491 days until the Annex III high-risk deadline — 2 Dec 2027

    EU AI Act readiness
    for fintech — enforced at deploy.

    If your models score credit or price insurance for EU customers, they are high-risk AI systems under Annex III. The Digital Omnibus moved the deadline to December 2027 — deferred, not repealed. Aegis Sovereign classifies your models, assembles the Article 11 technical documentation from evidence you already have, and blocks production deploys until the documentation is complete — so you use the extension to get provably ready.

    Read the compliance guide

    Does the Act apply to your models?

    The classification most fintechs get wrong — including the fraud-detection carve-out that most governance tools miss entirely.

    Credit scoring — HIGH RISK

    Annex III 5(b)

    AI evaluating creditworthiness or establishing credit scores of natural persons is high-risk. Full Article 8–15 obligations apply: risk management, data governance, technical documentation, logging, human oversight.

    Fraud detection — EXEMPT

    Annex III 5(b) carve-out

    Systems used for detecting financial fraud are expressly excluded from the high-risk classification. Our classifier applies the carve-out automatically — and explains when mixed credit+fraud signals void it.

    Life & health insurance pricing — HIGH RISK

    Annex III 5(c)

    Risk assessment and pricing for life and health insurance of natural persons is high-risk. The same documentation and enforcement obligations attach before market placement.

    From registered model to regulator-ready — automatically

    Automatic Annex III classification

    Every registered model is classified against Article 5 and Annex III with the category, legal basis, and rationale — not just a label. Fintech categories, including the fraud carve-out, are first-class.

    Annex IV documentation, assembled — not written

    The full nine-section technical documentation (Article 11) is generated from evidence the platform already holds: training data lineage, performance metrics, disparate-impact fairness results, robustness evaluations, human-oversight gates, and the tamper-evident audit chain.

    Enforced at deploy

    A high-risk model cannot be promoted to production while critical Annex IV items are missing. The gate returns exactly what is outstanding; overrides require a reason and land in the cryptographic audit chain.

    Regulator-grade evidence on demand

    One click exports the technical documentation with completeness scoring and verifiable audit references — the artifact your compliance officer hands to the market surveillance authority.

    What "enforced" actually means

    A real response from the promotion API — not a dashboard warning.

    POST /api/v1/models/credit-scorer-v4/promote

    422 EU_AI_ACT_NOT_READY
    {
      "risk_level": "high",
      "category": "Creditworthiness evaluation / credit scoring (Annex III 5(b))",
      "blocking": [
        "Intended purpose (Annex IV 1(a))",
        "Measures for examination of bias (Art. 10(2)(f-g))",
        "Conformity assessment reference (Art. 43 / Annex IV 8)"
      ],
      "documentation": "/api/v1/models/credit-scorer-v4/eu-ai-act/annex-iv"
    }

    Non-compliance penalties reach €15M or 3% of global turnover for high-risk obligations. Documentation created after an incident is evidence of the violation — documentation enforced before deploy is your defence.

    491 days. Classify your models today.

    The 14-day sandbox includes seeded credit-risk models — see the classification, the generated Annex IV document, and the promotion gate in minutes.

    No credit card · work email · your infrastructure or ours