Credit scoring under the AI Act
Credit scoring is named as high-risk in the AI Act itself. What the law demands of a lender, and which rulebooks apply at the same time.
Credit scoring is named as high-risk in the AI Act itself. What the law demands of a lender, and which rulebooks apply at the same time.
This piece first appeared in German. The English version is a rewrite rather than a line-by-line translation, and the German original stays online in the archive: KI trifft auf Regulierung - Beispiel: Banken.
Imagine you apply for a loan. Steady income, no outstanding debt, nothing unusual in the file. The rejection arrives anyway, automatically, within seconds. No case handler, no reasons given, no one to ask. Somewhere in a data center an algorithm decided you were not a suitable borrower.
What produced that decision stays out of sight. It might have been the postcode. Or a feature in the training data that has nothing to do with creditworthiness and correlates with it statistically. BaFin, the German financial supervisor, describes exactly this risk. A training dataset can leave out particular customer groups, which makes it unrepresentative of the actual customer base, and the algorithm then assesses those people without an empirical basis. Such a model discriminates because the data reflects reality unevenly, and not because anyone programmed it to.
That is the regulatory problem in one line. Highly automated decision processes with little human supervision can amplify discrimination risks that already exist, as BaFin puts it. It is why the European legislator wrote the AI Act. Banks using AI in lending or risk management now carry concrete duties, and the European legislator has already moved the date on which they apply once.
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and takes effect in stages. One date matters most for banks, and it has moved. The full obligations for high-risk AI systems were due on 2 August 2026, and the Digital Omnibus on AI, Regulation (EU) 2026/1744, postponed them for systems like credit scoring to 2 December 2027.
The law works from a risk-based approach, so the more deeply a system can reach into fundamental rights, the stricter the requirements on it. For banks the high-risk class is the one that counts, because a core part of the business sits inside it.
Annex III lists the applications that carry the classification. The entry for the financial sector is point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score. Systems used to detect financial fraud are excluded. The Bankenverband, the association of German banks, welcomes that distinction and asks the Commission for further clarification on anti-money-laundering and sanctions screening.
High-risk does not mean dangerous. In the language of the AI Act it means a system that shapes decisions with a serious effect on individuals. Credit scoring fits the definition because it governs access to financial services.
Anyone providing or operating a high-risk AI system has to meet several requirements. A continuous risk management system, under Article 9. Demonstrated data quality, including bias testing of the training data, under Article 10. Complete technical documentation, under Article 11, and mechanisms for human oversight.
Article 6(3) does allow an exemption from the classification where a system has no material influence on the outcome of a decision. The idea that an AI pre-check in lending escapes the classification because a person signs off is not supported by the regulation, as TÜV Consulting reads it. An upstream scoring model that hands a case handler a recommended value can fall under the high-risk requirements too.
In its position paper of July 2025 the Bankenverband asks for a clearer separation of roles between providers and deployers. That matters most where banks share AI inside a group structure or work with external service providers. Uncertainty about who holds which role, the association argues, damages legal certainty and can slow progress down.
A second strand of regulation deals with discrimination, and it sits in existing law independently of the AI Act. BaFin separates two forms. Direct discrimination puts a person at a disadvantage explicitly because of a protected characteristic such as age or gender. Indirect discrimination happens when apparently neutral criteria, income level for instance, systematically disadvantage particular groups.
Both forms are legally problematic without being absolutely prohibited. Unequal treatment that can be justified on the facts, because the criterion demonstrably correlates with actual default risk, counts as permissible. Where legitimate risk differentiation ends and unlawful discrimination begins is one of the central questions in any AI system that touches lending.
The risk usually sits in the data. In a machine learning context BaFin defines bias as a systematic distortion of results, arising for example when training data does not represent particular groups adequately. Feed a model historical lending decisions and past structural disadvantage travels into it, where it can take on a life of its own.
Article 10 of the AI Act sharpens that expectation into a condition: a high-risk system has to be trained on demonstrably representative data and tested for bias before it goes into operation.
The regulatory picture for AI in banking is complicated because more than one framework is live. In Germany for examlple, there are four of them: the AI Act, the GDPR, the MiFID II regime, and MaRisk, the German supervisory rules on risk management in banks. Germany has since added KI-MIG, the national act implementing the AI Act, which the federal cabinet adopted in February 2026.
The Bankenverband argues for consistent application of the AI Act across the Union, so that supervisory practice is harmonized and every market participant works under the same conditions. Fragmented national implementation would produce the opposite: different compliance requirements depending on location, and a disadvantage against competitors from outside the EU.
A risk-based framework makes sense for a sector with this much effect on people's lives, and what is hard about it is the speed of implementation. The postponement gives the many institutions that have tested AI mainly in pilot projects sixteen more months, and it does not change what they have to build.
Regulation and innovation do not exclude each other in finance, but they do require lead time. Banks treating AI governance as a strategic task can turn the requirements of the AI Act into an advantage. Those still waiting have until 2 December 2027, which is shorter than it sounds for a model that has to be documented, tested for bias and placed under human oversight.
Grouped by the section they support.
Opening
Credit scoring is named as high-risk in the law itself
The duties are specific, and none of them is a formality
Fairness was already law before the AI Act arrived
Several rulebooks apply to the same system at once
The problem was never the law, it was the lead time
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.