst the obligations for GPAI models will apply from August 2025. The transparency requirements will apply from August 2026. The obligations for high-risk systems will come into force at a later date.

When will the requirements for high-risk systems come into force?

The Digital Omnibus Package was adopted in June 2026. The obligations for systems listed in Annex III will come into force on 2 December 2027. For AI embedded in regulated products (Annex I), the deadline is 2 August 2028.

Is credit scoring a high-risk system under the AI Act?

Yes. Creditworthiness assessments and credit scoring for individuals are high-risk systems as defined in Annex III. The exception is systems used solely for the detection of financial fraud.

What does Article 50 mean for a bank?

Transparency obligations: informing users that they are interacting with an AI system (e.g. a chatbot) and labelling AI-generated content. These come into force on 2 August 2026.

Does the postponement of the deadlines mean we can wait?

No. The most time-consuming part of the work is taking stock of and classifying all AI applications. Postponing the deadline gives us time to do this properly, rather than being a reason to start later.

Interesting? Feel free to share!

Our Free Legacy Systems Guide

Diagnosis, Modernisation and Exit Strategy