Luware Blog | Expert Insights, News from the Cloud

EU AI Act Financial Services Compliance Guide

Written by Dale Cross | 29.09.2026, 14:53:57

AI is now part of banking and insurance processes under regulatory scrutiny in many organizations: credit scoring, insurance eligibility, employee monitoring, and surveillance of regulated conversations. The EU AI Act (also: AI Act) is the European Union's answer to the associated regulatory challenges and has the greatest impact on financial services firms.

This blog article covers how financial services firms are impacted by the EU AI Act, how it interacts with existing regulations, what non-compliance costs, and how to ensure regulatory adherence.

What is the EU AI Act?

The EU AI Act is the European Union's regulation on artificial intelligence, in force since August 1st, 2024 as Regulation (EU) 2024/1689. It classifies AI systems into four risk tiers and scales obligations to each. For financial services firms, the highest-impact rules land on high-risk systems used in credit scoring, insurance underwriting, employee monitoring, and any AI that decides material outcomes for a person.

The four risk tiers of the EU AI Act with examples

The EU AI Act assigns every AI system to one of four risk tiers. This determines the amount of governance needed per use case.

  • Unacceptable risk: AI systems deemed manipulative or harmful are strictly prohibited since February 2, 2025. Examples: Social-scoring systems and untargeted facial-image scraping.

  • High risk: These applications face the most comprehensive compliance requirements (Annex III). Examples: Creditworthiness assessment for natural persons. Risk assessment in life and health insurance. Employment AI including recruitment screening and AI used to evaluate employee conduct during recorded interactions.

  • Transparency risk: AI tools in this category require transparency disclosures, meaning users must be informed they are interacting with AI (Art. 50). Examples: chatbots, voice bots, and generative content.

  • Minimal to no risk: Low-impact applications do not need to fulfill compliance requirements under the EU AI Act. Voluntary codes of conduct can be put in place. Examples: spam filters and transaction-level fraud detection that does not profile natural persons.


The EU AI Act compliance timeline

The EU AI Act follows a staggered implementation over three years:

  • August 1st, 2024: The regulation entered into force.

  • February 2nd, 2025: Unacceptable AI systems have been banned.

  • August 2nd, 2025: General-purpose AI model obligations under Chapter V applied. This included the designation of national supervisory authorities.

  • December 2nd, 2027: Annex III high-risk system obligations apply. This deadline was originally August 2nd, 2026 and was deferred through the European Commission's Digital Omnibus package, which was enforced on 27 July 2026. The reason is practical: A simplification of the AI rules is expected to reduce administrative burden for businesses and grant more time for implementation while safety is preserved.

How the EU AI Act impacts financial services

The EU AI Act impacts financial services firms primarily as deployers of AI. As such, they are independently liable for third-party AI operated under their own authority. Additionally, the impact also scales with classification. High-risk use cases demand stronger compliance measures compared to those classified as transparency or minimal to no risk. Deployer liability and risk tier therefore have to be evaluated together.

Compliance leaders are already recalibrating vendor evaluations around that exposure. Christian Jordan, Global Head of Sales for Luware Recording, observed:

Deployer duties under the EU AI Act

Article 26 of the EU AI Act assigns AI deployers specific duties: use the system according to instructions, monitor operation, retain automatically generated logs for at least six months, and inform affected persons where the AI makes decisions about them.

For instance, unlike a provider, a retail bank usually does not build the model behind its virtual assistant itself; it licenses it. The consequence is that the due-diligence question shifts from "Did we buy from a reputable vendor?" to "Can we evidence conformity for every AI touchpoint in regulated communication, inbound or outbound?".

Which conversation AI is high-risk under the EU AI Act?

Not every AI in a regulated conversation is classified as high-risk under the EU AI Act. Classification depends on what the AI decides, whether the interaction is customer-facing, or internally reviewed.

Conversation AI use case Risk tier Rationale
Real-time creditworthiness scoring during a call High risk Annex III, credit-scoring category
Insurance eligibility scoring during a chat High risk Annex III, insurance-risk category
Sentiment analysis Transparency risk Art. 50, disclosure obligation
Transcription for the record Minimal to no risk Art. 14, human oversight applies
Generative reply suggestions to the agent Transparency risk Art. 50, transparency required
AI-driven post-call quality scoring of the agent High risk Annex III, employee-monitoring
AI flagging recorded conversations for compliance surveillance (keyword or pattern) Minimal to no risk Art. 14, human oversight applies
AI flagging recorded conversations to evaluate individual employee conduct High risk Annex III, employee-monitoring

This table illustrates that a single call can pass through three risk tiers at once. Governance has to cover the highest tier present at every point in the workflow.

How the EU AI Act interacts with DORA, GDPR, and MiFID II

Rather than replacing existing financial-services regulations, the EU AI Act adds an additional layer compliance teams must observe. The consequence is that an AI-touched conversation in a bank may have to comply with four regulatory rules simultaneously:

Regulation Requirement relevant to AI-touched conversations
EU AI Act Deployer conformity, logging, human oversight for high-risk systems
Digital Operations Resilience Act (DORA) ICT risk management, incident reporting, oversight of critical ICT third-party providers
General Data Protection Regulation (GDPR) Lawful basis, data-subject rights, transfer rules, Data Protection Impact Assessment (DPIA) for AI processing personal data
Markets in Financial Instruments Directive (MiFID II) Immutable record-keeping of investment communications for at least five years, tamper-proof

This means that AI vendor selection has to be evaluated against the full stack or regulations an organization has to comply with.

Note for Swiss financial institutions: Where Swiss data protection law applies, the Swiss Federal Act on Data Protection (DSG) takes precedence over the GDPR. For cross-border data processing involving the EU, both legal frameworks must be considered.

Penalties and enforcement: what EU AI Act non-compliance costs

Article 99 of the EU AI Act enforces sanctions for non-compliance through three fine tiers:

Violation Maximum fine Applies to
Article 5 prohibited practices € 35 M or 7% of global annual turnover, whichever is higher any operator
High-risk system obligations failure (Art. 16, 22-24, 26, 31, 33 (1, 3, 4), 34, 50) € 15 M or 3% of global turnover, whichever is higher providers, deployers, importers, distributors
Misleading, incorrect, or incomplete information supplied to authorities € 7.5 M or 1% of global turnover, whichever is higher any operator

Enforcement runs through national supervisory authorities designated by each Member State. As national regulators are still finalizing enforcement guidance, operational specifics may evolve.

How to comply with the EU AI Act: a deployer checklist

Complying with the EU AI Act as a deployer means executing four workstreams: inventory, provider evidence, human oversight, and audit trail. These enable an organization to move from ad-hoc AI use to a defensible governance posture.

1. Inventory existing third-party AI

The most important step is to catalog every AI system already operating in your firm's regulated communication, including shadow AI usage compliance did not sign off on. Embedded AI in existing Microsoft Teams, contact center, CRM, and compliance-surveillance tools is the largest inventory gap for most financial institutions.

Start with these areas:

  • Existing SaaS contracts: review renewal terms for AI clauses added in the last 18 months.

  • Feature-flag audits: Microsoft Copilot, transcription, summarization, and sentiment features often enable by default after a vendor update.

  • Shadow-IT scans: browser extensions, personal AI assistants, and departmental tools deployed outside procurement.

  • Business-line and compliance-surveillance interviews: teams often adopt AI features before central compliance is notified.

The inventory feeds every downstream workstream. Nothing else can be classified, governed, or logged until it is on the list.

2. Collect provider evidence

According to Article 26, deployers must operate high-risk systems per the provider's instructions and retain automatically generated logs. The evidence set for each high-risk system should include:

  • Provider declaration of conformity and CE marking (Art. 48)

  • Instructions for use, including intended purpose and known limitations

  • Technical documentation summary sufficient for internal review

  • Post-market monitoring reports where the provider issues them

  • Log-retention configuration (minimum six months; longer where sector rules apply as in the case of MiFID II)

3. Design human-in-the-loop review for high-risk conversation AI

Article 14 requires effective human oversight of high-risk systems. In practice, this means three things for AI in customer conversations and compliance surveillance:

  • A named human role authorized to intervene, override, or reverse the AI's output within the workflow.

  • Reviewer capacity to understand the AI system's capacities and limitations and interpret outputs correctly in order to monitor operation for anomalies, dysfunctions, or unexpected performance.

  • A record of the review decision that can be reconstructed at audit (Art. 12).

Oversight is not the same as post-hoc audit. It has to be integrated into the workflow before the customer or employee is affected.

4. Build an audit trail auditors will accept

An audit trail is only useful if it is complete, tamper-evident, and reproducible. For AI-touched conversations, four criteria matter:

  • Capture completeness: Every channel where high-risk AI operates must be recorded.

  • Tamper-evident storage: Cryptographic sealing is key to detect any post-hoc alteration.

  • Reproducibility: The AI's inputs, outputs, and decision context can be replayed as the auditor experienced them originally.

  • Certified storage environment: ISO 27001 and SOC 2 attestations on the storage provider are crucial so the chain of custody holds.

Five questions every financial services firm should ask an AI vendor

When selecting an AI vendor, it is incremental for a deployer under the EU AI Act to be able to defend an AI's decision in an examination. The following five questions help firms provide the evidence they need under Article 26:

  1. Where is the data processed and stored, and under whose jurisdiction? The answer determines GDPR exposure. EU-hosted, customer-controlled infrastructure removes the transfer question at source. Non-EU services require standard contractual clauses and a documented transfer impact assessment.

  2. Can you produce a declaration of conformity for any AI feature classified as high-risk? If a vendor cannot produce this on request, a deployer cannot legally operate their AI system under Article 26.

  3. What logs does the system generate automatically, and how long are they retained? In case the AI system does not keep a persistent record, the deployer has to add a separate compliance recording layer to capture the evidence. While six months is the minimum requirement for the EU AI Act, other regulations usually require more. In these cases, retention periods need to satisfy the longer applicable rule.

  4. How can human oversight be implemented in the product? Evaluate answers based on an AI system’s deployment mode and ask to see the reviewer interface and the audit record. SaaS AI: Oversight sits in the vendor's product interface and any workflow tool it integrates into. Private-cloud or on-premises AI: splits oversight between the vendor's controls and the deployer's own workflow tooling. Hybrid setups can put the reviewer interface in one place and the audit record in another.

  5. What certifications hold on the underlying infrastructure, and can we access the current attestations? ISO 27001 and SOC 2 are baseline. Sector frameworks like ISO 22301 for business continuity strengthen the case in DORA-scoped reviews.

How Luware Recording supports EU AI Act compliance

Luware Recording, Luware's compliance recording platform for regulated financial institutions, maps directly to the deployer obligations that carry the largest audit exposure. For instiance, the platform supports customer-selected data residency across the globe. It stores every record in a tamper-evident, cryptographically sealed format in the customer’s own storage account. Luware Recording's AI-driven Speech Analytics is also private and fully auditable.

Obligation Article Luware Recording capability
Deployer log retention EU AI Act Art. 26(6) Automatic logging of every conversation, retained per configured policy
Human oversight of high-risk output EU AI Act Art. 14 Reviewer interface with intervention record, and reproducible playback
Cross-regulation record-keeping EU AI Act Art. 26; MiFID II Art. 16(7); DORA Art. 5) One single archive that supports compliance with different record-keeping rule
Data residency and transfer control GDPR Chapter V Customer-selected data residency
Certified storage environment EU AI Act Art. 15 Certified for ISO 27001, ISO 9001, SOC 2, Microsoft 365. 99.99% SLA.

Luware Recording is leveraged by regulated financial institutions globally to consolidate compliance recording into one auditable record. Andrea Panarese described how Luware Recording supports the financial market infrastructure company SIX in adhering to different regulations:

See our security whitepaper for the underlying documentation or book a demo with one of our compliance experts to see Luware Recording in action.

AI that supports compliance with the EU AI Act

With the final enforcement step of the EU AI Act approaching fast, regulated organizations must learn how to transform AI from a compliance exposure into an operational asset.

Luware Recording is one way to make that shift. Routing automatically flagged conversations to a human reviewer is just one example of how it's AI-driven Speech Analytics supports adherence with EU AI Act requirements.

Fill in the form below to book a demo with one of our compliance recording experts and have all your AI questions answered.

This article contains general information on the EU AI Act and is not legal advice. Firms are advised to take their own legal and compliance advice on the regulation and related data-protection obligations.