EU AI Act in Financial Services: How to Manage AI Risk and Stay Compliant
Table of Contents
AI is now part of banking and insurance processes under regulatory scrutiny in many organizations: credit scoring, insurance eligibility, employee monitoring, and surveillance of regulated conversations. The EU AI Act (also: AI Act) is the European Union's answer to the associated regulatory challenges and has the greatest impact on financial services firms.
This blog article covers how financial services firms are impacted by the EU AI Act, how it interacts with existing regulations, what non-compliance costs, and how to ensure regulatory adherence.
TL;DR
-
The EU AI Act classifies AI into four risk tiers: unacceptable risk, high risk, transparency risk, and minimal to no risk.
-
Most banks and insurers are deployers of third-party AI and carry independent liability for how it operates.
-
AI governance exposure concentrates where AI touches regulated conversations, whether that is a customer-facing chatbot or an internal engine flagging recorded calls for compliance risk.
-
AI vendor selection should evidence conformity documentation, log retention, human oversight, and certified storage attestations before contracting.
What is the EU AI Act?
The EU AI Act is the European Union's regulation on artificial intelligence, in force since August 1st, 2024 as Regulation (EU) 2024/1689. It classifies AI systems into four risk tiers and scales obligations to each. For financial services firms, the highest-impact rules land on high-risk systems used in credit scoring, insurance underwriting, employee monitoring, and any AI that decides material outcomes for a person.
The four risk tiers of the EU AI Act with examples
The EU AI Act assigns every AI system to one of four risk tiers. This determines the amount of governance needed per use case.
-
Unacceptable risk: AI systems deemed manipulative or harmful are strictly prohibited since February 2, 2025. Examples: Social-scoring systems and untargeted facial-image scraping.
-
High risk: These applications face the most comprehensive compliance requirements (Annex III). Examples: Creditworthiness assessment for natural persons. Risk assessment in life and health insurance. Employment AI including recruitment screening and AI used to evaluate employee conduct during recorded interactions.
-
Transparency risk: AI tools in this category require transparency disclosures, meaning users must be informed they are interacting with AI (Art. 50). Examples: chatbots, voice bots, and generative content.
-
Minimal to no risk: Low-impact applications do not need to fulfill compliance requirements under the EU AI Act. Voluntary codes of conduct can be put in place. Examples: spam filters and transaction-level fraud detection that does not profile natural persons.

The EU AI Act compliance timeline
The EU AI Act follows a staggered implementation over three years:
-
August 1st, 2024: The regulation entered into force.
-
February 2nd, 2025: Unacceptable AI systems have been banned.
-
August 2nd, 2025: General-purpose AI model obligations under Chapter V applied. This included the designation of national supervisory authorities.
-
December 2nd, 2027: Annex III high-risk system obligations apply. This deadline was originally August 2nd, 2026 and was deferred through the European Commission's Digital Omnibus package, which was enforced on 27 July 2026. The reason is practical: A simplification of the AI rules is expected to reduce administrative burden for businesses and grant more time for implementation while safety is preserved.
How the EU AI Act impacts financial services
The EU AI Act impacts financial services firms primarily as deployers of AI. As such, they are independently liable for third-party AI operated under their own authority. Additionally, the impact also scales with classification. High-risk use cases demand stronger compliance measures compared to those classified as transparency or minimal to no risk. Deployer liability and risk tier therefore have to be evaluated together.
Compliance leaders are already recalibrating vendor evaluations around that exposure. Christian Jordan, Global Head of Sales for Luware Recording, observed:
The compliance officers from the financial sector whom I have spoken with have shown a great deal of interest in AI and have carefully started using it. It is becoming a standard requirement.
Christian Jordan
Global Head of Sales at Luware
Deployer duties under the EU AI Act
Article 26 of the EU AI Act assigns AI deployers specific duties: use the system according to instructions, monitor operation, retain automatically generated logs for at least six months, and inform affected persons where the AI makes decisions about them.
For instance, unlike a provider, a retail bank usually does not build the model behind its virtual assistant itself; it licenses it. The consequence is that the due-diligence question shifts from "Did we buy from a reputable vendor?" to "Can we evidence conformity for every AI touchpoint in regulated communication, inbound or outbound?".
Which conversation AI is high-risk under the EU AI Act?
Not every AI in a regulated conversation is classified as high-risk under the EU AI Act. Classification depends on what the AI decides, whether the interaction is customer-facing, or internally reviewed.
| Conversation AI use case | Risk tier | Rationale |
| Real-time creditworthiness scoring during a call | High risk | Annex III, credit-scoring category |
| Insurance eligibility scoring during a chat | High risk | Annex III, insurance-risk category |
| Sentiment analysis | Transparency risk | Art. 50, disclosure obligation |
| Transcription for the record | Minimal to no risk | Art. 14, human oversight applies |
| Generative reply suggestions to the agent | Transparency risk | Art. 50, transparency required |
| AI-driven post-call quality scoring of the agent | High risk | Annex III, employee-monitoring |
| AI flagging recorded conversations for compliance surveillance (keyword or pattern) | Minimal to no risk | Art. 14, human oversight applies |
| AI flagging recorded conversations to evaluate individual employee conduct | High risk | Annex III, employee-monitoring |
This table illustrates that a single call can pass through three risk tiers at once. Governance has to cover the highest tier present at every point in the workflow.
How the EU AI Act interacts with DORA, GDPR, and MiFID II
Rather than replacing existing financial-services regulations, the EU AI Act adds an additional layer compliance teams must observe. The consequence is that an AI-touched conversation in a bank may have to comply with four regulatory rules simultaneously:
| Regulation | Requirement relevant to AI-touched conversations |
| EU AI Act | Deployer conformity, logging, human oversight for high-risk systems |
| Digital Operations Resilience Act (DORA) | ICT risk management, incident reporting, oversight of critical ICT third-party providers |
| General Data Protection Regulation (GDPR) | Lawful basis, data-subject rights, transfer rules, Data Protection Impact Assessment (DPIA) for AI processing personal data |
| Markets in Financial Instruments Directive (MiFID II) | Immutable record-keeping of investment communications for at least five years, tamper-proof |
This means that AI vendor selection has to be evaluated against the full stack or regulations an organization has to comply with.
Note for Swiss financial institutions: Where Swiss data protection law applies, the Swiss Federal Act on Data Protection (DSG) takes precedence over the GDPR. For cross-border data processing involving the EU, both legal frameworks must be considered.
Penalties and enforcement: what EU AI Act non-compliance costs
Article 99 of the EU AI Act enforces sanctions for non-compliance through three fine tiers:
| Violation | Maximum fine | Applies to |
| Article 5 prohibited practices | € 35 M or 7% of global annual turnover, whichever is higher | any operator |
| High-risk system obligations failure (Art. 16, 22-24, 26, 31, 33 (1, 3, 4), 34, 50) | € 15 M or 3% of global turnover, whichever is higher | providers, deployers, importers, distributors |
| Misleading, incorrect, or incomplete information supplied to authorities | € 7.5 M or 1% of global turnover, whichever is higher | any operator |
Enforcement runs through national supervisory authorities designated by each Member State. As national regulators are still finalizing enforcement guidance, operational specifics may evolve.
How to comply with the EU AI Act: a deployer checklist
Complying with the EU AI Act as a deployer means executing four workstreams: inventory, provider evidence, human oversight, and audit trail. These enable an organization to move from ad-hoc AI use to a defensible governance posture.
1. Inventory existing third-party AI
The most important step is to catalog every AI system already operating in your firm's regulated communication, including shadow AI usage compliance did not sign off on. Embedded AI in existing Microsoft Teams, contact center, CRM, and compliance-surveillance tools is the largest inventory gap for most financial institutions.
Start with these areas:
-
Existing SaaS contracts: review renewal terms for AI clauses added in the last 18 months.
-
Feature-flag audits: Microsoft Copilot, transcription, summarization, and sentiment features often enable by default after a vendor update.
-
Shadow-IT scans: browser extensions, personal AI assistants, and departmental tools deployed outside procurement.
-
Business-line and compliance-surveillance interviews: teams often adopt AI features before central compliance is notified.
The inventory feeds every downstream workstream. Nothing else can be classified, governed, or logged until it is on the list.
2. Collect provider evidence
According to Article 26, deployers must operate high-risk systems per the provider's instructions and retain automatically generated logs. The evidence set for each high-risk system should include:
-
Provider declaration of conformity and CE marking (Art. 48)
-
Instructions for use, including intended purpose and known limitations
-
Technical documentation summary sufficient for internal review
-
Post-market monitoring reports where the provider issues them
-
Log-retention configuration (minimum six months; longer where sector rules apply as in the case of MiFID II)
3. Design human-in-the-loop review for high-risk conversation AI
Article 14 requires effective human oversight of high-risk systems. In practice, this means three things for AI in customer conversations and compliance surveillance:
-
A named human role authorized to intervene, override, or reverse the AI's output within the workflow.
-
Reviewer capacity to understand the AI system's capacities and limitations and interpret outputs correctly in order to monitor operation for anomalies, dysfunctions, or unexpected performance.
-
A record of the review decision that can be reconstructed at audit (Art. 12).
Oversight is not the same as post-hoc audit. It has to be integrated into the workflow before the customer or employee is affected.
4. Build an audit trail auditors will accept
An audit trail is only useful if it is complete, tamper-evident, and reproducible. For AI-touched conversations, four criteria matter:
-
Capture completeness: Every channel where high-risk AI operates must be recorded.
-
Tamper-evident storage: Cryptographic sealing is key to detect any post-hoc alteration.
-
Reproducibility: The AI's inputs, outputs, and decision context can be replayed as the auditor experienced them originally.
-
Certified storage environment: ISO 27001 and SOC 2 attestations on the storage provider are crucial so the chain of custody holds.
Five questions every financial services firm should ask an AI vendor
When selecting an AI vendor, it is incremental for a deployer under the EU AI Act to be able to defend an AI's decision in an examination. The following five questions help firms provide the evidence they need under Article 26:
-
Where is the data processed and stored, and under whose jurisdiction? The answer determines GDPR exposure. EU-hosted, customer-controlled infrastructure removes the transfer question at source. Non-EU services require standard contractual clauses and a documented transfer impact assessment.
-
Can you produce a declaration of conformity for any AI feature classified as high-risk? If a vendor cannot produce this on request, a deployer cannot legally operate their AI system under Article 26.
-
What logs does the system generate automatically, and how long are they retained? In case the AI system does not keep a persistent record, the deployer has to add a separate compliance recording layer to capture the evidence. While six months is the minimum requirement for the EU AI Act, other regulations usually require more. In these cases, retention periods need to satisfy the longer applicable rule.
-
How can human oversight be implemented in the product? Evaluate answers based on an AI system’s deployment mode and ask to see the reviewer interface and the audit record. SaaS AI: Oversight sits in the vendor's product interface and any workflow tool it integrates into. Private-cloud or on-premises AI: splits oversight between the vendor's controls and the deployer's own workflow tooling. Hybrid setups can put the reviewer interface in one place and the audit record in another.
-
What certifications hold on the underlying infrastructure, and can we access the current attestations? ISO 27001 and SOC 2 are baseline. Sector frameworks like ISO 22301 for business continuity strengthen the case in DORA-scoped reviews.
How Luware Recording supports EU AI Act compliance
Luware Recording, Luware's compliance recording platform for regulated financial institutions, maps directly to the deployer obligations that carry the largest audit exposure. For instiance, the platform supports customer-selected data residency across the globe. It stores every record in a tamper-evident, cryptographically sealed format in the customer’s own storage account. Luware Recording's AI-driven Speech Analytics is also private and fully auditable.
| Obligation | Article | Luware Recording capability |
| Deployer log retention | EU AI Act Art. 26(6) | Automatic logging of every conversation, retained per configured policy |
| Human oversight of high-risk output | EU AI Act Art. 14 | Reviewer interface with intervention record, and reproducible playback |
| Cross-regulation record-keeping | EU AI Act Art. 26; MiFID II Art. 16(7); DORA Art. 5) | One single archive that supports compliance with different record-keeping rule |
| Data residency and transfer control | GDPR Chapter V | Customer-selected data residency |
| Certified storage environment | EU AI Act Art. 15 | Certified for ISO 27001, ISO 9001, SOC 2, Microsoft 365. 99.99% SLA. |
Luware Recording is leveraged by regulated financial institutions globally to consolidate compliance recording into one auditable record. Andrea Panarese described how Luware Recording supports the financial market infrastructure company SIX in adhering to different regulations:
Since SIX is a highly regulated company that must comply with various standards like FINMA, FinfraG, and PCI DSS obligations, Luware Recording as certified compliance solution helps ensure our compliance and auditability against internal and external authorities. If compliance is a must for a company, Luware Recording is the state-of-the-art solution.
Andrea Panarese
Senior System Engineer at SIX
See our security whitepaper for the underlying documentation or book a demo with one of our compliance experts to see Luware Recording in action.
AI that supports compliance with the EU AI Act
With the final enforcement step of the EU AI Act approaching fast, regulated organizations must learn how to transform AI from a compliance exposure into an operational asset.
Luware Recording is one way to make that shift. Routing automatically flagged conversations to a human reviewer is just one example of how it's AI-driven Speech Analytics supports adherence with EU AI Act requirements.
Fill in the form below to book a demo with one of our compliance recording experts and have all your AI questions answered.
FAQ about the EU AI Act
What is the EU AI Act?
The EU AI Act is the European Union's regulation on artificial intelligence. It entered into force on August 1st, 2024 and applies extraterritorially to any AI system used in the EU or whose output is used in the EU. The regulation classifies AI systems into four risk categories and scales obligations to each.
What is the compliance deadline for the EU AI Act?
The main high-risk compliance deadline under Annex III of the EU AI Act has been deferred to December 2nd, 2027 through the Digital Omnibus package. Prohibited practices have applied since February 2nd, 2025 and general-purpose AI obligations since August 2nd, 2025. National supervisory authority designations have also already been appointed.
How is the EU AI Act connected to DORA?
The EU AI Act and DORA overlap on third-party risk. DORA (Regulation 2022/2554) governs ICT risk management for financial entities, including oversight of critical ICT service providers. Where an AI vendor is classified as a critical ICT third-party provider under DORA, deployer obligations under both regulations apply to the same contract. Vendor evidence collected for DORA can often be reused for the AI Act's deployer duties.
Is fraud detection AI classified as high-risk under the EU AI Act?
No. Fraud detection AI that analyzes transaction patterns without profiling natural persons is generally classified as minimal to no risk. The classification shifts to high-risk when the system evaluates the creditworthiness of a natural person or triggers adverse decisions about an individual. The determining question is whether the AI decides something about a person or something about a transaction stream.
What fines apply for non-compliance with the EU AI Act?
The EU AI Act sets three fine tiers. Prohibited-practice violations can reach € 35 M or 7% of global annual turnover. High-risk-system violations can amount to € 15 M or 3%. Misleading information supplied to authorities can reach € 7.5 M or 1%. Every ceiling applies the higher of the fixed or percentage figure.
Which authority enforces the EU AI Act in my country?
Each EU Member State designates one or more national competent authorities. Most designations were completed by August 2nd, 2025. Deployers should identify the relevant national authority for their use case.
This article contains general information on the EU AI Act and is not legal advice. Firms are advised to take their own legal and compliance advice on the regulation and related data-protection obligations.
Dale Cross is a voice capture and compliance recording technical expert with over 18 years of experience across multiple call recording platforms, including NICE, Verint, and Red Box. With 7 years in engineering and over 11 years in a pre-sales capacity, he brings a rare blend of deep technical knowledge, commercial acumen, and customer-facing expertise. At Luware, he leads product and partnership strategy, drawing on this broad platform experience and a deep understanding of customer requirements.