top of page

AI in Creditworthiness Assessment Following the Adoption of the Digital Omnibus

1 day ago
4 min read

By Piotr Putyra, Managing Partner, Barrister at Dudkowiak & Putyra


More Time, but Compliance Work Must Continue


Artificial intelligence is now standard in credit processes. Scoring algorithms analyse hundreds of variables almost instantly, so decisions take seconds rather than days. This improves risk management and speeds up customers’ access to financing. But more automation also means more responsibility for how the models work and what they decide.

Credit scoring is generally classified as a high-risk system.


Under Regulation (EU) 2024/1689 (the AI Act), AI systems that assess the creditworthiness of natural persons or establish their credit score are generally high-risk. The main exception covers fraud detection. The Article 6(3) derogation is also unavailable where the system profiles natural persons.


The reason is simple: these systems directly affect a person’s economic situation, including whether credit is granted, on what terms, or refused.


Three main areas of risk stand out.

  • Errors scale quickly in highly automated processes; a single flaw in a model can translate into thousands of incorrect decisions.

  • Many machine-learning models offer limited transparency; how they work is often hard to explain, sometimes even to their own designers.

  • There is a risk of unintended discrimination, caused by poor data quality, unrepresentative data, or the way data is processed.


To mitigate these risks, the AI Act sets obligations by role: a bank, fintech or technology company may be a provider, a deployer, or both. Providers of high-risk systems will be responsible for risk management, data governance, documentation, record-keeping, human oversight, accuracy, robustness, cybersecurity, conformity assessment and registration. Deployers of third-party systems must follow the provider’s instructions, assign human oversight, monitor the system, ensure relevant and representative input data, and retain logs.


Deployers of creditworthiness systems must also carry out a fundamental rights impact assessment before first use.



The Digital Omnibus Extends Deadlines: the AI Act Is Not Suspended


The Digital Omnibus created the impression that the AI Act had effectively been postponed. That reading goes too far.


The amending regulation, Regulation (EU) 2026/1744 of 8 July 2026, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The new timeline is therefore confirmed law: Sections 1, 2 and 3 of Chapter III, covering Annex III high-risk systems (including creditworthiness assessment), will apply from 2 December 2027 instead of 2 August 2026.


This gives the financial sector an extra sixteen months to build model risk management, documentation and registration procedures. It is not a suspension: the amendment brings targeted simplifications, but keeps the risk-based architecture and the Annex III classification of creditworthiness systems intact.


Financial institutions should treat the extra time as a chance to put their AI processes in order, not as a reason to halt implementation work.


2 August 2026 Remains Significant


The postponement does not make 2 August 2026 irrelevant. Since that date, the AI Act has applied more broadly, including the transparency obligations in Article 50: providers of AI systems that interact directly with people must make sure users know they are dealing with AI, unless this is obvious from the context. It is not, however, the start of the sanctions regime: penalties (Chapter XII, except Article 101) have applied since 2 August 2025, provided the given obligation itself already applied.


The Omnibus adds one transitional measure here, on the machine-readable marking of synthetic content under Article 50(2). Systems generating synthetic audio, image, video or text that were on the market before 2 August 2026 have until 2 December 2026 to meet this technical requirement; newer systems must comply immediately. The disclosure duty under Article 50(1) is unaffected, so institutions providing their own customer-facing chatbots have had to comply with this disclosure requirement since 2 August 2026. If the chatbot comes from a third party, the obligation generally rests with the provider, but the institution should check that disclosure works in its channel.


Regulatory Compliance Is Already Required Today, Not Only From 2027


The postponement also does not mean that compliance can wait until the end of 2027. Banks and fintechs already operate under rules limiting fully automated credit decisions.

Article 22 of the GDPR gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, with legal or similarly significant effects. The Court of Justice of the EU confirmed this in SCHUFA (C-634/21, 7 December 2023): an automated credit score may itself be a decision under Article 22 if the recipient gives it a determining role.


Outsourcing scoring does not remove an institution’s own GDPR obligations; responsibility depends on the parties’ roles and how the score is used. Where an automated decision falls under an Article 22(2) exception, Article 22(3) requires rights to human intervention, to express one’s view and to contest the decision.


Polish law adds its own layer. Under Article 105a(1a) of the Banking Law, automated creditworthiness and credit-risk decisions are allowed only if the person concerned can obtain an explanation, request human intervention leading to a new decision, and present their position. These duties apply today, regardless of the AI Act timeline.


Article 70a of the Banking Law requires banks and other lenders authorised by statute to provide, on request, a written explanation of their creditworthiness assessment. The applicant must be told, in clear language and on a durable medium, of this right and its deadline. The request may be made within one year; the answer must follow within 30 days. The explanation must identify the factors, including personal data, behind the assessment, also where it was fully automated. UKNF guidance of 21 July 2020, though not binding, expects individualised, detailed information rather than general data categories.


For complex AI models, that can be demanding.


In short, the AI Act does not replace or weaken existing obligations under the GDPR or national banking law. Institutions must implement AI so that they comply with all these regimes at once, especially on transparency, explainability and effective human oversight.

 
 
bottom of page