Legal documents and compliance framework representing EU AI Act enforcement
Regulation

The EU Just Made AI Credit Scoring a Compliance Item. Brazil Is Watching.

· August 2, 2026 · 5 min read

As of today, August 2, 2026, AI systems used for creditworthiness assessment and credit scoring are legally classified as high-risk under Annex III of the EU AI Act. The obligations—risk management systems, conformity assessments, human oversight mechanisms, explainability for individual decisions, and registration in the EU's AI database—are no longer aspirational. They are enforceable, with fines reaching €35 million or 7% of global annual turnover for operators that cannot demonstrate compliance.

For financial institutions operating inside the EU, this is a known event that compliance teams have been preparing for since the Act's entry into force in August 2024. For institutions outside the EU, the picture is more complicated. The EU AI Act follows a market-access logic structurally identical to GDPR: if your AI system processes data about EU residents or makes decisions that affect them, you are in scope regardless of where your servers or headquarters are located. Brazilian fintechs that have expanded into Portugal, Spain, or other EU markets via AI-driven credit decisioning models woke up today facing a new compliance requirement they may not have fully mapped.

The specific obligations for high-risk AI in financial services are more demanding than many operators assumed when they were first announced. Explainability is not satisfied by showing which variables a model uses—it requires the ability to explain, to a specific individual, why a specific credit decision was made in terms that person can contest. Human oversight is not satisfied by having a human in the approval chain who rubber-stamps model outputs; the human must be capable of meaningfully overriding the model and must have access to the information needed to do so. These are implementation challenges that require re-engineering existing decisioning workflows, not adding a disclosure paragraph to terms and conditions.

The Brazilian dimension is the medium-term story. PL 2338/2023—Brazil's comprehensive AI bill—has been through committee and is headed for a full Senate vote expected in September 2026. The bill takes a similar risk-tiered approach to the EU's, with high-risk financial AI subject to transparency, human oversight, and contestability requirements. The EU AI Act's enforcement architecture—including its fine structure and the role of national supervisory authorities—is actively cited in the Brazilian Senate debate as the comparator framework. What the EU decides to prioritize in its first wave of enforcement actions will directly inform what Brazilian legislators and the Banco Central do Brasil build into implementing regulations.

The BCB has made no secret of its interest in AI-driven credit systems. Its June 2025 AI monitoring agenda flagged algorithmic credit decisioning as a priority supervision area, particularly in the context of Pix-embedded credit products where speed of decisioning creates new fairness and explainability risks. Institutions that respond to today's EU enforcement deadline by building documentation frameworks—risk assessments, model cards, human oversight logs—will be creating artifacts that map onto what the BCB will eventually require. Those that treat EU compliance as a European-only project will face a second implementation cycle when Brazilian rules arrive.

The enforceability of AI compliance obligations in financial services is no longer a theoretical future event. It happened today. The institutions that treat this as an operational shift rather than a legal checkbox will be better positioned in both the European and Brazilian markets than those still waiting for a definitive domestic rule before investing in compliance infrastructure.

EU AI Act High-Risk Financial Obligations: Key Parameters (Effective August 2, 2026)
Requirement What It Means in Practice
Risk management system Documented process for identifying, analyzing, and mitigating AI model risks throughout the lifecycle
Conformity assessment Internal or third-party audit confirming the system meets Annex III high-risk requirements
Human oversight Trained human able to meaningfully override model outputs, with access to relevant decision information
Explainability Individual-level explanation of credit decisions in terms the affected person can understand and contest
EU AI database registration System must be registered in the EU's public AI register before deployment
Maximum penalty €35 million or 7% of global annual turnover, whichever is higher

Frequently Asked Questions

What does the EU AI Act require for credit scoring AI?

As of August 2, 2026, AI systems used for creditworthiness assessment and credit scoring are classified as high-risk under Annex III of the EU AI Act. Operators must maintain a conformity assessment, implement a risk management system, ensure meaningful human oversight, provide individual-level explainability for decisions, and register the system in the EU's AI database. Non-compliance carries fines up to €35 million or 7% of global annual turnover, enforceable by national competent authorities in each of the 27 EU member states.

Does the EU AI Act apply to Brazilian fintechs?

Yes, if they process data or provide AI-driven financial services to EU residents. The EU AI Act follows a market-access logic similar to GDPR: any company offering AI-driven credit decisioning to EU users must comply, regardless of where it is headquartered. Brazilian fintechs that have expanded into Portugal, Spain, or other EU markets via AI scoring models—or that process data about EU residents—are directly in scope as of today.

How does Brazil's AI bill PL 2338/2023 compare to the EU AI Act?

PL 2338/2023 takes a similar risk-tiered approach: high-risk AI systems in financial services require transparency, human oversight, and contestability mechanisms. The Brazilian Senate vote is expected in September 2026, with implementing regulations to follow. The EU AI Act's enforcement architecture—including its fine structure and the role of supervisory authorities—is actively cited in the Brazilian legislative debate. The Banco Central do Brasil's AI monitoring agenda also flags algorithmic credit decisioning as a priority area, suggesting implementing rules will be issued relatively quickly after the bill's passage.