[{"data":1,"prerenderedAt":362},["ShallowReactive",2],{"blog-\u002Fblog\u002Feu-ai-act-high-risk-requirements-finance-systems":3,"blog-related-\u002Fblog\u002Feu-ai-act-high-risk-requirements-finance-systems":339,"blog-surround-\u002Fblog\u002Feu-ai-act-high-risk-requirements-finance-systems":361},{"id":4,"title":5,"audience":6,"body":11,"cluster":289,"conversionGoal":290,"cornerstone":291,"date":292,"description":293,"draft":291,"extension":294,"factCheckedAt":292,"faq":295,"featured":291,"language":290,"meta":308,"minRead":309,"navigation":310,"order":311,"originalAsset":290,"path":312,"pillar":313,"primaryKeyword":314,"publicationOrder":315,"relatedProject":290,"releaseScope":316,"reviewCycle":317,"reviewMethod":318,"reviewStatus":319,"reviewedAt":292,"reviewedBy":320,"searchIntent":321,"seo":322,"sources":323,"stem":333,"tags":334,"type":337,"updated":292,"__hash__":338},"blog\u002Fblog\u002Feu-ai-act-high-risk-requirements-finance-systems.md","The EU AI Act's High-Risk Rules Are a Control Environment",[7,8,9,10],"enterprise-architect","finance-transformation-lead","financial-controller","transformation-lead",{"type":12,"value":13,"toc":280},"minimark",[14,22,28,33,36,70,73,79,82,86,89,101,122,133,144,150,156,177,181,184,187,195,203,207,210,216,226,237,248,252,255,258,266],[15,16,17,21],"p",{},[18,19,20],"strong",{},"On 2 August 2026 the European Union's biggest AI compliance deadline arrived, and most of it was not there."," The high-risk requirements everyone had been preparing for had been moved sixteen months earlier that summer, to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in products that are already regulated. The transparency duties in Article 50 did arrive, on the original date. So a lot of published guidance is now describing a deadline that did not happen, and a lot of programmes have quietly relaxed against a date that has not actually gone away — it has moved to a point where the work is bigger.",[15,23,24,25],{},"I am not a lawyer and nothing here is legal advice; whether a particular system falls in scope is a legal determination about that system in that use. What I can offer is the other half, which is much less written about: ",[18,26,27],{},"what the high-risk requirements actually ask you to build, and why a finance function has most of it already, under different names.",[29,30,32],"h2",{"id":31},"what-moved-and-what-did-not","What moved, and what did not",[15,34,35],{},"The Act entered into force on 1 August 2024 and applies in stages. The stages that are already live matter more than the one that slipped.",[37,38,39,46,52,58,64],"ul",{},[40,41,42,45],"li",{},[18,43,44],{},"2 February 2025"," — the prohibitions on unacceptable-risk practices, and the AI literacy obligation, began to apply. The literacy duty survived the Omnibus in a weakened form; it did not disappear.",[40,47,48,51],{},[18,49,50],{},"2 August 2025"," — obligations on providers of general-purpose AI models began to apply.",[40,53,54,57],{},[18,55,56],{},"2 August 2026"," — the Article 50 transparency duties applied as originally scheduled: disclose that a person is interacting with an AI system, and mark AI-generated or manipulated content. A short grace period applies to systems already on the market.",[40,59,60,63],{},[18,61,62],{},"2 December 2027"," — the high-risk requirements for Annex III stand-alone systems, moved from 2 August 2026.",[40,65,66,69],{},[18,67,68],{},"2 August 2028"," — the high-risk requirements for Annex I systems embedded in already-regulated products, moved from 2 August 2027.",[15,71,72],{},"The mechanism is worth one sentence because it changes how much you can rely on the dates. The Commission's original proposal made the deferral conditional on standards being ready; the agreed text replaced that with fixed dates. So these are dates, not triggers, and planning against them is reasonable.",[74,75,76],"pull-quote",{},[15,77,78],{},"A deferred deadline is not a smaller obligation. It is the same obligation, with more systems in scope by the time it lands.",[15,80,81],{},"That last point is the one I would put in front of a steering committee. Sixteen months is not relief if the number of AI-touching processes in your landscape doubles in the same period, which on current trajectory it will. The programmes that will find December 2027 comfortable are the ones treating the extension as time to build the evidence, not time to stop.",[29,83,85],{"id":84},"the-requirements-in-the-language-you-already-use","The requirements, in the language you already use",[15,87,88],{},"Chapter III, Section 2 of the Act sets out what a high-risk system must have. Read the seven articles cold and they sound like a new discipline. Read them as someone who has implemented financial systems and they are almost entirely familiar — because they are the same answers to the same problem, which is how you let a system do something consequential and still be able to say what happened and why.",[15,90,91,94,95,100],{},[18,92,93],{},"Article 9 — Risk management system."," A continuous, documented process for identifying what could go wrong across the lifecycle and doing something about it. This is a risk register with an owner and a review cadence. Every programme I have delivered ran one; the discipline that makes it real rather than decorative is that each entry carries an owner, a date and a next action, which is exactly what a ",[96,97,99],"a",{"href":98},"\u002Fblog\u002Fraid-log-risks-assumptions-issues-dependencies","RAID log"," is for.",[15,102,103,106,107,111,112,116,117,121],{},[18,104,105],{},"Article 10 — Data and data governance."," Training, validation and test data must be governed: relevant, representative, and examined for gaps and bias. A finance function has fought this fight already, in the form of ",[96,108,110],{"href":109},"\u002Fblog\u002Ftreasury-data-quality-and-governance","data quality and governance"," and the question of ",[96,113,115],{"href":114},"\u002Fblog\u002Ftreasury-system-of-record","which system owns which record",". The novelty is not the requirement. It is that a model makes bad data ",[118,119,120],"em",{},"confident"," rather than obviously wrong.",[15,123,124,127,128,132],{},[18,125,126],{},"Article 11 — Technical documentation."," A description of what the system is, how it was built, what it was tested against and how it performs. This is a ",[96,129,131],{"href":130},"\u002Fblog\u002Fsolution-design-and-blueprint-for-finance-systems","solution design document"," that stayed current — which is the hard part, and the reason most technical documentation fails an audit is not that it was never written.",[15,134,135,138,139,143],{},[18,136,137],{},"Article 12 — Record-keeping."," Automatically generated logs of events over the system's lifetime. Not a dashboard: records, at the grain of an event, retained. A treasury systems person will recognise this immediately as ",[96,140,142],{"href":141},"\u002Fblog\u002Faudit-trails-and-logging-treasury-systems","audit trails and logging",", and will also recognise the trap — a log that aggregates cannot answer the only question anyone ever actually asks, which is what happened to this specific record on this specific day.",[15,145,146,149],{},[18,147,148],{},"Article 13 — Transparency and provision of information to deployers."," The people operating the system must be told what it does, what its limitations are, and the conditions under which it works. In practice this is the honest version of a functional specification: not what it is supposed to do, but where it stops being reliable.",[15,151,152,155],{},[18,153,154],{},"Article 14 — Human oversight."," The system must be designed so a person can understand its output, decide not to act on it, and intervene. This is the closest match of all, and I will come back to it.",[15,157,158,161,162,166,167,171,172,176],{},[18,159,160],{},"Article 15 — Accuracy, robustness and cybersecurity."," It has to work, keep working under conditions it was not shown, and resist manipulation. This is ",[96,163,165],{"href":164},"\u002Fblog\u002Ftesting-strategy-for-finance-systems","testing strategy",", ",[96,168,170],{"href":169},"\u002Fblog\u002Finterface-monitoring-and-reconciliation","interface monitoring",", and ",[96,173,175],{"href":174},"\u002Fblog\u002Faccess-management-and-user-provisioning-treasury","access management",", applied to a component whose failure mode is producing a plausible wrong answer rather than an error.",[29,178,180],{"id":179},"human-oversight-is-the-one-that-will-be-got-wrong","Human oversight is the one that will be got wrong",[15,182,183],{},"Article 14 is where I would spend the attention, because it is the requirement most likely to be satisfied on paper and failed in operation.",[15,185,186],{},"The Act asks that oversight be effective — that the person can interpret the output, is aware of the risk of automation bias, can decide not to use the system, and can stop it. What that means in a real process is a throughput question, not a policy question. If a reviewer is presented with four hundred items and the process assumes they clear them in an afternoon, they are approving at a rate that makes reading impossible, and the oversight is decorative.",[15,188,189,190,194],{},"Finance already knows this failure. It is the four-eyes approval where the second signature is a habit, the exception queue nobody has time to work, the control that exists in the procedure document and not in anyone's day. The ",[96,191,193],{"href":192},"\u002Fblog\u002Fsegregation-of-duties-in-treasury-systems","segregation of duties"," discipline exists precisely because a control that cannot be exercised is not a control — and that reasoning transfers directly to a component that produces output faster than any human can evaluate it.",[15,196,197,198,202],{},"The design question, then, is not \"who signs off\". It is: what is the reviewer shown, how long do they have, what does declining cost them, and what evidence is captured when they accept. That is a workflow decision, and it is the same one as ",[96,199,201],{"href":200},"\u002Fblog\u002Fhuman-decision-rights-in-ai-native-workflows","who decides what, on what evidence",".",[29,204,206],{"id":205},"what-i-would-actually-do-with-the-extra-sixteen-months","What I would actually do with the extra sixteen months",[15,208,209],{},"Not compliance work. Inventory and design work, which is cheaper now than later and useful even if nothing in your landscape turns out to be high-risk.",[15,211,212,215],{},[18,213,214],{},"Know what you have."," Most organisations cannot currently list the AI-touching processes in their own landscape, because several arrived as features of software they already owned rather than as projects. You cannot classify what you have not enumerated, and the enumeration is a week of work that gets harder every quarter.",[15,217,218,221,222,225],{},[18,219,220],{},"Establish scope early, and write down the reasoning."," Whether a given system is high-risk is a legal determination — but the ",[118,223,224],{},"inputs"," to it are yours: what the system decides, about whom, with what consequence. Having that written before someone asks is the difference between a conversation and a project.",[15,227,228,231,232,236],{},[18,229,230],{},"Build the record-keeping first, whatever the classification."," Article 12-style logging is the requirement with the longest lead time and the widest usefulness. You cannot retrofit a log of what the system did last quarter. And if it turns out nothing you run is high-risk, you still have ",[96,233,235],{"href":234},"\u002Fblog\u002Fproduction-ai-observability","the observability"," that makes the thing debuggable, which you wanted anyway.",[15,238,239,242,243,247],{},[18,240,241],{},"Treat the control layer as the deliverable."," The requirements above are not properties of a model — they are properties of what surrounds it. Which is the argument I would make regardless of regulation: the safety and auditability of an AI capability live in ",[96,244,246],{"href":245},"\u002Fblog\u002Fthe-enterprise-ai-control-layer","the control layer",", not in the choice of model, and building that layer is what turns a deferral into a head start.",[29,249,251],{"id":250},"the-honest-summary","The honest summary",[15,253,254],{},"The deadline moved; the work did not. And the work is less alien than the framing around it suggests, because the requirements are a restatement — in unfamiliar vocabulary, for an unfamiliar component — of the control environment a regulated finance function has been running for decades. Risk register, data governance, current documentation, event-grain logs, honest limitations, real oversight, tested robustness.",[15,256,257],{},"The organisations that will struggle in December 2027 are not the ones with weak models. They are the ones that cannot say what their AI systems did, to what, on whose authority — which is the same thing that has always separated a system you can operate from a system you merely own.",[15,259,260,261,265],{},"If you want the same ground covered voluntarily rather than legally, ",[96,262,264],{"href":263},"\u002Fblog\u002Fnist-ai-rmf-functions-and-categories","the NIST AI Risk Management Framework"," organises it into four functions and nineteen categories, and most of them turn out to be controls a finance function already runs.",[15,267,268],{},[118,269,270,271,275,276,202],{},"See also ",[96,272,274],{"href":273},"\u002Fblog\u002Fwhy-enterprise-ai-is-an-architecture-problem","why enterprise AI is an architecture problem"," and ",[96,277,279],{"href":278},"\u002Fblog\u002Fagent-identity-and-permissions","agent identity: who is the AI acting as?",{"title":281,"searchDepth":282,"depth":282,"links":283},"",2,[284,285,286,287,288],{"id":31,"depth":282,"text":32},{"id":84,"depth":282,"text":85},{"id":179,"depth":282,"text":180},{"id":205,"depth":282,"text":206},{"id":250,"depth":282,"text":251},"governance",null,false,"2026-08-19","The high-risk deadline moved to December 2027. What the rules ask for did not move — and a finance function already runs most of it under other names.","md",[296,299,302,305],{"question":297,"answer":298},"Did the EU AI Act high-risk deadline move?","Yes, for the high-risk obligations specifically. Under the Digital Omnibus amendments, which the European Parliament approved on 16 June 2026, the requirements for Annex III stand-alone high-risk systems moved from 2 August 2026 to 2 December 2027, and the requirements for Annex I systems embedded in already-regulated products moved from 2 August 2027 to 2 August 2028. Fixed dates replaced the conditional trigger mechanism the Commission had originally proposed. What did not move is everything else: the prohibitions and the AI literacy duty have applied since February 2025, the general-purpose AI model obligations since August 2025, and the Article 50 transparency duties took effect on schedule on 2 August 2026.",{"question":300,"answer":301},"Which parts of the EU AI Act already apply in 2026?","Three groups. The prohibitions on unacceptable-risk practices and the AI literacy obligation have applied since 2 February 2025. The obligations on providers of general-purpose AI models have applied since 2 August 2025. The Article 50 transparency duties — telling a person they are interacting with an AI system, and marking AI-generated content — applied from 2 August 2026 as originally scheduled, with a short grace period for systems already on the market. Only the high-risk requirements in Articles 9 to 15 were deferred.",{"question":303,"answer":304},"Is an internal finance AI tool a high-risk AI system?","Usually not, and that is worth establishing early rather than assuming either way. Annex III lists the categories that make a stand-alone system high-risk, and ordinary finance operations — reconciliation, cash forecasting, close support — are not among them. Systems used in creditworthiness assessment of natural persons, or in employment decisions, are. This is a legal determination about a specific system in a specific use, not something to settle from a blog post; the point of establishing it early is that the answer changes how much documentation you need, and finding out late is what makes it expensive.",{"question":306,"answer":307},"What does the AI Act require for human oversight?","Article 14 requires that high-risk systems be designed so that a person can genuinely oversee them — understand what the system is doing, interpret its output, decide not to use it, and intervene or stop it. The word that does the work is 'genuinely'. An oversight arrangement where a person approves faster than they could possibly read is not oversight, and a finance function already knows this: it is the same failure as a four-eyes control where the second pair of eyes clicks through. The design question is what the reviewer is shown and how much time the throughput allows them.",{},12,true,7,"\u002Fblog\u002Feu-ai-act-high-risk-requirements-finance-systems","enterprise-ai-systems","EU AI Act high-risk requirements",216,"EU AI Act as amended by the Digital Omnibus, approved by the European Parliament on 16 June 2026. Dates verified 19 August 2026.","semiannual","editorial-and-factual","reviewed","Tan Gravam","informational",{"title":5,"description":293},[324,327,330],{"title":325,"url":326,"accessed":292},"EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes (Gibson Dunn)","https:\u002F\u002Fwww.gibsondunn.com\u002Feu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes\u002F",{"title":328,"url":329,"accessed":292},"EU Approves Delays and Other Amendments to Certain EU AI Act Obligations (Morgan Lewis)","https:\u002F\u002Fwww.morganlewis.com\u002Fpubs\u002F2026\u002F06\u002Feu-approves-delays-and-other-amendments-to-certain-eu-ai-act-obligations-what-businesses-should-know",{"title":331,"url":332,"accessed":292},"EU AI Act — Chapter III, Section 2: Requirements for High-Risk AI Systems (Articles 9–15)","https:\u002F\u002Fartificialintelligenceact.eu\u002Fchapter\u002F3\u002F","blog\u002Feu-ai-act-high-risk-requirements-finance-systems",[335,336,289],"enterprise-ai","controls","text","GkOXg5FKr27vk5XFeJJdsu2j2uY01XeelgU0fjFp2As",{"related":340,"prev":352,"next":355,"hasOrder":310,"place":357},[341,345,348],{"path":342,"title":343,"description":344},"\u002Fblog\u002Fowasp-llm-top-10-2026-for-enterprise-finance","The OWASP LLM Top 10 (2026), Read From a Finance Seat","All ten 2026 entries with what changed from 2025 — and which of them a finance or treasury deployment actually meets first.",{"path":234,"title":346,"description":347},"Production AI Observability in the Enterprise","You can't fix what you can't see. How to observe AI running inside an enterprise — quality, cost, latency, drift and failures — as data, not complaints.",{"path":349,"title":350,"description":351},"\u002Fblog\u002Fai-evaluation-and-regression-testing","Enterprise AI Evaluation & Regression Testing","How to build eval sets for AI running inside an enterprise — cases, scoring, a regression gate — so a prompt or model change is judged on evidence, not vibes.",{"path":353,"title":354,"type":337,"language":290},"\u002Fblog\u002Fprompt-and-model-versioning","Prompt & Model Versioning: Enterprise AI Governance",{"path":263,"title":356,"type":337,"language":290},"NIST AI RMF: The Functions and Categories, Explained",{"label":358,"position":359,"total":282,"hub":360},"Governance",1,"\u002Ftopics\u002Fenterprise-ai-systems",[],1787169868013]