AI Regulation Tracker / Financial services and lending
EBA Maps the AI Act Onto Credit Scoring and Finds No Escape Hatch
On November 21, 2025, the European Banking Authority told the European Commission the result of a year-long mapping exercise: AI used for creditworthiness assessment and credit scoring of natural persons is high-risk under Annex III(5)(b) of the AI Act, and there is no derogation from the AI Act duties on human oversight, data governance, and cybersecurity. Those obligations apply from August 2, 2026, and they sit on top of the CRD, DORA, and loan-origination rules banks already follow. The letter itself is a supervisory communication, not a binding rule.
If your bank uses a model to decide who gets a loan and on what terms, the EU just handed you a map showing how two rulebooks now cover that model at the same time. On November 21, 2025, the European Banking Authority sent the European Commission a letter reporting the outcome of a mapping exercise it started in January of that year. The job was narrow and practical: line up the requirements the AI Act puts on high-risk AI systems against the banking and payments rules that already apply to credit scoring.
I want to be honest about what this is and is not. The letter is not a new law, and it is not this week's news. It is a supervisory communication from the EBA to the Commission, dated last November, and it feeds into Guidelines the Commission is required to issue on how the AI Act and sectoral finance law fit together. What makes it worth reading now is timing. The AI Act's obligations for high-risk systems, the category that captures credit scoring, become applicable on August 2, 2026. This letter tells you, months ahead, exactly which AI Act duties come with an off-ramp inside the finance rulebook and which do not.
Why credit scoring is high-risk in the first place
The classification is not a judgment call. The EBA states the basis plainly. The mapping covered AI systems used for "creditworthiness assessment or credit scoring of natural persons, due to its classification as high-risk under Annex III(5)(b) of the AI Act." Annex III is the AI Act's list of high-risk use cases, and point 5(b) names credit scoring of individuals specifically. That is why a lending model gets the full weight of the high-risk regime, from risk management systems to record-keeping to human oversight.
Note the boundary. This is about scoring natural persons. Scoring a corporate borrower is not automatically inside Annex III on this basis, and there is a carve-out in the AI Act for detecting financial fraud. But the ordinary consumer and small-business retail lending decision, the one most banks automate first, is squarely high-risk.
The finding that matters: no derogation where it counts
Here is the heart of the letter. The AI Act anticipates that some of its high-risk requirements will overlap with existing sectoral law, and for those it allows what the EBA calls targeted derogations and other synergies, meaning you can satisfy the AI Act by meeting the equivalent finance rule instead of running a parallel process. But that mercy does not extend to everything.
In the EBA's words, "the AI Act does not envisage targeted derogations or other regulatory synergies for other requirements on high-risk AI systems (e.g. human oversight, data governance, cybersecurity)," for which the EBA found that EU financial services law already includes a wide range of requirements. Read that carefully. It cuts two ways. There is no formal derogation letting you skip the AI Act duties on human oversight, data governance, and cybersecurity. And at the same time, the EBA is saying you are probably already doing most of the underlying work under finance law, so the task is integration rather than a cold start.
The letter is concrete about where that existing coverage lives. It points to DORA as extensively covering the cybersecurity and business-continuity requirements the AI Act sets out, and it says the "CRR/CRD requirements already provide a comprehensive and technology-neutral governance and risk management framework that can be leveraged upon when supervising the use of AI tools." The loan-origination and monitoring guidelines, model-validation rules, and internal-governance guidelines all show up in the Annex as the sectoral counterparts to specific AI Act articles.
Layering, not replacing
The practical instruction is to layer the AI Act on top of the rules you already run, not to bolt on a separate AI compliance program that duplicates them. The EBA sent a detailed Annex mapping each AI Act high-risk requirement to the specific CRR, CRD, DORA, consumer-credit, mortgage-credit, and payment-services provisions that already address it. That Annex exists to feed the Commission Guidelines that Article 96(1)(e) of the AI Act requires on the interplay between the AI Act and sectoral law.
What this means operationally: your model risk management, your loan-origination controls, your internal governance, and your DORA program are the raw material for AI Act compliance on a credit-scoring system. The work is to check each AI Act high-risk requirement, see whether a derogation or synergy applies, and where it does not, confirm your existing controls actually meet the AI Act standard rather than just something adjacent to it. Human oversight, data governance, and cybersecurity are the three the EBA flags as having no derogation, so those are where a gap between "we have a finance-law process" and "it satisfies the AI Act" is most likely to bite.
What this means for US banks and AI vendors
Two audiences in the US should care. First, if you are a US banking group with an EU subsidiary or branch that makes retail credit decisions, that entity is inside the AI Act's high-risk regime for its scoring models, and this letter is the clearest official read on how the AI Act stacks with the CRD and DORA obligations that subsidiary already carries. Map your credit models against Annex III(5)(b), then use the EBA's Annex to see which AI Act duties you can satisfy through existing controls and which, like human oversight, data governance, and cybersecurity, you have to meet head-on.
Second, if you build or sell AI credit-decision tools into the EU, your bank customers will push these requirements onto you. The AI Act splits duties between providers and deployers, and the EBA's Annex maps requirements on both sides. Expect procurement questionnaires that ask how your system supports human oversight, how you govern training and input data, and how you meet the security expectations that DORA and the AI Act both impose. Getting your documentation aligned to the AI Act's high-risk requirements before August 2, 2026 is the difference between closing EU deals and stalling in due diligence.
Questions professionals are asking
Is the EBA letter a binding rule?
No. It is a supervisory communication from the EBA to the European Commission reporting the outcome of a mapping exercise, and it feeds the Commission Guidelines required under Article 96(1)(e) of the AI Act. It does not by itself impose new obligations. The AI Act requirements it maps, however, are binding and apply to high-risk systems from August 2, 2026.
Why is credit scoring classified as high-risk?
The AI Act lists it. Annex III(5)(b) names AI systems used for creditworthiness assessment or credit scoring of natural persons as a high-risk use case, which is the basis the EBA cites. That classification pulls in the full high-risk regime, including risk management, data governance, human oversight, and record-keeping.
Which AI Act duties have no derogation for banks?
The EBA singles out human oversight, data governance, and cybersecurity. The AI Act provides targeted derogations and synergies for some high-risk requirements that overlap with finance law, but not for these. The EBA notes that EU financial services law already regulates them heavily, through DORA and the CRR and CRD governance framework, so the task is integration rather than starting from zero.
Does this reach US banks and vendors?
Yes, where there is an EU nexus. A US banking group's EU subsidiary that scores retail credit is inside the high-risk regime, and vendors selling AI credit-decision tools into the EU face these requirements through their bank customers, split between provider and deployer duties. Firms with no EU operations and no EU customers are not directly captured.
What should firms do before August 2, 2026?
Map each credit-scoring model against Annex III(5)(b), then use the EBA's Annex to see which AI Act requirements can be met through existing CRD, DORA, and loan-origination controls and which cannot. Focus remediation on human oversight, data governance, and cybersecurity, where there is no derogation, and confirm current controls actually meet the AI Act standard rather than an adjacent one.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal or compliance advice. Confirm how the AI Act, CRD, DORA, and the EBA guidelines apply to your credit models with qualified counsel and your supervisor.