Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogCareersLabsContact
EN · FR
Test access Book a demo
AI ACT & DORA

The EU AI Act, DORA and your AI: what a bank actually has to prove

In July 2026 the EU quietly moved one of the AI Act's biggest deadlines: the high-risk obligations for stand-alone systems, credit scoring among them, now apply from 2 December 2027 instead of August 2026. It is tempting to read that as a year of breathing room. It is not. Some AI uses are already prohibited, DORA has applied to your ICT since January 2025, and the one thing both rulebooks demand, evidence, is the slowest thing to build.

SYNAPSE CONSULTING  ·  6 MIN READ

The deadline moved. The obligations underneath it did not.

The EU AI Act (Regulation (EU) 2024/1689) applies in phases, not all at once. Its prohibited practices have been in force since 2 February 2025. Its rules for general-purpose AI, governance and penalties followed on 2 August 2025. The heavy tier, the obligations for high-risk systems, was due on 2 August 2026, until the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) pushed the stand-alone high-risk deadline (Annex III) to 2 December 2027 at the latest, and the deadline for high-risk AI embedded in regulated products (Annex I) to 2 August 2028.

So the high-risk duties around, say, a credit-scoring model land in December 2027, not this year. That is real relief, but it is not a pause. Banned uses are banned today. And the evidence a high-risk system needs, the documentation, the logging, the oversight designed into the workflow, takes many months to stand up honestly, not a weekend before an audit. For scale, the penalties are not symbolic: up to 35 million euro or 7% of global turnover for a prohibited use, up to 15 million euro or 3% for a high-risk breach.

Which of a bank's AI is “high-risk”

The Act is risk-based: a small set of unacceptable uses is banned, a defined list of high-risk uses carries the heavy obligations, limited-risk uses owe transparency, and everything else is largely free. For a bank, the line that matters is in Annex III, point 5(b): AI systems used to evaluate the creditworthiness of natural persons or establish their credit score are high-risk, with one carve-out, AI used to detect financial fraud is not.

A practical test cuts through the classification faster than the legal text: does the system inform, recommend, or decide? The closer it sits to a decision about a person's access to credit or a service, the higher the risk. Credit scoring, loan-approval decision support and automated creditworthiness assessment fall squarely in scope. Fraud detection, back-office optimisation and a support chatbot do not carry the high-risk load, though the chatbot still owes transparency and, as we will see, all of them remain ICT you have to govern.

Your AI is ICT. DORA already covers it.

Here is what the December 2027 date hides. An AI model, its data pipeline and its inference API are ICT systems, and very often ICT services bought from a third party. That means DORA (Regulation (EU) 2022/2554), which has applied to financial entities since 17 January 2025, already governs them:

So the comfortable idea that AI governance can wait for 2027 has a hole in it: DORA is governing your AI now, and its supervisors are not waiting.

Two rulebooks, one control set

The most useful point in the current debate is also the simplest: do not run AI governance as a programme parallel to your resilience programme. The AI Act's high-risk duties, risk management, data governance, technical documentation, logging and traceability, human oversight, accuracy and robustness, post-market monitoring, map almost one-to-one onto controls DORA already asks you to operate. Build the machinery once, then tag each control for both regimes. One inventory, one risk classification, one evidence trail, two rulebooks satisfied.

From policy to evidence

Both texts judge you on what you can show, not on what you wrote. Put the obligations side by side and the AI programme has to be able to produce:

None of that is a document you write once. It is a set of records you keep, which is why the December 2027 date is misleading: the deadline is the exam, the evidence is the coursework, and the coursework starts long before.

How SynapseRM answers it

That is the logic SynapseRM is built on. The trap in all of this, running AI governance as a programme parallel to the resilience one you already operate, is exactly what a single data model avoids: you do not stand up an AI silo next to the risk and third-party registers, you treat each AI system and each model provider as a first-class object in the registers you already run.

The asset referential in SynapseRM: AI systems and their providers tracked with owners, criticality and risk
Treat each AI system and each model provider as a tracked object, with an owner, a criticality and a residual risk, in the same register that already answers DORA.

The high-risk date is 2027. The inventory that everything else hangs from is a job for today. Start there, and the deadline becomes a formality instead of a scramble.

NEXT STEP
Bring us one real project

In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.

Book a demo Request test access
Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog Careers Labs Privacy & cookies
Brussels, Belgium