As of today, August 2, 2026, AI systems used for creditworthiness assessment and credit scoring are legally classified as high-risk under Annex III of the EU AI Act. The obligations—risk management systems, conformity assessments, human oversight mechanisms, explainability for individual decisions, and registration in the EU's AI database—are no longer aspirational. They are enforceable, with fines reaching €35 million or 7% of global annual turnover for operators that cannot demonstrate compliance.
For financial institutions operating inside the EU, this is a known event that compliance teams have been preparing for since the Act's entry into force in August 2024. For institutions outside the EU, the picture is more complicated. The EU AI Act follows a market-access logic structurally identical to GDPR: if your AI system processes data about EU residents or makes decisions that affect them, you are in scope regardless of where your servers or headquarters are located. Brazilian fintechs that have expanded into Portugal, Spain, or other EU markets via AI-driven credit decisioning models woke up today facing a new compliance requirement they may not have fully mapped.
The specific obligations for high-risk AI in financial services are more demanding than many operators assumed when they were first announced. Explainability is not satisfied by showing which variables a model uses—it requires the ability to explain, to a specific individual, why a specific credit decision was made in terms that person can contest. Human oversight is not satisfied by having a human in the approval chain who rubber-stamps model outputs; the human must be capable of meaningfully overriding the model and must have access to the information needed to do so. These are implementation challenges that require re-engineering existing decisioning workflows, not adding a disclosure paragraph to terms and conditions.
The Brazilian dimension is the medium-term story. PL 2338/2023—Brazil's comprehensive AI bill—has been through committee and is headed for a full Senate vote expected in September 2026. The bill takes a similar risk-tiered approach to the EU's, with high-risk financial AI subject to transparency, human oversight, and contestability requirements. The EU AI Act's enforcement architecture—including its fine structure and the role of national supervisory authorities—is actively cited in the Brazilian Senate debate as the comparator framework. What the EU decides to prioritize in its first wave of enforcement actions will directly inform what Brazilian legislators and the Banco Central do Brasil build into implementing regulations.
The BCB has made no secret of its interest in AI-driven credit systems. Its June 2025 AI monitoring agenda flagged algorithmic credit decisioning as a priority supervision area, particularly in the context of Pix-embedded credit products where speed of decisioning creates new fairness and explainability risks. Institutions that respond to today's EU enforcement deadline by building documentation frameworks—risk assessments, model cards, human oversight logs—will be creating artifacts that map onto what the BCB will eventually require. Those that treat EU compliance as a European-only project will face a second implementation cycle when Brazilian rules arrive.
The enforceability of AI compliance obligations in financial services is no longer a theoretical future event. It happened today. The institutions that treat this as an operational shift rather than a legal checkbox will be better positioned in both the European and Brazilian markets than those still waiting for a definitive domestic rule before investing in compliance infrastructure.