The EU AI Act for banks is usually discussed as a list of prohibitions. For the project leadership of a supervised bank that lends to consumers, the real question was simpler and more urgent: where can we start using AI now without creating a compliance problem, and where should we not touch it yet? We built a one-page AI risk map that answers exactly that, so the discussion inside the bank moved from “should we use AI” to “where do we start”.
The problem: an AI decision nobody in the bank could make alone
A bank with fully automated consumer lending sits right on the most regulated line in the EU AI Act. Creditworthiness assessment of natural persons is listed in Annex III, point 5(b), as high-risk. At the same time, DORA already applies to every ICT third party the bank uses, and any AI or LLM provider counts as one.
The result inside the bank was predictable:
- IT, risk and compliance each held a piece of the answer, and none could approve an AI project alone.
- Deadlines were moving. The high-risk obligations for Annex III were postponed from August 2026 to December 2027, while the transparency obligations of Article 50 stayed on the original timeline.
- Unofficial use was likely already happening through personal ChatGPT-style accounts, which in a supervised institution is an unmanaged third-party channel.
- No shared document showed, on one page, what is allowed now, what waits, and why.
What we built
A one-page decision document, written for the bank’s own team and sourced line by line:
- Two zones, side by side. “Do not touch yet”: the regulated core, meaning creditworthiness scoring, automated decisions about customers and LLMs helping to write credit analysis. It shows the classification (Annex III 5(b)), the applicable articles (logging, transparency, human oversight, deployer duties), the deadline and the penalties of up to EUR 15 million or 3% of global turnover. “Can start now”: internal administration, meaning project status reports, meeting minutes, resource planning and internal knowledge search, which is minimal risk with no customer decisions.
- A timeline of what already applies and what waits. DORA from January 2025, prohibited practices from February 2025, general-purpose AI obligations from August 2025, the Digital Omnibus postponement, Article 50 transparency from August 2026, and Annex III obligations from December 2027. Each date has one line explaining what it means for this bank.
- What DORA means for an AI vendor. The register of information, Article 30 contract terms (audit rights, exit strategy, subcontractor control, data location) and concentration risk, including whose cloud the model actually runs on.
- A three-step path, where the first step needs neither budget nor approval: measure the hours spent on status reports, minutes and internal documents, and classify use cases against the map.
- Four questions to answer first, such as who owns the AI decision (IT, risk or compliance) and whether the DORA register is already complete.

What changes for the bank
| Before | With the risk map | |
|---|---|---|
| The AI question | “Should we use AI at all?” | “Where do we start?” |
| Regulatory picture | Scattered across IT, risk and compliance | One page, every claim sourced |
| Moving deadlines | Uncertain which dates still apply | Timeline of what applies now and what waits |
| AI vendors | “Just use ChatGPT” | DORA checklist before the first data transfer |
| First step | Waiting for a decision | Measuring hours, no deployment needed |
The postponement of the Annex III obligations leaves roughly 16 months. The map turns that into a plan: build skills, documentation habits and governance in the low-risk zone, so they already exist when the rules reach the lending core.
Where people stay in control
The map does not replace legal advice or the bank’s compliance function. It organises public regulation around one bank’s situation and lists the questions only the bank can answer. We ask those questions before proposing anything, because any recommendation made without the answers would rest on our assumptions, not the bank’s position.
Where else this works
The same decision document fits any regulated organisation facing its first AI step:
- Insurers: risk assessment and pricing in life and health insurance are also Annex III high-risk, while product documentation is not.
- Payment and e-money institutions: DORA vendor requirements apply in the same way.
- Public sector bodies: clear lines between citizen-facing decisions and internal administration.
Related use cases: KYB document checks · Competitor policy monitoring · AI meeting minutes and project status. All Internal assistants & tools use cases · How we deliver this: AI strategy & consulting
FAQ
Is credit scoring high-risk under the EU AI Act?
Yes. Creditworthiness assessment and credit scoring of natural persons are listed in Annex III, point 5(b). Under the Digital Omnibus the high-risk obligations apply from 2 December 2027.
What can a bank use AI for right now?
Internal administration with no customer decisions, such as status reports, meeting minutes, resource planning and internal search, is minimal risk. DORA vendor requirements still apply.
Does DORA apply to AI providers?
Yes. An AI or LLM provider used by a financial entity is an ICT third-party service provider. It needs a vendor assessment, Article 30 contract terms and an entry in the register of information.
Need a clear map of where your organisation can start with AI? Talk to us