EU AI Act Delays Offer Financial Services More Time, Not Less Responsibility

Finance and insurance organisations have been given some respite from the upcoming EU AI Act changes, but they need to utilise this extra time to strengthen their AI governance.
EU AI Act Delays Offer Financial Services More Time, Not Less Responsibility

The European Parliament has approved amendments to the AI Act that postpone several key compliance deadlines while making targeted refinements to the legislation. The changes acknowledge industry concerns that organisations lacked the technical guidance and harmonised standards needed to implement the regulation effectively. 

For banks and insurers as highly regulated firms, the most significant change is the postponement of obligations for high-risk AI systems. Standalone systems covered by Annex III (including those used in creditworthiness assessments, recruitment, education, and law enforcement) will now be subject to the Act from 2 December 2027, rather than 2 August 2026 as originally planned. High-risk AI embedded within regulated products will have until 2 August 2028 to comply, while watermarking requirements for certain AI-generated content have been deferred until December 2026. 

EU AI Act Implementation Timeline
The new timeline for the implementation of the EU AI Act provides some space for leaders, but also other considerations.
 

A welcome pause amid a complex regulatory landscape 

For financial institutions, the revised timeline offers an opportunity to better align AI governance with existing regulatory frameworks, rather than treating the AI Act as another standalone compliance exercise. 

Many organisations are already navigating a growing web of AI-related obligations, including the Digital Operational Resilience Act (DORA), GDPR, the forthcoming Financial Data Access (FiDA) framework, sector-specific guidance from the European Banking Authority and EIOPA, and supervisory expectations around model risk management. UK firms face an evolving landscape under the FCA’s principles-based approach to AI. 

The additional implementation time allows organisations to integrate AI governance into existing risk, compliance, and operational resilience frameworks instead of building parallel processes. 

 

Governance maturity remains the priority 

While the deadlines have shifted, the direction of travel has not. For financial services organisations, regulators continue to expect robust governance over AI systems, particularly where they influence lending decisions, fraud detection, underwriting, claims handling, customer service, or financial advice. 

The delay should be viewed as an opportunity to improve governance maturity and not an opportunity to postpone action. 

For data and AI leaders in finance and insurance, priorities over the next 18 months are unlikely to change significantly. Organisations should continue to: 

  • Maintain an inventory of AI systems and understand where they fall within the AI Act’s risk classifications.  
  • Strengthen governance around model development, validation, monitoring, and documentation.  
  • Embed clear accountability across technology, data, risk, and compliance functions.  
  • Prepare for evolving technical standards and regulatory guidance as implementation becomes more defined.  
  • Ensure AI governance complements existing operational resilience, model risk, and data governance frameworks.  

 

The implications remain global 

The AI Act’s extraterritorial scope means its impact extends well beyond EU-headquartered organisations. UK, US, and APAC firms may still fall within scope if they develop AI systems placed on the EU market or if those systems generate outputs used within the EU. 

For multinational financial institutions, this reinforces the need for globally consistent governance rather than region-specific compliance. As AI regulations evolve across jurisdictions, organisations with mature governance foundations will be better positioned to adapt than those responding to each regulatory development in isolation. 

The revised timeline offers welcome flexibility, but it does not alter the expectation that AI should be governed with the same rigour as any other critical capability within a regulated financial institution. The organisations that use this additional time to embed governance into their operating model will be in the strongest position when the deadlines arrive. 

 

Join DataIQ to receive in-depth insights and learnings to enhance your data and AI capabilities.