Money and essential services
Credit scores
Core judgement
As at 12 September 2026, the AI Act does not prohibit ordinary credit scoring. It lists AI that evaluates a person’s creditworthiness or establishes a credit score as high-risk, except when the system detects financial fraud.1 An enacted amendment moved the main duties to 2 December 2027.2
Since 2 August 2026, Article 86 requires the lender or other deployer to explain AI’s role and the main elements of a legally or similarly significantly adverse decision based on the output of an Annex III high-risk system. The relevant market-surveillance authority enforces the AI Act and can receive an Article 85 complaint. For a regulated lender, this will normally be the national financial supervisor.1 However, Article 86 applies only where EU law does not already provide an equivalent explanation right. Its current trigger refers to an Annex III high-risk system even though the classification rules apply later. No guidance or ruling supplied here resolves that interim problem.
The figure shows where the current and later safeguards attach during a credit decision.
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 900 460" role="img" aria-labelledby="credit-title" font-family="system-ui, sans-serif">
<title id="credit-title">Safeguards applying to an AI-assisted credit decision</title>
<rect x="30" y="35" width="190" height="85" rx="12" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="125" y="70" text-anchor="middle" fill="currentColor" font-size="18">Credit application</text>
<text x="125" y="98" text-anchor="middle" fill="currentColor" font-size="16">Personal data supplied</text>
<line x1="220" y1="77" x2="285" y2="77" stroke="currentColor" stroke-width="2"/>
<polygon points="285,77 272,69 272,85" fill="currentColor"/>
<rect x="290" y="35" width="230" height="85" rx="12" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="405" y="68" text-anchor="middle" fill="currentColor" font-size="18">AI score or assessment</text>
<text x="405" y="96" text-anchor="middle" fill="currentColor" font-size="16">Listed credit-scoring use</text>
<line x1="520" y1="77" x2="585" y2="77" stroke="currentColor" stroke-width="2"/>
<polygon points="585,77 572,69 572,85" fill="currentColor"/>
<rect x="590" y="35" width="280" height="85" rx="12" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="730" y="68" text-anchor="middle" fill="currentColor" font-size="18">Loan decision</text>
<text x="730" y="96" text-anchor="middle" fill="currentColor" font-size="16">Approval, refusal or terms</text>
<rect x="30" y="165" width="250" height="120" rx="12" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="155" y="195" text-anchor="middle" fill="currentColor" font-size="18">GDPR since May 2018</text>
<text x="155" y="224" text-anchor="middle" fill="currentColor" font-size="16">Controller duties if the decision</text>
<text x="155" y="248" text-anchor="middle" fill="currentColor" font-size="16">is based solely on automation</text>
<text x="155" y="272" text-anchor="middle" fill="currentColor" font-size="16">DPA and courts enforce</text>
<rect x="325" y="165" width="250" height="120" rx="12" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="450" y="195" text-anchor="middle" fill="currentColor" font-size="18">AI Act since August 2026</text>
<text x="450" y="224" text-anchor="middle" fill="currentColor" font-size="16">Article 86 deployer explanation</text>
<text x="450" y="248" text-anchor="middle" fill="currentColor" font-size="16">Market authority enforces</text>
<text x="450" y="272" text-anchor="middle" fill="currentColor" font-size="16">Current trigger is unsettled</text>
<rect x="620" y="165" width="250" height="150" rx="12" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="745" y="195" text-anchor="middle" fill="currentColor" font-size="18">AI Act from December 2027</text>
<text x="745" y="224" text-anchor="middle" fill="currentColor" font-size="16">Deployer notice and oversight</text>
<text x="745" y="248" text-anchor="middle" fill="currentColor" font-size="16">Rights impact assessment</text>
<text x="745" y="272" text-anchor="middle" fill="currentColor" font-size="16">Provider data safeguards</text>
<text x="745" y="296" text-anchor="middle" fill="currentColor" font-size="16">Market authority enforces</text>
<line x1="730" y1="120" x2="730" y2="155" stroke="currentColor" stroke-width="2"/>
<polygon points="730,165 722,152 738,152" fill="currentColor"/>
</svg>
Figure: Credit decisions attract current GDPR safeguards, a disputed current explanation trigger and fuller AI Act duties from December 2027.
For an automatic online refusal, the GDPR may be the more practical route now. Since 25 May 2018, Article 22 has required the controller not to make a legally or similarly significant decision based solely on automated processing unless an exception applies. Data-protection authorities and courts enforce this duty.3 For contract-based or consent-based decisions, the controller must offer human intervention, allow the person to express a view and provide a way to contest the decision. Articles 12 to 15 also require the controller to provide meaningful information about relevant automated decision-making and normally answer within one month; national data-protection authorities and courts enforce these duties.3 The Commission specifically identifies automatic online credit refusal as a situation in which human review may be requested.4
From 2 December 2027, Article 26 requires the lender deploying a covered system to provide an AI-use notice and assign competent, authorised human oversight. Article 27 requires that deployer to assess fundamental-rights effects before first use. Articles 10 and 16 require the provider to use sufficiently representative data and address discriminatory bias. The relevant market-surveillance authority, normally the financial supervisor for regulated lending, enforces these duties.1
Boundary. These are duties on lenders and system providers, not a promise that a loan will be approved. Article 86 sets no request format, response deadline or appeal route. National complaint forms and contact points were not mapped. It also remains unclear when a support tool is merely preparatory rather than influential enough to be high-risk.
Quellen
Quizze
An online lender refuses two applications. One refusal is solely automated, while a staff member genuinely decides the other. When is the GDPR Article 22 route more likely to apply?
- To the solely automated refusal, if it has legal or similarly significant effects
- To the human decision, if the staff member considered a software-generated score
- To either refusal, whenever software played any role in assessing the application
Article 22 concerns significant decisions based solely on automated personal-data processing. Genuine human decision-making may take a refusal outside that route.
For an automatically refused online loan, the most immediately usable legal route may be the ____.
- GDPR automated-decision route
- AI Act provider-data regime
- financial-fraud scoring exception
The GDPR has operated since 2018, while the main AI Act credit-scoring safeguards have been deferred.
The AI Act treats ordinary credit scoring as regulated high-risk activity rather than banning it outright.
- True
- False
The Act regulates ordinary credit scoring as high-risk; it does not ban the practice. Fraud-detection systems are excluded from this listing.
Kommentare
Noch keine Kommentare. Fang das Gespräch an.