ISHIGHRISK AI
Sector guide

Credit scoring and insurance AI under the AI Act

Annex III point 5(b) makes credit-scoring AI high-risk, but the fraud-detection carve-out is widely misread. Insurance pricing under 5(c) is caught too.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Annex III point 5(b) makes AI that evaluates the creditworthiness of natural persons or establishes their credit score high-risk, with one express carve-out: systems used for the purpose of detecting financial fraud. That carve-out is read far too widely, and it does not lift a lending decision out of the regime. Point 5(c) separately catches risk assessment and pricing for life and health insurance in relation to natural persons. Because scoring a person is profiling, the Article 6(3) derogation is foreclosed here just as it is in hiring. High-risk obligations apply from 2 December 2027, and for regulated firms supervision runs through the existing financial authority under Article 74.

Annex III point 5(b): creditworthiness and credit scoring

Annex III point 5(b) makes high-risk any AI system intended to evaluate the creditworthiness of natural persons or to establish their credit score. It is one of the shortest entries on the high-risk list and one of the widest in effect, because it does not describe a niche technology. It describes what a consumer lending stack already does: score an applicant, estimate a probability of default, rate affordability, and return an accept, decline or refer. From 2 December 2027 the full Chapter III obligation stack attaches to those systems.

The classification follows the function, not the product name or the model architecture. A bespoke scorecard, a gradient-boosted default model and a general-purpose model prompted to assess an application are the same thing for this purpose: each evaluates the creditworthiness of a natural person. That is why buying rather than building changes nothing, and why a system marketed as decision support rather than decision making is still caught if the score is what the lender acts on. The only words in 5(b) that carve anything out are the fraud-detection exception, and they carve out much less than firms assume.

The fraud-detection carve-out, and why it is misread

Point 5(b) high-risks creditworthiness AI with the exception of AI systems used for the purpose of detecting financial fraud. That clause is the single most over-claimed line in the whole of Annex III point 5. The argument runs: our model looks at risk, fraud is a kind of risk, therefore the exception applies. It does not. The exception turns on purpose. It removes systems whose job is to detect fraudulent applications or transactions, not systems that decide whether a genuine applicant is creditworthy.

The distinction is not academic, because the two functions answer different questions. A fraud-detection system asks whether this application is what it claims to be. A creditworthiness system asks whether this real person can afford and is likely to repay the credit. The first can be excluded; the second cannot. Bundling them in one model does not launder the lending decision through the fraud carve-out, and running a genuine fraud engine alongside a scorecard does not pull the scorecard out with it.

SystemAnnex III pointHigh-risk?Why
Consumer credit score or probability-of-default model5(b)YesIt evaluates the creditworthiness of a natural person. The named use, with no exception available to it.
Affordability or income-verification model feeding a lending decision5(b)YesIt assesses whether a real applicant can repay. That is creditworthiness, not fraud, whatever the internal team calls it.
Transaction-fraud or application-fraud detection engine5(b) exceptionNoIts purpose is detecting fraud, so the express carve-out reaches it, provided that is genuinely all it does.
One model that both scores creditworthiness and flags fraud5(b)Yes, for the scoring functionThe carve-out is read by purpose, function by function. The creditworthiness function stays high-risk; the fraud function does not rescue it.
Life or health insurance underwriting and pricing model5(c)YesRisk assessment and pricing for life and health insurance in relation to natural persons is separately named.
Commercial lending decision about an incorporated companynoneNo5(b) is limited to natural persons. A decision about a legal person is outside it, unless it scores an individual guarantor.

Read the carve-out by purpose, one function at a time.The exception in 5(b) is for systems used for the purpose of detecting financial fraud. It is not a general risk exemption, and it does not travel from a fraud module to a scoring module just because they share a codebase. Write down which model does which job, and treat any function that answers “should we lend to this real person” as high-risk.

Point 5(c): risk assessment and pricing for life and health insurance

Sitting next to credit in the same Annex III entry is point 5(c): AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Underwriting models, risk-rating engines and premium-setting tools for those two lines are high-risk on the same 2 December 2027 timeline. The reasoning is the same as for credit: these systems decide an individual's access to, and the cost of, a service that materially affects their life.

Two limits are written into the point and worth holding onto. It reaches life and health insurance only, so motor, home, travel and commercial lines are not caught by 5(c). And it reaches risk assessment and pricing in relation to natural persons, so a model pricing a group scheme at the level of an employer, rather than rating the individuals within it, is a different analysis. Do not stretch 5(c) to every insurance model, and do not assume a health or life product escapes it because the pricing is dressed up as portfolio analytics.

Natural persons, not companies, and where SME lending sits

Both 5(b) and 5(c) are tied to natural persons, and that word does real work. A lending or insurance decision about a company as a legal person is outside these points. The place it bites is small-business and sole-trader credit, where the borrower often is an individual. A facility to an incorporated company is generally outside 5(b); credit assessed against a sole trader, a partner, or a named personal guarantor is inside it, because the model is evaluating the creditworthiness of a natural person.

The practical error is to wave SME lending through as commercial and therefore exempt. It is not categorical. Where the decision blends a company and an individual, the function that scores the natural person is the high-risk one, and it has to be documented and classified as such even if the headline product is business lending.

Where the Article 6(3) derogation gets over-claimed

Credit and insurance are, after hiring, the second place the Article 6(3) derogation is most often stretched past what it can bear. The pitch is familiar: the model only produces a score, a human makes the decision, so it merely performs a preparatory task or improves a human activity and lifts out of the high-risk regime. The text does not support it, for two independent reasons.

First, Article 6(3) ends with an override: a system that performs profiling of natural persons is alwayshigh-risk, with no balancing and no human-in-the-loop cure. A credit score evaluates a person's economic situation and behaviour to predict their likelihood of repayment. That is profiling, and it forecloses the derogation before the four conditions are reached. Second, even without the profiling override, the derogation's first limb asks whether the system poses a significant risk by materially influencing the outcome. A score a lender acts on materially influences whether a person gets credit, so the significant-risk gate closes. Art 6(3)

A human signature at the end does not rescue it. Human review of a ranked or scored list does not undo profiling, and a reviewer who sees the score but not the applicants the model already filtered out is not exercising the oversight the derogation imagines. Claiming 6(3) also does not make paperwork disappear: under Article 6(4) the provider must document the assessment before placing the system on the market, and a system self-assessed as non-high-risk must still be registered in the EU database. The realistic comparison is the full Chapter III high-risk stack against a documented, registered, defensible assessment you have to stand behind.

The overlap with existing financial services supervision

Lenders and insurers do not meet the AI Act on a blank sheet. They are already supervised, already run risk-management and governance frameworks, and already document models. The Act is built to coordinate with that rather than duplicate it, and getting the interaction right saves genuine work.

  • Supervision runs through the financial authority. For high-risk AI systems placed on the market or used by regulated financial institutions, the market surveillance authority is the body already responsible for supervising that institution under Union financial services law, not a separate AI regulator. Art 74
  • Existing governance can carry the equivalent duties. The Act is designed so that internal governance you already run under prudential rules can be used to meet the corresponding Article 9 risk-management and Article 17 quality-management obligations, rather than building a parallel system that says the same thing twice. Art 9, Art 17
  • The AI-specific duties still stand. Coordination is not exemption. Data governance, logging, transparency to deployers, human oversight, accuracy and robustness and the conformity and registration steps apply on top of your prudential obligations.

One boundary is worth stating plainly, because clients ask: a lawful credit score is not the prohibited practice of social scoring. Article 5(1)(c) bans social scoring that leads to disproportionate or detrimental treatment across unrelated contexts, which is a different thing from assessing creditworthiness for a credit decision. A creditworthiness model is high-risk and permitted with obligations; it only strays toward the prohibition if it is turned into a general-purpose reputation score used to disadvantage people in contexts unrelated to the data. Keep the two apart in your documentation.

What to fix before 2 December 2027

Standalone Annex III obligations apply from 2 December 2027, a seventeen-month extension from the original 2 August 2026 date. For a lending or underwriting book that is not comfortable headroom: models live in production for years, and conformity assessment is not a sprint.

2 Feb 2025Article 5 prohibitions and the Article 4 AI-literacy duty apply. Social scoring is already banned, and the literacy duty already binds the teams running credit and pricing models. Already in force.
2 Aug 2025Penalties enforceable. The Article 99 tiers are live against the duties already in force.
2 Dec 2027High-risk obligations apply to standalone Annex III systems, which is where creditworthiness scoring and life and health insurance pricing sit.

Five things that belong in the model inventory and the vendor questionnaire now:

  1. A function-level map of every model. For each model, record whether it evaluates creditworthiness (5(b)), prices life or health insurance (5(c)), detects fraud (the carve-out), or does something outside Annex III, and treat any system that mixes these as several functions rather than one.
  2. A written purpose for every fraud claim. If you rely on the 5(b) exception, the documented purpose has to be fraud detection, and the model must not be the one deciding creditworthiness. A claim that cannot survive that reading is not a claim.
  3. A natural-person test on the lending book. Flag where SME and sole-trader decisions score an individual or a guarantor, and classify those functions as high-risk rather than assuming commercial lending is exempt.
  4. A conformity and registration commitment. A dated plan to complete the assessment, issue the EU declaration of conformity and register ahead of 2 December 2027, with the Annex IV technical documentation maintained and available.
  5. Clarity on who is the provider. A bought scorecard used as supplied puts the vendor in the provider seat and you in the deployer seat, but retraining it on your own book or repurposing a general model to score applicants can flip you into the provider role. Settle that before it is settled for you in an inspection. Provider and deployer roles sets out the flip.

If you want the per-system answer rather than a general one, run each model through the free seven-stage triage classifier, which walks scope, prohibitions, Annex III, the derogation and your role in order and keeps the dated output as the start of your record. Getting the classification wrong is expensive, with the detail on the penalties and enforcement page. The primary text is on EUR-Lex.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Is credit-scoring AI high-risk under the EU AI Act?

Yes. Annex III point 5(b) names AI systems intended to evaluate the creditworthiness of natural persons or to establish their credit score as high-risk, so a model that produces a score, a probability of default, an affordability rating or an accept/decline recommendation for a consumer is inside the regime. The classification attaches to the function, not the label: a general analytics model pointed at a lending decision is caught the same way a purpose-built scorecard is. The one express exclusion in the text is for AI systems used for the purpose of detecting financial fraud, and it is far narrower than it is usually read.

Does the financial-fraud exception cover our credit model?

Almost never. The exception in Annex III point 5(b) is for AI systems used for the purpose of detecting financial fraud, meaning a system whose job is to spot fraudulent applications or transactions, not one that decides whether to lend. A creditworthiness model does not leave the high-risk regime because it also carries some fraud signals, and a fraud-detection system does not pull the lending decision out with it. If the same model both scores creditworthiness and screens for fraud, the creditworthiness function is high-risk and has to be treated as such. Read the carve-out by purpose, one function at a time, and document which is which.

Is insurance pricing AI high-risk under the AI Act?

For life and health insurance, yes. Annex III point 5(c) names AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Underwriting, risk rating and premium-setting models for those two lines are high-risk. The point is limited to life and health insurance and to natural persons, so motor, property or commercial lines are not caught by 5(c), and a model that prices a policy for a company rather than an individual is outside it. Confirm the line of business and whose risk is being assessed before you conclude either way.

Can a credit-scoring model use the Article 6(3) derogation?

Realistically no. Article 6(3) ends with an absolute bar: a system that performs profiling of natural persons is always high-risk, whatever else is true. Credit scoring evaluates the economic situation and behaviour of a natural person to predict something about them, which is profiling in ordinary usage, so the four derogation conditions never come into play. Even setting profiling aside, a score that materially influences a lending decision fails the first limb of the test, which asks whether the system poses a significant risk by materially influencing the outcome. The honest posture is that creditworthiness scoring stays high-risk and the derogation is not the off-ramp vendors present it as.

Does the AI Act duplicate our existing financial services compliance?

It coordinates with it rather than duplicating it. For high-risk AI systems placed on the market or used by regulated financial institutions, the market surveillance authority under Article 74 is the authority already responsible for supervising that institution under Union financial services law, not a separate AI regulator. The Act is also designed so that governance you already run under prudential rules can be used to meet the equivalent Article 9 risk-management and Article 17 quality-management duties, instead of standing up a parallel system. What it does not do is switch those duties off: the AI-specific requirements on data governance, logging, transparency and human oversight still apply on top.

Is business lending to companies caught by Annex III point 5(b)?

Point 5(b) is limited to the creditworthiness of natural persons, so lending decisions about a company as a legal person sit outside it. The line matters most for small-business and sole-trader lending: a facility extended to an incorporated company is generally outside 5(b), while credit assessed against an individual, including a sole trader or a personal guarantor, is inside it. Where a single decision blends both, the part that scores a natural person is the high-risk function. Do not treat SME lending as categorically exempt; look at whose creditworthiness the model actually evaluates.

When do the credit and insurance AI rules apply?

The high-risk obligations for standalone Annex III systems apply from 2 December 2027, after the Digital Omnibus moved them from the original 2 August 2026 date. Credit scoring and life and health insurance pricing are standalone Annex III uses, so that is the date they are measured against. Two things already bind you: the Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025, and penalties have been enforceable since 2 August 2025. The 2027 date is not slack. Conformity assessment, Annex IV documentation and registration take a full cycle, and models underwritten today will still be scoring applicants then.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.