The EU AI Act (Regulation (EU) 2024/1689) applies in phases, not all at once. Its prohibited practices have been in force since 2 February 2025. Its rules for general-purpose AI, governance and penalties followed on 2 August 2025. The heavy tier, the obligations for high-risk systems, was due on 2 August 2026, until the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) pushed the stand-alone high-risk deadline (Annex III) to 2 December 2027 at the latest, and the deadline for high-risk AI embedded in regulated products (Annex I) to 2 August 2028.
So the high-risk duties around, say, a credit-scoring model land in December 2027, not this year. That is real relief, but it is not a pause. Banned uses are banned today. And the evidence a high-risk system needs, the documentation, the logging, the oversight designed into the workflow, takes many months to stand up honestly, not a weekend before an audit. For scale, the penalties are not symbolic: up to 35 million euro or 7% of global turnover for a prohibited use, up to 15 million euro or 3% for a high-risk breach.
The Act is risk-based: a small set of unacceptable uses is banned, a defined list of high-risk uses carries the heavy obligations, limited-risk uses owe transparency, and everything else is largely free. For a bank, the line that matters is in Annex III, point 5(b): AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are high-risk, with one carve-out, AI used to detect financial fraud is not.
A practical test cuts through the classification faster than the legal text: does the system inform, recommend, or decide? The closer it sits to a decision about a person's access to credit or a service, the higher the risk. Credit scoring, loan-approval decision support and automated creditworthiness assessment fall squarely in scope. Fraud detection, back-office optimisation and a support chatbot do not carry the high-risk load, though the chatbot still owes transparency and, as we will see, all of them remain ICT you have to govern.
Here is what the December 2027 date hides. An AI model, its data pipeline and its inference API are ICT systems, and very often ICT services bought from a third party. That means DORA (Regulation (EU) 2022/2554), which has applied to financial entities since 17 January 2025, already governs them:
So the comfortable idea that AI governance can wait for 2027 has a hole in it: DORA is governing your AI now, and its supervisors are not waiting.
The most useful point in the current debate is also the simplest: do not run AI governance as a programme parallel to your resilience programme. The AI Act's high-risk duties, risk management, data governance, technical documentation, logging and traceability, human oversight, accuracy and robustness, post-market monitoring, map almost one-to-one onto controls DORA already asks you to operate. Build the machinery once, then tag each control for both regimes. One inventory, one risk classification, one evidence trail, two rulebooks satisfied.
Both texts judge you on what you can show, not on what you wrote. Put the obligations side by side and the AI programme has to be able to produce:
None of that is a document you write once. It is a set of records you keep, which is why the December 2027 date is misleading: the deadline is the exam, the evidence is the coursework, and the coursework starts long before.
That is the logic SynapseRM is built on. The trap in all of this, running AI governance as a programme parallel to the resilience one you already operate, is exactly what a single data model avoids: you do not stand up an AI silo next to the risk and third-party registers, you treat each AI system and each model provider as a first-class object in the registers you already run.
The high-risk date is 2027. The inventory that everything else hangs from is a job for today. Start there, and the deadline becomes a formality instead of a scramble.
In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.