The essentials
The EU AI Act classifies AI systems into four tiers: Unacceptable Risk (prohibited), High Risk, Limited Risk, and Minimal Risk. For UK financial services, the most consequential obligations apply to High Risk systems — which include AI used in credit scoring, insurance underwriting, employment decisions, and financial market operations.
UK organisations are not automatically exempt. If you deploy AI systems to EU-based clients, operate EU subsidiaries, or use AI systems developed by EU providers, you are likely within scope.
The timeline
The Regulation phases in over three years. Five dates matter, and the last two are the ones a UK firm with EU exposure should be planning against.
- 1 August 2024 — the Act entered into force.
- 2 February 2025 — prohibited practices banned; the AI-literacy duty on providers and deployers applies.
- 2 August 2025 — obligations for general-purpose AI models; the governance bodies and most penalty provisions apply.
- 2 August 2026 — the Act applies in general, including the high-risk obligations for the Annex III use cases in the table below and the transparency duties.
- 2 August 2027 — high-risk obligations for AI embedded in products already covered by EU product-safety law (Annex I).
One caution. In November 2025 the European Commission proposed, in its Digital Omnibus package, to postpone the high-risk obligations — Annex III to as late as December 2027 and Annex I to August 2028 — until harmonised standards are available. That is a proposal until Parliament and Council adopt it; check its status before relying on either date.
High-risk classifications relevant to financial services
| AI application | Classification |
|---|---|
| Credit scoring and creditworthiness assessment | High Risk |
| AI in access to essential private and public services | High Risk |
| Employment, worker management and access to self-employment | High Risk |
| AI systems used in financial market operations | Under review |
| Customer service chatbots with limited output | Limited Risk |
| AI-generated marketing content | Minimal Risk |
What high-risk obligations require
For each system classified as High Risk, organisations must maintain: a risk management system, technical documentation, data governance procedures, transparency documentation for users, human oversight measures, and accuracy and robustness testing.
Most organisations cannot currently demonstrate compliance with these requirements because they do not have a complete inventory of which systems they operate — let alone which are in scope for High Risk classification.
The EAIC approach
The Sentinel engagement classifies every AI system in your estate against EU AI Act risk tiers, quantifies the monetary exposure of non-compliance, and builds the documentation and governance controls required for compliance — with a fixed-fee engagement.
Where you want the answer as a document rather than a live platform, the review runs on paper. Sentinel is for when you want the picture to stay live — the two front doors to the same estate review.