From 2 August 2026, the EU AI Act expands obligations for banks using AI. This article explains high-risk systems, governance, human oversight, cybersecurity, evidence requirements, and how financial institutions can align AI compliance with DORA and operational resilience.

July 29, 2026
KEY TAKEAWAYS
IN SUMMARY: 2 August 2026 marks the next major compliance milestone of the EU AI Act. Financial institutions should identify where AI is used, classify systems according to risk, implement appropriate governance controls, and align AI management with existing DORA operational resilience requirements.
WHAT DOES THE EU AI ACT MEAN FOR BANKS?
The EU AI Act does not prohibit banks from using artificial intelligence. Instead, it introduces a risk-based framework requiring appropriate governance, documentation, human oversight and cybersecurity controls for certain AI systems, particularly those classified as high risk.
Examples of potentially high-risk AI systems include:
This Sunday, 2 August 2026, marks an important milestone in the European regulatory calendar for artificial intelligence. Not because AI regulation begins on that date, but because it marks a significant expansion in the implementation of the European Union's AI Act.
The first provisions of the AI Act came into force in August 2024 and have been introduced gradually ever since. The ban on prohibited AI practices and AI literacy obligations took effect in February 2025, followed by requirements relating to general-purpose AI models, governance and enforcement in August 2025.
From 2 August 2026, most of the remaining provisions will begin to apply, including transparency requirements and much of the regulatory framework governing high-risk AI systems. However, the implementation timeline does not end there. Certain obligations for high-risk systems will continue to be phased in through 2027 and, in some cases, into 2028. For banks across the European market, this timeline should not simply be viewed as a legal compliance deadline. It is an opportunity to prepare. AI is no longer an isolated innovation initiative; it is becoming part of a bank's regulatory, technological and operational landscape.
The question is no longer whether a bank uses AI. The real question is whether it knows where AI is being used, which processes it influences, what decisions it affects, what data it depends on, who is accountable for it, and what happens when it fails or produces inaccurate results.
AI IS ALREADY EMBEDDED IN BANKING
AI is already embedded across most core banking functions, including fraud detection, credit assessment, anti-money laundering, customer service and internal operations. However, not every AI application presents the same level of regulatory or operational risk.
A system that summarises internal documentation presents very different risks from one that influences lending decisions. Likewise, an AI tool that helps prioritise fraud alerts is fundamentally different from one that automatically takes action on a customer's account, transaction or financial products.
Banks therefore need to distinguish between three levels of AI use:
AI can accelerate analysis, identify unusual patterns, reduce operational workload and support better decision-making. The risks emerge when AI outputs begin influencing important business processes without sufficient traceability, oversight or the ability for human review.
NOT EVERY SENSITIVE USE CASE IS PROHIBITED
The AI Act does not prohibit banks from using AI in sensitive processes. Instead, it classifies AI systems according to risk and requires governance controls appropriate to that level of risk.
Which banking AI systems are considered high risk?
For example, AI used for assessing creditworthiness or credit scoring for individuals may be classified as high-risk. This does not mean these applications are prohibited. Rather, they must comply with strict requirements covering risk management, documentation, traceability, human oversight, robustness and cybersecurity.
Fraud detection is also a critical banking function, although it is treated differently from credit scoring under the regulation. AI models can help detect suspicious behaviour, prioritise alerts and support fraud and security teams. The key is ensuring that high-impact decisions remain subject to appropriate controls, review processes, traceability and escalation mechanisms.
The objective is not to slow AI adoption, but to prevent AI from becoming an uncontrolled "black box" within processes that affect customers, regulated activities or other critical banking functions.
AI AS A CYBER-CRITICAL ASSET
An AI system is far more than a model. It is a combination of code, data, decision logic, prompts, APIs, connectors, credentials, logs, pipelines, internal tools, external suppliers and configuration decisions. Every one of these layers introduces potential risk. For example:
One of the clearest examples is data poisoning. If a fraud detection or anti-money laundering model is trained or fine-tuned using manipulated data, it may learn incorrect patterns. As a result, suspicious behaviour could appear legitimate, while legitimate customer activity could be incorrectly flagged as fraudulent.
Within banking, this is far more than a technical issue. It creates operational, regulatory, financial and, perhaps most importantly, reputational risk.
HOW DOES THE AI ACT INTERACT WITH DORA?
The AI Act and the Digital Operational Resilience Act (DORA) should be considered together within the banking sector, although they address different areas and should not be confused.
DORA does not regulate artificial intelligence itself. Instead, it focuses on the digital operational resilience of financial institutions, covering ICT risk management, incident reporting, resilience testing, business continuity, recovery and third-party technology risk.
The AI Act, by contrast, focuses on trustworthy, risk-based AI, introducing requirements around governance, transparency, record-keeping, human oversight, robustness, cybersecurity and lifecycle management.
The intersection between these two frameworks is particularly important for banks. An AI system used by a financial institution may simultaneously be subject to AI governance obligations while also qualifying as an ICT asset supporting an important or critical banking function.
For this reason, critical AI should not be managed solely by innovation, analytics or business teams. It should form part of the organisation's technology inventory, operational risk framework, cybersecurity programme, third-party risk management, incident response procedures and resilience testing.
FROM POLICIES TO EVIDENCE
Regulatory compliance will not be achieved simply by drafting policies. The real challenge will be demonstrating that the bank remains in control of the AI systems it deploys. Banks should be able to provide clear evidence whenever required, including:
Every financial institution should be asking one fundamental question: If an AI system fails, produces an incorrect recommendation, behaves unexpectedly or is compromised, can the bank reconstruct exactly what happened and respond quickly enough to correct it? If the answer is not documented, tested and supported by evidence, then the system is not truly under control.
HOW SHOULD BANKS GOVERN AI SYSTEMS?
2 August 2026 should be seen as a maturity milestone for European banking. It marks the point at which AI becomes part of the same strategic conversation that already surrounds cybersecurity, operational resilience and third-party technology risk.
The competitive advantage for banks will not come from being the first to adopt AI. It will come from adopting it more effectively than others. This includes implementing strong security, full traceability and the ability to respond rapidly to failures, hallucinations in critical systems or false positives.
In banking, trust cannot simply be claimed; it must be demonstrated, both to regulators and to customers. The AI Act, DORA and the broader wave of digital operational resilience regulation are all designed to ensure that artificial intelligence earns and maintains that trust.
FAQ
Auriga is a top international software solutions company, specialized in end-to-end systems that integrate the various delivery channels used in retail and internet banking.