Regulatory brief · EU AI Act

Credit scoring is high-risk. The date moved; the obligation did not.

Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases. The Digital Omnibus on AI deferred high-risk obligations for stand-alone Annex III systems — the category containing creditworthiness assessment — from 2 August 2026 to 2 December 2027.

The timeline, including the dates people get wrong

DateWhat applies
1 Aug 2024Regulation enters into force
2 Feb 2025Prohibited practices (original set) and AI literacy obligations
2 Aug 2025General-purpose AI (GPAI) model obligations
2 Aug 2026Most Article 50 transparency obligations — this date still stands
2 Dec 2026New prohibited practices; Article 50(2) transparency for legacy systems
2 Dec 2027High-risk obligations for stand-alone Annex III systems, including creditworthiness assessment (deferred from 2 Aug 2026)
2 Aug 2028High-risk obligations for AI embedded in regulated products under Annex I

Three errors we see repeatedly, worth stating plainly because they change planning:

  • “High-risk became enforceable in August 2025.” No. That was the GPAI model date. High-risk was never scheduled for 2025.
  • “High-risk applies from August 2026.” Formerly correct, now superseded. Annex III stand-alone systems moved to December 2027.
  • “So August 2026 no longer matters.” It does. Most Article 50 transparency obligations still land then.

The Digital Omnibus changes take effect on formal adoption and publication in the Official Journal.

Why lending is in scope

Annex III lists high-risk use cases for stand-alone AI systems. It includes creditworthiness assessment and credit scoring of natural persons. Credit underwriting, credit scoring and consumer lending decisions are therefore high-risk. The deferral extends the runway; it does not remove the classification.

There is a narrow carve-out for systems performing purely procedural tasks or not materially influencing the outcome of decision-making. Do not assume it covers something sitting in the credit decision path.

What high-risk actually requires, and what Sentinel supplies

ObligationWhat Sentinel provides
Risk management system across the lifecyclePer-agent guardrail thresholds, materiality tiering, release-gated evaluation before policy change
Data and data governance, examined for biasData-quality scoring on every decision; disparate-impact monitoring against the four-fifths rule
Technical documentationModel cards and inventory with metadata and review tracking
Record-keeping and automatic logging over the lifetimeHash-chained append-only audit events; per-decision evidence bundles you can verify independently
Transparency and information to deployersPlain-English decision summaries, decision paths, counterfactuals
Human oversightThe ESCALATE verdict and a human review queue; kill switches at agent, type and global scope
Accuracy, robustness and cybersecurityEleven-stage pipeline; injection scanning; published latency benchmarks

Supplying a control is not the same as discharging an obligation. Conformity assessment is yours; these are the artefacts it rests on.

Sources

Check every claim above. We would rather you did.

If we have characterised any of this incorrectly, tell us and we will correct the page.

Design partners

Two years is less runway than it sounds.

Annex III conformity needs logging, oversight and documentation that exist from day one, not reconstructed in 2027. Start in shadow mode and build the record now.