By Rafael Luque Ocaña

Financial services: high risk is in your business, but narrower than you'd think

Annex III.5 reaches creditworthiness assessment and life and health insurance pricing. Three carve-outs in the literal wording itself — natural persons only, and fraud detection expressly excluded — leave out much of what is feared.

In most companies high risk sits in HR, not in the core business. In financial services the answer flips: here it genuinely is in the business.

But it flips less than the sector fears, for a reason written into three carve-outs in Annex III itself that are almost never quoted.

What point 5 says

"(b) AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;"

"(c) AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;"

Two activities, and each carries a carve-out inside the same sentence.

Carve-out 1 — "natural persons"

Letter (b) does not say "evaluate creditworthiness." It says evaluate the creditworthiness of natural persons.

The consequence is significant and is routinely overlooked: corporate credit-risk analysis falls outside point 5. A model that scores the creditworthiness of a company, rates a corporate portfolio, or assesses the risk of a business-to-business transaction is not describing a natural person.

That leaves a considerable share of business banking, factoring, trade credit insurance and B2B financial analysis outside high risk. Not without obligations — these remain AI systems, subject to whatever their own classification requires — but outside this point.

Where it does apply in full: consumer credit, mortgages, microloans, retail financing, individual credit scoring. There, the person being assessed is a natural person and letter (b) applies.

Carve-out 2 — fraud, excluded in writing

Letter (b) ends with an express exception: "with the exception of AI systems used for the purpose of detecting financial fraud."

This is not interpretation or analogy: it is written into the same clause. A system whose purpose is to detect fraud does not fall under point 5(b), even if it analyses natural persons and even if its output has consequences for them.

The question that decides — and it is not always comfortable to answer — is what the system is for. If its function is to decide whether financing is granted, it is creditworthiness. If its function is to detect anomalous transactions, it is fraud. The same scoring engine can be doing the former under the label of the latter — and what counts then is the actual purpose, not the project's name.

Carve-out 3 — "life and health," not every line of insurance

Letter (c) does not cover the whole insurance book either. It names life and health insurance.

Motor, home, liability, commercial multi-risk: AI-driven pricing in those lines does not appear in point 5(c). The carve-out is as explicit as the previous ones and has the same effect: it narrows the perimeter considerably compared with what is usually assumed.

What these three carve-outs mean together

That classification in this sector is not resolved by the type of company, but system by system and purpose by purpose.

Two entities of the same size and the same business can have very different profiles depending on whom they assess (a natural person or a company), for what purpose (granting or detecting), and in which line of business. There is no "sector-wide" answer, and whoever gives one — in either direction — is oversimplifying.

It is exactly the same criterion that governs everything else: classification depends on actual use, not on the product or the nominal activity.

And the part it shares with everyone else

A financial entity also recruits and evaluates staff, and Annex III.4 applies to it just the same. With one nuance specific to this sector: the risk team usually has a culture of modelling, validation and documentation, while internal administration software does not go through that filter. The best-governed system and the worst-governed system live under the same roof, and the latter is on no one's radar.

The date

The Annex III regime starts on 2 December 2027 — and much of the guidance out there still says August 2026. Today, no non-compliance is possible through this route.

What is already in force since 2 February 2025, for any entity and any classification, is Article 4 on AI literacy — rewritten by the Digital Omnibus without ceasing to be binding — and Article 5. And in parallel, for decisions that produce legal effects or significantly affect a person, Article 22 GDPR has its own threshold and its own regime — one that does not depend on the EU AI Act's timeline and has been enforceable for years.

Content pursuant to Articles 4 and 5 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJ 24 July 2026), and Article 22 of Regulation (EU) 2016/679.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.