Breaking

EU AI Act delay spares credit-scoring AI; Aug 2 duties remain

EU AI Act delay spares credit-scoring AI; Aug 2 duties remain

The EU’s Digital Omnibus agreement of May 2026 postpones the AI Act’s high-risk regime — including credit-scoring and insurance-pricing systems — to December 2, 2027, but leaves the August 2, 2026 application date alive for transparency duties, penalties and national enforcement machinery. Financial firms that read the delay as a blanket reprieve are mis-reading it: the EU, UK and US are now regulating the same AI conduct on three different clocks.

The Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024 and becomes generally applicable on August 2, 2026. Under the Digital Omnibus provisionally agreed on May 6, 2026 and confirmed by member-state representatives on May 13, obligations for stand-alone high-risk systems listed in Annex III — the tier that captures creditworthiness assessment and credit scoring of natural persons — slip to December 2, 2027, and AI embedded in Annex I regulated products to August 2, 2028 (Gibson Dunn, May 27, 2026). This analysis walks through what still bites on August 2, how the EU’s paused rulebook compares with the UK’s principles-based approach and the US enforcement-led model, and what compliance teams should sequence between now and December 2027.

Key Facts:

• The AI Act becomes generally applicable on August 2, 2026; the Digital Omnibus defers Annex III high-risk obligations to December 2, 2027 and Annex I embedded systems to August 2, 2028 — Gibson Dunn client alert, May 27, 2026
• Creditworthiness assessment and credit scoring of natural persons sit in Annex III point 5(b); risk assessment and pricing in life and health insurance in point 5(c) — Regulation (EU) 2024/1689
• Article 50 transparency duties (disclosing AI interaction, marking AI-generated content) proceed on the original August 2, 2026 schedule, with a watermarking grace period for existing systems to December 2, 2026 — Gibson Dunn
• Article 99 penalties reach €35 million or 7% of global turnover for prohibited practices, and €15 million or 3% for most other breaches — Regulation (EU) 2024/1689
• The SEC’s first “AI-washing” enforcement — In re Delphia (USA) Inc. and In re Global Predictions, Inc., March 18, 2024 — imposed $225,000 and $175,000 civil penalties — SEC press release 2024-36
• The omnibus text awaits formal adoption and Official Journal publication, expected before August 2, 2026 — Gibson Dunn

Methodology and sources

This analysis draws on the text of Regulation (EU) 2024/1689 (the AI Act) as summarised by the European Commission’s AI regulatory framework page and the Article 26 deployer-obligations text; law-firm analyses of the May 2026 Digital Omnibus from Gibson Dunn and Travers Smith; the SEC’s March 18, 2024 enforcement release; and the FCA’s published AI approach. Jurisdictional scope: EU, UK, US, with Singapore for comparison. Time window: August 2024 – July 2026. Caveat: the omnibus remains subject to formal adoption and Official Journal publication; dates cited are as agreed politically in May 2026 and could shift in the final text.

What survives August 2, 2026 — and what just moved

The omnibus is a re-sequencing, not a repeal. What moved: the full Articles 9–15 high-risk suite — risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness — plus the Article 26 deployer obligations, for stand-alone Annex III systems. For a bank using AI to score consumer credit or an insurer pricing life and health cover, the compliance cliff is now December 2, 2027. What did not move: Article 50 transparency obligations still apply from August 2, 2026 — firms must disclose when customers are interacting with an AI system and ensure AI-generated content is machine-readably marked, with existing systems given until December 2, 2026 on watermarking. The governance chassis also arrives on schedule: member states must have designated national competent authorities, and the Article 99 penalty framework — up to €35 million or 7% of worldwide turnover for prohibited practices, €15 million or 3% for most other violations — becomes operative.

What is the practical effect of the AI Act omnibus for financial services firms? The omnibus, agreed provisionally on May 6, 2026, defers the AI Act’s high-risk obligations for stand-alone Annex III systems — including credit scoring of natural persons under point 5(b) and life and health insurance pricing under point 5(c) — from August 2, 2026 to December 2, 2027 (Gibson Dunn, May 27, 2026). It does not defer the Act’s August 2, 2026 general application date: Article 50 transparency duties for customer-facing AI, the designation of national enforcement authorities, and the Article 99 penalty regime of up to €35 million or 7% of global turnover all proceed on the original schedule. In-scope firms therefore face a two-stage timetable — disclosure and content-marking duties within weeks, and the full risk-management, documentation and human-oversight suite roughly 17 months later.

How the EU, UK, US and Singapore now compare

Jurisdiction / Regulator Instrument & status Effective date Key requirement for financial firms Penalty / sanction
EU (AI Office + national CAs) AI Act, Regulation (EU) 2024/1689, as amended by the Digital Omnibus (pending OJ publication) August 2, 2026 (general; Article 50 transparency); December 2, 2027 (Annex III high-risk incl. credit scoring) Articles 9–15 risk/data/logging/oversight suite for high-risk; Article 50 AI-interaction disclosure and content marking Article 99: up to €35m / 7% turnover (prohibited practices); €15m / 3% (other breaches)
UK (FCA / PRA) No statutory AI regime; 2023 principles-based framework applied through existing rules; FCA AI Update (April 2024) In force now via existing regimes Senior Managers & Certification Regime accountability, Consumer Duty outcomes, existing model-risk expectations Unlimited FCA fines under FSMA; SMCR individual accountability
US (SEC / CFTC) No AI statute; predictive-data-analytics rule proposed July 2023, withdrawn June 2025; enforcement via existing securities law Enforcement-led, ongoing Accurate AI disclosures (Advisers Act Marketing Rule; Section 206); CFTC December 2024 AI advisory for DCMs/FCMs Civil money penalties; Delphia $225,000 and Global Predictions $175,000 (March 18, 2024)
Singapore (MAS) FEAT principles (2018) + Veritas toolkit; supervisory guidance, not statute Voluntary, in effect Fairness, ethics, accountability and transparency assessments for AI in credit and insurance decisioning No AI-specific penalty; general MAS supervisory powers

Sources: Regulation (EU) 2024/1689; Gibson Dunn omnibus alert (May 27, 2026); FCA AI Update (April 2024); SEC press release 2024-36; MAS FEAT principles. Last updated July 4, 2026.

The divergence creates a familiar arbitrage geometry — the same three-way split already visible in best-execution rules for FX. The EU now runs the world’s only statutory AI regime for finance, but with its sharpest teeth parked until December 2027; the UK regulates the same models today through outcome-based rules that never mention AI by name; and the US has chosen enforcement over rulemaking, policing AI through disclosure law. A quantitative fund running identical credit or trading models in London, Frankfurt and New York faces three different questions: “can you evidence good customer outcomes?” (FCA), “does your documentation match Annex IV when the clock restarts?” (EU), and “did you describe the model accurately to investors?” (SEC). The last is the only one that has already produced penalties — which is why compliance teams that deprioritise the US exposure because “there is no US AI rule” have the risk exactly backwards.

“As more and more investors consider using AI tools in making their investment decisions or deciding to invest in companies claiming to harness its transformational power, we are committed to protecting them against those engaged in ‘AI washing.'”

Gurbir S. Grewal, Director of Enforcement, US Securities and Exchange Commission
(SEC press release 2024-36)

Enforcement context: Delphia and Global Predictions set the template

The SEC’s first AI-focused enforcement actions remain the operative precedent for what regulators do while statutes catch up. On March 18, 2024, the Commission settled charges against two registered investment advisers. In re Delphia (USA) Inc.: the Toronto-based adviser claimed from 2019 to 2023 — in SEC filings, a press release and its website — that it “put[s] collective data to work to make our artificial intelligence smarter so it can predict which companies and trends are about to make it big”; the SEC found it had no such capabilities and imposed a $225,000 civil penalty. In re Global Predictions, Inc.: the San Francisco firm falsely marketed itself as the “first regulated AI financial advisor”; it paid $175,000 (SEC, March 18, 2024).

The doctrinal point matters for every jurisdiction in the table above: neither case required an AI statute. Both were brought under the Advisers Act’s antifraud and Marketing Rule provisions — decades-old disclosure law applied to new technology claims. The same pattern is available to the FCA under its financial-promotions and Consumer Duty rules, and to EU national authorities under MiFID II conduct rules, today — regardless of when the AI Act’s high-risk tier switches on. The 2027 deferral pauses the paperwork, not the liability.

What this means for brokers, CASPs, fund managers and compliance teams

For brokers and trading firms: algorithmic-trading governance under MiFID II RTS 6 — testing, kill switches, annual self-assessment — already applies and is untouched by the omnibus. The AI Act’s trading-relevant exposure mostly runs through transparency (client-facing chatbots, AI-generated research content) from August 2, 2026, not through Annex III. Firms should map which customer touchpoints are AI-mediated and build the Article 50 disclosure into onboarding flows now.

For exchanges and CASPs: AI used in market-surveillance and fraud detection is not, in itself, Annex III high-risk, but outputs that feed decisions about natural persons’ access to services can be. The classification exercise — provider versus deployer under Article 26, in-scope versus out — is the deliverable for 2026; the documentation build-out can follow the 2027 clock. Firms already re-papering for DORA’s third-party oversight regime should fold AI-vendor dependencies into the same register.

For fund managers: the US lesson is blunt — market the model as it actually is. Every “AI-powered” claim in a prospectus, pitch deck or website is now testable against Delphia. Managers distributing into the EU should also note that MiCA’s grandfathering cliff of July 1, 2026 shows how EU phase-in dates tend to arrive without further grace.

For legal and compliance teams: sequence three workstreams — (1) August 2, 2026: Article 50 transparency inventory and disclosures, plus confirmation of which national authority supervises you; (2) December 2, 2026: watermarking for existing generative systems; (3) December 2, 2027: full Annex III conformity for credit-scoring and insurance-pricing systems, with Annex IV technical documentation started at least 12 months out. Teams tracking US divergence should read this alongside the CLARITY Act’s SEC–CFTC split — the same pattern of statute-versus-enforcement is playing out in crypto market structure.

“The political agreement on the AI Omnibus package is a pragmatic step towards greater legal certainty. By pushing back key obligations for high-risk systems, lawmakers have recognised that the AI Act cannot work effectively without clear standards, guidance and compliance tools in place.”

Dr Nils Rauer, Partner, Pinsent Masons
(Out-Law)

What’s next: the forward view

Three timelines to watch. First, the omnibus itself: formal adoption and Official Journal publication are expected before August 2, 2026; until publication, the deferred dates are politically agreed but not law, and Rauer’s own caveat — that the changes leave “companies reliant on secondary measures that are still to be finalised” — captures the residual uncertainty. Second, the standards gap the delay was meant to fix: harmonised standards from CEN-CENELEC and Commission guidance on Annex III classification are the documents that will convert the 2027 date from a deadline into a workable regime; their delivery pace through 2026–2027 is the single best indicator of whether December 2, 2027 holds. Third, the counter-current: critics — including civil-society voices arguing the delay “lets high-risk systems dodge oversight” — are pressing Parliament to narrow the deferral in the final text, and a tighter scope for the postponement remains possible. In the US, the SEC’s withdrawal of the predictive-data-analytics proposal in June 2025 leaves enforcement as the whole of the policy; expect further AI-washing actions rather than rulemaking. In the UK, the FCA has signalled continued reliance on existing frameworks in its April 2024 AI Update — meaning the regulatory gap between London and Frankfurt widens in 2027, then narrows sharply.

TL;DR

The EU’s Digital Omnibus, provisionally agreed May 6, 2026, defers the AI Act’s high-risk obligations — including credit scoring (Annex III 5(b)) and life/health insurance pricing (5(c)) — from August 2, 2026 to December 2, 2027, with Annex I embedded systems moving to August 2, 2028 (Gibson Dunn). But August 2, 2026 remains live: Article 50 transparency duties, national enforcement authorities and Article 99 penalties of up to €35 million or 7% of global turnover all arrive on schedule. The UK keeps regulating AI through existing principles, and the US through enforcement — the SEC’s Delphia and Global Predictions AI-washing settlements ($400,000 combined, March 18, 2024) show liability does not wait for statutes.

FAQ

When does the EU AI Act apply to financial services firms?

In stages. The Act became law on August 1, 2024 and is generally applicable from August 2, 2026, when transparency duties and penalties arrive. Under the May 2026 Digital Omnibus, the high-risk obligations most relevant to finance — credit scoring and insurance pricing under Annex III — are deferred to December 2, 2027, and AI embedded in Annex I regulated products to August 2, 2028, subject to formal adoption of the omnibus text.

Is credit scoring high-risk under the AI Act?

Yes. AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are listed in Annex III point 5(b) of Regulation (EU) 2024/1689, making them high-risk and subject to the Articles 9–15 suite — risk management, data governance, technical documentation, logging, human oversight and robustness — once the deferred December 2, 2027 date arrives.

What still takes effect on August 2, 2026?

Article 50 transparency obligations — telling users they are interacting with AI and marking AI-generated content in machine-readable form (existing systems have until December 2, 2026 on watermarking) — plus the designation of national competent authorities and the Article 99 penalty framework of up to €35 million or 7% of worldwide turnover for prohibited practices.

What are the penalties for breaching the AI Act?

Article 99 sets three tiers: up to €35 million or 7% of global annual turnover for prohibited AI practices; up to €15 million or 3% for breaches of most other obligations, including the high-risk and transparency rules; and up to €7.5 million or 1% for supplying misleading information to authorities. The higher of the fixed sum or turnover percentage applies.

How do the UK and US regulate AI in finance without an AI law?

The UK applies existing regimes — FCA Consumer Duty, the Senior Managers & Certification Regime and model-risk expectations — under its 2023 principles-based framework, refreshed in the FCA’s April 2024 AI Update. The US polices AI through existing securities law: the SEC’s Delphia ($225,000) and Global Predictions ($175,000) settlements of March 18, 2024 used the Advisers Act Marketing Rule, and the agency withdrew its predictive-data-analytics rule proposal in June 2025.

Does the omnibus delay reduce legal risk for firms using AI today?

Only narrowly. It pauses the Annex III documentation and conformity workload, not liability under existing law. Misleading AI claims remain actionable under the Advisers Act in the US, financial-promotions and Consumer Duty rules in the UK, and MiFID II conduct rules in the EU — none of which depend on the AI Act’s high-risk tier being in force.

This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.

Rick Steves has seen business and economics through many lenses. He joined the financial services industry in 2009, and has been a financial journalist since 2011. He holds a degree in Business Administration and has experience producing real-time news, from both buy-side and sell-side, as well as for retail traders, brokers and service providers. Steves' work has appeared in a variety of online publications including FX Street, NewsBTC, FinanceFeeds, and The Industry Spread. Rick has great interest in the dynamics of the trading industry. The never-ending clash between technology, economics, regulation, and more importantly, the people.

Most Read

Related Posts

Imdustry insights

Stay Ahead

Get the latest news, insights, and market updates delivered to your inbox every day.

Enter your email address