// news · policy2026-08-13source: European Commission / legal analysis

The EU AI Act's high-risk obligations reach credit scoring and insurance pricing

August is the point at which duties for many high-risk systems stop being a roadmap and become law — including uses like creditworthiness assessment and risk pricing in life and health insurance. Penalties under Article 99 run to €15m or 3% of worldwide turnover for GPAI breaches and €35m or 7% for prohibited practices.

The GPAI enforcement powers that activated on 2 August got the coverage. The high-risk annex is the part that will actually change how European firms deploy, because it does not regulate model builders — it regulates the people using models to make decisions about individuals.

The listed uses are specific and commercially central: creditworthiness assessment and credit scoring, risk assessment and pricing in life and health insurance, employment and worker-management decisions, education access. For those systems the obligations are the heavy ones — risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment before placing on the market.

The penalty schedule sets the seriousness. Article 99 provides for up to €35m or 7% of global turnover for prohibited practices, and up to €15m or 3% for GPAI obligations, in each case the higher of the two. For a large European bank or insurer, 3% of worldwide turnover is not a compliance line item.

The practical bind is that many of these systems predate the Act by a decade and were never documented to this standard. The compliance question is rarely "is our model fair" — it is "can we produce the technical file for a scoring system three vendors and two acquisitions ago." That is an archaeology problem, and archaeology takes longer than legal review.

See our analysis →

Holland & Knight — U.S. Companies Face EU AI Act's Possible August 2026 Compliance Deadline → · EU AI Act — Article 99: Penalties → · European Commission — Regulatory framework for AI →