
Date
13 August 2026
Category
AI, FinanceHow does the EU AI Act affect digital services in the financial sector?
Digital services in banking and insurance, such as mobile apps, chatbots, robo-advisors, digital onboarding, and fraud detection, are all infused with AI. But the EU AI Act doesn't treat them uniformly: the impact depends on what the service actually does.
What does the EU AI Act require from the most common types of financial digital services?
1. Transparency for chatbots and customer service bots
A chatbot in a mobile app or online bank falls under the EU AI Act’s transparency obligations, which came into force in August 2026. Users must be clearly informed that they are interacting with AI. This disclosure needs to be genuinely noticeable from the very first interaction. A small “AI” badge alone is rarely enough.
2. Digital credit applications are a core high-risk area
An in-app decision on a quick loan or credit card, where AI assesses the applicant’s creditworthiness, is explicitly named as a high-risk use case. Among financial digital services, risk assessment and pricing for life and health insurance also falls into the high-risk category.
In high-risk cases, both the provider and the deployer of the system carry a number of obligations that affect how the application is developed and maintained. Under the revised timeline, most of these obligations become applicable in December 2027, but it’s worth building the application’s logging, documentation, accessibility, and decision-making logic to meet the requirements now.
3. Robo-advisors and investment recommendations
Automated investment advice is not named as a high-risk use case in the EU AI Act, unlike credit scoring or life/health insurance pricing. That doesn’t mean a robo-advisor sits outside the scope of regulation, or that simply disclosing the use of AI is enough: if the application profiles the user, GDPR’s rules on automated decision-making come into play alongside it, and the Act’s prohibition on harmfully manipulative recommendation techniques still applies.
4. Digital onboarding (KYC) and biometric identification require careful line-drawing
Comparing a face image to verify identity is a different matter from biometric categorisation, where the image is used to infer, for example, race or political opinion. The latter is prohibited in all circumstances.
In practice, the problem arises because both capabilities are often sold in the same “biometric AI” package: the same tool that verifies identity sometimes offers an age-estimation feature from image data as an add-on. That’s why, when designing a KYC process, it’s worth clearly documenting what the tool is allowed to do (identity verification) and what it is not (categorisation), so that procurement and feature rollout are deliberate, informed decisions.
5. Fraud detection is not regulation-free
Real-time anomaly detection in payment transactions falls largely on the limited-risk side. Still, an algorithm’s automatic blocking of a transaction or payment instrument readily runs into the territory of consumer protection and GDPR’s rules on profiling and automated decision-making.
Summary for leadership
Among financial digital services, two categories (creditworthiness assessment and insurance risk assessment/pricing) carry the Act’s heaviest regulatory burden, and their full obligations have been pushed to December 2027.
Chatbots already require transparency today. KYC and fraud detection fall on the lighter-regulation side of the AI Act, but they frequently intersect with GDPR and consumer protection, which is why it’s worth reviewing a digital service’s AI features one at a time.
We help our clients build compliance in as a built-in part of their systems and processes, so it travels along with day-to-day work rather than sitting apart from it. The result is a lighter operational burden and a smoother everyday experience.