If your models score credit or price insurance for EU customers, they are high-risk AI systems under Annex III. The Digital Omnibus moved the deadline to December 2027 — deferred, not repealed. Aegis Sovereign classifies your models, assembles the Article 11 technical documentation from evidence you already have, and blocks production deploys until the documentation is complete — so you use the extension to get provably ready.
The classification most fintechs get wrong — including the fraud-detection carve-out that most governance tools miss entirely.
Annex III 5(b)
AI evaluating creditworthiness or establishing credit scores of natural persons is high-risk. Full Article 8–15 obligations apply: risk management, data governance, technical documentation, logging, human oversight.
Annex III 5(b) carve-out
Systems used for detecting financial fraud are expressly excluded from the high-risk classification. Our classifier applies the carve-out automatically — and explains when mixed credit+fraud signals void it.
Annex III 5(c)
Risk assessment and pricing for life and health insurance of natural persons is high-risk. The same documentation and enforcement obligations attach before market placement.
Every registered model is classified against Article 5 and Annex III with the category, legal basis, and rationale — not just a label. Fintech categories, including the fraud carve-out, are first-class.
The full nine-section technical documentation (Article 11) is generated from evidence the platform already holds: training data lineage, performance metrics, disparate-impact fairness results, robustness evaluations, human-oversight gates, and the tamper-evident audit chain.
A high-risk model cannot be promoted to production while critical Annex IV items are missing. The gate returns exactly what is outstanding; overrides require a reason and land in the cryptographic audit chain.
One click exports the technical documentation with completeness scoring and verifiable audit references — the artifact your compliance officer hands to the market surveillance authority.
A real response from the promotion API — not a dashboard warning.
POST /api/v1/models/credit-scorer-v4/promote
422 EU_AI_ACT_NOT_READY
{
"risk_level": "high",
"category": "Creditworthiness evaluation / credit scoring (Annex III 5(b))",
"blocking": [
"Intended purpose (Annex IV 1(a))",
"Measures for examination of bias (Art. 10(2)(f-g))",
"Conformity assessment reference (Art. 43 / Annex IV 8)"
],
"documentation": "/api/v1/models/credit-scorer-v4/eu-ai-act/annex-iv"
}Non-compliance penalties reach €15M or 3% of global turnover for high-risk obligations. Documentation created after an incident is evidence of the violation — documentation enforced before deploy is your defence.
The 14-day sandbox includes seeded credit-risk models — see the classification, the generated Annex IV document, and the promotion gate in minutes.
No credit card · work email · your infrastructure or ours