Regulatory brief · EU AI Act
Credit scoring is high-risk. The date moved; the obligation did not.
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases. The Digital Omnibus on AI deferred high-risk obligations for stand-alone Annex III systems — the category containing creditworthiness assessment — from 2 August 2026 to 2 December 2027.
The timeline, including the dates people get wrong
| Date | What applies |
|---|---|
| 1 Aug 2024 | Regulation enters into force |
| 2 Feb 2025 | Prohibited practices (original set) and AI literacy obligations |
| 2 Aug 2025 | General-purpose AI (GPAI) model obligations |
| 2 Aug 2026 | Most Article 50 transparency obligations — this date still stands |
| 2 Dec 2026 | New prohibited practices; Article 50(2) transparency for legacy systems |
| 2 Dec 2027 | High-risk obligations for stand-alone Annex III systems, including creditworthiness assessment (deferred from 2 Aug 2026) |
| 2 Aug 2028 | High-risk obligations for AI embedded in regulated products under Annex I |
Three errors we see repeatedly, worth stating plainly because they change planning:
- “High-risk became enforceable in August 2025.” No. That was the GPAI model date. High-risk was never scheduled for 2025.
- “High-risk applies from August 2026.” Formerly correct, now superseded. Annex III stand-alone systems moved to December 2027.
- “So August 2026 no longer matters.” It does. Most Article 50 transparency obligations still land then.
The Digital Omnibus changes take effect on formal adoption and publication in the Official Journal.
Why lending is in scope
Annex III lists high-risk use cases for stand-alone AI systems. It includes creditworthiness assessment and credit scoring of natural persons. Credit underwriting, credit scoring and consumer lending decisions are therefore high-risk. The deferral extends the runway; it does not remove the classification.
There is a narrow carve-out for systems performing purely procedural tasks or not materially influencing the outcome of decision-making. Do not assume it covers something sitting in the credit decision path.
What high-risk actually requires, and what Sentinel supplies
| Obligation | What Sentinel provides |
|---|---|
| Risk management system across the lifecycle | Per-agent guardrail thresholds, materiality tiering, release-gated evaluation before policy change |
| Data and data governance, examined for bias | Data-quality scoring on every decision; disparate-impact monitoring against the four-fifths rule |
| Technical documentation | Model cards and inventory with metadata and review tracking |
| Record-keeping and automatic logging over the lifetime | Hash-chained append-only audit events; per-decision evidence bundles you can verify independently |
| Transparency and information to deployers | Plain-English decision summaries, decision paths, counterfactuals |
| Human oversight | The ESCALATE verdict and a human review queue; kill switches at agent, type and global scope |
| Accuracy, robustness and cybersecurity | Eleven-stage pipeline; injection scanning; published latency benchmarks |
Supplying a control is not the same as discharging an obligation. Conformity assessment is yours; these are the artefacts it rests on.
Sources
Check every claim above. We would rather you did.
If we have characterised any of this incorrectly, tell us and we will correct the page.
Design partners
Two years is less runway than it sounds.
Annex III conformity needs logging, oversight and documentation that exist from day one, not reconstructed in 2027. Start in shadow mode and build the record now.