Skip to main content
< Back to all insights
  • Rules for stand-alone high-risk AI systems now applying from 2 December 2027.
  • Transparency obligations still took effect on 2 August 2026.
  • The share of companies scrapping most AI initiatives before production rose from 17% to 42% year over year.

Most banks heard that the EU had delayed the AI Act and switched off. That reading is understandable, but it’s also incomplete. The implementation of the EU AI Act’s high-risk obligations has moved, with rules for stand-alone high-risk AI systems now applying from 2 December 2027, and rules for high-risk AI embedded in regulated products applying from 2 August 2028.

However, the transparency rules of the AI Act still came into effect on 2 August 2026. The delay does not mean that AI risk has diminished for banks. Instead, it reflects something more practical: the standards, guidance and tools needed to support implementation were not ready. The European Commission has described the revised timetable as a way to ensure rules apply when companies have the right support tools, such as standards, to facilitate implementation.

That makes the additional 16 months a trap as well as an opportunity. Banks that treat the extension as permission to wait will face the same work later, under greater time pressure. Banks that use the window well can build the governance and technical foundations required to deploy AI safely, evidence decisions and prepare for the high-risk rules before they bite.

What does the EU AI Act delay mean for banks?

The first task is to separate what changed from what did not.

What changed is the application date for high-risk obligations. The AI Omnibus Regulation entered into force on 27 July 2026, setting new dates of 2 December 2027 for stand-alone high-risk AI systems and 2 August 2028 for high-risk AI systems embedded in products.

What has not changed is just as important. Transparency obligations still took effect on 2 August 2026. Existing legal requirements also remain in force. Banks using AI are still operating under GDPR, DORA and sector-specific financial regulation. DORA, for example, has applied since 17 January 2025 and continues to shape expectations around operational resilience and ICT risk management in financial services.

Nor has the AI Act’s basic logic changed. High-risk AI systems remain subject to strict obligations around risk management, data quality, logging, documentation, transparency, human oversight, robustness, cybersecurity and accuracy. The Commission’s own summary of the Act places credit scoring among the high-risk use cases relevant to access to essential private and public services.

So the delay should not be read as a weakening of the regulation. It is a revised implementation timetable. The destination is the same.

The 16-month window is time to build the foundation

The additional 16 months do not change what banks will ultimately need to demonstrate under the EU AI Act. High-risk AI systems will still need to meet requirements relating to data governance, documentation, record-keeping, transparency, human oversight and ongoing control.

A governed data foundation matters because it gives banks the underlying data, controls and auditability needed to meet those requirements in practice.

Connecting data governance to compliance

For high-risk AI systems, compliance starts with the data itself. Banks need to know which data is being used, where it comes from, how it has been transformed and whether it is appropriate for the intended use case.

That is difficult when data is spread across legacy systems, product lines and business units. A governed data foundation creates a more consistent view. It gives banks reliable data, clear ownership and common definitions across the systems feeding AI applications.

It also provides lineage. Banks may need to show not only what an AI system produced, but how the underlying information contributed to that output. Without that traceability, data governance remains a policy statement rather than an operational capability.

Policy controls are just as important. Banks need to ensure that data is accessed and used only in permitted ways, particularly where AI systems depend on sensitive customer, transactional or risk data.

Supporting documentation and record-keeping

The AI Act also places significant weight on technical documentation and record-keeping. For banks, that cannot be treated as a template to complete at the end of the process.

A complete audit trail needs to connect the data, model, policy, approval and action associated with an AI-supported decision. That allows the bank to reconstruct how a system operated, which controls applied and who approved the relevant process.

This is especially important in banking, where AI may support decisions that affect access to credit, fraud detection, customer treatment or compliance outcomes. Internal risk teams, auditors and regulators need evidence, not simply assurances.

A governed data foundation gives banks the structure to produce that evidence consistently.

Maintaining oversight and control

Compliance depends on effective oversight. Banks need visibility over where AI systems run, how they perform and when human intervention is required.

That makes deployment control part of the compliance architecture. Banks need to understand where data is processed, which systems have access to it and how third-party technology is governed.

This is where sovereignty becomes more than a procurement slogan. On-premise, customer-cloud and sovereign-cloud deployment models all speak to the same underlying requirement: banks need to keep AI within a control boundary they can manage, monitor and evidence.

Operational resilience, auditability and sovereignty therefore belong in the foundation itself. They cannot be added later as separate controls once AI is already in production.

Why the work needs to begin now

These requirements cannot be met through documentation alone. They depend on data architecture, governance processes, monitoring capabilities and audit mechanisms that often span several legacy systems.

That is why the 16-month extension matters. It gives banks time to build the foundation before the high-risk obligations apply. It does not make the foundation optional.

Banks that begin now can move toward production with governance, auditability and control already in place. Those that treat the delay as a pause risk leaving the most difficult implementation work until the final months.

Banks have 16 months to build compliant AI foundations before EU AI Act high-risk rules apply.

MythReality
The AI Act has been delayed, so banks can wait.The delay is a 16-month build window, not a pause.
Compliance starts in December 2027.Article 50 transparency obligations have applied since 2 August 2026, while existing requirements under GDPR, DORA and banking regulation remain in force.
AI compliance is mainly about documentation.Documentation depends on underlying capabilities such as data governance, lineage, auditability and operational controls.
Banks can address governance once AI is in production.Governance, monitoring and deployment controls need to be built into AI systems from the outset.
Building everything internally is the safest option.An internal build can increase cost, delay and execution risk because banks must develop the data, governance and deployment capabilities required for compliant AI.

The build is the risk hidden in the EU AI Act delay

There is another trap inside the delay. Banks may assume that, because they now have more time, they can build the required data, governance and deployment capabilities entirely in-house.

For some institutions, that may be possible. But it is not a low-risk choice.

An internal build means bringing together fragmented banking data, establishing lineage and policy control, creating end-to-end audit trails, supporting secure deployment and maintaining the specialist expertise needed to operate the environment over time. All of that has to happen while the bank continues to manage regulatory, operational, security and delivery risk.

The broader enterprise AI market shows how difficult that transition can be. S&P Global Market Intelligence found that the proportion of companies abandoning most of their AI initiatives before production increased from 17% to 42% year over year, with the average organization scrapping 46% of proof-of-concept projects before production.

For banks, the lesson is not that AI should be outsourced without scrutiny. Governance and accountability remain with the institution. The lesson is that building the foundation for compliant AI is itself a source of risk.

The share of companies scrapping most AI initiatives before production rose from 17% to 42% year over year.
According to: S&P Global. (2025). Generative AI experiences rapid adoption, but with mixed outcomes – Highlights from VotE: AI & Machine Learning

Working with a specialist provider

This is where the next 16 months should focus the procurement conversation. Banks do not need AI experiments that create new governance gaps. They need a foundation that allows AI to move into production within the bank’s control boundary, with the data, lineage, policy controls and auditability required for regulated use cases.

Working with a specialist provider can give banks access to those capabilities without requiring them to build the entire foundation from scratch. It can also shorten the route from experimentation to production, while allowing the bank to retain responsibility for oversight and control.

SBS AI Foundation is designed around that need. It provides a governed, banking-aware data foundation with generative AI built on top. It can be deployed on the bank’s own terms, including on-premise, in the customer’s cloud or in a sovereign cloud environment. It includes pre-built banking semantics, full data lineage, policy controls and an audit trail covering data, model, policy, approval and action.

That matters because the AI Act is not asking banks to prove that they have written a policy. It is asking them to show that high-risk AI can be understood, governed and controlled in practice.

The delay gives banks time to do that work properly. But it does not make the work optional. The institutions that move now can use the window to build the foundation, reach production and prepare for compliance before 2027. Those that wait may discover that the hardest part of the AI Act was never the deadline, but the build itself.

Contact a member of the SBS team today and find out how your bank can use the 16-month window to build a governed, sovereign foundation for compliant AI.

FAQ: Key facts about the EU AI Act delay

Only partly. The application date for certain high-risk AI obligations has moved, but Article 50 transparency obligations have applied since 2 August 2026. Existing requirements under GDPR, DORA and sector-specific banking regulation also remain in force.

Xavier Rebeuf

Xavier Rebeuf

Chief Product & Technology Officer

You might also like this content