Skip to content
New: ask the Rexfin Analyst Agent about your model. Every figure comes back cited.
· 8 min read

EU AI Act 2026: What Finance Teams Must Do Now

AI-driven credit scoring counts as high-risk under the EU AI Act. Here is what that means for your controlling function and how a traceable model layer protects you.

AI-driven credit scoring counts as high-risk under the EU AI Act. Here is what that means for your controlling function and how a traceable model layer protects you.

By The Rexfin team

A tool you use for a credit check today can be classified as a high-risk system tomorrow. Not because the AI changed. Because the law did.

That is exactly what many finance teams underestimate about the EU AI Act. This is not about futuristic robots in accounting. It is about the very concrete software running today that calculates scores, sets limits, and classifies receivables. The moment that software evaluates a person’s behavior, it falls into the strictest category the regulation defines.

Why credit scoring counts as high-risk

Annex III of the regulation lists the use cases that automatically qualify as high-risk. Point 5 covers access to essential services. It explicitly includes AI used to evaluate the creditworthiness of natural persons or to establish a credit score.

The reasoning is easy to follow. A wrong score can cost a person a loan, an apartment, or a business deal. Lawmakers want decisions like these to be explainable, documented, and verifiable. There is one carve-out: AI used solely to detect financial fraud does not fall under the rule.

For mid-market finance teams, the practical takeaway is simple. The moment you use AI to sort customers, suppliers, or applicants into credit classes, you are potentially in scope. That holds even when the model is only one building block inside a larger process.

What high-risk demands in practice

These obligations are not an abstract wish list. They are operational and auditable. The most important ones:

  • Risk management. A documented, continuous process that identifies and mitigates the system’s risks. Not a one-off, but across the entire lifecycle.
  • Data quality and data governance. Training and input data must be relevant, representative, and as error-free as possible. This is precisely where most projects fail, and there is more on that below.
  • Technical documentation. You have to be able to show how the system is built and how it arrives at its results.
  • Logging. The system must record events automatically so decisions can be reconstructed after the fact.
  • Transparency. Users need to understand what the system does and with what level of confidence.
  • Human oversight. A real person must be able to intervene, override, and stop it. No rubber-stamping on autopilot.

Read that list with a standard large language model in mind and the problem is obvious. A model that predicts numbers as text and produces no traceable chain of calculation satisfies almost none of these points on its own. For why LLMs structurally fail at exactly this kind of task, see our pillar on AI in finance.

The deadline nobody talks about plainly

This is where it gets uncomfortably honest. The high-risk obligations for Annex III systems were originally meant to apply from 2 August 2026. As part of the so-called Digital Omnibus, there has been discussion of pushing that deadline back significantly, toward the end of 2027. The exact status depends on the final legislative process.

What does that mean for you? Do not count on a grace period. First, the formal decision is not final as of this writing. Second, and this is the real point, a later deadline changes nothing about the substantive requirements. Data quality, traceability, and human oversight are not compliance hassle. They are the things that stop your AI from inventing a number you will personally have to stand behind.

A CFO who only cleans up the architecture in 2027 has not removed the risk. They have just dated it.

The real trap: data quality, not the model

Most debates about the AI Act revolve around the model. Which LLM, which vendor, which country. That is the wrong layer.

The regulation requires data quality, and that is exactly where finance teams stumble, long before the model enters the picture. If your numbers come from three systems, contradict each other, and nobody can say which version is correct, then every AI output is a documented risk. You can run a first-rate model on a messy foundation and still end up with a non-compliant system.

We wrote a separate piece on this because it matters so much: data quality beats the model. The core idea in one sentence. Before AI touches your numbers, a reconciled data base that ties out to the general ledger has to exist.

How a model layer meets the obligations, point by point

This is where Rexfin’s approach comes in, and not as a marketing line but obligation by obligation.

Rexfin connects your accounting and finance data sources, such as DATEV, QuickBooks, Xero, or NetSuite, or uploaded statements, and builds them into a single reconciled financial model. One source of truth that ties out to the ledger. That addresses the required data quality at the root.

The actual calculation is not handled by the LLM but by a deterministic engine. The AI retrieves values and frames the question, but the math runs through an auditable mechanism. The same model returns the same result for the same question. That is the basis for transparency and reproducible documentation.

Every number carries its origin with it. Click a value and you see the source document and the calculation path. That is precisely the logging and traceability the AI Act, and the GoBD in parallel, demand. For how this works technically, see how it works.

And because every output is bound to its source, a person can review it instead of trusting it blindly. That is human oversight worthy of the name. No black box you can only nod through.

What you can do this week

You do not have to wait for the final legal text to start. Three steps that make sense regardless of the deadline:

  1. Inventory. List every tool in your finance function that scores or classifies people or business partners. Include the unofficial shadow AI in an employee’s browser.
  2. Provenance test. Take any AI-generated number from your last reporting cycle and try to trace it back to the source document. Can you do it in under a minute? If not, you have found your gap.
  3. Foundation before automation. Settle the reconciled data base before you switch on more AI features. The order determines whether you stay compliant.

The AI Act does not punish the use of AI. It punishes the use of AI that nobody can explain. The difference is not in the model. It is in the layer underneath.

If you want to see how every number traces back to its source, book a demo. We will walk through your own data and show you what auditable actually means.

Part of AI in Finance, Audit-Proof: GoBD- and AI-Act-Defensible Models With Traceable Numbers

Keep reading

Book a demo

See your numbers tie out.

Book a 30-minute demo. Bring a question you can never answer fast enough, and we will model it live against real financial data.