AI in Finance

EU AI Act Annex III: what August 2026 actually means for finance teams

Published 16 May 2026 · Updated 14 August 2026

The headline most finance leaders have heard is that the EU AI Act’s high-risk obligations land on 2 August 2026, and that compliance preparation should already be underway. That headline is mostly out of date.

On 27 July 2026, the AI Omnibus entered into force. The standalone Annex III high-risk obligations now apply from 2 December 2027, while high-risk systems embedded in regulated products move to 2 August 2028. This is no longer a provisional political agreement. It is the confirmed timetable. (Source: European Commission, AI Omnibus enters into force.)

The deadline moved. The control work did not disappear. This is the current August 2026 position for Irish and UK finance leaders, including what is already in force and which typical finance use cases fall outside Annex III.


What is in force right now

Three things, regardless of whether the Omnibus is adopted.

Article 5 prohibitions, in force since 2 February 2025. Social scoring, untargeted facial-recognition database scraping, certain workplace emotion inference, and manipulative AI that exploits vulnerabilities. Penalties up to €35m or 7% of worldwide annual turnover. (Source: Article 99, Regulation (EU) 2024/1689.) These are unlikely to be triggered by a finance function using AI for variance commentary or KYC drafting, but the regulator’s biggest stick is already deployed.

Article 4 AI literacy, in force since 2 February 2025. Any operator deploying AI systems must ensure staff using them have sufficient AI literacy. This is a low-floor requirement but it is now binding. The CFO whose team uses Claude in Excel without any structured training on the tool’s limitations is already non-compliant with Article 4.

General-purpose AI provider obligations under Articles 53 to 55, in force since 2 August 2025. This is the one that matters most for most finance functions. If your team is using Claude, GPT-5, Gemini, or Llama, you are a deployer of a GPAI system. The model provider’s obligations under Articles 53 to 55 include technical documentation, training-data summaries, and downstream-deployer instructions. (Source: European Commission FAQ on GPAI.) The practical implication for the finance function: ask your AI vendor for their Article 53 documentation. If they cannot produce it, you have a procurement problem.


What Annex III §5 actually covers

The two categories of high-risk AI that affect finance, in the exact wording of the Act:

§5(b): “AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.”

§5(c): “AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance.”

(Source: Annex III, Regulation (EU) 2024/1689.)

Read carefully. The carve-outs matter.

Fraud detection AI is expressly outside §5(b). AML, KYC, and transaction-monitoring systems are not in Annex III at all. They are governed by AMLD, DORA, and the existing Central Bank of Ireland sectoral framework. The KYC screening post covered the operational version of this.

Credit scoring for legal persons is technically outside the literal wording, which refers to “natural persons.” In practice, sole traders and partnerships will usually fall in scope. Pure B2B credit risk on corporates does not.

Non-life insurance is not in §5(c). Only life and health. Motor, property, commercial, and reinsurance are outside Annex III on this category.

General-purpose financial AI deployment is not in Annex III at all. A finance function using AI for close production, variance commentary, board pack drafting, FP&A scenario modelling, or KYC drafting is a deployer of GPAI, not a deployer of high-risk AI. The obligations that apply are Article 4 literacy and the GPAI provider’s published documentation. Article 26 deployer obligations and Article 27 fundamental rights impact assessments do not apply.

That is the single most important point in this post. Most CFOs are not racing an August 2026 deadline. The deadline does not apply to the typical mid-market finance use case.


What the deferral does and does not do

The confirmed timeline is now as follows. (Source: European Commission implementation timeline.)

ProvisionOriginal dateUnder Omnibus
Article 5 prohibitions2 Feb 2025unchanged (in force)
Article 4 AI literacy2 Feb 2025unchanged (in force)
GPAI Articles 53-552 Aug 2025unchanged (in force)
Annex III standalone high-risk (incl. §5(b), §5(c))2 Aug 20262 Dec 2027
Article 50 transparency / synthetic content2 Aug 20262 Dec 2026
National regulatory sandboxes operational2 Aug 20262 Aug 2027
Annex I product-embedded high-risk2 Aug 20272 Aug 2028
New Article 5 NCII / CSAM prohibition (added)n/a2 Dec 2026

The deferral is conditional. It is also being driven by missed harmonised standards. CEN-CENELEC’s JTC 21 confirmed in October 2025 that the harmonised standards underpinning Annex III compliance would not be ready by Q4 2026. (Source: CEN-CENELEC, 23 Oct 2025.) That is the substantive reason the political deal exists. The standards have to catch up before conformity assessment is meaningful.

The position for a finance leader is now clear: use 2 December 2027 as the Annex III deadline. The additional time should be used to map affected systems, assign accountability and build evidence. It should not be treated as permission to leave the work until 2027.


What §5(b) and §5(c) deployers actually have to do

When Annex III obligations do bite, the operational requirements for a deployer of a high-risk system are in Articles 8 to 15 (for providers) and Articles 26 to 27 (for deployers). The deployer obligations are the ones most finance leaders need to know.

Article 26 requires the deployer to use the system in accordance with the provider’s instructions, assign human oversight to natural persons with appropriate competence and authority, ensure input data is relevant and sufficiently representative, monitor operation, retain logs for at least six months, inform affected natural persons that they are subject to high-risk AI use, and cooperate with competent authorities. (Source: Article 26.)

Article 27 requires deployers that are credit institutions, insurance undertakings, or reinsurance undertakings to conduct a Fundamental Rights Impact Assessment before the first use of an Annex III §5(b) or §5(c) system, notify the market surveillance authority, and provide the results. (Source: Article 27.) The FRIA is separate from a GDPR Data Protection Impact Assessment. Both apply where personal data is processed.

Penalties for deployer non-compliance: up to €15m or 3% of worldwide turnover. For incorrect information supplied to authorities: up to €7.5m or 1%. For SMEs, the lower of the percentage or the fixed figure applies. (Source: Article 99.)


Ireland-specific layers

S.I. No. 366 of 2025 (European Union (Artificial Intelligence) (Designation) Regulations 2025) was signed by Minister Peter Burke on 25 July 2025 and designates the Central Bank of Ireland as market surveillance authority for the financial sector under Article 74(6) of the AI Act. (Source: Irish Statute Book.) Ireland operates a distributed enforcement model with eight market surveillance authorities and a central AI Office to be established under the Regulation of Artificial Intelligence Bill 2026.

The General Scheme of the Regulation of Artificial Intelligence Bill 2026 was published by the Department of Enterprise on 4 February 2026. Pre-legislative scrutiny began at the Oireachtas Enterprise Committee on 6 May 2026. The AI Office of Ireland is targeted for establishment by 1 August 2026. (Source: DETE General Scheme; William Fry analysis.)

The Central Bank of Ireland’s Regulatory and Supervisory Outlook 2026, published 26 February 2026, names AI as a risk-amplifier and reaffirms that firms “remain fully accountable for outcomes generated by AI systems, including where solutions are developed, procured or operated by third party providers.” (Source: CBI Outlook 2026 PDF.)

The honest read of the Irish stack: SEAR, the revised Consumer Protection Code commencing March 2026, the Operational Resilience Cross-Industry Guidance, the Outsourcing Cross-Industry Guidance, and DORA already cover most of what a finance function deploying AI needs to think about, regardless of the AI Act timeline. The AI Act adds a specific layer for credit scoring and life-and-health insurance. It does not replace the existing supervisory framework.


What I would do if I were running a finance function in Ireland or the UK right now

For UK firms, the AI Act does not apply directly. The FCA’s principles-based approach via its 2024 AI Update and December 2025 reaffirmation governs. (Source: FCA AI Update.) The relevance of the EU AI Act to UK firms is via EU-exposed clients, vendors, or subsidiaries.

For Irish or EU-exposed firms, the practical compliance posture today:

If your function does not do credit scoring of natural persons or life/health insurance pricing, you are not an Annex III deployer. Your AI Act obligations are Article 4 literacy plus your GPAI vendor’s published documentation. The existing CBI, FCA, GDPR, and DORA frameworks govern your AI deployment more than the AI Act does.

If your function does do credit scoring of natural persons or life/health insurance pricing, 2 December 2027 is the confirmed deadline. Start the FRIA work now. The audit trail and human-oversight requirements in Articles 26 and 27 are not trivial to build under time pressure.

Regardless of category, ask your AI vendors for their Article 53 GPAI documentation. That is the live obligation. If a vendor cannot supply it, that tells you something about how they are managing the broader regulatory requirements.

Document your Article 4 literacy programme. Even if your function is below the Annex III threshold, the literacy requirement applies. The function whose people have been through a structured AI literacy session is the function whose audit committee can show the work.

The CFO 11 questions post covers the broader pre-deployment governance framework. The AI Act compliance posture is one layer of that, not the whole of it.


Where this lands

The EU AI Act is the most ambitious AI legislation in force globally. It is also narrower in its actual deployer obligations on a typical finance function than the headlines suggest. The August 2026 deadline is moving. The literacy and GPAI obligations are already binding and largely unhandled. The audit committee question that lands in the next twelve months is not “are we ready for Annex III.” It is “what is our actual AI Act compliance posture, and can we evidence it.”

The function that has answered that question already is the function whose next audit goes well. The function that has not is the function that will discover the answer in a written supervisory enquiry.


Maebh Collins is a Fellow Chartered Accountant (FCA, ICAEW) with Big 4 training and twenty years of operational experience as a founder and senior finance leader, based in Ireland, working across Ireland, the UK, and Europe.

Back to Blog | AI in Finance →